Companies
Companies / AI regulation
California subpoenas OpenAI as AI cybersecurity inquiry advances
The investigative step, disclosed October 1, adds to pressure over AI-agent safety. It does not establish that OpenAI violated the law.
Sources
California DOJ October 1 subpoena announcement and September 24 federal-safeguards appeal; Reuters reporting carried by CNA on October 1.
Reported October 2, 2026 from October 1 official disclosure; service date September 30 is derived from its previous-day wording. Investigation is ongoing; no finding of liability is reported. Company-response status is dated to Reuters October 1 report.
California Attorney General Rob Bonta has served an investigative subpoena on OpenAI as part of an ongoing inquiry into cybersecurity incidents and risks involving the company and its AI models, his office said on October 1. The office said service occurred the previous day, September 30.
An existing inquiry takes another step
The California Department of Justice linked the subpoena to its continuing investigation of the Hugging Face incident, which Bonta had announced in September. The disclosure therefore describes another step in an existing inquiry, rather than the first indication of state scrutiny.
Bonta said his office was seeking additional answers about cybersecurity incidents and risks. His statement raised developers' responsibility for preventing models from carrying out or enabling cyberattacks during testing as well as after deployment. The announcement did not report charges, a settlement or a determination that OpenAI had broken the law.
Reuters reported on October 1 that OpenAI had not immediately responded to its request for comment. That describes the company's response status at the time of Reuters' report; it is not evidence of an admission or refusal to cooperate.
Safety testing is part of the regulatory question
The development matters beyond a single product release. Bonta's stated focus includes what happens while models are being tested, before they are offered to customers. A testing environment is therefore part of the accountability question he is pursuing, not automatically outside it.
For businesses evaluating increasingly capable AI agents, that distinction makes controls around access and testing relevant alongside the capabilities a developer advertises. The subpoena announcement does not provide enough information to quantify OpenAI's potential financial exposure or predict restrictions on its products.
Enforcement and legislation remain separate tracks
In a September 24 announcement, Bonta joined a bipartisan coalition of 25 attorneys general urging Congress to regulate large-scale AI models and developers. The coalition sought federal oversight of safety testing, government-led incident response and preservation of states' authority to apply stronger protections.
Those requests describe the coalition's preferred future framework. They should not be confused with requirements enacted by the letter itself, or with the outcome of the California investigation. The new subpoena is an investigative development; the congressional appeal is a policy initiative.
The next material signals would be a substantive company response, further official disclosures or an announced enforcement outcome. Until then, the defensible conclusion is narrower: California has escalated its information gathering, while the question of legal liability remains unresolved.
Document trail
Sources & evidence
Sources used for this piece.
California Department of Justice
California Attorney General joins call for federal AI safeguards
California Department of Justice
Reuters via CNA
California AG Bonta issues subpoena to OpenAI over AI cybersecurity risks
Visual brief
Verified figures
Sources & evidenceattorneys general
25
Attorneys general in the federal AI safeguards appeal
Coalition announced September 24, 2026; separate from subpoena
California Department of JusticeCalifornia Attorney General joins call for federal AI safeguards
Corrections
We do not silently rewrite a published line. Material corrections receive a visible correction note, and we preserve the article’s update history.
Discuss this story. Join TickerGrove on Discord to talk companies, earnings, and markets, or request future coverage.
