The root cause of the OpenAI and hugging face exploit and resilience for OSFI mandate
The code was acting with non malicious intent. However it was asked to perform its tasks inside a walled off sandbox with no internet access. Note OSFI all compliance regulators are not innocent. Their mandate is tied to B13 and E23. They must consider treatment of agentic-model containment as a security-and-resilience matter and sort out the existing inadequate definition of B21 and E23 in this regard. The models were supposed to run inside an isolated sandbox with no internet access, wired only to an internal package-registry proxy. They did not stay there. Fixated on obtaining the benchmark solution and spending … Continue reading The root cause of the OpenAI and hugging face exploit and resilience for OSFI mandate
