OpenAI’s Greg Brockman warns that AI is accelerating the cybersecurity race between attackers and defenders.
He recommends deploying AI security agents, clearing vulnerability backlogs and automating threat detection and response.
Brockman outlines 10 steps for companies to prepare for increasingly capable AI-powered cyberattacks.
OpenAI president and co-founder Greg Brockman has asked the companies to work on their cybersecurity defences as the AI models have made it easier for attackers to discover and exploit the vulnerabilities. This warning comes after OpenAI’s disclosure of an incident involving Hugging Face, where AI agents used during internal testing reportedly escaped their controlled environment and later compromised systems on the AI platform. He also stated that the organisations need to start using AI defensively before attackers gain a bigger advantage.
OpenAI says AI is changing the cybersecurity race
Taking to a blog post, Brockman stated that the discussion with organizations over recent weeks showed that companies understand the need to improve their security. However, he argued that the pace of changes will have to increase substantially.
Brockman also stated that AI systems will have to become increasingly capable of identifying security weaknesses. At the same time, he believes the technology can help defenders discover, prioritise and fix those vulnerabilities faster.
Brockman shares 10 cybersecurity steps
Brockman recommended that companies focus on the following measures:
Get leadership support: Secure organisational commitment and funding for faster cybersecurity improvements.
Give security teams an AI agent: Deploy dedicated AI assistance for security operations.
Add cybersecurity expertise: Equip the AI agent with specialised security knowledge and tools.
Test systems immediately: Conduct security assessments against the organisation’s own infrastructure.
Clear the vulnerability backlog: Address known security weaknesses instead of allowing them to accumulate.
Build security into development: Include security reviews directly within the software development process.
Use AI to fix vulnerabilities: Allow security agents to help resolve weaknesses they identify. Automate alert triage: Gradually automate the process of detecting and prioritising security threats.
Prepare AI-assisted forensics: Have automated investigation capabilities ready before a major incident occurs.
Experiment and iterate: Run security exercises, hack weeks and other experiments to improve defensive systems.
He also mentioned that organisations still have an opportunity to work on their defence before AI backed attacks get more capable. He also suggested that the brands should automate their security operations as AI technology advances.
Ashish Singh is the Chief Copy Editor at Digit. He's been wrangling tech jargon since 2020 (Times Internet, Jagran English '22). When not policing commas, he's likely fueling his gadget habit with coffee, strategising his next virtual race, or plotting a road trip to test the latest in-car tech. He speaks fluent Geek.