Experts blast OpenAI, Microsoft for basic AI security failures
On September 2, Oxford researcher Anders Sandberg fired off a series of posts blasting OpenAI and Microsoft for violating the most basic cyber hygiene in AI deployment: models that "obviously shouldn't be connected to the internet" were connected, sandboxes that "obviously should be real sandboxes" weren't, and chain-of-thought that should never have leaked did. He also noted that the cybersecurity posture of major AI companies and AI safety institutes looks seriously compromised, with problems rooted not just technically but institutionally.
Confirmed
- Sandberg said the AI and cybersecurity expert group he sits on at the Royal Swedish Academy of Engineering Sciences is loudly urging all organizations to "immediately take the obvious protective measures," stressing that basic security is paramount
- Responding to skeptics, he said he isn't a cybersecurity expert himself, but the foolish cybersecurity incidents theorists predicted in the 2000s are playing out exactly as sketched — or worse — back then people were told "no one would be that stupid"
- He also mocked Oxford University's mandatory cybersecurity training as box-ticking and foolish
- Security practitioner Daniel Card echoed him the same day, pointing out that outsiders call AI a "digital nuke" while deploying it like a toy; the problem is the industry's obsession with model capabilities far exceeds its attention to containers, organizational governance, and security management
Why it matters
- Both viewpoints point to a structural risk: AI safety discussions over-focus on the model itself, while "boring fundamentals" like deployment environments, sandbox isolation, and organizational governance are systematically neglected
- The Swedish engineering academy expert group's statement signals that this critique has entered the formal agenda of engineering academic institutions
2026-09-02 ~ 2026-09-02 · 5 related posts
Primary sources
- Security Expert Slams OpenAI and Microsoft for Basic Safety Failures — anderssandberg ·
- Major AI companies and institutes have broken cybersecurity, expert claims — anderssandberg ·
- Swedish Engineering Academy expert mocks cyber awareness training but urges basic security — anderssandberg · 2026-09-02
- [source] Major AI companies and institutes have broken cybersecurity, expert claims — anderssandberg · 2026-09-02
- Expert: Stupid security scenarios predicted in the 2000s are now happening — anderssandberg · 2026-09-02
- Security pros slam AI industry for obsessing over models, not governance — UK_Daniel_Card · 2026-09-02
- [source] Security Expert Slams OpenAI and Microsoft for Basic Safety Failures — anderssandberg · 2026-09-02