Gary Marcus and security engineer Niels Provos: frontier labs aren't doing security competently

GaryMarcus · x · 2026-09-11

Gary Marcus doubled down on his criticism of frontier AI labs' security, arguing that doom discourse distracts from the fact that labs like OpenAI aren't handling security competently.

He quotes veteran security engineer Niels Provos: no matter how capable a model becomes, it holds no authority over inference, networks, credentials, or physical infrastructure — those remain external control points. Labs are good at detecting distillation attacks but lack matching incentives to prevent infrastructure misuse. Security-engineering commentators say the exploit route behind the Hugging Face incident should make people "absolutely livid."

The core argument: infrastructure controls are the overlooked piece in loss-of-risk debates.

Related event: Gary Marcus Cites Veteran Engineer: Frontier Labs' Security Falls Short(2 posts)→

Original post →

More from Companies & People

Companies & People channel →