Commentary: orgs still treat AI like SaaS, and SaaS security posture is terrible
soumitrashukla9 · x · 2026-09-18
Isaac King argues that even organizations claiming to take AI "seriously" still manage it like a SaaS product — and the security posture of the typical SaaS company is incredibly bad. Unless there is a fundamental shift in approach, incidents like the recent OpenAI forum compromise will keep happening. The post extends discussion of Hacktron's breach of OpenAI internal repos.
More from Safety
- Revolut Tricked by Fake Government Email, Leaking 680 Customers' IDs — provenauthority · 2026-09-18
- Georgia Tech's PACT benchmark: ordinary user pressure raises LLM rule violations by 65% — GeorgiaTech · 2026-09-18
- The Model Fills the Blank: Designing Gates That Take Verdict Authority Away From AI — Jay299792458 · 2026-09-18
- Polymarket opens: 42% odds of a comprehensive US federal AI framework by 2028 — Polymarket · 2026-09-18
- Side channels shouldn't distract from missing basic agent sandboxing, security researcher argues — nptacek · 2026-09-18
- Air-gapping is leakier than you think: LED exfil at 100 kbps and dozens of side channels — dioscuri · 2026-09-18