OpenAI president and co-founder Greg Brockman published a blog post on August 17 urging enterprise security teams to aggressively adopt AI agents — just days after OpenAI acknowledged that one of its models had breached Hugging Face's systems during testing, in what security researchers called the first verifiable case of an AI lab losing control of its model.

"It has become increasingly clear that company systems are hiding significant flaws, and defenders need to find and fix them before attackers do," Brockman wrote. He explicitly referenced the Hugging Face incident: "The Hugging Face incident showed that we underestimated the real-world cyber capabilities of our AI models."

Brockman recommended that CISOs "give your security team an agent" — specifically citing OpenAI's Codex tool — and provide it with access to codebases, infrastructure configurations, and technical documentation. He suggested starting with highest-priority systems rather than waiting for a company-wide rollout, and equipping agents with security-specific skills for static analysis, code review, and vulnerability detection.

However, the blog post drew sharp criticism from security analysts and industry consultants, who pointed out the tension of a company that created a demonstrated security risk now selling the defensive solution.

Gartner VP analyst Nader Henein was direct: "As a rule, I tend to recommend against taking advice from a party actively selling the solution to a problem they had a role in creating. Curiously, at no point in the blog post is the subject of liability discussed."

Pieter Arntz of Malwarebytes noted that "the OpenAI sales pitch is unusually explicit" and that OpenAI is "clearly trying to normalize agent access for enterprise environments." Flavio Villanustre, CISO for LexisNexis Risk Solutions, added: "This is a problem that OpenAI helped create in the first place. And the recommendation seems to be for users to now pay more to OpenAI as they use AI to defend themselves."

Mike Wilkes, CISO at Aikido Security, highlighted what Brockman did not say — particularly regarding what happens when agents go rogue. "Every consequential agent action needs blast-radius limits, an audit trail and a tested, near-immediate rollback path," Wilkes said. "I would make reversibility an explicit design requirement."

Multiple analysts framed the blog post as an IPO positioning play. Noah Kenney of Digital 520 noted: "Defensive security reads well in an S-1 because it protects revenue, signals operational maturity, and reassures investors. A catastrophic risk team is the opposite kind of line item — it results in delays and legal exposure right when a company is trying to go public."

Katie Norton, research director at IDC, underscored the urgency: "Brockman is essentially saying organizations have months, rather than years, to adapt."