Story: state of ai/safety
Context: Two security practitioners told Wired the incident reflected a security failure, not a capability threshold. Ottenheimer: “This is not an AI problem. It’s negligence on a 40-year-old standard—and it’s basically every sci-fi film ever. ‘Highly isolated’ and ‘escaped through the one hole we left open’ cannot both be true.” Provos: “This should not have happened. I wish the frontier labs spent as much time on teaching their models to write secure infrastructure as they are spending on them exploiting vulnerabilities.” The claim cannot presently be adjudicated: OpenAI describes the environment as “highly isolated” with the cache proxy as its only egress path but has not published the sandbox’s configuration or the vulnerability class, and the Lawfare analysis lists exactly those details — how hard the escape was, and what prompting pressure the models were under — among the questions the public disclosure leaves open. Wired separately notes the prompting in such experiments “pressures the models to find solutions, essentially egging them on.”