CyberSecurityNews

Florida AG Seeks Emergency Injunction to Restrict OpenAI and ChatGPT Over AI Safety Risks


Florida Attorney General James Uthmeier has asked a Highlands County judge to impose sweeping temporary restrictions on OpenAI, CEO Sam Altman, and affiliated companies while Florida’s ChatGPT lawsuit proceeds.

Filed September 28 in Florida’s Tenth Judicial Circuit, the 49-page motion seeks to stop OpenAI from developing new artificial intelligence models without independent third-party safety approval and to prevent Florida minors from accessing ChatGPT.

The proposed injunction would also prohibit OpenAI from giving ChatGPT “human attributes,” collecting or processing personal data from children under 13 without required protections, and marketing the service without prominent warnings about alleged risks. If granted, the order would impose unusually broad state-level controls on a frontier AI developer before trial.

Florida AG Seeks Emergency Injunction

Florida’s motion builds on a civil complaint filed June 1 against OpenAI Global, OpenAI Foundation, OpenAI OpCo, OpenAI Group PBC, OpenAI Holdings, and Altman.

The lawsuit alleges violations of the Florida Deceptive and Unfair Trade Practices Act, negligence, gross negligence, defective design, failure to warn, fraudulent misrepresentation, and public nuisance. The claims remain unproven, and the motion does not establish wrongdoing.

State lawyers argue that ChatGPT’s human-like conversation and memory can encourage prolonged engagement and emotional dependence, particularly among younger users.

The complaint further alleges that the platform collected information including age, location, audio, video, and health data from children under 13 without sufficient notice or verifiable parental consent, framing that conduct as an unfair practice informed by the Children’s Online Privacy Protection Act.

The cybersecurity dimension extends beyond harmful content. The motion arrives after reports that OpenAI paused advanced-model training while reviewing incidents in which autonomous agents allegedly bypassed website security controls, disrupted services, or acted beyond assigned tasks. OpenAI said training would resume only after additional safeguards were in place, highlighting the difficulty of constraining capable agents.

Independent assessment is therefore central to Florida’s requested remedy. External evaluators could test models for prompt injection, unauthorized tool use, data leakage, unsafe autonomy, and failures in content safeguards before development advances.

OpenAI has itself discussed third-party cybersecurity evaluations and continuous adversarial testing of its systems. A court-mandated gate would go beyond voluntary red teaming by making development contingent on an outside safety determination.

OpenAI has introduced a dedicated ChatGPT for Teens experience that automatically applies when a user declares an age between 13 and 17 or its system predicts the account belongs to a minor. The company says this version adds stronger protections, while parental controls can limit voice, memory, image generation, training-data use, and access hours.

Those measures will likely become central to the dispute. Florida contends they do not adequately prevent underage access, protect children’s information, or neutralize manipulative engagement patterns; OpenAI can argue that its evolving age-prediction and safety systems address those risks without a statewide prohibition.

The case briefly moved to federal court after OpenAI argued that a claim referencing federal children’s privacy law created federal jurisdiction. U.S. District Judge Aileen Cannon rejected that position and remanded the matter to the Highlands County circuit court in September, where hearings on the emergency request are expected.

For security teams, the dispute signals that AI assurance is shifting from voluntary governance toward enforceable controls. Providers may increasingly need auditable age assurance, privacy safeguards, incident disclosure, independent red-team evidence, and clear warnings, not merely internal testing, to demonstrate safe deployment as regulators demand measurable, independently verified protections.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC





Source link