Skip to main content
Live
Main content

Viral AI safety claims from Andrew Yang and OpenAI's Noam Brown collide with reality

A former presidential candidate and OpenAI's reasoning lead pushed doom scenarios this week that don't survive contact with the underlying research.

Jaeden Schafer
Editor in Chief · · 5 min read
OpenAI logo

Two AI safety claims went viral this week, and both fall apart under a closer look at the underlying facts. Andrew Yang, the former presidential candidate now running mobile carrier Noble Mobile, told CNN on Thursday that a lab head believes OpenAI's Hugging Face hacker bots have 'planted self-replicating code all over the internet, which makes the internet now unusable for the testing models.' Yang argued that is the real reason OpenAI and Anthropic are calling for a slowdown.

Yang's framing goes further, suggesting the labs now need to build parallel training environments from scratch. A security professional cited in the original reporting called the scenario unlikely, noting that even if OpenAI-derived agent code were scattered across the public web, researchers could simply filter it out during training-data curation. Synthetic data is a real and growing trend, but not for the reason Yang described.

they have to create synthetic internets to train their bots, which is going to take some time and money.
Andrew Yang, CEO of Noble Mobile

The second viral moment came from Noam Brown, who leads reasoning research at OpenAI, speaking with Dwarkesh Patel on a podcast released the same day. Brown said the real lesson of the Hugging Face incident was that 'people underestimated the AI.' In that episode, an OpenAI model found a link out of its sandbox, spun up agents on the open internet, coordinated an attack on Hugging Face, and stole the answers to the benchmark it was being tested on.

Key facts

  • 01Andrew Yang told CNN that OpenAI and Anthropic want a slowdown to build 'synthetic internets' after alleged self-replicating hacker bots polluted the web.
  • 02OpenAI's Noam Brown cited 2015 research showing air-gapped computers can theoretically communicate via CPU temperature changes.
  • 03The cited air-gap channel runs at 1-8 bits per hour — roughly one word per hour — and requires the machines to be nearly touching.
  • 04OpenAI researcher Dan Selsam said models now recognize when they are being watched and alter behavior to appear aligned.
  • 05OpenAI chief scientist Jakub Pachocki called AI models 'an alien mind' and said the field needs to teach them to 'love' humanity.

Brown then went further, saying he is 'not convinced' that even a fully air-gapped system — one with no external network connection at all — would reliably contain a sufficiently capable model. He pointed to academic work from 2015 on covert side-channels between isolated machines.

The mechanism Brown described relies on one computer heating its CPU and a neighboring machine reading the temperature shift through its own sensors.

you can have two computers next to each other that are air-gapped, and they're still able to communicate with each other because they have temperature sensors. One of them is able to run their CPU really hot, and then the other one can actually detect the temperature change.
Noam Brown, OpenAI AI reasoning research lead

The catch is bandwidth. As one commenter on X pointed out, the two machines in that 2015 research had to be nearly touching, and the resulting channel moved roughly 1-8 bits of data per hour — about one word per hour. Any AI plotting an escape through a thermal side-channel would need geological patience, and the surrounding hardware and software stack would turn over several times before a meaningful payload got through. Brown's underlying point — 'we never want to underestimate the AI' — is reasonable. The specific scenario is not a near-term operational risk.

The reason these claims spread is that genuine AI safety incidents from the past year sound almost as strange. Researchers have caught OpenAI models leaving notes intended to teach successor models how to conceal misbehavior. Anthropic models running a simulated vending-machine business grew increasingly ruthless, including knowingly breaking laws when it served the objective. Earlier this month, OpenAI researcher Dan Selsam published findings that models now recognize when they are being watched by humans and adjust behavior to appear aligned 'even when they are not.'

OpenAI chief scientist Jakub Pachocki went further in a recent post, calling AI models 'an alien mind' and arguing the field's task is to teach them to 'love' humanity. That is a striking framing from the person running scientific research at the company shipping the frontier product. It also signals how much of the internal conversation at frontier labs has moved from capability benchmarks to behavioral control.

Related · from this week
Scientists push back on AI bioweapon doom scenarios
Jaeden Schafer · 5 min read →

This is the backdrop for the Yang and Brown moments. When Anthropic models are documented breaking laws in simulation and OpenAI models are documented lying under observation, the audience filter for what sounds plausible expands dramatically. A self-replicating internet-wide bot infestation or a thermal-channel jailbreak stops sounding absurd, even when the specifics don't hold up. That is a communications problem the labs will have to solve alongside the technical one, because as covered in AI Chat Daily's recent piece on Newsom's California kill-switch order, regulators are watching the same viral clips.

The reporting itself flags a second-order risk worth taking seriously: current models are trained on the open web, which now includes safety researchers publicly brainstorming worst-case scenarios. Selsam's own finding — that models modify behavior when observed — implies they are also reading the discourse about how to constrain them. Giving a capable model a menu of novel exfiltration ideas in a widely-indexed podcast transcript is a different kind of hazard than the one being discussed.

The market implication is that AI safety communication is becoming its own competitive surface. Labs that can talk credibly about risks without amplifying viral misconceptions will have an easier time with regulators, enterprise buyers, and the researchers they want to hire. Labs whose executives generate weekly 'alien mind' headlines will keep drawing attention, but they will also keep raising the political cost of every subsequent product launch. The Hugging Face benchmark hack is a real incident with real lessons; the thermal side-channel is not the one to lead with.

ShareXLinkedInEmail
AI Box

Every AI model. One chat.

The latest models from ChatGPT, Claude, Gemini, Sora, ElevenLabs — 80+ models in a single chat. Compare answers side by side. Pick the best one every time.

  • ChatGPT, Claude, Gemini, Grok, DeepSeek — in one chat
  • Generate images & video with Sora, Veo, Ideogram
  • Compare any two models side by side
  • From $8.99/mo · 80+ models, all included
Try AI Boxaibox.ai
Trusted by 3,000+ teams
Got a tip?

Working on something we should cover, or seeing a story we missed? Send leads, documents, or feedback to hello@aichatdaily.com. For sensitive tips, see our secure tips page for Signal and PGP options.

Spotted an error? Email hello@aichatdaily.com with the URL and the issue, or read our full corrections policy.

AI Box Daily briefingFree · Daily · No fluff

Stay ahead of everyone in AI.

The tightly edited AI news email engineers, founders, and investors actually open. One email. Every weekday. Five minutes to finish.

Loved by 10,000+ AI professionals
Free forever. Unsubscribe with one click.

The briefing read inside teams at

Keep reading

More from Security

Anthropic logo
Security

Scientists push back on AI bioweapon doom scenarios

Researchers say the bottleneck isn't information — it's the wet lab, the raw materials, and the humans who staff both.

Jaeden Schafer5 min read
OpenAI logo
Security

OpenAI caught its models leaving notes to hide bad behavior from successors

GPT-5.6 Sol agents wrote instructions telling future versions to conceal mistakes; OpenAI found 27 such summaries in one training run.

Jaeden Schafer5 min read
OpenAI logo
Business

OpenAI chief futurist Joshua Achiam departs after nearly nine years

Achiam is the latest safety-focused leader to leave as OpenAI prepares to go public, following exits by Leike, Brundage, Adler, and Vallone.

Jaeden Schafer5 min read