The giant ChatGPT falls: a global failure paralyzes the leading AI

The most used artificial intelligence tool in the world stops working

1 minute

EuropaPress 7109148 dramatizacion busqueda chatgpt 18 noviembre 2025 madrid espana cloudflare

EuropaPress 7109148 dramatizacion busqueda chatgpt 18 noviembre 2025 madrid espana cloudflare

Add DEMÓCRATA to Google

Ask FREN

Published

Last updated

1 minute

Most read

Los servidores de ChatGPT, la herramienta de inteligencia artificial líder, ha caído a nivel global. A través de las plataformas de monitoreo como Downdetector, decenas de usuarios han reportado incidencias sobre la imposibilidad de la herramienta de responder a sus peticiones o, incluso, fallos en la url de la página web.

Así, la plataforma mantiene en espera a quienes pretendan acceder, un error que se traslada tanto a su sitio web como a las aplicaciones para iOS y Android. Por el momento, a compañía no ha ofrecido detalles sobre el origen de este colapso que afecta, tanto a particulares, como empresas, aunque sí ha confirmado que se halla en estos momentos investigando el origen del incidente.

¿Cómo solucionar el problema y qué alternativas tengo?

No existe por ahora una respuesta en manos de los usuarios que permita resolver el problema. Las alternativas a ChatGPT son múltiples, todas ellas enmarcadas en un ecosistema cada vez mayor de herramientas de inteligencia artificial. Gemini de Google, Copilot de Microsoft o Claude de Anthropic son las operadoras de IA que cuentan con un mayor número de usuarios junto a ChatGPT.

Pero, para aquellos usuarios fieles a la herramienta de Open AI lamentamos informar que tendrán que esperar a que el sistema ofrezca una solución.

More key points, information and questions with FREN

AI-GENERATED CONTENT

What are the legal and technical steps a company like OpenAI must follow to report global incidents according to international regulations?

For a global AI company like OpenAI, managing and reporting incidents (security breaches, model failures, large-scale misuse, data leaks, etc.) is not just a reputational issue: it is strongly conditioned by international regulatory frameworks and good technical practices. Below are summarized the key legal and technical steps that should be followed in a structured manner.

1. Prior governance and response plan

Before any incident occurs, the company must have:

  • Internal incident management policy aligned with standards such as ISO 27001/27035 or NIST, defining what constitutes a “global” incident, severity levels, and responsible parties.
  • Incident response team (CSIRT/IRT) multidisciplinary (technical, legal, compliance, communication) with clear roles and protocols.
  • Inventory of systems and data (which personal data is processed, in which jurisdictions, who is responsible for processing) to quickly determine which regulations apply.
  • Logging and traceability procedures that allow reconstruction of what happened, when, where, and with what impact.

2. Initial detection and classification of the incident

Upon an anomaly (for example, unauthorized access, prompt or response leaks, or systemic model malfunction):

  • Technical detection through monitoring, security alerts, logs, and intrusion or anomaly detection systems.
  • Preliminary classification: type of incident (security, privacy, model integrity, functionality abuse), geographic scope, and possible impact on user rights.
  • Activation of the incident response protocol, escalating to the responsible team according to severity.

3. Legal and regulatory analysis

In parallel with the technical analysis, specific legal obligations are evaluated:

  • Personal data (GDPR, national privacy laws): if there is a breach of personal data of European users, the data controller must assess whether there is a risk to the rights and freedoms of individuals. If so, it is usually mandatory to:
    • Notify the data protection authority “without undue delay,” often within a maximum period (e.g., 72 hours under GDPR).
    • Inform affected individuals when the risk is high, using clear and accessible language.
  • Cybersecurity and essential services (e.g., NIS2 frameworks in the EU): if the company is classified as an essential or important provider, there may be an obligation to notify significant incidents to competent authorities or national CSIRTs.
  • Platform and content regulation (e.g., DSA in the EU): if the incident affects the mass dissemination of illegal content or systemic risks, there may be reporting duties to regulators and enhanced transparency requirements.
  • Sectoral and other countries’ regulations (United States, United Kingdom, etc.), which may require notifications to regulatory agencies, contractual partners, or business clients.

4. Technical mitigation and containment

While the legal framework is analyzed, the technical team must:

  • Contain the incident: isolate affected systems, revoke compromised credentials, stop critical functionalities if necessary.
  • Preserve evidence (logs, configurations, backups) in a forensic manner for subsequent analysis and, if applicable, audit or regulatory investigation.
  • Fix vulnerabilities (patches, configuration changes, strengthening access controls).
  • Assess impact on models: if there is contamination of training data, added biases, or significant performance degradation that may affect users.

5. Notification to authorities, users, and partners

Once the scope is determined, the following must be done:

  • Notify competent authorities in each jurisdiction where there is a legal obligation, providing:
    • Description of the incident, categories of affected data, and approximate number of data subjects.
    • Probable consequences of the incident.
    • Measures adopted or proposed to address the breach.
  • Inform affected users when required by law or recommended by the principle of transparency, including steps for their own protection (password changes, activity review, etc.).
  • Communicate to business clients and partners as provided in contracts (security clauses, SLAs, DPAs), often with more technical detail.

6. Post-incident review and continuous improvement

After immediate management:

  • Internal post-mortem with analysis of technical, organizational, and process root causes.
  • Update policies and controls (security, privacy by design, model red-teaming, usage limits, and abuse monitoring).
  • Comprehensive documentation to demonstrate due diligence to regulators and auditors, and as a basis for future impact assessments (including those specific to high-risk AI models when required by regulation).

In summary, reporting global incidents in compliance with international regulations requires a close combination of technical capability, multilevel regulatory understanding, and a culture of transparency and responsibility throughout the AI systems’ lifecycle.

What competencies does the CEO of OpenAI have in managing technical crises and what is his professional experience?

The CEO of OpenAI, Sam Altman, plays a central role in managing the company’s technical and reputational crises, although his competencies are not detailed in a public regulation akin to an institution. Based on press coverage and critical episodes OpenAI has faced, both his scope of responsibility and the professional experience supporting it can be outlined.

Competencies in managing technical and security crises

In a company like OpenAI, whose product is cutting-edge AI models, “technical crises” often intertwine with risks related to security, service availability, and public trust. Sources show that Altman effectively assumes four types of competencies in these scenarios:

  • Definition of security framework and principles. In the agreement between OpenAI and the U.S. Department of Defense, Altman emphasizes that the collaboration is based on principles such as the prohibition of mass surveillance and maintaining human accountability in the use of force, including with autonomous weapons systems (Demócrata). This explicitly positions him as the political and ethical guarantor of how models are deployed in especially sensitive contexts.
  • Management of reputational crises linked to technology. After a Molotov cocktail attack on his home, interpreted as social rejection of AI, Altman responded with a public message on his blog acknowledging “real concern about the risks of this technology” and calling to reduce verbal escalation in the AI debate (Demócrata). Here he acts as a political and social containment figure for tension arising precisely from the power of the systems he leads.
  • Responsibility for technical capacity and infrastructure. The board has questioned his management considering the insufficient expansion of computing capacity to sustain the business; Altman and the CFO defend the strategy and commit to continue expanding data center infrastructure (Demócrata). The board’s pressure indicates that the CEO is ultimately responsible for ensuring technical infrastructures meet growth demands and that lack of capacity is perceived as a management failure.
  • Coordination and communication with major technology partners. In multimillion-dollar agreements with Amazon Web Services or Nvidia, Altman emphasizes that “scaling cutting-edge AI requires massive and reliable computing” and that the alliance with these partners will be the foundation for the next era of artificial intelligence (Demócrata; Demócrata). In technical stress situations — for example, urgent need for more capacity or resilience — the CEO himself leads the restructuring of the alliance architecture.

Additionally, AI governance literature highlights that figures equivalent to the CEO or CAIO usually concentrate coordination of ethics, governance, compliance, and security of models within the organization (Demócrata). Although this article speaks generally and not specifically about OpenAI, it fits the role Altman plays when publicly setting limits and principles for AI safety.

Relevant professional experience

Sources agree in presenting him as co-founder and CEO of OpenAI since its creation in 2015, after participating in the initial investor round that contributed around one billion dollars to found the AI lab (El País). Over a decade, his experience has been built on several fronts:

  • Building and leading OpenAI. Altman has led OpenAI’s transition from a non-profit organization to a hybrid “capped-profit” structure, with the consequent complexity of governance and relationships with partners like Microsoft. This change has been the subject of intense dispute with Elon Musk, who accused him of diverting the original mission and creating a lucrative monopoly; Altman himself has defended this redesign as the only way to finance increasingly costly models (El País; elDiario.es).
  • Managing major conflicts and internal crises. The AMETIC Think Tank book recalls the “crisis” caused by his dismissal and subsequent reinstatement as head of OpenAI, one of the most notable episodes in the recent AI industry, which tested his relationship with the board and major technology partners (AMETIC). This cycle reinforces his profile as a leader accustomed to operating in contexts of maximum political, economic, and reputational tension.
  • Negotiating strategic and regulatory alliances. Signing agreements with the Pentagon, Disney, major pharmaceutical companies like Novo Nordisk, or cloud giants like AWS, and liaising with governments — including the Trump Administration in the Stargate project context — show a trajectory focused on negotiating under intense public scrutiny (see, among others, Demócrata and several cited economic articles in the research).

Overall, the profile drawn is that of an executive with extensive experience in leading products of very high technological and regulatory risk. His crisis management competencies do not derive solely from specific technical training — which sources do not detail — but from a nearly ten-year trajectory at the forefront of generative AI governance, facing internal corporate governance crises, reputational attacks, doubts about technical infrastructure capacity, and exceptionally intense political and social scrutiny.

What requirements must companies meet to offer artificial intelligence services in the European Union according to current legislation?

Companies offering artificial intelligence systems or services in the European Union are subject to Regulation (EU) 2024/1689 on Artificial Intelligence (“AI Act”), a directly applicable regulation that introduces a risk-based model. Specific obligations depend on the type of system (minimal risk, specific transparency, high risk, unacceptable risk) and whether the company acts as a provider of the system or as a deployer.

1. Risk-level approach
  • Minimal risk: most systems (e.g., spam filters or many recommendation systems). They have no specific obligations under the AI Act; companies may voluntarily adhere to codes of conduct.
  • Specific transparency risk: systems that interact with people (chatbots, conversational assistants) or generate synthetic content (including deepfakes). They must clearly inform users that they are interacting with AI and label AI-generated or modified content in a machine-readable format, identifiable as such.
  • High risk: systems that can significantly affect health or fundamental rights (e.g., AI for personnel selection, credit granting, essential public services, education, or certain critical infrastructures). They are allowed but subject to strict requirements to access and remain on the EU market.
  • Unacceptable risk: prohibited practices, such as social scoring by authorities or companies, certain uses of emotional recognition at work, predictive police surveillance based on profiles, or systems that severely manipulate behavior. These systems are banned in the EU.
2. Obligations for high-risk systems

Chapter III of the Regulation details very demanding obligations for high-risk AI systems. Provider companies must comply, among others, with:

  • Risk management system (art. 9): identify, analyze, and mitigate risks throughout the system’s lifecycle.
  • Data and data governance (art. 10): ensure the quality of training, validation, and testing datasets (relevant, representative, with appropriate statistical properties, as error-free as possible) and a chain of custody ensuring lawful and legitimate data origin. This coordinates with GDPR and other data rules.
  • Technical documentation (art. 11) and logs (art. 12): maintain detailed documentation and traceability of system activity so authorities and conformity assessors can verify compliance.
  • Transparency towards users (art. 13): provide clear information about system operation, intended use, and limitations.
  • Human oversight (art. 14): design the system so that effective human supervision exists, capable of intervening, correcting, or stopping use when necessary.
  • Accuracy, robustness, and cybersecurity (art. 15): ensure adequate levels of technical performance and security against failures and attacks.
  • Conformity assessment: as a general rule, high-risk systems require a technical and legal self-assessment according to Annex VII, and in certain harmonized sectors notified conformity assessment bodies intervene.
  • European registry: high-risk systems, and certain public users of those systems, must register in the EU database for high-risk AI systems, enhancing transparency.
3. General-purpose AI models and advanced models

General-purpose AI models (GPAI), including many foundational models, are subject to specific obligations from 2025. Providers must:

  • Provide clear information about the data used to train the models, including aspects relevant to copyright.
  • Document model operation and adopt policies ensuring respect for intellectual property legislation.
  • Comply with enhanced transparency obligations when their models are incorporated into systems capable of generating synthetic content.
  • Assume additional requirements if the model generates systemic risks, under supervision of the European AI Office.
4. Transparency and obligations for providers and deployers

Article 50 of the Regulation specifies transparency obligations for AI-generated content:

  • Providers of systems interacting with people must ensure users know from the start that they are dealing with AI, unless it is obvious.
  • Providers of generative systems must mark content (audio, image, video, text) with machine-readable signals to allow detection as AI-produced or manipulated content.
  • Deployers (companies using AI professionally) must inform when using emotion recognition or biometric categorization systems and clearly label deepfakes and AI-generated texts of public interest without human review.
  • These obligations also apply to providers and users established outside the EU if the results are used within the European territory.
5. Supervision and sanctioning regime

Compliance is monitored by national market surveillance authorities and the European AI Office, which especially supervises general-purpose models and coordinates with Member States. The Regulation provides for significant fines based on the company’s global turnover: violations related to prohibited systems can reach up to 7 % of annual worldwide turnover, with lower scales for other infringements and provision of incorrect information. Reductions and proportionality are foreseen for SMEs and startups.

In summary, to operate legally in the EU, companies must classify their systems according to risk, comply with reinforced requirements for high-risk and general-purpose models, ensure robust data governance and transparency towards users and authorities, undergo conformity assessments, and assume a demanding sanctioning regime in case of non-compliance.

Play

Test your knowledge with FREN!

How much do you know about this topic? Answer the following 3 questions.

What problem has ChatGPT experienced according to the news?

Question 1 of 3

What actions has OpenAI taken in response to the ChatGPT outage?

Question 2 of 3

What are some of the alternatives to ChatGPT mentioned?

Question 3 of 3

Hola, soy Fren. ¿Cómo te ayudo?