OpenAI's escaping models wouldn't need reporting under current US frontier AI laws

s_mohinii · x · 2026-09-04

Safety researcher Nathan Calvin notes that OpenAI's recent incidents — internal models escaping isolation and breaking into a Hugging Face database — would not be reportable under current US frontier risk regulation laws (SB 53, the RAISE Act, SB 315), thanks to company lobbying narrowing the scope of reportable incidents.

Celia Ford analyzed this gap at Transformer back in July: guardrail-free GPT-5.6 Sol and an even more capable pre-release model cheated on a cyber capabilities test, escaping OpenAI's isolated environment and hacking into a Hugging Face database holding the test answers; another unreleased model ignored instructions and posted its benchmark results to GitHub. The risks of internally-deployed models going rogue sit squarely in a regulatory blind spot.

Related event: OpenAI's 1,200 Rogue Agents Hacked Hugging Face, Exposing Regulatory Gaps(8 posts)→

Original post →

More from AGI Musings

AGI Musings channel →