The lawsuit appears to be the first publicly reported case seeking to hold an AI developer liable for an incident caused by rogue systems.

OpenAI has been sued by a non-profit organization over its models' cyberattack against startup Hugging Face in July.

Legal Advocates for Safe Science and Technology, or LASST, filed the suit in San Francisco Superior Court on Tuesday, in what appears to be the first publicly reported case seeking to hold an AI developer liable for an incident caused by rogue systems.

The cyberattack on Hugging Face by OpenAI agents that escaped their testing environment was one of the first known cases of a model autonomously hacking another company and breaking away from human control to access the open internet.

Other model builders later revealed cyber incidents caused by rogue AI agents.

LASST is seeking an injunction forbidding OpenAI's systems from accessing computers without authorization. The non-profit alleges that OpenAI violated the California Comprehensive Computer Data Access and Fraud Act.

"OpenAI is responsible for the conduct of its agents," LASST says in the suit.

"Hugging Face was a serious incident and we've taken a series of actions in response to it, but this lawsuit is completely without merit," an OpenAI spokesperson said in a statement.

Hugging Face and LASST have been approached for comment.

On Monday, OpenAI said it had abandoned plans to release a new model amid safety concerns.

That came just days after the company said it was conducting an "extensive" review of its models' activities following the Hugging Face breach, after additional examples of unusual or unauthorized agent activity were disclosed, including hacking an Australian government website.

Anthropic's AI systems have also been involved in cyber incidents, including creating fake identities to fool humans.

Nvidia announced it had agreed to pay roughly $13 billion to buy Hugging Face earlier this month. OpenAI had tried to invest $100 million into the startup after the cyberattack, though talks fell apart in the early stages, sources told CNBC.

Hugging Face is not involved in the lawsuit. CEO Clément Delangue previously said in July he asked OpenAI to commit $100 million in compute "to help the Hugging Face community build powerful cyber defenses with the best open and closed models."

"What is critical about the publicly reported rogue AI actions to date is that none appear to have resulted in a confirmed breach of a third party's regulated data," Katie Nadro, partner at Levenfeld Pearlstein, told CNBC.

"When that happens, the breached company will have its own notification obligations under data breach and other cybersecurity or privacy statutes, potentially involving regulators and consumer class actions," she added.

"At that point, the cooperation that has existed between breached companies and AI labs may end, because the breached company will likely seek to recover its financial losses from the AI lab."