OpenAI has put a timeline on a shift many security teams were already sensing: open-weight models with significant cyber capability are only months behind frontier systems. In CSO Online’s reading of Greg Brockman’s warning, that turns the old “parity” idea into a narrower defender’s window, not a long-lived advantage.
The mechanism is simple: model capability is diffusing fast enough that the limiting factor is no longer access to AI, but whether security work can move to machine speed while staying controlled. OpenAI also says its own security alerts are already heavily triaged by intelligence before humans step in, with bounded automated responses handling more of the routine work.
For CISOs and SOC leaders, the practical meaning is that the gap between evaluation and usable automation is part of the risk now. If a team is still treating AI as a future project, the window may close before defensive workflows are ready to absorb it.
AI is set to help cyber attackers much more than defenders, says UK official
Dave Chismon, the NCSC’s chief technology officer for architecture, said in a blog post that the imbalance in AI means cyberattacks would likely grow as automated defenses struggle to keep pace.