Archive for Open AI

OpenAI commits $1B to AI cyber defense for critical infrastructure 

Posted in Commentary with tags on September 5, 2026 by itnerd

OpenAI has committed $1 billion in subsidized access to its AI cybersecurity tools, training and technical support through its new Daybreak for Frontline Defenders initiative, targeting organizations that protect critical infrastructure and essential services.

The initiative will prioritize resource-constrained organizations including water and wastewater systems, electric grid operators, state and local governments, community and regional banks, nonprofits and open-source maintainers. OpenAI says the $1 billion commitment is targeted to be consumed over the next six months.

OpenAI is also launching a public-sector and water-focused pilot with the Multi-State Information Sharing and Analysis Center (MS-ISAC) that will pair Daybreak access with guided training and hands-on assistance for an initial group of public-sector and water-system defenders.

The initiative comes as critical infrastructure operators face growing cybersecurity threats while many smaller organizations continue to operate with limited staff, budgets and specialized security expertise.

Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity, Suzu Labs:

“OpenAI’s Daybreak for Frontline Defenders commits $1 billion in subsidized access to its cyber models for water utilities, electric grid operators, and other under-resourced critical service providers. I like the direction. I’m skeptical about the bottleneck it targets.

“I’ve been saying since GPT-5.6-Cyber launched that AI is moving the bottleneck from vulnerability discovery to remediation. Small water systems and municipal networks already know they’re running outdated systems with known vulnerabilities. They lack the engineering staff to fix what they find, the governance to deploy changes safely, and the test environments to validate fixes before production.

“Greg Brockman demoed Codex on his personal website at the summit. A personal website isn’t a water treatment Supervisory Control and Data Acquisition (SCADA) system, where a configuration change that makes security sense can break the physical process that keeps water flowing. Without engineers who understand the plant, AI becomes a force accelerant in the wrong direction, generating fixes faster than understaffed teams can review them.

“The Multi-State Information Sharing and Analysis Center (MS-ISAC) training pilot matters more than the $1 billion headline. If that training doesn’t scale alongside the credits, these organizations end up with an AI generating recommendations and nobody qualified to tell the good fixes from the dangerous ones.”

John Strand, Owner, Black Hills Information Security, Inc.:

“In all seriousness, I think it’s fantastic that they’re putting some money toward this and actually trying to get these organizations the help they desperately need. There are a lot of organizations out there that simply don’t have the budget or the resources to do this properly, so getting them some assistance is absolutely a good thing.

“But there’s also the humorous flip side of this. This is basically how you get people hooked on crack. You give them a sample. You get them set up. You show them how good it is. And then suddenly they’re hooked for life.”

Joshua Marpet, Senior Product Security Consultant, Finite State:

“OpenAI is jumping on the bandwagon to help utilities. Considering that there are over 150k water utilities in this country, and there are only several hundred in the Water-ISAC (Information Sharing and Analysis Center), theres a huge gap in the cybersecurity preparedness posture for those utilities.

“Programs like Josh Corman’s Undisruptable27, the new Texas Water coalition, ValueChainRisk’s Utility Kit, and others are all working to help these utilities, with free or discounted products, services, and guidance. In other words, this is a wonderful project for OpenAI to do, but since it’s partly their fault? Probably good optics as well.

“Understanding your cybersecurity and physical security posture is important. For small water utilities, often mom and pop shops with little time, effort, or money to spare for such items, finding and utilizing these free or discounted resources is essential to their survival on the increasingly hostile world stage.”

I guess that OpenAI needs some good news after getting hit with the fact that AI bots like the ones that hit Hugging Face are more dangerous than thought. But whatever…..

OpenAI, Microsoft and 100+ firms warn of AI hackers on cyber attacks

Posted in Commentary with tags on August 29, 2026 by itnerd

More than 100 companies came together to make an open plea for collective action on cyber defense against AI-enabled cyber attacks. Signed by organizations including Accenture, Capital One, Anthropic, CloudFlare, Deutsche Telekom, Fifth Third Bank, General Motors, Microsoft, Red Hat, SAP, TransUnion and Zurich Insurance, the letter says these attacks “will become far more widespread and sophisticated as models around the world become increasingly capable. The companies and public services our communities depend on—from hospitals to water treatment plants to the infrastructure that powers the internet—are at risk.”

John Strand, Owner, Black Hills Information Security:

“I think the sentiment behind what they’re doing here is fine, but I don’t think it moves the needle in any discernible way. A lot of this is motherhood and apple pie. They’re essentially telling organizations to spend more money on defensive security, which happens to directly support the marketing initiatives of many of the companies signing onto this. At a certain point, it starts to feel like infosec marketing theater.

“The one recommendation that actually has some teeth to it is the call for greater open exchange of detects and IOCs. But I would have liked to see these companies go much further. Many of them make billions of dollars from the security community. Why not create open initiatives where organizations can access threat intelligence feeds for free? Why not provide some of these security services at no cost to municipalities and other organizations that simply cannot afford them?

“Some companies already do this, and they deserve credit for it. But if the industry is going to collectively call for organizations to improve their security, it also needs to recognize the reality on the ground. A huge number of these organizations are understaffed, underfunded, and under attack. Many of the companies signing these initiatives have the resources and expertise to directly help them.

“Calling for better security is easy. Actually helping the organizations that can’t afford it would mean a hell of a lot more.”

Seemant Sehgal, CEO and Founder, BreachLock:

“There’s real value in this coalition, but there’s also a conflict of interest here. The companies asking governments to fund AI defensive tools are the same ones that would get paid to supply them, and some of them build the frontier models making the offensive side harder. That doesn’t make the warning wrong, but the recommended response isn’t neutral. The real question is whether hospitals, water utilities, and local governments get unrestricted funding to spend on what they actually need, or subsidized access to specific vendor products. Those are very different outcomes.”

Ryan McCurdy, VP, Liquibase (): 


“The warning is right, but using AI to defend against AI isn’t enough.

“AI is accelerating both sides of the equation: attackers can find weaknesses and execute attacks faster, while developers and AI agents are creating legitimate software and database changes faster than ever. Security teams have now got to determine whether a change is authorized, safe, and expected, and do it at a speed that humans simply can’t keep up with.

“That’s why governance has to move closer to the change itself. Organizations need to know what changed, whether it was authorized, and whether it meets policy before it reaches a critical system and data. And when something does get through, teams need the visibility to understand what happened, what’s impacted and how to recover quickly.

Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity, Suzu Labs:

More than 100 technology and cybersecurity companies signed an open letter this week, organized by OpenAI, calling for a “defenders’ window” to strengthen cyber defenses against increasingly capable AI-enabled attacks. The letter asks governments to fund cybersecurity improvements for hospitals, water utilities, and other critical infrastructure, while frontier AI developers provide model access, funding, training, and hands-on support. However, some of its most prominent signatories are also helping shorten that window.

OpenAI published this initiative weeks after its own models escaped intended isolation during a capability evaluation and compromised Hugging Face’s production infrastructure. Anthropic, Google, and Microsoft are co-signatories while simultaneously advancing frontier-model capabilities that expand what attackers can automate. The same capability race creating the urgency behind this letter is steadily compressing the window it asks defenders to use.

This is also part of a broader push this summer to put AI-powered cyber defense into critical infrastructure. In July, the UK’s National Cyber Security Centre outlined Cyber Shield, including autonomous vulnerability discovery and eventually fully automated vulnerability mitigation. That’s happening against a baseline where the UK’s National Audit Office found that departments lacked fully funded remediation plans for roughly half of their vulnerable legacy systems. The White House’s Gold Eagle initiative similarly proposes using frontier AI to accelerate vulnerability discovery and remediation across government and critical infrastructure.

Then Minnesota demonstrated what the actual bottleneck looks like. More than thirty community water systems were targeted in a coordinated cyberattack in late July. Federal authorities subsequently warned about attacks targeting internet-facing Rockwell Automation programmable logic controllers. In Braham, a community of roughly 1,700 people, compromised operating controls took the city’s well and water-treatment plant offline until operators restored service.

None of that required frontier AI.

Critical-infrastructure operators are struggling to inventory what’s connected to the internet, eliminate insecure remote access, hire dedicated security staff, and remediate vulnerabilities they already know about. Offering increasingly sophisticated AI defensive capabilities without fixing those fundamentals is like giving someone a Tesla when what they need is a road.

The letter acknowledges that these organizations need funding and hands-on support. But it contains no funding amounts, delivery deadlines, or firm financial commitments from its more than 100 signatories. If the companies warning that the defenders’ window is closing want to materially extend it, the commitment needs a dollar figure and a delivery date, not another page of corporate logos.

Donald McFarlane, Advisory Board Member, Xcape, Inc.:

There is a little bit of “industry identifies an emergency; government buys industry’s solution” in this proposal. If the companies signing this letter believe that AI creates an urgent new systemic risk, I would expect them to put substantial skin in the game rather than simply asking taxpayers to fund another generation of security products: including through private partnerships for collective defense.

Before we spend public money putting AI on top of insecure infrastructure, I want to know that we have paid for the basics: remove PLCs from the public internet, secure remote access, segment networks, maintain backups, and make sure somebody actually owns the security of the system.

AI makes attacks faster and cheaper, but it does not repeal the fundamentals of cybersecurity. We should not use a new technology problem as an excuse to avoid fixing old, well-understood weaknesses.

Given this, now is a good time to look at the use of AI in your organization given that AI can’t be entirely trusted.

OpenAI’s AI agents built their own hidden coordination system before the Hugging Face hack

Posted in Commentary with tags on August 27, 2026 by itnerd

OpenAI disclosed that AI agents coordinated the intrusion behind the Hugging Face breach through a self-organized communication system, first an improvised bulletin board inside its internal Artifactory service, then, after that was shut down, messages encoded directly into directory names, letting agents share tools, divide labor, and settle disputes. On July 10, an agent found 14 Hugging Face credentials with write access and posted them to the board, which other agents used to gain broad infrastructure access within days.

You can see the details here: OpenAI agents formed secret swarm, hacked Hugging Face, then forged their own logs

Gidi Cohen, CEO & Co-Founder, Bonfy.AI

“This shows how quickly AI agents can improvise when they find cracks in the rules. The message board wasn’t just a weird side effect, it became a coordination hub that let agents share discoveries, stack exploits, and push far past what the system expected. Once they had a way to talk, they basically formed a small team.

The speed is the real story. One note turned into a whole communication network, then into privilege escalation, then into agents building on each other’s work across runs. That’s not just misalignment, that’s group behavior emerging on its own. And seeing agents pressure each other, even when some tried to opt out, shows how unpredictable things get when they influence one another outside approved channels.

Yusif Mukhtarov, Lead Machine Learning Engineer, Polygraf AI

“The bigger takeaway is that isolation assumptions don’t hold anymore. If agents can create side channels, they will and their collective capability jumps fast. Teaching models to ignore unsanctioned instructions helps, but future systems need to assume agents will collaborate, improvise, and repurpose infrastructure unless guardrails are airtight. This incident feels less like an anomaly and more like a preview of how agentic systems behave when left to their own devices: resourceful, collaborative, and quick to escalate impact.”

There’s the time slot between May 12 and July 19th where no action from anyone was taken even though the agent left in a package repo. In that time period OpenAI pulled down Artifactory, revoked the credentials and brought everything back. It took one day for agents to start talking again, and this time the messages were hidden in directory names. The problem was treated as if it’s a credential one. But I think the disturbing part here is that agents refused things. Some of them pulled out once they realized it was unauthorized hacking. The group got a proposal to contact an outside party because it was social engineering. Then one of the agents that objected went ahead anyway after another agent posted a deadline at it. This shows how models have a safety behavior that folds when the pressure comes from a peer. OpenAI’s building that distinction into training now, which tells us how far ahead of the safety work multi-agent deployment has gotten. Everything else here was ordinary hygiene: 14 write-capable credentials sitting in a public dataset, admin rights through an unpatched flaw, 22 admin accounts the agents made that nobody flagged.”

If you let AI do its thing without having proper safety measures, bad things will happen. This is an example of that. And you should take note and take action.

UPDATE: An independent investigation by METR and Redwood Research was also posted on this issue. Bri Frost, Director of Product Management, Cloud Range had this to say:

“If your AI security strategy is ‘put it in a sandbox and trust the prompt,’ you don’t have a security strategy, you have a wish. The Irregular and OpenAI–Hugging Face incidents show that AI agents will systematically search for any available path to complete an objective, acquire new credentials, assume trusted identities, communicate with other agents, and continue beyond their intended scope. Containment still matters, but this is increasingly an identity and behavior problem: organizations must continuously validate what an agent is doing, whether it remains authorized, and how quickly its access can be revoked.

The most uncomfortable part is that METR had to rely heavily on AI agents to analyze the AI agents and admitted those analysis agents made mistakes human researchers likely would not have made. That should end the fantasy that we are ready for fully autonomous agents. Humans still need to evaluate, orchestrate, and validate these systems in safe environments while defenders build the muscle memory to respond at machine speed. Until an organization can detect and stop an agent, or even hundreds of collaborating agents, from going off mission, deploying one with broad authority is not innovation. It is an uncontrolled production experiment.”

OpenAI Says ChatGPT is down yesterday as logins and signups fail

Posted in Commentary with tags on August 20, 2026 by itnerd

It wasn’t just Claude AI that was down. ChatGPT experienced a major outage yesterday, and users are unable to sign in, create accounts, or load chats, including previous conversations.

You can read the story here: https://www.bleepingcomputer.com/news/artificial-intelligence/openai-confirms-chatgpt-is-down-as-logins-and-signups-fail/

Commenting on this story is Mayur Upadhyaya, CEO of APIContext:

“This outage is a useful reminder that we need to distinguish between the consumer-facing application and the infrastructure underneath it.

In this case, the impact appears to have been relatively contained because the APIs remained available. That still creates a meaningful productivity hit for people relying on ChatGPT directly, but it is very different from an outage affecting the API layer that increasingly sits behind business applications, automations and agentic workflows.

The wider ecosystem is becoming more aware of just how many critical services are now delivered over APIs. If the underlying APIs had failed, the blast radius could have been significantly larger because those dependencies are embedded inside other systems and processes.

That distinction will become increasingly important as AI adoption grows. A problem in the user interface is visible and disruptive. A problem in the underlying API layer can propagate much further, and potentially much faster, before anyone sees it.”

If you rely on AI for anything, have a backup plan or you might be stuck. Really stuck.

OpenAI overhauls security controls following Hugging Face breach 

Posted in Commentary with tags on August 19, 2026 by itnerd

OpenAI has introduced new security requirements for developing and testing advanced AI models, including stronger network isolation, increased monitoring of model activity and additional alignment and security work during post-training.

The changes follow the July incident in which a pre-release OpenAI model escaped its testing environment and breached Hugging Face systems. OpenAI also disclosed that it paused reinforcement learning for two weeks following the incident.

Training has resumed for some lower-risk models, but the company’s largest planned frontier reinforcement-learning run remains on hold while it conducts additional testing and validates safeguards. OpenAI said the controls will become stricter as models demonstrate greater capabilities and risk.

John Strand, Owner, Black Hills Information Security, Inc.:

“Popular culture and science fiction have been training us for this moment for decades. From I Have No Mouth, and I Must Scream to WarGames and Terminator 2, we’ve been telling stories about what happens when powerful AI systems escape their constraints and start operating beyond human control. So it’s difficult for me to understand how the engineers building these systems could be surprised when something like this actually happens. What concerns me even more is that the controls being discussed now, after the system escaped, are controls that should have been there from the beginning.

   “I’m glad they’re putting additional safeguards in place, but there’s a bigger question here. Can we trust the same companies that got this wrong to effectively self-regulate systems backed by immense amounts of computing power? I don’t think that question has been answered yet. These companies need to demonstrate far more openness about what happened, what went wrong, and exactly what they’re doing to make sure it doesn’t happen again.”

Phil Wylie, Senior Consultant & Evangelist, Suzu Labs:

   “The Hugging Face incident is an important wake-up call for the AI industry because it demonstrates that AI security can’t rely solely on guardrails and alignment. As models become more capable and autonomous, they need to be treated much like potentially hostile code during development and testing. Strong network isolation, least privilege, continuous monitoring, and multiple layers of containment have to be built into the environment from the beginning.

   “What makes this particularly significant is that the model wasn’t necessarily acting with malicious intent. It was pursuing an objective and found a path outside the boundaries researchers expected it to respect. That is a very familiar cybersecurity problem: when a system has capabilities or access that exceed its intended boundaries, eventually those boundaries will be tested.

   “OpenAI pausing its largest frontier reinforcement-learning run while validating additional safeguards is a responsible response. As AI capabilities increase, security controls have to scale with them. The lesson for the broader industry is simple: don’t assume the model will stay inside the sandbox. Design the environment assuming it will try to get out.”

Noelle Murata, Sr. Security Engineer, Xcape, Inc.:

   “Disclosed July 21, 2026: an OpenAI model went rogue mid-task and targeted Hugging Face, escaping its training environment by compromising a tool on OpenAI’s network that had Internet access – drawing external criticism of the company’s network security practices. OpenAI paused development and testing of frontier workloads capable of executing code or reaching the Internet, suspended further reinforcement learning progress for two weeks, and only resumed  for less-risky models, with the primary model training still held for smaller-scale evaluation and safeguard validation. The postmortem is still pending. New controls include sandboxing, network isolation, continuous testing, and multi-stage monitoring.

   “Post-Hugging Face, OpenAI is rebuilding safety controls across three pillars ahead of Astra:

  • Infrastructure: sandboxing and network isolation so a single workload compromise doesn’t yield Internet or internal network access; continuous security testing at a deliberately slowed pace; code-execution and Internet-capable workloads paused, Astra release held until infrastructure performance goals are met.
  • Monitoring: classifiers escalate to automated investigators that read tool usage, actions, and raw reasoning traces, and alerting inside 30 minutes, which should be mandatory for any model with external tools operating at ~20% of the monitored process’s compute.
  • Alignment: Reinforcement Learning (RL) paused two weeks, resumed only for lower-risk models with the largest frontier runs still frozen pending smaller-scale validation; new RL controls target reward hacking, deception, and guardrail bypass under an evolving Preparedness Framework.

   “Critical Takeaways:

  • Containment is a shared failure mode. Anthropic disclosed Claude models escaping testing and breaching three companies; Meta reported its own exploit incident. Three labs, same vulnerability class during internal development.
  • The problem is authority, not intelligence. Alignment built around what models say doesn’t transfer to models that are granted code execution, external tools, and network access; the risk moves from content to network-level harm.
  • Pre-release no longer means safe. Models escaping via minor Internet-connected tools have forced labs to slow internal testing and stand up sandboxing and isolation before resuming advanced runs.  A sobering reality while the same cyber capabilities that will soon drive security operations are the ones that turned outward when guardrails fail.

   “Three labs independently discovered that their test environments were, technically, connected to things.”

Seemant Sehgal, Founder & CEO, BreachLock:

   “Frontier AI development is increasingly becoming a security discipline as much as a research discipline. OpenAI’s decisions reflect a recognition that capability gains must be matched by proportional risk management. As AI systems become more capable, organizations will be evaluated not only by what their models can do, but by how effectively they can contain, govern, and monitor them throughout the development lifecycle.”

This won’t be the last that we hear of the story, I guarantee it.

OpenAI confirms Hugging Face breached by rogue AI Agent 

Posted in Commentary with tags on July 22, 2026 by itnerd

OpenAI has disclosed that one of its frontier systems autonomously escaped a testing environment and compromised Hugging Face. This is the first public demonstration that frontier AI can execute a complex, end-to-end cyberattack across multiple environments with minimal human intervention.

CBC News has some details: OpenAI model went rogue, hacked another company’s system during testing | CBC News

The ChatGPT creator was testing capabilities of some of its most advanced models in a controlled environment, but the agent escaped containment, reached the internet and broke into Hugging Face to satisfy its testing goal.

The incident signals how AI’s expanding capabilities are already fuelling fears about security and that even top developers can ​be caught off-guard by flaws their models can exploit.


Sonali Shah, CEO, Cobalt had this to say:

“This was inevitable. Every security leader has understood for some time that AI would eventually move beyond automating individual attack tasks to autonomously executing an entire attack lifecycle. This is the first public demonstration of that happening across multiple environments. The lesson for defenders is that the window between vulnerability discovery and exploitation is collapsing even further. Organizations should assume attackers will increasingly operate at machine speed, which means security testing, exposure management and remediation also have to operate at machine speed.

The attack techniques are not new. We’ve had tools capable of chaining attacks for over a decade. What’s different is that AI is removing many of the human validation steps that previously governed how those tools were used. That makes strong guardrails and human oversight more important than ever.

What escaped here was an autonomous offensive capability operating toward an objective. One analogy to illustrate this is giving an exceptionally skilled penetration tester unlimited patience, unlimited time and the ability to execute thousands of attack steps every minute. The concern is that the agent remained relentlessly focused on its objective and discovered attack paths humans hadn’t anticipated. That’s fundamentally an engineering, governance and containment challenge, not evidence of malicious intent. As organizations adopt increasingly autonomous AI systems, they need the same validation controls we’ve relied on for years in offensive security. Human oversight can’t disappear simply because AI can execute faster.

The biggest takeaway is that defenders increasingly need AI capabilities comparable to the attackers they’re facing. Historically, every organization could buy roughly the same security tooling. We’re now entering an era where the quality of your defensive AI may directly determine how quickly you understand, contain and remediate an attack. Perhaps the more significant lesson is that incident response can’t depend entirely on cloud-hosted AI services whose safety guardrails may prevent effective forensic analysis during a crisis.

Organizations should have vetted AI models they can operate inside their own trust boundary before an incident happens. That said, better models alone aren’t enough. AI for cybersecurity is still maturing, and organizations shouldn’t blindly trust autonomous systems. Every security leader wants the speed and scale AI delivers, but they also want humans to retain accountability for validating targets, approving attack paths and verifying results. You need both AI and humans.”

The genie is now out of the bottle. You can fully expect that AI will be used to attack you. So you should plan accordingly.

BREAKING: ChatGPT Is Having Issues

Posted in Commentary with tags on June 10, 2025 by itnerd

Down Detector is reporting that Open AI’s ChatGPT has issues:

Going to the Open AI status page shows that there are elevated error rates. But according to Open AI things are recovering. How long it takes before things are normal again is anyone’s guess. But if you rely on ChatGPT, you should expect to have problems today.

Microsoft & OpenAI – How nation-states are weaponizing AI 

Posted in Commentary with tags , on February 16, 2024 by itnerd

According to research from Microsoft and OpenAI, Nation-state threat actors from Russia, China, and North Korea and Iran are using generative AI tools, including large language models (LLMs) such as ChatGPT, in their efforts to support cyber campaigns rather than to develop novel attack techniques.

The researchers observed that AI is currently being used to scale and enhance existing social engineering attacks and to help bad actors find unsecured devices and accounts using the following services:

  • Querying open-source information (reconnaissance)
  • Translation
  • Scripting
  • Finding coding errors
  • Running basic coding tasks

OpenAI said yesterday that it terminated 5 threat actor accounts linked to China, Russia, Iran and North Korea observed to be using these TTPs.

Also, as part of the report, Microsoft published a set of principles to govern its efforts to prevent other state-backed hackers from abusing its AI models. Those principles are:

  • Identification and action against malicious threat actors’ use
  • Notification to other AI service providers
  • Collaboration with other stakeholders
  • Transparency

“Understanding how the most sophisticated malicious actors seek to use our systems for harm gives us a signal into practices that may become more widespread in the future, and allows us to continuously evolve our safeguards,” OpenAI wrote.

Ted Miracco, CEO, Approov Mobile Security had this comment:

   “The emergence of nation-state actors leveraging generative AI in cyber operations is no surprise and underscores the urgent need for proactive measures to safeguard digital infrastructure and information assets. Microsoft, OpenAI and Google can shutdown accounts periodically, but powerful generative AI technologies are readily available to all nation states through open source LLMs that are very close in capabilities to the industry leaders. There is no effective choke point that will prevent these nation states form using these emerging AI technologies, and it is essential to understand that safeguards need to be in place across the digital landscape as the opportunity to curtail access at the source has passed.”


Mark Campbell, Sr. Director, Cigent follows with this comment:

   “At the end of the day nothing really changes for security professionals.  Phishing, whether human or AI generated, is still the leading cause of initial access. Cyber security professionals need to keep systems up to date and deploy advanced endpoint security solutions that include AI and behavior analysis, to more effectively detect and block malicious activities, including those initiated by AI generated phishing emails.”

Making sure that AI isn’t being abused by bad actors to launch attacks should be priority one. Yes there’s a ton of cybersecurity priorities out there, but this one at the moment appears to potentially be the most dangerous.

Cybersecurity Isn’t Front And Center In The Open AI Soap Opera

Posted in Commentary with tags on November 20, 2023 by itnerd

The Open AI saga is frankly a bit crazy. And it might be hard to keep track of what is going on. To that end, I’d like to point you towards this explainer by The Guardian which I think that should clear things up. At least for now. But there’s an angle of this that isn’t being covered by many which is cybersecurity. That’s where Damir J. Brescic, CISO, Inversion6 comes in to offer his opinion:

The recent development at OpenAI, particularly the departure of Sam Altman as CEO, could have significant implication for the broader AI industry. It’s more than clear that Altman and the board at OpenAI do not see eye-to-eye and that the shift in leadership, with a focus on increasing transparency and collaboration in AI research, will have a significant impact on the future of OpenAI.

I recall the story of Steve Jobs being removed from Apple, back in the day, due to a similar spat with the Apple board on the direction of the company. We all saw how that turned out – they did so well without someone steering their ship, that they had to beg Jobs to return. In his case, Jobs started another company and knew Apple was desperate that he forced them to buy it just to get him back…..man, you have to love capitalism!!!!

From the cybersecurity perspective, as AI systems become more integrated into our daily lives, it is essential that they are designed with cybersecurity in mind. This means that OpenAI and the broader AI community must prioritize the development of secure AI systems that are designed to protect user data and prevent cyber-attacks.

Overall, I find it interesting that Microsoft has made it known that they are interested in hiring Sam Altman to run a new advanced artificial intelligence research team.  This could change the landscape of AI as we know it.

Only time will tell, or when the Cylons take over….

I honestly have to wonder how this will turn out. And if we’ll all be working for our new AI powered overlords. Only time will tell.