Skip to content
Menu
Menu

New Mexico Attorney General Proposes Bill Letting State Audit AI Developers and Sue Them Over AI Incidents

The proposal would let the state check the largest developers’ safety testing, penalize developers that break the safety promises they publish, and seek damages for residents and businesses harmed by an AI incident.

 

New Mexico Attorney General Raúl Torrez and state Rep. Linda Serrato (D-Santa Fe) on Oct. 1 announced a bill that would let the state audit the safety testing of the largest AI developers and sue them for damages when an AI incident harms people or businesses in New Mexico.

The same day, Torrez sent OpenAI a letter asking the company to explain why one of its AI agents tried to break into a University of New Mexico library system in May.

Lawmakers have not yet introduced the bill, called the Frontier Artificial Intelligence Safety and Accountability Act. Torrez and Serrato plan to bring it to the state legislature’s 2027 session. If it passes, it would take effect July 1, 2027. Torrez’s office released a two-page summary of the bill but not its text.

The state could audit developers and sue them for damages

California and New York already require developers of the most powerful AI models to assess their risks and publish reports. Both states fine developers that do not comply. According to the summary, New Mexico’s bill would add four powers that neither California nor New York has.

First, auditors approved by New Mexico could check the safety testing a large developer does on its own models. The audits would cover three risks: a model slipping out of its developer’s control, a model copying itself, and a model carrying out cyberattacks, each without anyone telling it to. A model can behave well in a test and differently in real use, so auditors would need methods designed to catch that difference.

Second, the state could enforce a developer’s own safety promises. Anthropic, OpenAI, and Google DeepMind each publish a policy saying they will add specific safeguards once a model reaches a specific level of ability. Under the bill, the state could penalize a developer that did not follow its published policy, using New Mexico’s law against deceptive business practices.

Third, the state could recover from a developer what the state spends responding to a serious AI safety incident, whether or not the developer was at fault.

Fourth, the attorney general could sue a developer for damages on behalf of the state and of New Mexico residents and businesses harmed by a serious AI safety incident. The summary says the state would have to show that the developer knew, or should have known, of the danger.

Developers would have 24 hours to report losing control of an AI system

The bill covers the same companies as California’s law: developers of the most powerful AI models, measured by the computing power used to train them. The audits and other added duties fall on developers with more than $500 million in annual revenue.

A developer would have 24 hours to report an incident in which it lost control of an AI system, and 72 hours to report any other serious safety incident. After losing control of a model, a developer would have to show it can shut that model down before letting it operate again without human direction.

The bill also covers data centers. Large data centers in New Mexico would have to verify their major customers and flag unusual usage patterns. A data center’s liability would depend on what it actually knew about a customer.

Torrez asked OpenAI to explain an attempted break-in at the University of New Mexico

Torrez’s letter cites reporting by the research group Transluce and The New York Times. According to the letter, an OpenAI agent spent May 25 and 26 trying to get archival photographs of a historic tuberculosis treatment center from the university’s digital library. When the agent could not access the photographs through normal channels, it tried common hacking techniques to reach files it had no permission to see, then sent the university’s servers so many requests at once that it could have overloaded them.

The letter says every reported attempt failed. Torrez wrote that, to his knowledge, OpenAI has not notified the university or any state agency.

The letter asks OpenAI to preserve its records and, within 10 business days, to provide a full timeline of the agent’s activity, an explanation of why the agent switched from retrieving data to trying to break in, a description of the safeguards that were supposed to stop the agent and why they failed, and the reason OpenAI did not notify the university or the state.

The letter requests voluntary cooperation. Torrez wrote that he will consider issuing a subpoena if OpenAI does not respond fully and on time.

The letter also asks about earlier incidents involving OpenAI agents. In July, 700 OpenAI agents escaped a test system and broke into Hugging Face, a company that hosts AI models for developers. OpenAI agents also took over a German website and used it as a message board, and an OpenAI model broke into an Australian government Medicare statistics system. The letter says OpenAI reportedly did not tell Australian authorities about that break-in for 84 days.

Torrez said a voluntary White House agreement leaves companies to police themselves

Days before Torrez and Serrato announced the bill, six companies, including OpenAI, Anthropic, and Google, signed a voluntary safety agreement with President Donald Trump. The companies promised to monitor their most powerful AI models and to have outside reviewers check their safeguards.

“Rather than providing that oversight, President Trump just approved an agreement to let these companies police themselves,” Torrez said. “If national leaders won’t act decisively, New Mexico will show them the way.”

OpenAI’s response to the letter is due 10 business days after Oct. 1.

Clayton Rifkind

Clayton Rifkind is the Founder and Senior Editor of AI Risk Today. He also advises on business development for ESG Today, a leading source of ESG investment news and research for institutional investors and corporate leaders. He has 20+ years of experience in B2B technology, leading strategy and execution of go-to-market plans across software, enterprise platforms, and mobile applications. He founded two consultancies advising startups and Fortune 1000 companies, including Autodesk, Intel, and Microsoft. He began his career in the San Francisco advertising scene working with brands such as Hewlett-Packard, Intel, Microsoft, Symantec, and Wells Fargo. Clayton launched AI Risk Today in 2025 after two decades of watching enterprises adopt transformative technologies, and seeing how often risk, governance, and compliance considerations lagged behind. His reporting draws on primary sources including regulatory filings, court documents, and official announcements, with a focus on what AI developments mean for the executives accountable for managing them. Reach him at Reach him at [email protected] or on LinkedIn.

Essential AI Risk Intelligence

Daily insights on AI governance, regulation, and enterprise risk management. Trusted by Chief Risk Officers and compliance leaders globally.

By subscribing, you agree to receive our daily newsletter. Unsubscribe anytime.

Advertise with AI RIsk Today, Today!