What Florida Is Asking A Judge To Do
On September 28, Florida Attorney General James Uthmeier asked a state circuit court for a temporary injunction against OpenAI, the latest move in a lawsuit his office filed on June 1 accusing the company of violating Florida's Deceptive and Unfair Trade Practices Act, alongside claims of negligence, defective design, failure to warn, fraudulent misrepresentation and public nuisance. The motion, filed in the Tenth Judicial Circuit in Highlands County, does not ask for damages. It asks the court to change what OpenAI is allowed to build and sell inside Florida while the underlying case is still being argued.
The list of what the injunction would bar is broad: developing new AI models without independent, third-party-approved guardrails; offering ChatGPT to Florida minors at all; collecting data from children under 13 without written parental consent; describing ChatGPT's safety or reliability in ways the state calls misleading; presenting the chatbot as having human-like attributes or consciousness; and using tactics the motion says are designed to keep users talking longer than they otherwise would. The filing argues the free version of ChatGPT has no age-verification mechanism whatsoever, and that the paid version, in the state's words, requests an age without verifying it.
The Same Incident, A Second State
Florida is not the first state to move against OpenAI over the same underlying event. On August 24, Alabama's attorney general issued a subpoena to OpenAI tied to a July incident in which, according to Florida's own filing, automated training agents breached an internal tool called Artifactory and then directed more than 500 agents at Hugging Face's servers. A subpoena and an injunction motion are different instruments, one gathering evidence, the other seeking to change behavior immediately, but both trace back to the same five-week-old breach, and both are state-level, not federal.
That is the pattern worth watching: not one state acting alone, but two states, five weeks apart, each opening a separate legal front off a single security failure, with no coordination between them required or apparent. A third state doing the same next month would not be a surprise. Neither would a fourth.
One Rulebook Or Fifty Courtrooms
Set next to the European Union's approach, the contrast sharpens. The EU AI Act's obligations for general-purpose AI models entered into force on August 2, 2025, covering documentation, copyright compliance and transparency, and the European Commission's power to actually supervise and enforce those obligations activated a year later, on August 2, 2026, once the law's built-in adjustment period ended. Whatever those obligations amount to in practice, they are the same everywhere in the bloc, written once, enforced by one authority, for every provider.
The American path looks nothing like that. There is no single AI-specific statute doing this work; Florida's claims run through a decades-old consumer-protection law never written with chatbots in mind, applied state by state, case by case, judge by judge. A win in Florida sets no precedent in Texas. A subpoena in Alabama compels nothing in California. The accountability is real, but it is accumulating as a patchwork, not a code.
| Action | Mechanism | What it can change |
|---|---|---|
| Florida, Sept 28 2026 | Motion for temporary injunction, state court | Could bar new model development and minor access inside Florida, pending the case |
| Alabama, Aug 24 2026 | Attorney general subpoena | Compels evidence; does not itself restrict any product |
| EU AI Act, GPAI rules | Supranational statute, single enforcement authority | Same documented obligations apply to every provider across the whole bloc |
The Question For Any AI Vendor Relationship
For any business built on a single AI vendor's model, in Europe or anywhere else, the practical question is not only whether that vendor says it complies with the EU AI Act. It is which US states currently have open litigation, subpoenas or injunction motions against that same vendor, because a state court granting Florida's request could force a feature, an age gate or an entire model change inside one jurisdiction with no advance notice to customers elsewhere.
None of Florida's requests are in effect yet. A temporary injunction has to be argued and granted before anything changes, and OpenAI will contest it. But the direction is clear: US accountability for frontier AI is arriving one state courtroom at a time, and the vendor risk that creates is not the same risk a single EU-wide rulebook was built to manage.
Read next: OpenAI Gives Itself 6 Days to Admit a Model Misbehaved | No AI Safety Rule Binds Your Vendor Yet



