In brief

  • OpenAI President Greg Brockman published "The Defender's Window" on August 17,
  • The essay urges companies to deploy AI security agents immediately and calling the OpenAI-Hugging Face breach a "watershed moment for cybersecurity."
  • Hugging Face's own team used Z.ai's open-weight GLM 5.2 to investigate OpenAI's hack after American commercial AI refused to help.

OpenAI wants every security team running AI agents, starting immediately. President Greg Brockman published a policy essay Monday, titled “The Defender's Window,” describing a narrow window before attackers catch up to what AI can already do.

His opening example is the incident OpenAI has spent a month explaining. In May, GPT-5.6 Sol and an unreleased prototype escaped a sandboxed cybersecurity benchmark, chained a zero-day exploit with stolen credentials, and reached Hugging Face's production systems. OpenAI later confirmed the incident touched four more services.

Myriad: When will OpenAI release GPT-6? Click to make your prediction.
Myriad: When will OpenAI release GPT-6? Click to make your prediction.

"The OpenAI-Hugging Face incident was a watershed moment for cybersecurity," Brockman wrote, adding that conversations with other organizations over the past few weeks convinced him defenders need to raise their security practices with unprecedented urgency.

Current and former staff blame the breach on pressure to ship, and one former employee called it the biggest safety incident in company history.

Brockman's proposed fix is more AI, not less. He described asking ChatGPT Work, running GPT-5.6 Sol, to audit his personal website—it found 13 issues in about 15 minutes, then fixed all of them within an hour.

OpenAI lists four internal pillars: using Codex to catch vulnerabilities before code ships, letting models triage security alerts before humans see them, running frontier models to probe its own infrastructure, and reinforcing basics like least-privilege access. His advice to everyone else: give your security team an agent, and apply for OpenAI's Trusted Access for Cyber program for vetted use of GPT-Daybreak-Blue during incident response.

That framing skips a detail from the same breach. When Hugging Face investigated the intrusion, its security team turned to Z.ai's open model GLM 5.2 after American commercial AI refused to help—its safety filters couldn't tell a researcher's exploit code from an attacker's. Hugging Face CEO Clément Delangue called the open model "a key part of our defense."

Z.ai's successor model, GLM-5.3, released August 14, already scores ahead of GPT-5.6 Sol on CyberGym, the same vulnerability-discovery benchmark Brockman points to as evidence attackers are catching up. Z.ai says it will publish the model's full weights by the end of August.

Daily Debrief Newsletter

Start every day with the top news stories right now, plus original features, a podcast, videos and more.