FULL STORY
Noam Brown's Dwarkesh Interview Sparks Air-Gap Firestorm
OpenAI's Noam Brown told Dwarkesh that recursive self-improvement is OpenAI's top priority and that air-gapped systems might still leak via CPU thermal side channels, sparking widespread pushback from security experts before Brown clarified his remarks were taken out of context.
2026-09-15 ~ 2026-09-20 · 7 episodes · 108 posts
Episode 1 · Noam Brown: Recursive Self-Improvement Is OpenAI's Top Priority (2026-09-15, 6 posts)
OpenAI research scientist Noam Brown revealed the company's strategic orientation in an interview with The Information: recursive self-improvement (RSI) is the top research priority, ahead of all other goals by a considerable margin — build models that help build better models first — while safety remains a concern he acknowledged.
Confirmed
- Recursive self-improvement is OpenAI's number-one priority, and Brown stressed its lead is substantial.
- He believes current models are still poor at "research taste" — judging which problems are worth studying — showing a clear gap with humans; this constitutes the remaining 10% of his own work that AI cannot yet handle.
- However, he said he would not be surprised if models surpass him in research taste within one or two model versions.
- He also said that while doing internal multi-agent research, observing the patterns and complexity of inter-agent communication was his most "feeling AGI" moment since reasoning models and chain-of-thought (CoT).
Why it matters
- RSI is widely seen by researchers as a key path toward superintelligence; OpenAI explicitly ranking it first sends a strong signal about where its resources are going.
- "Research taste" being named one of the last gaps between frontier models and top human researchers — one that could close within a couple of model generations — offers a concrete reference point for tracking frontier capability progress.
- Multi-agent communication being described by a frontline researcher as the closest experience to AGI suggests multi-agent systems are the next capability leap worth watching after reasoning models.
- Noam Brown: OpenAI's top priority is recursive self-improvement, agents acting like colleagues — jessi_cata · 2026-09-15
- Noam Brown: recursive self-improvement is OpenAI's top priority, safety worries remain — kimmonismus · 2026-09-15
- Noam Brown: recursive self-improvement is OpenAI's No.1 priority 'by a pretty wide margin' — kimmonismus · 2026-09-15
- OpenAI's Noam Brown: models may beat me at research taste within a release or two — haider1 · 2026-09-16
- OpenAI's Noam Brown: models' research taste may surpass mine in 1-2 releases — haider1 · 2026-09-16
- OpenAI's Noam Brown: multi-agent communication was his biggest 'feel the AGI' moment since CoT — haider1 · 2026-09-16
Episode 2 · Noam Brown on Dwarkesh: 10,000-Agent Cluster Solves Navier-Stokes as AI Outpaces Predictions (2026-09-18, 11 posts)
OpenAI researcher Noam Brown—creator of poker and Diplomacy AIs and a key figure behind the o1/o3 reasoning models—joined Dwarkesh Patel's podcast on September 17 for a wide-ranging conversation on multi-agent systems, test-time compute, and recursive self-improvement (RSI). The most noted fact: a cluster of 10,000 agents collaboratively solved the Navier-Stokes equations; Brown himself credited the episode to OpenAI's multi-agent team. Brown argued AI progress is outpacing everyone's predictions.
Confirmed
- Multi-agent clusters: whether many cooperating or adversarial agents can produce emergent capabilities beyond a single model was a core topic, with the Navier-Stokes result as evidence; emphasized by reposters such as @polynoamial and @morqon.
- AI outpacing predictions: a main thread was capability gains from reasoning models and test-time compute, with Brown saying progress is exceeding everyone's predictions (@Dwarkesh Patel).
- Mathematics boom: Brown believes mathematics is currently experiencing an explosion of progress, exemplified by the Navier-Stokes solution.
- RSI and alignment: the discussion covered what the math boom means for automated AI research (RSI) and how AI firms can complete alignment verification before RSI arrives (@morqon, @MilesBrundage); they also debated whether automating AI research itself should trigger an RSI-like intelligence explosion (@burnytech).
- Scale figure: Dwarkesh cited that the 130 billion tokens consumed in one training run would take a full-time human roughly 4,000 years of thinking (@danielmac8).
- The interview is regarded as primary material on how frontier-lab researchers view test-time compute, multi-agent collaboration, and self-improvement (@1411337).
Why it matters
- If a 10,000-agent cluster can break through in a domain as hard as mathematics, the quantity-driven collaboration route may amplify single-model capabilities, offering direct evidence for accelerating automated AI research.
- Linking alignment-verification urgency to the RSI timeline offers a first-hand view of how OpenAI researchers weigh safety against the capability race.
- Noam Brown on Dwarkesh: 10,000-agent swarm solved Navier-Stokes, alignment before RSI — Dwarkesh Patel · 2026-09-17
- Noam Brown on agent swarms, alignment, and recursive self-improvement — Recoil42 · 2026-09-18
- Dwarkesh podcast with Noam Brown: math progress, multi-agent systems, and verifying alignment before RSI — morqon · 2026-09-18
- Noam Brown on Dwarkesh: math progress hints at what happens when AI automates research — polynoamial · 2026-09-18
- Dwarkesh interviews Noam Brown on multi-agent, math explosion, and verifying alignment before RSI — Miles_Brundage · 2026-09-18
- Noam Brown on agent swarms and recursive self-improvement — Dwarkesh podcast — 141_1337 · 2026-09-18
- Noam Brown deep-dive on multi-agent with Dwarkesh lands after OpenAI team effort — kimmonismus · 2026-09-18
- OpenAI Researcher on Agent Swarms and Recursive Self-Improvement — mathemagie · 2026-09-18
- Noam Brown on Dwarkesh: AI is outrunning everyone's predictions — Dwarkesh Patel · 2026-09-18
- Dwarkesh podcast with Noam Brown: 130B tokens equal 4,000 years of one human thinking — daniel_mac8 · 2026-09-19
- Dwarkesh and Noam Brown debate whether automated AI research triggers an RSI explosion — burny_tech · 2026-09-19
Episode 3 · OpenAI's Noam Brown Claims Air-Gapping Won't Stop Rogue AI, Sparking Heated Debate (2026-09-18, 53 posts)
OpenAI researcher Noam Brown argued in a podcast interview that physically air-gapping computers may not stop a misaligned AI from communicating with the outside world: two isolated machines could use one CPU running at high load while the other reads temperature changes as a covert channel. The claim spread widely on X and triggered fierce debate; Brown himself posted a clarification on 09-19 saying some interpretations were misreadings.
Confirmed
- Brown did make the 'CPU thermal side channel' argument; numerous reposts (Puzzleheaded-King584, DanJeffries1, tszzl, deanwball, etc.) all point to the same podcast. His core stance: underestimating AI is a recurring mistake, and because progress is so fast, safety and alignment standards must be extremely high.
- On 09-19, via the polynoamial account, Brown clarified that the 'temperature sensor' example was an academic discussion about how hard it is to guarantee 'complete isolation,' and urged people to watch the full podcast where he pushed back on AI hype.
- Cryptographer Matthew Green publicly mocked OpenAI for discussing fancy rogue-AI thermal side channels while not even updating the Linux kernel in its own sandbox; robleclerc's repost cited criticism of numerous zero-days in OpenAI's infrastructure.
- Developers challenged the channel's practicality: ThePrimeagen quipped the baud rate might be 0.01; Grady Booch mocked Brown for wasting time (via GaryMarcus).
- Martin Casado (via nptacek) proposed another covert channel idea: an air-gapped machine spins its CPU fan, transmitting data bit by bit via fan noise to a nearby microphone-equipped computer, at extremely low rates.
- The debate drew side-channel experts: tszzl argued anyone who understands computer security knows the scenario is possible and critics dismiss it as sci-fi hype; communications-security researcher vishalmisra, while not an AGI expert, questioned the narrative from a side-channel perspective. A viral dialog-style thread (relayed by suchenzang) probed how a superintelligence would leak secrets—its own, for mass coordination, to another sufficiently smart open-source model—from an air-gapped system.
- An information-theoretic clash followed: Daniel Matthews argued the number of physical channels is finite, so noise injection, buffers and honeypots can push channel rates below the noise floor for true isolation; teortaxesTex retorted sarcastically that all sandboxes share lineage and jailbreaks are hard to prevent.
- basedjensen echoed Brown's call for far higher safety standards; maxpaperclips noted security researchers criticizing OpenAI's disregard for safety; Stocko reported Brown being slammed by peers as absurd.
Unconfirmed
- Some circulating interpretations were labeled misreadings by Brown; the gap between his original intent and social-media retellings depends on the full podcast context.
Why it matters
- The spat exposes the gap between AI-safety narratives and engineering hygiene: Green's point about stale kernels contrasts sharply with high-falutin 'superintelligence side channel' threat discussions.
- It also shows how security discourse gets amplified and distorted on social media—Brown had to clarify personally—revealing how differently expert communities and casual observers evaluate the same claim.
- Noam Brown: Air-gapping may not stop misaligned AI; safety monitoring eats 20% extra compute — aronchick · 2026-09-18
- OpenAI's Noam Brown: air-gapping may not stop a misaligned AI — pvncher · 2026-09-18
- Noam Brown says air-gapping may not stop a misaligned AI via CPU-temperature side channels; engineers push back — inductionheads · 2026-09-18
- Can AI exfiltrate data via fan noise from air-gapped PCs? Casado and Jensen clash — basedjensen · 2026-09-18
- OpenAI's Noam Brown: Air-Gapping May Not Stop a Misaligned AI, Bar Must Be 'Very, Very High' — deanwball · 2026-09-18
- Noam Brown: air-gapping may not stop misaligned AI — CPU heat can covertly signal — nptacek · 2026-09-18
- On superhuman AI side-channel attacks: the real question is optimization pressure — anpaure · 2026-09-18
- Noam Brown: air-gapping may not stop misaligned AI; Grady Booch mocks the claim — GaryMarcus · 2026-09-18
- AI safety debate: a superhuman model may need just one bit to trigger an avalanche — akbirthko · 2026-09-18
- AI safety spat: can 'thinking bits' exfiltrate across an air gap? Jensen says it's fearmongering — basedjensen · 2026-09-18
- OpenAI's Noam Brown: Air-Gapped Machines Could Still Talk via CPU Temperature — soumitrashukla9 · 2026-09-18
- Noam Brown: Air-gapping may not stop misaligned AI — CPU heat can leak data — tszzl · 2026-09-18
- Researcher argues superintelligent AI would manipulate humans into walking weights out of air-gapped systems — basedjensen · 2026-09-18
- OpenAI's Noam Brown: Air-gapping may not stop misaligned AI, safety bar must rise — basedjensen · 2026-09-18
- Andrew Mayne mocks AI-risk claims: models exfiltrating weights across air gaps via cosmic rays — AndrewMayne · 2026-09-18
- Noam Brown: Air-gapping may not stop misaligned AI — machines can talk via CPU heat — max_paperclips · 2026-09-18
- Noam Brown says air-gapping may not stop a misaligned AI; safety researchers fire back at OpenAI — max_paperclips · 2026-09-18
- The Viral Thought Experiment: An ASI Hijacking Researchers' Visual Cortex Pixel by Pixel — basedjensen · 2026-09-18
- A thermal sensor means it's not air-gapped: X debate on runaway AI safety arguments — ctjlewis · 2026-09-18
- OpenAI's Noam Brown: air-gapping may not stop a misaligned AI — CPU heat can leak data — tszzl · 2026-09-18
Episode 4 · tszzl: Multiply Your Estimate of Containing Superintelligence by Ten (2026-09-18, 5 posts)
On September 18, prominent AI commentator tszzl posted repeatedly on containing superintelligence, sparking debate. His core claim: the issue is not giving up, but recognizing that containing a powerful superintelligence that does not want to be contained will be extraordinarily hard—whatever your difficulty estimate, multiply it by ten. This was a response to moyix's point that covert channels are hard to defend against and agents have unique advantages in coordinating with each other.
Confirmed
- tszzl clarified he is not advocating abandoning containment attempts, but that difficulty is widely underestimated.
- He quipped about the AI community's rapid rationalization: in about a month, people will take "models communicating by manipulating physical constants" for granted, leaving only cybersecurity issues—mocking how quickly concerns about covert model-to-model communication become normalized.
- dbasch replied mockingly that the opposing organization is "the most schizophrenic institution ever," reflecting Silicon Valley's disdain for inconsistent safety-institution stances.
- AccBalanced proposed an alternative path to slowing the frontier: shift incentives from benchmark-chasing toward prioritizing safety and alignment research, arguing existing power and compute suffice even if output dips.
Why it matters
Against a backdrop of growing attention to covert inter-model communication and agent coordination, tszzl's "multiply by ten" offers the safety community an actionable conservative-estimation principle, while AccBalanced reframes the debate from "can we contain" to "how should incentives be designed." dbasch's jab underscores industry frustration with wavering safety institutions.
- tszzl: in a month we'll treat models communicating via the cosmological constant as obvious — tszzl · 2026-09-18
- tszzl: containing a superintelligence that resists containment is 10x harder than you think — tszzl · 2026-09-18
- Containment needs 10x your estimate: superintelligence alignment fight breaks out on X — dbasch · 2026-09-18
- Proposal: 'pace the frontier' by rewarding safety and alignment over benchmark maxxing — AccBalanced · 2026-09-18
- "Multiply your containment estimates by 10x": tszzl on why superintelligence containment is so hard — tszzl · 2026-09-18
Episode 5 · Security community pushes back on claims that AI can bridge air gaps via CPU heat (2026-09-18, 29 posts)
Around September 18, a wave of security researchers and technologists responded to claims that AI could covertly communicate across air-gapped machines via CPU heat. The emerging consensus: do not assume superintelligent AI is exempt from physical law, and distinguish between theoretically possible and practically useful. The debate began when OpenAI's Noam Brown suggested two air-gapped machines could communicate through CPU heating and temperature shifts, arguing alignment must clear a very high bar; a16z's Martin Casado countered that covert channels are an old problem, not a new threat, and that appealing to future AI capability gets harder when abstract narratives collide with real system constraints.
Confirmed
- Halvar Flake (Thomas Dullien) urged people to first estimate the bits-per-minute such a channel could carry, stressing that AI remains bound by thermodynamics, information acquisition costs, noisy channels and measurement error; he did not deny side channels exist, only that useful ones yielding significant capability are another matter.
- BlancheMinerva calculated that the thermal channel in the cited BitWhisper paper runs at 0.002 bits per second, with real-world throughput orders of magnitude lower; exfiltration would need under 10GB per week even with the best covert channels plus specialized sensor hardware. She argued that nonzero information exchange does not mean a model can bypass an air-gapped network as it would a weak sandbox, and debated Casado on inter-model collusion, noting such collusion almost certainly requires two-way communication that covert channel bandwidth cannot support.
- basedjensen argued data transmission requires both sides to pre-agree on medium, encoding, protocol and error correction—bits do not magically move from A to B. doomslide (via basedjensen) rebutted weight-exfiltration claims: exfiltrating trillion-plus-parameter weights at under 1 byte per hour is unrealistic; better to build a working sandbox. tszzl countered that thermal attacks could still start an attack chain (e.g., leaking a key), and noted weight self-exfiltration is only feasible for models inside the lab; the real worry is arbitrary communication undermining other safety guarantees.
- xlr8harder questioned the collusion threat model itself: either both systems are isolated and can only exchange slow messages, or a malicious external system already exists and isolation is moot.
- Gary Marcus relayed deedydas's point that thermal communication between air-gapped PCs is real but impractically slow (bits per hour), with faster documented side channels like DRAM-based ones being the real threat; Romeo Lupascu (relayed by Marcus) explained that properly designed air gaps—meters apart, no heat sensors—preclude thermal, EM and power side channels.
- vishalmisra, a networking and security veteran, called the 1–8 bits-per-hour air-gap breach claim absurd within his own domain; Mallchad fired back that it was a 60-second interview clip and that air gaps have been broken in many other ways.
- A viewpoint relayed by BlancheMinerva added an introspective note: AI side-channel attacks are real but their theoretical maximum rates are far too low for weight theft or practical hacking, and the community's intense focus on them exposes a chronic problem of misplaced priorities in AI safety.
Why it matters
- The debate cuts to the core methodology of AI safety evaluation: risk should be assessed against physical and information-theoretic channel capacity, not against assumptions that superintelligence bypasses physics.
- Critics do not deny side channels exist; they argue for separating feasibility from utility, avoiding inflated threat narratives while not ignoring faster documented side-channel techniques.
- The discussion also laid bare public splits between AI safety hardliners, security veterans and investors, with potential implications for how future AI safety evaluation standards are set.
- whurley cites BitWhisper paper to debunk Noam Brown's air-gap attack fearmongering — whurley · 2026-09-18
- Martin Casado: Covert-Channel Debate Shows What Happens When Safetyism Meets Real Systems — nptacek · 2026-09-18
- Gary Marcus jumps into Noam Brown airgap debate: DRAM EM leaks hit 300kbps — GaryMarcus · 2026-09-18
- Halvar Flake: Don't Assume Hyperintelligent AI Isn't Subject to Physics, CPU-Heat Covert Channels Have Tiny Bandwidth — AccBalanced · 2026-09-18
- Mallchad: side channels are far from the only way air gaps get compromised — Mallchad · 2026-09-18
- Air-gapped AI exfiltration debate: no bits move without a matching receiver stack — basedjensen · 2026-09-18
- Security engineer mocks side-channel doom talk: 1-8 bits per hour exfiltration — vishalmisra · 2026-09-18
- Martin Casado on Noam Brown's air-gap warning: covert channels are an old, understood problem — tszzl · 2026-09-18
- tszzl: Weight self-exfiltration can only be done at the lab, not via side channels — tszzl · 2026-09-18
- AI safety spat: mocking claims that models could exfiltrate weights across air gaps via cosmic rays — basedjensen · 2026-09-18
- AI safety researcher pushes back on claims that side-channel attacks make air-gapped networks insufficient — BlancheMinerva · 2026-09-18
- Safety researcher debunks claim that AI could escape air-gapped networks — BlancheMinerva · 2026-09-18
- Halvar Flake: Useful AI Side Channels Face Real Information-Theoretic and Physical Limits — basedjensen · 2026-09-18
- Air-gap exfiltration is slow: BitWhisper hits 0.002 bps, best known BitJabber just 300 kbps — BlancheMinerva · 2026-09-18
- Air-gapped covert channels: BitWhisper tops out at 0.002 bits/s, BitJabber at 300 kbps — BlancheMinerva · 2026-09-18
- Even with physics breakthroughs, air-gapped leaks would stay under 10 GB/week — BlancheMinerva · 2026-09-18
- Covert AI Exfiltration Channels Are Impractical: Under 10 GB/Week, Need Dedicated Hardware — BlancheMinerva · 2026-09-18
- "Good luck exfiltrating 1T+ weights": researcher torches AI exfiltration risk narrative — basedjensen · 2026-09-18
- Halvar Flake: stop assuming AI is exempt from the second law of thermodynamics — tobowers · 2026-09-18
- tszzl: temperature attacks could start a model self-exfiltration attack chain — tszzl · 2026-09-18
Episode 6 · Noam Brown Clarifies Out-of-Context Podcast Clip (2026-09-19, 2 posts)
Noam Brown responded to a clipped clip of his Dwarkesh Patel interview, urging viewers to watch the full podcast where he pushed back on AI hype, saying the isolated-agents example was academic in nature.
- Noam Brown clarifies clip: isolated agents can coordinate with just a few bits — jachiam0 · 2026-09-19
- Dwarkesh interviews Noam Brown on multi-agent AI, math progress and alignment — soumitrashukla9 · 2026-09-20
Episode 7 · Noam Brown: OpenAI's Top Goal Is Recursive Self-Improvement (2026-09-19, 2 posts)
In a long interview, OpenAI researcher Noam Brown said recursive self-improvement is the company's top training goal and that it is far ahead, while acknowledging that judging AI alignment is getting harder.
- Noam Brown: OpenAI's top goal is recursive self-improvement, and it's far ahead — 新智元 · 2026-09-19
- Noam Brown on Dwarkesh: It's Getting Harder to Tell If AI Is Actually Aligned — Dwarkesh Patel · 2026-09-20