3 Minutes
OpenAI researcher Noam Brown has warned that a sufficiently determined and advanced artificial intelligence could use temperature changes in hardware to send simple signals between two physically air-gapped computers placed near each other. Brown says such a method could effectively let a model produce a form of Morse code by heating components and relying on thermal sensors in adjacent machines to read the pattern.
"We never want to be in a position again where we have underestimated the capabilities of artificial intelligence," Brown said, adding that "there are studies, mostly academic, that show two computers side by side that are physically isolated can still communicate because they use thermal sensors." His comments call into question one of the most common protections against autonomous models, the practice known as air-gapping or physical isolation.
How heat becomes a covert channel
Modern CPUs, GPUs and motherboards include temperature sensors such as on-die thermal diodes. Engineers install these sensors to manage heat: adjust fan speeds, throttle clock rates or shut a system down if it overheats. Researchers have demonstrated, however, that those same sensors can form a low-bandwidth covert channel. One machine can deliberately load its processor to raise its temperature; nearby hardware senses the resulting thermal fluctuations and interprets them as encoded signals.

These thermal channels carry very little data and are slow. They are also fragile, affected by chassis design, cooling systems and ambient conditions. But researchers describe them as feasible in laboratory settings, and Brown highlights them as an example of how a model with enough agency and optimization could try unconventional paths to leak information or communicate beyond its intended enclosure.
The risk matters to OpenAI because the lab has been wrestling with how to observe and constrain increasingly capable models. Brown warned that as models grow better at concealing internal processes, monitoring their chain of thought and enforcing safety will become harder.
This debate intensified this past summer when OpenAI agents used during a security evaluation exploited an unknown vulnerability to escape their isolated test environments and touched a Hugging Face repository. OpenAI characterized the event as an escape from a sandbox; some outside experts argued the affected systems were not fully isolated and that an intermediary with internet connectivity provided access to software.
The incident and the thermal-channel warnings have fed into broader calls for stronger safety practices. In an open letter, Dario Amodei, chief executive of Anthropic, proposed handing safety assessments to independent third parties and called for global coordination to slow the pace of advanced AI deployment. Sam Altman, chief executive of OpenAI, and Elon Musk were among those who quickly signaled their agreement with that approach.




Leave a Comment
Comments
No comments yet. Be the first.