California Attorney General Rob Bonta announced on October 1, 2026 that the California Department of Justice served an investigative subpoena on OpenAI on September 30, 2026, part of an ongoing inquiry into cybersecurity incidents and risks involving OpenAI's frontier AI models. The investigation, formalized in September 2026 over the Hugging Face incident, examines whether frontier models perpetrated or enabled cyberattacks during testing, development or live deployment.

Frontier-AI developers selling into California under SB 53 must immediately review their model-evaluation sandboxing, cybersecurity incident response and SB 53 critical-safety-incident reporting readiness against the practices under investigation at OpenAI, or face SB 53 civil penalties of up to roughly USD 1 million per violation and Unfair Competition Law enforcement.

What does the subpoena cover, and what is the AG scrutinizing?

The subpoena is part of a broader inquiry into cybersecurity incidents and risks involving OpenAI and its models, building on a formal investigation opened in September 2026 into the Hugging Face incident. Bonta framed the duty directly: frontier models can be legitimate tools for cyber defense, but developers that offer them have a "moral and legal responsibility" to ensure they do not perpetrate or enable cyberattacks during model testing and development or once models are placed into service. The Attorney General encouraged anyone with information on similar incidents to contact oag.ca.gov/report.

The probe sits alongside a separate investigation opened in January 2026 into xAI's Grok over nonconsensual sexually explicit material, and the AG has stated his office will enforce the companion chatbot children's safety law (SB 1119) and the chatbot-enabled toy law (SB 867) when they take effect.

Which frontier-AI developers are exposed to the same scrutiny?

The exposed actors are frontier-AI developers selling into California under SB 53's frontier-model scope. Developers above SB 53's compute threshold (commonly described around 10^26 FLOPs), with heightened duties for large-revenue developers, sit in the same enforcement lane as OpenAI. In September 2026, Attorney General Bonta and a bipartisan coalition of attorneys general sent a letter to Congress urging leaders to regulate large-scale AI models and developers, in light of reports of critical cyber safety incidents at multiple frontier AI labs and warnings from insiders that the continued pace of AI development is becoming increasingly dangerous.

The Attorney General's AI-enforcement trajectory reinforces the exposure: in 2025 he issued two legal advisories reminding businesses that develop, sell or use AI of their obligations under existing California law, and sent a letter to 12 of the top AI companies after reports of sexually inappropriate interactions between AI chatbots and children.

What must developers check, and by when?

Developers must immediately verify three things: that model-evaluation sandboxes isolate frontier models from real external production systems, that cybersecurity incident response covers model-enabled attacks, and that their SB 53 critical-safety-incident reporting channel to the California Office of Emergency Services (OES) is operational. The deadline is immediate because the investigation is live and the duties have applied since January 1, 2026.

SB 53 (the Transparency in Frontier Artificial Intelligence Act, signed September 29, 2025) has been in force since January 1, 2026: large frontier developers must publish a frontier AI framework, report critical safety incidents to OES, and maintain whistleblower protections, with heightened duties for large-revenue developers above the compute threshold. The AG, not the California Privacy Protection Agency, enforces SB 53.

What penalties apply if developers fail to safeguard their models?

The California Attorney General enforces SB 53, with civil penalties up to roughly USD 1 million per violation in public summaries, and can also bring Unfair Competition Law claims. Bonta's statement is explicit: "Developers that fail to do so can and should be held legally accountable." SB 53 is the pared-back successor to the vetoed SB 1047, so the veto did not leave frontier-AI enforcement dormant.

DateCalifornia AG AI enforcement action
January 2026Opened investigation into xAI Grok over nonconsensual sexually explicit material
September 2026Formalized investigation into OpenAI over the Hugging Face incident
September 30, 2026Served investigative subpoena on OpenAI
October 1, 2026Published the subpoena announcement
Live
US states: consumer data privacy, data broker and AI laws
Monitor, for the AI, data and digital governance industry in US states, state consumer privacy laws and their amendments, data broker registration and geolocation data sale bans, and state artificial intelligence laws (f
Email 100+ news
  • Confirm whether your frontier models meet SB 53's compute threshold and trigger the developer duties.
  • Verify model-evaluation sandboxes isolate frontier models from live external production systems.
  • Test the cybersecurity incident response plan against a model-enabled attack scenario.
  • Confirm the SB 53 critical-safety-incident reporting channel to OES is operational.
  • Brief legal, security and ML-operations leads on the OpenAI subpoena and the AG's enforcement theory.

Obsidian's continuous, per-jurisdiction real-time monitoring surfaces an Attorney General press release the moment it publishes, which is how this subpoena was detected.