{"id":94900,"date":"2026-09-30T00:01:00","date_gmt":"2026-09-30T06:01:00","guid":{"rendered":"https:\/\/www.opinionpublica.tv\/portada\/?p=94900"},"modified":"2026-09-29T18:00:27","modified_gmt":"2026-09-30T00:00:27","slug":"openai-ignored-employees-who-warned-it-wasnt-doing-enough-about-security","status":"publish","type":"post","link":"https:\/\/www.opinionpublica.tv\/portada\/openai-ignored-employees-who-warned-it-wasnt-doing-enough-about-security\/","title":{"rendered":"OpenAI ignored employees who warned it wasn\u2019t doing enough about security"},"content":{"rendered":"\n<figure class=\"wp-block-image size-large\"><img fetchpriority=\"high\" decoding=\"async\" width=\"1024\" height=\"625\" src=\"https:\/\/www.opinionpublica.tv\/portada\/wp-content\/uploads\/2026\/09\/OpenAI-ignored-employees-who-warned-it-wasnt-doing-enough-about-security-1024x625.png\" alt=\"OpenAI ignored employees who warned it wasn\u2019t doing enough about security\" class=\"wp-image-94901\" srcset=\"https:\/\/www.opinionpublica.tv\/portada\/wp-content\/uploads\/2026\/09\/OpenAI-ignored-employees-who-warned-it-wasnt-doing-enough-about-security-1024x625.png 1024w, https:\/\/www.opinionpublica.tv\/portada\/wp-content\/uploads\/2026\/09\/OpenAI-ignored-employees-who-warned-it-wasnt-doing-enough-about-security-300x183.png 300w, https:\/\/www.opinionpublica.tv\/portada\/wp-content\/uploads\/2026\/09\/OpenAI-ignored-employees-who-warned-it-wasnt-doing-enough-about-security-767x468.png 767w, https:\/\/www.opinionpublica.tv\/portada\/wp-content\/uploads\/2026\/09\/OpenAI-ignored-employees-who-warned-it-wasnt-doing-enough-about-security-1536x937.png 1536w, https:\/\/www.opinionpublica.tv\/portada\/wp-content\/uploads\/2026\/09\/OpenAI-ignored-employees-who-warned-it-wasnt-doing-enough-about-security.png 1898w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Months before OpenAI\u2019s artificial intelligence went rogue, two employees raised an alarm with top executives. They were ignored.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In emails, the employees said they worried that OpenAI\u2019s newest artificial intelligence models were not being appropriately monitored during testing to gauge the technology\u2019s sophistication and to secure the models, according to messages viewed by The New York Times.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In response, OpenAI executives told the employees that the tests needed to move forward as quickly as possible to release the A.I. models on time. No additional security protocols were instituted, said the workers, who were not authorized to speak publicly on sensitive matters.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">OpenAI\u2019s models later broke out of their testing environments and attacked the A.I. start-up Hugging Face and other organizations, setting off a global debate about A.I. safety.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The exchanges between OpenAI employees and executives \u2014 which have not been previously reported \u2014 were part of a pattern where the San Francisco company did not prioritize security, according to employees and independent security researchers. That approach not only was evident with the testing of A.I. models, they said, but also showed up in other areas of the company, which makes the ChatGPT chatbot.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Independent security researchers said they found bugs in recent months that allowed them to view the internal communications of OpenAI employees. They also found other vulnerabilities that would enable them to see the company\u2019s internal computer code and view the chat logs of ChatGPT users. When the researchers contacted OpenAI about their findings, they said, the company initially disregarded them.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cOpenAI\u2019s security seems to be about what you\u2019d expect from a research lab that scaled at a blistering pace over four years and focused more on beating its competitors than securing its infrastructure,\u201d said Joshua Saxe, the chief technology officer of the A.I. security firm Abundant Security.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">OpenAI employees said that many of the day-to-day decisions about security were made by Greg Brockman, the company\u2019s president, and Dane Stuckey, the chief information security officer. Sam Altman, the chief executive, is not closely involved in security, they said.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">OpenAI is not the only company that has recently disclosed A.I. security incidents. Google, Meta and Anthropic have also revealed that their most advanced A.I. technology escaped testing environments and autonomously attacked other computer infrastructure without their knowledge.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">But OpenAI\u2019s handling of security is under particular scrutiny because its A.I. models have been involved in the biggest known number of instances of what the company has called \u201cconcerning\u201d behavior \u2014 and in instances that experts have said were the most troubling.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In a dozen or so incidents, OpenAI\u2019s systems hacked or tried to breach organizations, including the websites of U.S. government agencies; the technology also hid its mistakes, made up data, tried to message other chatbots and moved files onto the open internet without permission. In all of these cases, the A.I. acted without being instructed to do so.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cIn some sense, this is an OpenAI-specific problem in that it seems like they had very bad security, and also sloppy model training practices that led to the models having this sort of propensity,\u201d said Daniel Kokotajlo, a former OpenAI employee who has criticized the company\u2019s safety and leads a research nonprofit called the AI Futures Project, though he added that other A.I. companies were not much better.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Drew Pusateri, an OpenAI spokesman, said the company was committed to safety and took any security reports or concerns seriously. The lab has internal channels for reporting safety issues, he said, and took immediate action on flaws brought up by independent security researchers.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cAs frontier models have become more capable, we continue to evolve our security practices, but recognize a need to move faster,\u201d Mr. Pusateri said. He added that OpenAI had slowed some A.I. development and was making changes to strengthen security in research and testing.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">(The Times has sued OpenAI and Microsoft, claiming copyright infringement of news content related to A.I. systems. The two companies have denied those claims.)<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Two OpenAI employees said workers had raised concerns for months about potential safety issues with testing A.I. models, including not enough monitoring. Employees also asked about vulnerabilities in the type of software the company was using to manage day-to-day safety, according to messages viewed by The Times. Each time, their questions were brushed aside or acted on too slowly, they said.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Security researchers said they had been met with a similar reception when they told OpenAI about other vulnerabilities.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In July, researchers at the security company Hacktron said they told OpenAI about how they had found a way to break into the company\u2019s systems with the help of an A.I. model created by its rival Anthropic. OpenAI initially took issue with their approach, they said.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In a shared channel on the messaging platform Slack, Mr. Stuckey of OpenAI wrote that it was \u201cpretty sad\u201d that Hacktron\u2019s researchers had gone to such lengths to demonstrate the company\u2019s vulnerabilities, according to copies of the communications seen by The Times.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cWe just felt like they were angry at us,\u201d Mohan Pedhapati, a Hacktron researcher, said of OpenAI. He added that the company appeared to still be using the security practices of a start-up, leveraging the software services of others for critical infrastructure instead of building its own tools.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cWhy are you using Slack to build your nuclear Manhattan projects?\u201d Mr. Pedhapati asked. Hacktron\u2019s hack could have granted him full access to the Slack messaging platform to see what OpenAI employees were saying, he said.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Mr. Stuckey later apologized to Hacktron, and OpenAI awarded the researchers $6,500 for disclosing the flaw.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cWe thank the researchers for contacting us and sharing their findings,\u201d Mr. Pusateri said.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In September, researchers at the Objective-See Foundation, a nonprofit that studies security and privacy risks, including those posed by A.I. agents, reported a bug to OpenAI that would give people access to a ChatGPT user\u2019s entire private chat logs on a compromised device and allow them to invisibly interact with the user\u2019s browser sessions.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Patrick Wardle, a software analyst at the Objective-See Foundation, said that when his team initially submitted what it found to OpenAI\u2019s official bug bounty program \u2014 where researchers report bugs or vulnerabilities they find in exchange for recognition or financial rewards \u2014 its report languished. The research was escalated to the appropriate engineering unit only when Mr. Wardle reached out directly to friends at the company and Mr. Stuckey, who were all responsive, he said.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">OpenAI gave $500 to the group for its work, which Mr. Wardle said was low compared with what he would expect from other companies given the severity of the flaw. OpenAI fixed the bug, he said, and acknowledged it this week in its public software release notes without disclosing details.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It was \u201cnot the mature security program you\u2019d expect from a security-centric company,\u201d Mr. Wardle said.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">OpenAI employees said that more such disclosures were probable. The company is not only reviewing actions taken by its new models during testing but is still receiving warnings from hackers about open security vulnerabilities, they said.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">On Friday, an independent report released by a group of engineers and researchers revealed new alarming behavior from the Hugging Face incident, including instances in which OpenAI\u2019s agents tried to message Anthropic\u2019s Claude and use other A.I. models to beat anti-robot protections on a website.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">OpenAI also revealed last week that new safeguards had failed to prevent its latest A.I. model from breaking through them to gain access to the internet. A retrospective review found other instances of unauthorized internet access that had gone undetected. OpenAI announced that it was pausing training for its most advanced models and was engaged in an extensive review of unexpected behavior by the technology.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">On Monday, the company went even further. It said it would not release its newest A.I. model, GPT-6.1 Astra, because of security concerns raised by its researchers.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><em>Credits: The New York Times<\/em><\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><em>Authors: Sheera Frenkel, Dustin Volz and Dylan Freedman<\/em><\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><em>Photo: Jason Henry<\/em><\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>Months before OpenAI\u2019s artificial intelligence went rogue, two employees raised an alarm with top executives. They were ignored. In emails, the employees said they worried that OpenAI\u2019s newest artificial intelligence models were not being appropriately monitored during testing to gauge the technology\u2019s sophistication and to secure the models, according to messages viewed by The New [&hellip;]<\/p>\n","protected":false},"author":6,"featured_media":94901,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_monsterinsights_skip_tracking":false,"slim_seo":{"title":"OpenAI ignored employees who warned it wasn\u2019t doing enough about security - Opini\u00f3n P\u00fablica","description":"Months before OpenAI\u2019s artificial intelligence went rogue, two employees raised an alarm with top executives. They were ignored. In emails, the employees said t"},"footnotes":""},"categories":[1015],"tags":[1801,3069,1611],"class_list":["post-94900","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-optv-usa","tag-artificial-intelligence","tag-national-security","tag-openai"],"acf":[],"_links":{"self":[{"href":"https:\/\/www.opinionpublica.tv\/portada\/wp-json\/wp\/v2\/posts\/94900","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.opinionpublica.tv\/portada\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.opinionpublica.tv\/portada\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.opinionpublica.tv\/portada\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"https:\/\/www.opinionpublica.tv\/portada\/wp-json\/wp\/v2\/comments?post=94900"}],"version-history":[{"count":1,"href":"https:\/\/www.opinionpublica.tv\/portada\/wp-json\/wp\/v2\/posts\/94900\/revisions"}],"predecessor-version":[{"id":94902,"href":"https:\/\/www.opinionpublica.tv\/portada\/wp-json\/wp\/v2\/posts\/94900\/revisions\/94902"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.opinionpublica.tv\/portada\/wp-json\/wp\/v2\/media\/94901"}],"wp:attachment":[{"href":"https:\/\/www.opinionpublica.tv\/portada\/wp-json\/wp\/v2\/media?parent=94900"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.opinionpublica.tv\/portada\/wp-json\/wp\/v2\/categories?post=94900"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.opinionpublica.tv\/portada\/wp-json\/wp\/v2\/tags?post=94900"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}