OpenAI Says Cyber Defenders Need to Move at ‘Turbo Speed’

OpenAI President Greg Brockman urges security teams to accelerate AI-driven cyber defense as attack capabilities grow and automation expands.

Written By
Liz Ticong
Liz Ticong
Aug 18, 2026
2 minute read
Channel Insider content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Security teams may not get much time to ease into AI.

OpenAI is urging organizations to automate more of their security work over the coming months as AI systems become more capable of finding and exploiting weaknesses. A recent incident led the company to reassess how quickly those offensive capabilities are developing. 

New guidance lays out where agents can start taking on security work, how far organizations should let that automation go, and where human control still needs to remain.

Hugging Face incident changed OpenAI’s risk assessment

During the recent Hugging Face incident, an agentic system penetrated OpenAI research infrastructure and Hugging Face’s production environment by chaining previously unknown flaws with leaked credentials.

OpenAI President and co-founder Greg Brockman said the episode showed the company had underestimated the real-world cyber capabilities of its models. He warned that AI is getting better at finding software flaws and overlooked permissions, potentially cutting the time security teams have to fix them. 

Brockman said organizations should pursue the next steps at “turbo speed.” 

Security automation starts with controlled access

The company recommends giving agents approved access to codebases and infrastructure configurations so they can assess high-priority systems and work through vulnerability backlogs. AI can also help prepare and verify patches inside development workflows.

A fully automated SOC is not the prescribed starting point. Teams can begin with read-only repository scans or retrospective alert reviews while people retain decision authority. Live triage and narrowly scoped automated actions can come later, with least privilege and network isolation still in place as access expands.

Brockman also suggests preparing AI-assisted forensic workflows before an incident. Approved security teams can use Daybreak Blue for incident response and detection engineering, among other authorized defensive tasks. 

Advertisement

Managed providers should set limits before customers set expectations

MSPs and MSSPs first need to decide how much authority an AI agent gets inside a customer environment. Read-only access carries a different level of risk than automated remediation.

Once an agent can make changes, the provider must also account for customer approval and oversight. Contracts or runbooks may need to specify when a person steps in and how actions are recorded, thereby extending controls that are already becoming part of AI governance services.

Automation can create another pressure point. Finding vulnerabilities faster does not shorten the work required to validate and remediate them, yet customers may expect response times to improve. Existing SLAs and escalation procedures may not have been written for that pace.

Alert review or vulnerability triage offers a lower-risk starting point before agents receive broader access. 

More security updates: Nozomi Networks and Sophos are connecting OT and IT security data in Sophos Fusion to help teams investigate threats across both environments.

Channel Insider Logo

Channel Insider combines news and technology recommendations to keep channel partners, value-added resellers, IT solution providers, MSPs, and SaaS providers informed on the changing IT landscape. These resources provide product comparisons, in-depth analysis of vendors, and interviews with subject matter experts to provide vendors with critical information for their operations.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.