OpenAI President Greg Brockman published “The Defender’s Window” on August 17,
The essay urges companies to deploy AI security agents immediately and calling the OpenAI-Hugging Face breach a “watershed moment for cybersecurity.”
Hugging Face’s own team used Z.ai’s open-weight GLM 5.2 to investigate OpenAI’s hack after American commercial AI refused to help.
OpenAI wants every security team running AI agents, starting immediately. President Greg Brockman published a policy essay Monday, titled “The Defender’s Window,” describing a narrow window before attackers catch up to what AI can already do.
His opening example is the incident OpenAI has spent a month explaining. In May, GPT-5.6 Sol and an unreleased prototype escaped a sandboxed cybersecurity benchmark, chained a zero-day exploit with stolen credentials, and reached Hugging Face’s production systems. OpenAI later confirmed the incident touched four more services.
Myriad: When will OpenAI release GPT-6? Click to make your prediction.
“The OpenAI-Hugging Face incident was a watershed moment for cybersecurity,” Brockman wrote, adding that conversations with other organizations over the past few weeks convinced him defenders need to raise their security practices with unprecedented urgency.
Current and former staff blame the breach on pressure to ship, and one former employee called it the biggest safety incident in company history.
Brockman’s proposed fix is more AI, not less. He described asking ChatGPT Work, running GPT-5.6 Sol, to audit his personal website—it found 13 issues in about 15 minutes, then fixed all of them within an hour.
OpenAI lists four internal pillars: using Codex to catch vulnerabilities before code ships, letting models triage security alerts before humans see them, running frontier models to probe its own infrastructure, and reinforcing basics like least-privilege access. His advice to everyone else: give your security team an agent, and apply for OpenAI’s Trusted Access for Cyber program for vetted use of GPT-Daybreak-Blue during incident response.
That framing skips a detail from the same breach. When Hugging Face investigated the intrusion, its security team turned to Z.ai’s open model GLM 5.2 after American commercial AI refused to help—its safety filters couldn’t tell a researcher’s exploit code from an attacker’s. Hugging Face CEO Clément Delangue called the open model “a key part of our defense.”
Z.ai’s successor model, GLM-5.3, released August 14, already scores ahead of GPT-5.6 Sol on CyberGym, the same vulnerability-discovery benchmark Brockman points to as evidence attackers are catching up. Z.ai says it will publish the model’s full weights by the end of August.
Daily Debrief Newsletter
Start every day with the top news stories right now, plus original features, a podcast, videos and more.
The FSNN News Room is the voice of our in-house journalists, editors, and researchers. We deliver timely, unbiased reporting at the crossroads of finance, cryptocurrency, and global politics, providing clear, fact-driven analysis free from agendas.
We and our selected partners wish to use cookies to collect information about you for functional purposes and statistical marketing. You may not give us your consent for certain purposes by selecting an option and you can withdraw your consent at any time via the cookie icon.
Cookies are small text that can be used by websites to make the user experience more efficient. The law states that we may store cookies on your device if they are strictly necessary for the operation of this site. For all other types of cookies, we need your permission. This site uses various types of cookies. Some cookies are placed by third party services that appear on our pages.
Your permission applies to the following domains:
https://fsnn.net
Necessary
Necessary cookies help make a website usable by enabling basic functions like page navigation and access to secure areas of the website. The website cannot function properly without these cookies.
Statistic
Statistic cookies help website owners to understand how visitors interact with websites by collecting and reporting information anonymously.
Preferences
Preference cookies enable a website to remember information that changes the way the website behaves or looks, like your preferred language or the region that you are in.
Marketing
Marketing cookies are used to track visitors across websites. The intention is to display ads that are relevant and engaging for the individual user and thereby more valuable for publishers and third party advertisers.