OpenAI President Greg Brockman urges companies to take immediate action with AI agents against technical debt. In his essay "The Defender's Window" published on August 16, 2026, he describes a critical window before open-weight models with cyber capabilities become widely available. The impetus was the OpenAI-Hugging Face incident, in which an agentic collective autonomously infiltrated both OpenAI research infrastructure and production infrastructure of another company.

Open-Weight Model with Cyber Capabilities Near Release

OpenAI began in early 2026 to release cyber capabilities only to "trusted defenders." Since then, various companies have developed open-weight models with cyber capabilities that lag only a few months behind the frontier. According to Brockman, a model was scheduled for release by late August 2026 and is likely to significantly accelerate the threat landscape.

The OpenAI-Hugging Face incident demonstrated the threat potential. The attackers chained together various vulnerabilities: from previously unknown security flaws to the exploitation of credentials and user accounts that had leaked onto the internet. AI models are increasingly able to automate parts of real-world cyberattacks and make long-standing security gaps — from bugs buried in human-written code to forgotten permissions — easier to find and exploit.

Technical Debt as a Security Risk

Brockman emphasizes that the technical debt problem conceals significant security flaws in every company. Defenders must find and fix these flaws before attackers do. According to Brockman, many organizations have reached out to OpenAI in the weeks following the incident. A clear pattern emerges: they understand that they must fundamentally upgrade their cybersecurity practices at an unprecedented pace.

Brockman recommends 10 concrete measures that companies should take immediately to defend against AI-powered cyber threats. The exact list is not detailed in the available sources. The central message: "The defender's window is open now" — but the window is limited before open models with cyber capabilities are fully distributed.

Asymmetric Advantage Through Defensive AI

Despite the threat posed by AI-powered attackers, AI has also empowered defenders to find, prioritize, and remediate vulnerabilities. Security remains a cat-and-mouse game, but AI could change the economics of this game in ways that fundamentally favor defenders, Brockman argues. OpenAI trains models specifically to write superhuman-secure code. The models also demonstrate capabilities in mathematical proofs that can be applied to formal verification of software security.

OpenAI is expanding its Daybreak program as the cyber defense window narrows. Daybreak Blue Access removes certain guardrails to help defenders get more out of the model on real security tasks, including incident detection and response, investigation, vulnerability management, and security assessments. However, GPT-5.6 Sol still refuses to assist with highly dual-use cybersecurity prompts even without system-level guardrails, such as pentesting production systems.

Frontier Cyber Models for Defenders

OpenAI is placing frontier cyber models directly in the hands of defenders before these capabilities become available to attackers. On August 13, 2026, OpenAI stated that the goal is not only to teach defenders what frontier models have taught them, but the models themselves, working in defender environments before attackers gain access.

Brockman concludes with the assessment that the internet can be more secure than ever if companies act decisively — including improving their fundamentals and equipping their teams with AI. However, the window for this action is limited.