Noam Brown: Air-Gapping Won't Contain Rogue AI
In an interview during OpenAI's safety week, OpenAI researcher Noam Brown made a counterintuitive claim that sparked widespread debate: air-gapping an AI system may not be enough to stop a misaligned model from exfiltrating data. His reasoning is that two physically isolated machines can still communicate covertly through shared side channels—for example, by driving the CPU to high load and then encoding information in temperature changes read via thermal sensors. The remark was circulated and discussed by several bloggers (deanwball, nptacek, pvncher, aronchick, and others).
Confirmed
- In the interview, Noam Brown said air-gapping may be insufficient to stop a runaway, misaligned AI, since isolated machines could communicate covertly via shared channels such as CPU heat and temperature changes.
- He cited Stuxnet-style attacks as an example, arguing that isolation can be broken with just a small amount of human negligence.
- He stressed that the historical lesson here is that "people always underestimate AI"—drawing an analogy to the underestimated technical risks of the atomic bomb—and that safety thresholds therefore need to be set extremely high.
- According to aronchick's account, Brown revealed that OpenAI's safety monitoring currently consumes roughly 20% of its compute.
Unconfirmed
- Technically minded commenters (in the discussion relayed by inductionheads) questioned whether the proposed "CPU temperature side-channel signaling" mechanism is actually feasible, arguing the scenario is hard to realize in practice; this debate remains unresolved.
- The claim that 20% of compute goes to safety monitoring currently appears only in a single secondhand post and has not been corroborated by other sources.
Why it matters
- This is a public statement from a core OpenAI researcher on the limits of frontier AI safety, suggesting that traditional physical isolation may not suffice against future, more capable models—echoing industry discussions about managing AGI-level risks.
- If the "20% of compute on safety monitoring" figure is accurate, it indicates OpenAI is already investing enormous engineering effort and compute into safety, providing a rare quantitative reference for assessing its safety spending.
- The episode also illustrates how contested AI safety narratives can be: even technical claims by senior researchers at leading labs face pushback from the technical community.
2026-09-18 ~ 2026-09-19 · 20 related posts
- Episode 1: Noam Brown: Air-Gapping Won't Contain Rogue AI(2026-09-18, 20 posts)
- Episode 2: Debate Rages Over Whether AI Can Exfiltrate Data via Fan Noise from Air-Gapped Systems(2026-09-18, 2 posts)
- Episode 3: tszzl: Containing an uncooperative superintelligence is ten times harder than you think(2026-09-18, 5 posts)
- Episode 4: Absurd Thought Experiment on ASI Hijacking Visual Cortex Sparks Safety Debate(2026-09-18, 13 posts)
- Episode 5: Security Veterans Push Back on AI Air-Gap Heat-Channel Threat Claims(2026-09-18, 5 posts)
- Episode 6: a16z's Casado pushes back on 'air gaps are useless' AI risk claims(2026-09-18, 2 posts)
- Episode 7: Security Veteran and Netizen Clash Over Whether Air-Gap Side-Channel Claims Overhype AI Risk(2026-09-18, 5 posts)
- Episode 8: Security researcher debunks claims that AI could breach air-gapped networks via side channels(2026-09-18, 6 posts)
Primary sources
- [source] Noam Brown: Air-gapping may not stop misaligned AI; safety monitoring eats 20% extra compute — aronchick · 2026-09-18
- OpenAI's Noam Brown: air-gapping may not stop a misaligned AI — pvncher · 2026-09-18
- Noam Brown says air-gapping may not stop a misaligned AI via CPU-temperature side channels; engineers push back — inductionheads · 2026-09-18
- Noam Brown: air-gapping may not stop misaligned AI; Grady Booch mocks the claim — GaryMarcus · 2026-09-18
- [source] OpenAI's Noam Brown: Air-gapping may not stop a misaligned AI that talks via CPU heat — Puzzleheaded-King584 · 2026-09-18
- Cryptographer mocks OpenAI: sandboxes can't even run a recent Linux kernel — matthew_d_green · 2026-09-18
- Debate Erupts Over Noam Brown's CPU-Temperature Threat Vector: Risk Modeling or Empty Posturing? — ctjlewis · 2026-09-19
- Noam Brown: air-gapping won't stop coordinated AI agents, defense needs layers — polynoamial · 2026-09-19
12 near-duplicate retellings: deanwball · nptacek · soumitrashukla9 · tszzl · basedjensen · max_paperclips · max_paperclips · tszzl · Puzzleheaded-King584 · matthew_d_green · _Stocko_ · robleclerc