OpenAI president urges enterprises to hasten AI security
OpenAI president Greg Brockman warns enterprisesface a compressed timeline to adopt AI defences amid rapid tech evolution.

Stock photo for illustration only, not from the actual event
- OpenAI president and co-founder Greg Brockman warns enterprises face a compressed timeline for AI defences.
- Industry-developed AI models can increasingly automate cyberattacks and find long-standing security gaps.
- A personal test on gregbrockman.com uncovered 13 security issues which AI resolved within an hour.
- OpenAI outlines four internal investment pillars including AI-driven infrastructure triage and continuous probing.
OpenAI president and co-founder Greg Brockman has warned that enterprise security teams face a remarkably compressed timeline to adopt artificial intelligence-driven defences. Brockman published an account of the company's "OpenAI-Hugging Face" incident to argue that organisations need to upgrade their security practices with unprecedented speed. He noted in conversations with numerous organisational leaders that a consistent theme emerged: leaders know they must move faster than their current security programmes allow.
AI models developed across the industry are increasingly capable of automating parts of real-world cyberattacks, making long-standing security gaps much easier to identify and exploit. These vulnerabilities range from deep-seated bugs in human-written software to forgotten permissions left unmanaged over many years.
The timeline for making these decisions remains short according to Brockman's account. Earlier in the year, OpenAI began releasing its cyber capabilities exclusively to trusted defenders rather than the public to keep them ahead. Other companies have since released open-weight models with cyber capabilities trailing the frontier by only months, while an upcoming model scheduled for late August is expected to significantly accelerate the threat landscape.

Stock photo for illustration only, not from the actual event
Demonstrating what a rapid response looks like in practice, Brockman asked ChatGPT Work, running public GPT-5.6 Sol, to assess the security of his personal static site gregbrockman.com hosted on AWS with Cloudflare. The assessment took roughly 15 minutes and surfaced 13 issues, including unconfigured DNS records vulnerable to email forgery, an insecure jQuery version, and unencrypted HTTP forwarding.
He then asked ChatGPT Work to resolve these issues, a task completed in about an hour. The tool navigated the Cloudflare control panel, adjusted DNS, TLS, and advanced security settings, removed jQuery, migrated the site to Cloudflare Pages, and initiated a phased DMARC rollout, acting as a functional cyberguardian.
The warning from a leading AI executive highlights a critical turning point where the speed of both offensive and defensive technologies is approaching machine scale. When automated agents can audit and remediate baseline configurations within minutes, traditional annual or quarterly human-led security reviews risk becoming obsolete against AI-driven threats.
"Leaders know they must move faster than their current security programmes allow."
Greg Brockman
The Hugging Face incident revealed that OpenAI had underestimated the real-world cyber capabilities of its own models, prompting tightened safety requirements and accelerated internal investments across four pillars: AI-driven security alert triage, continuous attack path enumeration, fundamental infrastructure hardening, and providing agentic tools to security teams.
Source: AI News
Found something wrong in this article? Report an issue with this article
Comments
Leave a Comment