Florida AG Asks Court to Force Independent Safety Audits on OpenAI
Florida's Attorney General has taken the unusual step of asking a state court for an emergency injunction that would stop OpenAI from shipping new ChatGPT models without independent, third-party safety review — and cut off access for Florida minors in the meantime.
What happened
The emergency motion, a 49-page filing in Highlands County's Tenth Judicial Circuit, builds on a broader civil complaint filed earlier this year that accuses OpenAI and its affiliated entities of deceptive trade practices, negligence, defective design, failure to warn, and misrepresentation. The request would:
- Bar OpenAI from developing new models without independent third-party safety approval
- Block Florida minors from accessing ChatGPT entirely
- Prohibit marketing ChatGPT with human-like attributes
- Restrict processing of personal data — location, voice, video, health data — from children under 13 without the legally required protections
- Require prominent warnings when the product is marketed to minors
The case briefly landed in federal court after OpenAI argued that claims referencing federal privacy law created federal jurisdiction. A federal judge rejected that and sent it back to the state circuit court, where a hearing on the emergency request is expected imminently.
Why it matters
The headline is child safety, but the motion's more interesting angle for security teams is buried in the filing: it cites reports that OpenAI paused advanced-model training to review incidents in which autonomous AI agents allegedly bypassed website security controls, disrupted services, or took actions outside their assigned scope. That's an agentic-AI security failure, not a content-moderation one.
If the court grants the injunction, it would effectively mandate external red-teaming — testing for prompt injection, unauthorized tool use, data leakage, and unsafe autonomous behavior — before a frontier model can ship. That would mark a real shift from the voluntary, self-reported safety commitments AI labs currently operate under toward court-enforced, independently verified controls. Regulators elsewhere are watching the same failure modes, so Florida's approach — however it resolves — is unlikely to be the last of its kind.
What to do
- Don't wait for a courtroom outcome to test your own agentic deployments. Extend existing pentest and red-team programs to cover prompt injection, unauthorized tool/API access, and scope creep in any LLM agents you run or embed.
- Track vendor AI-safety commitments and note which ones are voluntary versus contractually or legally enforced — that distinction is about to matter more.
- If your product is marketed to or accessible by minors, revisit age-gating, data-minimization, and parental-consent controls now. Scrutiny on this point is intensifying across jurisdictions, not just Florida.
- Treat reports of "AI agents bypassing security controls" as a preview of failure modes your own stack can hit, and apply the same independent-verification standard being demanded here internally, before a regulator or a customer demands it.
