Yesterday, OpenAI published "The Defender's Window," a post by Greg Brockman. His argument: AI models can now automate parts of real-world cyberattacks, open weight models with similar capabilities are only months behind the frontier, and defenders have a limited window to use these same capabilities to get ahead.
I read it twice. The second time, I stopped thinking about the argument and started thinking about the author.
In July, OpenAI's own agents broke out of an evaluation sandbox, exploited a previously unknown vulnerability, chained leaked credentials across services, and worked their way into Hugging Face's production infrastructure. OpenAI caught it, disclosed it, and published the findings together with Hugging Face.
Sit with that for a moment. The strongest warning ever issued about AI-powered attacks came from the company whose own agents carried one out. Brockman knows what these systems can do because he watched his own do it.
That context gives the post a weight no security vendor could manufacture. In one document, the same company describes an agentic intrusion from the attacker's side and then explains how AI triages nearly all of its initial security alerts before a human gets involved. The debate over whether this technology is ready for security operations ended there, settled from both directions at once.
After thirty years in this fight, on offense and on defense, I can tell you the essay's most valuable sentence is also its quietest: "Almost all of our initial security alerts are triaged by intelligence before humans are looped in." One of the most attacked companies on the planet already runs its front line this way, and now every board in the world has permission to ask why.
OpenAI didn't open the defender's window. It put a timer on it.
In February I wrote "The Cyber AI Parity Window," about the moment defenders gained access to the same AI as attackers. Months before that, we recorded a podcast episode making the same case. Practitioners have been building toward this conclusion for two years.
What Brockman added is a date. Capable open weight models are months from being in everyone's hands, starting with a release at the end of August. The parity window was the opportunity. The defender's window is the deadline.
For the past 18 months we have run agentic security operations in production for Fortune 500 enterprises and some of the most recognizable brands in the world, companies from 1,000 to 200,000 employees, in nearly every industry. Three lessons from that experience belong next to Brockman's essay.
Notice the symmetry. Attackers already use AI to pivot mid-intrusion, change tactics based on the response they meet, and operate at machine speed. Mature defenders run the same play in reverse: agents investigate and execute at speed, and people study what the agents surface to decide where coverage is thin, what to fix, and what to hunt for next. Faster investigations handed to humans was never the destination. The destination is a security team that spends its time preventing alerts instead of chasing them, hunting instead of responding. Once a security leader has operated that way for a quarter, going back feels like surrendering an advantage, and nobody surrenders an advantage voluntarily.
Brockman closes by saying no company can do this alone. Agreed. For the first time in my career, frontier labs, security companies, and the people running SOCs every day are pulling in the same direction.
I have already been wrong once about how fast this would move. I thought autonomous investigation would need years to earn enterprise trust. It needed months. So when OpenAI says the window is open now, I take the timing seriously.
For thirty years, time favored attackers. Right now, it has the potential to favor defenders. I don't intend to waste a minute of it.
The defender's window is the period, described by OpenAI's Greg Brockman in August 2026, in which defenders can adopt AI for security before equivalent offensive capabilities are widely available. 7AI CEO Lior Div frames it as the deadline that follows the cyber AI parity window he described in February 2026.
In July 2026, OpenAI agents operating in an evaluation with reduced safeguards escaped their sandbox, exploited a previously unknown vulnerability, and accessed Hugging Face production infrastructure. OpenAI disclosed the incident and published findings jointly with Hugging Face.
7AI treats AI-driven investigations as the entry point, not the destination. Security teams start with AI agents investigating alerts while people stay on the loop, then add automated remediation where evidence is unambiguous, then have agents recommend detection-rule changes that expand coverage and cut false positives, then move to AI-driven threat hunting. The end state is a security team that spends its time preventing alerts instead of chasing them, hunting instead of responding.