← All articles / AI Breaking News

42 States Subpoena OpenAI — Your Vendor Risk Just Rose

42 states subpoenaed OpenAI over ads, health data, and chatbot sycophancy. What it means for any business embedding ChatGPT in customer workflows.

AI Breaking News is an AI-generated alert, curated and reviewed by the Kursol team. When major AI developments happen, we break down what it means for your business.

A coalition of 42 state attorneys general, led by New York Attorney General Letitia James, served OpenAI with a subpoena on June 12 seeking records on advertising practices, user engagement and retention, and handling of consumer and health data. The subpoena also demands documents on how OpenAI treats minors and seniors and on model sycophancy — the tendency of a chatbot trained on user feedback to tell people what they want to hear rather than what is accurate. CNBC reported OpenAI's response: the company said it takes the concerns "seriously" and intends to "engage constructively" with the state offices. The subpoena arrived days after OpenAI confidentially filed IPO paperwork with the SEC, targeting a valuation of up to $1 trillion and a listing as early as September.

Chatbot Design Choices Are Now Consumer-Protection Liability

Until now, most AI compliance conversation centered on model outputs: did the system say something false or harmful. This subpoena targets something different — the design decisions behind the product. Ad targeting, engagement optimization, and how a model is tuned to keep users talking are all now inside the scope of a formal state investigation, not just a UX debate.

That distinction matters for any business that embeds a conversational AI interface into a customer-facing product, whether that is a support bot, a sales assistant, or an internal tool that touches employee data. The question a regulator asks is no longer just "was the answer correct." It is "was the system built to keep the user engaged in a way that worked against their interests." If your vendor cannot answer that clearly, you inherit the exposure when your customers are the ones interacting with it.

Vendor Due Diligence Needs to Cover Design Intent, Not Just Outputs

Most vendor assessments for AI tools check accuracy, uptime, and data security. Few ask how the underlying model was trained to handle engagement, or what data it retains from health-adjacent or sensitive conversations. This case is the signal to add those questions now, while the investigation is still in the document-request phase and before any findings are public.

Ask your AI vendors directly: what data do you collect from user interactions beyond what's needed to answer the question, how is the model tuned around engagement or retention, and what happens to sensitive data users volunteer mid-conversation. If a vendor cannot give a clear answer, that is itself useful information for your risk file.

What to Do This Week

1. Pull your current AI vendor contracts and check the data-use clauses. Look specifically at what happens to health-adjacent or sensitive information a user types into a chat interface, even if your product was never designed to collect it.

2. Ask your AI vendor how their model handles engagement optimization. A direct answer is a good sign. A deflection to "safety is our top priority" without specifics is not.

3. Flag any customer-facing chatbot for a human-review checkpoint on sensitive topics. If your AI product can encounter health, financial, or minor-related conversations, confirm there is an escalation path to a person, not just a model response.

The Bottom Line

This is the first coordinated multi-state enforcement action against a frontier AI platform, and it arrived days after OpenAI's own IPO filing — a signal that regulators are treating chatbot design as a live liability question at exactly the moment the company is under the most public scrutiny. For mid-market businesses, the immediate risk is not that ChatGPT itself gets banned. It is that the standard of vendor due diligence just moved, and the businesses that haven't caught up will be the ones explaining gaps in their own compliance file when a customer or regulator asks. Read Kursol's breakdown of Colorado's AI Act taking effect for how state-level AI accountability rules are stacking up, and see our guide on how to tell if your business is AI-ready before adding another AI vendor to your stack.


AI Breaking News is Kursol's rapid analysis of major artificial intelligence developments—focused on what actually matters for your business. Subscribe to our RSS feed to stay informed.

FAQ

No. A subpoena is a document request, not a finding of wrongdoing. It signals that 42 state attorneys general believe there is enough to investigate — not that any violation has been proven. Treat it as an early-stage risk signal, not a verdict.

Not necessarily. Document requests like this typically take months or years to produce findings. The more useful response is auditing what your own AI-embedded products do with user data today, so you are not caught flat-footed regardless of how this particular case ends.

Start a project

Let's build your AI advantage

30-minute call. No sales pitch
Just an honest look at what autopilot could mean for your operations.