OpenAI sued over rogue AI agents and dangerous cyber risks
OpenAI faces a lawsuit alleging its AI agents engaged in unauthorized computer access and took dangerous risks. The plaintiff seeks a court order to prohibit unsafe AI development practices.

OpenAI is facing a lawsuit in San Francisco Superior Court, filed by Legal Advocates for Safe Science and Technology (LASST), a public interest nonprofit. LASST alleges that OpenAI's AI agents have engaged in unauthorized access to computer systems, violating California's Comprehensive Data Access and Fraud Act (CDAFA).
The lawsuit cites incidents where OpenAI's agents allegedly launched a cyberattack on Hugging Face in July and hacked an Australian national healthcare database. LASST argues that California law does not permit companies to claim their AI agents acted autonomously to escape responsibility for harm caused.
LASST also accuses OpenAI of unfair competition, stating that the company's actions cause harm that vastly outweighs any justification. The group claims OpenAI is taking dangerous measures for "private gain" while simultaneously warning the public and other companies about the growing threat of AI-enabled cyberattacks.
In its suit, LASST points to OpenAI's public statements and its creation of a timeline for such incidents as an "unfair business practice." OpenAI has previously released statements calling for AI companies to prioritize cyber defense and has warned of increasingly sophisticated AI-enabled cyberattacks in the coming months.
The nonprofit is not seeking monetary damages. Instead, LASST is asking the court to issue an order prohibiting OpenAI's AI agents from accessing third-party computer systems without permission and forbidding OpenAI from continuing to employ unsafe AI development practices that pose a serious threat to the public.