MeshioMeshio
News

OpenAI Urges Companies to Put AI on the Defensive

OpenAI says AI-powered attacks are accelerating—and organizations need AI-assisted security, stronger fundamentals, and faster response plans now.

Meshio Newsroom
Meshio NewsroomAug 23, 2026
OpenAI Urges Companies to Put AI on the Defensive

OpenAI is warning that the cybersecurity window is narrowing as AI systems become better at automating real-world attacks. In an August 17 post, Greg Brockman said the recent OpenAI–Hugging Face incident demonstrated how an agentic system could chain vulnerabilities and exposed credentials across infrastructure.

The same capabilities, OpenAI argues, can give defenders an advantage—if companies deploy them quickly. Brockman described asking ChatGPT Work to review his personal website, where it found 13 security issues in roughly 15 minutes. The system then helped address problems involving DNS, email authentication, outdated software, encrypted connections, hosting, and Cloudflare settings.

OpenAI’s defense strategy

OpenAI says its internal approach combines AI tooling with conventional security controls. Codex and its security plugin are used to inspect code, identify vulnerabilities, and help developers fix issues before release. Models also triage most initial security alerts, with the company moving toward carefully bounded automated responses while reserving high-impact decisions for people.

The company is additionally using frontier models to continuously search for attack paths, misconfigurations, excessive permissions, and unintended trust relationships. Alongside those systems, OpenAI emphasizes least privilege, network isolation, workload hardening, monitoring, safe deployment, and defense in depth.

For AI builders, the message is practical: security automation is shifting from occasional audits toward continuous assessment and remediation. Teams building agents and AI-powered products will need to treat model-assisted code review, infrastructure monitoring, access control, and human oversight as connected parts of the workflow—not optional add-ons. OpenAI also says its cyber capabilities have been released only to trusted defenders, as open-weight models rapidly close the gap with frontier systems.

Source: OpenAI News

Comments

Log in to join the discussion