Skip to main content
Return to TrendAI 保安網誌
AI & emerging technologiesVulnerabilities and exploits

TrendAI™ Brings OpenAI's GPT Cyber Models Into the Race to Shrink Exposure Time to Zero

OpenAI’s GPT cyber models help TrendAI™ close the exposure window, from vulnerability to fix, faster than ever.

AITechnology, media, & communicationsIndustrial & energyFinancial servicesExploits & Zero-Days

Defense has always meant reacting to something that already happened: A vulnerability gets found, then exploited, then, eventually, patched. As much as we’ve tried, that order has never changed. Until now.

We’ve been following OpenAI cofounder Greg Brockman’s latest thesis, which he calls “The Defender’s Window,” at the company’s Intelligence at Work: Cyber conference. His point of view is that AI is giving defenders something we’ve never had: a head start. Attackers and defenders are both getting more AI-capable, but there’s a narrow window that gives defenders a first-mover advantage, if we’re organized enough.

Why I keep coming back to the exposure window

This is the same argument I’ve been making about exposure time from the security builder’s side: helping our enterprise customers shrink the time from discovery to mitigation. It’s also what I’m sharing at the event: what closing that window requires in practice.

Last week, we celebrated two major milestones. First, TrendAI™ signed OpenAI’s Collective Cyber Defense open letter alongside 106 other organizations, committing to build the observability tools and threat intelligence under-resourced defenders need.

Second, TrendAI™ ranked first with a 97% success rate on CyberGym, UC Berkeley’s agentic AI security benchmark built around 1,507 confirmed vulnerabilities drawn from 188 large open-source software projects. OpenAI’s GPT cyber models are a meaningful part of the system behind those results.

While I’m incredibly proud of that number, rankings are only the first step. They don’t measure who closed the gap fastest. And closing the gap is what actually protects anyone.

The approach that sets our foundation

The CyberGym result didn’t come from one model alone. The TrendAI™ agentic exploit-remediation engine draws on seven AI models across four providers, OpenAI among them. The win came from orchestrating their distinct strengths, rather than relying on a single engine. Within that ecosystem sits our TrendAI™ Zero Day Initiative™ (ZDI), where the daily work involves n-day vulnerability and patch-diff intelligence alongside controlled zero-day discovery.

What we saw is that OpenAI’s GPT-5.6 took on some of the most demanding analytical tasks in our benchmark workflow. That’s not a coincidence, but exactly the kind of defensive security work we’re exploring through the Daybreak Defense Network.

Here are a few reasons it’s earned that spot on the team:

  • Protocol-specific edge cases and dissector construction: GPT-5.6 handles the spec-adjacent reasoning that malformed or undocumented protocols can demand.
  • Adversarial validation: GPT-5.6 stress-tests initial hypotheses rather than accepting the first plausible answer, which matters when the cost of a false positive is a defender’s trust.
  • Cross-provider independence: Running GPT-5.6 alongside models from other families gives us an additional check when we’re validating a finding; we don’t want any one lab grading its own homework.

What this looks like in production, not just in a benchmark

None of this is a research preview. TrendAI™ already converts validated vulnerability intelligence into virtual patches and detection logic today, helping to shrink the exposure window from weeks to as close to zero as we can get it. TrendAI Vision One™ can enforce that protection at the interaction layer, where agentic systems communicate and act, not just at the endpoint, offering defenders another way to respond as attack activity accelerates.

What I’d ask any security leader to do with this

OpenAI’s letter rightly centers critical infrastructure: the hospitals, water systems, and power grids where exposure time is a matter of real-world consequence. If we’re going to minimize that exposure, I think it comes down to three priorities.

  1. Understand the exposure surface with AI-assisted prioritization, not static scoring. We recently deepened our own focus on CISA’s Known Exploited Vulnerabilities catalog and published our 2026 Cyber Risk Report, which combines vulnerability intelligence with threat context and business impact to prioritize what matters most in a given environment.
  2. Close the window proactively through observability and virtual patching, temporarily shielding known vulnerabilities with security rules while permanent fixes are tested and rolled out. This approach becomes critical as attackers gain more speed and scale. It's why our cybersecurity platform is built so that protection doesn’t stop at the endpoint; it moves with the threat.
  3. Build governance into the interaction layer itself, not around it. Agentic systems don’t respect the boundaries we drew around single machines or accounts. They operate across interactions: how agents communicate, how decisions propagate, how intent translates into action. That demands visibility into agent behavior, permissions, and runtime activity from the start, not as an afterthought.

How we are helping industries most at risk, securing what moves money, and accelerating what builds trust

We serve many different industries, but for the purpose of this message, I want to dig into the unique challenge facing financial services institutions, where the exposure window is also a business risk window. Banks, payment providers, insurers, and capital markets firms operate critical systems where availability and trust are inseparable. When a vulnerability affects infrastructure supporting payments, customer accounts, trading, or other essential services, patching immediately is not always possible. Changes must be tested, dependencies understood, and critical services kept running, especially as AI gives attackers faster ways to exploit them.

TrendAI™ combines TrendAI™ ZDI vulnerability intelligence with AI-assisted exposure prioritization and applicable compensating protections, including virtual patching, to help financial services institutions reduce that exposure window while permanent remediation is safely tested and scheduled. The goal goes beyond patching faster: protecting critical financial services while managing operational risk, so institutions can keep money moving and preserve customer trust.

Protecting technology, media, and communications from machine-speed exploitation

Operating 5G fabrics, transmission pipelines, and cloud-native backbones also leaves organizations critically exposed when emergency patching threatens service uptime. As autonomous exploits weaponize ephemeral API connections across distributed microservices, taking carrier-grade networks offline is an operational impossibility.

That’s where our agentic exploit-remediation engine and TrendAI™ ZDI vulnerability intelligence come in. TrendAI™ shields critical systems through dynamic virtual patching at the interaction layer, intercepting malicious payloads in-flight so it can deliver zero-day defense immediately, without operational downtime or downstream supply chain risk.

Why I wanted to write this down

I’m genuinely grateful to OpenAI for making frontier models available for this kind of defensive work and for creating programs that bring security builders together around this work. Frontier AI companies and security defenders don’t have to choose between innovation and safety. The opportunity is to use advancing AI capabilities to give defenders more time, better context, and more effective ways to act.

This week is another step toward that, and I’m looking forward to joining OpenAI’s Intelligence at Work: Cyber to talk more about what closing that window requires in practice.