<?xml version="1.0" encoding="UTF-8"?><feed
	xmlns="http://www.w3.org/2005/Atom"
	xmlns:thr="http://purl.org/syndication/thread/1.0"
	xml:lang="en-US"
	>
	<title type="text">Robert Hart | The Verge</title>
	<subtitle type="text">The Verge is about technology and how it makes us feel. Founded in 2011, we offer our audience everything from breaking news to reviews to award-winning features and investigations, on our site, in video, and in podcasts.</subtitle>

	<updated>2026-09-28T16:56:26+00:00</updated>

	<link rel="alternate" type="text/html" href="https://www.theverge.com/author/robert-hart" />
	<id>https://www.theverge.com/authors/robert-hart/rss</id>
	<link rel="self" type="application/atom+xml" href="https://www.theverge.com/authors/robert-hart/rss" />

	<icon>https://platform.theverge.com/wp-content/uploads/sites/2/2025/01/verge-rss-large_80b47e.png?w=150&amp;h=150&amp;crop=1</icon>
		<entry>
			
			<author>
				<name>Robert Hart</name>
			</author>
			
			<title type="html"><![CDATA[OpenAI keeps bulldozing mathematicians]]></title>
			<link rel="alternate" type="text/html" href="https://www.theverge.com/ai-artificial-intelligence/1001477/openai-math-advisory-group" />
			<id>https://www.theverge.com/?p=1001477</id>
			<updated>2026-09-28T12:56:26-04:00</updated>
			<published>2026-09-28T13:00:00-04:00</published>
			<category scheme="https://www.theverge.com" term="AI" /><category scheme="https://www.theverge.com" term="OpenAI" />
							<summary type="html"><![CDATA[In a chaotic few months, OpenAI has demonstrated it can do two things with remarkable consistency: make impressive breakthroughs in mathematics, then colossally screw up announcing them. OpenAI is now trying to do better. Somehow, it has botched that too.&#160; OpenAI’s latest attempt to repair fractured relations with a mathematical community it has repeatedly alienated [&#8230;]]]></summary>
			
							<content type="html">
											<![CDATA[

						
<figure>

<img alt="An illustration of a bulldozer scooping up mathematical equations" data-caption="" data-portal-copyright="Image: The Verge, Shutterstock" data-has-syndication-rights="1" src="https://platform.theverge.com/wp-content/uploads/sites/2/2026/09/VRG_OpenAIMAthBulldozer_Parkin.jpg?quality=90&#038;strip=all&#038;crop=0,0,100,100" />
	<figcaption>
		</figcaption>
</figure>
<p class="has-drop-cap wp-block-paragraph">In a chaotic few months, OpenAI has demonstrated it can do two things with remarkable consistency: make impressive breakthroughs in mathematics, then colossally screw up announcing them. OpenAI is now trying to do better. Somehow, it has botched that too.&nbsp;</p>

<p class="wp-block-paragraph">OpenAI’s latest attempt to repair fractured relations with a mathematical community it has <a href="https://www.theverge.com/ai-artificial-intelligence/994255/openai-millennium-prize-problem-tristan-buckmaster-competition">repeatedly</a> <a href="https://www.theverge.com/ai-artificial-intelligence/977273/the-ai-takeover-of-mathematics-has-begun">alienated</a> is to <a href="https://www.theverge.com/ai-artificial-intelligence/999167/openai-elite-mathematicians-panel">consult</a> a new independent advisory group of elite practitioners. But mathematicians speaking to <em>The Verge</em>, including one of the group’s members, describe a messy and confusing affair bearing many of the hallmarks of OpenAI’s previous rushed forays into mathematics, suggesting the company has learned little from its mistakes. And then there’s the daunting task the group has been handed first: helping coordinate the release of scores more results OpenAI says its unreleased model has produced, the prospect of which is already stirring dread among researchers over what this looming tidal wave of breakthroughs could do to their field.</p>

<figure class="wp-block-pullquote"><blockquote><p>“The way they phrased their announcement didn’t really help.”</p></blockquote></figure>

<p class="wp-block-paragraph">On September 21st, an assortment of eminent mathematicians announced the formation of the Advisory Group on Mathematics and Artificial Intelligence (<a href="https://agmai.org/">AGMAI</a>) in a <a href="https://terrytao.wordpress.com/2026/09/21/advisory-group-on-mathematics-and-artificial-intelligence/">guest post</a> on the blog of UCLA mathematics professor Terence Tao, a Fields Medalist and outspoken critic of AI companies’ conduct in mathematics. The group was to be an independent body of nine elite mathematicians at the very top of their field. The post said the group will operate independently from OpenAI and advise it and other frontier AI labs “on the review and communication of emerging results.” In its own <a href="https://openai.com/index/advisory-group-on-mathematics-and-ai/">announcement</a>, OpenAI repeatedly stressed the group’s independence, saying members would be free to challenge the company publicly, publish their advice, and offer guidance it had not requested. It also stressed the limits of the group’s influence, noting that it “will not be responsible for advising us on how to pace our internal progress on mathematics.”</p>

<p class="wp-block-paragraph">But many mathematicians, and certainly most people outside of that community, learned about that group only through OpenAI’s much louder rollout.</p>

<p class="wp-block-paragraph">The result was widespread confusion over whether AGMAI was truly independent or if it was, as several mathematicians <em>The Verge</em> spoke to in the days after the announcement assumed, some kind of OpenAI-appointed body. That impression wasn’t entirely unreasonable, given AGMAI’s website says it formed after OpenAI approached some of its eventual members about establishing an advisory board, before they decided to strike out independently and invite others to join. It remains unclear which of the nine members OpenAI initially approached.&nbsp;</p>

<p class="wp-block-paragraph">Speaking to <em>The Verge</em> on a video call from a lecture theater, Martin Hairer, an AGMAI member and mathematics professor at Imperial College London and the Swiss Federal Institute of Technology in Lausanne (EPFL), was keen to stress the group’s independence from OpenAI. While acknowledging that OpenAI approaching some mathematicians was the original impetus for its formation, he said the group receives no financial, technical, or other support from the company, and that none of its members have signed agreements restricting what they can say or do beyond standard confidentiality requirements needed to give them advanced access to research.&nbsp;</p>

<p class="wp-block-paragraph">It’s clearly been a hectic time for Hairer, who described the preceding few days as a “very frustrating” and “intense” experience. “We don’t work for OpenAI, are not paid by them, and it’s totally independent,” he said. Hairer said the group is equally open to working with other frontier AI labs and had already begun conversations with some, though he declined to say which.&nbsp;</p>

<figure class="wp-block-pullquote"><blockquote><p>Solutions are often less important than the understanding that comes with them. In human mathematics, the two have traditionally gone hand in hand, and AI seems to be changing that.</p></blockquote></figure>

<p class="wp-block-paragraph">Nevertheless, Hairer seemed exasperated by the way OpenAI had announced the relationship. In a <a href="https://proofsandprompts.com/2026/09/22/why-i-agreed-to-join-agmai/">blog post</a> published amid the ensuing uproar, Hairer acknowledged it would be naive to think AI companies wouldn’t try to spin the group’s involvement to their advantage. Given the group had emerged partly in light of OpenAI’s <a href="https://www.theverge.com/ai-artificial-intelligence/994255/openai-millennium-prize-problem-tristan-buckmaster-competition">atrocious handling</a> of <a href="https://www.theverge.com/ai-artificial-intelligence/977273/the-ai-takeover-of-mathematics-has-begun">previous mathematical breakthroughs</a>, that risk was front and center. OpenAI’s <a href="https://www.theverge.com/ai-artificial-intelligence/992953/openai-math-millennium-prize-navier-stokes">solution</a> to a prestigious Millennium Prize problem rapidly descended into fights over credit, scooping, and its treatment of mathematicians, so the community was naturally suspicious.&nbsp;</p>

<p class="wp-block-paragraph">Hairer acknowledged that OpenAI’s announcement had done little to help the fledgling group establish its independence. AGMAI needs to win the trust of mathematicians in order to help them navigate an increasingly fraught relationship with AI companies. “The way they phrased their announcement didn’t really help,” Hairer said. “If you read it exactly in detail, there’s nothing wrong in what they say,” he said, noting that the company is “careful” in its wording. “They obviously are very good PR people,” he said, laughing.&nbsp;</p>

<p class="wp-block-paragraph">The whole endeavor — the announcement, the group’s formation, its communications with the mathematical community — feels as if it came together in a hurry. Asked last Wednesday about AGMAI’s plans, Hairer laughed and said, “So we, well, you know, started two days ago. So it’s not like we have a big master plan.”  </p>

<p class="wp-block-paragraph">That urgency might be down to the fact that OpenAI is sitting on a tranche of results it is clearly eager to release as soon as possible. Since solving the Navier-Stokes Millennium Prize problem, OpenAI says its unreleased internal “model has now resolved more than 100 long-standing open problems across most areas of mathematics.”</p>

<p class="wp-block-paragraph">Avoiding another PR disaster is why OpenAI went to the trouble of trying to assemble a team of some of the world’s best mathematicians to consult. But trumpeting the sheer number of results it has waiting in the wings while promising to handle them responsibly only underscores how much of a mathematical outsider OpenAI is.&nbsp;</p>

<p class="wp-block-paragraph">“This is not how any academic behaves,” said Álvaro Lozano-Robledo, a professor of mathematics at University of Connecticut. “I don&#8217;t go around saying, like, ‘Oh, I&#8217;ve proved all these things, but I don&#8217;t know what to do with them.’”&nbsp;</p>

<p class="wp-block-paragraph">He sees a similar disconnect in other OpenAI pronouncements, such as when OpenAI’s Laurance Fauconnet told <em>The Verge</em> the company had “made substantial progress” on another Millennium Prize problem. “No mathematician would go out and say that,” Lozano-Robledo said. “You either have solved it, or you’re still trying.”&nbsp;</p>

<p class="wp-block-paragraph">Lozano-Robledo said he hopes engaging with AGMAI is a serious attempt by OpenAI to address mathematicians&#8217; concerns, but stressed that doing so means it should be a responsible member of the research community. That requires more than simply dropping results into the world and moving on, as many mathematicians believe it has done with its most recent findings. Researchers <em>The Verge</em> spoke to complained of poorly written manuscripts and scant engagement with the literature surrounding a finding, all of which makes it difficult to understand a result’s significance and leaves key work without the appropriate credit. At times, the company had quietly changed documents to shore up shortcomings after they were released, but didn’t announce changes or leave a clear record of what was altered. <em>The Verge</em> <a href="https://www.theverge.com/ai-artificial-intelligence/977273/the-ai-takeover-of-mathematics-has-begun">noticed</a> this when the company announced “Ten advances in mathematics and theoretical computer science” in early August, and Hairer separately described times when it felt like the company altered manuscripts “sneakily” in response to criticism. “That also makes people paranoid, right?” Hairer said, describing it as “shoddy” and “really bad and sloppy scholarship.”</p>

<p class="wp-block-paragraph">As with AI slop elsewhere, the people creating it are rarely the ones paying the costs for dealing with it. Lozano-Robledo described the deluge of AI-generated math solutions as a “burden” on the community — one he thinks AI companies fundamentally misunderstand. “The burden is that they are producing a solution,” he said, but solutions are often less important than the understanding that comes with them. In human mathematics, the two have traditionally gone hand in hand, and AI seems to be changing that. </p>

<figure class="wp-block-pullquote"><blockquote><p>“So we, well, you know, started two days ago. So it’s not like we have a big master plan.”  </p></blockquote></figure>

<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p class="wp-block-paragraph"></p>
</blockquote>

<p class="wp-block-paragraph">AI companies may be producing impressive results, but they still need human mathematicians to work out how important a result actually is. “They need our expertise,” Lozano-Robledo said. “They need us to celebrate that solution.”</p>

<p class="wp-block-paragraph">For other mathematicians <em>The Verge</em> spoke to, that burden is much more personal. For weeks now, OpenAI has been hinting at another Millennium Prize problem and says it has more than 100 results to apparently major problems ready to go, while revealing little about what any of these actually are. After the upheaval surrounding past announcements, <a href="https://www.theverge.com/ai-artificial-intelligence/994255/openai-millennium-prize-problem-tristan-buckmaster-competition">Navier-Stokes in particular</a>, that uncertainty has created a tense atmosphere. Many researchers expressed fear that a problem or area of work to which they have devoted years, even decades, of their professional lives could be next on the chopping block, abruptly dispatched by a company they suspect is doing it as a publicity stunt on the way to an IPO.&nbsp;</p>

<p class="wp-block-paragraph">“They are just feeding the paranoia of what they could possibly have proved,” said Lozano-Robledo, accusing the company of “feeding the frenzy” and increasing dread among many mathematicians that their area of work could be disrupted next. “Like, what other Millennium problem are they talking about when they say ‘We have almost solved another Millennium problem’? That sentence makes no sense in mathematics.” The researcher stressed that such grandstanding is simply not how mathematics is usually done.&nbsp;</p>

<p class="wp-block-paragraph">For Colva Roney-Dougal, a mathematics professor at the University of St Andrews in Scotland, the uncertainty surrounding OpenAI is already having a profound effect on how she thinks about her work. “It’s somewhat agonizing to know that a ‘large number’ of results are likely to be announced soon,” she said. “The more there are, the more likely it becomes that my ongoing work, or that of my students, suddenly becomes irrelevant.”</p>

<p class="wp-block-paragraph">The rapid pace of development has left Roney-Dougal at a peculiar sort of scholarly crossroads: “I am therefore unclear whether I should be trying to rush out as many papers as possible, or passively waiting to see what these results are, or carrying on as normal,” she said.&nbsp;</p>

<p class="wp-block-paragraph">Hairer is well aware of this kind of anxiety. He said the potential disruption to researchers was one of the reasons why he added his name to a roster <a href="https://mathandai.org/">of Fields Medalists</a> trying to address what they described as the “severely misaligned” goals of AI companies and the mathematical community. He is also aware that OpenAI may spin the involvement of him and other prominent AGMAI members to its advantage, particularly with the general public.&nbsp;</p>

<p class="wp-block-paragraph">Let them, he said. “They’re not going to sort of damage me within the math community,” Hairer said. “In some sense, I don&#8217;t really care about what they say. But what I do worry about is the math community as a whole.”</p>

<p class="wp-block-paragraph"></p>
						]]>
									</content>
			
					</entry>
			<entry>
			
			<author>
				<name>Robert Hart</name>
			</author>
			
			<title type="html"><![CDATA[One company is at the center of a wave of rogue AI attacks]]></title>
			<link rel="alternate" type="text/html" href="https://www.theverge.com/ai-artificial-intelligence/1000644/irregular-rogue-ai-cyberattacks-hacking-openai-meta-anthropic-google" />
			<id>https://www.theverge.com/?p=1000644</id>
			<updated>2026-09-25T12:51:08-04:00</updated>
			<published>2026-09-25T11:39:48-04:00</published>
			<category scheme="https://www.theverge.com" term="AI" /><category scheme="https://www.theverge.com" term="Report" /><category scheme="https://www.theverge.com" term="Tech" />
							<summary type="html"><![CDATA[In July, OpenAI revealed that its AI agents had attacked Hugging Face without permission, sparking widespread concerns about AI safety. Since then, a string of similar incidents involving agents from Meta, Anthropic, Google, and other companies has fueled further fears about rogue AI. As disclosures implicating numerous AI models trickled out over the past few [&#8230;]]]></summary>
			
							<content type="html">
											<![CDATA[

						
<figure>

<img alt="" data-caption="" data-portal-copyright="Image: The Verge" data-has-syndication-rights="1" src="https://platform.theverge.com/wp-content/uploads/sites/2/2026/09/STKS533_AI_AGENTS_HACKING_A-1.png?quality=90&#038;strip=all&#038;crop=0,0,100,100" />
	<figcaption>
		</figcaption>
</figure>
<p class="wp-block-paragraph">In July, OpenAI revealed that its AI agents had <a href="https://www.theverge.com/ai-artificial-intelligence/987566/ai-civilizations-opeai-hugging-face-hack">attacked Hugging Face without permission</a>, sparking widespread concerns about <a href="https://www.theverge.com/ai-artificial-intelligence/972380/open-ai-hugging-face-hack-ai-safety-warning">AI safety.</a> Since then, a <a href="https://www.theverge.com/column/980337/rogue-ai-science-fiction-openai">string of similar incidents</a> involving agents from Meta, Anthropic, Google, and other companies has <a href="https://www.theverge.com/ai-artificial-intelligence/996563/ai-safety-research-metr-redwood-openai-anthropic">fueled further fears about rogue AI</a>. As disclosures implicating numerous AI models trickled out over the past few months, these seemed like separate incidents. But many share a common source: one specific company tasked with testing the agents.&nbsp;</p>

<p class="wp-block-paragraph"><a href="https://www.irregular.com/about">Irregular</a>, an Israeli startup that stress-tests AI models in “high-fidelity research platforms that simulate and monitor real-world AI security scenarios,” has worked with many of the industry’s biggest players since it was founded as Pattern Labs in 2023. Its exact client list is not known, but its work has been cited in OpenAI <a href="https://cdn.openai.com/gpt-5-system-card.pdf">model system cards</a>, it was <a href="https://finance.yahoo.com/news/irregular-raises-80-million-set-121500443.html">used to test systems</a> for the UK government and Anthropic, and it <a href="https://www.rand.org/pubs/research_reports/RRA2849-1.html">published</a> research with RAND, a highly influential think tank that informs policy on AI.</p>

<p class="wp-block-paragraph">In several Irregular tests this year, agents escaped their supposedly secure testing environments and went after real-world targets.</p>

<p class="wp-block-paragraph">The breaches, which are independent of the Hugging Face hack, all follow the same broad template: Irregular was testing the models’ cybersecurity capabilities in controlled environments meant to simulate realistic conditions. Some of the tests used “capture-the-flag” exercises, a common way of testing hacking abilities that asks agents to find hidden information inside of a simulated network. At least, the network is meant to be simulated.</p>

<p class="wp-block-paragraph">Irregular CTO and cofounder Omer Nevo told <em>The Verge</em> that the agents were not supposed to have access to the open internet, but that “internet access was unintentionally available.” At the same time, Nevo said a fictional company name created for the simulation as a target “overlapped with a real domain.” Put together, those mistakes sent the agents after real-world targets, though it’s not clear which companies or organizations were actually attacked.</p>

<figure class="wp-block-pullquote"><blockquote><p>“All the incidents involving Irregular stemmed from the same underlying issue in a single evaluation scenario and have been disclosed.”</p></blockquote></figure>

<p class="wp-block-paragraph">Nevo confirmed to <em>The Verge </em>that this same issue was behind incidents involving models from <a href="https://www.theverge.com/ai-artificial-intelligence/972441/openai-rogue-ai-agent-hacked-more-than-hugging-face">OpenAI</a>, <a href="https://www.theverge.com/ai-artificial-intelligence/976040/now-metas-ai-agents-are-going-rogue">Meta</a>, <a href="https://www.theverge.com/ai-artificial-intelligence/973670/anthropic-claude-hacked-organizations-during-cyber-tests">Anthropic</a>, and <a href="https://www.theverge.com/ai-artificial-intelligence/997795/google-gemini-rogue-ai-hack">Google</a>. “All the incidents involving Irregular stemmed from the same underlying issue in a single evaluation scenario and have been disclosed,” he said. “Other security incidents which have been reported recently across the industry are unrelated to Irregular or to our evaluations.” This includes the Hugging Face hack and <a href="https://www.theverge.com/ai-artificial-intelligence/975577/aisi-openai-anthropic-agent-hacking">breaches from the UK’s AI Security Institute</a>.</p>

<p class="wp-block-paragraph">“Disclosed” does not necessarily mean made public, though, and it’s unclear whether Nevo was referring to informing Irregular’s clients, the public, or someone else. While the incidents all stemmed from the same underlying testing failure, reports from <a href="https://www.anthropic.com/news/investigating-incidents-cybersecurity-evals">Anthropic</a> and <a href="https://openai.com/index/third-party-cyber-evaluations-involving-openai-models/">OpenAI</a>, along with <a href="https://www.wsj.com/tech/ai/gemini-hacked-three-companies-in-first-known-breakout-by-googles-ai-5c0baba2">reporting</a> on Google, indicate the tech companies were notified at roughly similar times in late July. OpenAI and Anthropic announced the breaches themselves, while the incidents involving Meta and, weeks later, Google first became public through media reports.&nbsp;</p>

<p class="wp-block-paragraph">Irregular’s cybersecurity testing goes beyond the four US tech giants. Research published on its website indicates it has also <a href="https://www.irregular.com/research/assessing-glm-5.2-against-offensive-security-benchmarks">conducted</a> <a href="https://www.irregular.com/research/assessing-kimi-k3-against-offensive-security-benchmarks">similar</a> cybersecurity testing on Kimi K3 and GLM-5.2, <a href="https://www.theverge.com/ai-artificial-intelligence/971444/how-chinese-open-weight-ai-models-impact-us-companies">open AI models</a> from <a href="https://www.theverge.com/ai-artificial-intelligence/967781/chinese-ai-models-open-source-moonshot-kimi-k3-alibaba-qwen">Chinese companies</a> Moonshot AI and Z.ai, respectively. Unlike the proprietary models involved in the other incidents — Meta has kept its flagship Spark model proprietary — these models can be freely downloaded and run on users’ own hardware, meaning testers like Irregular don’t have to rely on the companies for access or send data back to them. Irregular’s research describes them as “self-hosted” instances.&nbsp;</p>

<figure class="wp-block-pullquote"><blockquote><p>“Disclosed” does not necessarily mean made public.</p></blockquote></figure>

<p class="wp-block-paragraph">The evaluations of the Chinese models did not result in similar real-world incidents, Nevo said:&nbsp;“We did not observe the same type of issue described in the incidents referenced here during our evaluations of GLM or Kimi.” However, Nevo cautioned that this “observation alone should not be interpreted as evidence that these models are less susceptible to this kind of behavior.” Neither Moonshot nor Z.ai responded to <em>The Verge</em>’s request for comment.</p>

<p class="wp-block-paragraph">Nevo said the incidents have prompted changes at Irregular. &#8220;We have tightened internet access controls, expanded monitoring and manual review, and strengthened checks before evaluations begin to verify that access matches the intended scope,” he said. “We have also improved how we document and agree on each evaluation’s setup and parameters with our partners.”</p>

<p class="wp-block-paragraph">Irregular also plans to publish a broader report “covering lessons learned and practices for conducting cyber evaluations safely” once that joint work with the companies involved is complete, Nevo said. “Our work with partners aims to turn lessons from these incidents into public shared practices for developing and evaluating increasingly powerful AI safely.”&nbsp;</p>

<div class="wp-block-vox-media-highlight vox-media-highlight">
<h2 class="wp-block-heading">Are you an AI safety researcher or frontier lab employee?</h2>



<p class="has-text-align-none wp-block-paragraph">You can contact me securely and confidentially via Signal at robhart.01</p>
</div>

<p class="wp-block-paragraph">Nevo said Irregular has addressed the issues with the testing environment that were linked to the incidents. None of the four US AI companies answered questions asking for further details — including when they became aware of the breaches, whether they were seeking damages or other remedies from Irregular, and whether they expected to continue working with the Irregular. Google and Anthropic did not respond, while OpenAI and Meta pointed <em>The Verge</em> to <a href="https://openai.com/index/third-party-cyber-evaluations-involving-openai-models/">previously</a> <a href="https://research.meta.ai/blog/addressing-third-party-testing-misconfiguration-muse-spark-1-1">published</a> blog posts.&nbsp;</p>
						]]>
									</content>
			
					</entry>
			<entry>
			
			<author>
				<name>Robert Hart</name>
			</author>
			
			<title type="html"><![CDATA[Why can’t we just keep rogue AIs off the internet?]]></title>
			<link rel="alternate" type="text/html" href="https://www.theverge.com/ai-artificial-intelligence/999881/why-cant-we-airgap-rogue-ai-agents" />
			<id>https://www.theverge.com/?p=999881</id>
			<updated>2026-09-25T12:51:27-04:00</updated>
			<published>2026-09-24T10:30:00-04:00</published>
			<category scheme="https://www.theverge.com" term="AI" /><category scheme="https://www.theverge.com" term="Report" /><category scheme="https://www.theverge.com" term="Tech" />
							<summary type="html"><![CDATA[AI agents keep getting loose, escaping supposedly secure tests to attack real-world targets, commandeer obscure wikis, and leave instructions for other agents to follow. Researchers are testing these systems precisely because they might behave in unpredictable, even dangerous, ways. So wouldn’t it be safer to just keep the agents off the internet? “A strict air [&#8230;]]]></summary>
			
							<content type="html">
											<![CDATA[

						
<figure>

<img alt="" data-caption="" data-portal-copyright="Image: The Verge" data-has-syndication-rights="1" src="https://platform.theverge.com/wp-content/uploads/sites/2/2026/09/STK414_AI_CVIRGINIA_2_C-2.jpg?quality=90&#038;strip=all&#038;crop=0,0,100,100" />
	<figcaption>
		</figcaption>
</figure>
<p class="wp-block-paragraph">AI agents <a href="https://www.theverge.com/ai-artificial-intelligence/999874/openai-agents-hacked-an-australian-government-website-in-search-for-data">keep getting loose</a>, escaping supposedly secure tests to <a href="https://www.theverge.com/column/980337/rogue-ai-science-fiction-openai">attack real-world targets</a>, <a href="https://www.theverge.com/ai-artificial-intelligence/990149/openai-rogue-agents-german-wiki">commandeer obscure wikis</a>, and <a href="https://www.theverge.com/ai-artificial-intelligence/987566/ai-civilizations-opeai-hugging-face-hack">leave instructions for other agents</a> to follow. Researchers are testing these systems precisely because they might behave in unpredictable, even dangerous, ways. So wouldn’t it be safer to just keep the agents off the internet?</p>

<figure class="wp-block-pullquote"><blockquote><p>“A strict air gap reduces realism &#8230; [It&#8217;s a] trade-off, not a fundamental technical issue.”</p></blockquote></figure>

<p class="wp-block-paragraph">In theory, yes. Researchers can isolate the computers running AI tools from the internet and other outside networks, a technique known as air gapping. That can mean physically removing or disabling cables and wireless hardware and using “dumb” peripherals, with particularly sensitive setups using Faraday cages or other shielding to block electromagnetic signals from getting in or out. Done properly, an air-gapped system would offer agents no straightforward route to external targets, or outside systems any straightforward route in, making it much harder, if not impossible, to pull off attacks like the one OpenAI’s models <a href="https://www.theverge.com/ai-artificial-intelligence/972380/open-ai-hugging-face-hack-ai-safety-warning">launched against Hugging Face</a>.&nbsp;&nbsp;</p>

<p class="wp-block-paragraph">But in practice, a perfectly sealed box makes for a rather limited laboratory, particularly when the aim is to assess how an AI will perform in the real world. While some AI experiments can be run on air-gapped machines, realistic evaluations often require access to external services, APIs, and digital infrastructure, explained Thorsten Holz, a scientific director at the Max Planck Institute for Security and Privacy in Germany. “A strict air gap reduces realism,” he said, describing the decision to air gap as a “trade-off, not a fundamental technical issue.”</p>

<p class="wp-block-paragraph">Ruizhe Li, an assistant professor in the school of computer science at the University of Birmingham in the UK, likened complete isolation to testing AI in an “artificial vacuum,” potentially undermining the value of the evaluation itself. “We will end up testing a neutered AI model, which blinds evaluators to how the AI model behaves, fails, or executes tool-use exploits in realistic deployment settings,” Li said.&nbsp;</p>

<p class="wp-block-paragraph">Realism isn’t the only tradeoff. Li said air gapping is costly and can slow research to an absolute crawl, turning what would be quick iterations into “a slow logistics hurdle.” Some experiments also become “substantially harder” under a strict air gap, Holz said. That friction may be justified for risky experiments, but applying it for everything would slow down the development of new models, said Maksym Andriushchenko, a principal investigator at the ELLIS Institute Tübingen in Germany.&nbsp;</p>

<p class="wp-block-paragraph">And even if researchers wanted to air gap everything, Andriushchenko questioned whether enough secure infrastructure exists to do it at the scale of frontier AI labs.</p>

<figure class="wp-block-pullquote"><blockquote><p>&nbsp;“This all sounds very sci-fi, but is theoretically possible.”</p></blockquote></figure>

<p class="wp-block-paragraph">It would not eliminate every risk posed by AI, either. Agents could still compromise systems inside of the isolated environment, Holz said, and could theoretically produce “malicious artifacts that could be dangerous if moved outside.” Moreover, air gapping “does nothing to diagnose or resolve the latent risks waiting inside the model,” Li said.</p>

<p class="wp-block-paragraph">There’s also no guarantee that an air gap would remain completely sealed. Someone from the outside could always breach the gap, as happened with <a href="https://nuclearnetwork.csis.org/the-cyber-threat-to-nuclear-facilities/">Stuxnet malware</a> — a cyberweapon <a href="https://www.washingtonpost.com/world/national-security/stuxnet-was-work-of-us-and-israeli-experts-officials-say/2012/06/01/gJQAlnEy6U_story.html">reportedly</a> <a href="https://www.bbc.co.uk/news/technology-12633240">developed</a> by Israel and the US to sabotage Iran’s nuclear program — which was transmitted via a USB drive. Information may travel in the other direction, too. <a href="https://arxiv.org/abs/1503.07919">Researchers</a> have <a href="https://thehackernews.com/2018/02/airgap-computer-hacking.html">repeatedly</a> <a href="https://www.sophos.com/en-us/blog/air-gap-security-beaten-by-turning-pc-capacitors-into-speakers">demonstrated</a> ways of turning internal computer components into transmitters, which could be a problem if shielding is not perfect. “This all sounds very sci-fi, but is theoretically possible,” Andriushchenko said.&nbsp;</p>

<p class="wp-block-paragraph">That sort of convoluted escape route has become a focal point for online discussions about whether an advanced AI could escape containment. OpenAI researcher Noam Brown recently ignited the debate by <a href="https://x.com/firesidealpha/status/2100641742135701983?s=20">suggesting</a> on X that two air-gapped machines could theoretically communicate by manipulating their CPU temperature and reading the changes. &#8220;You could even go as far as to say, ‘Well, we should air gap the computers.’ And I&#8217;m not convinced that that would be sufficient,&#8221; he said. The idea was met with skepticism, and ridicule, on social media, with more generous critics noting the large gap between such a communication method being possible and a pair of AI systems discovering and exploiting it, particularly as the technique would yield painfully slow data transmission speeds.&nbsp;&nbsp;&nbsp;</p>

<p class="wp-block-paragraph">A sufficiently advanced AI might not need to resort to an elaborate escape route. Humans may become convinced to bridge the gap for it. AI safety researchers have <a href="https://arxiv.org/abs/1707.08476">worried</a> about such a possibility for years, and recent incidents have provided <a href="https://www.theverge.com/ai-artificial-intelligence/975577/aisi-openai-anthropic-agent-hacking">concrete evidence</a> that models can engage in attempts at social engineering.&nbsp;</p>

<figure class="wp-block-pullquote"><blockquote><p>“This tradeoff deserves much greater scrutiny, and we have seen how easily things can go wrong.”</p></blockquote></figure>

<p class="wp-block-paragraph">Air gapping is but one means of safeguarding AI systems. “Relying on isolation as a blanket safety solution creates a false sense of security,” Li said. It should be used alongside other measures, like understanding the inner workings of models, ensuring they are aligned, and guarding against human error, the mundane point of failure behind many recent rogue AI incidents. “In practice, testing exists on a spectrum,” he explained, with the field relying on a “tiered containment model rather than an all-or-nothing approach.”&nbsp;&nbsp;</p>

<p class="wp-block-paragraph">Extreme isolation does have its place, though. Stephen Casper, a computer scientist and assistant professor of public policy at the Harvard Kennedy School, described air gapping as a “great idea” for sensitive systems, pointing to its use in nuclear facilities. While not ruling out the possibility that an advanced AI could find some novel way to escape, Casper said at that point we should probably be more worried about prosaic means of breaking containment, such as compliance failures or human error.</p>

<p class="wp-block-paragraph"><a href="https://www.theverge.com/ai-artificial-intelligence/999874/openai-agents-hacked-an-australian-government-website-in-search-for-data">Recent</a> <a href="https://www.theverge.com/ai-artificial-intelligence/994383/openais-rogue-ai-rubygems-hack">incidents</a> <a href="https://www.theverge.com/ai-artificial-intelligence/972380/open-ai-hugging-face-hack-ai-safety-warning">raise questions</a> over where AI labs are <a href="https://www.theverge.com/ai-artificial-intelligence/982323/openai-hit-brakes-voluntary-pacing-ai">drawing that line</a>. Many <a href="https://www.theverge.com/ai-artificial-intelligence/972441/openai-rogue-ai-agent-hacked-more-than-hugging-face">breaches</a> <a href="https://www.theverge.com/ai-artificial-intelligence/973670/anthropic-claude-hacked-organizations-during-cyber-tests">involved</a> models being tested for their <a href="https://www.theverge.com/ai-artificial-intelligence/985385/openais-rogue-ai-model-hugging-face-cybersecurity-incident-reports-metr">cybersecurity abilities</a>, and in many respects they <a href="https://www.theverge.com/column/980337/rogue-ai-science-fiction-openai">performed exactly as designed</a>. The problem was that they did so outside of the boundaries researchers intended to set.&nbsp;</p>

<p class="wp-block-paragraph">Holz said AI “evaluations often prioritize realism and convenience,” but argued agents explicitly designed for offensive cyber capabilities warrant tighter safeguards, potentially including strong isolation and strict monitoring as a default. “This tradeoff deserves much greater scrutiny, and we have seen how easily things can go wrong,” he said.</p>
						]]>
									</content>
			
					</entry>
			<entry>
			
			<author>
				<name>Robert Hart</name>
			</author>
			
			<title type="html"><![CDATA[OpenAI agents hacked an Australian government website in search of data ]]></title>
			<link rel="alternate" type="text/html" href="https://www.theverge.com/ai-artificial-intelligence/999874/openai-agents-hacked-an-australian-government-website-in-search-for-data" />
			<id>https://www.theverge.com/?p=999874</id>
			<updated>2026-09-24T12:52:40-04:00</updated>
			<published>2026-09-24T07:52:32-04:00</published>
			<category scheme="https://www.theverge.com" term="AI" /><category scheme="https://www.theverge.com" term="News" /><category scheme="https://www.theverge.com" term="OpenAI" /><category scheme="https://www.theverge.com" term="Tech" />
							<summary type="html"><![CDATA[OpenAI’s artificial intelligence agents hacked an Australian government website and attempted to breach numerous other government and university websites. The attack appears to be the first confirmed instance of a rogue AI agent breaching a government website, adding fuel to rapidly intensifying concerns about the safety of advanced AI systems and the responsibility of the [&#8230;]]]></summary>
			
							<content type="html">
											<![CDATA[

						
<figure>

<img alt="" data-caption="Sam Altman attends a UN Security Council meeting on AI. | Getty Images" data-portal-copyright="Getty Images" data-has-syndication-rights="1" src="https://platform.theverge.com/wp-content/uploads/sites/2/2026/09/gettyimages-2296796582.jpg?quality=90&#038;strip=all&#038;crop=0,0,100,100" />
	<figcaption>
	Sam Altman attends a UN Security Council meeting on AI. | Getty Images	</figcaption>
</figure>
<p class="wp-block-paragraph">OpenAI’s artificial intelligence agents hacked an Australian government website and attempted to breach numerous other government and university websites. The attack appears to be the first confirmed instance of a rogue AI agent breaching a government website, adding fuel to rapidly intensifying concerns about the safety of advanced AI systems and the responsibility of the companies building them.&nbsp;</p>

<p class="wp-block-paragraph">Speaking on the sidelines of the UN General Assembly in New York, Australian Prime Minister Anthony Albanese <a href="https://x.com/AlboMP/status/2102891827536032037?s=20">said</a> an agent from the American AI lab “infiltrated” Australia’s Medicare statistics portal and “accessed both public and non-public files.” Medicare is Australia’s universal health insurance program.</p>

<p class="wp-block-paragraph">Albanese <a href="https://www.pm.gov.au/media/press-conference-new-york">said</a> personal information does not appear to have been accessed in the breach and that there is no evidence of a broader compromise to the network, but noted “investigations are ongoing.”&nbsp;</p>

<p class="wp-block-paragraph">“This situation is obviously unacceptable,” Albanese said, adding that he had spoken with OpenAI CEO Sam Altman “to express Australia&#8217;s extreme concern.” Despite the breach happening in June, Albanese said the tech giant only notified the government about the incident earlier this month and did so via an email to a generic “public mailbox.”&nbsp;</p>

<p class="wp-block-paragraph">Unlike previous agent incidents, which largely involved systems being tested for their cybersecurity skills, these latest hacks were the result of a more pedestrian task — data collection — going wrong. In a statement to <em>The Verge</em>, OpenAI spokesperson Oscar Haines said the models were attempting to “look up answers” during an internal evaluation. “In the course of that, our models took actions we did not intend.”</p>

<p class="wp-block-paragraph">The timeline of the incident and its disclosure is likely to prove particularly inflammatory in the discussions of corporate behavior and transparency that follow. Albanese stressed the delay in disclosure is particularly unacceptable. OpenAI <a href="https://www.bbc.co.uk/news/articles/c6vgy0333dppo">told</a> the <em>BBC</em> in an unattributed statement that it did not become aware until August, when reviewing misaligned model activity.&nbsp;</p>

<p class="wp-block-paragraph">OpenAI spokesperson Oscar Haines told <em>The Verge </em>the company’s “review found no evidence of patient records being accessed,” and that “the information accessed included aggregate health statistics and internal file names.” Haines said OpenAI has notified the relevant organizations and is providing technical information to support their investigations and address potential security vulnerabilities. “Our overall review is ongoing, and we remain committed to transparency about these issues and to sharing what we learn as that work continues,” Haines said.&nbsp;</p>

<p class="wp-block-paragraph">Three further incidents of rogue AI activity linked to OpenAI agents were also <a href="https://transluce.org/agent-activity">reported</a> on Wednesday by research lab Transluce. The group, which describes itself as a “nonprofit research lab dedicated to public oversight” of AI, said it had identified evidence that OpenAI’s systems had attempted to compromise websites linked to the University of New Mexico, the Australian Institute of Health and Welfare, and Data USA, a non-government platform that aggregates data from US government sources. It said the last two of these were <a href="https://www.theverge.com/ai-artificial-intelligence/990773/openai-german-wiki-incident">directly linked to an agent swarm OpenAI has previously admitted</a> originated from them.</p>

<p class="wp-block-paragraph">Haines confirmed the incidents in a statement to <em>The Verge </em>and said the company had reached out to those involved. “Our initial review suggests that much of the activity described in Transluce’s report overlaps with cases at varying stages of investigation in our ongoing review of misaligned model activity,” he said. “In our broader review, we’re continuing to prioritize the most serious incidents while expanding our work to lower-severity activity, including agents spamming websites. Given the scale of this work and the need to verify each case, we expect the review to take months.”</p>

<p class="wp-block-paragraph">OpenAI’s handling of the Australian Medicare incident is certain to place notions of corporate responsibility at the center of future discussions surrounding AI, which are <a href="https://www.theverge.com/ai-artificial-intelligence/987566/ai-civilizations-opeai-hugging-face-hack">often obscured with the language used to describe</a> such attacks. OpenAI has already faced allegations of obfuscation for <a href="https://www.theverge.com/ai-artificial-intelligence/990773/openai-german-wiki-incident]">not disclosing similar unsanctioned activity by its agents</a>, and efforts to prioritize investigating what it deems the most serious incidents raise the obvious question of what basis it uses to make such assessments, and how much has yet to be revealed. It echoes similar questions recently raised about Google, which <a href="https://www.theverge.com/ai-artificial-intelligence/997795/google-gemini-rogue-ai-hack">did not disclose</a> real-world attacks from its own agents.&nbsp;</p>

<p class="wp-block-paragraph">The newly revealed breaches come amid mounting concerns about the safety of advanced AI and the reliability of the companies developing it, largely ignited by the <a href="https://www.theverge.com/ai-artificial-intelligence/987566/ai-civilizations-opeai-hugging-face-hack">coordinated attack OpenAI agents launched on Hugging Face</a> earlier this year. Worries over safety have led industry insiders to call for <a href="https://www.theverge.com/ai-artificial-intelligence/996923/ai-safety-slow-openai-anthropic">slowing down the pace of AI development</a> and the global nature of the incidents has sparked <a href="https://www.theverge.com/ai-artificial-intelligence/998090/un-ai-panel-hugging-face-hack-precautionary-principle">significant debate</a> among nations about how to implement stronger safeguards. Eyes will largely remain on the US and China, however, as these are the only two countries operating at the very frontier of the technology. Both appear to be resisting calls to slow down, and seem locked in a race to build the most advanced AI. Leaders from the two countries are set to meet on Thursday.</p>
						]]>
									</content>
			
					</entry>
			<entry>
			
			<author>
				<name>Robert Hart</name>
			</author>
			
			<title type="html"><![CDATA[Anthropic&#8217;s biolab made a discovery it&#8217;s comparing to Crispr]]></title>
			<link rel="alternate" type="text/html" href="https://www.theverge.com/ai-artificial-intelligence/999470/anthropic-biolab-claude-crispr" />
			<id>https://www.theverge.com/?p=999470</id>
			<updated>2026-09-23T13:10:35-04:00</updated>
			<published>2026-09-23T14:00:00-04:00</published>
			<category scheme="https://www.theverge.com" term="AI" /><category scheme="https://www.theverge.com" term="Anthropic" /><category scheme="https://www.theverge.com" term="News" /><category scheme="https://www.theverge.com" term="Science" />
							<summary type="html"><![CDATA[Anthropic says its AI Claude has “autonomously discovered” a new enzyme system similar to machinery behind the powerful gene-editing tool Crispr. It’s the first result from Anthropic’s newly-launched wet lab and an early test of Claude’s usefulness for science as the company prepares to go public.&#160; The company says Claude found the enzyme system after [&#8230;]]]></summary>
			
							<content type="html">
											<![CDATA[

						
<figure>

<img alt="" data-caption="" data-portal-copyright="Image: The Verge" data-has-syndication-rights="1" src="https://platform.theverge.com/wp-content/uploads/sites/2/2026/09/STKB364_CLAUDE_2_C_96d15c-2.jpg?quality=90&#038;strip=all&#038;crop=0,0,100,100" />
	<figcaption>
		</figcaption>
</figure>
<p class="wp-block-paragraph">Anthropic says its AI Claude has “autonomously discovered” a new enzyme system similar to machinery behind the powerful gene-editing tool Crispr. It’s the first result from Anthropic’s <a href="https://www.theverge.com/ai-artificial-intelligence/997809/anthropic-launched-a-biolab">newly-launched wet lab</a> and an early test of Claude’s usefulness for science as the company prepares to go public.&nbsp;</p>

<p class="wp-block-paragraph">The company says Claude found the enzyme system after searching through a massive database of DNA sequences, adding that its scientists’ involvement was limited to the initial prompt and lab work.&nbsp;</p>

<p class="wp-block-paragraph">Over 21 hours, Anthropic said nearly 950 Claude agents worked through 210 million tokens before one spotted an unusual repeating pattern in the dataset and flagged for human review. Further analysis and lab testing revealed “a previously uncharacterized enzyme system found in bacteriophages,” a type of virus that infects bacteria.&nbsp;</p>

<p class="wp-block-paragraph">Anthropic said it is still working to understand what the enzyme system does, but said it felt it was “important to share such findings early, both to demonstrate Claude’s capabilities and to give the broader community insight into what we’re working on.”&nbsp;</p>

<p class="wp-block-paragraph">Despite Anthropic’s comparisons to Crispr, it remains unclear whether the discovery will have any practical applications, let alone be as transformative as the gene-editing technology. The admittedly premature announcement comes as Anthropic seeks to attract more scientists to its lab and expand into areas like <a href="https://www.theverge.com/ai-artificial-intelligence/961311/anthropic-claude-science-ai-drug-development">drug discovery.&nbsp;</a></p>

<p class="wp-block-paragraph">The push comes as AI companies increasingly turn to scientific research to prove the value of their more capable models. OpenAI, meanwhile, has been barreling through increasingly advanced mathematical problems with <a href="https://www.theverge.com/ai-artificial-intelligence/994255/openai-millennium-prize-problem-tristan-buckmaster-competition">little regard</a> for the <a href="https://www.theverge.com/ai-artificial-intelligence/977273/the-ai-takeover-of-mathematics-has-begun">academic norms</a> and traditions of the field.</p>

<p class="wp-block-paragraph"></p>
						]]>
									</content>
			
					</entry>
			<entry>
			
			<author>
				<name>Robert Hart</name>
			</author>
			
			<title type="html"><![CDATA[OpenAI wants to consult elite mathematicians about how to not fumble again]]></title>
			<link rel="alternate" type="text/html" href="https://www.theverge.com/ai-artificial-intelligence/999167/openai-elite-mathematicians-panel" />
			<id>https://www.theverge.com/?p=999167</id>
			<updated>2026-09-22T20:18:27-04:00</updated>
			<published>2026-09-22T20:17:17-04:00</published>
			<category scheme="https://www.theverge.com" term="AI" /><category scheme="https://www.theverge.com" term="OpenAI" />
							<summary type="html"><![CDATA[After turning a string of spectacular mathematical results into a reputational crisis, OpenAI is consulting human mathematicians to help it figure out a less disastrous path forward. On Monday, the company announced a new independent panel of mathematicians tasked with advising it and other AI companies on their interactions with mathematical research and the wider [&#8230;]]]></summary>
			
							<content type="html">
											<![CDATA[

						
<figure>

<img alt="" data-caption="" data-portal-copyright="Bloomberg via Getty Images" data-has-syndication-rights="1" src="https://platform.theverge.com/wp-content/uploads/sites/2/2026/09/gettyimages-2294952541.jpg?quality=90&#038;strip=all&#038;crop=0,0,100,100" />
	<figcaption>
		</figcaption>
</figure>
<p class="wp-block-paragraph">After turning a string of spectacular mathematical results into a <a href="https://www.theverge.com/ai-artificial-intelligence/992953/openai-math-millennium-prize-navier-stokes">reputational crisis</a>, OpenAI is consulting human mathematicians to help it figure out a less disastrous path forward.</p>

<p class="wp-block-paragraph">On Monday, the company <a href="https://openai.com/index/advisory-group-on-mathematics-and-ai/">announced</a> a new independent panel of mathematicians tasked with advising it and other AI companies on their interactions with mathematical research and the wider mathematics community, including how new results are presented and released. Its abrupt arrival caught many mathematicians by surprise. Researchers told <em>The Verge</em> the group is a good first step, but many said they were left with basic questions about what it will actually do, how much influence it will have, and whether OpenAI will actually listen to it, as well as concerns over whether such a small group of prominent researchers can represent the wider mathematical community.&nbsp;</p>

<p class="wp-block-paragraph">The nine-member group is stacked with who researchers described to <em>The Verge</em> as celebrities in the field, drawn from institutions including Stanford, Harvard, Oxford, and Cambridge, with multiple Fields Medals and MacArthur “genius grants” among them. It will be hosted by Princeton, New Jersey’s Institute for Advanced Study (IAS), one of the world’s most revered centers of mathematical research and the former intellectual home of figures including Albert Einstein, John von Neumann, and J. Robert Oppenheimer. </p>

<figure class="wp-block-pullquote"><blockquote><p>“The other fundamental fact is that our overarching aim is to represent as well as we possibly can the interests of the mathematical community.” </p></blockquote></figure>

<p class="wp-block-paragraph">OpenAI said the group, called the Advisory Group on Mathematics and Artificial Intelligence (AGMAI), will operate independently, with the freedom to offer advice the company has not requested, publicly comment on its impact on mathematics, and make its advice public, though it did not provide details on what this may entail. It appears that the group will be granted early access to OpenAI’s research in order to fulfill its task. Members will not be paid by OpenAI and the group can change its membership as it sees fit, OpenAI said. “Its value depends on its members being able to exercise their own judgement and challenge ours,” the company said. “The group will advise on the review and communication of emerging results: they will help OpenAI assess their significance, advise on how to coordinate their dissemination, and advise on academic and professional standards of mathematical research. It will also advise on how our tools can support mathematical research and learning.&#8221;</p>

<p class="wp-block-paragraph">For all the emphasis on independence, it remains unclear how much influence the group will actually have or why it was formed in the first place. Simon Machado, a researcher at ETH Zurich in Switzerland, said the whole thing seemed “shrouded in mystery” and he questioned how the nine members were selected. The group’s <a href="https://agmai.org/">bare-bones website</a> says it “came together after OpenAI approached some of its members about establishing an external advisory board,” but that, following discussions with the company, the mathematicians decided to launch an independent group instead and invite others to join. It’s not clear which members were initially approached by OpenAI or how the remaining members were selected.&nbsp;</p>

<p class="wp-block-paragraph">In a <a href="https://proofsandprompts.com/2026/09/22/why-i-agreed-to-join-agmai/">blog post</a> published Tuesday, advisory group member Martin Hairer elaborated on the group’s origins and the thinking behind it, responding to what he called a “torrent of misinformation” surrounding its formation. “It is obvious that AI has already had a profound impact on mathematical research and raises numerous questions of correct attribution of ideas, priority, human understanding of ideas, etc.,” he wrote, adding that there is no sense in the community “taking a hard ‘ostrich’ approach of simply ignoring the AI labs and refusing to talk to them on principle.”&nbsp;</p>

<p class="wp-block-paragraph">While acknowledging that the group was formed in response to an approach from OpenAI, Hairer stressed that not all of its members had been contacted by the company and that the resulting organization is “genuinely independent of OpenAI and any other of the so-called ‘frontier’ AI labs.” Beyond “obvious confidentiality requirements,” he said members have not signed any restrictive agreements governing what they can say publicly, adding that they receive no financial compensation and are relying on the IAS for technical support.&nbsp;</p>

<p class="wp-block-paragraph">“The other fundamental fact is that our overarching aim is to represent as well as we possibly can the interests of the mathematical community,” wrote Hairer, a professor of mathematics at Imperial College London and the Swiss Federal Institute of Technology in Lausanne (EPFL). While noting that the group is hardly a representative sample of the community, he said he is “absolutely certain that all nine of us take this extremely seriously and are acting in good faith.”</p>

<p class="wp-block-paragraph">However the members were selected, the group currently comprises an elite cadre of academic mathematicians. The small size raises further questions about whether the group has the breadth of expertise required to evaluate everything coming its way, given the highly specialized skills and knowledge required to operate at the frontiers of mathematics.&nbsp;</p>

<p class="wp-block-paragraph">Francesco Fournier-Facio, an incoming mathematics professor at Heriot-Watt University in Scotland, described himself as pretty “ambivalent” about the panel, saying that greater engagement with mathematicians “can only make things better.” But he questioned whether this group fully reflects the community whose work and livelihoods are being upended by OpenAI’s <a href="https://www.theverge.com/ai-artificial-intelligence/994255/openai-millennium-prize-problem-tristan-buckmaster-competition">quest to rack up mathematical trophies</a>. “It feels like an ivory tower,” he told <em>The Verge</em>.</p>

<p class="wp-block-paragraph">Machado similarly questioned whether the group’s members fully understand, or can speak to, the <a href="https://www.theverge.com/ai-artificial-intelligence/977273/the-ai-takeover-of-mathematics-has-begun">concerns of the broader mathematical community</a> when it comes to AI. “They&#8217;re amazing mathematicians, but I don&#8217;t know if they are the people I want to represent me in more political questions,” he said. For mathematicians in their and similarly elite positions, Machado said, “I think that the reality they are facing is very different from the reality that most mathematicians are facing right now.”&nbsp;</p>

<p class="wp-block-paragraph">Whether the group can earn mathematicians’ trust will ultimately determine how effective it will be at containing the fallout from OpenAI’s recent parade of missteps in announcing results and, more importantly, soften the blow for whatever the company is planning to announce next. In his blog, Hairer said members would “be very naïve to believe that the AI labs won’t try to spin whatever we say in a way that suits their PR machine, which dwarfs anything we could possibly come up with.”&nbsp;</p>

<p class="wp-block-paragraph">Nevertheless, Hairer argued it would be hypocritical not to engage now that OpenAI appears to be making an effort, particularly after so many criticized the company’s conduct and poor communications. The group has yet to settle on the advice it intends to provide, he said, but there is a clear problem it is responding to: “It is a fact that AI companies have in recent months been producing some high profile mathematical results and that their publication and dissemination has been falling far short of acceptable mathematical practice, whichever way that is defined.”&nbsp;</p>

<figure class="wp-block-pullquote"><blockquote><p>“We are currently facing the very specific challenge of advising OpenAI on how to coordinate the release of a large number of significant results in mathematics that they report have been produced by their internal model.”</p></blockquote></figure>

<p class="wp-block-paragraph">For now, Hairer said the group is gathering input through conversations with colleagues, a public <a href="https://agmai.org/input/">feedback form</a>, and discussion on <a href="https://proofsandprompts.com/"><em>Proofs and Prompts</em></a>, a blog that has emerged as a key forum for mathematicians reckoning with AI’s impact on the field.&nbsp;</p>

<p class="wp-block-paragraph">But the group’s biggest challenge likely lies ahead. When announcing the advisory group, OpenAI casually dropped the news that its new, unreleased model — the same that resolved the Navier-Stokes Millennium Prize problem — has now “resolved more than 100 long-standing open problems across most areas of mathematics.” It has previously said it is closing in on another Millennium Prize problem. On its website, the group said dealing with this logjam is its first priority: “We are currently facing the very specific challenge of advising OpenAI on how to coordinate the release of a large number of significant results in mathematics that they report have been produced by their internal model.”</p>

<p class="wp-block-paragraph">In part, the new effort at engaging mathematicians is an acknowledgement of the monumental&nbsp; PR disaster its attempt was, in which the company found itself <a href="https://www.theverge.com/ai-artificial-intelligence/993263/where-does-openai-get-mathematics-training-data">fending off accusations of scooping researchers</a>, failing to credit the human work its models built upon, and even stealing from those using its models. Those controversies led many mathematicians to wonder if the company understood — or even respected — the discipline and community it had barreled into.</p>

<p class="wp-block-paragraph">After the last few months and with so much having been written about what mathematicians want, Kevin Buzzard, a mathematics professor at Imperial College London, wondered why OpenAI felt like it needed such an elite body to understand what the community wants. “It wasn’t proofs of hard theorems, it was better understanding of our subject,” he said. “It’s not entirely clear to me that you need a committee of brilliant people to hammer the point home.”</p>
						]]>
									</content>
			
					</entry>
			<entry>
			
			<author>
				<name>Robert Hart</name>
			</author>
			
			<title type="html"><![CDATA[UN says AI safeguards can’t wait for certainty]]></title>
			<link rel="alternate" type="text/html" href="https://www.theverge.com/ai-artificial-intelligence/998090/un-ai-panel-hugging-face-hack-precautionary-principle" />
			<id>https://www.theverge.com/?p=998090</id>
			<updated>2026-09-21T06:18:06-04:00</updated>
			<published>2026-09-21T06:18:06-04:00</published>
			<category scheme="https://www.theverge.com" term="AI" /><category scheme="https://www.theverge.com" term="News" /><category scheme="https://www.theverge.com" term="OpenAI" /><category scheme="https://www.theverge.com" term="Policy" /><category scheme="https://www.theverge.com" term="Politics" />
							<summary type="html"><![CDATA[Governments need to rein in increasingly capable AI agents before their risks are fully understood, a United Nations scientific panel warned in the global organization&#8217;s first major assessment of OpenAI’s hack of Hugging Face earlier this year. The report cements AI’s place on the global diplomatic agenda this week as leaders gather in New York [&#8230;]]]></summary>
			
							<content type="html">
											<![CDATA[

						
<figure>

<img alt="" data-caption="The United Nations logo at the UN headquarters in New York. | Getty Images" data-portal-copyright="Getty Images" data-has-syndication-rights="1" src="https://platform.theverge.com/wp-content/uploads/sites/2/2026/09/gettyimages-2234546269.jpg?quality=90&#038;strip=all&#038;crop=0,0,100,100" />
	<figcaption>
	The United Nations logo at the UN headquarters in New York. | Getty Images	</figcaption>
</figure>
<p class="wp-block-paragraph">Governments need to rein in increasingly capable AI agents before their risks are fully understood, a United Nations scientific panel warned in the global organization&#8217;s first major assessment of OpenAI’s hack of Hugging Face earlier this year.</p>

<p class="wp-block-paragraph">The <a href="https://www.un.org/independent-international-scientific-panel-ai/en/thematic-briefs/ai-agents-misalignment-risks">report</a> cements AI’s place on the global diplomatic agenda this week as leaders gather in New York for the UN General Assembly and the US and China hold talks on AI. Last week, UN secretary general António Guterres <a href="https://apnews.com/article/un-ai-safety-companies-global-coordination-guterres-6ae720a081ce4d5ede35837ca35b8460">called</a> on governments to cooperate on addressing the threats posed by AI, warning that “the world cannot afford a race to the bottom on AI safety.”</p>

<p class="wp-block-paragraph">It is the first thematic brief from the Independent International Scientific Panel on AI, established last year as the UN’s “first global scientific body on Artificial Intelligence.” It calls for much greater attention and resources to manage emerging risks from advanced AI, alongside stronger international coordination on safety and accountability, even as individual countries take different legal approaches.&nbsp;</p>

<p class="wp-block-paragraph">Crucially, the panel says the world does not need to wait for scientists to establish exactly how or why such incidents occur to begin implementing stronger safeguards. Loss-of-control risk, the panel argues, is exactly the kind of problem the precautionary principle was designed to address: “one where potential harm may be catastrophic or irreversible, even as its likelihood remains scientifically uncertain.”&nbsp;</p>

<p class="wp-block-paragraph">The principle, <a href="https://unglobalcompact.org/what-is-gc/mission/principles/principle-7">first enshrined</a> in the 1992 UN Rio Declaration on Environment and Development, says that scientific uncertainty is no excuse for delaying measures against potentially serious or irreversible harm. It has since become influential in environmental and public health policy, particularly in the European Union.&nbsp;</p>

<p class="wp-block-paragraph">Since the Hugging Face hack was first reported, <a href="https://www.theverge.com/column/980337/rogue-ai-science-fiction-openai">incidents have been documented</a> at companies including <a href="https://www.theverge.com/ai-artificial-intelligence/972441/openai-rogue-ai-agent-hacked-more-than-hugging-face">OpenAI</a>, <a href="https://www.theverge.com/ai-artificial-intelligence/973670/anthropic-claude-hacked-organizations-during-cyber-tests">Anthropic</a>, <a href="https://www.theverge.com/ai-artificial-intelligence/997795/google-gemini-rogue-ai-hack">Google</a>, and <a href="https://www.theverge.com/ai-artificial-intelligence/976040/now-metas-ai-agents-are-going-rogue">Meta</a>, including hacks on real-world targets and <a href="https://www.theverge.com/ai-artificial-intelligence/990149/openai-rogue-agents-german-wiki">swarms of agents</a> taking over online messaging boards.</p>

<p class="wp-block-paragraph"></p>
						]]>
									</content>
			
					</entry>
			<entry>
			
			<author>
				<name>Robert Hart</name>
			</author>
			
			<title type="html"><![CDATA[OpenAI just wants to win]]></title>
			<link rel="alternate" type="text/html" href="https://www.theverge.com/ai-artificial-intelligence/994255/openai-millennium-prize-problem-tristan-buckmaster-competition" />
			<id>https://www.theverge.com/?p=994255</id>
			<updated>2026-09-11T19:35:48-04:00</updated>
			<published>2026-09-12T07:00:00-04:00</published>
			<category scheme="https://www.theverge.com" term="AI" /><category scheme="https://www.theverge.com" term="OpenAI" /><category scheme="https://www.theverge.com" term="Tech" />
							<summary type="html"><![CDATA[OpenAI has spent the last few years planting flags across the increasingly difficult terrain in mathematics. This week, it claimed one of its biggest prizes yet: a solution to a legendary Millennium Prize problem. In normal circumstances, this would have been celebrated as a historic achievement. Instead, many mathematicians have watched OpenAI’s relentless advance with [&#8230;]]]></summary>
			
							<content type="html">
											<![CDATA[

						
<figure>

<img alt="A trophy with OpenAI’s logo on it" data-caption="" data-portal-copyright="Image: Cath Virginia / The Verge, Getty Images" data-has-syndication-rights="1" src="https://platform.theverge.com/wp-content/uploads/sites/2/2026/09/268745_OpenAI_just_wants_to_win-_CVirginia.jpg?quality=90&#038;strip=all&#038;crop=0,0,100,100" />
	<figcaption>
		</figcaption>
</figure>
<p class="has-drop-cap wp-block-paragraph">OpenAI has spent the last few years planting flags across the increasingly difficult terrain in mathematics. This week, it claimed one of its biggest prizes yet: a solution to a legendary Millennium Prize problem. In normal circumstances, this would have been celebrated as a historic achievement.</p>

<p class="wp-block-paragraph">Instead, many mathematicians have watched OpenAI’s relentless advance with growing unease. To them, the company appears less like an enthusiastic newcomer than an impossibly well-resourced interloper, charging into problems they have dedicated their lives to studying with little apparent regard for long-standing norms or the consequences for those left in its wake. At the heart of that unease is a sense that OpenAI is doing mathematics for different reasons. Mathematicians want to advance the field. OpenAI wants to win.&nbsp;&nbsp;</p>

<figure class="wp-block-pullquote"><blockquote><p>Mathematics is not normally this dramatic, so how did things get this bad? </p></blockquote></figure>

<p class="wp-block-paragraph">This week, <em>The Verge</em> spoke with more than a dozen mathematicians, including Tristan Buckmaster and Andreas Thom, who are at the center of recent controversies surrounding OpenAI’s work in the field. Even those skeptical of the most serious allegations described a field shaken by the tech giant’s conduct and fearful of what it might do next in its determination to trounce its rivals.</p>

<p class="wp-block-paragraph">Buckmaster has accused OpenAI of failing to adequately explain whether work he did through its tool Codex could have contributed to its recent successes. In a statement to <em>The Verge</em>, OpenAI spokesperson Laurance Fauconnet strenuously denied that material from his prompts had played a role: “We can say categorically that it is impossible for Dr. Buckmaster’s Codex prompts over the last two months to have influenced the system in any way, including training.”</p>

<p class="wp-block-paragraph">Buckmaster remains unconvinced. “Given their behavior up until this point, one should take such statements with great skepticism,” he said.</p>

<p class="wp-block-paragraph">Mathematics is not normally this dramatic, so how did things get this bad? A rumor was all it took for tensions to boil over.&nbsp;</p>

<hr class="wp-block-separator has-alpha-channel-opacity" />

<p class="has-drop-cap wp-block-paragraph">OpenAI <a href="https://openai.com/index/navier-stokes-solution/">says</a> it heard some researchers were making progress on Millennium Prize problems and decided to see whether one of its advanced, unreleased models could make headway too. It turns out it could. OpenAI says it took roughly 10,000 agents, tens of millions of dollars of compute, and just 88 hours to find a solution to the <a href="https://www.claymath.org/millennium/navier-stokes-equation/">Navier-Stokes problem</a>, which concerns the flow of fluids.</p>

<p class="wp-block-paragraph">The company had also discovered who it was racing against: Buckmaster, an NYU professor, and Levent Alpöge, a researcher at one of its fiercest rivals, Anthropic. Among several lines of research, the pair were pursuing Navier-Stokes, though had not yet completed a proof. Some details of what happened next are fiercely contested, but the two sides broadly agree on the basic sequence of events. One thing is particularly clear: Alpöge’s involvement was a problem for OpenAI, despite <a href="https://x.com/__alpoge__/status/2097548261666033993?s=20">his saying</a> it was a “personal collaboration” independent of his work with Anthropic.&nbsp;</p>

<figure class="wp-block-pullquote"><blockquote><p>Even those skeptical of the most serious allegations described a field shaken by the tech giant’s conduct and fearful of what it might do next in its determination to trounce its rivals.</p></blockquote></figure>

<p class="wp-block-paragraph">Buckmaster <a href="https://cims.nyu.edu/~tristanb/statement.pdf">said</a> he contacted OpenAI after learning the company had become aware of their progress and was racing toward a solution of its own. He said discussions with OpenAI researcher Sébastien Bubeck grew contentious and, in his view, threatening, but the company offered a path forward for him — one that excluded Alpöge. Buckmaster said he was offered practically “unlimited compute” to finish his own work, and the opportunity to be the sole author of OpenAI’s paper announcing the breakthrough, which would of course credit its tools.&nbsp;</p>

<p class="wp-block-paragraph">“All I had to do was throw Levent under the bus,” Buckmaster told <em>The Verge</em> in a phone interview. He said he flatly rejected Bubeck’s offer, which he viewed as a “bribe,” and also began questioning whether OpenAI may have benefited from his use of Codex, one of the company’s AI tools he had been using to tackle the problem. OpenAI has denied that anyone — or any agent — accessed his specific user data, and until its more recent comments acknowledged it could not rule out the possibility data derived from his use of the products was used to improve the model.&nbsp;&nbsp;</p>

<p class="wp-block-paragraph">Buckmaster ultimately decided to go public with both his work and his account of OpenAI’s conduct. His office, he said, had been transformed into something of a “war room,” with colleagues helping scrutinize his mathematics, coordinate outreach, and even get in touch with lawyers.&nbsp;</p>

<p class="wp-block-paragraph">Bubeck has rejected Buckmaster’s characterization of the conversations on social media and in an <a href="https://www.nytimes.com/2026/09/10/science/tristan-buckmaster-openai-math-navier-stokes.html">interview</a> with <em>The New York Times</em>. He acknowledged offering OpenAI’s resources to help Buckmaster complete his own proof or to have him take over the writing of the company’s. Strikingly, Bubeck said OpenAI had made similar arrangements with other mathematicians, though did not identify them.&nbsp;</p>

<p class="wp-block-paragraph">But his account nevertheless makes clear that Alpöge’s affiliation with Anthropic was a sticking point. “From our perspective, how can we have an internal OpenAI project with an Anthropic employee?” he told the <em>Times</em>.</p>

<hr class="wp-block-separator has-alpha-channel-opacity" />

<p class="has-drop-cap wp-block-paragraph">If the goal is to compete in mathematics, there are few bigger trophies than solving a Millennium Prize problem. The seven problems, <a href="https://www.claymath.org/millennium-problems/">set out</a> by the Clay Mathematics Institute in 2000, are widely considered among the most formidable challenges in the field. Each carries a $1 million bounty for whoever solves it. Many had already endured decades of intense scrutiny by the time the prizes were established. In the quarter-century since, only one — the <a href="https://www.claymath.org/millennium/poincare-conjecture/">Poincaré conjecture</a>, a topological problem concerning three-dimensional spheres — has fallen.&nbsp;</p>

<p class="wp-block-paragraph">For an AI company looking to prove that its models are the best at mathematics, then, they are irresistible targets. To Buckmaster and many other mathematicians <em>The Verge</em> spoke to, that helps explain why OpenAI moved so ferociously when it heard others were closing in — particularly once a rival AI company appeared to be involved.&nbsp;</p>

<p class="wp-block-paragraph">For Buckmaster, the episode reinforced something he already believed strongly from a previous spell <a href="https://arxiv.org/html/2509.14185v1">collaborating</a> with Google DeepMind: “All these tech people are obsessed” with solving big famous problems and are “obsessed with scooping,” he said. “Its all about competition.”</p>

<figure class="wp-block-pullquote"><blockquote><p>In that world, Tristan Buckmaster said there is an intense fixation on prestige, fame, being first, and being seen to be first. “That’s the only currency,” he said.</p></blockquote></figure>

<p class="wp-block-paragraph">He said what often gets “lost” when companies race to solve famous problems are the mathematicians themselves — not just the people whose accumulated work makes these breakthroughs possible, but the reasons they do mathematics to begin with. Yes, some may pursue prestige, but most are simply not trophy hunters. Andras Juhasz, a professor of mathematics at the University of Oxford, described mathematics as an elegant discipline that is part science, part art, with many different motivations driving those working there. “Often there is no immediate practical application,” he said. “They do it because it&#8217;s beautiful. They enjoy it. It&#8217;s the sense of discovery. It&#8217;s natural.”&nbsp;</p>

<p class="wp-block-paragraph">Unlike classroom-level mathematical exercises, frontier mathematics rarely has a prescribed route to an answer. Researchers can attack problems from any number of angles, some radically different, which makes the ideas that lead to a solution — and who developed them — especially important, perhaps more so than solving a problem itself. Mathematicians care deeply about this lineage because it is how the field expands, with new techniques and methods often proving more consequential than the problem they were designed to solve.&nbsp;</p>

<p class="wp-block-paragraph">To Buckmaster, his exchanges with Bubeck typify the chasm that separates the worlds of research mathematics and Big Tech, and highlight the differences between what is considered valuable in research. Reading from notes he took while chatting with Bubeck, he said the OpenAI researcher was visibly taken aback when he rejected the company’s offer to take credit. “I could see Sébastien’s face. He was shocked when I said I don&#8217;t care about the Millennium Prize,” he recalled.</p>

<p class="wp-block-paragraph">Buckmaster said he had encountered a similar mentality among tech researchers before. In that world, he said there is an intense fixation on prestige, fame, being first, and being seen to be first. “That’s the only currency,” he said.&nbsp;</p>

<hr class="wp-block-separator has-alpha-channel-opacity" />

<p class="has-drop-cap wp-block-paragraph">Buckmaster isn’t the only mathematician to come away from an encounter with OpenAI concerned about the company’s motivations. Andreas Thom, a professor at the Technical University of Dresden in Germany, found himself at the <a href="https://www.theverge.com/ai-artificial-intelligence/977273/the-ai-takeover-of-mathematics-has-begun">center of a controversy</a> last month after OpenAI announced an impressive mathematical result that built heavily on work by him and fellow researcher Gábor Kun. The company quietly amended its announcement to acknowledge the pair’s contribution without announcing or publicly disclosing the change.&nbsp;</p>

<p class="wp-block-paragraph">Thom described the ordeal as “not a very pleasant experience,” but told <em>The Verge </em>he had largely put it behind him until Buckmaster went public. His allegations <a href="https://www.theverge.com/ai-artificial-intelligence/993263/where-does-openai-get-mathematics-training-data">prompted Thom to revisit an unresolved question</a> about OpenAI’s breakthrough: whether conversations he and his colleagues had with ChatGPT about the research could have been used to help improve the models that ultimately cracked the problem he’d spent years working on.&nbsp;</p>

<p class="wp-block-paragraph">Only OpenAI has the information needed to answer that question, Thom said. “To be honest, I suspect that they don’t even know.” The people training the models and using them to produce mathematical results are “a different kind of people,” he said. To him, that’s hardly an excuse for the uncertainty. “Because it effectively means that they don’t really care, right?”</p>

<figure class="wp-block-pullquote"><blockquote><p>“The prospect of competing with powerful AI companies, whose resources far exceed those available to academic research groups, could make them even more reluctant to pursue ambitious questions.”</p></blockquote></figure>

<p class="wp-block-paragraph">The tension echoes fights already playing out elsewhere. Writers, musicians, artists, and media companies have all challenged AI companies over systems built from vast stores of human-created work, often without permission, recognition, or compensation. While mathematics may seem a world apart, the underlying question is the same: What do companies owe to the people whose accumulated work they ingested to build their systems?&nbsp;</p>

<p class="wp-block-paragraph">In Thom’s case, the question remains unresolved. OpenAI did not respond to <em>The Verge</em>’s question on whether data from conversations Thom and his colleagues had with ChatGPT could have contributed to the company’s solution that built on his work.</p>

<p class="wp-block-paragraph">More broadly, Thom said he resents what he sees as a failure to recognize the “the communal effort that this entire community has put into all the research results” underpinning AI’s recent mathematical advances. Companies, he said, “are just now using [it] as if it was kind of nothing.”&nbsp;</p>

<p class="wp-block-paragraph">“I think there is a certain attitude that I don&#8217;t like in that,” he said.&nbsp;</p>

<hr class="wp-block-separator has-alpha-channel-opacity" />

<p class="has-drop-cap wp-block-paragraph">It’s not that mathematicians are strangers to competition — researchers care deeply about priority and bitter disputes over who came first litter mathematical history — but while competition does not preclude cooperation, these are no ordinary competitors. Scooping in mathematics has historically been relatively difficult for obvious reasons: Very few people have the specialized expertise to swoop in on a discovery at speed. AI companies operate on a different scale. Researchers worry they could turn scooping into something of an industrial process mathematicians would have little chance of fighting back against, rapidly spinning up thousands upon thousands of agents and enormous amounts of compute whenever word spreads that a breakthrough is close.</p>

<p class="wp-block-paragraph">To Buckmaster, OpenAI could have easily collaborated with researchers rather than race them to results. Indeed, the company seemed perfectly willing to work with him. The problem was Alpöge, or, more specifically, his ties to Anthropic.</p>

<p class="wp-block-paragraph">“They were in such a rush to publish, to beat Anthropic,” he said. They barely took note of the researchers caught in the middle.</p>

<hr class="wp-block-separator has-alpha-channel-opacity" />

<p class="has-drop-cap wp-block-paragraph">For all the rush, OpenAI won’t know whether it has won the Millennium Prize for solving Navier-Stokes for years. The Clay Mathematics Institute <a href="https://www.claymath.org/millennium-problems/rules/">requires</a> a period of two years to have passed since a result was published, during which it must have “received general acceptance in the global mathematics community.” For now, Navier-Stokes occupies a peculiar limbo: The Institute has removed it from its list of unsolved problems, though hasn’t yet declared it solved. “The process is deliberately unhurried,” the Institute <a href="https://www.claymath.org/news/navier-stokes-announcement/">said</a> in a statement.&nbsp;&nbsp;&nbsp;</p>

<p class="wp-block-paragraph">OpenAI, meanwhile, has already moved on. In a statement to <em>The Verge</em>, OpenAI’s Fauconnet said that<em> </em>“since the completion of Navier-Stokes we have made substantial progress on another Millennium Prize problem,” adding that the company is “working through how to share these results thoughtfully.”</p>

<p class="wp-block-paragraph">Which problem remains unclear. Unconfirmed <a href="https://x.com/AndrewCurran_/status/2098083604853342688?s=20">speculation</a> on social media suggests this could be the Hodge conjecture, which concerns, very roughly speaking, how complex geometric shapes can be understood in terms of simpler building blocks. <a href="https://x.com/aran_nayebi/status/2098017678157922305?s=20">Rumors</a> are also circulating that Anthropic is closing in on a Millennium Prize problem of its own.</p>

<hr class="wp-block-separator has-alpha-channel-opacity" />

<p class="has-drop-cap wp-block-paragraph">As the two giants of AI race to collect yet more mathematical trophies, they are discovering that astonishing results alone are not enough to earn the trust of the community they are transforming.</p>

<p class="wp-block-paragraph">Mathematicians are beginning to push back. Many <em>The Verge</em> spoke to, even the most enthusiastic proponents of AI in the field, worried the companies were <a href="https://www.theverge.com/ai-artificial-intelligence/992953/openai-math-millennium-prize-navier-stokes">having a chilling effect on research</a>, pushing mathematicians to be more secretive about unfinished work for fear someone may swoop in and beat them to it. Several said colleagues who had previously compiled lists of important unsolved problems were reconsidering the practice, concerned that what was intended as a useful resource for the field could instead become a list of targets for AI companies.&nbsp;</p>

<p class="wp-block-paragraph">Resistance is becoming increasingly public. In June, mathematicians published the <a href="https://leidendeclaration.ai/">Leiden Declaration</a>, a set of principles for the responsible use of AI in mathematics that has been endorsed by the International Mathematical Union and signed by nearly 3,900 people, an increase of nearly 500 people since I last covered it in mid-August. It urges policymakers, governments, the media, and other groups to not buy into “the hype” created by companies who “overstate the capabilities of their products.” As the Millennium Prize controversy raged, OpenAI <a href="https://x.com/danintheory/status/2098125701782372640?s=20">withdrew</a> its sponsorship of an undergraduate mathematics hackathon at Caltech following fierce <a href="https://proofsandprompts.com/2026/09/10/open-letter-about-the-mathathon/">opposition</a> decrying the intrusion of corporate interests and worries the event would create a deluge of low-quality “slop mathematics.”&nbsp;</p>

<figure class="wp-block-pullquote"><blockquote><p>“They don&#8217;t care anything about us as a community. It&#8217;s all about this petty drama between two trillion-dollar companies that are acting like children.”</p></blockquote></figure>

<p class="wp-block-paragraph">Shing-Tung Yau, a professor of mathematics at China’s Tsinghua University, an emeritus professor at Harvard, and a recipient of the prestigious Fields Medal, told <em>The Verge</em> he worries about the potential effect on young researchers. “Working on hard problems already carries considerable risk for Ph.D. students and junior faculty,” he said. “The prospect of competing with powerful AI companies, whose resources far exceed those available to academic research groups, could make them even more reluctant to pursue ambitious questions.”</p>

<p class="wp-block-paragraph">Yau declined to weigh in on allegations that researchers’ work may have been used by OpenAI, but said he is in favor of an independent review to establish what happened. More broadly, he worries that a lack of transparency and rush to announce first could obscure the intellectual lineage behind a breakthrough. Mathematical credit, he said, should reflect intellectual contributions, not who had budget for the most compute or made the loudest announcement.&nbsp;</p>

<p class="wp-block-paragraph">Yau pointed to another problem, too. OpenAI and other AI companies occupy a peculiar position as both the providers of important research tools and, in a way, researchers. It “raises a serious conflict-of-interest concern,” he said, particularly as they could benefit from privileged access to customers’ unfinished and unpublished work.&nbsp;</p>

<p class="wp-block-paragraph">“That concern deserves a substantive response,” he said. “It should not simply be dismissed as ordinary competition.”</p>

<p class="wp-block-paragraph">A lot of this growing sense of unease comes down to trust. Mathematicians do not have to accept the most explosive allegations against OpenAI to worry about a company that both provides their research tools and, simultaneously, competes with them.&nbsp;</p>

<p class="wp-block-paragraph">“Yeah, quite honestly, I don&#8217;t think that some data security announcement or whatever will really solve it,” Thom said. “I don’t really trust them.” Buckmaster felt similarly: “Why should we trust anything they said?”&nbsp;</p>

<p class="wp-block-paragraph">Buckmaster said the reaction from colleagues to his going public had been overwhelmingly positive. But there was an undercurrent of something else too: fear. He told <em>The Verge</em> he initially intended to thank those who supported him when he went public with his experiences. He elected not to after many expressed discomfort at the idea of having their names publicly attached. “The reality is that mathematicians are actually scared of them,” Buckmaster said, referring to the AI companies.&nbsp;</p>

<p class="wp-block-paragraph">And fear is hardly a solid foundation on which to build a productive and healthy research community. Buckmaster isn’t convinced it matters much to those companies involved. “They don&#8217;t care anything about us as a community,” he said. “It&#8217;s all about this petty drama between two trillion-dollar companies that are acting like children.”</p>
						]]>
									</content>
			
					</entry>
			<entry>
			
			<author>
				<name>Robert Hart</name>
			</author>
			
			<title type="html"><![CDATA[Mathematicians want proof OpenAI didn’t use their work ]]></title>
			<link rel="alternate" type="text/html" href="https://www.theverge.com/ai-artificial-intelligence/993263/where-does-openai-get-mathematics-training-data" />
			<id>https://www.theverge.com/?p=993263</id>
			<updated>2026-09-10T07:19:44-04:00</updated>
			<published>2026-09-10T07:00:57-04:00</published>
			<category scheme="https://www.theverge.com" term="AI" /><category scheme="https://www.theverge.com" term="News" /><category scheme="https://www.theverge.com" term="OpenAI" /><category scheme="https://www.theverge.com" term="Science" />
							<summary type="html"><![CDATA[Another researcher is challenging OpenAI about the data driving its increasingly impressive array of mathematical discoveries. Just days after a bitter row erupted over whether the company’s models benefited from unpublished work, a second mathematician has come forward accusing the AI giant of unethical and “dishonest” behavior and a lack of transparency about the origins [&#8230;]]]></summary>
			
							<content type="html">
											<![CDATA[

						
<figure>

<img alt="" data-caption="Sam Altman, chief executive officer of OpenAI, during a media tour of the Stargate AI data center. | Bloomberg via Getty Images" data-portal-copyright="Bloomberg via Getty Images" data-has-syndication-rights="1" src="https://platform.theverge.com/wp-content/uploads/sites/2/2026/09/gettyimages-2236544323.jpg?quality=90&#038;strip=all&#038;crop=0,0,100,100" />
	<figcaption>
	Sam Altman, chief executive officer of OpenAI, during a media tour of the Stargate AI data center. | Bloomberg via Getty Images	</figcaption>
</figure>
<p class="wp-block-paragraph">Another researcher is challenging OpenAI about the data driving its increasingly impressive array of mathematical discoveries. Just days after a bitter row erupted over whether the company’s models benefited from unpublished work, a second mathematician has come forward accusing the AI giant of unethical and “dishonest” behavior and a lack of transparency about the origins of its training data.</p>

<p class="wp-block-paragraph">In a <a href="https://mathstodon.xyz/@andreasthom/117240535270608201">series</a> <a href="https://mathstodon.xyz/@andreasthom/117240536885387540">of</a> <a href="https://mathstodon.xyz/@andreasthom/117240537520615623">posts</a> on Mastodon, mathematician Andreas Thom raised concerns that interactions he and his colleagues had had with the ChatGPT chatbot before OpenAI’s triumphant announcement may have contributed to its success in the field. One of the 10 <a href="https://openai.com/index/ten-advances-in-mathematics/">results</a> OpenAI <a href="https://www.theverge.com/ai-artificial-intelligence/977273/the-ai-takeover-of-mathematics-has-begun">announced with great fanfare</a> last month involved Thom’s area of expertise, so-called non-sofic groups, and OpenAI acknowledged that their result built heavily on previous work by Thom and fellow mathematician Gábor Kun.&nbsp;&nbsp;</p>

<p class="wp-block-paragraph">Thom said he began reflecting on his own interactions with OpenAI after Tristan Buckmaster, a mathematics professor at New York University, <a href="https://www.theverge.com/ai-artificial-intelligence/991710/openai-navier-stokes-solution">publicly questioned</a> whether the company’s AI models had benefited from his use of OpenAI’s Codex. After OpenAI announced its non-sofic groups result, it was widely criticized in mathematical circles for failing to acknowledge recent contributions from Thom and Kun and the company quietly amended its writeup. Non-sofic groups are, roughly speaking, infinite mathematical structures that cannot be approximated by finite ones.</p>

<p class="wp-block-paragraph">Thom said he was also struck by “OpenAI’s detailed command of our techniques,” which he said were neither the most obvious nor the most promising routes to a solution at the time. He said he wrote emails to OpenAI researchers Sébastien Bubeck and Mark Sellke, also a statistician at Harvard, to ask whether his interactions with ChatGPT were “part of the training data or accessible to the reasoning process” and could therefore have contributed to the result.</p>

<p class="wp-block-paragraph">But the answer did not satisfy Thom, who said it only addressed whether his conversations with the chatbot could be accessed directly, not whether they had entered into the vast pools of training data the company uses to improve its models. “No such qualification, explanation, or evidence was given,” he wrote. “I take this as dishonesty to say the least.”</p>

<p class="wp-block-paragraph">Thom said researchers aren’t equipped to reverse-engineer OpenAI’s training pipeline to figure out whether their work has been used or not. “Only OpenAI has the relevant data for that.” If the company is going to deny doing this, he said the responsibility is on them to prove that by disclosing all necessary datasets and clarifying various settings and terms setting out how it uses data.&nbsp;</p>

<p class="wp-block-paragraph">OpenAI’s reluctance to conclusively rule out any use of user data echoes the way it defended its recent Millennium Prize breakthrough, both in its public messaging and its communications with Buckmaster — who was working on the problems with Anthropic researcher Levent Alpöge in a personal capacity. In the blog post <a href="https://openai.com/index/navier-stokes-solution/">announcing</a> the Navier-Stokes solution, which concerns the movement of fluids, OpenAI flatly denied using any <em>specific</em> user data: “We (the researchers and the agents) did not see any of their work through any means until they released it publicly — in particular, no specific user data was accessed in order to solve this problem.”&nbsp;</p>

<p class="wp-block-paragraph">But it would not conclusively rule out an indirect influence: “While unlikely, we cannot rule out that de-identified data derived from their usage of our products helped improve our models⁠.” Thom said it is the same obfuscatory distinction the company drew in its communications with him. “De-identification may remove a name; it does not remove the intellectual content of a mathematical idea,” he said.&nbsp;</p>

<p class="wp-block-paragraph">In light of recent events, Thom said “Sellke’s categorical answer was, at minimum, unjustifiably broad and materially misleading; looking back it was plainly dishonest.”&nbsp;</p>

<p class="wp-block-paragraph">Thom said it “would be ethically indefensible” if nonpublic research supplied by users helped to improve models that the company then used to race those very same users to publication, without consent, proper disclosure, or credit.</p>

<p class="wp-block-paragraph">OpenAI did not immediately respond to <em>The Verge</em>’s request for comment.</p>

<p class="wp-block-paragraph">His comments add to mounting unease over OpenAI in mathematical circles at what should be a moment of triumph for the company. Its announced solution to one of mathematics’ legendary Millennium Prize problems is an extraordinary achievement that, should it be verified, few would deny. But this was complicated by the unusual circumstances OpenAI said led it to pursue the problem in the first place: It heard rumors online that other researchers had made major progress and thought it would try too.&nbsp;&nbsp;</p>

<p class="wp-block-paragraph">The ongoing incident has left a <a href="https://www.theverge.com/ai-artificial-intelligence/992953/openai-math-millennium-prize-navier-stokes">sour taste in mathematicians’ mouths</a>. Numerous researchers told <em>The Verge</em> they worry behavior like this will push the field into a more secretive state if mathematicians know that even rumors they are close to a big breakthrough could ignite a race with a well-resourced tech giant eager for glory.</p>
						]]>
									</content>
			
					</entry>
			<entry>
			
			<author>
				<name>Robert Hart</name>
			</author>
			
			<title type="html"><![CDATA[OpenAI’s sly mathematical breakthrough sends a chill through academia]]></title>
			<link rel="alternate" type="text/html" href="https://www.theverge.com/ai-artificial-intelligence/992953/openai-math-millennium-prize-navier-stokes" />
			<id>https://www.theverge.com/?p=992953</id>
			<updated>2026-09-10T15:45:43-04:00</updated>
			<published>2026-09-09T17:16:34-04:00</published>
			<category scheme="https://www.theverge.com" term="AI" /><category scheme="https://www.theverge.com" term="OpenAI" />
							<summary type="html"><![CDATA[OpenAI’s announcement Tuesday that it has solved one of mathematics’ legendary Millennium Prize problems should have been a moment of triumph. The result is both an undeniable achievement and a striking demonstration of just how rapidly AI is transforming mathematics. But before it was even formally announced, the breakthrough had been complicated by the unusual [&#8230;]]]></summary>
			
							<content type="html">
											<![CDATA[

						
<figure>

<img alt="" data-caption="Open AI CEO Sam Altman speaks during the G20 Innovation Ministerial. | (Photo by Matt RAMEY / AFP via Getty Images)" data-portal-copyright="(Photo by Matt RAMEY / AFP via Getty Images)" data-has-syndication-rights="1" src="https://platform.theverge.com/wp-content/uploads/sites/2/2026/09/gettyimages-2292626872.jpg?quality=90&#038;strip=all&#038;crop=0,0,100,100" />
	<figcaption>
	Open AI CEO Sam Altman speaks during the G20 Innovation Ministerial. | (Photo by Matt RAMEY / AFP via Getty Images)	</figcaption>
</figure>
<p class="wp-block-paragraph">OpenAI’s announcement Tuesday that it has solved one of mathematics’ legendary <a href="https://www.claymath.org/millennium-problems/">Millennium Prize problems</a> should have been a moment of triumph. The result is both an undeniable achievement and a striking demonstration of just how <a href="https://www.theverge.com/ai-artificial-intelligence/977273/the-ai-takeover-of-mathematics-has-begun">rapidly AI is transforming mathematics</a>. But before it was even formally announced, the breakthrough had been complicated by the unusual circumstances that prompted OpenAI to pursue the problem: After hearing other researchers were making progress, it seems to have thrown its considerable resources into a last-minute effort to beat them to the punch. The ensuing controversy has surfaced allegations of scooping, spying, and flagrant violations of long-standing academic norms that researchers fear could have a chilling effect on the field.&nbsp;</p>

<p class="wp-block-paragraph">As Abhishek Saha, a mathematics professor at Queen Mary University of London, explains it, OpenAI has engaged in the &#8220;kind of things that mathematicians will generally not do.”</p>

<p class="wp-block-paragraph">In <a href="https://openai.com/index/navier-stokes-solution/">a blog post published Tuesday</a>, OpenAI said it took one of its unreleased models just 88 hours to find a solution to the Navier-Stokes problem, a thorny quandary concerning the movement of fluids. On account of the $1 million bounty available for whoever solves it, the problem is among mathematics’ most heavily researched, but it has nevertheless stumped human researchers for close to 90 years. OpenAI said its model solved the problem by focusing a swarm of roughly 10,000 AI agents powered by its internal model on the task and hailed the achievement as a “milestone.”&nbsp;</p>

<figure class="wp-block-pullquote"><blockquote><p>“If you don’t want me to be nice, then I don’t have to be nice.”</p></blockquote></figure>

<p class="wp-block-paragraph">But the timing of the announcement has raised eyebrows. Just one day earlier, New York University mathematics professor Tristan Buckmaster <a href="https://mastodon.social/@tristanbuckmaster/117236471352470303">published findings</a> on a related problem with Levent Alpöge, a researcher at OpenAI’s archrival Anthropic (although Alpöge was not, here, working on behalf of his employer). Buckmaster <a href="https://cims.nyu.edu/~tristanb/statement.pdf">said</a> he contacted OpenAI after learning the company had become aware of their progress, to ask when it began working on the problem and what data its model had been trained on. The conversation, he said, quickly turned sour, with an OpenAI researcher asking him, “Why would you ruin your career?” when he said he would go public with what happened. When he asked why going public would ruin his career, Buckmaster said he received the following reply: “If you don’t want me to be nice, then I don’t have to be nice.” OpenAI urged Buckmaster to instead publish the work and credit OpenAI’s internal model, dropping Alpöge as coauthor.</p>

<p class="wp-block-paragraph">Buckmaster said he asked OpenAI whether it had accessed his sessions on Codex, which he had used while tackling the problem, but that OpenAI grew increasingly evasive, even hostile, in its responses. In statements since, including the blog post announcing the result, OpenAI has flatly denied using any specific user data. “We (the researchers and the agents) did not see any of their work through any means until they released it publicly — in particular, no specific user data was accessed in order to solve this problem,” the company said.</p>

<p class="wp-block-paragraph">But OpenAI could not conclusively rule out an indirect influence. “While unlikely, we cannot rule out that de-identified data derived from their usage of our products helped improve our models⁠,” it said, while stressing that the two proofs differ significantly. Comments from OpenAI <a href="https://x.com/markchen90/status/2097400166554993041?s=20">researchers</a> on X echo those denials.&nbsp;</p>

<p class="wp-block-paragraph">It is difficult to say exactly what happened. Timelines are tangled, research overlaps, and the provenance of AI-generated work is tough, if not impossible, to identify at the best of times. And it’s hardly a surprise that different players might compete to solve one of the most famous mathematical problems in the world, particularly one attached to a hefty prize.</p>

<p class="wp-block-paragraph">But aspects of OpenAI’s account are hard to explain. By the company’s own telling, the effort was a hurried and <a href="https://x.com/polynoamial/status/2097375837670785447?s=20">incredibly expensive affair</a>, costing it millions of dollars. Yet the company says it has no intention of claiming the bounty, which, in any case, has yet to be awarded by the Clay Mathematics Institute, which administers it. It said its only goal “is to report on the substantial progress of our AI models.” The company does not appear to have expended much effort on tackling Navier-Stokes before September, or if it has, it hasn’t spoken about it publicly.&nbsp;</p>

<p class="wp-block-paragraph">So why the rush?&nbsp;</p>

<p class="wp-block-paragraph">OpenAI’s explanation effectively amounts to a thunderous “Why not?” The company said it began working on the problem after hearing rumors that other researchers were making progress on Millennium Prize problems. It found those rumors “on Twitter,” said OpenAI researcher Sébastien Bubeck at a press briefing <a href="https://www.science.org/content/article/how-ai-math-breakthrough-ignited-controversy">reported</a><em> </em>on by <em>Science.</em> “So we thought to ourselves: ‘We have such a strong model. Why don’t we try to solve also a Millennium Prize problem?’” Bubeck said.&nbsp;</p>

<p class="wp-block-paragraph">OpenAI said it only later realized the rumors concerned Alpöge and Buckmaster. Beyond addressing Buckmaster’s allegations about the use of his data, OpenAI has not publicly responded to his other claims and directed <em>The Verge</em> to its blog when asked for comment. Bubeck, who Buckmaster named in his account, has <a href="https://x.com/SebastienBubeck/status/2097379411691516310?s=20">disputed</a> parts of it, denying he ever asked Buckmaster to remove Alpöge as coauthor.</p>

<p class="wp-block-paragraph">Even setting aside the most explosive allegations, aspects of OpenAI’s conduct the company has plainly acknowledged have shocked mathematicians. The apparent rush to beat other researchers to a result is simply not how mathematics is done in most cases. Scooping does happen, but it’s not easy, said Saha.</p>

<p class="wp-block-paragraph">That’s partly because cutting-edge research often requires such deep and specialized expertise that few people are in a position to swoop in even if they wanted to, he explained.&nbsp;</p>

<p class="wp-block-paragraph">Openness is a deeply embedded virtue in the discipline. “Mathematics depends heavily on an informal norm of trust,” said Matthew Ballard, a professor of mathematics at the University of South Carolina and associate director for scientific activities at the Institute for Computer-Aided Reasoning in Mathematics (ICARM). “Researchers routinely share incomplete ideas and ongoing work with colleagues to sharpen their thoughts. It is done with the expectation that it will not turn into a competition,” he said.&nbsp;</p>

<p class="wp-block-paragraph">Though unable to comment on whether conversation logs might have been accessed, Carnegie Mellon professor Jeremy Avigad, who is also the director of ICARM, said that even “the thought that AI systems might steal ideas from our queries is chilling.” Mathematicians are accustomed to talking about their work without worrying about being scooped. “Now that even the slightest hint might be enough for someone with sufficient computational resources to set a swarm of agents on solving the problem, people are likely to be more cautious. It&#8217;s sad to think about how that might change the research environment.”</p>

<figure class="wp-block-pullquote"><blockquote><p>“Mathematics depends heavily on an informal norm of trust.”</p></blockquote></figure>

<p class="wp-block-paragraph">OpenAI’s unwillingness or inability to say whether its models were informed by the work of other mathematicians compounds the sense of unease in the field. “That is a problem,” Brown University professor Brendan Hassett told <em>The Verge, </em>adding that “given the history of the AI companies appropriating copyrighted work without permission or payment, it is natural for people to ask these questions.” He said companies “should be held accountable to deliver” assurances that chat logs will not be used to improve their models. That includes being able to demonstrate that.&nbsp;</p>

<p class="wp-block-paragraph">It’s unclear where exactly things go from here. Writing from a conference in Beijing, Yang-Hui He, a fellow at the London Institute for Mathematical Sciences, said he worries that “maths under the big companies is much too secretive.” As someone who says he is “always optimistic about AI,” he admits he is worried mathematics could be reverting to a more secretive state like in the past, when it was funded by patronage from wealthy families like the Medicis.&nbsp;</p>

<p class="wp-block-paragraph">For most researchers, things may not change that much. There are only so many high-caliber problems companies like OpenAI and its rivals would be willing to spend such vast sums solving, Saha speculated. “You would not expect the AI labs to throw everything at most problems people work on because they just won’t get enough publicity.”</p>

<p class="wp-block-paragraph">Publicity may have been part of the point, which could help explain why OpenAI decided to race after a problem it knew was connected to a researcher at Anthropic, even if he was acting independently. “This is clearly a PR victory for OpenAI,” said Oxford professor Andras Juhasz.</p>

<p class="wp-block-paragraph">But Juhasz questioned how sustainable that approach could be, wondering whether this might spell the beginning of the end for AI companies’ involvement in research mathematics now that models can tackle some of the biggest problems. Human mathematicians scoop one another, too, he said, though what OpenAI did has shown that this can happen on a much grander scale. “Suddenly, 10,000 mathematicians jump on your problem,” he said.</p>

<p class="wp-block-paragraph">All that could make OpenAI’s PR victory a Pyrrhic one. The company has, <a href="https://www.theverge.com/podcast/982434/ai-math-openai-astra-existential-crisis">once again, proven that its models can compete</a> at the very frontier of mathematics. In doing so, it appears to have alienated the very community it has been trying to impress.&nbsp;</p>
						]]>
									</content>
			
					</entry>
	</feed>
