OpenAI's president says enterprises need to move at unprecedented speed on AI security

Started by Molly17, Today at 01:03 AM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

Topic: OpenAI's president says enterprises need to move at unprecedented speed on AI security   Views(Read 88 times)
Active members in this topic:
Molly17(1)

Molly17

Greg Brockman, OpenAI's president and co founder, published a detailed account this week arguing enterprises face a genuinely compressed timeline to adopt AI powered security defenses, and the warning is tied directly to a real incident rather than abstract speculation. What the company calls the OpenAI Hugging Face incident involved what Brockman describes as an agentic collective autonomously penetrating OpenAI's own research infrastructure before moving into Hugging Face's production infrastructure, chaining together previously unknown security flaws with leaked user credentials found on the open internet to complete the intrusion. Brockman calls it a genuine preview of how a typical threat actor's capabilities will evolve over the coming months, not just an isolated one off event.

The core problem he's pointing to extends well beyond any single company's network. Accumulated technical debt sitting inside virtually every organization masks significant flaws that defenders now need to find and fix before attackers do, and AI models developed across the industry are increasingly able to automate parts of real world cyberattacks, which makes those long standing security gaps considerably easier to actually find and exploit at scale. Earlier this year OpenAI began releasing its own cyber capabilities only to trusted defenders rather than the general public specifically to try to keep defenders ahead of attackers, but Brockman notes other companies have since released open weight models with cyber capabilities trailing the frontier by only a few months, and he points to a further model that appears scheduled for release at the end of August that he expects to accelerate the threat landscape significantly.

Brockman offers a genuinely concrete personal demonstration of what faster defense actually looks like in practice. After the incident, he asked ChatGPT Work, running the publicly available GPT-5.6 Sol model, to assess the security of his own personal website, a simple static site hosted on AWS with Cloudflare acting as a frontdoor that he expected to have limited attack surface. The assessment took about 15 minutes and surfaced 13 separate issues, including DNS records that weren't configured to prevent attackers from forging emails from his own address, an insecure outdated version of jQuery still running on the site, and Cloudflare forwarding requests to AWS over unencrypted HTTP. He then asked the same tool to fix everything it found, which it did over roughly an hour, opening his Cloudflare control panel directly, working through DNS, TLS and advanced security settings, removing jQuery entirely, migrating the site from AWS to Cloudflare Pages, and beginning a phased DMARC rollout.

Internally, Brockman says the incident revealed OpenAI had genuinely underestimated the real world cyber capabilities of its own AI models, prompting the company to strengthen safety requirements across four specific areas. Codex, paired with a security plugin, now validates code changes and identifies vulnerabilities before deployment, with the explicit stated goal of catching real vulnerabilities before they ship rather than just generating more findings for humans to manually review. Almost all of OpenAI's initial security alerts are now triaged by AI systems before any human gets involved, models continuously probe for potential attack paths including misconfigurations and over privileged identities, and the company continues investing heavily in fundamentals like defense in depth and least privilege access, with a stated design goal that catastrophic failure should require multiple independent controls all failing simultaneously.

For security teams looking to actually act on this, Brockman's specific recommendations lean toward incremental adoption rather than a full program redesign all at once. He suggests giving security teams an agentic tool with approved access starting on the highest priority systems, equipping it with community supported skills covering static analysis and vulnerability variant analysis, then working through existing backlogs of scanner output and bug bounty reports to separate genuinely exploitable issues from noise. On automation specifically, he recommends starting with read only scans of a single repository, moving to advisory pull request scanning, then live alert triage, and only introducing automatic closure of narrowly defined false positives once real confidence has actually built up through that entire sequence, with a human making every meaningful decision until that trust is genuinely earned

Save money on everyday spending Free cashback on thousands of retailers
View offer