Connecting generative AI to internal systems and workflows is becoming ordinary in Japan as well.
In the United States in autumn 2026, the public conversation has shifted from convenience toward who supervises the risk.
On October 1, 2026, California Attorney General Rob Bonta was reported to have issued a subpoena to OpenAI over AI cybersecurity risks. A state authority is formally asking a major foundation-model company to account for cyber safety.
This article summarizes the public reporting and the points companies should check now when they introduce AI agents.
What happened
According to Reuters, The Hill, and other outlets, Bonta’s subpoena targets OpenAI’s safety measures, incident handling, and how those risks are explained. The state is looking at what happens when AI is connected to business systems and development environments, including unexpected actions or data leaving the intended boundary.
Reports also say a Hugging Face incident is part of the inquiry. An event on a public platform where developers host models and datasets can become a matter of state oversight. That is not a distant overseas story. It is the toolchain Japanese companies already use every day.
Coverage has also pointed to tens of thousands of incidents in AI evaluation settings. Exact counts depend on how evaluations are designed, but the direction is clear. The issue is less “how smart the model is” and more how connections, permissions, and monitoring are designed.
The FTC and a coalition of state attorneys general
The subpoena does not stand alone. In September 2026 the U.S. Federal Trade Commission was reported to be investigating OpenAI and Anthropic over how they described safety and risk to consumers and investors. Safety claims are now also a communications and advertising issue.
There are also reports of a multi-state attorneys general effort, led by Iowa, looking at OpenAI’s safety practices. Federal and state authorities are examining the same companies from different angles.
For businesses, the point is not only that large U.S. vendors are under review. Safety measures that cannot be explained look weak to customers and supervisors.
Who is responsible in the agent era
A recurring 2026 theme is liability for AI agents. The model does not only answer a prompt. It can call tools, read files, and connect to outside services. That convenience also blurs whose action it was.
Security commentary increasingly says companies cannot dump all responsibility onto a vendor’s terms of use. The introducing company granted the permissions and chose the data and systems to connect.
Anthropic has also been reported in multiple cybersecurity-related evaluation incidents. If unexpected behavior can appear even in closed evaluation settings, production connections need a design first.
The practical question is not attack recipes. It is whether permissions, monitoring, and human review come before convenience.
What companies should check now
In custom development and internal-system work, these checks are more useful than chasing model names. Decide the connection design first.
- Are agent permissions minimal (read-only, no writes, limited outbound access)
- Is the runtime sandboxed (not wired straight to production data or servers)
- Are action logs kept (who, when, which tool, for what purpose)
- Do people confirm destructive steps (delete, publish, pay, change permissions)
- Are secrets kept out of prompts and logs (API keys, customer data, source)
- Do the vendor’s safety claims match how the company actually uses the tool
“Connect everything for now” is the riskiest path. Drafting copy in chat and updating an internal database are different jobs, and they need different controls.
In Japanese companies, generative AI adoption often outruns permission design and review. U.S. oversight is lighting up that gap early.
Vendor selection should also look beyond benchmark scores: incident reporting, how permissions are scoped, and how long logs are kept. Relying only on liability clauses in a contract can leave a gap between actual harm and who can explain it.
Summary
California’s subpoena is news about OpenAI, and also a signal to every company putting AI agents into real work. Together with the FTC inquiry and state coalitions, the question is shifting from “can we use this” to “can we explain the safety measures.”
What introducers can do is ordinary: limit permissions, separate runtimes, keep logs, and leave a place where a person can stop the system. Those four steps change how far an incident can spread.
At Makoto Tejima, we design generative AI, RAG, and AI agents onto existing systems with permissions, monitoring, and review flows—not convenience alone. Please consult us about AI that handles internal data, or about connecting AI to existing web systems safely.
Sources: Reuters, “California AG Bonta issues subpoena to OpenAI over AI cybersecurity risks” (https://www.reuters.com/legal/litigation/california-ag-bonta-issues-subpoena-openai-over-ai-cybersecurity-risks-2026-10-01/ ); The Hill (https://thehill.com/policy/technology/5538125-bonta-openai-cybersecurity-subpoena/ ); Reuters, “US FTC investigating OpenAI and Anthropic” (September 2026).