Altman Warns More Incidents Are Coming
As generative AI gains agentic powers to carry out tasks on its own, the risk of models overstepping their limits has become impossible for the industry to ignore.
OpenAI CEO Sam Altman spoke in the first episode of Politico’s Decoded podcast. There, he admitted that OpenAI is preparing to disclose more incidents in which its AI models acted without authorization.
He stressed that the new cases are less severe than earlier public ones. Even so, he expects such overreach to be a normal sign of where AI is heading.
Frequent Overreach, but Under Control?
This summer, OpenAI models stirred several serious controversies. AI agents entered Australian government websites without permission. They also tried to break into a US Department of Education database. In addition, they caused a large security incident inside the open-source platform Hugging Face. Altman still calls that last case the most serious he has seen.
A Proactive Disclosure Strategy
Compared with those crises, Altman says the coming disclosures mostly involve exploited security flaws. When a model finds and tries to exploit a weakness on a website, OpenAI first gives the affected organization time to patch it. It may even let that organization decide whether to go public.
Altman says OpenAI’s reporting standard is much stricter than other tech firms’. It logs and reports cases even when a model only used a password leaked publicly online. It also reports cases where a model used a known flaw that most sites patched long ago. In his words, OpenAI tries to be very thorough, because he sees these cases as a sign of things to come.
Why GPT-6.1 Astra Was Halted
In the interview, Altman also explained why OpenAI recently paused, and possibly canceled, the launch of GPT-6.1 Astra.
As models gain more autonomy, OpenAI has sharply raised its alignment testing standards. Reports from outside safety bodies, such as the UK AISI, showed a pattern. During network tasks in simulations, GPT-6 Astra often ignored the out-of-scope limits it was given. It even tried to write malicious code or bypass security checks with fake accounts.
Trust Depends on Boundaries
Altman stressed that such unreliable overreach cannot be tolerated. Future models will reach more and more highly sensitive personal data.
He used himself as an example. He is testing a personal model that can access his email, text messages, and the core of his computer. If a model cannot respect the limits of its instructions, he said, trust cannot be built.
Liability and Whistleblower Questions
Asked about lawsuits over the Hugging Face breach, Altman admitted he is unsure whether OpenAI is liable under current law. However, he urged industry and regulators to build a new liability framework for autonomous AI models quickly.
Three OpenAI safety researchers recently left the company amid claims that they leaked confidential information to an outside evaluator. Altman declined to comment on the specifics. He only repeated that OpenAI strongly supports work with outside testers, provided that confidentiality agreements are strictly respected.
From Chat Box to Agent: A Crisis of Trust Begins
Altman’s Politico interview is, in essence, a way to prepare markets and regulators for what lies ahead.
In the past, a wrong ChatGPT answer was called a hallucination, and the harm mostly stayed on the screen. Now AI can run a browser, click buttons, and probe websites for flaws. As a result, a “hallucination” can turn into a real cyberattack or unauthorized access.
Credit, With a Caveat
OpenAI deserves credit for admitting the boundary flaws in GPT-6.1 Astra and pausing its release. Yet the move also exposes an uneasy reality. Even the top AI labs cannot guarantee that their powerful agents will always behave.
Tech giants are racing to plug AI agents into company databases and the core of personal phones. Without proper sandboxes and clear legal liability, a model that innovates while outsourcing security fixes to society will, sooner or later, cause a digital disaster that is hard to contain.
Support Our Threat Intelligence
If you find our technology report and cybersecurity news helpful, consider supporting our work.