OpenAI is warning that security teams have a limited window to improve defenses before AI-assisted attackers become more capable and common. In a post by Greg Brockman, the company frames the recent OpenAI-Hugging Face incident as a preview of how ordinary threat actors may use AI in the coming months.

The main concern is not a single exotic attack. OpenAI says models can help automate pieces of real-world cyber operations, making old software bugs, forgotten permissions, and weak security hygiene easier to find and exploit. The same tools can help defenders discover and fix those problems, but only if organizations improve fundamentals and give security teams AI support now.

The post is also a public signal about OpenAI's own defensive posture after a high-profile incident. Its practical message is straightforward: companies should treat AI as an accelerant on both sides of cybersecurity, not as a future risk that can wait for a later planning cycle.