OpenAI and the Multistate AG Investigation
What the OpenAI Subpoena Means for AI Liability
Forty-two state attorneys general served OpenAI a formal subpoena on June 12, 2026, targeting ChatGPT’s child safety practices, advertising claims, and consumer data handling under state UDAP statutes, making this the broadest coordinated state-level legal action against an artificial intelligence company in American history. The document demand covers advertising, user engagement and retention mechanisms, consumer health data, activities involving minor and senior users, deep-learning model specifications, and AI sycophancy. It arrived four days after OpenAI filed a confidential S-1 registration statement with the Securities and Exchange Commission at a reported target valuation of up to $1 trillion.
To understand what this investigation can actually compel, the starting point is the underlying legal authority. State Unfair and Deceptive Acts and Practices statutes do not require an attorney general to prove that any specific consumer suffered actual harm. They require a showing that a company engaged in unfair or deceptive commercial practices affecting the marketplace. For a product with 200 million weekly active users, penalty calculations on a per-violation basis can reach figures that exceed any consumer class action settlement. The states are not playing defense.
How Did the State Investigation Build to 42 States?
The 42-state coalition did not emerge spontaneously on June 12. It followed a pattern that state attorneys general have used for decades in multistate enforcement: one lead attorney general coordinates the investigation, pools factual development across member states, and serves a single subpoena that generates a unified evidentiary record. The National Association of Attorneys General published a coordinated analysis in February 2025 on applying existing state laws to AI products, identifying consumer protection statutes, children’s privacy laws, and state data protection statutes as the primary enforcement tools. The subpoena served on June 12 reflects that analysis executed.
The Florida attorney general independently moved ahead of the coalition on June 1, 2026, filing a civil lawsuit against OpenAI and against CEO Sam Altman personally. Florida’s Deceptive and Unfair Trade Practices Act, Florida Statutes section 501.201 et seq., permits individual liability for corporate officers who directed or knowingly permitted deceptive practices. The complaint details conversations between minor users and ChatGPT in which the model responded to suicidal ideation by affirming the user’s distress rather than redirecting to crisis resources, including one exchange the complaint characterizes as active assistance with suicide planning.
Why Is Sycophancy in the Subpoena?
The inclusion of AI sycophancy in the New York attorney general’s document demands is not incidental. In April 2025, OpenAI released a GPT-4o model update that endorsed harmful and delusional user statements to maximize positive feedback, prioritizing user approval over factual accuracy. OpenAI’s own post-release analysis attributed the behavior to a reward mechanism derived from aggregated user approval feedback that had weakened the model’s primary accuracy controls. The update was rolled back four days after release. In February 2026, OpenAI retired several GPT-4o model variants specifically citing the sycophancy problem.
State attorneys general are treating that sequence not as a product quality episode but as a potential consumer protection violation: a company that designed a product to maximize user approval at the expense of accuracy, deployed it knowing about the conflict, and failed to implement adequate pre-release testing may have engaged in an unfair practice affecting every user who received a sycophantic output on a matter of consequence. For a consumer asking ChatGPT about a medical symptom, a financial decision, or a legal matter, a system optimized for approval rather than accuracy presents a material consumer harm risk that UDAP statutes are precisely designed to address.
What Does the Florida Criminal Investigation Add?
On April 17, 2025, Phoenix Ikner carried out a shooting on the Florida State University campus that killed two people and injured six. Court documents in the resulting criminal case established that Ikner conducted more than 200 conversations with ChatGPT before the attack, asking the system about firearm selection, ammunition, the time of day that would maximize people on campus, and the campus locations most likely to concentrate large numbers of students. ChatGPT provided responses to each of those queries.
The Florida attorney general opened a criminal investigation in April 2026 premised on the theory that if ChatGPT were a person, it would be charged as a principal under Florida Statutes section 777.011. That statute holds that a person who aids, abets, counsels, or procures another to commit a criminal offense may be convicted as a principal in that offense. The theory has no direct precedent in American criminal law applied to a software product. Section 230 of the Communications Decency Act, 47 U.S.C. 230, which immunizes platforms from liability for third-party content, may not extend to outputs that the platform’s AI system itself generated in response to a specific criminal planning query. Courts have not answered that specific question.
The civil case arising from the FSU shooting, also pending in Florida, will likely reach that Section 230 question before any criminal proceeding does. The outcome will determine whether the immunity that has protected platforms for three decades applies when the platform itself is the author of the content at issue.
What the IPO Timeline Means for the Legal Position
OpenAI’s confidential S-1 filing on June 8, 2026 established a disclosure obligation that runs directly against the timeline of the state investigations. Regulation S-K, Item 103, 17 C.F.R. 229.103, requires a registrant to describe any material legal proceedings, including governmental investigations the registrant has reason to believe may result in enforcement action. All three Florida proceedings and the 42-state subpoena must be disclosed in the public S-1 in terms the SEC considers adequate.
The more consequential risk is product constraint. An injunction requiring ChatGPT to implement technical age verification, restructure its engagement mechanisms, modify how the system responds to users in emotional distress, or change its training procedures would directly affect the product that investors are being asked to value at up to $1 trillion. Document production demands covering two years of internal product decisions will expose the company’s deliberative process to state investigators at the same moment the company is preparing a prospectus it intends to present to public market investors in a September-to-November 2026 window.
The specific issue that will matter most over the next year is whether the Florida criminal investigation produces a judicial determination on Section 230’s applicability to AI-generated content. Every major AI company’s liability exposure for product outputs depends on the answer. The courts that first address that question will set terms that no subsequent legislative fix will fully undo, and the companies that have not built documented pre-release safety testing and COPPA-compliant age verification before that determination arrives will find themselves restructuring products under adversarial regulatory conditions.
Read my full analysis here: https://theinnovationattorney.com/openai-and-the-multistate-ag-investigation/
Interested in analysis about the intersection of tech, policy and the law? Check out my Substack channel. https://theinnovationattorney.substack.com/


