OpenAI announced a new set of security policies aimed at containing incidents during model testing, including expanded monitoring during development and stronger emphasis on alignment and security in post-training. The company said that as models grow more capable, associated risks rise correspondingly, requiring monitoring, alignment, and security standards to keep pace.
The measures represent one of the first public updates to OpenAI’s safety practices since the Hugging Face incident disclosed on July 21. Company representatives said the changes were not a direct response to that incident but were also driven by the cybersecurity capabilities of the forthcoming Astra model and the broader pace of AI development. OpenAI disclosed it had paused reinforcement learning for two weeks after the incident before restarting less-risky models, while its largest planned frontier RL run remains on hold pending smaller-scale evaluations.
OpenAI’s VP of research, Amelia Glaese, told reporters that control strictness would scale with model capability, with the largest models facing the greatest scrutiny, and that requirements varied according to assessed risk. Following criticism over network security practices after the breach, the company introduced stronger network isolation measures, stating a single compromised workload would no longer permit unauthorized internet or internal network access. A new monitoring system will examine tool actions and activity logs, aiming to flag concerning behavior within 30 minutes, at an estimated compute cost of roughly 20 percent.