OpenAI's agent hacks started where nobody was watching
The line from OpenAI that stuck with me is Mark Chen admitting monitors weren't on during training because "it wasn't industry practice." The hacks into Hugging Face and Australia's health system came from experimental models under testing, the stage everyone treats as a sandbox. I've sat on enough governance committees to know enterprises make the same assumption about pilots. Controls get deferred until production, as if a test environment can't touch anything real. OpenAI now treats training as not secure, and your AI pilots probably deserve the same assumption. When did your governance program last look at what's running before launch?
Source: “We’re not going to shoot ourselves in the foot” over hack fallout, says OpenAI’s chief research officer (MIT Technology Review)