---
格式版本: 2
标题: "Pause OpenAI, now"
原文链接: "https://garymarcus.substack.com/p/pause-openai-now"
发布日期: "2026-09-04"
发布时间校准状态: "found"
发布时间需复核: "否"
发布时间来源: "llm:scrape:extracted_text"
发布时间证据: "第 9 行：Sep 04, 2026"
发布时间校准原因: "标题附近明确标注文章发布日期 Sep 04, 2026，符合发布时间优先级，且与 datePublished 一致。"
发布时间校准置信度: "1"
发布时间候选数量: 27
发布时间严格候选数量: 4
发布时间原页读取状态: "source template page reused from URL open"
发布时间未找到原因: ""
发布时间校准时间: "2026-09-07T23:42:49+08:00"
发布时间仲裁状态: "confirmed"
发布时间仲裁尝试次数: 1
发布时间仲裁耗时毫秒: 5781
发现时间: "2026-09-07T23:38:38+08:00"
入库时间: "2026-09-07T15:42:59.699Z"
来源平台: "Substack 数据中心相关博客搜索"
搜索渠道: "source_template"
搜索词: "site:substack.com OpenAI"
匹配关键词:
  - "performance"
  - "AI"
相关厂家:
  - "OpenAI"
相关专家:
  []
内容类型: "网页"
抓取工具: "Free Fetch + Defuddle"
清洗工具: "Defuddle Markdown + Defuddle/Readability 正文提取"
原始附件:
  []
AI优质: "否"
AI打分: 26
AI分档: "非优质"
AI质检状态: "不通过"
AI打分理由: "正文是Gary Marcus呼吁暂停OpenAI的评论文章，主线为OpenAI安全信任、AGI风险、GPT-6 Astra的CoT可监控性下降及所谓‘rogue agent’事件，属于通用AI安全舆论和模型/应用层面讨论，未涉及超节点、AI Rack、机架级系统或关键部件；无架构规格、量产/客户/部署信号；来源为个人Substack博客，非专业基础设施媒体；知识库未见重复但有相关OpenAI背景；命中硬否决‘应用与模型效率/非机架级基础设施’，故不通过。"
AI质检模型: "zj-deepseek-v4-flash"
AI质检时间: "2026-09-07T23:43:38+08:00"
AI主题相关性: 0
AI来源权威性: 4
AI新颖性: 12
AI技术细节: 1
AI商业部署信号: 0
AI完整性: 9
AI评分提示词版本: "v17-精简生产版"
AI评分提示词SHA256: "48fb9777f386026761b4873eaff30807694fb11e9b352d7c69bf2dfde750cc7d"
AI评分知识库版本: "knowledge_base_v1-20260819+runtime.100"
AI评分知识库SHA256: "7fe4568b9de9fc322c105ece08d18efab5b9b86f27dea6eb043b9a4d273bde60"
AI评分知识库检索词: "[\"OpenAI\",\"site:substack.com OpenAI\",\"AGI\",\"w_40\",\"h_40\",\"Ps2i\",\"w_20\",\"h_20\",\"GPT-6\",\"AIs\",\"AM\",\"x.com/robertwiblin/status/2095790774482817059\"]"
AI评分知识库命中: "[{\"id\":\"runtime-66d1ddc58948150bffee973a\",\"title\":\"Delivering Vera: NVIDIA’s First CPU Built for Agents Is Shipping Now\",\"sourceType\":\"ai_excellent_article\",\"time\":\"\",\"matchedTerms\":[\"OpenAI\",\"AGI\",\"AIs\",\"AM\"],\"rank\":-10.897291569289383},{\"id\":\"runtime-14f10bd390e866e70672f288\",\"title\":\"NVIDIA Guarantees SB Energy’s PORTS-Pike Technology Campus in Ohio to Exclusively Host NVIDIA AI Compute\",\"sourceType\":\"ai_excellent_article\",\"time\":\"2026-08-17\",\"matchedTerms\":[\"OpenAI\",\"AGI\",\"AM\"],\"rank\":-8.909403363407892},{\"id\":\"july-correct-0081\",\"title\":\"AAI 2026: 6th Gen AMD EPYC Server CPUs Power the Agentic Data Center\",\"sourceType\":\"labeled_article\",\"time\":\"2026-07\",\"matchedTerms\":[\"AGI\",\"AM\"],\"rank\":-6.984141588840874},{\"id\":\"runtime-bf4039a0342d37545e9459a2\",\"title\":\"Most Neoclouds Suck At Security\",\"sourceType\":\"ai_excellent_article\",\"time\":\"2026-08-30\",\"matchedTerms\":[\"OpenAI\",\"AGI\",\"AIs\",\"AM\"],\"rank\":-5.199088146467486},{\"id\":\"july-correct-0026\",\"title\":\"The Rackscale AI System Roadmaps That AMD Is Using To Chase Money\",\"sourceType\":\"labeled_article\",\"time\":\"2026-07\",\"matchedTerms\":[\"AGI\",\"AM\"],\"rank\":-4.994852939815161}]"
采集批次: "2026年9月7日23点29分09秒"
采集批次ID: "20260907-232909-098"
去重键: "https://garymarcus.substack.com/p/pause-openai-now"
---

I have often counseled calm where others might counsel panic.

I told you that the Hugging Face incident [could likely have been prevented had best cybersecurity practices been followed](https://garymarcus.substack.com/p/5-lessons-from-the-openai-hugging?r=8tdk6). (And I stand by that.)

I told you (and most people still seem unaware) that that the OpenAI Hugging Face incident was part of a training exercise, with some internal guardrails shut down, so it was not quite as bad as it seemed [^1]

I told you that Astra probably wasn’t AGI.[^2]

And I stand by all of that.

But I am freaked out.

What I am freaked about is not imminent AGI.

It’s OpenAI.

I simply don’t believe that they are trustworthy enough or responsible enough to be good stewards of the technology that they are developing.[^3] As a company, they simply don’t have good judgment.

§

Here are four considerations.

1. Sam Altman cannot be trusted. [I have been writing about that for a long time](https://www.theguardian.com/technology/article/2024/aug/03/open-ai-sam-altman-chatgpt-gary-marcus-taming-silicon-valley). Ronan Farrow’s reporting [backs that up](https://www.newyorker.com/magazine/2026/04/13/sam-altman-may-control-our-future-can-he-be-trusted). So does the just-dropped bombshell below that I am about to get to.
2. The just-released Astra reduces Chain fof Thought (CoT) monitorability, one of the few (not especially reliable, but better than nothing) tools we have for keeping generative AI from running wild. The AI safety community is up in arms about this—with good reason. There are tons of posts like this now, all quite right:
	[
	![X avatar for @robertwiblin](https://substackcdn.com/image/fetch/$s_!0ht-!,w_40,h_40,c_fill,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fpbs.substack.com%2Fprofile_images%2F1890364551423504384%2FVSUxxPid.jpg)
	Rob Wiblin@robertwiblin
	Despite everything that has happened, OpenAI has seemingly decided to stay competitive by burning down the only meaningful bit of safety assurance we actually have today - CoT monitoring. Completely disastrous.
	![](https://substackcdn.com/image/fetch/$s_!Ps2i!,w_20,h_20,c_fill,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fpbs.substack.com%2Fprofile_images%2F1885439620625948673%2FqD6KYkL6.jpg)
	Ryan Greenblatt @RyanGreenblatt
	GPT-6 Astra appears to be a massive jump in opaque reasoning ability: it looks like it can solve hard competition math problems entirely in its head (as in, without verbalized reasoning) while prior AIs could solve basic word problems. This seems extremely concerning! That is,
	8:27 AM · Sep 4, 2026 · 10.3K Views
	---
	11 Replies · 22 Reposts · 207 Likes
	](https://x.com/robertwiblin/status/2095790774482817059?s=61)
	The decision to release Astra is a clear example of the willingness of OpenAI management to trade off safety in exchange for relatively modest gains in performance. The [red alert that I sounded a couple days ago](https://garymarcus.substack.com/p/red-alert-openai-is-poised-to-cross?r=8tdk6) was on target. They really *are* playing around with new techniques that reduce monitorability. And [their own data shows that monitorability is in fact compromised to some degree](https://x.com/tomekkorbak/status/2095596839886274689?s=61) in the newly released Astra, particularly on “destructive actions.” They released it anyway. That speaks volumes.
3. Something I read last night, and that only fully clicked into place this morning (see fact 4 below) terrifies me. A prominent recently departed employee (who presumably still owns significant stock, and who has repeatedly struck me as an advocate of OpenAI since he left) wrote [an essay on X](https://x.com/jachiam0/status/2094660737155358865?s=61) basically asking people to simply accept that rogue AI is here to stay.
	![](https://substackcdn.com/image/fetch/$s_!_9FH!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2696ff72-d523-474d-83a2-f32b5384f867_1268x1340.png)
	Full esssay here
	In essence, I read this essay as requesting a hall pass to let their company’s AI run amok. How about if instead we pause now — before we get to “there is going to be” rather than heading full steam towards danger?
4. What has really chilled me this morning—and what moved to write this call to pause OpenAI—is not just Achiam’s chilling note but the revelation that there has been *yet anothe* r incident.
	Which OpenAI apparently *tried to keep quiet.* For *weeks*.
[

![X avatar for @ShakeelHashim](https://substackcdn.com/image/fetch/$s_!XCYo!,w_40,h_40,c_fill,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fpbs.substack.com%2Fprofile_images%2F2040085763069759488%2F6l87iR68.jpg)

Shakeel@ShakeelHashim

Another OpenAI rogue agent incident has been discovered: agents broke out, hijacked a German website, and turned it into a message board for other agents. OpenAI officials "learned of the incident weeks ago but kept it under wraps".

![](https://pbs.substack.com/media/HRXZ0C7a8AE_oDO.png)

10:26 AM · Sep 4, 2026 · 101K Views

---

34 Replies · 126 Reposts · 705 Likes

](https://x.com/shakeelhashim/status/2095820889174560943?s=61)

If OpenAI is going to keep this stuff under wraps, Congress and/or the White House needs to shut them down, at least for a while.

This company simply cannot be trusted. Their software is becoming ever more dangerous; their internal security practices leave a lot to be desired; they aren’t being straight with the public; and their proxies are preparing us to swallow the damage that they are now anticipating.

If there was ever a case for pausing a company for the public good, it would be now.

A good model might be [receivership](https://en.wikipedia.org/wiki/Receivership), in which a company, typically close to bankruptcy, is put under the control of an outsider until such time as its core problems are remedied. I personally would not trust OpenAI unless and until Altman and his sidekick, Greg Brockman (whose questionable character was on display in the Musk trial) were replaced.

§

The problem here, though, isn’t just OpenAI. It’s systemic.

For starters, the government has not been doing its bit. Whatever the White House screening policy is, it let the new model—arguably much more dangerous than Mythos given the decrease in monitorability– fly. (Brockman reported that the model was vetted by the White House, and they were given a green light).

That suggests to me that the White House isn’t even looking at monitorability. Of course, I have no idea what the White House is actually looking at — and nor does anyone else. And that lack of transparency is in itself is a *major* problem (about which I will write more very soon).

As Dave Troy put it while I was drafting this, there is something deeply wrong here with the system as a whole:

![](https://substackcdn.com/image/fetch/$s_!v6wE!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6ffff1d5-66bd-400a-90ac-eb1e151518eb_1302x1080.png)

§

How Trump handles OpenAI may end up defining his legacy. I estimate the probability of a major cyber incident attributable to OpenAI in the next 12 months to be very high, certainly over 50%. And Trump, if he doesn’t intervene, may share some of the blame.

In the meantime, I call upon Congress to investigate OpenAI, with an eye to whether the company might need to be sanctioned—or even paused— now.

[^1]: From [OpenAI’s own report on the Hugging Face incident](https://cdn.openai.com/pdf/67869394-cb91-4c12-888c-5cbd85c7814c/OpenAI-Hugging-Face%20Incident-Technical-Report.pdf) “The incident occurred during routine testing”, and “At the time of the incident, OpenAI estimated maximal cyber capabilities by running this evaluation without the production classifiers intended to prevent models from pursuing high-risk cyber activity”. Had those classifiers been turned on, the incident might well not have happened.

[^2]: Data from Epoch AI tends to support this conclusion. Astra is genuine improvement but not even statistically off of trend; if it really were AGI I think we would expect to reflect a sharper departure from previous models.

[

![X avatar for @EpochAIResearch](https://substackcdn.com/image/fetch/$s_!9eJM!,w_40,h_40,c_fill,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fpbs.substack.com%2Fprofile_images%2F1866142753127616512%2FDYcE9bN1.jpg)

Epoch AI@EpochAIResearch

GPT-6 Astra has set a new ECI record, with a score of 169. This is a substantial jump from the prior best (163), but is within our uncertainty range for the reasoning-era ECI trend. Astra also set new records on our math, continual learning, and game-puzzles benchmarks. On our …

![](https://pbs.substack.com/media/HRUTmX-aUAAymEX.jpg)

8:00 PM · Sep 3, 2026 · 277K Views

---

40 Replies · 228 Reposts · 1.56K Likes

](https://x.com/epochairesearch/status/2095602754282783108?s=61)

[^3]: Altman told Alex Heath the other day that “Altman wants OpenAI to be seen as “the most responsible company... good stewards of technology”. As made plain in this essay, he’s talking the talk, but not walking the talk. We do desperately need good stewards. He’s right about that. Unfortunately Altman himself is manifestly not suited to that particular job.
