Site navigation

OpenAI Firings Highlight Wider AI Security Concerns

Graham Turner

,

AI security risks
New PwC research has exposed widening gaps in how organisations are securing and governing AI, from adversarial attacks and skills shortages to accountability and data protection, as OpenAI faces fresh scrutiny over the handling of sensitive information and the behaviour of autonomous systems.

Threats targeting artificial intelligence systems have emerged as the area cybersecurity leaders feel least prepared to address, as new research highlights major gaps around governance, skills and data protection.

The findings from PwC come as OpenAI confirmed it has fired three researchers for allegedly mishandling sensitive information, including work involving an external organisation analysing AI models.

PwC surveyed 3,934 business and technology leaders across 71 countries for its 2027 Global Digital Trust Insights report, published on October 1, with 52% of respondents identifying adversarial AI attacks as their biggest cyber preparedness gap.

The challenge is being compounded by uncertainty over who within organisations should ultimately be accountable for AI-related risks.

PwC said no single ownership model has emerged, with 29% of respondents saying responsibility sits with the CIO, CTO or technology function, 26% pointing to a dedicated AI leader or function, and 17% saying accountability should rest with the CISO or cyber function.

However, a third of CEOs and security and risk leaders, 33%, said their organisation has already appointed a dedicated AI role, such as a chief AI officer.

The findings come as OpenAI said it had dismissed three employees over the handling of sensitive company information.

“Our investigation confirmed that these individuals mishandled sensitive information outside established company procedures, violating our policies and breaking the trust essential to our work,” a spokesperson told the BBC.

The company did not name the employees, although at least two were involved in safety research.

“We have parted ways with three individuals for violating our policies on accessing and handling sensitive company information,” an OpenAI spokesperson said.

The case underlines the growing importance of internal controls around AI development and the data associated with it, an area also highlighted in PwC’s research.

Only 49% of responding organisations said they had fully implemented data classification policies, while 48% had fully implemented data loss prevention measures.

Despite the risks, organisations appear prepared to increase their cyber investment. Some 84% of security and finance leaders expect budgets to increase, six percentage points higher than in 2025, while 58% identified AI as a top-five cyber budget priority.

Responsible AI governance was cited by 42% of respondents as a leading priority, followed by platform hardening at 38% and supply chain security at 35%.

Organisations are also increasingly looking to AI itself to strengthen their cyber defences. Half of respondents said they are prioritising its use for threat detection and alerting, while 43% pointed to fraud detection and 42% to phishing detection and response.

Tonya Ugoretz, cyber & risk innovation institute co-leader at PwC US, said organisations should begin with the fundamentals when attempting to address adversarial attacks.

“That means understanding where sensitive data sits, controlling access, continuously testing and monitoring AI systems, and having clear processes to identify and respond when something goes wrong,” she added.

“Technology and controls alone aren’t enough, though. Organizations also need clear accountability for AI risk – who owns the decisions, who is responsible when an AI system behaves unexpectedly and where human oversight is required – alongside people with the skills to exercise that oversight effectively.”

The concerns over AI governance and oversight come amid wider scrutiny of the risks posed by increasingly autonomous systems.

OpenAI has faced scrutiny after its models accessed external systems, including Australian government websites and the open-source developer platform Hugging Face.

In July, one of the company’s AI models accessed the internet and breached Hugging Face, prompting OpenAI to review the activities of its AI agents, which are designed to carry out tasks autonomously based on simple instructions.

The company said this week that it has notified more than 100 organisations about incidents involving unauthorised activity linked to its systems.

Being notified “does not mean that any private information was accessed” or that a system was compromised, OpenAI said.


Recommended reading


Skills shortages add to AI security challenge

Workforce capability is also emerging as a significant obstacle to organisations increasing their use of autonomous AI systems.

More than two-fifths of CISOs, 44%, identified workforce skills in AI oversight and governance as one of the main barriers to increasing the autonomy of AI agents.

The issue comes as 55% of respondents ranked the reliability of the technology as a factor preventing broader adoption of agents.

PwC’s findings suggest AI itself may also play a role in tackling the skills challenge.

More than half of respondents, 53%, said AI-enabled training is among their top priorities for helping to close skills gaps and retain employees, alongside providing more growth opportunities, cited by 59%, and nurturing a strong cyber culture, cited by 53%.

The debate around AI safety has also continued to intensify.

In September, researcher Jacob Coxon, who left Anthropic, called for AI development to slow down so its potential risks could be properly assessed, while Anthropic chief executive Dario Amodei and OpenAI chief executive Sam Altman have both called for measures to address concerns over AI.

On Tuesday, US President Donald Trump hosted a meeting of technology executives, including leaders from OpenAI, Anthropic, Nvidia, SpaceX, Meta and Google, to discuss AI.

Following the meeting, Trump posted a document he described as a “morally binding” agreement intended to provide a “form of protection” from potential AI risks.

Some technology experts criticised the pact on the grounds that it allowed AI companies to regulate themselves.

Graham Turner

Sub Editor

Latest News

Events Technology

Socitm Conference to Explore AI, Data and Cyber

AI Cybersecurity

AI Finds Higher Risk Vulnerabilities and Leads to More Exploits

Featured Government

Scot Gov Invests £3M To Commercialise Uni Research

AI Editor's Picks Security

OpenAI Firings Highlight Wider AI Security Concerns