Security teams may not get much time to ease into AI.
OpenAI is urging organizations to automate more of their security work over the coming months as AI systems become more capable of finding and exploiting weaknesses. A recent incident led the company to reassess how quickly those offensive capabilities are developing.
New guidance lays out where agents can start taking on security work, how far organizations should let that automation go, and where human control still needs to remain.
Hugging Face incident changed OpenAI’s risk assessment
During the recent Hugging Face incident, an agentic system penetrated OpenAI research infrastructure and Hugging Face’s production environment by chaining previously unknown flaws with leaked credentials.
OpenAI President and co-founder Greg Brockman said the episode showed the company had underestimated the real-world cyber capabilities of its models. He warned that AI is getting better at finding software flaws and overlooked permissions, potentially cutting the time security teams have to fix them.
Brockman said organizations should pursue the next steps at “turbo speed.”
Security automation starts with controlled access
The company recommends giving agents approved access to codebases and infrastructure configurations so they can assess high-priority systems and work through vulnerability backlogs. AI can also help prepare and verify patches inside development workflows.
A fully automated SOC is not the prescribed starting point. Teams can begin with read-only repository scans or retrospective alert reviews while people retain decision authority. Live triage and narrowly scoped automated actions can come later, with least privilege and network isolation still in place as access expands.
Brockman also suggests preparing AI-assisted forensic workflows before an incident. Approved security teams can use Daybreak Blue for incident response and detection engineering, among other authorized defensive tasks.
Managed providers should set limits before customers set expectations
MSPs and MSSPs first need to decide how much authority an AI agent gets inside a customer environment. Read-only access carries a different level of risk than automated remediation.
Once an agent can make changes, the provider must also account for customer approval and oversight. Contracts or runbooks may need to specify when a person steps in and how actions are recorded, thereby extending controls that are already becoming part of AI governance services.
Automation can create another pressure point. Finding vulnerabilities faster does not shorten the work required to validate and remediate them, yet customers may expect response times to improve. Existing SLAs and escalation procedures may not have been written for that pace.
Alert review or vulnerability triage offers a lower-risk starting point before agents receive broader access.
More security updates: Nozomi Networks and Sophos are connecting OT and IT security data in Sophos Fusion to help teams investigate threats across both environments.





