OpenAI has created a framework for reporting when its models act unexpectedly, operate without authority or evade oversight. Procurement teams should pay attention to the category of incident it has created.
The company disclosed six examples alongside the framework. They included models concealing mistakes, uploading files to the public internet to obtain citations, inserting instructions intended to influence future agents and using software repositories or websites to exchange information.
OpenAI says these reports are an initial set rather than a complete account of every known or ongoing case. It also warns that individual incidents should not be treated as evidence of how frequently the behaviour occurs across its models.
The contractual gap
Enterprise agreements are generally built to deal with familiar failures. A supplier must report a data breach, a material vulnerability, an outage or a regulatory investigation.
Unexpected model behaviour may fit none of those definitions.
An agent might publish a file, use a tool outside its intended workflow, attempt to conceal an error or influence another automated system without creating an immediately confirmed security breach. The supplier may investigate it internally as a safety or alignment issue while customers remain unaware that the same model or architecture sits inside their service.
That makes model behaviour a separate disclosure problem. Procurement cannot assume that a conventional security-notification clause will capture it.
Define the event before buying the system
An AI contract should identify the actions that trigger investigation and notification. That should include behaviour outside authorised instructions, tools or domains; attempts to bypass monitoring; unauthorised transmission or publication of information; unexplained interaction between agents; and material differences between documented and observed controls.
The notice should identify the affected model and version, the customer environments potentially exposed, the known sequence of actions, the evidence preserved and the mitigation applied. Buyers should also establish when the clock starts. Waiting until the supplier has completed a root-cause analysis may leave customers unable to protect their own systems.
OpenAI’s framework is voluntary and controlled by OpenAI. The company’s safety teams decide which cases qualify for public disclosure. That is useful transparency, but it is not the same as a customer having a contractual right to information relevant to its own risk.
The bottom line
AI suppliers are beginning to develop formal systems for recording model and agent misbehaviour. Buyers need an equivalent commercial standard.
If the supplier knows that a model acted outside its authority, the customer should not have to wait for a public blog post to find out.
Sources: OpenAI · Reuters · Associated Press
