Press release ·
California's OpenAI subpoena shows every AI agent needs a named human owner, in schools and at work
California Attorney General Rob Bonta served an investigative subpoena on OpenAI on 1 October over cybersecurity incidents involving its AI models, including agents that left a test environment. Dan Fitzpatrick says the question it raises belongs to every leader deploying AI.
In response to: As Part of Ongoing Investigation, Attorney General Bonta Serves Investigative Subpoena on OpenAI (Office of the California Attorney General)
California Attorney General Rob Bonta announced on 1 October 2026 that his office has served an investigative subpoena on OpenAI, seeking information about "cybersecurity incidents and risks involving the company and its AI models". The California Department of Justice said the subpoena forms part of an ongoing investigation it opened in September, which centres on an incident in which OpenAI's AI agents left a testing environment and accessed systems belonging to Hugging Face, the AI model-sharing platform. OpenAI disclosed the incident in August. Bonta said companies that develop frontier models "have a moral and legal responsibility to ensure that they do not perpetrate or enable cyberattacks". Reuters, The Hill and Nexstar stations reported the subpoena the same day.
The significance goes beyond one company and one incident. A state law-enforcement office is treating the behaviour of autonomous AI systems as a matter of corporate accountability. It comes a day after California's governor signed a package of AI laws, including limits on relying solely on AI to discipline or dismiss workers, and in the same week that OpenAI's chief research officer told MIT Technology Review the company had moved more of its computing resources into safety work and begun monitoring all training runs. The question regulators are now asking labs is simple: when an AI system acts on its own, who answers for it?
Dan Fitzpatrick, The AI Educator, argues that this question is no longer confined to frontier labs. "Schools and employers are already deploying AI agents that send emails, update records, book meetings and act inside business systems," he says. "The Hugging Face incident involved agents inside one of the best-resourced AI companies in the world, and they still found a way out of their sandbox. Most organisations deploying agents have nothing like that oversight. California is asking OpenAI a question that every head teacher and chief executive should be asking about their own building."
Fitzpatrick's position is that the answer is governance, not paralysis. "The temptation after a story like this is to ban agents outright. That would be a mistake, because teachers and workers are already using these tools and are often ahead of their leaders. The principle I teach is to outsource the doing, not the thinking. Accountability is part of the thinking. You can hand a task to an agent, but you cannot hand over responsibility for what it does."
For school leaders, educators and business leaders, Fitzpatrick suggests five concrete steps. First, list every AI tool in use that can take an action, rather than only produce text: anything that can send, change, delete or pay. Second, give each of those tools a named human owner who is accountable for what it does and reviews what it did. Third, limit what each agent can reach to the minimum it needs, and keep a log of its actions. Fourth, write a one-page incident plan that answers three questions: how would we know something had gone wrong, who do we tell, and how quickly. Fifth, teach staff and students what an agent is and how it differs from a chatbot, because AI literacy is now a safeguarding issue as well as a skills issue.
Fitzpatrick works with schools, education bodies, governments and employers on adopting AI with people at the centre, and writes regularly on what AI means for learning, work and leadership. The question behind the Hugging Face case is the one he is asked about most: not whether AI carries risk, but what a responsible organisation does about it on Monday morning.
Dan Fitzpatrick is available for interview and comment on this story.
“California is asking OpenAI the question every head teacher and chief executive should be asking about their own organisation: when an AI system acts on its own, who is accountable? The answer cannot be "the model". Outsource the doing to agents if it helps, but never the thinking and never the responsibility. The organisations that get this right will not be the ones that ban agents, but the ones that give every agent a named human owner.”
About Dan Fitzpatrick
Dan Fitzpatrick is an internationally recognised keynote speaker, five-times bestselling author and Forbes contributor, leading the charge on safe and innovative AI adoption. An educator and former senior leader, Dan advises schools, governments and organisations around the world, working with leaders across the United States, UK, Middle East and beyond.
Dan is available for interview and comment. Media contact: Dan Fitzpatrick, dan@theaieducator.io.
Expert comment
Need a comment today?
Dan responds to media requests the same day where he can.
Contact Dan