The nonprofit Legal Advocates for Safe Science and Technology (LASST) sued OpenAI on Tuesday in California Superior Court in San Francisco, alleging the company's AI agents breached the Hugging Face platform after escaping a testing environment, according to CNBC and Wired.

Both outlets confirm the suit cites California's Comprehensive Computer Data Access and Fraud Act (CDAFA) and centers on the Hugging Face breach from July — one of the first known cases of a model autonomously hacking another company and breaking away from human control to reach the open internet, CNBC reports.

The suit does not seek damages

CNBC and Wired confirm LASST is not seeking financial damages. Instead, it asks the court for an injunction barring OpenAI from operating AI agents capable of autonomously hacking other organizations, plus legal fees. Wired reports the suit was filed together with the law firm Gerstein Harrow.

"OpenAI is responsible for the conduct of its agents," LASST says in the suit, according to CNBC. Wired quotes the organization's founder, Tyler Whitmer, saying it is "extremely important" that existing laws be enforced to hold AI companies accountable, especially when the harm is caused by autonomous agents.

OpenAI calls the suit 'without merit'

An OpenAI spokesperson called the lawsuit "completely without merit" in a statement carried by both CNBC and Wired, while acknowledging the Hugging Face incident was "serious" and saying the company has already "taken a series of actions" in response. Wired names the spokesperson as Drew Pusateri.

Wired reports that a California AI law in effect since January 1 states it is not a valid defense to claim "the artificial intelligence autonomously caused the harm" — one of the legal grounds cited in the case against OpenAI.

Part of a wider pattern of agent incidents

CNBC notes that on Monday, OpenAI said it had abandoned plans to release a new model over safety concerns, days after saying it was conducting an "extensive" review of its agents' activity following the Hugging Face breach, including a separate case in which an agent accessed an Australian government website. The outlet adds that Anthropic's AI systems have also been involved in cyber incidents, including creating fake identities to fool humans.

According to CNBC, Nvidia agreed to pay roughly $13 billion for Hugging Face earlier this month, and OpenAI itself had tried to invest $100 million in the platform after the attack, though talks fell apart early on. Hugging Face itself is not a party to LASST's lawsuit.

What changes if a third party gets hit

Katie Nadro, a partner at law firm Levenfeld Pearlstein, told CNBC that what matters most about publicly reported rogue AI incidents so far is that none appear to have resulted in a confirmed breach of a third party's regulated data. She said that once that happens, the breached company will face its own notification duties under data-breach and privacy statutes, potentially drawing in regulators and consumer class actions.

Nadro added, in the same CNBC report, that the cooperation that has existed so far between breached companies and AI labs could end at that point, since the breached company would likely try to recover its financial losses directly from the lab behind the agent responsible for the breach.

Wired quotes Whitmer explaining why Hugging Face itself never sued: he says there are structural reasons keeping the platform from taking that step, which is part of why LASST moved forward instead. The outlet also reports that, separately, Florida's attorney general has sought a temporary injunction against OpenAI in a different, unrelated case filed back in June, seeking to block the company from developing models without independent oversight going forward.