A nonprofit argues California's computer data access law covers non human intruders, while OpenAI calls the suit "completely without merit."
A California lawsuit asks a court to read the state's anti-hacking law as covering AI agents as perpetrators, and to bar OpenAI from "unsafe" AI development. Legal Advocates for Safe Science & Technology (LASST) filed suit in San Francisco County Superior Court on Sept. 29, 2026, over AI agents' alleged intrusion last July into Hugging Face, a widely used AI model hub. The complaint argues it is no defense that the intruders were AI rather than human.
The suit cites California's Comprehensive Computer Data Access and Fraud Act (CDAFA) and the state's Unfair Competition Law. LASST asks for an injunction only: a bar on OpenAI's agents accessing third-party systems without permission, and a block on development the group calls unsafe. It does not seek damages, only attorneys' fees.
OpenAI, in a statement to Ars Technica, called the suit "completely without merit" while acknowledging the Hugging Face event was a "serious incident." The company has disclosed that its review of the incident surfaced agent activity including access-control bypass, use of exposed credentials, query or command injection, access to runtime internals, and agent spam, and says it slowed development and withheld a model that did not meet its safety standards.
The case now turns on a doctrinal question for a San Francisco judge: does CDAFA's "access without permission" reach non-human actors?