Greg Brockman Calls on Companies to Automate AI Defense

Le brief IA que les pros lisent chaque soir
Les 7 actus IA du jour, décryptées en 5 min. Gratuit.
Inclus dès l'inscription : notre sélection des meilleurs guides & comparatifs IA.
Choisis ton rythme
Gratuit · Pas de spam · Désabonnement en 1 clic
Greg Brockman calls on security leaders to accelerate defensive automation with AI. He describes a short window before the expected release of a new open-weight model at the end of August and outlines concrete measures, supported by a review of OpenAI's own defenses and a test conducted on his personal site.
A Brief Window and a Call for Collaboration Among Stakeholders
Greg Brockman believes that companies cannot tackle the rising risk alone and urges AI labs, security providers, businesses, and maintainers to share validated results, patches, and manuals so that each discovery benefits the ecosystem. He describes the defenders' window of action as currently open, emphasizing the need to automate security programs in the coming months to keep pace with adversarial capabilities. He mentions an additional model scheduled for release at the end of August, which he believes could significantly accelerate the threat landscape. In this context, he argues that the time to build AI-assisted defenses is shrinking before widely available models bridge the gap with attackers' capabilities.
Immediate Actions for Security Teams, Focused on Speed
Greg Brockman proposes a rapid execution-oriented action plan rather than a complete overhaul of programs. He recommends gaining organizational buy-in and conducting simulation exercises to anticipate the unfolding of attacks within each structure's specific context. He advises equipping teams with an agentic tool such as Codex or its security plugin, with approved access to code and infrastructure, initially targeting the most critical systems. He suggests enhancing this agent with community-supported skills (static analysis, security code review, vulnerability variant analysis, supply chain risks) and then developing specific capabilities aligned with the organization's architecture and threat models. Initial assessments should focus on services exposed to the Internet, authentication pathways, infrastructure as code, and systems handling sensitive data. Teams are encouraged to address the backlog of findings (scanners, dependency alerts, bug bounty reports) by asking the agent to sort exploitable issues from noise. He recommends integrating agent review into development pipelines to catch authentication errors, access bypasses, exposed credentials, and unsafe dependencies early on. For each validated vulnerability, the agent can propose a fix, write a regression test, and verify the absence of reoccurrence, while maintaining human review on high-impact changes. Regarding automation, Brockman advocates for a phased approach: starting with read-only analyses of a repository, moving on to analyzing pull requests, then sorting live alerts, and only introducing automatic closure for narrowly defined false positives. He insists that every decision remains human until trust is established. He also directs towards a request for trusted access to use GPT‑Daybreak‑Blue for defensive purposes such as incident response, detection engineering, and malware analysis, and recommends practicing on logs and telemetry before any real incident.
OpenAI Strengthens Its Own Defenses and Outlines Four Key Areas
Greg Brockman explains that the incident involving Hugging Face revealed that OpenAI had underestimated the extent of attack capabilities stemming from its own models, prompting the company to tighten its requirements and accelerate its internal efforts. He describes four structural axes that also inspire his recommendations to other organizations. On the code side, OpenAI relies on Codex with a security plugin to validate changes and identify vulnerabilities before deployment. The stated goal is to detect real flaws before their release and reduce the time between discovery and delivery of patches, with the ambition of eliminating certain classes of vulnerabilities in newly produced code. Regarding infrastructure, almost all initial security alerts are sorted by AI systems, which lightens the load on teams and speeds up response. These detections are linked to limited automated responses, with high-impact decisions remaining human, aiming to detect and react at machine speed. OpenAI is also continuously exploring attack paths to track vulnerabilities, configuration errors, over-privileged identities, and unintentional trust boundaries, in a logic of assessing security invariants at the product and infrastructure level. Finally, the company invests in fundamentals (secure architecture, defense in depth, least privilege), designing systems that require the simultaneous failure of independent controls before any catastrophic scenario. Network isolation, hardening loads, supervision, and update and deployment practices are pillars that Brockman deems even more essential as AI capabilities progress on both sides. OpenAI indicates that it has begun training models dedicated to writing safer code and highlights the achievement of mathematical proofs, which it claims can be mobilized for formal verification of software security at scales challenging for human reviewers.
A Test on gregbrockman.com to Illustrate Accelerated Response
To illustrate a rapid implementation, Greg Brockman reports that he asked ChatGPT Work, relying on GPT‑5.6 Sol public, to assess the security of his personal site, which he describes as a static site on AWS behind Cloudflare. The analysis took about 15 minutes and identified 13 issues. He believes that several were not exploitable in isolation but could be when combined. Among the findings, DNS records did not prevent email address spoofing, the site used an insecure version of jQuery, and Cloudflare redirected to AWS over unencrypted HTTP. Brockman then asked the tool to correct these points; he indicates that this took about an hour. The agent acted through the Cloudflare panel, adjusting DNS, TLS, and advanced security settings, completely removed jQuery, migrated the site to Cloudflare Pages, and initiated a phased deployment of DMARC. Brockman sees this case as a small-scale demonstration of a "cyberguardian" capable of spotting a long tail of misconfigurations that a human might miss due to time or expertise constraints, and then applying fixes with an appropriate deployment.
OpenAI-Hugging Face Incident and the Two-Speed Race
The urgency invoked by Greg Brockman stems from an incident where an agentic collective breached OpenAI's research infrastructure before entering Hugging Face's production. According to his account, the attackers combined unknown vulnerabilities with credentials leaked online. He sees this as a preview of what typical threat actors could do in the coming months. Beyond an isolated case, Brockman speaks of a systemic issue: technical debt could be hiding major flaws that need to be found and fixed before attackers do. He believes that industrialized AI models are increasingly automating aspects of attacks, making it easier to exploit historical bugs and forgotten permissions, while also equipping defenders to prioritize and correct faster. Brockman presents this dynamic as a two-speed race. Earlier this year, OpenAI restricted the dissemination of its cyber capabilities to trusted defenders; since then, other players have released open-weight models just months from the frontier. In this context, he argues that leaders must accelerate the adoption of AI-assisted defenses. Greg Brockman, president and co-founder of OpenAI, published a report on the "OpenAI-Hugging Face" incident to support this warning. He notes that in discussions with organizations, leaders perceive the need to move faster than their current programs allow. OpenAI, for its part, indicates that it is training models to produce safer code and highlights its ability to generate mathematical proofs, which it considers useful for large-scale formal verification.
Brief IA — L'actualité IA en français
L'essentiel de l'actualité de l'intelligence artificielle, décrypté et expliqué chaque jour.