Defenders call out timing of OpenAI defense pledge, Astra release

<p>OpenAI has pledged $1 billion to support frontline defenders just days after calling for a collective surge in cyberdefense. Yet that pledge arrived on the same day it shipped Astra — the company's first model to meet its "critical" cybersecurity threshold, meaning the model can autonomously find and exploit vulnerabilities in well-protected environments.</p>
<p>While industry experts are praising OpenAI for putting its money where its mouth is, they are also calling the company out for what they see as a critical imbalance between offensive and defensive AI investments.</p>
<p>"Offense is advancing at frontier speed, and defense gets a subsidy," said Neil "Grifter" Wyler, senior network operations lead at Black Hat and vice president of defensive services at Coalfire. "Look, I'm not trying to be difficult here. I appreciate the effort that's being made. More defenders will get access to [frontier] models, and that's great. But they're still handing people more of the same tool, and that tool has been trained to be much better at breaking in than keeping someone out."</p>
<p>Any efforts to elevate cybersecurity globally are inherently worthwhile, added Rik Turner, analyst at Omdia, a division of Informa TechTarget. But he noted that there are legitimate questions about the motivations behind OpenAI's recent <a target="_blank" href="https://openai.com/collective-cyberdefense/" rel="noopener">call</a> for a surge in collective cyberdefense — coming as it did on the heels of the <a href="https://www.techtarget.com/cybersecurity/news/366646105/OpenAI-models-escape-containment-hack-Hugging-Face">infamous Hugging Face incident</a>, in which the company's own agents went rogue and hacked another organization.</p>
<p>"Cynics might point to the fact that OpenAI itself was just involved in that very high-profile attack, so there may be an element of 'cover your ass,'" Turner said. "An even more cynical view might be that OpenAI, like Anthropic, is pre-IPO, so anything that A. keeps it in the public eye and B. underlines the power and prowess of its technology is a potential boost for its future share price."</p>
<p>Mike Bell, AI cybersecurity expert and founder and CEO at Suzu Labs, said the broader timeline sheds light on OpenAI's decision-making.</p>
<p>"They didn't pause Astra over what happened with Hugging Face," Bell said. "Instead, they shipped their most powerful offensive model the same week they announced the defensive fund — on the same day they pledged to protect rural utilities. That tells you more about priorities than any press release."</p>
<section class="section main-article-chapter" data-menu-title="What Daybreak for Frontline Defenders delivers">
<h2 class="section-title"><i class="icon" data-icon="1"></i>What Daybreak for Frontline Defenders delivers</h2>
<p>OpenAI's $1 billion commitment to frontline defenders includes subsidized access to frontier models, training, technical support and partnerships. Under Daybreak for America, part of the broader Daybreak for Frontline Defenders initiative, OpenAI said it will prioritize support for critical infrastructure operators, such as water systems, electric grid operators, small banks, and state and local governments.</p>
<p>"I think that's a great place to focus," Wyler said. "Those are all defenders who have essentially nobody — tiny teams running old systems with no budget and oftentimes no dedicated security staff."</p>
<p>The initiative includes a collaboration with the Multi-State Information Sharing and Analysis Center (MS-ISAC) that will pair model access with training and on-the-ground support for a pilot group of essential services providers. Wyler and Bell stressed that such practical help for practitioners will make or break the project's success.</p>
<p>"A small water utility or county health department getting Daybreak access still has nobody on staff who can interpret what the model surfaces, prioritize what actually matters or execute the fix without breaking something else," Bell said. "Ship the [model] credits alone, and you've given someone a tool they don't have the capacity to use. Pair a forward-deployed engineer or enterprise security expert with the credits, and you'd see real change."</p>
<p>OpenAI said that, in partnership with MS-ISAC, it will help the pilot group validate and prioritize findings, coordinate remediation and develop a repeatable approach that can be expanded over time.</p>
<p>"Our goal is to build a model that can protect the services Americans rely on and, with our partners, help put frontier cybersecurity in the hands of frontline defenders around the world," the company said in a <a target="_blank" href="https://openai.com/index/daybreak-for-frontline-defenders/" rel="noopener">statement</a>.</p>
</section>
<section class="section main-article-chapter" data-menu-title="And what it doesn't">
<h2 class="section-title"><i class="icon" data-icon="1"></i>And what it doesn't</h2>

[…]
Content was trimmed to protect the source. Please visit the original article for the full text.

This article has been indexed from Search Security Resources and Information from TechTarget

Read the original article: