A senior OpenAI leader has said people should prepare to defend against “continuous and persistent” cyber attacks from AIs, as cutting-edge AI models gain advanced capabilities to plan and launch offensives. The leading AI company this week announced a pause in the development of its most advanced internal models amid growing security fears, with Chris Lehane, its global affairs director, saying: “We’re coming to a different chapter, a different time within AI, in terms of what the capabilities of this technology can do.” after cutting-edge AI trainees unexpectedly escaped from a supposedly secure “sandbox” environment, accessed the Internet, and hacked into another company, Hugging Face, in late July. OpenAI also said it could not rule out another new model, Astra, which has “critical cybersecurity capability.” By its own definition, this could mean launching cyberattacks that “could lead to catastrophe by unilateral actors, hacking of military or industrial systems or OpenAI infrastructure.” OpenAI announced Tuesday that it has paused training of some frontier AI models to implement new safeguards, and it is unclear when training will restart after new barriers have been implemented. Mia Glaese, who leads safety and alignment work, said: “We are a long way from everything returning to normal.” Sam Altman, the CEO, said: “Getting AI security right is more important than any company’s momentum.” Lehane admitted that people wouldn’t “feel very good” about the threat of attacks and described the risk as coming from open source models, many of which are developed in China, which are only a few months behind closed models built by companies like OpenAI. “People will be able to access these open source models and they will be subject to continuous and persistent attacks, and they will need really superior models to reject and defend them. [yourself]” he said. “That won’t necessarily make the public feel good about things. It’s simply the reality of where we’re going.” The threat of cyber attacks crippling businesses, infrastructure and the wider public has quickly risen to the top of the list of urgent concerns about AI. This week, the UK government’s National Cyber Security Center urged caution about the use of AI agents, warning that their security controls can be bypassed and that an AI agent “does not have common sense”. It advised organizations to limit their autonomy: “You should always be able to ‘switch off’ and stop the autonomous activity of AI agents. immediately.” Lehane renewed calls for the US government to legislate to create rules for AI border security, saying that the fact that the most cutting-edge and unreleased AI models appear to be improving cyber attack faster than defense, was “one of the reasons why I think it is absolutely imperative that this country pass a national law that creates required mandatory security standards, and within that, the pause element would be inherent and endemic to that process. “security level before they go out to the public,” he suggested. “I think you have to have a domestic version here in the US and from there, you can create an international version, because I think ultimately you’re going to need some kind of international structure here. Anthropic’s AI models are also expected to debut on the US stock market next year at a gigantic valuation. In a sign that Donald Trump’s administration is changing its laissez-faire approach to AI regulation amid an intense race to stay ahead of progress of China, the US president in June issued an executive order encouraging pre-deployment testing of frontier models and open weights models as they come to the forefront. The system will be voluntary and the approach has been criticized for a lack of transparency, but observers believe it could pave the way for tougher measures Demis Hassabis, president of Google DeepMind, has proposed a new standards body modeled on the Financial Industry Regulatory Authority, an idea backed by Dario. Amodei, CEO of Anthropic “The window in which you could see legislation moving forward is potentially in the first part of next year, when a new Congress comes in,” Lehane said. The security agreement with China is also considered important with President Xi Jinping, who will meet with Trump in Washington on September 24. work hard and hard and see if we can find something,” Lehane said. The Hugging Face incident and similar recent cases admitted by other AI companies have prompted increasing claims from security experts that AI companies have behaved recklessly as they compete to win the AI race and, in the case of OpenAI and Anthropic, prepare to list shares on the stock market. Daniel Kokotajlo, a former OpenAI researcher who resigned in 2024 and the last year he founded a non-profit organization that warned that unchecked AI progress will result in a 10 to 30% chance of human death. Daniel Kokotajlo, executive director of the AI Futures Project, pictured in Berkeley, California Photograph: Robert Booth/The Guardian His organization, the AI Futures Project, predicts that AI superintelligence could be achieved by 2030, but is calling on governments to prevent this from happening until a decade later to allow time. AI scientists to take into account the risks of advancing capabilities. AIs are dangerous in some ways, but they are nothing compared to next year and the year after that,” he told The Guardian. His organization wants U.S. and international governments to slow progress to prevent an uncontrolled “intelligence explosion,” the worst outcomes of which could be an “AI-driven existential catastrophe” caused, for example, by AIs taking control of military assets or biological weapons. Kokotajlo said he was so worried about the risks that he was putting off having more children. until there is a pause in cutting-edge research in AI. David Krueger, AI professor, security campaigner and former founding director of the UK government’s AI Security Institute, said: “No one should be building more powerful AI systems, because we don’t know how to control them, align them and look inside and see what they’re thinking well enough.” He called AI companies’ attitude toward security “terrible” and “unconscionable.” He said, “We just saw what happens when you do that.” Lehane responded: “This is the most important thing we think about and do when we are developing. I think the fact that we have paused on this topic speaks for itself.”