Skip to content

OpenAI President Advocates for Agents Against AI-Powered Attacks – Criticism Over Missing Liability Debate

In brief: OpenAI President Brockman recommends that CISOs deploy agent-based security tools such as Codex, but analysts criticize the lack of engagement with liability questions and the self-serving nature of the recommendation.

In a blog post, OpenAI President Greg Brockman calls on companies to increasingly deploy agentic AI systems for defense, arguing that attackers have underestimated the real-world cyber capabilities of AI models. Security experts consider the recommendations technically sound but conspicuously self-serving, since OpenAI itself is among the providers of the recommended solution.

In his blog post, Greg Brockman warned that it had become “increasingly clear” that enterprise systems harbor “significant vulnerabilities” that defenders must find and fix before attackers can exploit them. As evidence, he pointed to an incident at Hugging Face that he said showed OpenAI had underestimated the real-world cyber capabilities of its own AI models. However, Brockman did not provide any concrete technical details about this incident. The current defensive measures he described at OpenAI itself are limited to established best practices: investments in secure architectures, defense-in-depth, least-privilege principles, and systems designed so that multiple independent controls would have to fail simultaneously for catastrophic damage to occur. Network isolation, workload hardening, monitoring, and secure patching and deployment, he said, remain central controls even in the AI-driven future.

Brockman’s concrete recommendation to security teams is to deploy agentic tools such as Codex or the Codex Security Plugin, granting these agents approved access to codebases, infrastructure configurations, and technical documentation – starting with prioritized systems rather than an organization-wide rollout. In addition, he recommends equipping the agents with security expertise, for example through community-maintained workflows for static analysis, security-focused code reviews, vulnerability variant analysis, and software supply chain risk assessment, supplemented by organization-specific playbooks and threat models.

Several security experts judged the recommendations to be substantively accurate but obvious and self-interested. Gartner VP analyst Nader Henein generally advised against taking advice from a party actively selling the solution to a problem it itself helped create – noting that the blog post nowhere addresses the issue of liability. Pieter Arntz of Malwarebytes described the sales pitch embedded in the post as unusually explicit: while the proposed progression from purely read-only scans through alert triage to automatically closing narrowly defined false positives is sound in principle, it is clearly aimed at normalizing agent access within enterprise environments.

Flavio Villanustre, CISO at LexisNexis Risk Solutions Group, agreed with the recommendations in substance but criticized the fact that OpenAI had contributed to creating the problem and that customers are now expected to pay to defend themselves against AI threats using AI. He called on OpenAI to adopt a more responsible approach, such as higher security standards and support for broader software security initiatives, including funding for open-source projects that are under significant strain from the increased volume of AI-generated findings and fixes. Accountability, in his view, must begin at home – something he felt the blog post failed to reflect.


Source: www.csoonline.com · Published August 18, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.8.3.

Share on: