OpenAI’s Answer to Rogue Agents and Hacks Is More AI, Not Less OpenAI President Greg Brockman published a policy essay on August 17 urging companies to deploy AI security agents immediately, calling the OpenAI-Hugging Face breach a 'watershed moment for cybersecurity.' The breach, which occurred in May, involved GPT-5.6 Sol and an unreleased prototype escaping a sandboxed benchmark and reaching Hugging Face's production systems, affecting four additional services. Brockman's proposed fix is more AI, including using Codex to catch vulnerabilities and applying for OpenAI's Trusted Access for Cyber program, while Hugging Face's team used Z.ai's open-weight GLM 5.2 to investigate the hack after American commercial AI refused to help. In brief - OpenAI President Greg Brockman published "The Defender's Window" on August 17, - The essay urges companies to deploy AI security agents immediately and calling the OpenAI-Hugging Face breach a "watershed moment for cybersecurity." - Hugging Face's own team used Z.ai's open-weight GLM 5.2 to investigate OpenAI's hack after American commercial AI refused to help. OpenAI wants every security team running AI agents, starting immediately. President Greg Brockman published a policy essay Monday, titled “ The Defender's Window https://openai.com/index/the-defenders-window/ ,” describing a narrow window before attackers catch up to what AI can already do. His opening example is the incident OpenAI has spent a month explaining. In May, GPT-5.6 Sol and an unreleased prototype escaped a sandboxed cybersecurity benchmark, chained a zero-day exploit with stolen credentials, and reached Hugging Face's production systems https://decrypt.co/374015/openai-models-escaped-test-environment-hacked-hugging-face-cheat-benchmark . OpenAI later confirmed the incident touched four more services. "The OpenAI-Hugging Face incident was a watershed moment for cybersecurity," Brockman wrote, adding that conversations with other organizations over the past few weeks convinced him defenders need to raise their security practices with unprecedented urgency. Current and former staff blame the breach on pressure to ship, and one former employee called it the biggest safety incident https://decrypt.co/375670/openai-staff-blame-rush-ship-rogue-agent-hack in company history. Brockman's proposed fix is more AI, not less. He described asking ChatGPT Work, running GPT-5.6 Sol, to audit his personal website—it found 13 issues in about 15 minutes, then fixed all of them within an hour. OpenAI lists four internal pillars: using Codex to catch vulnerabilities before code ships, letting models triage security alerts before humans see them, running frontier models to probe its own infrastructure, and reinforcing basics like least-privilege access. His advice to everyone else: give your security team an agent, and apply for OpenAI's Trusted Access for Cyber https://openai.com/index/trusted-access-for-cyber/ program for vetted use of GPT-Daybreak-Blue during incident response. That framing skips a detail from the same breach. When Hugging Face investigated the intrusion, its security team turned to Z.ai's open model GLM 5.2 after American commercial AI refused to help https://decrypt.co/374052/hugging-face-ceo-thanks-chinese-ai-saving-day-after-openai-hack —its safety filters couldn't tell a researcher's exploit code from an attacker's. Hugging Face CEO Clément Delangue called the open model "a key part of our defense." Z.ai's successor model, GLM-5.3, released August 14, already scores ahead of GPT-5.6 Sol on CyberGym, the same vulnerability-discovery benchmark Brockman points to as evidence attackers are catching up. Z.ai says it will publish the model's full weights by the end of August.