OpenAI faces a multi-state investigation into its business practices, with attorneys general examining the company's advertising policies, data handling procedures, and health information management. The scope of the inquiry remains broad, though specific states involved have not been publicly identified.

The investigation signals growing regulatory scrutiny of generative AI companies. State-level enforcement actions have become a primary mechanism for holding tech firms accountable on consumer protection issues, particularly around data privacy and deceptive marketing practices. OpenAI's prominence in the AI space makes it a natural target for regulators concerned about how these systems collect, use, and protect user information.

The focus on health data handling carries particular weight. OpenAI's products interact with sensitive medical information when users ask health-related questions or upload personal documents. How the company stores, processes, and deletes this data determines whether it complies with state privacy laws and healthcare-specific regulations.

Ad policies also appear central to the inquiry. OpenAI generates revenue partly through enterprise partnerships and advertising around its products. Regulators likely want to confirm the company uses transparent practices in how it presents sponsored content and whether it clearly discloses which recommendations come from paid partnerships versus algorithmic ranking.

This investigation reflects a pattern of state attorneys general acting as first movers on AI regulation. Federal privacy legislation remains stalled in Congress, leaving states to enforce existing consumer protection statutes against AI companies. California, New York, and Massachusetts have emerged as particularly active enforcers, though the investigation's scope suggests involvement across multiple jurisdictions.

OpenAI has not publicly commented on the investigation's specifics. The company has positioned itself as committed to safety and transparency, but these claims now face formal scrutiny. The outcome could shape how all large AI companies manage sensitive data and advertise their capabilities going forward.