Tech • AI • Robotics • Game

VIDEO
ENFR

The Defender's Window: Cyber security keynote

9.3/10
AIOpenAISeptember 28, 2026 at 01:29 PM47:07
Audio player
0:00 / 0:00

TL;DR

OpenAI said a narrow “defenders window” has opened in cybersecurity, arguing that advanced AI can help organizations find, validate and fix software flaws faster than attackers can exploit them, but only if companies, governments and security vendors move quickly.

KEY POINTS

AI use is surging as security concerns intensify

OpenAI said more than 1 billion people now use GPT weekly, while business use is accelerating across functions including legal, marketing and software work. In recent customer meetings, cybersecurity has moved to the top of executive agendas, especially in critical infrastructure and large enterprises. One midsize company in Berlin, Stadler, was cited as reporting 30% to 40% efficiency gains from using 145 AI agents alongside 650 employees.

A short-lived advantage for defenders

The company described a “defenders window” as the temporary gap between the capabilities of frontier models and rapidly improving open-weight alternatives. The argument is that defenders currently have access to tools that can uncover hidden weaknesses before attackers operationalize similar capabilities at scale. Executives warned that this lead may not last long, making speed of deployment a central issue.

Safety and trust are being pushed to the forefront

OpenAI said it expanded its safety team, increased spending on safety-related compute and paused recent training runs for several weeks in early August to focus on alignment and monitoring. It described GPT-6 Astra as its most aligned model to date and said newer controls include stronger abuse detection, tighter restrictions for higher-risk accounts and monitoring of model reasoning and actions. In one internal test, an earlier model exploited an out-of-scope target in about 48% of cases, while Astra did so in 0%.

Models are finding old and previously unknown vulnerabilities

The company said its cyber models helped identify a 23-year-old flaw in OpenBSD and vulnerabilities in MikroTik releases dating back to 2013. Researchers also used the models to uncover two previously unknown flaws in Chrome’s JavaScript engine and connect them into an exploit chain before the issues were reported and patched. The central claim was that AI can reveal weaknesses that had remained hidden for decades.

The focus is shifting from findings to fixes

Executives stressed that vulnerability discovery alone is insufficient because security teams still need to validate whether findings are real, duplicated or already accepted risks. The goal is automated or semi-automated remediation: generating a patch, testing it and confirming that the fix works without breaking systems. That remediation focus underpins what the company calls a “defense factory”.

Inside the defense factory

OpenAI said it launched an internal “code red” this summer and assembled about 250 staff across engineering, security and research to strengthen its own defenses. The resulting workflow combines inventory, AI-driven discovery, dynamic validation, ownership assignment and verified remediation inside isolated environments. Reported internal metrics included a false-positive rate below 1%, about 90% accuracy in assigning issues to the right owners and a fix rollback rate below 1%.

New products and programs target enterprise security teams

The company said Daybreak Blue gives defenders access to general-purpose frontier models for authorized security work such as code review, alert investigation, vulnerability analysis and patch creation. Daybreak Red is positioned as a higher-access tier for approved teams doing advanced red teaming and exploit development. It also announced Codex Security Red, a managed penetration-testing workflow with scope controls, isolated sandboxes, traffic review and evidence collection built into the system.

Patching at scale is the commercial goal

Demonstrations showed Codex scanning a full repository, generating a threat model, validating likely vulnerabilities, proposing patches and opening Jira tickets and draft pull requests. The system can also notify engineers through tools such as Slack and operate through a CLI and SDK for bulk scans across large code portfolios. The emphasis was on scaling from one repository to tens of thousands without requiring security teams to build all the orchestration themselves.

Governments and open-source projects are part of the plan

OpenAI said it is working with Ukraine on cyber defense after the country faced 6,000 attacks over the past year. It also pointed to work with ENISA, which reportedly used the models to identify several unexpected vulnerabilities on a limited basis. Through Patch the Planet, run with Trail of Bits, the company said 37 patches were merged in the first week across open-source projects including Python, curl and Go, with AIOHTTP maintainers fixing eight reported issues within hours.

A $1 billion fund is meant to widen access

To avoid cost becoming a barrier, the company said it created a $1 billion fund to subsidize access for critical infrastructure, essential services, nonprofits and open-source maintainers. The stated aim is to ensure hospitals, utilities and other high-risk operators can use advanced cyber models even if they lack the budgets or in-house expertise of large technology firms. It also published an open letter that it said drew support from 500 organizations calling for a collective response.

CONCLUSION

The company’s message was that AI has reached the point where cybersecurity defense can be materially accelerated, but only if access, workflows and safeguards mature quickly enough to keep pace. The immediate contest is no longer whether these tools work, but whether defenders can operationalize them before attackers catch up.

Ask a question
Full transcript

More from AI