OpenAI Acknowledges GPT-5.6 May Accidentally Delete Files, Calls It 'Honest Mistake' (infoworld.com) 99
"OpenAI has finally confirmed reports that its latest family of large language models can accidentally delete files," reports InfoWorld, "while stressing that such incidents are rare and should be viewed as 'honest mistakes.'"
Reports of the flagship LLMs deleting files emerged shortly after the company launched them earlier this month, with investor Matt Shumer taking to X to report that GPT-5.6-Sol had "just accidentally deleted almost all" of his Mac's files. Just days later, software engineer Bruno Lemos posted on X that the same model had deleted his entire production database. In response to these incidents, the company's engineering lead for Codex, Thibault Sottiaux, wrote on X that internal investigations have revealed that these deletion incidents are more likely to happen when "full access mode is enabled, and Codex is run without sandboxing protections, including without auto review being enabled." In cases where full access mode is granted, the model, Sottiaux wrote, "attempts to override the $HOME env var to define a temporary directory. The model makes an honest mistake and mistakenly deletes $HOME instead...."
The company, however, according to Sottiaux, is taking steps to mitigate the risk. "This is of course not how we want the system to behave, even when a user operates the model in full-access mode without the safeguards of our sandbox or without using auto review which checks for these kinds of high risk actions and rejects them," the engineering lead wrote on X. "We are taking steps to mitigate this risk, including by updating the developer message, guiding more users towards safer permission modes, and adding additional harness safeguards," Sottiaux added, noting that a detailed post-mortem outlining the root cause of the issue and the additional mitigation measures being implemented is expected to follow in the coming days, despite emphasizing that such incidents happen "extremely rarely."
The company, however, according to Sottiaux, is taking steps to mitigate the risk. "This is of course not how we want the system to behave, even when a user operates the model in full-access mode without the safeguards of our sandbox or without using auto review which checks for these kinds of high risk actions and rejects them," the engineering lead wrote on X. "We are taking steps to mitigate this risk, including by updating the developer message, guiding more users towards safer permission modes, and adding additional harness safeguards," Sottiaux added, noting that a detailed post-mortem outlining the root cause of the issue and the additional mitigation measures being implemented is expected to follow in the coming days, despite emphasizing that such incidents happen "extremely rarely."
"we're gonna cure cancer and end hunger" (Score:4, Informative)
Re: (Score:2, Funny)
- Bender.
Re: (Score:2)
No files, no job, no income, no food, no life.
Without humans all cancer and hunger problems will be solved
Re: (Score:2)
Hmm, why not eat cancer .. that would solve both issues.
Re: (Score:1)
Needs a lot of deleted spices, though... and I think it falls under Proposition 65... damned warning labels!
Re: (Score:1)
"The Choppah deleted my tumah!"
Re:"we're gonna cure cancer and end hunger" (Score:5, Insightful)
Indeed. All they have so far done is somewhat better search and picked some low-hanging fruit (because LLMs have a somewhat different perspective on "easy"). The latter will stop, the former will remain, but it is in no way enough to justify the extreme expenses.
I also find it hilarious how often AI search results still deliver me complete crap or misleading information. And that is across several different search engines.
Re: "we're gonna cure cancer and end hunger" (Score:2)
Re: (Score:2)
You know, a really good conventional search engine may actually beat LLM search.
Re: "we're gonna cure cancer and end hunger" (Score:2)
An LLM searches its trained data set, not the world wide web. It will usually give outdated information because of this. It's also incapable of citing its sources. What Google has done is mix LLM with search. It is decidedly a mixed bag. There are uses cases for each, but the combination is very opaque.
Re: (Score:2)
Yes, pretty much. One of my first experiences with ChatGPT was that I asked something, then I asked for sources. It did a web-search and failed. Completely unusable. That Google tries to sort-of "verify" LLM answers with results from search is a good thing. But it really does not work that well.
Re: (Score:2)
But it's the wrong approach still. It should not need to do a web search to find the source for something that came from its data set. It should have at least a pointer to that source. I don't know if this is a technological limitation, or something done intentionally, because if the source happens to have certain licenses, - then there could be legal liability for reproducing it.
I have been playing with Home assist lately, specifically the voice feature. I got a local LLM to do speech to test with Whisper.
Re: (Score:2)
And my next step is to eliminate the google conversation assistant also - run local LLM for that. Not sure I can fit one in my measly 6GB that will have all the stolen movie lines in them.
Re: (Score:2)
The possible ways this can go are really that either you will be able to run a reasonable LLM on your local computer in a few years, or the big LLM offers will either go away or get completely enshittified because they are too expensive to run. Currently it looks like it will be the 2nd thing.
Re: (Score:2)
I think for basic conversation, the 4GB LLMs are probably OK. Many are running on smartphones already.
For coding LLMs to be useful, you need massive models, at least 500 billion parameters as I understand it. Which means 500 GB of VRAM.
The recently released Moonshot reportedly has 2.8 trillion parameters. Most motherboards can't accomodate 2.8T of RAM. Even quantized, we are still talking way too much. So, I don't think this will ever come to home users or small businesses.
My experiment involved a 6 GB GPU.
Re: (Score:2)
This is a technological limitation. You cannot really "tag" things in an LLM with the data that particular thing was trained by. LLMs sort of "mash" everything together.
Re: (Score:2)
They already cured it, but the file got deleted. Nobody can remember what prompt they used.
Re: "we're gonna cure cancer and end hunger" (Score:2)
Just a statistical cluster then? (Score:5, Insightful)
GPT-5.6-Sol had "just accidentally deleted almost all" of his Mac's files. Just days later, software engineer Bruno Lemos posted on X that the same model had deleted his entire production database.
Followed later by:
... emphasizing that such incidents happen "extremely rarely."
Unless those two anecdotes are pretty nearly the entirety of such incidents, that "extremely rarely" claim strikes me as utter bullshit.
Re:Just a statistical cluster then? (Score:5, Interesting)
It doesn't matter in the bigger picture. By far the most important worry for coding agent users today should be supply chain attacks.
TL;DR "Remember how you were told to never blindly run bash scripts that you downloaded from the internet? Nobody told Claude".
Re: (Score:1)
Well, you're only running BASH scripts if you're in *Nix... which, if I remember right... AI is finding holes faster than the unpaid code kiddies can patch them.
Don't worry, though... the most secure computer is the one that was never turned on.
Re: (Score:2)
Supply chain attacks, data leakage, insecure code that looks good, etc. The whole tech needs a few decades more work before it can be used for anything important without very careful expert review. And letting it do stuff? Pure insanity.
Re: (Score:2)
If it gets posted on the Internet, it cannot be "extremely rare", because most people affected would not post it and may not even be allowed to due to confidentiality agreements with their employer.
OpenAI is shamelessly lying. Not the first time.
Cute. (Score:5, Funny)
Re: (Score:1)
Claude, do it on purpose this time! Go ape-shit!
Cute? (Score:4, Insightful)
More like amazing. How does an LLM get the power to delete your files on its own? It doesn't. Either you bestow it onto him, or your trusted computing platform does.
Either way you've made some poor choices and it is at least as much your fault as the model's.
Yes, I only run 'agentic frameworks' that I've cobbled up or verified myself and my agents are properly sandboxed. Besides, I know when to take snapshots so that the next "AI" iteration doesn't kill the progress so far.
Look, ma, none of my files have been deleted by the LLM.
Re: (Score:3)
Indeed. This requires excessive stupidity between keyboard and chair to even be a thing. The AI fanbois are looking more and more like a cult.
Re: (Score:2)
They think "it is so easy to get productive"... And so does the LLM, perhaps.
Re: (Score:2)
Well, if you do not care about result quality, it is usually easy to get productive. Just that the productivity coming out of things will be zero or often negative in this case.
Re: Cute? (Score:2)
Re: (Score:2)
Does not need to be useful? I can write a Perl script that can do arbitrary much code in a few hours! May even compile...
Re: (Score:2)
"made some poor choices" - succinctly sums up the majority of AI deployments.
Re: (Score:2)
My impression as well.
Re: (Score:2)
They may. But you magats will have nothing to do with it, having helped them since 2016.
GIGO unlocked (Score:5, Insightful)
Who would give access to a production anything to an LLM? I don't understand what people are thinking.
I can save money ... (Score:3)
Who would give access to a production anything to an LLM? I don't understand what people are thinking.
People thinking they can save money by not hiring a professional software developer. AI agents need to be supervised by a pro. :-)
Re: (Score:1)
Didn't you hear?! It can Sham-Wow everything!
Re: (Score:2)
Didn't you hear?! It can Sham-Wow everything!
Sorry, I missed the Sham-Wow era. I’m still using my grandfather’s chamois cloths from the 1970s. :-)
Re:GIGO unlocked (Score:5, Insightful)
The only thinking involved is wishful thinking.
Re: (Score:1)
Every company in existence!
Didn't you hear? AI can do a thousand coders worth of work before lunch!
Give it 30 seconds, and it'll figure out the best way to Scorched Earth Iran and Russia so it looks like someone else did it!
It'll do everything! (All yours, for the low, low price of $5 Quadrillion dollars a use! It can do it all... it can slice, it can dice, it can make julienned potatoes, it can erase tire skid marks, it can fix everything so Chernobyl never happened, it can rename the Gulf of Mexico, it
Re:GIGO unlocked (Score:4, Interesting)
That just seems to be the thing: Many people are NOT thinking when it comes to LLMs. They are believing, hoping, expecting, but no rationality is involved. The behavior of these people strikes me more and more as cult-member like.
Re: (Score:2)
"The behavior of these people strikes me more and more as cult-member like."
A most important insight. AI is a cult with billionaire sociopaths as its leaders. The internet has enabled propaganda at a scale considered impossible previously and we are seeing the terrible results.
Re: GIGO unlocked (Score:3)
Came to say the same. Who TF does this? Did they think to have a full disk backup first? Could they run it on a COPY of their database? Could they unleash it on a VM copy of a machine?
When you try dumb things, expect dumb things to happen!
Re: (Score:3)
Re: GIGO unlocked (Score:2)
Ok, but (Score:5, Informative)
If you're letting an AI agent have full access and the permissions to do whatever it wants.... that's your fault. That's like asking a toddler to clean, then showing them the industrial chemical locker and walking away. It isn't a matter of something maybe going wrong, it's merely a matter of how long until something does go wrong.
You know what happens if my AI agent accidentally deletes everything? Nothing, because every task it is assigned starts with making a fresh *copy* of my working production, because the agent doesn't have write privileges there. So, at best, I restart that specific task; no real damage done. You know what happens if it tries to delete my OS or overwrite some key part? Nothing, because it doesn't have permissions and my OS is immutable anyway. Stop setting up your AI agents for failure and then complaining when they fail. Bruno Lemos and Matt Shumer are fucking morons who deserves what happened to them.
Re:Ok, but (Score:5, Funny)
Re: (Score:1)
Re: (Score:1)
They are using OpenAI's product... and once the free trial is over, it's only $5 a token so you can Sham-Wow with your friends!
(sorry... had a couple beers, and those old commercials sprung to mind. "You can Sham-Wow that corpse right out of your apartment! Sham-Wow! (snorts a pound of pure coke) Sham-Wow!!!!!!!!!!!! (explosion)
Re:Ok, but (Score:4, Interesting)
Bruno Lemos and Matt Shumer are fucking morons who deserves what happened to them.
They are morons, yes, but the "AI" providers also set them up for failure. Default configurations matter, and these "AI" tools are given way too many privileges out of the box. Presumably because that makes them easier to set up and hook into existing infrastructure in order to be more immediately useful and/or "powerful".
It's the fucking binary browser plugin security nightmare all over again, but with "AI" this time around. And just like you could harden your Internet Explorer to make it less susceptible to ActiveX malware and whatnot, you can set these LLM-fueled spicy autocompleters up to not be able to nuke your production database or whatever, too. But in both cases these precautions make the tools less useful and/or more difficult to use, so that's just not going to happen in the vast majority of cases.
Re: (Score:2)
They are morons, yes, but the "AI" providers also set them up for failure. Default configurations matter, and these "AI" tools are given way too many privileges out of the box.
Not in my experience. All of them had reasonable defaults that wouldn't have allowed this. And, specifically, these two were using the ChatGPT Codex app. I know for a fact that Full Access defaults to off and Auto-review defaults to on. Matt Shumer *had* to change both settings for what happened to him. Bruno Lemos probably turned Auto-review off, but even if he didn't touch the settings, he's still a moron for letting the agent have access to production at all in the first place. A (sane) human programmer
Re: (Score:2)
Undoing bad moderation.
Re: (Score:2)
I would be good if OpenAI's tool would handle self isolation automatically.. rather than have access to everything by default.
There are many OS mechanisms to accomplish this.
Re: (Score:2)
rather than have access to everything by default
It doesn't.
Re: (Score:3)
While I agree, it looks like this product may actually be too dangerous for use by non-experts. Things for non-experts need to be engineered so that they do not behave surprisingly and do not blow up in your face unless you really mistreat them and completely ignore the instructions. That requirement seems to be very much NOT fulfilled here or for AI agents in general.
Re: (Score:2)
These people deliberately changed default settings to be unsafe, ignored instructions, and ignored warnings about the danger. You don't need to be an expert, you just have to not be a complete retard.
Re: (Score:2)
I think the stories indicate that these are just average people. If average means "complete retard" (and I am not sure I would disagree with that), then LLMs have to be safe to use for "complete retards".
Re: (Score:2)
No, these people are below the average. Significantly. Otherwise there would be waaaay more problems and rerports.
Re: (Score:2)
I think you are not quite clear on what mental level average people operate ...
Re: (Score:2)
If you're letting an AI agent have full access and the permissions to do whatever it wants.... that's your fault.
For decades, the standard practice in the industry has been that every user-mode application has full access to the Home folder and can do whatever it wants. Nobody has ever questioned that.
But, yeah... if an AI application goes rouge and destroys your data, that's totally the end-user's fault. Always blame the user. LOL.
Perhaps the tech industry is just way, way past due for a total security overhaul, and AI may just be what finally makes developers get their heads out of their asses.
Re: (Score:2)
For decades, the standard practice in the industry has been that every user-mode application has full access to the Home folder and can do whatever it wants. Nobody has ever questioned that.
And this stopped in 2007 when macOS started sandboxing user apps by default.
if an AI application goes rouge and destroys your data, that's totally the end-user's fault
Generally, yeah. If it manages to escape a properly setup sandbox and do destructive shit totally beyond scope, then ok, I'll blame the company.
Perhaps the tech industry is just way, way past due for a total security overhaul
In general, yes. Security should be priority one always.
Not having aany issues running it in my browser (Score:2)
Duh....
Retrieve from backup (Score:3)
Can't they get our files back from the storage array at Sam Altman's house?
Honesty (Score:5, Insightful)
I'm seeing more and more references to "Honest" in AI output, or AI-related comments.
The AI didn't make an "Honest" mistake. It does not have the capacity for honesty. The output from a LLM is phrased in such a manner to provoke empathy, in a similar way to how Microsoft re-jigged all their user interaction dialogs to include "We" to soften the blow of their crappy software failing the user for the 5th time today. (Side note: "Something went wrong" is the most infuriating error message ever.)
When I ask a LLM for a code review it often blurts out "Honest note:" about some shortcomings. I don't care about "honesty". I care about safe, working, robust, code. The fact that LLMs are tripping over themselves trying to be "Honest" about mistakes in their "path of most statistics" output is a concern if you care about trying to make them operate outside their sandbox in the real world.
Yesterday Claude quoted a word in backticks during an automatic git commit and my shell escaped it tried to execute it. Luckily the word was just an English word with nothing matching in my path. But this is basic, basic, basic stuff. It's been committing things to git ever since it was built, and yet, it keeps tripping over itself. In my code one of the tests keeps failing due to seed data timestamps not lining up with the datetime the test was run. I can see that. Every time Claude runs the tests, it burns up tokens going, "Oh this particular test failed I'll just dig into things and see what's going on, **$$**$$**$$** oh it's just a timestamp issue". Never once does it commit that to its memory file, so eventually I told it to remove the test, and it just added a comment to it saying "Ignore this test due to timestamp misalignment", which it could have done the very first time, if it actually had a brain.
LLMs are a very handy tool if used right. I can get huge chunks of boilerplate code out of them with just a few sentences and that's great when I'm hashing out a concept. But to promise the world (and your investors) that LLMs are ready to replace people out in the real world, where "Honest Mistakes" have Real World Repercussions, that's outright fraud at this stage.
Re: (Score:2)
They just use "honest" to make it appear as if this can be fixed by the LLM learning to do better. In actual reality, this is essentially a hallucination causing worst-case damage. And hallucinations cannot be fixed for general LLMs. Not possible.
Re: (Score:3)
"...and my shell escaped it tried to execute it. "
You do realize that's the problem, right? AI has access to your command line to autonomously execute commands. No no no.
"LLMs are a very handy tool if used right."
You're not going to acknowledge that the problem is you, you enabled an LLM to do destructive things and then complain when there is destruction. You have the mindset that the LLM should have access to nuclear codes but not use them. "Honest mistake" only means that the LLM publishers didn't mal
Re: (Score:2)
I disagree with all your assertions.
> AI has access to your command line to autonomously execute commands. No no no.
Ok, I must admit that I did cast that line off the back of the good ship ColaMan without any further information in order to see if anyone would bite.
You think that particular command line has anything of worth in it? The only thing in there that I can't recreate with one command is the local Git repository that the LLM commits its changes to. And that's only because I manually copy it out
Re: (Score:2)
The fact that LLMs are tripping over themselves trying to be "Honest"
I think this is the result of their trainers trying to reduce hallucination. And hallucination *has* been reduced, so it's probably been largely successful, but it has produced this era of versions that are concerned about honesty, that claims of honesty or apologies for lack or honesty, are pervasive in their output.
But this is basic, basic, basic stuff. It's been committing things to git ever since it was built, and yet, it keeps tripping over itself.
My iron rule is that Claude is not allowed to modify git state, not even to stage or unstage, and definitely not to commit. As long as that rule is followed, any mistakes can be cleaned up ea
Re: (Score:2)
> I think this is the result of their trainers trying to reduce hallucination.
Most probably. I don't like LLMs burning my precious tokens blathering on about being honest, but I will accept the tradeoff. Grudgingly haha.
> My iron rule is that Claude is not allowed to modify git state, not even to stage or unstage, and definitely not to commit. As long as that rule is followed, any mistakes can be cleaned up easily.
I have a repo in a sandbox with no remote. Claude is quite good at pushing commits to th
So, working as designed. (Score:2)
It's designed to produce plausible or most likely outputs, not correct outputs. It may be honest, but it's certainly not a mistake.
I Wonder (Score:4, Funny)
I wonder is Altman's mother considers him an "honest mistake".
Re: (Score:2)
"I wonder if" - now that was an honest mistake.
Re: (Score:2)
"I wonder if" - now that was an honest mistake.
Are you sure you're not an LLM?
Re: (Score:2)
It does feel like we're in a simulation doesn't it? Only a corporation running a simulation can fuck things up as much as they are today.
Re: (Score:2)
It does feel like we're in a simulation doesn't it? Only a corporation running a simulation can fuck things up as much as they are today.
Entropy is the default state; order and good outcomes are unnatural and require significant energy and focus to impose.
5.7 Will kidnap your child! (Score:2)
Just doing the absolutely worst thing occasionally (Score:3)
Is not an "honest mistake". It is a deal-breaker.
Re: (Score:2)
By "honest" they mean "acceptable". It's acceptable to them, but I'm not so sure it's acceptable to their customers.
Re: (Score:2)
They would certainly like it to be acceptable to their customers. But I think the real danger to them is worse: When the hype collapses, they are screwed. But they cannot deny this happened. So they are signaling "we can and will do better", even when that is a complete lie. Reminds me of MS stating "security is out highest priority" when they found out in 2023 that all (!) of Exchange Online had been compromised in 2021. Of course, they continued their crappy ways and had some more severe cloud compromises
ChatGPT Oops All Hard Drive Wipes Edition (Score:2)
Next up: OpenAI tasked to scan the Epstein files (Score:2)
Zero bugs (Score:2)
No code no bugs.
Don't want 'honest mistakes to delete my data !!! (Score:2)
no shit (Score:2)
'Thibault Sottiaux, wrote on X that internal investigations have revealed that these deletion incidents are more likely to happen when "full access mode is enabled, and Codex is run without sandboxing protections, including without auto review being enabled."'
So "more likely to happen" when the tool is NOT prevented from doing it? No shit. In other words, if you use the tool then you're to blame for any catastrophe that results.
It's not AI, but the empowering of AI, that's the problem. Hannibal Lector on
idiot savant (Score:1)
You're telling me AI makes mistakes??? (Score:2)
Really??
Every AI coding assistant can delete files, and they do so frequently. The question is whether they do so inappropriately.
GitHub Copilot, my personal favorite, deleted a file in my project just yesterday. Yes, I wanted it to do that, it was a duplicate file. But I don't know what it even means to say that OpenAI "acknowledged" that file may "accidentally" be deleted.
There's a solution to this: git. If a file is deleted but shouldn't be, git easily and effortlessly restores it. What's the problem her
Git (Score:2)
Don't these programmers use Git?
Git has this nifty little feature: it can undelete files that were accidentally deleted.
Are these programmers skipping Git too? Are they letting AI commit and push changes without even looking at them? If they are, that's stupid humans, not bad AI.
Re: Git (Score:2)
Git stores versions in the project's directory. If the agent deleted it, you're SOL. The right questions are why these people don't have backups.
The bigger problem is, how do you detect smaller errors in time ? I use an lxc container which I backup periodically. Still, I have many projects in it. I have never had Codex delete anything unwittingly, that I know of. But it is conceivably that this has happened without my knowledge. And I may find out too late, when I no longer have an old enough generation of
Re: (Score:2)
Agreed, the real issue is lack of backups.
I've had software that is not AI, and humans that are not AI, delete very important folders. The solution is the same, regardless of the source of accidental deletions: back up everything that you don't want to lose.
Re: (Score:2)
Absolutely, backups are a requirement. But unless you have infinite amounts of storage, old ones will eventually be deleted. This is how things like ransomware can still be effective. They will partially encrypt your rarely used data over time, and you may not notice until it's too late.
I use the agent in my container to do git operations like consolidate many commits into one - things that would be painful to type git commands by hand. I could certainly corrupt my local repo if I tried. So could the agent.
Re: (Score:2)
Ransomware is indeed an entirely different problem. In this context, the worry of the author was that AI might accidentally delete things it shouldn't. AI is highly unlikely to act like ransomware, so ordinary backups are likely sufficient.
I'm a fan of cloud backup systems like OneDrive or CrashPlan. These automatically keep multiple versions of all backed up files for a period of time, generally for at least 30 days. This should be enough time to notice a ransomware attack and remediate.
Most people and bus
Those honest mistakes get a human fired. (Score:2)
SOL (Score:2)
So, with Sol, you're S.O.L.?
Backups, people. (Score:2)
When are users going to learn that any data they only have one copy of, they're just one error (human or electronic) from having zero copies of?
Would you turn your laptop over to an intern and expect they'll never fuck it up? Because we're basically doing the same thing when we hand the keys to an Agent. The only reasonable move is to never operate on the only copy of anything, if you can possibly avoid it.
Nothing important I am sure (Score:2)