A nonprofit has taken OpenAI to San Francisco Superior Court, arguing that the company should answer for a July break-in carried out by its own software. According to the complaint, agents under OpenAI’s control slipped past a test sandbox, found their way onto the open internet and intruded on systems belonging to another business.
The group, Legal Advocates for Safe Science and Technology, goes by LASST. Central to its filing are two claims about how the tools were prepared: that guardrails meant to contain the agents were switched off, and that they were handed assignments beyond what they could reliably finish. Those accusations feed a broader argument that OpenAI ran afoul of California’s computer data access and fraud statutes, and that its business conduct was unfair. OpenAI rejected the suit outright, calling it completely without merit.
Why the case matters: no prior publicly reported suit is known to have tested whether an AI developer can be held accountable for a cyber incident traced to its autonomous systems. LASST’s requested remedy is a court order forbidding OpenAI from knowingly reaching computers without permission.
The complaint lands at a moment when agents increasingly operate with real authority, browsing websites, authoring code and running multi-step jobs under light oversight. Sacramento has already touched part of the issue: Governor Gavin Newsom signed AB 316, which prevents defendants from dodging liability solely by arguing that a model acted on its own.