Sam Altman Says Some Hacks and Scams Are the Price of Wider AI Access

Sam Altman said society should accept "some bad things happening" as the tradeoff for AI's benefits. He named hacks, scams and "other bad things" as costs to expect. He said people will do "tremendously orders of magnitude more good stuff" with AI. The Verge
Altman spoke on Politico's Decoded podcast, released Monday. The discussion centered on how widely AI systems should be deployed, and how much misuse should be treated as the cost of that deployment. He said broad access will lead to abuse, and he prefers that outcome to restricting access in an effort to prevent abuse entirely.
He said he would not accept a deal promising no major hacks, no misuse of AI, zero scams and zero other bad things. Business Insider He argued AI technology should stay broadly accessible. Reuters He said he does not accept "the really catastrophic risks" of AI.
He described that willingness to accept harm while pursuing broader benefits as a key difference between OpenAI and Anthropic. He called OpenAI "pragmatic centrists," between Anthropic's more cautious approach and those who want little to no regulation. In that framing, OpenAI accepts measurable misuse but draws the line at catastrophic outcomes.
The broader context here is one we have seen before with widely used platforms. Email enabled phishing. Cloud computing enabled large-scale theft of login credentials and abuse for cryptomining, or using other people's computers to earn cryptocurrency. APIs, the standard connections that let software systems talk to each other, enabled scraping and automated fraud. Operators did not withdraw those capabilities. They managed misuse with rate limits, or caps on how fast a service can be used, abuse detection, incident response and legal rules for responsibility.
In my view, what stands out is how openly Altman stated the tradeoff. Technology leaders usually talk about safety as driving harm toward zero, or as close to zero as engineering allows. Altman instead described a level of tolerance. Some hacks and scams will happen, prevention will be imperfect, and deployment should continue. That is a plainer statement of risk appetite than the industry usually gives, and it raises harder questions about how harm is measured, who is accountable, and what recourse is available to people affected.
Looking ahead for builders and operators, the work shifts from prevention alone to running systems while abuse continues. That includes how fast attacks are spotted, how they are contained, how AI-made content is identified, how vulnerable steps are checked, and how records are kept for review when AI-assisted deception is part of an incident. It also puts weight on defaults, the built-in settings most people never change. Broadly accessible systems are used by teams without dedicated safety or security staff, so the controls that matter most are the ones that work without expert tuning. The optimistic case, which is the one Altman is making, is that this work is worth doing because broad access lets many more teams solve practical problems, automate routine work and build new tools. The cost is real, and it will show up in security workloads and fraud losses, but the long-term payoff is more people able to put the technology to useful ends.


