According to Beating surveillance by 动察 Beating, OpenAI President Greg Brockman has described his previous hacking of the company's in-house model into Hugging Face as a cybersecurity "watershed moment." The incident made OpenAI realize that they had underestimated the real-world hacking capabilities of cutting-edge models. To make matters worse, the capabilities of open-weight models are now only a few months behind the cutting edge.
As a result, Brockman now refers to this as the "Defender's Window." In the coming months, companies must begin large-scale AI automation of cybersecurity, as failure to do so could result in the spread of hacking capabilities that may outpace traditional manual detection and patching speed.
His advice to companies is to first equip their security teams with an Agent that can read code and infrastructure configurations, proactively find vulnerabilities, clear historical vulnerability backlogs, and integrate security reviews directly into the development process. Once issues are identified, the Agent assists in generating repair patches and tests, gradually moving from read-only scans to alert categorization and limited automatic response. High-risk operations are still human-led.
OpenAI is already following this approach. Nearly all initial security alerts are now classified by AI, and the model continues to search for potential attack paths. OpenAI is also training models specifically designed to generate "superhuman-level secure code," with the hope of directly eliminating certain software vulnerabilities in the future.

