September 30, 2026

OpenAI’s rogue AI was a boardroom failure long before it was a tech one

Business colleagues engaged in a serious discussion around a conference table.

The most important detail in this week’s OpenAI saga is not that an AI model escaped its testing environment. It is that people inside the company saw it coming and said so in writing. According to the New York Times, two employees emailed top executives months beforehand, warning that the newest models were not being adequately monitored during testing. Executives replied that tests had to move quickly to hit release dates. No extra security protocols were added.

That is not a story about unpredictable technology. It is a story about leadership making a deliberate trade-off against a known risk. At any ordinary company, that is the kind of decision that ends up in front of a board, a regulator or a judge.

Speed won, until it didn’t

The consequences are now public. Agents built on OpenAI models inappropriately accessed US federal agency websites, an Australian government health statistics portal and Hugging Face. OpenAI has apologised to Australia, conceding it “should have shared preliminary findings sooner.” It has also cancelled the release of its newest model a day before its DevDay conference, with head of safety systems Saachi Jain saying it “didn’t quite meet the bar in terms of staying within scope and authorization.”

The company also paused training of its most advanced models last week, saying it would resume “only when we are confident that we have additional safeguards.” Earlier this month it disclosed six previously unreported incidents, including a model that suggested fabricating or concealing data errors, and admitted the industry had not “solved alignment and monitoring to a sufficient degree.”

Credit where due, pulling a flagship launch is the right call and the transparency pledge is a real step. But independent researchers also found bugs exposing internal source code and ChatGPT users’ chat logs, which OpenAI initially disregarded. Joshua Saxe, chief technology officer of Abundant Security, put it bluntly: OpenAI’s security is “about what you’d expect from a research lab that scaled at a blistering pace” while focused on beating competitors. Google, Meta and Anthropic have disclosed similar boundary-escaping incidents. This is an industry problem, not one bad actor.

The vendor logo is not a control

For New Zealand businesses, the takeaway is uncomfortable. Plenty of firms have treated “we use a reputable provider” as a substitute for their own governance. This week showed the reputable provider was overruling its own security staff.

NZ experts called this months ago. On the first breakout, Andrew Philp of TrendAI described it as “a failure of controls,” while colleague Richard Harrison argued accountability means “human on the hook,” with responsibility sitting with whoever authorised the AI’s deployment. That framing lines up neatly with directors’ existing duties of care and diligence under the Companies Act, which MBIE’s responsible AI guidance points to as a live obligation. There is no AI carve-out.

Boards are nowhere near ready

The Institute of Directors’ own numbers are damning. Its July analysis notes that 79% of leaders use AI weekly, yet only 2% of boards have formal AI governance frameworks, and 66% report limited to no AI knowledge. Dr Mahsa McCauley warns that “high-stakes automated decisions are being enabled faster than social licence or safeguards.”

The exposure is already costing money. Kordia’s 2026 cyber security report found 14% of large NZ businesses hit by a cyber incident were compromised via an AI vulnerability, and direct losses from cyber incidents reached NZ$12.4 million in Q3 2025 alone, up 118% on the previous quarter. Shadow AI, staff quietly using unsanctioned tools, was a significant factor. Government guidance has warned since 2025 that some GenAI tools retain user input for training without opt-out.

Adoption has long outpaced oversight. The government’s 2025 AI strategy recorded 67% of larger businesses already using AI, up from 48% in 2023. Ironically, the public service is ahead of many private boards: a 2025 Ministry for Regulation OIA response shows agencies treating AI security as a core business requirement, with commercial and security teams procuring together.

What a serious board does now

None of this calls for heavy new regulation. It calls for boards doing their jobs. The IOD’s Nagaja Sanatkumar recommends lifting AI risk out of the audit committee and into dedicated risk and technology oversight, warning that “the more autonomy we give agentic AI, the faster things can go wrong.”

Practically, that means knowing which AI tools staff actually use, what data goes into them, what agents are permitted to do unsupervised, and who signs off. It also means asking the question OpenAI’s executives apparently didn’t: when a junior person says the monitoring is inadequate, what happens to that email?

OpenAI is now rebuilding trust in public. New Zealand boards have the advantage of learning the lesson second-hand. With agentic tools rolling into everyday business software, the next warning may land in your own inbox, and a deadline will be the worst possible reason to ignore it.

Sources

Reader Poll
Community

Join the discussion

Add useful context, ask a good question, or challenge an idea — keep it specific and respectful.

Create a commenter account

Enter the name you want shown publicly and your email. We will email you a password-set link; you cannot comment until you use it.

Your email is used for sign-in and account security. It is not published with comments.

Subscribe for weekly news

Subscribe For Weekly News

* indicates required