AI Security

OpenAI’s Defense Factory: agent-first cyber ops, with the Done≠Deployed caveat still on the chart.

250+ people, 100+ service areas, IR urgency. Day 1 closed 53 P0/P1. Ownership 90.6%, 37% dupes, 0.81% FP after runtime, 100% Codex remediations / 0.53% rollback. Playbook = leadership surge + 6-week loop.

Sep 9, 2026 · 5 min read

Traditional scanners are not the underwrite anymore. OpenAI just published the operating system it wants defenders to copy.

On September 9 OpenAI launched The Defense Factory — a continuous, agent-first operation to find, validate, and fix vulnerabilities — plus a public playbook. The thesis is blunt: traditional cyber defenses alone are no longer sufficient when agents can abuse increasingly available open-weight models for long-running, machine-speed attacks. OpenAI’s own sprint ran with incident-response urgency: 250+ people mobilized across 100+ service areas. Thibault Sottiaux, Head of Core Products & Platform: “We are strengthening our defenses with the urgency of an incident. This is an all-hands effort that takes precedence over everything except critical business operations.” @OpenAI’s Sep 9 post (~4:37 PM ET) framed the same package — cyber models, shared architecture, and the playbook — for operators who need a build brief, not a brand video.

The numbers that matter are the loop metrics, not the slogans. Even before inventory finished, teams closed 53 urgent/high issues on day 1. After routing, accepted ownership hit 90.6%. Triage identified 37% of findings as duplicates. With isolated runtime environments, 19.5% of findings reproduced; the false-positive rate after dynamic validation was 0.81%. Remediation was 100% Codex-based, with a rolled-back fix rate of 0.53%. OpenAI’s own P0/P1 weekly remediations chart carries the honesty caveat CyberMerge will not sand off: “Recorded completion does not establish independently verified deployed remediation.” Treat Done/Resolved as workflow state, not as independent proof the fleet is patched.

Architecturally this is glue on top of tools you already own. The defensive loop is Inventory → Discovery → Dynamic validation → Ownership assignment → Verified remediation, with SECURITY.md as shared system context (not a sixth step). The stack splits a control plane (workload orchestration, policy enforcement, credential proxy) from a data plane of isolated ephemeral development environments, plus host/infrastructure/agent audit. Models named on the page: security models Daybreak Blue / Daybreak Red; general-purpose Astra / Sol / Terra / Luna; plus Codex Security skills (scan, triage, fix). Teams at Cloudflare, Ramp, and Google are also exploring the approach, per OpenAI. Related context only: Cloudflare is already shipping Vulnerability Discovery and Remediation with OpenAI Daybreak / GPT-5.6 Cyber — same Daybreak family, different product surface (CyberMerge Breaking).

POV for operators and investors: the “defender’s window” chart — the gap between frontier capability and broadly diffused open-weight capability — is labeled by OpenAI as illustrative trajectories, not a measured forecast. It does not set a calendar. Underwrite the operating change the playbook actually asks for: a leadership surge that pauses lower-priority work, funds models/environments/access, and names an executive sponsor plus delivery lead, then runs six-week workstreams (mobilize → fix priority exposures → inventory/ownership → reproducible envs → codify skills). The product question is whether your security org can turn scanners + tickets into an agent loop with verified owners and independently retested deploys — or whether you are still measuring “closed” tickets that never proved out in production.

Underwrite sheet — sourced only: 250+ people / 100+ service areas; 53 urgent/high closed day 1; accepted ownership 90.6%; duplicates 37%; runtime-reproduced 19.5%; FP after dynamic validation 0.81%; remediation 100% Codex; rolled-back fix 0.53%; P0/P1 chart caveat (recorded Done ≠ independently verified deployed remediation); loop Inventory→Discovery→Dynamic validation→Ownership→Verified remediation + SECURITY.md; control plane + ephemeral data plane + audit; Daybreak Blue/Red + Astra/Sol/Terra/Luna; Cloudflare/Ramp/Google exploring; playbook leadership surge + 6-week workstreams; defender’s window illustrative only (OpenAI Defense Factory page + playbook PDF, Sep 9 2026). Question the Done≠Deployed gap. Source: the playbook. The factory is the story — not a press-release paste.

Sources