Infoglobez
Live Coverage
Sign in Sign up
Trending: Champions League Transfer News Premier League World Cup
Infoglobez
AI & ML

OpenAI's Greg Brockman Advocates for Agentic AI Amid Cybersecurity Woes

Greg Brockman underscores the importance of agentic AI in cybersecurity, though critiques arise over OpenAI's responsibility in the evolving landscape.

Aug 18, 2026 | 3 min read
Sign in to save

In a recent blog post, OpenAI president Greg Brockman issued a clarion call for enterprise chief information security officers (CISOs) to adopt agentic systems more proactively, arguing that the stakes for cybersecurity have reached alarming heights. He emphasized that company infrastructures harbor significant vulnerabilities that must be addressed before malicious actors exploit them. Brockman acknowledged the Hugging Face incident, which exposed the limitations of current cybersecurity models, particularly the real-world capabilities of AI tools.

While Brockman's insights resonate, the specifics he outlined primarily revolve around standard security practices that many organizations have been employing for years. He stated, “We continue to invest in secure architecture and controls, embrace strategies like defense in depth and least privilege..." His focus on traditional measures like network isolation and workload hardening does not radically depart from established protocols.

Encouraging Agentic Systems

Alongside these conventional strategies, Brockman advocated for increased integration of agentic systems, naturally promoting OpenAI's own tools. His guidance to security teams was pointed: “Give your security team an agent.” This entails using products like Codex and the Codex Security plugin, equipping them with access to essential codebases and infrastructure configurations necessary for robust security assessments. He urged CISOs to implement these systems without waiting for comprehensive organization-wide rollouts, particularly focusing on high-priority assets.

Brockman encouraged firms to begin integrating agent capabilities by leveraging community-supported skills, which include functions for static analysis and security-oriented code reviews. He urged organizations to tailor the skills to fit their specific architectures and security protocols, reflecting a realistic approach to melding AI tools within existing frameworks.

Criticism of Self-Interest

Despite acknowledging the importance of Brockman's recommendations, industry experts noted that his stance might reflect a self-serving agenda. Gartner VP analyst Nader Henein bluntly remarked, "I tend to recommend against taking advice from a party actively selling the solution to a problem they had a role in creating." He pointed out that Brockman failed to address liability issues related to the potential misuse of AI technologies.

Other cybersecurity professionals echoed Henein's skepticism. Pieter Arntz, a malware intelligence researcher, noted that the explicit sales pitch for OpenAI products feels disproportionate considering the overarching thematic concerns for AI safety. His paraphrasing of Brockman's advice reflects the implicit push towards greater agent access: “The trajectory from read-only scans to automatic closure of narrowly defined false positives is sensible...but OpenAI aims to normalize agent access in enterprises.”

Flavio Villanustre, CISO at LexisNexis, also expressed skepticism, suggesting that while Brockman's guidance is valid, it eludes the ethical responsibility OpenAI should uphold given its role in creating the current cybersecurity landscape. Villanustre called for a more responsible approach, urging OpenAI to contribute meaningfully to higher safety standards and possibly fund critical open-source projects strained by the pressures of AI-generated vulnerabilities.

Missing Elements in Cybersecurity Strategies

Critics highlighted critical omissions in Brockman's blog post. Mike Wilkes, an enterprise CISO at Aikido Security, remarked specifically on the lack of discussion regarding how to mitigate damage from rogue agent actions. He insisted that every significant function of an agent should include safety measures such as audit trails and rapid rollback options. This understanding adds a vital layer to agent deployment—ensuring that organizations can reverse any unauthorized changes swiftly.

Wilkes also noted the importance of maintaining human oversight in high-stakes decisions, a sentiment echoed throughout the industry as organizations increasingly consider relinquishing control to automated systems. He emphasized, “Brockman’s suggestion for bounded automated responses aligns with this, but fast, reliable ‘undo buttons’ are essential for maintaining control.”

Industry-Wide Challenges

The concerns raised by Brockman’s advice point to a broader industry challenge in which AI vendors prioritize profit and market share over comprehensive safety measures. Mark Tauschek, a distinguished analyst at Info-Tech Research, lamented the regression in safety and ethics standards, indicating that many leading labs have shifted focus away from foundational guardrails in a rush to seize cybersecurity opportunities. “There’s nothing truly innovative in Brockman’s points,” he stated. “The emphasis on monetizing cybersecurity capabilities takes precedence over ethical responsibility.”

Noah Kenney, principal consultant at Digital 520, contextualized these insights within OpenAI’s upcoming IPO ambitions. He suggested that the blog's emphasis on defensive security might be a strategic posture to appease potential investors as the company aims for profitability. Conversely, emphasizing catastrophic risk management would likely raise red flags, contributing to operational delays and legal concerns right as the company prepares to go public.

Research director Katie Norton from IDC highlighted the urgency in Brockman’s message. She interpreted his admission regarding the underestimated cyber capabilities of AI models as a signal for organizations: they have a limited window to adapt to these emerging threats. The implication here is clear: as the cybersecurity landscape evolves, so too must the strategies employed by organizations to defend against increasingly sophisticated attacks.

This article originally appeared on Computerworld.

Source: Joseph Miller · www.csoonline.com
Sign in to join the discussion.