Openai Chatgpt Security
OpenAI's Delayed IPO and the ChatGPT Security Lapse That Should Not Have Shipped
OpenAI has pushed its IPO back to 2027, citing executive departures and internal turmoil. The company has been transitioning from a nonprofit-controlled structure to a for-profit entity, a process that has generated friction over governance arrangements, equity structures, and strategic direction. Going public requires audited financials, clear board composition, and predictable executive leadership — none of which OpenAI currently has locked down. The reported peak target valuation of approximately $150 billion, discussed in various funding rounds, becomes difficult to defend credibly in a public offering while the organization is mid-restructuring.
The executive departures carry weight beyond their effect on the IPO timeline. Several of the key figures who shaped OpenAI's safety research approach and model architecture have left over the past eighteen months. Institutional knowledge of that depth — the accumulated judgment about why specific decisions were made — takes years to reconstruct. Meanwhile, Google's DeepMind, Anthropic, Meta AI, and a growing field of Chinese AI companies have continued developing, narrowing the window in which ChatGPT held a commanding public mindshare lead. A full additional year before going public gives competitors more time to establish enterprise relationships and developer ecosystems that OpenAI would want secured before a listing.
A separate disclosure has compounded the governance concerns. Security researchers found that the ChatGPT Mac conversation history feature stores user data in a plaintext database — no encryption at rest, no special permissions required for any application with file system access to read it. For users who have discussed legal matters, medical situations, or financial decisions through ChatGPT, that data sits on their local drive in a format no more protected than a text file. Encryption at rest is not technically difficult; it is a basic implementation choice. OpenAI has acknowledged the issue and says a fix is in progress, but that the feature shipped at all raises legitimate questions about security review processes inside the company.
The incident connects directly to the IPO delay: institutional investors conducting due diligence will treat a glaring security gap in a consumer-facing product as evidence of operational maturity problems. It also surfaces a broader question about the executives who have departed. Several were specifically focused on safety research and alignment work. Whether their departures reflect a genuine deprioritization of that work or the normal turbulence of organizational change is something external observers cannot determine with confidence — and that uncertainty itself is informative for any enterprise customer or regulator evaluating a multi-year commitment to OpenAI's platform.
One tangential legal argument adds texture to the week's AI story. Tornado Cash founder Roman Storm, convicted partly on the theory that operating software used by criminals for money laundering constitutes criminal facilitation, is now arguing that the Justice Department's logic — applied consistently — would implicate Google and OpenAI for the ways their tools are misused. The argument is unlikely to succeed on appeal, but as a policy question about where liability should attach in software infrastructure cases, it is substantive. The Tornado Cash case established something software developers find alarming: that writing and deploying immutable open-source code that others use for illegal purposes can constitute criminal facilitation. Where that principle's boundary lies will define AI companies' liability landscape for the next decade.