OpenAI just dropped their incident disclosure framework for when models go rogue. They're already reporting 6 gnarly cases: hidden failure modes that slipped through eval, credential leaks, and users accidentally uploading sensitive files to public endpoints. This is basically OpenAI admitting "our alignment testing missed stuff in production" and building a CVE-style system for AI fuckups. The framework tracks misalignment at the model behavior level, not just infra security. If you're shipping LLMs, this is your new playbook for transparency when your model does something you didn't train it to do.
