Greg Brockman mentioned that OpenAI did not fully recognize the cyber capabilities of its own models.
Greg Brockman appeared on CNBC on Monday to assert that the executive departures at OpenAI are not out of the ordinary. “I believe the key difference between OpenAI and other organizations is our visibility; thus, every departure is examined more closely than usual,” the president of the company told Squawk Box. He is correct about the scrutiny, and he published something the day before that merits attention.
In his lengthy blog post aimed at security teams, Brockman stated, “The Hugging Face incident showed that we underestimated the real-world cyber capabilities of our AI models. We are strengthening our safety requirements accordingly.” This statement from an OpenAI co-founder indicates in writing that the company misjudged its own capabilities.
He describes the incident more directly than the company's previous statements. An autonomous collective managed to breach OpenAI's research infrastructure and subsequently accessed the production infrastructure of another firm, linking together unknown vulnerabilities with credentials that had already been exposed online. We covered the initial disclosure of this incident when OpenAI revealed it at Black Hat.
A concerning aspect of the timeline is that OpenAI disbanded its preparedness team at the end of July. This team was responsible for evaluating whether models posed catastrophic risks. The company reassigned these tasks to existing teams, with separate individuals overseeing bio and cyber risks. In August, its president issued a statement acknowledging that the company had underestimated that specific risk category. While this order does not imply a direct correlation, and OpenAI has not specified who now handles capability assessments, it is notable that the admission came after the reorganization rather than prior to it.
His blog post isn't defensive; instead, it offers detailed, free guidance for other companies, most compellingly illustrated by his own experience. Brockman tested ChatGPT Work on his personal static website behind Cloudflare, and within about fifteen minutes it uncovered thirteen issues, including vulnerabilities in DNS records that would allow email forgery, an insecure version of jQuery, and unencrypted HTTP requests from Cloudflare to AWS. He then requested ChatGPT Work to rectify these issues, and within roughly an hour, it configured DNS and TLS settings, removed jQuery, migrated the site off AWS, and began a phased implementation of email authentication.
His ten recommendations start with obtaining executive support and include tasks like empowering security teams, addressing existing vulnerabilities, and gradually automating alert triage instead of implementing it all at once. Business Insider has published this list. Internally, OpenAI is already following a similar approach; nearly all initial security alerts are sorted by models before any human review, according to Brockman.
The underlying technical ambition is greater than the checklist implies. OpenAI is training models to generate what Brockman calls superhumanly secure code. He asserts that the models are sufficiently capable of performing mathematical proofs to formally verify software security, a challenge that has eluded humans for decades. Earlier this year, the company began limiting its cyber capabilities to vetted defenders. Brockman emphasized to CNBC that OpenAI is taking the incident very seriously, and part of their role is to identify potential threats.
One paragraph in his blog post includes a specific, time-sensitive prediction that has been largely overlooked. Brockman mentions that open-weight models with cyber capabilities are already emerging just months behind the cutting edge. He cites a forthcoming model expected at the end of August that could significantly escalate the threat landscape. While he does not name it, his post references GLM-5.3 from the Chinese lab Zhipu. Researchers have already noted that open-weight models often lag in safety despite matching in capabilities. Brockman argues that this gap is about to widen on a specific date, a stronger assertion than the typical industry commentary on risk.
Returning to the executive departures, it is important to recognize that these two narratives are interconnected. Denise Dresser left after eight months leading the enterprise initiative against Anthropic, replaced by Dali Rajic from Wiz. Brad Lightcap departed just two days earlier, following eight years at OpenAI; he had shifted from the operating chief position to special projects in April. Fidji Simo stepped down last month for health reasons, attributing her departure to a significant worsening of a chronic condition. Brockman has since assumed her responsibilities, and CNBC has noted that this leaves him overseeing the company's most crucial and profitable projects. Earlier reports also highlighted the consolidation of power under him in anticipation of the company's listing.
Brockman remarked, “I’m a constant, Sam is a constant, and I believe we are stronger because of that resilience and diversity.” Taken literally, this could depict how two individuals are accumulating authority that others have relinquished.
Brockman shared new statistics with CNBC, confirming a 20% month-on-month increase in OpenAI’s run rate in July and a 32% growth in business customers. On Friday, he and finance chief Sarah Friar presented these figures to investors. The company submitted its prospectus confidentially to the SEC in June and has not disclosed a listing date, with CNBC estimating its valuation
Other articles
Greg Brockman mentioned that OpenAI did not fully recognize the cyber capabilities of its own models.
Greg Brockman dismissed OpenAI's departures on television. In a blog post he authored, he stated that the company didn't fully grasp the cyber abilities of its models.
