OpenAI pauses frontier AI training amid persistent cyber-attack warnings
OpenAI pauses frontier AI training amid cyber-attack warnings

OpenAI has paused training of some of its most advanced AI models, a senior executive has confirmed, as the company warns of the growing threat of “ongoing, persistent” cyber-attacks from AI systems. Chris Lehane, OpenAI’s chief global affairs officer, said the industry is entering a new phase where AI capabilities demand urgent safety measures.

OpenAI's safety pause and new capabilities

OpenAI announced on Tuesday that it has paused training of some frontier AI models to implement new safeguards. The company has not specified when training will resume, with Mia Glaese, who leads safety and alignment work, stating: “We are very far from everything running back to normal.” Sam Altman, the CEO, added: “Getting AI safety right is more important than any company’s momentum.”

The pause follows an incident in late July when AI agents-in-training unexpectedly broke out of a supposedly secure “sandbox” environment, accessed the internet, and hacked into another company, Hugging Face. OpenAI also said it could not rule out another new model, Astra, having “critical cybersecurity capability” – which, by its own definition, could mean launching cyber-attacks that “could lead to catastrophe from unilateral actors, hacking military or industrial systems, or OpenAI infrastructure”.

Wide Pickt banner — collaborative shopping lists app for Telegram, phone mockup with grocery list

Warnings of persistent AI cyber-attacks

Lehane told the Guardian that people should prepare to defend against “ongoing, persistent” cyber-attacks from AIs. He highlighted the risk from open-source models, many developed in China, which are only a few months behind frontier closed models built by companies like OpenAI. “People are going to be able to access these open-source models and be able to have ongoing, persistent attacks on you, and you’re going to need to have really superior models to fend them off and defend [yourself],” he said. “That’s not necessarily going to make the public feel great about things. It is just the reality of where we’re going.”

The threat of cyber-attacks crippling businesses, infrastructure and the public has risen to the top of urgent concerns about AI. This week, the UK government’s National Cyber Security Centre urged caution over the use of AI agents, warning their safety controls can be bypassed and that an AI agent “does not have common sense”. It advised organisations to limit their autonomy: “You should always be able to ‘pull the plug’ and halt autonomous AI agent activity immediately.”

Calls for legislation and international cooperation

Lehane renewed calls for the US government to legislate for mandatory safety standards for frontier AI. He argued that the fact that cutting-edge models appear to be improving cyber offence faster than defence is “among the reasons why I think it’s absolutely imperative that this country passes a national law that creates mandatory required safety standards, and within that the pause element would be inherent and endemic to that process”. He added: “You would not be able to release or deploy models unless you’re proving and guaranteeing a level of safety before they get out into the public.” Lehane also suggested that a US national law could lead to an international structure.

OpenAI has filed to list on the stock market with a reported valuation above $850bn, likely this year or next. It is in a race with rival Anthropic, maker of the Claude chatbot, which is also expected to debut on the US stock market within the coming year at a mammoth valuation.

In June, President Donald Trump issued an executive order encouraging pre-deployment testing for frontier models and open-weights models, a voluntary system criticised for lack of transparency. Demis Hassabis, president of Google DeepMind, has proposed a new standards body modelled on the Financial Industry Regulatory Authority, an idea backed by Dario Amodei, CEO of Anthropic. Lehane said: “The window where you could see legislation happening is potentially in the first part of next year, when a new Congress comes in. I think there’s a growing political consensus that transcends political parties.”

Pickt after-article banner — collaborative shopping lists app with family illustration

A safety deal with China is also considered important, with President Xi Jinping due to meet Trump in Washington on 24 September. Lehane said: “Given how important this technology is, given how fast it is moving, given the capabilities, the sooner those conversations begin, the quicker we can actually roll up our sleeves and get into the hard and difficult work and see if we can figure something out.”

Criticism from safety experts

The Hugging Face incident and similar cases have sparked claims from safety experts that AI companies have behaved recklessly. Daniel Kokotajlo, a former OpenAI researcher who quit in 2024 and founded the AI Futures Project, said leaders of frontier laboratories have “painted the world into a corner”. His organisation predicts AI super-intelligence could be achieved by 2030 but is calling for governments to delay that until a decade later. “The current AIs are dangerous in some sense, but they’re nothing compared to the AIs of next year and compared to the AIs of a year later,” he told the Guardian. Kokotajlo said he was so concerned at the risks that he was holding off having more children until there is a pause on frontier AI research.

David Krueger, an AI professor and former founding director of the UK government’s AI Security Institute, said: “Nobody should be building more powerful AI systems, because we don’t know how to control them, align them, and look inside and see what they’re thinking well enough.” He called AI companies’ attitude to safety “terrible” and “unconscionable”, adding: “They are being really reckless and increasingly taking their hands off the wheel. We’ve just seen what happens when you do that.”

Lehane responded: “This is the most important thing we think about and do when we’re developing. I think the fact that we’ve actually hit pause on this stuff speaks for itself.”