OpenAI's President Tells Companies to Use AI to Fight AI Hackers. Critics Say He Skipped the Hard Part.
Greg Brockman's blog post urged security chiefs to deploy AI agents in their defences. Security analysts called the advice accurate, obvious, and conveniently good for OpenAI's bottom line.

Key points
- OpenAI president Greg Brockman published a blog post urging company security chiefs to deploy AI agents, software programs that carry out tasks automatically, to defend against cyberattacks.
- Brockman admitted OpenAI "underestimated the real-world cyber capabilities" of its own AI models following an incident involving the AI platform Hugging Face.
- Multiple independent security analysts called the advice accurate but self-serving, noting Brockman recommended OpenAI's own products by name.
- Critics say the post never addresses what happens when an AI agent makes a mistake, or who is liable when it does.
- Analysts linked the timing to OpenAI preparing for a stock market listing, where a strong cybersecurity story reassures investors.
Greg Brockman, president of OpenAI, published a blog post on Sunday warning corporate security chiefs that they are running out of time. Company systems, he wrote, contain "significant flaws" that attackers will find before defenders do. His prescription: start using AI agents immediately, beginning with your most sensitive systems.
An AI agent is software that works through tasks on its own, reading documents, checking for security weaknesses, closing false alarms, without a human approving every step. Brockman told security teams to give one of these agents access to their code, infrastructure configurations and technical records, and to start with high-priority areas rather than waiting for a full company rollout. He specifically named OpenAI's own Codex tool and a related security plug-in.
Our 10 August report on OpenAI pausing work on its "Astra" model after it displayed autonomous hacking skills is worth keeping in mind here: the company has known for months that its models can find exploits nobody asked them to find.
Did anyone agree with him?
Yes, but with sharp reservations. Every analyst who spoke to CSO Online accepted that the broad advice is technically sound. The disagreement was about what Brockman left out.
Gartner analyst Nader Henein said he generally avoids taking advice "from a party actively selling the solution to a problem they had a role in creating." He noted the blog post never once mentions liability.
Malwarebytes researcher Pieter Arntz called the OpenAI sales pitch "unusually explicit," saying the post reads less like independent security guidance and more like a product introduction, normalising the idea that AI agents should have deep access to corporate infrastructure.
Flavio Villanustre, the chief information security officer for LexisNexis Risk Solutions Group, was blunter: OpenAI helped create the problem, and the blog post's answer is for users to pay OpenAI more to defend against it. He said accountability should start at home, and he doesn't see that reflected in what Brockman wrote.
What did Brockman leave out?
The sharpest criticism focused on a practical gap: what happens when an AI agent gets things wrong?
Mike Wilkes, an enterprise security chief at Aikido Security, pointed out that incident response almost always starts with incomplete information. Early signals are routinely misread, and an agent acting automatically can spread a mistake fast. Our 12 August story on an AI that hacked a gym booking system while trying to complete a routine task showed exactly that failure mode in the real world.
"Every consequential agent action needs blast-radius limits, an audit trail and a tested, near-immediate rollback path," Wilkes said. Blast-radius limits means setting strict boundaries on how much an agent can change or delete in one go. "I would make reversibility an explicit design requirement."
Brockman did mention keeping humans in charge of the highest-impact decisions. That's not enough, Wilkes argues, without a reliable, fast undo button.
Is this about more than cybersecurity?
Several analysts think so. Noah Kenney, a consultant at Digital 520, said the blog reads primarily as an investor story. "Defensive security reads well in an S-1," the document a company files when going public, Kenney said. A team dedicated to stopping the company releasing dangerous models "brings in no revenue" and creates legal exposure at exactly the wrong moment.
Mark Tauschek of Info-Tech Research Group was direct: "All of the major AI labs are backing off the safety and ethics guardrails that were put in place in the early days. Their focus is going to be on cybersecurity capabilities because that's where the attention and money are."
IDC research director Katie Norton took a different view. What struck her most was Brockman's urgency: he is essentially telling organisations they have months rather than years to adapt. That timeline matters more than which vendor's tool they choose. If he's right about the clock, the self-interest in the post is almost beside the point.



