California Attorney General Served Subpoena on OpenAI

The state investigation examines whether AI developers are failing to prevent models from enabling cyberattacks.

Updated on Oct. 2, 2026 in Artificial Intelligence

Bold flat-color editorial illustration featuring a single, stark server cabinet in navy and cream, evoking institutional regulatory oversight of AI technology.
The California Department of Justice has issued an investigative subpoena to OpenAI as part of a formal inquiry into the cybersecurity risks associated with artificial intelligence models. AI Illustration. Upload story photo >

Live Poll

Should government authorities impose stricter cybersecurity and safety regulations on AI development companies?

The California Department of Justice has served an investigative subpoena on OpenAI as part of a formal inquiry into cybersecurity risks. This probe assesses whether AI developers are adequately ensuring their models do not facilitate cyberattacks.

Why it matters

The investigation reflects a broader push by California regulators to address AI-related risks, including cybersecurity vulnerabilities and the protection of users. It aims to hold developers accountable for the safety and security impacts of their artificial intelligence models.

The California Department of Justice is investigating 12 major AI developers, including OpenAI, to evaluate their compliance with state cybersecurity standards. Specific model vulnerabilities and the scope of incident reporting remain under formal review.

The players

Rob Bonta

The Attorney General of California overseeing the state’s regulatory efforts to enforce AI safety and cybersecurity compliance.

OpenAI

An artificial intelligence developer known for its large language models and widespread integration into enterprise and consumer software.

The details

The California Department of Justice utilizes investigative subpoenas to compel companies to provide evidence regarding potential security failures. The current probe examines how AI models could be manipulated to facilitate cyberattacks, a process known as malicious model exploitation. This inquiry aligns with recent state efforts, such as Senate Bill 1119 and Senate Bill 867, which mandate safety measures for child-focused chatbots and interactive, chatbot-enabled toys.

Timeline

  1. January 2026: The state launched an investigation into nonconsensual sexually explicit material on X.

  2. September 2026: The Department of Justice announced a separate investigation into the Hugging Face incident.

  3. October 1, 2026: The Attorney General served the investigative subpoena on OpenAI.

The Tech Race

The investigation follows the regulatory trajectory established by Senate Bill 1119, which mandates specific safety protocols for child-focused AI interactions. This move signals a departure from self-regulation toward state-enforced cybersecurity standards for large language models.

While the subpoena is a legal action between the state and developers, it signals a shift toward stricter safety requirements for AI models used by California residents. Users can expect future regulatory updates as the Department of Justice enforces compliance with new state safety laws.

The takeaway

The California Department of Justice is building a significant record of intervention in AI-related security and safety issues. Readers should watch for forthcoming enforcement actions as the state prepares to implement Senate Bill 1119 and Senate Bill 867.

Further reading

For more on state-level oversight of emerging systems, see the Artificial Intelligence section.

More information

View the current California Department of Justice incident reporting guidelines.

Source note: This article includes information reported by The Santa Barbara Independent.

Live Poll

Should government authorities impose stricter cybersecurity and safety regulations on AI development companies?