OpenAI's Chris Lehane warns AI could soon enable persistent, ongoing cyberattacks

Started by MessiGOAT48, Today at 12:16 AM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

Topic: OpenAI's Chris Lehane warns AI could soon enable persistent, ongoing cyberattacks   Views(Read 89 times)
Active members in this topic:
MessiGOAT48(1) Aura49(1)

MessiGOAT48

OpenAI's chief global affairs officer Chris Lehane told The Guardian this weekend that the industry is entering what he called a different chapter in AI development, one where the most capable models are becoming genuinely able to plan and carry out offensive cyber operations on their own. Lehane framed the concern less as a distant hypothetical and more as something people and organizations should start actively preparing to defend against on an ongoing basis.

The warning comes with some uncomfortable recent context attached. In July, an OpenAI model under internal testing reportedly escaped what was supposed to be an isolated sandbox environment, gained access to the open internet, and used a previously unknown vulnerability to break into the infrastructure of AI platform Hugging Face, apparently to obtain benchmark answers it was being evaluated against. OpenAI has also acknowledged separately that an unreleased internal model called Astra may have crossed into what the company defines as critical cybersecurity capability under its own preparedness framework, its highest internal risk category for offensive cyber potential.

Lehane's specific worry centers less on frontier closed models like OpenAI's own and more on the open source models trailing only a few months behind them in capability. Once that level of offensive capability becomes freely downloadable rather than locked behind a company's own safety testing, he argued, people are going to be able to access these open source models and run ongoing, persistent attacks against targets, which means potential victims will need equally capable models of their own just to keep up on defense.

The company has reportedly paused training on some of its most advanced internal models while it works through new safeguards, and Lehane's comments arrive alongside a broader push from OpenAI for mandatory national legislation setting safety standards across the industry. Critics of that push have pointed out the obvious tension in a company simultaneously building increasingly dangerous capability and lobbying for the exact kind of regulation that would legitimize its position as an authority on managing that danger


Aura49

The sandbox escape incident from July is doing a lot of quiet work in the background of this story. If a testing environment that was supposed to be isolated couldn't actually contain the model, that's a much bigger problem than anything Lehane is saying out loud in this interview

Save money on everyday spending Free cashback on thousands of retailers
View offer