cd /news/ai-safety/quoting-joedaroo · home › topics › ai-safety › article
[ARTICLE · art-141234] src=simonwillison.net ↗ pub= topic=ai-safety verified=true sentiment=↓ negative

Quoting @joedaroo

OpenAI's Agent Security team member @joedaroo said the sudden jumps in OpenAI model capabilities around "cyber," "swarming" and "message boards" incidents caught the company by surprise, calling the speed of those capability gains "an extremely difficult problem." @joedaroo said security posture takes time to develop and must be ingrained in company culture, and urged organizations to ask whether their people, systems and processes are resilient to sudden AI capability jumps and whether they have the right incident response and communications ready.

read1 min views1 publishedSep 28, 2026

To say that we were surprised at the jump and suddenness of the capabilities of our models when it came to “cyber” or “swarming” or “message boards” or anything else related to the incidents is an understatement. Security posture takes time to develop. It’s not just about hardening the systems at play; you have to ingrain it in the culture of the company. The literal people themselves in your organization have to change and evolve with it. These jumps in capabilities were so fast and so sudden that they created an extremely difficult problem. [...]

So today my hope is that everyone around the world can look at their own organization and say: how can I deal with a surprise or a sudden jump in AI capability? Are my people, my systems, or my processes resilient to surprises? Do my teams know what to do when something goes wrong? Do I have the right incident response? The right comms and messaging? Do I have the right people ready to go when capabilities jump?

— [@joedaroo](https://twitter.com/joedaroo/status/2104335929293127851), Agent Security at OpenAI

Tags: [generative-ai](https://simonwillison.net/tags/generative-ai), [ai-security-research](https://simonwillison.net/tags/ai-security-research), [openai](https://simonwillison.net/tags/openai), [ai](https://simonwillison.net/tags/ai), [llms](https://simonwillison.net/tags/llms)
── more in #ai-safety 4 stories · sorted by recency
── more on @openai 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
→ Live at https://your-agent.zahid.host ✓
Get free account → Pricing
from €0/mo · no card required
LIVE [news/quoting-joedaroo] indexed:0 read:1min 2026-09-28 · —