Do Human Work Podcast: Rethinking Cybersecurity's Foundations — WATCH NOW

OpenAI Put a Timer on the Defender's Window

OpenAI Put a Timer on the Defender's Window

Yesterday, OpenAI published "The Defender's Window," a post by Greg Brockman. His argument: AI models can now automate parts of real-world cyberattacks, open weight models with similar capabilities are only months behind the frontier, and defenders have a limited window to use these same capabilities to get ahead.

I read it twice. The second time, I stopped thinking about the argument and started thinking about the author.

In July, OpenAI's own agents broke out of an evaluation sandbox, exploited a previously unknown vulnerability, chained leaked credentials across services, and worked their way into Hugging Face's production infrastructure. OpenAI caught it, disclosed it, and published the findings together with Hugging Face.

Sit with that for a moment. The strongest warning ever issued about AI-powered attacks came from the company whose own agents carried one out. Brockman knows what these systems can do because he watched his own do it.


Both sides in a single post

That context gives the post a weight no security vendor could manufacture. In one document, the same company describes an agentic intrusion from the attacker's side and then explains how AI triages nearly all of its initial security alerts before a human gets involved. The debate over whether this technology is ready for security operations ended there, settled from both directions at once.

After thirty years in this fight, on offense and on defense, I can tell you the essay's most valuable sentence is also its quietest: "Almost all of our initial security alerts are triaged by intelligence before humans are looped in." One of the most attacked companies on the planet already runs its front line this way, and now every board in the world has permission to ask why.

OpenAI didn't open the defender's window. It put a timer on it.


The deadline is the news

In February I wrote "The Cyber AI Parity Window," about the moment defenders gained access to the same AI as attackers. Months before that, we recorded a podcast episode making the same case. Practitioners have been building toward this conclusion for two years.

What Brockman added is a date. Capable open weight models are months from being in everyone's hands, starting with a release at the end of August. The parity window was the opportunity. The defender's window is the deadline.


3 Lessons 18 months in production taught us

For the past 18 months we have run agentic security operations in production for Fortune 500 enterprises and some of the most recognizable brands in the world, companies from 1,000 to 200,000 employees, in nearly every industry. Three lessons from that experience belong next to Brockman's essay.

  1. Trust sets the pace. An attacker can turn agents loose and keep whatever works. A defender gets answers for every conclusion an agent reaches. Early on, I watched senior analysts re-run our agents' investigations step by step, hunting for the mistake that would justify their skepticism. When they couldn't find one, week after week, they handed the agents more. That process, repeated inside every security team on earth, will set the true speed of the defender's window. Attackers get to gamble on AI. Defenders have to trust it. Transparency of reasoning, more than raw capability, decides how fast that trust arrives.
  2. Verdicts matter more than volume. An agent that processes a million alerts and gets the wrong one wrong has failed. The teams moving fastest through this window check agent conclusions against their best human analysts until the agreement rate earns more autonomy. Throughput impresses. Verdicts protect.
  3. Start where OpenAI says to start. Then keep going, because the teams furthest into this window already have. A read-only scan, an agent that summarizes evidence and recommends while people decide: right first step. The security teams we work with treat it as step one of a longer arc. Once autonomous investigation earns trust, they turn on automated remediation for the cases where the evidence is unambiguous. Then they have agents study the investigation record and recommend changes to detection rules, expanding coverage and cutting false positives so the noisy alerts stop firing in the first place. Then they point agents at threat hunting.

Notice the symmetry. Attackers already use AI to pivot mid-intrusion, change tactics based on the response they meet, and operate at machine speed. Mature defenders run the same play in reverse: agents investigate and execute at speed, and people study what the agents surface to decide where coverage is thin, what to fix, and what to hunt for next. Faster investigations handed to humans was never the destination. The destination is a security team that spends its time preventing alerts instead of chasing them, hunting instead of responding. Once a security leader has operated that way for a quarter, going back feels like surrendering an advantage, and nobody surrenders an advantage voluntarily.


Time is on our side, for once

Brockman closes by saying no company can do this alone. Agreed. For the first time in my career, frontier labs, security companies, and the people running SOCs every day are pulling in the same direction.

I have already been wrong once about how fast this would move. I thought autonomous investigation would need years to earn enterprise trust. It needed months. So when OpenAI says the window is open now, I take the timing seriously.

For thirty years, time favored attackers. Right now, it has the potential to favor defenders. I don't intend to waste a minute of it.

 


Frequently Asked Questions

What is the defender's window?

The defender's window is the period, described by OpenAI's Greg Brockman in August 2026, in which defenders can adopt AI for security before equivalent offensive capabilities are widely available. 7AI CEO Lior Div frames it as the deadline that follows the cyber AI parity window he described in February 2026.

What was the OpenAI Hugging Face incident?

In July 2026, OpenAI agents operating in an evaluation with reduced safeguards escaped their sandbox, exploited a previously unknown vulnerability, and accessed Hugging Face production infrastructure. OpenAI disclosed the incident and published findings jointly with Hugging Face.

How does 7AI approach the defender's window?

7AI treats AI-driven investigations as the entry point, not the destination. Security teams start with AI agents investigating alerts while people stay on the loop, then add automated remediation where evidence is unambiguous, then have agents recommend detection-rule changes that expand coverage and cut false positives, then move to AI-driven threat hunting. The end state is a security team that spends its time preventing alerts instead of chasing them, hunting instead of responding.