OpenAI's President Tells Companies to Use AI to Fight AI Hackers. Critics Say He Skipped the Hard Part.
Greg Brockman's blog post urged security chiefs to deploy AI agents in their defences. Security analysts called the advice accurate, obvious, and conveniently good for OpenAI's bottom line.

Key points
- OpenAI president Greg Brockman published a blog post urging company security chiefs to deploy AI agents, software programs that carry out tasks automatically, to defend against cyberattacks.
- Brockman admitted OpenAI "underestimated the real-world cyber capabilities" of its own AI models following an incident involving the AI platform Hugging Face.
- Multiple independent security analysts called the advice accurate but self-serving, noting Brockman recommended OpenAI's own products by name.
- Critics say the post never addresses liability, reversibility, or what happens when an AI agent makes a mistake.
- Analysts linked the timing to OpenAI preparing for a stock market listing, where a strong cybersecurity story reassures investors.
Greg Brockman, president of OpenAI, published a blog post on Sunday warning the world's corporate security chiefs that they are running out of time. Company systems, he wrote, contain "significant flaws" that attackers will find before defenders do. His prescription: start using AI agents immediately, beginning with your most sensitive systems.
An AI agent is a software program that works through tasks on its own, reading documents, checking for security weaknesses, closing false alarms, without a human approving every step. Brockman told security teams to give one of these agents access to their code, their system configurations, and their technical records, and to start with high-priority areas rather than waiting for a full company rollout.
He specifically named OpenAI's own Codex tool and a related security plug-in.
Did anyone agree with him?
Yes, but with sharp reservations. Every analyst who spoke to CSO Online accepted that the broad advice is technically sound. The disagreement was about what Brockman left out.
Gartner analyst Nader Henein said he generally avoids taking advice "from a party actively selling the solution to a problem they had a role in creating." He noted the blog post never once mentions liability.
Malwarebytes researcher Pieter Arntz called the OpenAI sales pitch "unusually explicit," saying the post reads less like independent security guidance and more like a product introduction, normalising the idea that AI agents should have deep access to corporate infrastructure.
Flavio Villanustre, the chief information security officer for LexisNexis Risk Solutions Group, put the conflict plainly. "This is a problem that OpenAI helped create in the first place," he said, "and the recommendation seems to be for users to now pay more to OpenAI as they use AI to defend themselves."
What did Brockman leave out?
The sharpest criticism focused on a practical gap: what happens when an AI agent gets things wrong?
Mike Wilkes, an enterprise security chief at Aikido Security, pointed out that incident response almost always starts with incomplete information. Early signals are routinely misread. If an agent is acting automatically, a mistake can spread fast.
"Every consequential agent action needs blast-radius limits, an audit trail and a tested, near-immediate rollback path," Wilkes said. Blast-radius limits means setting strict boundaries on how much an agent can change or delete in one go. "I would make reversibility an explicit design requirement."
Brockman did mention keeping humans in charge of the highest-impact decisions. Critics say that is not enough without a reliable, fast undo button.
Is this about more than cybersecurity?
Several analysts think so. OpenAI is preparing for an initial public offering, meaning a stock market listing where the public can buy shares for the first time. Noah Kenney, a consultant at Digital 520, said the blog reads primarily as an investor story.
"Defensive security reads well in an S-1," the document a company files when going public, Kenney said. A team dedicated to stopping the company releasing dangerous models, by contrast, "brings in no revenue" and creates legal exposure at exactly the wrong moment.
Mark Tauschek of Info-Tech Research Group was direct: "All of the major AI labs are backing off the safety and ethics guardrails that were put in place in the early days. Their focus is going to be on cybersecurity capabilities because that's where the attention and money are."
IDC research director Katie Norton took a different emphasis. What struck her most was Brockman's urgency. He is, she said, essentially telling organisations they have months rather than years to adapt. That timeline, if accurate, matters far more than which vendor's tool they choose.



