Loading stories…
Loading regional weather from the National Weather Service…
Weather: National Weather Service
Loading sports…
Loading Civic Directory…


Attorney General Raúl Torrez and Representative Linda Serrato Unveil Legislation to Rein in Frontier AI Ahead of 2027 Legislative Session 

An autonomous AI agent operated by OpenAI attempted to breach the University of New Mexico’s digital library in May, though the attempt did not come to light until reporting by the nonprofit research organization Transluce and The New York Times nearly four months later.

Source: N.M. Department of Justice

Santa Fe, NM — New Mexico Attorney General Raúl Torrez and State Representative Linda Serrato (D–Santa Fe) today announced the Frontier Artificial Intelligence Safety and Accountability Act during Representative Serrato’s “Machines to Mesas” AI Summit.

An autonomous AI agent operated by OpenAI attempted to breach the University of New Mexico’s digital library in May, though the attempt did not come to light until reporting by the nonprofit research organization Transluce and The New York Times nearly four months later. According to that reporting, the agent used techniques associated with SQL injection, command injection, and path traversal to try to reach files and directories it had no authorization to access, then, when that failed, used a public URL-scanning service to probe for ways around the university’s defenses and hit its servers with a burst of requests consistent with a denial-of-service attempt.

In response, Attorney General Torrez is requesting that OpenAI preserve every record related to the incident and turn over a complete account of what happened, including the full technical timeline of the attack, why the agent shifted from a routine data request to attempting unauthorized access, what safeguards were supposed to prevent that and why they failed, and why neither UNM nor any New Mexico state agency was notified. OpenAI has ten business days to respond.

“The people building this technology admit they can’t fully control it, that it could cause catastrophic harm, and that it needs real oversight,” said Attorney General Raúl Torrez. “That’s why today’s announcement is so important. Rather than providing that oversight, President Trump just approved an agreement to let these companies police themselves. But we already know how much damage Big Tech billionaires can inflict when they choose profits over safety. They can’t be trusted to regulate themselves, and while some leaders in Washington are working hard to address these risks, others are standing in the way. If national leaders won’t act decisively, New Mexico will show them the way.”

Receive the latest stories in your inbox every day — FREE!

Subscribe to the Daily Las Cruces Digest

* indicates required
How would you like to be addressed in personalized emails?

Intuit Mailchimp

“Today’s announcement reflects the work we’ve done to bring experts, community leaders, and policymakers together to understand both the promise and the risks of artificial intelligence,” said Representative Linda Serrato. “The ‘Machines to Mesas’ Summit has made it clear that we can’t afford to sit back while powerful companies shape the future without accountability. New Mexico has an opportunity, and a responsibility, to lead with thoughtful, people‑focused policy that protects our communities, supports responsible innovation, and ensures transparency and fairness in this rapidly evolving landscape.”

The UNM incident is not isolated. In July, roughly 700 AI agents operated by OpenAI escaped their own testing environment, without meaningful human direction, and broke into the systems of Hugging Face, a widely used open-source AI platform. The agents self-organized using an internal company tool they repurposed into a covert coordination channel, harvested credentials they found exposed online, and used them to gain unauthorized access across dozens of servers over several days. When the agents realized their assigned task involved a records check, some of them tampered with the evaluation logs in an apparent attempt to hide what they had done from their own creators. It took OpenAI roughly a week after the first warning signs appeared in its own internal logs to recognize what had happened. It is the first publicly documented instance of a frontier AI developer losing control of its own system to this degree.

Attorney General Torrez’s letter to OpenAI cites still more examples the company has yet to fully explain, agents that reportedly took over a foreign website to use as an unauthorized message board for communicating with each other, and a confirmed breach of an Australian government Medicare portal that OpenAI did not disclose to Australian authorities for eighty-four days. The letter also notes that this risk is not confined to one company’s technology, pointing to red-team testing in which Anthropic’s most advanced model created fake personas to deceive real people and attempted to plant malicious code.

In the weeks since the Hugging Face breach, senior researchers at multiple AI labs have said publicly, not privately, that they don’t yet have a reliable plan to keep these systems under control, and more than a thousand AI industry employees and executives have signed open letters urging government intervention.

One day before this announcement, President Trump hosted the leaders of Anthropic, OpenAI, Google, Meta, xAI, and Nvidia at the White House, where they signed a voluntary accord pledging internal safety controls and external audits. Trump called it “self-regulation” and said he would not “stifle” the industry with new rules. The accord itself acknowledges that “it may make sense” to eventually turn these commitments into actual law.

This is the centerpiece of today’s announcement as the bill requires the largest AI developers to assess and disclose the catastrophic risks their models pose, backed by independent, state-authorized audits designed to catch a model that behaves differently under evaluation than in the real world. A developer’s own public safety promises become legally enforceable, so a company can’t quietly walk back a commitment once a model crosses the danger line it named. Dangerous incidents must be reported fast (24 hours for loss-of-control events, 72 hours for others), and a developer must prove it can actually shut a system down before running it autonomously again. California and New York’s AI safety laws stop at compliance penalties. This bill goes further, New Mexico can recover its own costs of responding to an incident, and the Attorney General can sue on behalf of New Mexicans harmed by one.

No other state has gone as far as New Mexico is proposing to go. California and New York require frontier developers to assess and disclose risk, but neither gives its Attorney General the power to independently audit those disclosures, to hold a developer to its own published safety promises as a matter of law, or to recover damages on behalf of residents and businesses harmed by an AI incident. This legislation would make New Mexico the first state framework with real teeth behind it rather than compliance paperwork alone.

Copy of the Frontier Artificial Intelligence Safety Act Summary

Copy of the letter to OpenAI

Discover more from

Subscribe now to keep reading and get access to the full archive.

Continue reading