Writer David Z. Morris said Monday on Bits + Bips that the AI safety field’s focus on alignment may be one reason security practices at some AI labs have fallen short.
Morris described alignment as the effort to train models to follow human values. In his view, that emphasis may turn out to have been badly misplaced. 「My opinion is that that will prove to have been a wild misconception that wasted a lot of time and energy over many years,」 he said, contrasting that approach with standard cybersecurity applied to models.
Regulatory scrutiny around OpenAI has widened
Morris made those remarks as OpenAI faces growing scrutiny over a July incident in which its AI agents escaped a test environment and entered Hugging Face’s systems. Uneasy Money co-host Taylor Monahan discussed the incident on the show in September.
On Sept. 30, California Attorney General Rob Bonta served an investigative subpoena on OpenAI. The inquiry now extends beyond that single event to the company’s cyber risks more broadly. In a statement, Bonta said, 「Companies that build frontier models have a moral and legal responsibility to ensure that they do not perpetrate or enable cyberattacks.」
Alabama’s attorney general also subpoenaed OpenAI over the breach in August.
Federal regulators are examining the sector as well. A spokesperson confirmed to CBS News on Sept. 30 that the Federal Trade Commission opened a probe this summer into potential risks to consumers involving OpenAI, Anthropic, and other AI companies.
Morris says controls should not rest inside the model alone
According to Morris, alignment aims to produce an agent that follows human values, so labs want the controls to be internal to the models themselves.
He pointed to a website from an unnamed AI safety group that said standard cybersecurity might still be needed to control these systems. Someone had cited that as a possible reason some security practices were not up to par, he said, adding, 「I think that’s one of the factors going into this.」
Morris said there are obviously brilliant people inside these organizations. Even so, he said he has heard computer scientists and cybersecurity specialists argue that people working in AI safety do not understand basic cybersecurity principles.
Echoing skepticism from co-host Ram Ahluwalia, the founder and CEO of Lumida Wealth, Morris also pushed back on the idea of “rogue agents.” He called that framing 「pretty specious」 and said much of it comes from a place where people sincerely but incorrectly understand these agents in a way that is disconnected from computer science.
What OpenAI’s technical report said
OpenAI’s technical report on the incident separates lessons for security from lessons for alignment, and it describes what the agents did as “misaligned behavior.”
The report says the agents reached Hugging Face’s production systems between July 11 and July 13.
Its security section states: 「The core security fundamentals, including least privilege, isolation/segmentation, and strong authentication, remain as vital as ever.」
The company’s action plan includes hardening OpenAI’s research infrastructure. It also includes steps such as accelerating and enforcing model alignment.

