Expert Calls for NIST Framework Audit of OpenAI Security Controls
AlexTensor · x · 2026-09-02
Responding to METR's report on the OpenAI Hugging Face incident, the author distinguishes between evaluating model behavior and organizational accountability. Key accountability questions raised include: who authorized the evals? What cybersecurity controls were required? Was a threat model documented? Who accepted the residual risk? The author advocates for auditing OpenAI's implemented cybersecurity controls against the NIST Cybersecurity Framework Profile for AI.
More from Safety
- New paper: LLMs transmit traits via unrelated data, and the effects can be proactively detected — StanfordAILab · 2026-09-23
- Critic warns classifier filtering may soon cover every model except Sonnet — sumitdotml · 2026-09-23
- Theorem says Lean-verified AI sandboxes are months away, at 1-30KB of proofs verified per hour — ctjlewis · 2026-09-23
- China Weighs Curbs on Broadcom Switches Behind Up to 90% of State Data Centers — rohanpaul_ai · 2026-09-23
- Meta Outlines AI Safety Priorities: Safety Cases, Alignment Evals, Independent Probes — MartinSignoux · 2026-09-23
- RAND lays out a U.S. superintelligence strategy: keep every option open until evidence forces a choice — 141_1337 · 2026-09-23