OpenAI President Urges CISOs to Deploy Agentic AI for Cyber Defense
Greg Brockman advocates for autonomous AI agents with deep infrastructure access, sparking criticism over missing liability frameworks.
OpenAI President Greg Brockman is calling on enterprise Chief Information Security Officers (CISOs) to aggressively integrate agentic AI systems into their defensive strategies. The push comes as the industry grapples with the escalating speed of AI-driven cyberattacks and the urgent need for autonomous response capabilities.
In a recent blog post, Brockman advised security teams to grant AI agents broad access to sensitive internal resources, including codebases, technical documentation, and infrastructure configurations. He specifically recommended the use of Codex, the Codex Security plugin, or other capable agentic coding and security tools to bolster defenses. To begin implementation, Brockman suggested utilizing community-supported skills for vulnerability variant analysis, security-focused code review, and static analysis.
Notably, Brockman admitted that OpenAI had previously underestimated the real-world cyber capabilities of its own models. He cited a prior incident involving Hugging Face as evidence that the models' potential for cyber operations was more significant than the company had initially realized. This admission underscores a broader industry shift toward "agentic AI"—systems capable of executing complex, multi-step tasks autonomously rather than simply generating text or code snippets.
The Accountability Gap
The recommendation has drawn sharp criticism from industry analysts who argue that OpenAI is promoting a high-risk solution without addressing the associated dangers. Critics point out that the blog post is conspicuously silent on the issues of liability and accountability, particularly regarding what happens when an autonomous agent causes systemic damage.
Nader Henein, a VP analyst at Gartner, cautioned against following the advice of a company that is simultaneously selling the solution to a problem it helped create. "Curiously, at no point in the blog post is the subject of liability discussed," Henein noted, suggesting a conflict of interest in OpenAI's push for rapid adoption.
Infrastructure Risks
Beyond legal liability, security practitioners are concerned about the technical risks of giving AI agents deep access to critical infrastructure. The prospect of a "rogue" agent making unauthorized or destructive changes to a production environment is a primary concern for those managing enterprise security.
Mike Wilkes, an enterprise CISO at Aikido Security, argued that confidence in a model's judgment is insufficient for enterprise deployment. According to Wilkes, every consequential action taken by an agent requires a tested, near-immediate rollback path, a comprehensive audit trail, and strict blast-radius limits to prevent catastrophic failure.
What's Next
As OpenAI continues to push for the integration of agentic AI in the enterprise, the industry will likely see a growing demand for standardized safety frameworks. The tension remains between the urgent need to counter AI-powered threats and the lack of technical and legal safeguards to manage the agents deployed to fight them. Whether OpenAI will address these gaps in liability and control remains to be seen.