OpenAI presidentâs blog pushing agentic AI most notable for what it did not say
Given the urgency, analysts and consultants want to hear more about what to do when agents go rogue, as well as how to better control all agent actions.
OpenAI president Greg Brockman on Sunday warned enterprise CISOs that they need to more aggressively embrace agents if they want to survive upcoming cyberattacks.
Brockman said in a blog post that it has become âincreasingly clearâ that company systems are hiding âsignificant flaws, and defenders need to find and fix them before attackers do.â
He added: âThe Hugging Face incident showed that we underestimated the real-world cyber capabilities of our AI models.â
The details he shared about OpenAIâs current defensive efforts, however, were mostly routine best practices familiar to enterprises.
âWe continue to invest in secure architecture and controls, embrace strategies like defense in depth and least privilege, and are designing systems that require multiple independent controls to fail simultaneously for something catastrophic to occur,â Brockman said. âClassic security controls like network isolation, workload hardening, monitoring, and safe patching and deployment will be more important than ever in the AI future.â
To combat emerging threats, Brockman also advised enterprise CISOs to increase their use of agentic systems, not surprisingly recommending those from OpenAI.
âGive your security team an agent,â he wrote. âStart using Codex, the Codex Security plugin, or another capable agentic coding and security tool. Give it approved access to the codebases, infrastructure configurations, and technical documentation your security team needs to assess. Do not wait for a company-wide rollout to start with your highest-priority systems.â
Then, he said, âEquip that agent with security expertise. Start from community-supported skills, which include workflows for static analysis, security-focused code review, vulnerability variant analysis, software supply-chain risk, and other security workflows. Then build your own skills around your organizationâs architecture, security standards, threat models, and playbooks.â
Accurate advice, but self-serving
Analysts and consultants said that Brockmanâs advice was accurate, but that it was also obvious and somewhat self-serving.
Gartner VP analyst Nader Henein put it bluntly: âAs a rule, I tend to recommend against taking advice from a party actively selling the solution to a problem they had a role in creating. Curiously, at no point in the blog post is the subject of liability discussed.â
Pieter Arntz, malware intelligence researcher at Malwarebytes, added âthe thing that really stands out to me is that the OpenAI sales pitch is unusually explicit.â
ââGive your security team an agentâ and provide it access to code, infrastructure configurations, and technical documentation, and begin with high-priority systems rather than waiting for a company-wide rollout,â Arntz said, paraphrasing Brockmanâs post. âThe recommended trajectory from read-only scans to alert triage to automatic closure of narrowly defined false positives is sensible in outline, but OpenAI is clearly trying to normalize agent access for enterprise environments.â
Flavio Villanustre, CISO for the LexisNexis Risk Solutions Group, was also skeptical.
âAlthough I agree in general with Mr. Brockmanâs recommendations, this is a problem that OpenAI helped create in the first place. And the recommendation seems to be for users to now pay more to OpenAI as they use AI to defend themselves,â he said. âIâm fully aware that the cat is now out of the bag and cannot be put back, but I believe that OpenAI should take a responsible approach and help address the problem with higher safety standards, and even fund initiatives that increase software security in general. Perhaps help fund key open source projects that are currently severely overtaxed with the increased volumes of AI-generated findings and fixes.â
âAccountability should always start at home,â he added, âand I donât see this reflected in that blog post.â
Mike Wilkes, enterprise CISO at Aikido Security, noted what is more important are the many things that Brockman did not say, such as suggesting ways to limit the damage when agents go rogue.
âEvery consequential agent action needs blast-radius limits, an audit trail and a tested, near-immediate rollback path, not simply confidence in the modelâs security judgment,â Wilkes said. âBrockmanâs own recommendation to expand autonomy only incrementally is consistent with that, but I would make reversibility an explicit design requirement.â
He added, âBrockman appropriately talks about âbounded automated responsesâ and keeping humans responsible for the highest-impact decisions, but enterprises deploying defensive agents also need extremely fast and highly reliable âundo buttonsâ for whatever those agents change.â
Incident response always operates with incomplete knowledge, he pointed out, and early indicators are often wrong, leading teams to pursue the wrong thing until new evidence modifies their hypothesis about who is attacking, what has been breached and where they are going next.
An industry-wide problem
Analysts and consultants agreed that these problems are industry-wide, and that many AI vendors have been focusing on what makes the most money and positions them to control the greatest market share, instead of ways to make systems truly safer.
âBrockmanâs blog post is a good summary, but thereâs nothing really new or noteworthy in it. All of the major AI labs are backing off the safety and ethics guardrails that were put in place in the early days,â said Mark Tauschek, a distinguished analyst at Info-Tech Research Group. âTheir focus is going to be on cybersecurity capabilities because thatâs where the attention and money are. The appetite to spend money and slow development in order to ensure new models are acting ethically and safely for average users has waned.â
Noah Kenney, principal consultant at Digital 520, agreed, and added that there are reasons for OpenAI to do this, given that they are preparing for an IPO.
âTo me, this is an IPO story more than anything else. Defensive security reads well in an S-1 because it protects revenue, signals operational maturity, and reassures investors,â Kenney said. âA catastrophic risk team is the opposite kind of line item, because its entire purpose is to walk into a launch meeting and say this model may be too dangerous to release. That results in delays and legal exposure right when a company is trying to go public, and it brings in no revenue.â
Katie Norton, research director of cloud security at IDC, said the key point that struck her about the post was the immediacy of the suggested actions.
âWhat stands out is the urgency of Brockmanâs message and OpenAIâs admission that it underestimated the real-world cyber capabilities of its models following the OpenAI-Hugging Face incident,â Norton said. âHe is essentially saying organizations have months, rather than years, to adapt.â
This article originally appeared on Computerworld.
How it works
Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content â general knowledge won't be enough. Score 70+ to count toward your certificate.
Questions are cached â you'll always get the same 5 for this article.