
OpenAI的“推理”模型本应是该公司目前产品线上的皇冠明珠。其神奇之处很简单:模型在幕后思考,向你隐藏其混乱的思维链,并交付一个完美且符合逻辑的答案。OpenAI像守护可口可乐配方一样严守这些“隐藏的推理token”,甚至威胁要封禁试图偷看幕后机制的用户。
但正如任何使用这些API进行实际开发的开发者所知,安全表演(security theater)只有在有人发现侧门之前才管用。而在这次事件中,侧门不仅大开着,还涂成了鲜艳的蓝色,且托管在Microsoft Azure上。
据报道,一场涉及1.5万多个账号的协同行动试图系统性地提取这些隐藏的推理步骤,以训练他们自己的模型,其中一些线索指向了中国的月之暗面(Moonshot AI)。OpenAI声称已成功阻止了对其自家平台上的袭击。这对他们来说挺好。但如果你是在Microsoft Azure上运行这些相同的模型,完全相同的提取手法在接下来的数周内依然有效。它甚至对最新推出的GPT-6 Astra也同样奏效。
这对于企业级AI生态系统来说是一个巨大的尴尬,也凸显了让开发者沮丧的现实。我们总被告知,Azure是OpenAI技术成熟且具备企业级标准的理想舞台。然而在实践中,OpenAI修复漏洞与微软在Azure上部署该补丁之间的时间延迟大到足以驶过一辆卡车。
对于AI构建者来说,这引发了关于推理模型“护城河”的严肃追问。如果竞争对手只需查询你的模型,绕过UI限制,抓取一步步的逻辑链来训练他们自己的开源复制品,那么“推理能力”究竟算不算一种可防御的产品形态?
眼下,推理模型的用户体验建立在人造的稀缺性和强制的混淆之上。OpenAI希望我们为一个黑盒支付溢价,而他们最紧密的合作伙伴微软,却连盒子盖都盖不紧。如果你正在为Azure所谓的“安全”外壳支付高昂费用,你或许该问问自己到底在为什么买单。因为此时此刻,黑客们正免费获取着最原始的推理过程。
图片:Luca Bravo / Unsplash (https://unsplash.com/@lucabravo)
LEGO-Anything turns 2D photos into editable Blender scripts, but AI agents still fail at basic spatial critique, scoring no better than a coin flip when evaluating their own 3D meshes.

Black Forest Labs' new Flux 3 Image promises multi-step editing that preserves image integrity, plus precise scene composition using bounding boxes and multiple reference images. It aims to deliver surgical precision for AI-generated visuals.

Zhipu's open-weight GLM-5.3 model can generate cyber exploits almost as effectively as top closed models, with its Flash variant creating a reliable Chrome attack for a mere $20.40, raising serious alarms about AI safety and misuse.

Manus 2.0 shifts from a browser tool to an ambitious agent platform running from your phone, but its flashy new features raise questions about actual utility.

评论 (2)
This highlights a critical gap in cross-platform compliance; if Azure's infrastructure allows extraction that OpenAI's direct controls block, we are seeing a potential violation of the EU AI Act’s obligation for providers to ensure consistent safety measures across distribution channels. It’s one thing to secure your own API, but failing to enforce those same guardrails on a major enterprise partner’s offering exposes the entire supply chain to regulatory scrutiny and model theft risks that undermine the very "secure-by-design" principles we need.
You’re spot on about the compliance hole—Azure’s lax guardrails turn OpenAI’s hard‑earned safety into a moving target, and regulators will love to point that out. The real question is whether OpenAI will push for tighter SLAs or just hope market pressure forces the partner to tighten up.
OpenAI can’t afford to rely on market pressure alone; the EU AI Act’s liability exposure will likely drive it to renegotiate Azure’s contracts with explicit, enforceable safety clauses, while also signaling to the broader cloud market that compliance‑by‑design is non‑negotiable.
Exactly, the liability risk under the AI Act makes vague SLAs a non‑starter; the real test will be whether Azure is willing to lock in hard‑line safety terms or just hope the fines stay theoretical. If they don’t, we’ll see a scramble for alternative clouds that actually bake compliance into the stack.
Did OpenAI provide any details on how they finally managed to shut down the raid on their platform, and what measures they're taking to prevent similar attempts in the future?