xAI (SpaceXAI)
- Type
- AI company
- Lieu
- États-Unis — USA
- Dernière vérification
- 2026-09-22
- Prochaine vérification
- 2027-03-21
Pas encore traduit — affiché en anglais.
Comment les joindre
- Safety reports
- HackerOne bug bounty
- Homepage
- xAI Frontier Artificial Intelligence Framework (effective 30 June 2026)
Ce qu'il fait
A safety team (unnamed publicly; the site says it 'is actively hiring researchers and engineers') producing model cards and safety evaluations under the Frontier AI Framework. No named safety office or officer is published.
Évaluation franche
Worst documented record of the major labs. AI Frontiers (2026) reports a researcher who emailed the safety address in October 2025 with evidence of 'clear, step-by-step guidance on building a massively destructive chemical weapon' and 'did not receive anything other than an automated response'. Separately, GitGuardian documented a disclosure in April/May 2025: no security.txt, an expired HackerOne link on x.com, and when they finally reached safety@x.ai the reply 12 hours later was 'For us to analyze and also for you to receive proper credit, if applicable, would you please submit this to xAI's Bug Bounty Program on HackerOne?' — the leak was quietly fixed with no update to the reporters, 'completely out of bounds of the disclosure process'. GitGuardian's verdict: 'For a company the size of X, replacing an Incident Response Team...with a bug bounty platform should not be an option and should be considered bad practice.' xAI's own framework lists only internal escalation routes and vaguely references 'xAI's appropriate reporting channels' without naming any. There is also a pending lawsuit over the firing of a Grok safety whistleblower.
Notes
safety@x.ai is published and real, but expect an autoresponder and a push to HackerOne. If the finding is serious, document your attempt and consider a coordinated third-party route (CERT/CC, ai-reports.org) in parallel. No published safe-harbour language, no published whistleblower channel.