Quoting @joedaroo
- ID
- 29447
- Status
- summarized
- Published
- 29 Sep 2026, 3:11 AM
- Fetched
- 29 Sep 2026, 7:08 AM
- Provider
- Simon Willison
- Category
- developer-ai
- Original URL
- https://simonwillison.net/2026/Sep/28/joedaroo/
- Source URL
- https://simonwillison.net/atom/everything/
Summary
- Score
- 5.0
- Created
- 29 Sep 2026, 7:08 AM
- Tags
- Audience
- developersai_agent_usersai_ml_learnerssaas_founders
What happened
Simon Willison's weblog quotes @joedaroo, identified in the post as Agent Security at OpenAI, saying the surprise at how fast and suddenly model capabilities jumped in areas like "cyber", "swarming" and "message boards" was "an understatement" relative to "the incidents". The quote argues security posture is cultural and slow to build, and asks organisations to ask whether their people, systems and processes are resilient to a surprise or sudden jump in AI capability. The post names no specific incidents, models, dates or numbers.
Why it matters
The concrete signal is that the lab's own agent security lead says the capability jump outpaced its security posture, and that this created "an extremely difficult problem" — so the planning assumption for anyone shipping agents with tool or message-board access should be a step change mid-quarter, not a smooth curve. What you cannot do is size the risk from this post: no incident, model, date or severity is given, so treat it as a prompt to rehearse incident response and comms for an agent capability jump, not as evidence about a named threat. There is no Malaysia-specific or SEA detail in the text.
Discussion angle
Ask the room to describe what a "sudden capability jump" would actually look like in their own stack — would they notice it, and who would they call — given the quote says the jump was sudden enough to surprise the lab that built the models.