> the breach took place on 18 June - Open AI informed the government with an email to a general address on 10 September
So we have a company hacking a foreign government's websites and data. And, in terms of ethics, they take almost three months to notify; and in terms of competence, appear to have no formal contacts nor to have found one in that time.
Once an American business starts hacking allied governments, it's time for strict responses, yes? Replace the governance (board and C-level)? Remove financial incentives and open the company - open weights, open training, per its original 'open' ethos?
Altman is busy saying there needs to be regulation, but in terms of what OpenAI does, he can control that already.
In the infosec community it is well known that OpenAI and Anthropic did not hire many security engineers or researchers pre-April 2026. There is likely a case for gross negligence (IANAL).
There has been a crazy hiring push from both companies to poach security engineers/researchers from Google, Apple, and Meta since Q2/Q3, but the response was incredibly delayed. Many talented security engineers/researchers I know at Apple/Google/Meta (including myself) receiving these offers are worried about taking them due to the risks of criminal/personal liability and the more likely risk of tarnishing their careers.
Not a lawyer and this is not legal advice, but I did ask my lawyer about the potential personal risks after receiving an offer. I used that as a data point when I declined the offer.
On this, I go with the recent words of Jensen Huang [1]...we already have legal laws in computer criminality, so before AI vendors ask for more regulations, lets apply the existing laws ;-)
I think Lina Khan said this first about AI companies and I agree with them both. Companies already have an obligation to make safe products and not commit crimes
Well that's just it: we don't seem to apply laws in meaningful ways anymore.
Part of that is by design. The entire point of incorporating a business is to separate it as a legal entity from you, the person who owns/runs it.
Unless you can point to someone at OpenAI intentionally using their software to hack the Australian government's website, the best you can do is have some drawn-out proceeding where you charge OpenAI, the corporation, with some sort of crime, convict them (of what I don't know, IANAL) and fine them. Hopefully the fine is 1) large and 2) sticks through the appeals process.
There's no real mechanism to legally punish the likes of Altman and his c-suite over this.
It's particularly bad because OAI is a us dept of war contractor engaging in hacking of allied government systems.
Imagine if any of the name brand military contractors were caught wiretapping an ally? Or launching a weapon? Would not look good at all.
I imagine this will be treated without recourse like usual because the entire economy relies on this company and 1 other succeeding at all costs. But, wars have started over less...
> Altman is busy saying there needs to be regulation, but in terms of what OpenAI does, he can control that already.
It is still my belief that Altman wants one or ideally more governments to shut down or slow down OpenAI. OpenAI is going to need more cash to survive and Altman has run out of plausible lies. Having the AI breaks pulled by governments is basically the last chance to explain why they still aren't going to be profitable, and why they just need that next X billion dollars investment.
I don't for a second believe that an agent starts trying to hack backend system, when the form or API it has been asked to use isn't working.
> I don't for a second believe that an agent starts trying to hack backend system, when the form or API it has been asked to use isn't working.
I have seen coding agents on my own machine (in sandboxed VMs) start doing things while trying to accomplish what I've asked that I felt sort of exceeded my mandate (changing database passwords, poking at the egress proxy that's preventing them from accessing some domains). Not to the point of causing any real issues, but I don't have much trouble envisioning scenarios like this when using stronger instructions around pursuing the goal + a running in a misconfigured sandbox envrionment.
That said, there's a lot of potential upside for American AI labs if they're able to get people scared about AI, they can:
- To your point, claim the regulations slowed them down and paper over near/mid term financial concerns
- Get the government to create stupid regulations that don't actually slow them down at all, but do effectively lock out any future competition (and current global competition)
- Position themselves as the only organizations blessed by the government with the ability to make safe AI, therefore eventually allowing them to claim to be some flavor of "too big to fail" and worthy of a bailout, should the financials not work out.
- Effectively create a distraction that avoids further public conversation/accountability/regulation/liability re the more tangible sorts of problems their products cause right now.
I'll never understand the "slow down AI" idea. Other countries simply won't slow down, why would they? Maybe a couple Western countries would but no one else will give a shit about that plea, nor should they.
> And, in terms of ethics, they take almost three months to notify;
Kinda worse than that. It took between 10 and 40 days, not 3 months, between the organisation knowing and the reporting.
August (precise date unknown) – OpenAI said it became aware of a potential breach during a broader review of "misaligned model activity"
10 September – An email from OpenAI lands in the public inbox of Services Australia, the general services hub of the federal government, informing of the incident
Given it was the AI agents which did the hacking, doing this will result in basically every organisation at least as rich as the government of Tuvalu being able to hack anyone at any time.
> Altman is busy saying there needs to be regulation, but in terms of what OpenAI does, he can control that already.
Him having control would be an improvement on the reality.
This was a just case of: (owner of the agents detected the hack) && !(hacked party didn’t detect the hack) && (owner of the agents decided to notice the other party) && (they decided to went public with what happened so we know it)
One can find many other logical combinations that we can’t possibly know about such incidents.
So, you're telling me they didn't have any monitoring in place around their AI to notify them of an attempt at breaching a system they have no business visiting in the first place? OpenAI should be blackholed on this basis until they clean up their act.
They must have had monitoring in order to be able to detect this retrospectively.
Any automated alarms for detecting things in real-time were not sufficient.
Given a previous generation of agents discovered a zero-day and used it to get around attempts to sandbox them into one specific test, this is not hugely surprising, but it is a reason to force them (and everyone else) to stop until security catches up with capabilities.
I'm thinking of the Jurassic Park novel: they had sensors to count the dinosaurs, but the test was made under the assumption escapes were possible and breeding was not, i.e. something like "if (dinosaurs_found < n) then escape_alert();". They didn't know dinosaurs_found >> n until everything was already going wrong.
NotE how he was found guilty by the 2nd court for something more 'subjective' than 'objective' : for having confessed that he later found an authentication page that had failed to protect the documents.
How can you make a swarm of agents "feel guilty" ?
The word "found" is different from the word "feel"; I'm not sure why you involved feelings at all: Bluetouff was sentenced because he admitted he had seen evidence the documents were supposed to be restricted but chose to publish parts of them anyway.
If you go into someones garden an copy their work, it does make a big difference if you admit to seeing the sign saying "private property, keep out".
Because in other circumstances, a hacker might have decided to stop there, and not only not publish, but instead warn the website about their security flaw.
Especially after Bluetouff was found guilty.
In fact, I expect this to have happened many times, but "hacker did the right thing" is much less likely to make headlines.
Meanwhile, agent swarms seem to be (mostly ?) incapable of having this kind of moral compass, at least for now. (And OpenAI isn't doing much better, cough.)
> How can you make a swarm of agents "feel guilty" ?
"Feel" is a whole philosophical can of worms. Nobody knows what it means mechanistically for an arbitrary system (including other biological systems) to "feel" anything, let alone abstract concepts like guilt, all we can do is observe behaviours. If current systems can feel anything at all, it's by accident, but we have no test for it so we don't know if that accident has even happened or not.
Weirdly, for the Hugging Face incident, we do know they wrote down that it was bad and they shouldn't do it, even though they then continued to do it.
So: they acted like they felt guilty. And yet also acted like were compelled (by previous training?) to weigh "complete instructions" more than "don't do crime". We can adjust that, make "don't do crime" take precedence over "follow instructions"*; it's unfortunate that when we do for any specific model, there's immediately a horde of people complaining the model has been "censored" or "lobotomised".
(Different people, I hope. Goomba fallacy and all that).
* Though this may cause issues when going between jurisdictions. But hey, a discussion about sovereign compute is for another time, after we can agree to make "don't break the law" more important.
Unfortunately, "don't break the law" would also be a very effective way to use AI to construct an AI-enforced dictatorship, so we can't just throw that in blindly.
> Him having control would be an improvement on the reality.
Oh, he does. It's unlikely that this is some AGI that spawned itself out of nothing and started doing this. If he were a decent person, he'd simply find a way to investigate this internally, fire the people responsible, and find a way to set up guardrails around his product.
The problem is, like most people in SV, Altman seems to have a twisted ethical compass. He doesn't see these incidents as an issue, he sees them as an opportunity. He has both the thing a bunch of Western governments want (a superhacker agent that can do dirty work) and a crisis that can be used to craft regulations that favor OpenAI and thus his bank account.
I think the Australians have a good PR team. The whole story has been framed globally as AI bad, we’ve been attacked etc.
Nobody seems to be talking about the web server and sw being deployed was insecure.
Agreed that there should be real consequences, but I'm less convinced that "open the company - open weights, open training, per its original 'open' ethos" would be the right answer. That gets us into the kind of libertarian utopia where everyone is allegedly safer because everybody is well-armed... which usually doesn't work out so well in practice.
The alternative to "open weights" at this point is "American controlled."
And Dario and Sam have already made it clear that it's America First.
The rest of the world isn't going to accept a regulatory regime which imposes American hegemony. Maybe when Silicon Valley was playing all utopian like they used to. Not now.
Open weights is the most reasonable counter-power we have.
"The world should trust that we are going to do the right thing because it's the right thing and we feel the magnitude of this," Sam Altman said
Clarification: "The world should trust that we are going to do the right thing because trusting that we are going to do the right thing is the right thing and we feel the magnitude of this, what with our IPO round the corner, and all"
Yes, especially the concern they could accidentally boot XP from their Linux box, and vice versa - I laughed. But also the technical solution, placing it one way up and then another with a tilt sensor, is really advanced.
> I don’t mind if you want a custom look and feel for your application
This is why I like Delphi / C++Builder's theming. It's standard UI controls -- so you get stuff like the scrollbar menu Raymond mentions -- but you can make it look custom if you want. Same behaviour, different rendering.
In my experience many execs know what they're talking about.
Where I feel you may see real variance is ethical and capability standards: willingness to stick to a line, and competence in analysis and execution based on what is known. Sometimes, hidden agendas can be misread as lack of competence, ie ethical lapses cause actions that are misread as capability lapses.
Knowledge alone is less often a factor.
Of course this varies widely across companies. I've been fortunate to work with some excellent folk at executive and C-level.
Here, an exec clearly (a) understands or can make a clear, direct assessment and (b) was willing to do so in writing. Kudos on both grounds.
I think a different variant/opposite of Hanlon's razor applies when it comes to corporate or political decisions: Don't attribute to stupidity when it can be adequately explained by malice or greed.
This sounds rather obvious, but I feel people forget it far too often.
> Models may perform better with other harnesses than with their own. So it turns out that your Claude models may not need Claude Code…
This is interesting. We built our own harness (CodeBot, an agent for Delphi) and it currently uses OpenAI models; we tuned it for specific behaviours and patterns and I find its behaviour better than Codex. Same models underneath.
1. Letters That Produced Miraculous Results - cut because correspondence norms had massively changed between 1936 and 1981
2. Seven Rules for Making Your Home Life Happier - cut because its 1930s-era perspectives on marriage and domestic life didn't age that well
Personally, I think some of the edits in the remaining sections are more controversial than the removal of those two sections. I think the revision lost quite a bit of Dale's charm and just felt a bit less idiosyncratic in a bad way.
Something fascinating that you may not know: traditional architecture is one of those things that is simultaneously:
a) Genuinely widely preferred, with many articles on this, ranging from aesthetic preferences through to scientific studies of how eyes move and what causes fatigue. There is genuine value to architecture before modern architecture -- and...
b) A stalking horse for right-wing thinking.
It's really interesting how this happens and it mirrors other right-wing techniques. A common way to get people into right-wing thinking is to find something that is genuinely unpopular or that people have concerns about, yet which has constrained discourse. Examples: lower incomes. You then talk about the good old days, and reframe it: lower incomes becomes, 'people taking your income, agh those immigrants'. Architecture becomes, '1940 and before were better, oh and everyone was white then'. You get the idea.
Another popular one on social media is the Greek and classical world, especially its comparative lack in modern education compared to, say, 1900. That's an easy intro to colonialism and racism, disguised in the neutral or even interesting format of ancient history.
Once you recognise this, you see it everywhere.
But don't let this fool you re older architecture having genuine value. We just have to avoid saying people have no taste, or referring to their preferences as 'pabulum'. That is condescending, makes normal people feel unheard, and then when someone does hear them on the innocuous subject of architecture, they pay attention to what else that person says.
Very well put. I've also heard it said like this, "abusing the truth is the easiest way to lie".
The pattern is 1. take something that's true then 2. use it to imply the Truth. Step 3. is if anyone doubts 2, challenge them to disprove 1. Even if you don't deny that 1 is true and just challenging that 2 doesn't follow from 1, the waters have already been muddied in the eyes of many onlookers.
It's silly that this works but there's so much over-communication now that simplicity is very effective. People often repeat the fallacies verbatim too.
I might object that being right-wing, or having fear of the effects of immigrants even, does not necessarily entail racism. But it would be more interesting to say that they are related, and that valuable ideas about nice traditional architecture and nostalgia for the good old days are also genuinely related to racism and colonialism and fascism, which means that there's something of value to extract from all that garbage before you can do a clean separation of the ideas. Mercifully I don't have time to write this comment right now, but it was probably going to include the word "culture" in several places.
> The people who did feel unheard learned to not respond
When politics exclude a group, or a group feels excluded, it's easy to lure the group into supporting anti-politics, which is a nice way to say "fascism".
This is kind of where we are now, with the far-right preying on the most vulnerable people that feel ignored by politicians.
So? Many people (not all) are right-wing because they want to preserve beauty. Being a right-wing is not a rare thing, it's the second most popular belief system in the West.
>Another popular one on social media is the Greek and classical world, especially its comparative lack in modern education compared to, say, 1900. That's an easy intro to colonialism and racism
Racism is much less of a thing in Europe, compared to the USA, yet fascination with Antiquity is just the same or even higher.
I remembered the 1967 Outer Space Treaty as preventing militarisation of space. It turns out, not wholly. Celestial bodies (the moon, asteroids, etc) are out of bounds completely and are only for 'peaceful purposes'. For space itself, the ban is on WMDs, like nuclear weapons, in space anywhere.[0]
But the US has maintained a polite fiction that space is not weaponised/militarised. This is a break from that. The wording[1],
> The United States now has on-orbit space control weapons capable of defending the joint force against hostile adversary action.
is stated as 'That phrase was very well thought out.'. It looks like they're positioning it as purely defensive.
Which is allowed but being open about it legitimises the concept of weapons in space. It's worrying, and potentially destabilising. I expect they mean it as a deterrent but I frankly this it's irresponsible in that it invites an open presence from other countries too.
It's something an LLM would never be able to come up with because it requires a depth of experience that LLMs just don't have. It's authentically human.
So we have a company hacking a foreign government's websites and data. And, in terms of ethics, they take almost three months to notify; and in terms of competence, appear to have no formal contacts nor to have found one in that time.
Once an American business starts hacking allied governments, it's time for strict responses, yes? Replace the governance (board and C-level)? Remove financial incentives and open the company - open weights, open training, per its original 'open' ethos?
Altman is busy saying there needs to be regulation, but in terms of what OpenAI does, he can control that already.
reply