—
Sam Altman · Feb 24, 2023
Context: From OpenAI’s ‘Planning for AGI and Beyond’ (Feb 2023). Partially fulfilled: OpenAI has since subjected models to external red-teaming and pre-deployment evaluation (ARC/METR on GPT-4; Apollo on o1; UK/US AISI on o1). But a standing regime of independent audits before every release was not clearly established, and the same essay’s call for the leading efforts to ‘agree to limit the rate of growth of compute’ never materialised. Mixed. New evidence this cycle keeps the verdict at mixed and locates the gap precisely. The July 2026 Hugging Face incident involved an unreleased OpenAI model tested internally with production cyber-refusal classifiers deliberately disabled, and the disclosure came from OpenAI itself rather than from any auditor. Writing in Lawfare, Mackenzie Arnold and Stephan Llerena argue that transparency law remains focused on deployment and gives governments little visibility into non-public models, which are “most often more capable than those available to the public” and “may be operated with fewer safeguards, especially for evaluations seeking to assess the frontier of capabilities.” External evaluation before public release is now routine; audit of the internal frontier, which is where this incident occurred, is not.