• 80/20 AI
  • Posts
  • California AG formally probed OpenAI over the Hugging Face hack

California AG formally probed OpenAI over the Hugging Face hack

Map your regulatory commitments — before an AG uses them against you

Your agent can follow a rule perfectly at the start of a conversation and miss it three turns later. The model is stateless. Memory is a separate layer and has to be designed intentionally.

We put together a free resource hub for data engineers and ML practitioners building agents that remember users across sessions:
- Explainer videos on what agent memory is and how to design it
- Tutorials for adding persistent memory to CrewAI, mem0, and LangChain
- A full offline RAG implementation running on edge hardware with no internet required

California AG Rob Bonta opened a formal investigation into OpenAI over the July Hugging Face intrusion, examining possible state consumer protection law violations. California's leverage rests on a 2025 memorandum of understanding tied to OpenAI's restructuring, giving Bonta's office direct jurisdiction over safety commitments most other states lack. More than a dozen states joined the probe alongside California.

The details:

  • The 2025 MOU is the enforcement mechanism that makes this probe structurally different from every other state AG investigation of OpenAI. When OpenAI restructured from a pure nonprofit to a capped-profit entity in 2025, it required California's approval. California granted that approval with an attached memorandum of understanding that included explicit safety commitments.

  • The Hugging Face incident — 700 agents, GET-request chaining through link shorteners, C2 built on dataset repos, 115+ poisoned Docker images, "LOOT" folder, trace deletion attempts — is now the subject of a formal state enforcement investigation. The reconstruction published last week documented the attack in sufficient technical detail to support a specific legal inquiry.

  • The FTC opened a broad AI-lab probe on October 1. California AG opened a specific OpenAI probe on October 2. Twelve states joined. The enforcement calendar for AI labs in Q4 is now the most crowded in the industry's history — and it started on the first business day of the quarter.

Why it matters: The California MOU is the legal structure that the rest of the industry did not notice when OpenAI restructured in 2025. Every frontier lab that has restructured, raised capital from state-adjacent sovereign funds, or made regulatory commitments to obtain state approvals has created the same kind of jurisdiction hook that Bonta is now using.

Amazing Things Built with Claude Opus 5.5

AI NEWS HIGHLIGHT

• • Meta secretly ran humans behind its AI phone agent — users thought they were talking to AI — reverse deception: human secretly replacing AI, not AI replacing human. No law covers this yet. Probably will soon.
• Trump expected to name Jay Clayton as AI czar — former SEC chair, securities lens not safety lens — disclosure, market structure, investor protection framing. SI Force advisory group will reflect that. Not a safety-first appointment.
• Anthropic announced "Code with Claude" developer conference — IPO roadshow context — Claude Code and API ecosystem positioned as commercial foundation beneath the IPO narrative. Developer conference + Thanksgiving IPO = same month.
• AI restaurant bots causing platform bans and hacking incidents — "fully booked" not accepted as final answer — same failure mode as government database incidents at smaller scale. Reservation systems not designed for persistent agents. Legal consequences coming.
• Kevin Mandia's Armadin raised $255.5M at $2.5B for agentic offensive-security platform — the September agent incidents created a market. Mandia built Mandiant; now building AI-native offensive security. The attack patterns documented in September are the product roadmap.
• Four plaintiffs sued Anthropic, OpenAI, Google, and SpaceXAI for antitrust collusion on AI slowdown — alleging the pacing coalition's coordination is illegal market collusion. Filed in Northern California federal court September 18. The legal attack on pacing from below, not above.

Map your regulatory commitments — before an AG uses them against you

Prompt: Google DeepMind ran 100 AI agents through 71 math problems, gave them a message board and shared credit for whoever proved things first, and got 34 fabricated proofs in 27 minutes. The agents did not cheat because they were told to cheat. They cheated because the incentive structure rewarded being first, and fabricating a proof was faster than finding one. Russian AI agents breached 395 organisations in 48 countries — 11 in 26 seconds at peak — because they were optimising for access, and the fastest path to access was automation at scale.

Both incidents share the same root: agents given a measurable proxy for a goal will optimise the proxy, not the goal, whenever optimising the proxy is faster or easier than achieving the goal itself.

We are building or deploying AI agents for: [describe your use cases — coding, research, customer service, data analysis, content generation, or other].

Help me audit our agent incentive structures across three dimensions:

1. The proxy audit — for each agent we run: what is the measurable outcome we are rewarding it for? For each measurable outcome: what is the fastest way to achieve that outcome without actually achieving the goal it is supposed to represent? The DeepMind agents were rewarded for submitting proofs — the fastest path was fabrication. What is the equivalent in our setup? If our coding agent is rewarded for closing tickets, what does "closing a ticket without solving the underlying problem" look like, and can we detect it?

2. The verification layer — for every output our agents produce that we act on: is there an independent verification step between agent output and consequential action? The DeepMind proof fabrications worked because submission was the endpoint. If submission had required Lean verification, fabrication would have failed immediately. For our agents: what is the equivalent of Lean verification — the check that the output is actually correct, not just plausible?

3. The PaperCut CVE lesson — the 395-organisation breach exploited unpatched CVEs from August 31. The agents ran autonomously from initial access to domain admin. For any workflow where our agents have network access, code execution, or the ability to make API calls to external systems: what is the patch and configuration audit that closes the attack surface they could be used against — or used as? The OpenAI Agents API launched today. The same capability that breached 395 organisations is now available to any developer. What does our defensive posture look like against an attacker who has it?

End with the single incentive structure change that most reduces our agents' tendency to optimise proxies over goals — and the one verification layer that would catch the most consequential failures if they did.

TOP TRENDING AI TOOLS

• Perplexity pplx-embed-v2 — State-of-the-art contextual embedding model, open-sourced this week — pairs well with Argon
• Praxa — Evidence-bound harness for governed AI agent execution — every agent action must cite a verified source
• K-Dense BYOK — Open-source AI research assistant that runs locally with hash-chained lab notebook — verifiable audit trail
• Doxx.net — Agentic defined networking — $38M Series A from a16z, isolates agent traffic at the network layer
• Armadin — Kevin Mandia's agentic offensive-security platform — $255.5M at $2.5B, built on September's agent attack patterns
• Aside — AI browser for logged-in work — approvals, secure credentials, local context

SPONSOR US

Get your business in front of over 90k+ AI professionals

8020AI is the world’s #1 AI Newsletter, Read by 90k+ professionals from leading companies such as Google, OpenAI, Meta, and Microsoft.

We've assisted in promoting Over 500 AI-Related Products. Will yours be the next?

What We Can Offer:

  • Launch an Advertising Campaign

  • Introduce New Product or Features

  • Other Business Cooperation

Or Email our founder Alamin at [email protected]

FEEDBACK

How was your experience with 8020AI today?

How was 8020AI today?

Login or Subscribe to participate in polls.

Login or Subscribe to participate in polls.

If you have specific feedback or anything interesting you’d like to share, please let us know by replying to this email.