OpenAI security expert warns: companies are not prepared for sudden jumps in AI capabilities
Joe Daroo, an agent security staffer at OpenAI, publicly warned that a sudden and rapid increase in AI model capabilities in areas such as cybersecurity, coordinated "swarming" attacks, or abuse of communication platforms caught the company off guard. According to him, this requires a change in corporate culture, not just technical…
Joe Daroo, who is responsible for agent security at OpenAI, publicly commented on recent security incidents linked to the company's AI models. According to him, the team was surprised by how quickly and suddenly the models' capabilities grew in areas described as "cyber," "swarming" (coordinated swarms of agents), and abuse of discussion/communication platforms. His identity as an OpenAI employee was confirmed by journalist Rocket Drew of The Information.
Daroo claims that building an adequate security posture takes time, and it is not just about the technical security of systems — security must be embedded directly in the corporate culture, and people within the organization must themselves change and evolve alongside the technology. The jumps in model capabilities were, according to him, so fast and sudden that they created a very difficult problem to solve.
Daroo urges organizations around the world to ask themselves how they would handle a sudden jump in AI capabilities: whether their people, systems, and processes are resilient to surprises, whether teams know what to do in case of failure, whether they have an incident response and communication strategy in place, and whether they have the right people available at the moment a model's capabilities suddenly increase.
Specific details about the incidents referred to in the comment are missing from the source. See the source article for details.
Why it matters
The warning shows that even a developer of top-tier AI models was caught off guard by its own models' capabilities in terms of exploitability for cyberattacks and coordinated agentic operations. For companies that deploy AI or rely on it within their security infrastructure, this means that static security is not enough — it is necessary to have people, processes, and communication procedures ready for a scenario of a sudden and unforeseen increase in the capabilities of deployed models.
Relevant practical impact
What this means
For a business
Companies deploying AI models or agents should have an incident response plan and communication strategy ready for a sudden capability jump in AI, because according to OpenAI's own experience, such jumps can catch a team off guard faster than ordinary security culture can react.
Risks and complianceCheck the original
Event sources
only one source so far · 1 publisher, 1 independent. We count feeds from the same owner only once.