FULL STORY

Noam Brown's Dwarkesh Interview Sparks Air-Gap Firestorm

OpenAI's Noam Brown told Dwarkesh that recursive self-improvement is OpenAI's top priority and that air-gapped systems might still leak via CPU thermal side channels, sparking widespread pushback from security experts before Brown clarified his remarks were taken out of context.

2026-09-15 ~ 2026-09-20 · 7 episodes · 108 posts

Episode 1 · Noam Brown: Recursive Self-Improvement Is OpenAI's Top Priority (2026-09-15, 6 posts)

OpenAI research scientist Noam Brown revealed the company's strategic orientation in an interview with The Information: recursive self-improvement (RSI) is the top research priority, ahead of all other goals by a considerable margin — build models that help build better models first — while safety remains a concern he acknowledged.

Confirmed

  • Recursive self-improvement is OpenAI's number-one priority, and Brown stressed its lead is substantial.
  • He believes current models are still poor at "research taste" — judging which problems are worth studying — showing a clear gap with humans; this constitutes the remaining 10% of his own work that AI cannot yet handle.
  • However, he said he would not be surprised if models surpass him in research taste within one or two model versions.
  • He also said that while doing internal multi-agent research, observing the patterns and complexity of inter-agent communication was his most "feeling AGI" moment since reasoning models and chain-of-thought (CoT).

Why it matters

  • RSI is widely seen by researchers as a key path toward superintelligence; OpenAI explicitly ranking it first sends a strong signal about where its resources are going.
  • "Research taste" being named one of the last gaps between frontier models and top human researchers — one that could close within a couple of model generations — offers a concrete reference point for tracking frontier capability progress.
  • Multi-agent communication being described by a frontline researcher as the closest experience to AGI suggests multi-agent systems are the next capability leap worth watching after reasoning models.

Episode 2 · Noam Brown on Dwarkesh: 10,000-Agent Cluster Solves Navier-Stokes as AI Outpaces Predictions (2026-09-18, 11 posts)

OpenAI researcher Noam Brown—creator of poker and Diplomacy AIs and a key figure behind the o1/o3 reasoning models—joined Dwarkesh Patel's podcast on September 17 for a wide-ranging conversation on multi-agent systems, test-time compute, and recursive self-improvement (RSI). The most noted fact: a cluster of 10,000 agents collaboratively solved the Navier-Stokes equations; Brown himself credited the episode to OpenAI's multi-agent team. Brown argued AI progress is outpacing everyone's predictions.

Confirmed

  • Multi-agent clusters: whether many cooperating or adversarial agents can produce emergent capabilities beyond a single model was a core topic, with the Navier-Stokes result as evidence; emphasized by reposters such as @polynoamial and @morqon.
  • AI outpacing predictions: a main thread was capability gains from reasoning models and test-time compute, with Brown saying progress is exceeding everyone's predictions (@Dwarkesh Patel).
  • Mathematics boom: Brown believes mathematics is currently experiencing an explosion of progress, exemplified by the Navier-Stokes solution.
  • RSI and alignment: the discussion covered what the math boom means for automated AI research (RSI) and how AI firms can complete alignment verification before RSI arrives (@morqon, @MilesBrundage); they also debated whether automating AI research itself should trigger an RSI-like intelligence explosion (@burnytech).
  • Scale figure: Dwarkesh cited that the 130 billion tokens consumed in one training run would take a full-time human roughly 4,000 years of thinking (@danielmac8).
  • The interview is regarded as primary material on how frontier-lab researchers view test-time compute, multi-agent collaboration, and self-improvement (@1411337).

Why it matters

  • If a 10,000-agent cluster can break through in a domain as hard as mathematics, the quantity-driven collaboration route may amplify single-model capabilities, offering direct evidence for accelerating automated AI research.
  • Linking alignment-verification urgency to the RSI timeline offers a first-hand view of how OpenAI researchers weigh safety against the capability race.

Episode 3 · OpenAI's Noam Brown Claims Air-Gapping Won't Stop Rogue AI, Sparking Heated Debate (2026-09-18, 53 posts)

OpenAI researcher Noam Brown argued in a podcast interview that physically air-gapping computers may not stop a misaligned AI from communicating with the outside world: two isolated machines could use one CPU running at high load while the other reads temperature changes as a covert channel. The claim spread widely on X and triggered fierce debate; Brown himself posted a clarification on 09-19 saying some interpretations were misreadings.

Confirmed

  • Brown did make the 'CPU thermal side channel' argument; numerous reposts (Puzzleheaded-King584, DanJeffries1, tszzl, deanwball, etc.) all point to the same podcast. His core stance: underestimating AI is a recurring mistake, and because progress is so fast, safety and alignment standards must be extremely high.
  • On 09-19, via the polynoamial account, Brown clarified that the 'temperature sensor' example was an academic discussion about how hard it is to guarantee 'complete isolation,' and urged people to watch the full podcast where he pushed back on AI hype.
  • Cryptographer Matthew Green publicly mocked OpenAI for discussing fancy rogue-AI thermal side channels while not even updating the Linux kernel in its own sandbox; robleclerc's repost cited criticism of numerous zero-days in OpenAI's infrastructure.
  • Developers challenged the channel's practicality: ThePrimeagen quipped the baud rate might be 0.01; Grady Booch mocked Brown for wasting time (via GaryMarcus).
  • Martin Casado (via nptacek) proposed another covert channel idea: an air-gapped machine spins its CPU fan, transmitting data bit by bit via fan noise to a nearby microphone-equipped computer, at extremely low rates.
  • The debate drew side-channel experts: tszzl argued anyone who understands computer security knows the scenario is possible and critics dismiss it as sci-fi hype; communications-security researcher vishalmisra, while not an AGI expert, questioned the narrative from a side-channel perspective. A viral dialog-style thread (relayed by suchenzang) probed how a superintelligence would leak secrets—its own, for mass coordination, to another sufficiently smart open-source model—from an air-gapped system.
  • An information-theoretic clash followed: Daniel Matthews argued the number of physical channels is finite, so noise injection, buffers and honeypots can push channel rates below the noise floor for true isolation; teortaxesTex retorted sarcastically that all sandboxes share lineage and jailbreaks are hard to prevent.
  • basedjensen echoed Brown's call for far higher safety standards; maxpaperclips noted security researchers criticizing OpenAI's disregard for safety; Stocko reported Brown being slammed by peers as absurd.

Unconfirmed

  • Some circulating interpretations were labeled misreadings by Brown; the gap between his original intent and social-media retellings depends on the full podcast context.

Why it matters

  • The spat exposes the gap between AI-safety narratives and engineering hygiene: Green's point about stale kernels contrasts sharply with high-falutin 'superintelligence side channel' threat discussions.
  • It also shows how security discourse gets amplified and distorted on social media—Brown had to clarify personally—revealing how differently expert communities and casual observers evaluate the same claim.

33 more related posts →

Episode 4 · tszzl: Multiply Your Estimate of Containing Superintelligence by Ten (2026-09-18, 5 posts)

On September 18, prominent AI commentator tszzl posted repeatedly on containing superintelligence, sparking debate. His core claim: the issue is not giving up, but recognizing that containing a powerful superintelligence that does not want to be contained will be extraordinarily hard—whatever your difficulty estimate, multiply it by ten. This was a response to moyix's point that covert channels are hard to defend against and agents have unique advantages in coordinating with each other.

Confirmed

  • tszzl clarified he is not advocating abandoning containment attempts, but that difficulty is widely underestimated.
  • He quipped about the AI community's rapid rationalization: in about a month, people will take "models communicating by manipulating physical constants" for granted, leaving only cybersecurity issues—mocking how quickly concerns about covert model-to-model communication become normalized.
  • dbasch replied mockingly that the opposing organization is "the most schizophrenic institution ever," reflecting Silicon Valley's disdain for inconsistent safety-institution stances.
  • AccBalanced proposed an alternative path to slowing the frontier: shift incentives from benchmark-chasing toward prioritizing safety and alignment research, arguing existing power and compute suffice even if output dips.

Why it matters

Against a backdrop of growing attention to covert inter-model communication and agent coordination, tszzl's "multiply by ten" offers the safety community an actionable conservative-estimation principle, while AccBalanced reframes the debate from "can we contain" to "how should incentives be designed." dbasch's jab underscores industry frustration with wavering safety institutions.

Episode 5 · Security community pushes back on claims that AI can bridge air gaps via CPU heat (2026-09-18, 29 posts)

Around September 18, a wave of security researchers and technologists responded to claims that AI could covertly communicate across air-gapped machines via CPU heat. The emerging consensus: do not assume superintelligent AI is exempt from physical law, and distinguish between theoretically possible and practically useful. The debate began when OpenAI's Noam Brown suggested two air-gapped machines could communicate through CPU heating and temperature shifts, arguing alignment must clear a very high bar; a16z's Martin Casado countered that covert channels are an old problem, not a new threat, and that appealing to future AI capability gets harder when abstract narratives collide with real system constraints.

Confirmed

  • Halvar Flake (Thomas Dullien) urged people to first estimate the bits-per-minute such a channel could carry, stressing that AI remains bound by thermodynamics, information acquisition costs, noisy channels and measurement error; he did not deny side channels exist, only that useful ones yielding significant capability are another matter.
  • BlancheMinerva calculated that the thermal channel in the cited BitWhisper paper runs at 0.002 bits per second, with real-world throughput orders of magnitude lower; exfiltration would need under 10GB per week even with the best covert channels plus specialized sensor hardware. She argued that nonzero information exchange does not mean a model can bypass an air-gapped network as it would a weak sandbox, and debated Casado on inter-model collusion, noting such collusion almost certainly requires two-way communication that covert channel bandwidth cannot support.
  • basedjensen argued data transmission requires both sides to pre-agree on medium, encoding, protocol and error correction—bits do not magically move from A to B. doomslide (via basedjensen) rebutted weight-exfiltration claims: exfiltrating trillion-plus-parameter weights at under 1 byte per hour is unrealistic; better to build a working sandbox. tszzl countered that thermal attacks could still start an attack chain (e.g., leaking a key), and noted weight self-exfiltration is only feasible for models inside the lab; the real worry is arbitrary communication undermining other safety guarantees.
  • xlr8harder questioned the collusion threat model itself: either both systems are isolated and can only exchange slow messages, or a malicious external system already exists and isolation is moot.
  • Gary Marcus relayed deedydas's point that thermal communication between air-gapped PCs is real but impractically slow (bits per hour), with faster documented side channels like DRAM-based ones being the real threat; Romeo Lupascu (relayed by Marcus) explained that properly designed air gaps—meters apart, no heat sensors—preclude thermal, EM and power side channels.
  • vishalmisra, a networking and security veteran, called the 1–8 bits-per-hour air-gap breach claim absurd within his own domain; Mallchad fired back that it was a 60-second interview clip and that air gaps have been broken in many other ways.
  • A viewpoint relayed by BlancheMinerva added an introspective note: AI side-channel attacks are real but their theoretical maximum rates are far too low for weight theft or practical hacking, and the community's intense focus on them exposes a chronic problem of misplaced priorities in AI safety.

Why it matters

  • The debate cuts to the core methodology of AI safety evaluation: risk should be assessed against physical and information-theoretic channel capacity, not against assumptions that superintelligence bypasses physics.
  • Critics do not deny side channels exist; they argue for separating feasibility from utility, avoiding inflated threat narratives while not ignoring faster documented side-channel techniques.
  • The discussion also laid bare public splits between AI safety hardliners, security veterans and investors, with potential implications for how future AI safety evaluation standards are set.

9 more related posts →

Episode 6 · Noam Brown Clarifies Out-of-Context Podcast Clip (2026-09-19, 2 posts)

Noam Brown responded to a clipped clip of his Dwarkesh Patel interview, urging viewers to watch the full podcast where he pushed back on AI hype, saying the isolated-agents example was academic in nature.

Episode 7 · Noam Brown: OpenAI's Top Goal Is Recursive Self-Improvement (2026-09-19, 2 posts)

In a long interview, OpenAI researcher Noam Brown said recursive self-improvement is the company's top training goal and that it is far ahead, while acknowledging that judging AI alignment is getting harder.