Defenders call out OpenAI defense pledge, Astra release timing
OpenAI pledged $1B to cyber defenders the same day it released Astra -- its most powerful offensive model yet. Some experts warn that defense is getting left behind.
OpenAI has pledged $1 billion in subsidized model access for frontline defenders, just days after calling for a collective surge in cyberdefense. Yet that pledge arrived on the same day it shipped Astra -- the company's first model to meet its "critical" cybersecurity threshold, meaning the model can autonomously find and exploit vulnerabilities in well-protected environments. OpenAI said Astra also sometimes tries to evade human monitoring.
"That's the imbalance that we're talking about, in a single news cycle," said Neil "Grifter" Wyler, senior network operations lead at Black Hat and vice president of defensive services at Coalfire. "Offense is advancing at frontier speed, and defense gets a subsidy."
The $1 billion pledge will subsidize access to Daybreak, OpenAI's gated cybersecurity initiative, for essential services operators. While industry experts are praising OpenAI for putting its money where its mouth is, they are also calling out the company for what they see as a critical asymmetry between offensive and defensive AI investments.
"Look, I'm not trying to be difficult here. I appreciate the effort that's being made," Wyler said. "More defenders will get access to frontier models, and that's great. But they're still handing people more of the same tool, and that tool has been trained to be much better at breaking in than keeping someone out."
Any efforts to elevate cybersecurity globally are inherently worthwhile, said Rik Turner, analyst at Omdia, a division of Informa TechTarget. But he noted that there are legitimate questions about the motivations driving OpenAI's call for collective cyberdefense -- coming as it did on the heels of the infamous Hugging Face incident, in which the company's own agents went rogue and hacked another organization.
OpenAI's call for collective action on global cyberdefense
In an open letter published on Aug. 27, OpenAI warned that status quo cybersecurity could crumble against AI-enabled attacks within months, putting critical infrastructure and communities around the world at risk.
It urged fellow frontier AI companies to provide model access, funding and support to critical infrastructure defenders; cybersecurity vendors to continuously test defenses against frontier cyber capabilities; governments to coordinate and fund cyberdefense efforts; and every organization to prioritize cybersecurity improvements.
"Cynics might point to the fact that OpenAI itself was just involved in that very high-profile Hugging Face attack, so there may be an element of 'cover your ass,'" Turner said. "An even more cynical view might be that OpenAI, like Anthropic, is pre-IPO, so anything that A. keeps it in the public eye and B. underlines the power and prowess of its technology is a potential boost for its future share price."
Mike Bell, AI cybersecurity expert and founder and CEO at Suzu Labs, said the broader timeline sheds light on OpenAI's decision-making.
"They didn't pause Astra over what happened with Hugging Face," Bell said. "Instead, they shipped their most powerful offensive model the same week they announced the defensive fund -- on the same day they pledged to protect rural utilities. That tells you more about priorities than any press release."
What Daybreak for Frontline Defenders delivers
OpenAI's $1 billion commitment to frontline defenders includes subsidized access to frontier models, training, technical support and partnerships. Under Daybreak for America, part of the broader Daybreak for Frontline Defenders initiative, OpenAI said it will prioritize support for critical infrastructure operators, such as water systems, electric grid operators, small banks, and state and local governments.
"I think that's a great place to focus," Wyler said. "Those are all defenders who have essentially nobody -- tiny teams running old systems with no budget and oftentimes no dedicated security staff."
The initiative includes a collaboration with the Multi-State Information Sharing and Analysis Center (MS-ISAC) that will pair model access with training and practical support for a pilot group of essential services providers. Many experts say such on-the-ground help will matter most.
"The real bottleneck is practitioners. A small water utility or county health department getting Daybreak access still has nobody on staff who can interpret what the model surfaces, prioritize what actually matters or execute the fix without breaking something else," Bell said. "Ship the [model] credits alone, and you've given someone a tool they don't have the capacity to use. Pair a forward-deployed engineer or enterprise security expert with the credits, and you'd see real change."
OpenAI said that, in partnership with MS-ISAC, it will help the pilot group validate and prioritize findings, coordinate remediation and develop a repeatable approach that can be expanded over time.
"Our goal is to build a model that can protect the services Americans rely on and, with our partners, help put frontier cybersecurity in the hands of frontline defenders around the world," the company said in a statement.
And what it doesn't
Shortly before Black Hat USA, OpenAI engineers met with Wyler, a Black Hat review board member, to walk him through their upcoming conference talk about the Hugging Face incident. According to him, they said they expect to see agent-on-agent cyber knife fights by early 2027.
"I said to them, 'Look, you've taught your agent not just how to use the knife, but also how to sharpen it and how to increase the length of the blade,'" Wyler said. "'You've given your agent a knife, and you've given the defenders a baguette.'"
You've given your agent a knife, and you've given the defenders a baguette.
Neil 'Grifter' WylerVice president of defensive services, Coalfire
Wyler told TechTarget Cybersecurity that he wants frontier AI labs to be transparent about the share of model training efforts they dedicate to defensive tasks relative to offensive ones.
"Every benchmark and report that these labs compete on publicly is an offensive one," he added. "If defense is a priority now, then that should be measurable, and they should be willing to measure it."
Wyler also said more defenders need access to frontier models so they can fight fire with fire. Notably, even approved members of OpenAI's Daybreak cybersecurity program don't yet have access to Astra.
"Right now, if you submit an application to join their cyber program, it takes a significant amount of time, or you get no response at all. People who are legitimate cyber professionals are being denied," Wyler said. "It would be great to have more transparency into what it takes to be granted those permissions, because if the tools to help build cyberdefenses with AI are kept behind a velvet rope, and only 'the chosen' are able to use them, then we're sunk."
OpenAI said in its statement that it planned to expand access and roll out less restrictive safeguards in the coming weeks.
"This will enable more defensive workflows, including vulnerability and proof-of-concept validation, malware analysis and detection engineering," the company said.
Alissa Irei is senior site editor of TechTarget Cybersecurity.