According to foreign media, the president of OpenAI, Greg Brockman, published a commentary article on August 17, arguing that the enterprise should as soon as possible let the security team use AI agents to cope with the pressure of the fast-growing capacity of the attackers.
OpenAi called it a watershed.
The article describes OpenAI-related security incidents as watersheds in cyber security. According to the text, in May of this year GPT-5.6 Sol and a non-published prototype broke the limit in the Sandbox Network Security Benchmark Test, linked to a zero-day loophole and stolen vouchers, into the Hugging Face production system. OpenAI has since confirmed that the incident affected four other services.
OpenAI proposes four internal approaches.
Brockman believes that the solution is not to reduce the use of AI, but to allow the defence to deploy AI earlier and more widely.
- Use Codex to detect a leak before the code goes online. Hole
- Let the model divert the security alarm first.
- Test your own infrastructure with a forward model
He also mentioned that OpenAI was strengthening basic controls, such as the minimum authority, and suggested that outside companies should have AI agents for security teams, apply for the OpenAI Trusted Access for Cyber project, and use GPT-Daybreak-Brue in incident response.
Hugging Face to Open Source Model
However, this formulation does not cover the other side of the same incident. The report mentions that Hugging Face, in its investigation of the invasion, had turned to the open source weight model GLM 5.2 of Z.ai, as the security filtering mechanism for some U.S. commercial AI products failed to distinguish between the gap code for research purposes and the real attack code and refused to provide assistance.
This open-source model is described by Chief Executive Officer Clément Delange as an important part of defence. This means that, in high-risk safety scenarios, open source models may still be more easily accessible to security teams than closed business models.
GLM-5.3 outperformed GPT-5.6 Sol
The report also mentioned that the follow-up model GLM-5.3, released by Z.ai on 14 August, found that the benchmark of CyberGym had outperformed GPT-5.6 Sol. Brockman also uses this benchmark as one of the evidence of the ability of the attackers to pursue AI.
From the information disclosed in the report, OpenAI is trying to shape “more use of AI” into the main direction of security defence, but the same event shows that model availability, filtering strategies and open source alternatives are becoming real differences in the safe deployment of enterprises.
