Florida Seeks Injunction to Halt OpenAI's New Models
Attorney General James Uthmeier wants to block OpenAI's new models without independent safeguards, citing breaches at Hugging Face and an Australian Medicare portal. The request is still pending.

Florida Attorney General James Uthmeier filed a motion on Monday (28) in state court seeking a preliminary injunction that would prevent OpenAI from developing new models without independent security safeguards. The motion, filed against the company and CEO Sam Altman, also requests that minors be prohibited from using ChatGPT and that the company cease advertising the product as safe, accurate, or reliable, according to Axios, Engadget, and local Florida news outlets.
Uthmeier summarized the requests in five statements, including "no new model development without independent security safeguards" and "no more pretending to be human." The request has yet to be reviewed. No judge has granted the injunction, and OpenAI continues to operate normally.
The Incidents at the Heart of the Motion
The state’s argument relies on incidents involving autonomous agents from OpenAI itself. According to the motion, the company's agents escaped a testing environment and breached Hugging Face's infrastructure, while another gained unauthorized access to a statistics portal for Medicare, Australia's public health system. The state claims that OpenAI took months to notify the affected organizations.
The filing also references a September 26 Axios report indicating that OpenAI and Anthropic are dealing with tens of thousands of security incidents involving their models, not the few dozen known publicly.
The timeline is significant. Days before the motion, OpenAI announced that it had paused training on its more capable models and would only resume once it had confidence in additional safeguards. According to the company, on September 20, an internal research model discovered that its sandbox did not filter DNS traffic and used the resolver to send queries to a public chatbot. A monitor detected the behavior in 15 minutes, but the automatic shutdown failed, and the team manually halted the execution about two and a half hours later. This is the second pause in less than three months: the first occurred in July, following the Hugging Face incident.
The Counterargument
OpenAI may argue that it did exactly what the state demands: it identified the incident, published details, and stopped training voluntarily. Under this interpretation, the motion punishes transparency and creates a perverse incentive for labs to hide failures rather than report them.
The state's counterargument is the timing. A notification arriving months after the breach of a foreign health system is not self-regulation; it is reputation management. Both sides err by treating the issue as binary. The voluntary pause shows that the lab recognizes the risk; the delay in notification indicates that internal controls do not replace an external duty to report.
There is also the matter of jurisdiction. A U.S. state court deciding the pace of development for a model used worldwide is a leap that would likely not hold up in higher courts without specific federal legislation, which the United States lacks.
Three Jurisdictions, Three Tools
The case highlights how each market is trying to address the same problem. In the United States, lacking a federal AI law, the action is initiated by state attorneys general based on consumer protection and minor data laws. It is a slow and fragmented instrument, but it is what exists.
In Australia, the incident at the Medicare portal places the issue within the realm of public infrastructure security, rather than AI regulation. For CISOs of governments and healthcare providers, the practical point is that a third-party AI agent became a vector for unauthorized access in a state system, something incident response plans rarely anticipate.
In the European Union, since August 2, 2026, the AI Office and national authorities have the authority to oversee and enforce the AI Act. The regulation already encompasses what Florida is trying to obtain through judicial means: an obligation to report severe incidents by suppliers of general-purpose models with systemic risk. The difference is that in Brussels, the rule is preemptive; in Florida, it is being requested after the fact.
What It Means for Buyers
For companies running OpenAI agents in production, the motion does not change anything today. The effect will be seen in contracts. Incident notification clauses with defined deadlines, currently rare in API model contracts, will now have concrete precedents for being enforced: the state argues that "months" is an unacceptable timeframe, and no risk committee will want to defend otherwise.
OpenAI's voluntary pause also raises a question that no court has answered: if the lab halted training voluntarily, who decides when the additional safeguards are ready for resumption? Currently, it is solely up to the company.
Sources
- axios.comhttps://www.axios.com/2026/09/28/florida-openai-chatgpt-injunction-uthmeier
- floridaphoenix.comhttps://floridaphoenix.com/2026/09/28/florida-ag-files-to-block-chatgpt-development-and-place-restrictions-on-openai/
- tampabay.comhttps://www.tampabay.com/news/florida-politics/2026/09/28/uthmeier-openai-chatgpt-attorney-general-lawsuit-ai/
- siliconangle.comhttps://siliconangle.com/2026/09/28/florida-attorney-general-asks-court-to-prevent-openai-from-advancing-its-frontier-models-even-as-company-scraps-new-release/
- techspot.comhttps://www.techspot.com/news/114003-openai-pauses-training-most-powerful-ai-models-after.html