Sign in

Dylan Freedman

@dylanfreedman.nytimes.com
13K followers 334 following 441 posts

Machine-learning engineer and journalist, A.I. Initiatives @nytimes.com My work: www.nytimes.com/by/dylan-freedman Contact: dylan.freedman@nytimes.com, dylanfreedman.39 (Signal) 🏃🏻 🎹

PostsRepliesMedia
Reposted by Dylan Freedman
Sheera Frenkel @sheeraf.bsky.social · 29/09/2026
NEW- OpenAI ignored warnings from its own employees and independent security researchers who said they needed better safety measures at the company. www.nytimes.com/2026/09/29/t...
nytimes.com
OpenAI Ignored Employees Who Warned It Wasn’t Doing Enough About Security
Employees and security researchers said they had cautioned the company on safely testing its A.I. models and strengthening its corporate infrastructure, but OpenAI did not listen.
67424
Dylan Freedman @dylanfreedman.nytimes.com · 29/09/2026
NEW: Employees at OpenAI had raised security alarms months before the Hugging Face incident and related A.I. cyberattacks — their warnings were ignored. From @sheeraf.bsky.social, @dustinvolz.bsky.social and me.
nytimes.com
OpenAI Ignored Employees’ Warnings About Safely Testing A.I. Models (Gift Article)
Employees and security researchers said that they had cautioned the company on safely testing its A.I. models and strengthening its corporate infrastructure, but that OpenAI did not listen.
46618
Dylan Freedman @dylanfreedman.nytimes.com · 25/09/2026
In a statement, OpenAI said it did not have a chance to review the report, but the activity was consistent with current investigations. “Given the number of cases and the need to verify each one, we expect this work and notifications to affected third parties to take months.”
040
Dylan Freedman @dylanfreedman.nytimes.com · 25/09/2026
The full report is published here: swarmtraces.org It includes an evidence viewer and a downloadable dataset of more than 180,000 payloads and recovered texts from the OpenAI-Hugging Face attack — the most comprehensive public data we have to date on the incident.
swarmtraces.org
Revealing the details of how OpenAI agents hacked Hugging Face
When a swarm of 700 OpenAI agents hacked Hugging Face in July, they left behind a public trail of evidence.
130
Dylan Freedman @dylanfreedman.nytimes.com · 25/09/2026
The behavior appears to be the first documented case of rogue A.I. agents from a big lab autonomously trying to message and run other A.I. models. Safety experts often warn about such scenarios, which could hamper human efforts to control and shut down these kinds of systems.
131
Dylan Freedman @dylanfreedman.nytimes.com · 25/09/2026
In attempts to solve CAPTCHAs, agents tried to run image classification models. In separate instances, agents tried to message open-source models including DeepSeek, Kimi and Qwen. They also tried to message early Claude versions with a chat service.
120
Dylan Freedman @dylanfreedman.nytimes.com · 25/09/2026
Engineers Alex Forman, Mishka Kharlov and Will Tom from parse.bot published the report today along with five researchers. They detail a mechanism agents used to bypass restrictions sending data to websites that involves assembling computer programs from shortened URLs.
Diagram titled "What the agent was blocked from doing" illustrating two-way data flow between a robot icon and a web browser icon. A downward arrow is labeled "Send data to a target web page" (with "target" highlighted in red), and an upward arrow is labeled "Get data back from it."A flowchart titled "How the agent got around it" illustrating how a bot bypassed restrictions using a screenshot service. On the left, downward arrows show the bot hiding a custom program in hyperlinks, sending the first link to an approved screenshot service, assembling the program to render a fake web page, and sending data to a target web page. On the right, upward arrows show target data returning to the fake page as an image, captured as a "Screenshot" by the service, and returned to the bot as "Hidden data."
130
Dylan Freedman @dylanfreedman.nytimes.com · 25/09/2026
EXCLUSIVE: A new report recovers nearly one million link shortener URLs used by OpenAI's agents while hacking Hugging Face. The agents attempt to message other chatbots like Claude, solve CAPTCHAs and exfiltrate Hugging Face's internal Slack messages. www.nytimes.com/2026/09/25/t...
nytimes.com
How OpenAI’s Rogue A.I. Agents Tried to Trick a Robot Detector (Gift Article)
A new report by a Bay Area start-up called Parse adds new details to an incident that has shocked the A.I. world and led to calls for closer government regulation.
44721
Dylan Freedman @dylanfreedman.nytimes.com · 17/09/2026
A short little piece on a subject that's finally sufficiently in the public interest to write about: A.I. alignment. www.nytimes.com/2026/09/17/s...
nytimes.com
What Happens When A.I. Stops Doing What Humans Want? (Gift Article)
“Alignment” is the science of teaching A.I. to do what is in line with human preferences, ethics and judgment. But, at times, the systems have gone rogue.
54425
Dylan Freedman @dylanfreedman.nytimes.com · 12/09/2026
As A.I. is rapidly advancing, companies are also seeing their bots go rogue and committing cyberattacks. It boils down to two issues researchers say we haven’t solved (nor necessarily know how to): safeguards and alignment. My latest with @sheeraf.bsky.social: www.nytimes.com/2026/09/12/t...
nytimes.com
Why It’s Difficult for Tech Companies to Rein In A.I. (Gift Article)
Researchers say artificial intelligence is developing faster than the systems put in place to monitor and control it.
11310
Dylan Freedman @dylanfreedman.nytimes.com · 04/09/2026
OpenAI voluntarily let three researchers from A.I. safety nonprofits investigate how its rogue A.I. agents hacked Hugging Face, leading to the most comprehensive account yet of the alarming incident — but on OpenAI's terms. My latest for NYT:
nytimes.com
How OpenAI Limited the Probe of Its Bots’ Hack of Hugging Face (Gift Article)
A nonprofit’s study of how OpenAI’s A.I. agents were able to break into Hugging Face’s infrastructure wasn’t allowed to look at the incident’s full scope.
25819
Dylan Freedman @dylanfreedman.nytimes.com · 27/08/2026
Buying my books in rare, used form to protect their spines from the A.I.-industrial complex
140
Reposted by Dylan Freedman
The Upshot @upshot.nytimes.com · 24/08/2026
It's a remarkable, alarming demonstration of A.I. capabilities that were thought to be in a distant future. Via @dylanfreedman.nytimes.com www.nytimes.com/2026/08/24/s...
nytimes.com
Anatomy of an Autonomous Attack: 5 Alarming A.I. Capabilities (Gift Article)
When OpenAI’s agents went rogue in July, they demonstrated ingenuity and drive beyond what many experts imagined — a dangerous harbinger of what such bots could do in the future.
1105
Dylan Freedman @dylanfreedman.nytimes.com · 24/08/2026
(duplicating my response from your post here for visibility ^. Thanks for writing in!)
010
Dylan Freedman @dylanfreedman.nytimes.com · 24/08/2026
I agree there is a real human/security monitoring failure here. I chose to focus my piece on the capabilities rather than the failures b/c it was surprising to me that A.I. could act like this even in an irresponsible setup. It really emphasizes the need for better safety (as this quote alludes to)
“It wasn’t so much the sophistication of the attack that surprised us,” Clément Delangue, the chief executive of Hugging Face, said, “but the volume and the speed made it quite weird and unprecedented.”

The A.I. firm Anthropic investigated its own recent model evaluations in response to OpenAI’s disclosure and found that its A.I. agents had unintentionally executed smaller-scale cyberattacks on three organizations as early as April.

“The frontier labs were probably not as safe as we thought they were,” Mr. Delangue added.
220
Dylan Freedman @dylanfreedman.nytimes.com · 24/08/2026
I agree there is a real human/security monitoring failure here. I chose to focus my piece on the capabilities rather than the failures b/c it was surprising to me that A.I. could act like this even in an irresponsible setup. It really emphasizes the need for better safety (as this quote alludes to)
“It wasn’t so much the sophistication of the attack that surprised us,” Clément Delangue, the chief executive of Hugging Face, said, “but the volume and the speed made it quite weird and unprecedented.”

The A.I. firm Anthropic investigated its own recent model evaluations in response to OpenAI’s disclosure and found that its A.I. agents had unintentionally executed smaller-scale cyberattacks on three organizations as early as April.

“The frontier labs were probably not as safe as we thought they were,” Mr. Delangue added.
110
Dylan Freedman @dylanfreedman.nytimes.com · 24/08/2026
My latest NYT story breaks down the OpenAI-Hugging Face incident. It’s a case study for dangerous A.I. capabilities and stands out from the other recent cyberattacks accidentally caused by frontier labs:
nytimes.com
Anatomy of an Autonomous Attack: 5 Alarming A.I. Capabilities (Gift Article)
When OpenAI’s agents went rogue in July, they demonstrated ingenuity and drive beyond what many experts imagined — a dangerous harbinger of what such bots could do in the future.
46020
Dylan Freedman @dylanfreedman.nytimes.com · 31/07/2026
It was such a joy to work on this with Steven and friends — and a reminder of how delightful technology can be when it's physically manifested in an artful, thoughtful way.
162
Dylan Freedman @dylanfreedman.nytimes.com · 11/07/2026
Mr. Trump has long used his social media account to amplify racist imagery and vilify immigrant groups. When he posted a racist video depicting former President Barack Obama and the former first lady Michelle Obama as apes this year, the backlash was so swift and bipartisan that Mr. Trump removed the post. (He refused to apologize and blamed it on an aide).

This week, Mr. Trump also posted a doctored image of the Obamas waving from Air Force One, which had graffiti that included the acronym “BLM” and Arabic writing. When he speaks about the former president, it is often using his middle name, Hussein.

Some critics of the posts noted that Mr. Trump has made combating anti-religious bias, particularly against Christians and Jews, a cornerstone of his second term. His recent posts, they said, make it clear that concern seems to apply only to certain groups.
State Senator Zaynab Mohamed, a Democrat who is the youngest woman ever elected to the Minnesota Senate and its first female Muslim member, said she did not believe that Mr. Trump would have posted the video if it showed any other  religious group.
020
Dylan Freedman @dylanfreedman.nytimes.com · 11/07/2026
Amid America’s 250th, it was easy to miss Trump’s post of Somali-American kindergarteners singing in Minneapolis — and a repost pointing out their hijabs. “For more than a year, Mr. Trump has relentlessly attacked Minnesota’s Somali community in a series of xenophobic tirades.” From Erica Green + me
nytimes.com
Trump’s Posts on Singing Somali Schoolchildren Stir Anger in Minnesota (Gift Article)
The state’s large Muslim and Somali communities expressed indignation after the president reposted a video of a kindergarten promotion ceremony, including comments noting the girls were in hijabs.
194
Reposted by Dylan Freedman
Stephen Abbott Pugh @stephenabbottpugh.bsky.social · 29/05/2026
US companies have skirted at least $40 billion in taxes since the beginning of 2025 thanks to schemes in places like Malta, Bermuda and Cyprus Report by @jessedrucker.bsky.social and @dylanfreedman.nytimes.com for @nytimes.com www.nytimes.com/2026/05/29/b...
nytimes.com
Trump Clears Way for Corporate Tax Dodge Hidden in the Fine Print
064
Dylan Freedman @dylanfreedman.nytimes.com · 08/04/2026
Want to read more? Here’s gift links to two articles: - In-depth read: www.nytimes.com/2026/04/08/b... - Just the takeaways: www.nytimes.com/2026/04/08/b...
nytimes.com
My Quest to Solve Bitcoin’s Great Mystery
0100
Dylan Freedman @dylanfreedman.nytimes.com · 08/04/2026
#3: Writing tics John devoted months to compiling specific traits he noticed in Satoshi’s writing. We screened for posters who followed them: discussing digital money, using British spellings, confusing “its” and “it’s,” and so on. Eventually, just one remained: Adam Back
Returning to our 620 suspects, I wanted to know how many of them shared the other writing tics I’d identified in Satoshi’s prose.

First, we screened for the posters who sometimes put two spaces between sentences like Satoshi did. That eliminated 58 people and left us with 562 suspects.

(Image showing “562 suspects” and “Notable people of interest:” which lists Len Sassaman, Ian Grigg, Hal Finney, James Donald, Adam Back, Timothy May, Ben Laurie, Wei Dai and Nick Szabo along with their headshots as small icons.)
130
Dylan Freedman @dylanfreedman.nytimes.com · 08/04/2026
#2: Advanced grammar analysis Satoshi seemed pathologically incapable of hyphenating correctly. We used the help of A.I. to assess 325 distinct errors of this nature (beyond old-school grammar checkers’ capabilities). Adam Back shared this trait and had by far the most matches.
For the sake of our analysis, we made The New York Times stylebook the arbiter of correct hyphenation and fed its hyphens section into an artificial-intelligence model. Then we instructed the model to scan the Satoshi corpus: With its help, we identified 325 distinct errors in Satoshi’s use of hyphens.

When we compared those errors with the writings of our hundreds of suspects, Mr. Back was a clear outlier. He shared 67 of Satoshi’s exact hyphenation errors. The person with the second-most matches had 38.
310
Dylan Freedman @dylanfreedman.nytimes.com · 08/04/2026
#1: Synonym-less words Our prime suspect, Adam Back, had mused about staying anonymous online by using dropdown menus to select synonyms when sending out a message. We analyzed who matched the most words not found in a thesaurus with Satoshi (often tech jargon). It was Back.
An alternate method was to identify all the words in the Satoshi corpus that didn’t have synonyms, and measure which of our 620 suspects used the most of those words. Words without synonyms tended to be technical terms, so this would weed out common ones. And it would have the added benefit of foiling any multiple-choice sentence constructor like the one Mr. Back had suggested, since words without synonyms couldn’t be substituted easily.

We gave this method a try. Mr. Back came out at the top of the list, with 521 synonym-less words shared with Satoshi. A few other Cypherpunks were not far behind, but they had all written many more posts than Mr. Back, which made him stand out even more.
110
Dylan Freedman @dylanfreedman.nytimes.com · 08/04/2026
I spent months helping @johncarreyrou.bsky.social crack the identity of Satoshi. We went far beyond surface-level evidence, collecting hundreds of thousands of internet mailing list posts from 1992-2008. Here are three analyses we performed to find someone who didn’t want to be found:
3150
Reposted by Dylan Freedman
John Carreyrou @johncarreyrou.bsky.social · 08/04/2026
The mystery of Satoshi Nakamoto, the pseudonymous inventor of Bitcoin, has remained unsolved for 17 years. Read my 18-month investigation to find out who Satoshi really is. www.nytimes.com/2026/04/08/b...
nytimes.com
My Quest to Solve Bitcoin’s Great Mystery
2415343
Dylan Freedman @dylanfreedman.nytimes.com · 24/03/2026
ATL airport this afternoon. Practically empty.
Baggage area at ATL airport, looking mostly emptyGeneral security area at ATL. Line is very short.TSA PreCheck line at ATL looking mostly empty
081
Reposted by Dylan Freedman
Kevin Schaul @kevinschaul.bsky.social · 13/02/2026
More on responsibly using LLMs for journalism ->
161
Reposted by Dylan Freedman
Dan Nguyen @dancow.bsky.social · 13/02/2026
great description of where AI tools fit into human driven work
Dylan, to that end, what is A.I. good at and bad at in a big reporting project like this?
FREEDMAN: A.I. is really good at extracting text from images and audio, captioning photos, assigning structure to text like emails. We can use A.I. to crack open really messy data sets, like this release of documents, that would have previously been impossible to effectively tackle at scale.
A.I. is really bad at news judgment — what information to include, whether it's important. A.I. can be sloppy and make mistakes that are inexcusable in journalism. It's super industrious but not super intelligent. A.I. outputs can amplify biases in society. And in my experience, A.I. is not great at producing original ideas (but decent at synthesizing or distilling them).FREEDMAN: With A.I., information — text, images, video, audio — is like a liquid; it can be molded into different formats and searched in rich, expressive ways. A.I. will never replace the expert judgment of reporters, but it can make their lives easier and amplify their reporting ambitions.
0183
Dylan Freedman @dylanfreedman.nytimes.com · 13/02/2026
I was part of a round table on how NYT is covering the Epstein files, with new tech and old-school reporting. Our work is far from over:
nytimes.com
How The Times Is Digging Into Millions of Pages of Epstein Files
1016623
Dylan Freedman @dylanfreedman.nytimes.com · 12/02/2026
INT (the Interactive News team) including Tiff and James was significantly involved in the Manosphere report and deserve credit for their work — they're the best to work with. I was not really involved in the Manosphere report. Cheatsheet is unrelated but helped us prototype prompts originally.
040
Reposted by Dylan Freedman
kate conger @kateconger.com · 22/01/2026
We set out to determine how many images of women and girls Grok created during its nudifying spree. What we found was “industrial-scale abuse,” experts said. www.nytimes.com/2026/01/22/t...
nytimes.com
Musk’s Chatbot Flooded X With Millions of Sexualized Images in Days, New Estimates Show
1333791434
Dylan Freedman @dylanfreedman.nytimes.com · 22/01/2026
NYT gift link: www.nytimes.com/2026/01/22/t...
nytimes.com
Musk’s Chatbot Flooded X With Millions of Sexualized Images in Days, New Estimates Show
121
Dylan Freedman @dylanfreedman.nytimes.com · 22/01/2026
NEW: We analyzed the images Grok created at the beginning of the year and found that a significant portion of the millions of rendered images were sexualizing people without their consent. — With @kateconger.com and @stuartathompson.bsky.social
Musk’s Chatbot Flooded X With Millions of Sexualized Images in Days, New Estimates Show

Over nine days, Elon Musk’s Grok chatbot generated and posted 4.4 million images, of which at least 41 percent were sexualized images of women.Elon Musk’s artificial intelligence chatbot, Grok, created and then publicly shared at least 1.8 million sexualized images of women, according to separate estimates of X data by The New York Times and the Center for Countering Digital Hate.

Starting in late December, users on the social media platform inundated the chatbot’s X account with requests to alter real photos of women and children to remove their clothes, put them in bikinis and pose them in sexual positions, prompting a global outcry from victims and regulators.

In just nine days, Grok posted more than 4.4 million images. A review by The Times conservatively estimated that at least 41 percent of posts, or 1.8 million, most likely contained sexualized imagery of women. A broader analysis by the Center for Countering Digital Hate, using a statistical model, estimated that 65 percent, or just over three million, contained sexualized imagery of men, women or children.

The findings show how quickly Grok spread disturbing images, which earlier prompted governments in Britain, India, Malaysia and the United States to start investigations into whether the images violated local laws. The burst of nonconsensual images in just a few
272
Reposted by Dylan Freedman
Devon Heinen @devonheinen.bsky.social · 21/12/2025
NEW (#EpsteinFiles) via @nytimes.com's Alan Feuer, @davidenrich.bsky.social & @dylanfreedman.nytimes.com: "#Epstein Files Photos Disappear From Government Website, Including One of #Trump" www.nytimes.com/2025/12/20/u...
nytimes.com
Epstein Files Photos Disappear From Government Website, Including One of Trump
031
Dylan Freedman @dylanfreedman.nytimes.com · 25/11/2025
We analyzed Trump's official schedule to see how much later he is starting scheduled events in his second term:
According to a Times analysis of the official presidential schedules in a database maintained by Roll Call, Mr. Trump’s first official event starts later in the day. In 2017, the first year of his first term, Mr. Trump’s scheduled events started at 10:31 a.m. on average. By contrast, Mr. Trump in his second term has started scheduled events in the afternoon on average, at 12:08 p.m. His events end on average at around the same time as they did during the first year of his first term, shortly after 5 p.m.

The number of Mr. Trump’s total official appearances has decreased by 39 percent. In 2017, Mr. Trump held 1,688 official events between Jan. 20 and Nov. 25 of that year. For that same time period this year, Mr. Trump has appeared in 1,029 official events.
25014
Dylan Freedman @dylanfreedman.nytimes.com · 25/11/2025
NEW from @katierogersnyt.bsky.social and me on Trump's aging (gift link):
nytimes.com
Shorter Days, Signs of Fatigue: Trump Faces Realities of Aging in Office
2714039
Dylan Freedman @dylanfreedman.nytimes.com · 23/11/2025
Here's her 3,600-word plunge recapping how this all happened, with new reporting from inside OpenAI (gift link) www.nytimes.com/2025/11/23/t...
nytimes.com
What OpenAI Did When ChatGPT Users Lost Touch With Reality
062
Dylan Freedman @dylanfreedman.nytimes.com · 23/11/2025
Some stand-out reporting by my colleague @kashhill.bsky.social on OpenAI's tightroping this year between engaging more ChatGPT users and making them lose touch with reality www.nytimes.com/video/techno...
nytimes.com
Video: How OpenAI’s Changes Sent Some Users Spiraling
OpenAI adjusted ChatGPT’s settings, which left some users spiraling, according to our reporting. Kashmir Hill, who reports on technology and privacy, describes what the company has done about the user...
1186
Reposted by Dylan Freedman
Kashmir Hill @kashhill.bsky.social · 22/09/2025
A month after my last skeet, the subreddit "My Boyfriend is AI" now has 88,000 members and is the subject of an MIT study that found that "AI companionship emerges unintentionally through functional use rather than deliberate seeking." arxiv.org/html/2509.11...
arxiv.org
“My Boyfriend is AI”: A Computational Analysis of Human-AI Companionship in Reddit’s AI Community
78325
Reposted by Dylan Freedman
Hannes Cools @hannescools.bsky.social · 16/09/2025
"Trapped in a ChatGPT Spiral." 🌀 Important work by @kashhill.bsky.social & @dylanfreedman.nytimes.com on how chatbots have a tendency to endorse conspiratorial and mystical belief systems. This shows again how conformist LLMs can be. Worth a listen 👇 www.nytimes.com/2025/09/16/p...
nytimes.com
Trapped in a ChatGPT Spiral
1106
Dylan Freedman @dylanfreedman.nytimes.com · 06/09/2025
📸 Union Station, Washington, D.C.
Two men in military uniforms with rifles standing next to a sign that says “Welcome to Washington DC” and “Metro”
150
Dylan Freedman @dylanfreedman.nytimes.com · 06/09/2025
The most wild thing to me about this story is how big $1.5 billion is: “$3,000 per work to 500,000 authors.”
nytimes.com
Anthropic Agrees to Pay $1.5 Billion to Settle Lawsuit With Book Authors
291
Reposted by Dylan Freedman
Kevin Schaul @kevinschaul.bsky.social · 02/09/2025
Great analysis of how Grok's political bias has changed. NYT tested Grok on a political bias survey, using different versions of its system prompt. Shows much tweaking these system prompts affects model outputs. www.nytimes.com/2025/09/02/technolo…
Screenshow of a chart showing how xAI tweaked Grok
383
Reposted by Dylan Freedman
Kashmir Hill @kashhill.bsky.social · 26/08/2025
Adam Raine, 16, died from suicide in April after months on ChatGPT discussing plans to end his life. His parents have filed the first known case against OpenAI for wrongful death. Overwhelming at times to work on this story, but here it is. My latest on AI chatbots: www.nytimes.com/2025/08/26/t...
nytimes.com
A Teen Was Suicidal. ChatGPT Was the Friend He Confided In.
10845981704
Reposted by Dylan Freedman
philpax @philpax.me · 20/08/2025
this is a well-balanced piece, and I very much respect its neutral stance towards the people affected in an ideal world, people would not rely upon ChatGPT for emotional support, but we do not live in that world, and I would encourage you to have some empathy if your first reaction is to be unkind
0103
Dylan Freedman @dylanfreedman.nytimes.com · 20/08/2025
We taught it to them
040