OpenAI President Urges CISOs to Adopt Security Agents
OpenAI President Greg Brockman has urged security leaders to deploy autonomous AI agents to defend against cyber threats, sparking industry debate over vendor liability and safety.

OpenAI President Greg Brockman has warned enterprise security leaders that they must aggressively integrate autonomous agents into their defensive strategies to survive upcoming cyberattacks. In a recent blog post, Brockman stated that corporate systems harbor critical vulnerabilities that defenders must patch before malicious actors exploit them. He acknowledged that a recent security incident involving Hugging Face revealed that OpenAI had underestimated its models' real-world cyber capabilities. To counter these emerging threats, Brockman urged chief information security officers to deploy agentic tools, specifically recommending OpenAI's Codex and its Codex Security plugin.
For practitioners, Brockman advised granting these security agents direct access to codebases, infrastructure configurations, and technical documentation. He recommended starting with high-priority systems rather than waiting for a broad corporate rollout. While he advocated for standard defensive practices like network isolation, workload hardening, and defense in depth, his push for autonomous agents represents a shift toward giving AI systems active roles in scanning, triage, and automated remediation.
However, cybersecurity analysts and enterprise CISOs have reacted with skepticism, characterizing the blog post as an explicit sales pitch that glosses over critical safety risks. Critics pointed out that OpenAI is monetizing solutions to security problems that its own generative models helped create. Furthermore, experts noted that Brockman failed to address how organizations should handle rogue agents. Practitioners deploying these tools require strict blast-radius limits, audit trails, and what Mike Wilkes of Aikido Security called "undo buttons" to quickly reverse automated changes.
Other industry observers suggest the sudden urgency is tied to OpenAI's financial ambitions. Analysts noted that highlighting defensive security capabilities helps reassure investors ahead of a potential initial public offering, whereas funding safety and catastrophic risk teams can delay profitable product launches. Ultimately, the push highlights a broader industry trend where major AI labs are prioritizing lucrative cybersecurity features over early safety and ethical guardrails, leaving enterprises to navigate the operational risks of autonomous deployment.
This is our own summary of reporting by Computerworld AI



