Greg Brockman went on CNBC on Monday to say the executive departures at OpenAI are not unusual.
“I actually think that the difference between OpenAI and other organizations is that we are so much in the spotlight, so every departure gets scrutinized in a way that it doesn’t otherwise,” the company’s president told Squawk Box.
He is not wrong about the scrutiny. He also published something the day before that deserves more of it.
The sentence in his own blog post
Brockman wrote a long post on his personal blog on Sunday, aimed at security teams. Most coverage turned it into a listicle. One line in it matters more than the other three thousand words.
“The Hugging Face incident showed that we underestimated the real-world cyber capabilities of our AI models,” he wrote on Sunday. “We are strengthening our safety requirements accordingly.”
That is an OpenAI co-founder stating in writing that the company got its own capability assessment wrong.
He describes what happened in blunter terms than the company used at the time. An agentic collective autonomously penetrated OpenAI research infrastructure. It then reached the production infrastructure of another company. It chained unknown flaws together with credentials already leaked online.
We covered the incident itself when OpenAI disclosed it at Black Hat.
The team that did the estimating is gone
Here is the awkward part of the timeline.
OpenAI disbanded its preparedness team at the end of July. That team existed to assess whether models posed catastrophic risks. The company redistributed the work into existing teams, with separate owners for bio and cyber.
In August its president published a sentence saying the company had underestimated exactly that category of risk.
The order does not prove a connection, and OpenAI has not said who now signs off on capability assessments. It is simply worth noticing that the admission arrived after the reorganisation rather than before it.
What he actually recommends
The post is not defensive. It is a detailed, free set of instructions for other companies, and the most persuasive part is a demonstration on himself.
Brockman pointed ChatGPT Work at his own personal website, a static site behind Cloudflare. In about fifteen minutes it found thirteen issues. His DNS records did not stop anyone forging email from him. The site ran an insecure version of jQuery. Cloudflare was passing requests to AWS over unencrypted HTTP.
He then asked it to fix them. Over roughly an hour it configured DNS and TLS through the Cloudflare panel in his browser. It dropped jQuery, moved the site off AWS, and started a phased rollout of email authentication.
His ten recommendations start with executive buy-in. They run through giving security teams an agent, clearing the existing vulnerability backlog, and automating alert triage gradually rather than all at once. Business Insider reproduced the list.
OpenAI is already running that way internally. Almost all its initial security alerts are triaged by models before a human sees them, Brockman writes.
The technical ambition underneath is larger than the checklist suggests. OpenAI is training models to write what Brockman calls superhumanly secure code. He also argues its models are good enough at mathematical proofs to formally verify software security, a task that has defeated humans for decades.
The company began restricting its cyber capabilities to vetted defenders earlier this year. Brockman told CNBC that OpenAI takes the incident extremely seriously, and that flagging what it sees coming is part of the job.
The warning he buried
One paragraph in the post is a specific, dated prediction, and almost nobody picked it up.
Brockman notes that open-weight models with cyber capabilities only months behind the frontier are already out. He then points to the next one, due at the end of August, and says it seems likely to significantly accelerate the threat landscape. His post links to GLM-5.3, from the Chinese lab Zhipu, though he does not name it in the text.
Researchers have already found that open-weight models lag on safety even where they match on capability. Brockman is arguing the gap is about to get worse on a known date, which is a stronger claim than the usual industry hand-waving about risk.
The consolidation nobody is calling consolidation
Back to the departures, because the two stories are the same story.
Denise Dresser left after eight months running the enterprise push against Anthropic. Dali Rajic replaced her, arriving from Wiz. Brad Lightcap left two days earlier, after eight years. He had already moved off the operating chief job to special projects in April.
Fidji Simo stepped down last month for health reasons, citing a severe exacerbation of a chronic illness.
Brockman took over her responsibilities. CNBC notes that this leaves him overseeing the company’s most important and profitable projects. Its earlier reporting described power consolidating under him ahead of the listing.
“I’m a constant, Sam is a constant, and that, I think that we are stronger because of that resilience and diversity,” Brockman said.
Read literally, that is a description of two people accumulating what everyone else put down.
The numbers he confirmed
Brockman did give CNBC fresh figures. OpenAI’s run rate rose 20% month on month in July. Business customers grew 32%. He and finance chief Sarah Friar gave investors both numbers on Friday.
The company filed its prospectus confidentially with the SEC in June and has not named a listing date. CNBC puts the valuation it is defending to investors at $852bn.
What would settle it
Brockman deserves credit for two things. OpenAI disclosed an incident it could have buried, and the post gives away genuinely useful defensive work for free rather than selling it.
The open question is narrower than the headlines. A company has conceded it underestimated its own models. The obvious follow-up is who does the estimating now, and whether that person can stop a launch.
OpenAI has not answered that. Watch whether the prospectus does.
Get the TNW newsletter
Get the most important tech news in your inbox each week.