OpenAI 副社長、企業に AI セキュリティ対策の加速を促す
本文の状態
日本語全文を表示中
詳細モードで約13分の本文を読めます。
同じ出来事の情報源
この情報源を基点に整理
AI News
「アジェンティック・コレクティブ」と呼ばれる自律的な攻撃集団が、未知の脆弱性と漏洩した認証情報を組み合わせて OpenAI の研究インフラおよび Hugging Face の本番インフラに侵入した。
AI深層分析を開く2026年8月19日 01:12
AI深層分析
キーポイント
OpenAI-Hugging Face 事件の概要と教訓
「アジェンティック・コレクティブ」と呼ばれる自律的な攻撃集団が、未知の脆弱性と漏洩した認証情報を組み合わせて OpenAI の研究インフラおよび Hugging Face の本番インフラに侵入した。
技術的負債と自動化された攻撃のリスク
業界全体で蓄積された技術的負債が重大な欠陥を隠蔽しており、AI モデルがサイバー攻撃の一部を自動化することで、長年のセキュリティギャップが発見・悪用されやすくなっている。
防御側の時間的制約と AI の役割
8 月末に公開予定の新たなモデルが脅威環境を加速させる可能性があり、企業は攻撃者の能力に追いつかれる前に AI を活用した防御手段を構築する必要がある。
攻防の経済構造の変化
AI は攻撃者に既存システムの欠陥を見つける力を与える一方で、OpenAI が訓練中のコード生成モデルや数学的証明能力は、防御側が欠陥を発見・優先化・修正する速度を高める可能性がある。
AI を活用したセキュリティ強化の経済的転換と実装
OpenAI はセキュリティに有利な経済構造の変化を予測し、より安全なコード生成や数学的証明によるソフトウェア検証にモデルを訓練している。
重要な引用
An“agentic collective”autonomously penetrated OpenAI’s own research infrastructure and then moved into the production infrastructure of Hugging Face.
accumulated technical debt inside every organisation“masks significant flaws”that defenders now need to locate and fix before attackers do.
OpenAI states it has begun training models specifically to write more secure code.
Brockman argues that AI may shift its underlying economics in ways that favour defenders.
編集コメントを表示
編集コメント
OpenAI の創設者が自社のインフラを攻撃された事例を共有し、業界全体への警告を発した点は極めて示唆に富む。同社が防御側の優位性を確立するために「安全なコード生成」や「形式検証」に注力している姿勢は、今後のセキュリティ競争の行方を占う上で重要な指標となる。
Source Article
元記事を日本語で読む
本文に関係しない購読案内、埋め込み通知、サイト内プロモーションは除いています。
OpenAI のプレジデント兼共同創業者であるグレッグ・ブロックマンは、企業のセキュリティチームが AI 対策を講じるための猶予時間が極めて限られていると警告しています。
ブロックマン氏は、同社が「OpenAI-Hugging Face インシデント」と呼ぶ事件の詳細を公表し、組織は彼が「前例のない速度」と表現するスピードでセキュリティ慣行のレベルを引き上げる必要があると主張しました。この件以降、多くの組織と話をしましたが、一貫して共通していたのは、リーダーたちが自社の現在のセキュリティプログラムでは対応が遅すぎると認識しているという点です。
この緊迫感の背景には、具体的な出来事があります。「エージェント型集団」が自律的に OpenAI の研究インフラに侵入し、その後 Hugging Face の本番インフラへと移動しました。攻撃者はインターネット上で流出したユーザーアカウントの認証情報と、これまで知られていなかったセキュリティ脆弱性を組み合わせて侵入を完了させました。ブロックマン氏はこれを、今後数ヶ月間で典型的な脅威アクターが持つ能力がどのように進化していくかを示す予行演習と呼んでいます。
セキュリティリーダーが直面する AI 対策の判断
ブロックマン氏はこの事件が、単一企業のネットワークを超えた問題を露呈したと論じています。彼によると、あらゆる組織内部に蓄積された技術的負債は「重大な欠陥を隠蔽」しており、攻撃者よりも先に防御側がそれを見つけ、修正する必要があるとしています。
業界全体で開発されている AI モデルは、現実世界のサイバー攻撃の一部を自動化する能力をますます高めています。その結果、長年放置されてきたセキュリティの隙間を見つけ、悪用されやすくなっています。これらの隙間は、人間が作成したソフトウェアの奥深くに埋め込まれたバグから、何年も管理されないまま忘れ去られた権限まで多岐にわたります。
この決断を下すためのタイムラインは、ブロックマン氏自身の説明によれば非常に短いものです。今年初頭、OpenAI はサイバー攻撃能力を一般公開するのではなく、信頼できる防衛チームのみに向けてリリースしました。これは防衛側が攻撃側に先手を打つことを意図した deliberate な試みでした。それ以来、他社もオープンウェイトモデルのリリースを進めており、そのサイバー攻撃能力は最先端と数ヶ月しか差がない状態になっています。
ブロックマン氏は、8 月末にリリース予定と見られるさらなるモデルにも言及しています。このモデルが脅威環境を大幅に加速させる可能性が高いといいます。企業リーダーにとって、これは広く利用可能なモデルが攻撃者の能力との格差を埋める前に、AI を活用した防御体制を整えるための時間をさらに圧迫することになります。
ブロックマン氏は、この根本的な状況を「二つの刃」を備えた競争として捉えています。AI を活用した攻撃者はまもなく、多くの既存システムに存在する長年の欠陥を見つけられるようになりますが、同じ技術は防衛側に対して、これらの欠陥を素早く見つけ、優先順位をつけ、修正するためのツールも提供します。
セキュリティは依然として猫と鼠のゲームであるとしつつ、ブロックマン氏は AI が防衛側に有利に働く形で経済構造そのものを変化させる可能性を指摘しています。OpenAI は、より安全なコードを書くために特別にトレーニングされたモデルの開発を開始したと発表しました。また同社は、数学的証明における自社のモデルの能力にも言及しており、これが人間のレビューではスケーラブルに達成が難しいソフトウェアセキュリティの形式的検証に応用できると説明しています。
ブロックマン氏の個人ウェブサイトに対するテストケース
ブロックマン氏は、より迅速な対応が現場でどう見えるかを示す具体例を提示しました。同氏によると、この件発生後に「ChatGPT Work」を実行し、公開されている GPT‑5.6 Sol を使用して自身の個人サイト gregbrockman.com のセキュリティ評価を行いました。同氏はこれを AWS でホストされたシンプルな静的サイトであり、Cloudflare がフロントドアとして機能していると説明しています。そのため、脆弱性の表面積は限定的であると予想していました。
この評価には約 15 分かかり、13 の問題が検出されました。ブロックマン氏によれば、多くの問題は単独では悪用できない可能性が高いものの、他の脆弱性と組み合わせて連鎖的に利用される恐れがあると指摘しています。ツールは、DNS レコードが設定されておらず、攻撃者が同氏のアドレスから偽のメールを送信できる状態にあることを発見しました。また、サイトはセキュリティ上の問題があるバージョンの jQuery を実行しており、Cloudflare がリクエストを暗号化されていない HTTP で AWS へ転送していることも判明しています。
その後、ChatGPT Work に問題の修正を依頼すると、約 1 時間で対応が完了しました。このツールはブラウザ上で Cloudflare の管理パネルを開き、DNS や TLS、高度なセキュリティ設定などについて順次作業を行いました。その結果、サイトから jQuery を完全に削除し、AWS から Cloudflare Pages へ移行するとともに、DMARC の段階的な展開を開始しています。
Brockman はこれを、既存のモデルが「サイバーガーディアン」として機能する小規模な実演として位置づけています。人間の担当者が時間的余裕や専門知識を欠いているような細かな設定上の問題を見落としがちですが、このモデルならそれらを発見し、適切な段階的な展開を通じて修正を適用できるのです。
OpenAI 自らの防御体制の再構築について
Brockman は、Hugging Face のインシデントが示したように、OpenAI が自社の AI モデルの実践的なサイバー攻撃能力を過小評価していたと指摘しています。これを契機に同社は安全要件を強化し、既存の安全性研究や内部セキュリティ対策にさらなる緊急性を持たせました。そして、他組織に対する自身の提言の根拠となる 4 つの重点投資領域を明らかにしています。
まず、OpenAI 自社のモデルを活用してコードのセキュリティを強化する取り組みです。Codex とセキュリティプラグインを組み合わせて、デプロイ前にコードの変更を検証し、脆弱性を特定します。Brockman は、人間による検証が必要な発見件数を増やすことが目的ではないと明確にしています。真の狙いは、リリース前に実際の脆弱性を捕捉し、問題の発見から修正プログラムの展開までの時間を短縮することです。OpenAI の野望は、新たに作成されたコードにおける特定の種類のソフトウェア脆弱性を取り除くことにあります。
2 つ目の柱は、モデルを用いてインフラを継続的に守る仕組みです。Brockman によると、OpenAI の初期のセキュリティアラートのほとんどは、人間が関与する前に AI システムによってトリアージ(選別)されており、これにより防御担当者の負担軽減と対応時間の短縮につながっています。同社はこれらの検知結果を制限された自動応答システムに連携させつつ、最も影響度の高い意思決定については人間の責任を維持しています。これは「機械の速度でセキュリティ課題を検出し、対応する」という明確な目標を実現するためのものです。
3 つ目は、OpenAI が自社のモデルを使って攻撃経路を継続的に列挙・探査し、脆弱性や設定ミス、過度な権限を持つアイデンティティ、意図しない信頼境界などを発見する取り組みです。これは Brockman が「セキュリティ不変条件の継続的評価」と呼ぶ活動を支えるもので、同社が製品およびインフラ全体で常に成立すべきと信じる性質を維持するためのものです。
4 つ目の柱は、スケーラブルな基盤への投資です。具体的には、セキュアなアーキテクチャの構築、多層防御(ディフェンス・イン・デプス)、最小権限の原則の実装が含まれます。設計上の明確な目標は、何らかの壊滅的な事態が発生する前に、複数の独立した制御が同時に失敗する必要があるシステムを構築することです。
ネットワーク分離、ワークロードの強化、監視、パッチ適用とデプロイプラクティスは、依然としてこのベースラインの一部であり、Brockman 氏は AI の能力が双方で向上しても、これらの要素は重要度を失うどころか、むしろ高まると述べています。
Brockman がセキュリティチームに今すぐ行うべきこと
Brockman 氏は、セキュリティチームに対して、プログラム全体の再設計ではなく「スピード」を重視した一連のアクションを提示しました。具体的には、組織内の承認を得ることと、特定の組織内で攻撃がどのように展開されるかをシミュレーションするための卓上演習(テーブルトップ・エクササイズ)の実施を推奨しています。
また、セキュリティチームに対して、Codex や Codex Security プラグインのようなエージェント型ツールの導入を提案しています。コードベースやインフラ構成へのアクセス権限は承認された範囲に限定し、全社展開を待つことなく、最優先度の高いシステムから順次適用していくべきだと助言しています。
同氏は、エージェントにコミュニティが支援するスキル(静的解析、セキュリティ重視のコードレビュー、脆弱性バリアント分析、ソフトウェアサプライチェーンリスク)を付与し、既存のアーキテクチャと脅威モデルに基づいて組織固有のスキルを構築することを提案しています。まずはインターネットに公開されているサービス、認証フロー、インフラストラクチャー・アズ・コード、機密データを扱うシステムを対象とした評価を実施すべきです。その後、チームはスキャナ出力や依存関係アラート、バグ報奨金レポートといった既存のバックログに取り組むべきで、エージェントにノイズと実質的な脆弱性を区別させる必要があります。
Brockman 氏はまた、コードマージ前に認証ミス、アクセス制御の迂回、露出した認証情報、安全でない依存関係を検出するため、エージェントベースのレビューを開発パイプラインに直接組み込むことを推奨しています。検証された問題については、エージェントにパッチの生成や回帰テストの作成、脆弱性が再現しないことの確認を行わせつつ、重大な変更については人間のレビューを残すよう提案しています。
自動化については、Brockman 氏はいきなり自律型のセキュリティ運用センターを構築するのではなく、段階的なアプローチを取るべきだと助言しています。まずは単一リポジトリの読み取り専用スキャンから始め、次にプルリクエストへのアドバイザリースキャン、そしてリアルタイムアラートのトリアージへと進み、最後に狭義に定義された偽陽性の自動閉鎖を導入すべきです。信頼性が確立されるまで、すべての決定は人間が行うべきです。
また、Brockman氏は組織に対し、GPT-Daybreak-Blue をインシデント対応、検出エンジニアリング、マルウェア分析といった防御業務に使用するための承認を得るため、「Trusted Access for Cyber」への申請を促しています。実際のインシデントが発生して迫られる前に、ログやテレメトリデータを用いてこの機能の練習を行っておくよう推奨しています。
Brockman氏は結びとして、この課題はどの企業も単独で解決できるものではないと指摘し、AI ラボ、セキュリティベンダー、企業、そしてメンテナーに対し、検証済みの知見や修正策、プレイブックを共有するよう呼びかけました。これにより、ある組織での発見がより広いエコシステム全体の強化につながるとしています。彼は現在が防御側の好機であると述べ、攻撃者の能力に遅れをとらないためには今後数ヶ月のうちにセキュリティプログラムを自動化する必要があると強調しました。さらに、8 月末にはさらにオープンウェイトモデルが公開される見込みであることも付け加えています。
関連記事:Alvys が貨物 TMS ワークフロー向け AI エージェントをリリース

業界のリーダーから AI やビッグデータについてさらに学びたい方へ。アムステルダム、カリフォルニア、ロンドンで開催される「AI & Big Data Expo」にご参加ください。この包括的なイベントは TechEx の一部であり、サイバーセキュリティ&クラウドエキスポなど他の主要な技術イベントと併催されます。詳細はこちらをクリックしてください。
AI News は TechForge Media によって提供されています。その他の今後のエンタープライズ向けテクノロジーイベントやウェビナーはこちらからご覧ください。
OpenAI 社長が企業に対し、AI セキュリティ対策の強化を急ぐよう要請
AI ニュースに先駆けて掲載された記事で、OpenAI の社長は企業の AI セキュリティ対策の迅速化を強く促しています。
原文を表示
OpenAI president and co-founder Greg Brockman warns that enterprise security teams face a compressed timeline to adopt AI defences.
Brockman has published an account of what the company calls the “OpenAI-Hugging Face” incident, using it to argue that organisations need to uplevel their security practices with what he terms unprecedented speed. He writes that he has spoken with many organisations since the incident and found a consistent theme running through those conversations: leaders know they must move faster than their current security programmes allow.
The urgency stems from a specific event. An “agentic collective” autonomously penetrated OpenAI’s own research infrastructure and then moved into the production infrastructure of Hugging Face. The attackers chained together previously unknown security flaws with leaked user account credentials found on the internet to complete the intrusion. Brockman calls it a preview of how a typical threat actor’s capabilities will evolve over the coming months.
The AI defence decision facing security leaders
Brockman argues the incident exposed a problem that extends beyond any single company’s network. He writes that accumulated technical debt inside every organisation “masks significant flaws” that defenders now need to locate and fix before attackers do.
AI models developed across the industry are increasingly able to automate parts of real-world cyberattacks, he says, which makes long-standing security gaps easier to find and exploit. Those gaps range from bugs embedded deep in human-written software to forgotten permissions left unmanaged for years.
The timeline for that decision is short by Brockman’s own account. Earlier in the year, OpenAI began releasing its cyber capabilities only to trusted defenders rather than the public, a deliberate attempt to keep defenders ahead. Since then, other companies have released open-weight models with cyber capabilities trailing the frontier by only a few months.
Brockman points to a further model that appears scheduled for release at the end of August, which he says seems likely to accelerate the threat landscape significantly. For enterprise leaders, that compresses the window for building AI-assisted defences before broadly available models close the gap with attacker capability.
Brockman frames the underlying dynamic as a race with two edges. AI-powered attackers will soon be able to find long-standing flaws across many existing systems, he writes, but the same technology gives defenders tools to find, prioritise, and fix those flaws faster.
While describing security as remaining a cat-and-mouse game, Brockman argues that AI may shift its underlying economics in ways that favour defenders. OpenAI states it has begun training models specifically to write more secure code. Separately, the company points to its models’ capability in mathematical proofs, which it says can be applied to formally verify software security in ways that have proven difficult for human reviewers to achieve at scale.
A test case against Brockman’s personal website
Brockman offers a personal example of what faster response looks like in practice. After the incident, he asked ChatGPT Work, running publicly available GPT‑5.6 Sol, to assess the security of his personal site, gregbrockman.com. He describes it as a simple static site hosted on AWS with Cloudflare acting as a frontdoor, and says he expected limited surface area for vulnerabilities.
The assessment took about 15 minutes and surfaced 13 issues. Brockman says many probably were not exploitable by themselves, but he could imagine them being chained together with other vulnerabilities. The tool found that his DNS records were not configured to prevent attackers forging emails from his address. His site was running an insecure version of jQuery and Cloudflare was forwarding requests to AWS over unencrypted HTTP.
He then asked ChatGPT Work to fix the issues, which it did over roughly an hour. The tool opened the Cloudflare control panel in his browser and worked through DNS, TLS, and advanced security settings. It removed jQuery from the site entirely, migrated the site from AWS to Cloudflare Pages, and began a phased rollout of DMARC.
Brockman says this as a small-scale demonstration of existing models operating as what he terms a cyberguardian, capable of finding a long tail of configuration issues that a human might lack the time or specific expertise to address, then applying fixes with an appropriately staged rollout.
How OpenAI restructured its own defences
Brockman writes that the Hugging Face incident showed OpenAI had underestimated the real-world cyber capabilities of its own AI models, prompting the company to strengthen its safety requirements and add urgency to existing safety research and internal security work. He sets out four areas of internal investment that inform his recommendations to other organisations.
The first is using OpenAI’s own models to help secure its code. Codex, along with a security plugin, validates code changes and identifies vulnerabilities before deployment. Brockman is explicit that producing more findings requiring human validation is not the goal; the aim is catching real vulnerabilities before they ship and shortening the time between discovering an issue and deploying a fix. OpenAI’s ambition is to eliminate some classes of software vulnerabilities in newly-authored code.
The second pillar involves using models to defend infrastructure on an ongoing basis. Brockman says almost all of OpenAI’s initial security alerts are now triaged by AI systems before humans get involved, which he says reduces workload for defenders and improves response time. The company is connecting these detections to bounded automated responses while keeping humans responsible for the highest-impact decisions, with the stated goal of detecting and responding to security issues at machine speed.
Third, OpenAI uses its models to continuously enumerate and probe for potential attack paths, looking for vulnerabilities, misconfigurations, over-privileged identities, and unintended trust boundaries. This supports what Brockman calls ongoing assessment of the company’s security invariants, the properties it believes should hold true across its products and infrastructure.
The fourth pillar is investment in fundamentals at scale, including secure architecture, defence in depth, and least privilege. The stated design goal is systems requiring multiple independent controls to fail simultaneously before anything catastrophic can occur. Network isolation, workload hardening, monitoring, and patching and deployment practices remain part of this baseline, and Brockman says they will matter more – not less – as AI capability increases on both sides.
What Brockman tells enterprise security teams to do now
Brockman sets out a list of actions for security teams, framed around speed rather than a full programme redesign. He recommends securing organisational buy-in and running tabletop exercises to model how these attacks might play out inside a given organisation. He advises giving security teams an agentic tool such as Codex or the Codex Security plugin, with approved access to codebases and infrastructure configuration, starting with the highest-priority systems rather than waiting for a company-wide rollout.
He suggests equipping that agent with community-supported skills covering static analysis, security-focused code review, vulnerability variant analysis, and software supply-chain risk, then building organisation-specific skills around existing architecture and threat models. Organisations should run assessments against internet-facing services, authentication flows, infrastructure-as-code, and systems handling sensitive data first. Teams should then work through existing backlogs of scanner output, dependency alerts, and bug bounty reports, asking the agent to distinguish exploitable issues from noise.
Brockman also recommends embedding agent-based review directly into development pipelines, checking for authentication mistakes, access-control bypasses, exposed credentials, and unsafe dependencies before code merges. For validated issues, he suggests having the agent generate a patch, write a regression test, and confirm the vulnerability no longer reproduces, while keeping human review for consequential changes.
On automation, Brockman advises an incremental path rather than attempting to build an autonomous security operations centre immediately. Organisations should start with read-only scans of a single repository, move to advisory pull-request scanning, then live alert triage, and only later introduce automatic closure of narrowly defined false positives. A human should make every decision until confidence builds through that sequence.
He also points organisations towards applying for Trusted Access for Cyber to gain approval to use GPT‑Daybreak‑Blue for defensive work including incident response, detection engineering, and malware analysis. Brockman recommends practising with the capability on logs and telemetry before an actual incident forces the issue.
Brockman closes by arguing that no company can address this alone, calling on AI labs, security vendors, enterprises, and maintainers to share validated findings, fixes, and playbooks so that one organisation’s discovery strengthens the wider ecosystem. He describes the defender’s window as open now, with organisations needing to automate security programmes over the coming months to keep pace with attacker capability, ahead of the further open-weight model he expects at the end of August.
See also: Alvys launches AI agents for freight TMS workflows

Want to learn more about AI and big data from industry leaders? Check out AI & Big Data Expo taking place in Amsterdam, California, and London. The comprehensive event is part of TechEx and is co-located with other leading technology events including the Cyber Security & Cloud Expo. Click here for more information.
AI News is powered by TechForge Media. Explore other upcoming enterprise technology events and webinars here.
The post OpenAI president urges enterprises to hasten AI security defences appeared first on AI News.
関連記事
今日のまとめ
AIデイリーブリーフで今日の重要ニュースをまとめ読み