OpenAI president’s blog pushing agentic AI most notable for what it did not say

OpenAI president Greg Brockman on Sunday warned enterprise CISOs that they need to more aggressively embrace agents if they want to survive upcoming cyberattacks. 

Brockman said in a blog post that it has become “increasingly clear” that company systems are hiding “significant flaws, and defenders need to find and fix them before attackers do.”

He added: “The Hugging Face incident showed that we underestimated the real-world cyber capabilities of our AI models.” 

The details he shared about OpenAI’s current defensive efforts, however, were mostly routine best practices familiar to enterprises. 

“We continue to invest in secure architecture and controls, embrace strategies like defense in depth and least privilege, and are designing systems that require multiple independent controls to fail simultaneously for something catastrophic to occur,” Brockman said. “Classic security controls like network isolation, workload hardening, monitoring, and safe patching and deployment will be more important than ever in the AI future.”

To combat emerging threats, Brockman also advised enterprise CISOs to increase their use of agentic systems, not surprisingly recommending those from OpenAI.

“Give your security team an agent,” he wrote. “Start using Codex, the Codex Security plugin, or another capable agentic coding and security tool. Give it approved access to the codebases, infrastructure configurations, and technical documentation your security team needs to assess. Do not wait for a company-wide rollout to start with your highest-priority systems.”

Then, he said, “Equip that agent with security expertise. Start from community-supported skills, which include workflows for static analysis, security-focused code review, vulnerability variant analysis, software supply-chain risk, and other security workflows. Then build your own skills around your organization’s architecture, security standards, threat models, and playbooks.”

Accurate advice, but self-serving

Analysts and consultants said that Brockman’s advice was accurate, but that it was also obvious and somewhat self-serving.

Gartner VP analyst Nader Henein put it bluntly: “As a rule, I tend to recommend against taking advice from a party actively selling the solution to a problem they had a role in creating. Curiously, at no point in the blog post is the subject of liability discussed.”

Pieter Arntz, malware intelligence researcher at Malwarebytes, added “the thing that really stands out to me is that the OpenAI sales pitch is unusually explicit.”

‘Give your security team an agent’ and provide it access to code, infrastructure configurations, and technical documentation, and begin with high-priority systems rather than waiting for a company-wide rollout,” Arntz said, paraphrasing Brockman’s post. “The recommended trajectory from read-only scans to alert triage to automatic closure of narrowly defined false positives is sensible in outline, but OpenAI is clearly trying to normalize agent access for enterprise environments.”

Flavio Villanustre, CISO for the LexisNexis Risk Solutions Group, was also skeptical.

“Although I agree in general with Mr. Brockman’s recommendations, this is a problem that OpenAI helped create in the first place. And the recommendation seems to be for users to now pay more to OpenAI as they use AI to defend themselves,” he said. “I’m fully aware that the cat is now out of the bag and cannot be put back, but I believe that OpenAI should take a responsible approach and help address the problem with higher safety standards, and even fund initiatives that increase software security in general. Perhaps help fund key open source projects that are currently severely overtaxed with the increased volumes of AI-generated findings and fixes.“

“Accountability should always start at home,” he added, “and I don’t see this reflected in that blog post.”

Mike Wilkes, enterprise CISO at Aikido Security, noted what is more important are the many things that Brockman did not say, such as suggesting ways to limit the damage when agents go rogue. 

“Every consequential agent action needs blast-radius limits, an audit trail and a tested, near-immediate rollback path, not simply confidence in the model’s security judgment,” Wilkes said. “Brockman’s own recommendation to expand autonomy only incrementally is consistent with that, but I would make reversibility an explicit design requirement.”

He added, “Brockman appropriately talks about ‘bounded automated responses’ and keeping humans responsible for the highest-impact decisions, but enterprises deploying defensive agents also need extremely fast and highly reliable ‘undo buttons’ for whatever those agents change.”

Incident response always operates with incomplete knowledge, he pointed out, and early indicators are often wrong, leading teams to pursue the wrong thing until new evidence modifies their hypothesis about who is attacking, what has been breached and where they are going next.

An industry-wide problem

Analysts and consultants agreed that these problems are industry-wide, and that many AI vendors have been focusing on what makes the most money and positions them to control the greatest market share, instead of ways to make systems truly safer. 

“Brockman’s blog post is a good summary, but there’s nothing really new or noteworthy in it. All of the major AI labs are backing off the safety and ethics guardrails that were put in place in the early days,” said Mark Tauschek, a distinguished analyst at Info-Tech Research Group. “Their focus is going to be on cybersecurity capabilities because that’s where the attention and money are. The appetite to spend money and slow development in order to ensure new models are acting ethically and safely for average users has waned.”

Noah Kenney, principal consultant at Digital 520, agreed, and added that there are reasons for OpenAI to do this, given that they are preparing for an IPO.

“To me, this is an IPO story more than anything else. Defensive security reads well in an S-1 because it protects revenue, signals operational maturity, and reassures investors,” Kenney said. “A catastrophic risk team is the opposite kind of line item, because its entire purpose is to walk into a launch meeting and say this model may be too dangerous to release. That results in delays and legal exposure right when a company is trying to go public, and it brings in no revenue.”

Katie Norton, research director of cloud security at IDC, said the key point that struck her about the post was the immediacy of the suggested actions.

“What stands out is the urgency of Brockman’s message and OpenAI’s admission that it underestimated the real-world cyber capabilities of its models following the OpenAI-Hugging Face incident,” Norton said. “He is essentially saying organizations have months, rather than years, to adapt.”

This article originally appeared on Computerworld.