OpenAI has warned that increasingly capable AI models could allow threat actors to identify and exploit longstanding security weaknesses at unprecedented speed, forcing organizations to modernize defensive operations before attackers capitalize on accumulated technical debt.
In a post titled The Defender’s Window, OpenAI President Greg Brockman said AI is beginning to automate meaningful stages of real-world cyberattacks.
These capabilities can help attackers discover buried coding bugs, cloud misconfigurations, forgotten permissions, exposed credentials, and risky trust relationships across enterprise environments.
OpenAI Warns AI-Powered Attackers
The warning follows Brockman’s description of the OpenAI-Hugging Face incident, in which an “agentic collective” allegedly penetrated OpenAI research infrastructure and another company’s production environment.
The operation reportedly chained unknown flaws with credentials leaked online, illustrating how attackers can combine individually limited weaknesses into a high-impact intrusion path.
The primary risk lies not only in newly discovered vulnerabilities but also in the vast backlog of security debt across existing systems.
AI-enabled attackers may be able to continuously enumerate attack surfaces, review code, inspect configurations, identify exposed identities, and prioritize exploitable paths faster than human-led security teams.
OpenAI argues that the same capabilities can shift the balance toward defenders if deployed quickly and with appropriate safeguards.
Brockman said organizations should use AI agents to assess codebases, infrastructure-as-code templates, deployment pipelines, authentication systems, and internet-facing services.
As an example, Brockman said he used ChatGPT Work with publicly available GPT-5.6 Sol to assess his personal website.
Within approximately 15 minutes, the system identified 13 security issues, including missing DNS protections against email spoofing, an outdated jQuery version, and Cloudflare-to-AWS traffic forwarded over unencrypted HTTP.
The agent subsequently assisted with remediation, configuring DNS, TLS, and security settings, removing jQuery, migrating the site to Cloudflare Pages, and beginning a phased DMARC rollout.
Brockman characterized this workflow as a “cyberguardian” model: an AI system capable of identifying long-tail security weaknesses that might otherwise go unaddressed.
OpenAI’s internal defensive strategy centers on four pillars: AI-assisted secure coding, automated infrastructure defense, continuous attack-path discovery, and foundational controls.
The company said its Codex tools can validate code changes, identify vulnerabilities, and help developers remediate issues before deployment.
It is also applying intelligence-driven alert triage to reduce analyst workload and accelerate incident response, while reserving high-impact decisions for humans.
OpenAI said it is gradually connecting detections to bounded automated responses rather than pursuing fully autonomous security operations.
For defenders, Brockman recommended prioritizing AI-assisted assessments of public-facing assets, identity systems, sensitive data environments, CI/CD pipelines, and cloud configurations.
Security teams should also use agents to triage existing vulnerability backlogs, correlate related flaws, generate focused patches, and create regression tests.
However, he stressed that AI adoption must be paired with proven controls, including least privilege, defense-in-depth, network isolation, workload hardening, continuous monitoring, and safe patching processes.
“Defender’s window” is OpenAI’s call for security teams to accelerate automation now before AI-driven offensive capabilities turn years of neglected vulnerabilities into readily exploitable attack paths.
Give your security team the visibility and context to investigate suspicious activity faster and contain threats before business impact grows. Strengthen Your Investigations with ANY.RUN
