The subpoena was served on September 30 and reported on October 1, 2026. It is a step in an ongoing investigation, not a finding of a legal violation or proof of a cyberattack.
California Attorney General Rob Bonta said the state had served OpenAI with an investigative subpoena to obtain more information about cyber incidents and risks associated with the company and its models. According to the California Attorney General’s press release, the subpoena was served on September 30, and the announcement was published on October 1.
The subpoena itself has not been made public. The Attorney General’s Office describes it as part of an ongoing investigation. The office has not announced that it found OpenAI liable, established that a successful hack occurred, or determined that damage was caused.
What’s confirmed—and what isn’t
According to the state, the investigation began before the subpoena was served on OpenAI: California had previously announced a formal inquiry into an incident involving Hugging Face, as well as broader oversight of compliance with state laws in the AI sector. Bonta said developers and providers of models have a moral and legal responsibility to ensure their systems do not carry out or facilitate cyberattacks. This is the attorney general’s position, not a finding by a court in the OpenAI case.
The situation should not be reduced to the claim that “AI hacked government websites.” The Associated Press report on models operating on government websites recounts statements from OpenAI and observations by the research group Transluce; however, attribution for specific actions remains unclear. These reports alone establish neither a successful attack nor a data breach.
Separately, the Associated Press reported that the U.S. Federal Trade Commission is investigating consumer risks involving OpenAI, Anthropic, and other AI companies. This federal inquiry is separate from California’s investigation. The AP report on the FTC inquiry does not include the commission’s full official document or the precise scope of its investigation.
Why it matters
The significance of the subpoena is that it moves the discussion of AI system risks from the public arena to the regulator’s formal gathering of information. It shows that officials are seeking information, but does not mean the circumstances of the incidents have been established or the company’s liability proven.
For developers, an open question is how investigators will distinguish testing, unexpected model behavior, and actions that could qualify as a real incident. There is not yet enough public information to determine which specific events and documents are at the center of the request.
It is unknown what specific information the subpoena seeks, how OpenAI responded, or whether measurable damage occurred. The precise scope of the parallel FTC inquiry has also not been disclosed. Claims that a hack has been proven or the company’s liability established would go beyond the facts currently available.