Skip to content

OpenAI President Advocates Agentic Tools Against AI-Powered Attacks – Criticized for Ignoring Liability Debate

In brief: OpenAI President Brockman recommends CISOs deploy agentic security tools like Codex, but analysts criticize the lack of engagement with liability questions and the self-serving nature of the recommendation.

OpenAI President Greg Brockman calls on companies in a blog post to increasingly deploy agentic AI systems for defense, arguing that attackers have underestimated the real-world cyber capabilities of AI models. Security experts view the recommendations as technically sound but conspicuously self-serving, since OpenAI itself is among the providers of the recommended solution.

Greg Brockman warned in his blog post that it had become “increasingly clear” that enterprise systems harbor “significant vulnerabilities” that defenders must find and fix before attackers can exploit them. As evidence, he pointed to an incident at Hugging Face, which he said demonstrated that OpenAI had underestimated the real-world cyber capabilities of its own AI models. However, Brockman did not provide concrete technical details about this incident. The current defensive measures he described at OpenAI itself are limited to established best practices: investments in secure architectures, defense-in-depth, least-privilege principles, and systems designed so that multiple independent controls would have to fail simultaneously for catastrophic harm to occur. Network isolation, workload hardening, monitoring, and secure patching and deployment reportedly remain central controls even in an AI-driven future.

Brockman’s concrete recommendation to security teams is to deploy agentic tools such as Codex or the Codex Security Plugin, and to grant these agents approved access to codebases, infrastructure configurations, and technical documentation – starting with prioritized systems rather than a company-wide rollout. In addition, the agents should be equipped with security expertise, for example via community-maintained workflows for static analysis, security-focused code reviews, vulnerability variant analysis, and software supply chain risk assessment, supplemented by organization-specific playbooks and threat models.

Several security experts assessed the recommendations as substantively accurate but obvious and self-interested. Gartner VP analyst Nader Henein generally advised against taking advice from a party actively selling the solution to a problem it helped create – and noted that the blog post at no point addresses the topic of liability. Pieter Arntz of Malwarebytes described the sales pitch embedded in the post as unusually explicit: the proposed progression from purely read-only scans to alert triage and ultimately to automatically closing narrowly defined false positives is sound in principle, but clearly aims to normalize agent access within enterprise environments.

Flavio Villanustre, CISO at LexisNexis Risk Solutions Group, agreed with the recommendations in substance but criticized the fact that OpenAI had contributed to creating the problem, and that customers are now expected to pay to defend themselves against AI threats using AI. He called on OpenAI to adopt a more responsible approach, such as higher security standards and support for initiatives promoting general software security, including funding for open-source projects that are under significant strain from the increased volume of AI-generated findings and fixes. In his view, accountability must begin in-house — something the blog post, in his assessment, fails to reflect.


Source: www.csoonline.com · Published August 18, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.8.3.

Share on: