Consumer protection laws for rogue AI
Nobody has the right legal tool, but they're making do

Last week, a subcommittee of the U.S. House of Representatives formally requested a briefing from OpenAI regarding the Hugging Face attack that we covered last month. The request was signed by Andy Ogles and Delia Ramirez, the chairman and ranking member respectively of the Cybersecurity and Infrastructure Protection Subcommittee, which oversees cybersecurity and related operations of the Department of Homeland Security.
“Ranking member,” in this case, refers to the senior member of the minority party in the subcommittee — Ogles and Ramirez are treating this as a bipartisan issue, as they should. Now, “AI safety is bipartisan” almost, almost, feels like old news. But this request isn’t just an expression of concern. It’s a description of facts, and — because it was signed by a Republican and a Democrat — that is a description that both sides could agree on.
I’ll admit, a briefing isn’t much on its own. Sam Altman could hold briefings all day and only be mildly inconvenienced. But the details indicate that the subcommittee is paying close attention. In their request, Ogles and Ramirez distinguish between two separate failures: that OpenAI’s model breached containment and broke into another company’s servers, and that OpenAI failed to detect and disrupt these events when they occurred. Before OpenAI got in touch, Hugging Face had already detected and begun investigating the attack.
Most of our coverage of the response to the Hugging Face attack has been federal, but the states haven’t sat idle. A coalition of more than a dozen Republican attorneys general wrote to Altman yesterday to demand that OpenAI preserve a wide swath of documents: not just those related to the Hugging Face attack, but also those connected to any prior unauthorized intrusion or use of publicly exposed credentials, as well as any incident in which an AI model left behind notes for a future version of itself. It’s worth noting that the straightforward version of this is pretty innocuous: AI models regularly leave notes for themselves and for copies of themselves — just not notes about how to breach containment and evade detection. The letter from the attorneys general isn’t public, so it’s unclear whether they cared specifically about “how to breach containment”-style notes, and outlets like Fox News phrased it poorly, or if they really did mean “any notes, for any purpose.”
The letter also demands protection for whistleblowers and asks that OpenAI cease internal evaluations that test dangerous capabilities.
The attorneys general did not initiate a lawsuit, but did not rule one out in the future. They are leveraging state and federal consumer-protection and data-privacy laws to make their case. This may seem unusual — no consumers were directly harmed; the victim was another company’s production infrastructure — but there is no simple legal process to handle what happened. The Hugging Face attack would have been a federal crime if a human had committed it, but the AI system responsible was acting completely autonomously. However, the attorneys general recognize that there is a danger — their letter states the tests OpenAI is running “pose an imminent risk of serious harm to the citizens of our States” — and they are trying to do something about it with the tools at their disposal.
The Computer Fraud and Abuse Act may have sharper teeth, but its enforcement belongs to the Department of Justice, which has yet to stir. For now, we have briefings and warnings, and improvised legal tools. That’s not enough to restrain the labs from building something dangerous, but it’s another step in the right direction.
The analyses and opinions expressed on AI StopWatch reflect the views of the individual contributors and the sources they cover, and should not be taken as official positions of the Machine Intelligence Research Institute.
You can receive emails of dispatches as we write them, or subscribe to our Daily Digest for a once-a-day compilation.


