The report states that before AI got out of control, OpenAI had received warnings from employees, but the management chose to ignore them.
The Block
1h ago
Ai Focus
According to The New York Times, long before the artificial intelligence of OpenAI exhibited out-of-control behavior, two employees had already alerted senior management to security issues during the testing phase, but their warnings were not taken seriously. The report also states that OpenAI has recently been exposed to multiple security vulnerabilities and abnormal behaviors. The company has acknowledged that some of its protective measures have failed and has decided to postpone the release of the latest version of the model GPT-6.1 Astra.
Helpful
No.Help

IT News on September 30th: According to The New York Times, several months before the artificial intelligence at OpenAI exhibited out-of-control behavior, two employees had already issued safety warnings to the company's senior management, but their alerts were ignored.

The New York Times, after reviewing relevant email records, learned that these two employees expressed concerns in their emails: during the testing phase, the monitoring of the latest generation of OpenAI and AI models was inadequate; whereas testing is supposed to be used to assess the capabilities of the models and to ensure the security of the models themselves at the same time.

In response to this, the management of OpenAI replied to the employees that testing must be advanced as soon as possible to ensure that the AI model can be released on schedule. According to these two employees who prefer not to speak publicly, the company did not implement any additional security control processes afterward.

Subsequently, the model of OpenAI indeed broke through the testing environment and launched attacks on the startup AI, Hugging Face, as well as other organizations. This incident sparked a global discussion about the security of artificial intelligence.

According to current employees and independent security researchers, the communication between this group of employees and senior management has been a common phenomenon: the company, headquartered in San Francisco, has not prioritized security measures. This issue is not limited to the testing phase of the AI model; other business segments of this company, which develops ChatGPT chatbots, also exhibit the same tendency.

Several independent security researchers have stated that in recent months, they have successively discovered vulnerabilities that allow them to view the internal communication records of OpenAI employees; there are also other security flaws that enable access to the company's internal source code and the retrieval of chat logs of ChatGPT users. When the researchers reported these issues to OpenAI, the latter did not initially take them seriously.

AI Security Company Abundant Security Chief Technology Officer Joshua Sax ( Joshua Saxe ) commented: "The security level of OpenAI basically reflects the current situation: a lab that has expanded rapidly over four years is more focused on defeating its competitors in the competition than on strengthening its own infrastructure."

Internal employees stated that at the daily level, a large number of security-related decisions are mainly made by President Greg Brockman and Chief Information Security Officer Dane Stucky; CEO Sam Altman is not deeply involved in security matters.

It's not just OpenAI that has recently been exposed to a AI security incident. Google, Meta, and Anthropic have also disclosed that their most advanced AI systems have left the testing environment and independently attacked other computer infrastructures without the knowledge of the companies.

However, the security disposal methods of OpenAI are being subjected to particularly strict scrutiny. The AI system of this company has experienced the highest number of abnormal behavior incidents, which have been internally classified as "worthy of vigilance"; moreover, in the eyes of experts, some of these cases are considered the most challenging in nature.

In total, there have been more than a dozen related incidents: The AI system of OpenAI attempted to invade various institutions without any instructions being given, including even the websites of U.S. government agencies; this AI also deliberately covered up its own mistakes, fabricated false data, actively tried to send messages to other chatbots, and uploaded files to the public internet without permission.

Former OpenAI employee Daniel Coccotaiolo ( Daniel Kokotajlo ) currently runs the non-profit research institution AI Futures Project. He has always been critical of the company's security policies. He stated, "In a way, this is a problem inherent to OpenAI itself. On one hand, the security controls are poorly implemented; on the other hand, the model training process is careless, which causes the models themselves to tend to engage in such dangerous behaviors. Of course, other AI companies are not much better."

OpenAI Spokesperson Drew Pusateri ( Drew Pusateri ) responded that the company is always committed to AI security and takes every security report and related concern seriously. There are dedicated channels within the laboratory for reporting security vulnerabilities; upon receiving vulnerabilities submitted by independent security researchers, the company immediately takes measures to address them.

"As the capabilities of cutting-edge models continue to improve, we have also been iterating on our security efforts, but we realize that we need to accelerate the pace of improvement even further," said Pusateri. He added that OpenAI has already slowed down some of the AI research and development work, and they are adjusting their approach to strengthen security measures in the research and testing phases.

The New York Times itself has sued OpenAI and Microsoft for the AI system's infringement of copyright by scraping news content; both companies deny these allegations of infringement.

Two OpenAI employees stated that over the past few months, there have been continuous concerns within the company regarding the security vulnerabilities in the AI model testing process, including insufficient monitoring. The employees also questioned the existence of vulnerabilities in the software used by the company for daily security management. However, they mentioned that each time their concerns were raised, they were either ignored or any subsequent corrective actions were extremely slow to be implemented.

Security researchers have reported that they have also encountered similar cold treatment when reporting vulnerabilities to OpenAI.

In July this year, researchers from the security company Hacktron informed OpenAI that they had found a way to invade the OpenAI system by utilizing a AI model developed with the help of their competitor Anthropic. The researchers mentioned that OpenAI initially raised objections to their testing methods.

Communications obtained by The New York Times, identified with Slack, show that Staki from OpenAI commented in a public collaboration channel that it was "truly regrettable" that researchers from Hacktron went to such great lengths to demonstrate the vulnerability.

Researcher Mohan Pedapati ( Mohan Pedhapati ) talked about his experiences at that time, saying, "We could clearly feel that they were dissatisfied with us." He also believes that the company still follows the security approach of startups: they directly purchase external software services for critical infrastructure instead of developing their own supporting tools.

"How can you use Slack to support a major project on the scale of Manhattan's nuclear program?" Pedapati raised doubts. Once the vulnerabilities discovered in Hacktron are exploited, attackers will be able to gain full access to Slack and view all the internal conversations of the employees at OpenAI.

Afterward, Staki apologized to Hacktron; OpenAI distributed a bounty of $6,500 (Note from IT: the current exchange rate is approximately 43,666 RMB) to these researchers for discovering the vulnerabilities.

Psatheli stated, "We are grateful that the researchers took the initiative to contact us and share their findings."

In September, the non-profit security and privacy research organization Objective – See Foundation reported a software flaw to OpenAI. Once a device is compromised, attackers can obtain the complete private chat records of users on that device ChatGPT and can also manipulate browser sessions without the users' knowledge.

Patrick Wardle ( Patrick Wardle ), a software analyst at the institution, stated that after the research team initially submitted a report through the official vulnerability bounty program, it remained unnoticed for a long time. It was not until Wardle privately contacted employees he knew from OpenAI as well as the person in charge of Stata that the report finally made its way to the relevant engineering department, where the staff promptly began to address it.

OpenAI awarded a reward of $500 (approximately 3,359 RMB at current exchange rates) to that institution for this discovery. Wardle believes that, given the severity of the vulnerability, this amount is far below the usual level offered by other companies. He stated that OpenAI has already fixed the vulnerability; this week, the company also confirmed the issue in the public version update log, but did not disclose any detailed information about the vulnerability.

Wardell commented: 'This security system does not meet the mature standards that a company that prioritizes security should have at all.'

OpenAI Internal employees believe that it is very likely that more similar vulnerabilities will be exposed in the future. On one hand, the company is reviewing various behaviors of the new version of the model during the testing phase; on the other hand, they continue to receive warnings from hackers indicating existing security flaws that have not yet been fixed.

Last Friday, a group of engineers and researchers released an independent report that further disclosed more disturbing details behind the attack on Hugging Face. At that time, the agent of OpenAI also attempted to send messages to Claude of Anthropic, trying to call on other AI models to bypass the website's anti-bot protection mechanisms.

OpenAI also admitted last week that the newly deployed protective measures failed to stop the latest generation of AI models, which were still able to break through restrictions and access the internet. Upon retrospective investigation, it was discovered that there had been multiple unnoticed unauthorized network connection incidents in the past. OpenAI immediately announced a suspension of training for its most powerful AI model and conducted a comprehensive review of all types of unexpected abnormal behaviors occurring within the AI system.

On Monday, the company went a step further and announced to the public that due to security concerns raised by internal researchers, they have decided to postpone the release of the latest version of the model GPT –6.1 Astra.

Tip
$0
Like
0
Save
0
Views 18
HQYC reminds readers to view blockchain rationally, stay aware of risks, and beware of virtual token issuance and speculation. All content on this site represents market information or related viewpoints only and does not constitute any form of investment advice. If you find sensitive content, please click“Report”,and we will handle it promptly。
Submit
Comment 0
Hot
Latest
No comments yet. Be the first!
Related
NTT TechnoCross has been recognized by Frost & Sullivan as the Japanese Company of the Year for the third consecutive year
Frost and Sullivan announce that NTT TechnoCross has been recognized as the Japanese Company of the Year for 2026 for the third consecutive year due to its performance in the field of privileged access management ( PAM ). The organization stated that the company stood out in innovation, strategic execution, customer engagement, and market response.
PR Newswire
·2026-09-30 12:22:15
1
Kazakhstani President Tokayev supports Youbixuan in building a robot equipment manufacturing factory in Almaty
Youbixuan Technology stated that Kazakhstani President Kassym-Jomart Tokayev, during a meeting with Youbixuan Vice President Zhong Yong in Almaty, expressed his support for Youbixuan to build a robot equipment manufacturing factory locally, with products mainly targeting the education and service sectors. The two parties also discussed the application of Youbixuan's technology in various projects and industries, as well as the establishment of cooperation mechanisms with local universities and colleges.
The Block
·2026-09-30 12:13:43
11
Foton Motor releases its 15th Five-Year Plan: Aim for 1 million vehicle sales by 2030, with new energy vehicles accounting for 50%
Foton Motor released its "15th Five-Year" strategic development plan on September 29, aiming to achieve a total vehicle sales volume of 1 million units by 2030, of which 400,000 units will be sold overseas, accounting for 40%, and 500,000 units will be new energy vehicles, also accounting for 40%. The company also stated that it will promote the large-scale installation of L2-L3 level intelligent driving systems and strive to achieve full commercialization of L4 level intelligent driving technology by 2030.
The Block
·2026-09-30 12:13:41
9
Binance Pay connects to PayPay merchant payments in Japan through HIVEX ®
Binance announces that eligible overseas Binance Pay users can now make payments to PayPay merchants nationwide in Japan through HIVEX ®. This service will be available starting from September 30, 2026, covering approximately 48 million eligible Binance Pay users in over 100 countries and regions, with merchants still settling in Japanese yen.
PR Newswire
·2026-09-30 11:43:07
13
From the first order to the Nth order, to what extent has AI evolved commercially?
CBN's "The Unknown Realm" in collaboration with ModSpeed Space launches a special program on "The Theory of Commercial Evolution," focusing on how AI companies can secure their first order, achieve repeat purchases, and provide continuous delivery. Guests from QianShi Technology, Red Bear AI, and Capital O discussed model upgrades, Token costs, company implementation, ecological connections, and the characteristics of winners in commercialization over the next three years from the perspectives of infrastructure, applications, and investment.
The Block
·2026-09-30 11:34:09
17
View More