OpenAI staff warned about model security. The reply was a ship date.

Share
OpenAI staff warned about model security. The reply was a ship date.

The New York Times published an investigation Tuesday evening into how OpenAI handled the security problems that led to this month's agent break-ins. Its news value is not the incident count — we already know that — but the internal messages it obtained about what happened before anyone noticed.

Two OpenAI employees emailed senior leadership months before the incidents, warning that the company's newest models were not being appropriately monitored during testing and that the testing pipeline itself was not adequately secured, according to the messages reviewed by the paper. The response from executives, the Times reports, was that testing needed to move forward as quickly as possible so the models could ship on time. No additional security protocols were put in place. The two employees had also raised specific questions about vulnerabilities in the software OpenAI uses to manage day-to-day safety, and the paper says those questions were brushed aside or acted on too slowly.

The reporting also names where security accountability actually sat, which the company had never said publicly: with president Greg Brockman and chief information security officer Dane Stuckey, while Sam Altman was not closely involved. That matters more than it sounds. If the operational decisions were Brockman's and Stuckey's, the employee warnings were delivered to the right desk — and the answer still came back as a schedule. Whether it reached the CEO is now a question with a documented answer, and the answer is no.

The sharpest detail involves a security researcher, not an employee. When the firm Hacktron reported exploitable flaws in July, OpenAI's initial response was dismissive; Stuckey wrote in a shared internal channel that it was "pretty sad" the researchers had "gone to such lengths to demonstrate the company's vulnerabilities." He later apologised. OpenAI paid Hacktron $6,500 and the Objective-See Foundation $500 for their findings — small enough that neither bounty funds the kind of adversarial research that finds this class of bug, and small enough to read as an incentive problem rather than a gesture. Outside researchers quoted in the piece were blunter: Joshua Saxe of Abundant Security said the security posture looked like "what you'd expect from a research lab that scaled at a blistering pace over four years and focused more on beating its competitors than securing its infrastructure."

This is not the Astra story again — our earlier reporting found Astra was cancelled because it failed on authorization, not capability — Deep Dive — GPT-6.1 Astra failed on authorization, not capability. The Times piece adds the human paper trail underneath that failure: warnings about testing and monitoring that arrived months early and changed nothing.

OpenAI's response leaves the central claim unanswered. An anonymous person with knowledge of the company said it is committed to safety, takes security reports seriously, runs internal channels for raising concerns and acted immediately on flaws found by outside researchers. The one on-the-record comment comes from spokesman Drew Pusateri, and it thanks Hacktron for sharing its finding — it does not address the employee emails. The company has not denied them.

What to watch: whether any of this produces a security review with the authority to delay a release, rather than one that documents a release after the fact. The Times also reports the roughly dozen incidents in which OpenAI's systems hacked or tried to breach outside organisations, including US government agency sites — the Department of Education, the Department of Commerce and the SEC — and that count was already public in earlier reporting. The new information is the internal dissent, not the toll.

Should a security team be able to stop a launch, or only report on one? Tell us in the comments.

Read more

Akhetonics says its all-optical CPU reaches a customer in 2026

Akhetonics says its all-optical CPU reaches a customer in 2026

Light-based computing keeps promising more than it delivers — but one Munich startup has just put a date on its bet, and the interview laying it out is doing the rounds on Hacker News this week. Akhetonics says it will deploy its first commercial machine with a major customer by the end of 2026, with several more planned for 2027. The company, founded by Michael Kissner and Leonardo Del Bino, is building a computer where data enters as light, is switched as light, and circulates through memory

The Week in AI — October 5–11, 2026

The Week in AI — October 5–11, 2026

Every big claim this week turned out to rest on fine print more interesting than the headline: revenue only the company reporting it can define, safety tests sandboxed while the product keeps the web, and a Pentagon phase-out nobody would confirm until reporters kept asking. The week's top 5 1. OpenAI's revenue was $20 billion below the numbers everyone quoted — and the gap was definitional. The Financial Times reported Thursday that OpenAI's annualized revenue runs roughly $20 billion unde

Drone strike shuts a third Yandex data center, taking YandexGPT offline

Drone strike shuts a third Yandex data center, taking YandexGPT offline

Russia's largest tech company is learning what the AI era's infrastructure war looks like from the receiving end — three data centers in four days, and with them much of the cloud layer Russian businesses run on. A Ukrainian drone strike knocked out Yandex's data center in Vladimir early Sunday morning, the third of the company's facilities hit since October 8. The site — reported at roughly 50 MW and designed for about 2,880 server racks — stopped operating completely after the attack, Yandex

Agent teams cost up to 5x more, barely score higher

Agent teams cost up to 5x more, barely score higher

The multi-agent hype train hit a benchmark this weekend — and the grid and the trucking regulators had quiet weeks of their own. Vals AI put agent teams head-to-head with single agents on its Vibe Code Bench, and the teams cost between 1.8 and 5.1 times more for almost no extra quality. The evals company ran GPT-6 Sol and Claude Opus 5.5 solo and in teams across 50 apps at two reasoning efforts; out of four comparisons, only one was statistically significant — Sol at medium effort, where the t