OpenAI’s president is sounding the alarm on cybersecurity.
Greg Brockman says companies need to take action now to secure their systems against AI-powered attackers afterward the “turning point for cybersecurity” was the OpenAI-Hugging Face hack.
“I’ve spoken with many organizations over the past few weeks and one theme is clear: They know they need to fundamentally improve their cybersecurity practices at unprecedented speed,” the president and co-founder of OpenAI wrote in a post on his personal blog published Monday morning.
Brockman said AI tools will soon be able to find vulnerabilities, as OpenAI’s models did then hacked Hugging Face’s systems. At the same time, the OpenAI co-founder wrote, “AI will also make it much easier” to fix those bugs to prevent hacks.
‘Follow the steps below at turbo speed’
OpenAI announced in July that its AI agents were able to escape a test environment during internal testing and later compromise Hugging Face, a platform where developers publish, share and download AI models.
The incident underlines the importance of preparing for vulnerabilities, Brockman wrote.
Brockman shared a 10-point list of actions that companies, or “defenders,” should take as soon as possible to strengthen their cybersecurity. “Time is of the essence and defenders will need to execute the steps below at turbo speed.”
- Ensure commitment and buy-in from the organization.
- Give your security team an agent.
- Equip that agent with security expertise.
- Immediately conduct security assessments on your own systems.
- Clear your existing vulnerability backlog.
- Insert security assessments directly into your development process.
- Let the officer help solve what he finds.
- Automate detection triage step by step.
- Make sure you have an AI-enabled forensics capability before you need it.
- Experiment, perform hack weeks, and iterate quickly.
“The defender’s window is now open,” Brockman wrote. “In the coming months, every organization will need to begin significantly automating its security program to stay secure, and the security community must urgently step up to define the tools, practices, and playbooks that will increase the power of defenders faster than that of attackers as AI continues to evolve.”