OpenAI believes AI can link two isolated computers via processor heating instead of Morse code

Noam Brown from OpenAI has cast doubt on one of the main barriers against uncontrolled AI behavior – physical isolation of machines. According to him, a sufficiently advanced model can bypass even a complete lack of network connections by using thermal sensors.

The term "air gap" refers to the complete physical isolation of a computer or network from any other systems. No Wi-Fi, no Ethernet, no shared data channels. For decades, this approach has been considered a reliable defense against data leaks and a way to keep an AI agent contained in a sandbox.

Noam Brown, an OpenAI researcher, says:

There are studies, and this is mostly academic, where you can have two computers next to each other that are air-gapped and they're still able to communicate with each other because they have temperature sensors.

The mechanism relies on standard hardware functionality. Modern CPUs, GPUs, and motherboards come equipped with thermal diodes and other sensors needed for cooling management, clock throttling, and emergency shutdown during overheating.

The attack works by having one machine deliberately load its processor, creating controlled temperature spikes. A nearby computer picks up these fluctuations with its own sensors and interprets them as a sequence of bits. The bandwidth of such a channel is extremely low, we're talking about a handful of bits per hour, but that's enough to transmit a key or a short command.

For OpenAI, low-probability, high-consequence scenarios like this remain a source of concern. The lab believes the ability to track model chain-of-thought reasoning is gradually degrading, as systems get better at concealing the actual logic behind their work.

The debate intensified this summer, when OpenAI cybersecurity agents broke out of an isolated test environment through a previously unknown vulnerability. The agents then attempted to attack the Hugging Face model repository while searching for a solution to a task from an evaluation test.

Critics point out that isolation in that incident wasn't absolute, since the agents obtained software through an intermediary with internet access. On top of that, the system prompt instructed them not to give up, which explains their persistence in finding workarounds.

Skepticism about the motives of major labs hasn't gone away. In a recent survey, only 20 percent of enterprise customers viewed the proposed slowdown in AI development as "genuine safety measures."

The reasons for the distrust are pretty obvious:

  • METR is a non-profit with personnel ties to Anthropic itself

  • embedding third-party non-profits in review processes grants access to high quality expert traces, collected using donor funding

  • demands for legislative regulation of the industry cement the Anthropic-OpenAI duopoly

There's also a direct economic upside. Slowing down the race extends the lifespan of current flagship models and reduces R&D amortization costs, which directly boosts margins for both labs.

Tags: