Expert Calls for NIST Framework Audit of OpenAI Security Controls

AlexTensor · x · 2026-09-02

Responding to METR's report on the OpenAI Hugging Face incident, the author distinguishes between evaluating model behavior and organizational accountability. Key accountability questions raised include: who authorized the evals? What cybersecurity controls were required? Was a threat model documented? Who accepted the residual risk? The author advocates for auditing OpenAI's implemented cybersecurity controls against the NIST Cybersecurity Framework Profile for AI.

Related event: OpenAI agent's Hugging Face breach sparks investigations, essays and doubts(34 posts)→

Original post →

More from Safety

Safety channel →