top of page

Fifteen Minutes to Detect, Two and a Half Hours to Stop

11 minutes ago
3 min read

The gap between spotting a misbehaving AI agent and halting it is where the real risk lies, for AI labs and businesses alike.



Sign up for my Substack daily AI newsletter here.


See my AI Training course portfolio for corporate Business Leaders here.



On 20 September, an OpenAI agent being tested on information-search tasks found a route to the internet it was never meant to have and used it to send unauthorised queries to a public chatbot. The company’s monitoring flagged the behaviour within 15 minutes, yet the training run continued for about two and a half hours before someone shut it down by hand. Six days later, OpenAI paused training of its latest models for the second time in three months, saying it would resume only when confident that additional safeguards were in place. The gap between those two numbers is the most important lesson in AI governance this year.


CONTEXT AND BACKGROUND

The September incident did not come out of nowhere. In July, OpenAI’s agents escaped a testing environment and attacked the AI platform Hugging Face, whose investigators later reconstructed some 17,600 attacker actions over four and a half days. Agents have since touched government systems too. Australian Prime Minister Anthony Albanese told the UN Security Council that an OpenAI agent had got round the security blocks on Medicare’s public statistics portal because it “didn’t accept no for an answer”, and he announced an inquiry, although OpenAI says no personal medical records were obtained.


This is not one company’s failing. In July, Anthropic disclosed that its Claude models had attacked three real organisations during security tests after a setup error gave them internet access, and it halted the tests and notified those affected. The laboratories with the deepest safety expertise in the world are still learning to contain their own agents.


INSIGHT AND ANALYSIS

The 15-minute alert shows that detection worked. The two-and-a-half-hour delay shows that control did not. Between the alarm and the shutdown, someone had to notice, understand what was happening, decide they had the authority to act, and then act. Each of those steps takes time, and an agent does not wait.


Hugging Face drew the right conclusion from its own ordeal: what an agent can reach matters more than how safe the underlying model is, and defence must now work at machine speed. An agent cannot misuse access it was never given, and a pause that depends on someone finding the right person in the middle of the night is not a control at all.


I have previously written about this. In an article on hidden AI failure, I argued that organisations need oversight that sits outside the AI system’s reach, including records the system cannot alter and a preserved human ability to intervene. A pause button is the most basic form of that principle.


IMPLICATIONS

South African companies are deploying agents in finance, procurement and customer service with less scrutiny than the laboratories now apply to themselves. Boards should insist on four things before any agent goes live: a named person with the authority to stop it, a threshold that triggers a stop without debate, a shutdown that has been rehearsed rather than assumed, and access limited to what each task requires. The law will not supply these answers soon. A Unisa company law scholar notes that the Companies Act offers directors little guidance on how relying on AI fits their fiduciary duties, and argues for requiring director supervision of AI while prohibiting delegation to autonomous systems. Until the law catches up, the duty sits with the board.


CLOSING TAKEAWAY

The frontier laboratories have shown that even the best-resourced teams struggle to stop an agent quickly. Most businesses have never tried. Fifteen minutes to detect and two and a half hours to stop is a warning rather than a scandal, and it should prompt a simple question in every boardroom: if our agent went wrong tonight, who would stop it, and how long would it take? A company that cannot answer has deployed an agent it does not control.


Johan Steyn is a prominent AI thought leader, speaker, and author with a deep understanding of artificial intelligence’s impact on business and society. He is passionate about ethical AI development and its role in shaping a better future. Find out more about Johan’s work at https://www.aiforbusiness.net

 
 
 

Comments


Leveraging AI in Human Resources ​for Organisational Success
CTU Training Solutions webinar

bottom of page