[DigitalToday reporter Seulgi Son] OpenAI warned that open-weight AI models have relatively low guardrails and, after fine-tuning and additional computation, can gain cyberattack capabilities approaching frontier models, requiring safeguards against misuse.
Wana Tun (와나 툰), an applied AI security specialist at OpenAI, said on Sept. 7 at Aim Intelligence's "AI Risk Conference Seoul 2026" held at Samsung Finance Campus in Seocho-gu, Seoul, "What we worry about is not frontier models initiating cyberattacks. If a malicious attacker fine-tunes an open-weight model, it can cause significant damage."
Tun said even non-frontier models can raise their attack capabilities if given enough time and tokens. She assessed the gap with frontier models in terms of intelligence at about 6 to 8 months.
She said cyberattacks using AI are also evolving rapidly toward greater autonomy.
Tun said, "In 2022, AI was used as a coding assistant tool, but now, 4 years later, it can not only find vulnerabilities and write exploits but also autonomously carry out cyberattacks."
She said AI can continuously conduct reconnaissance and scanning, search for vulnerabilities in areas such as security equipment control, and take over networks. She added that multiple subordinate agents can work in parallel or exchange information with each other to sustain attacks over long periods.
She described the situation between existing corporate security systems and AI-based attacks as "asymmetric warfare." Tun said, "When responding to security incidents, people can only handle limited information in real time, but AI can maintain context information numbering in the millions." She added, "AI-based attacks are powerful because they can connect and perform multiple tasks in parallel."
She said corporate defense systems should shift accordingly to be centered on AI agents.
Tun said, "We need to deploy AI agents that monitor network changes and analyze security incidents to increase the speed of threat detection and response." She said AI should handle tasks from finding vulnerabilities to verifying the possibility of real-world exploitation and generating patches, while people focus on final decisions.
She added, "In a situation where AI attacks environments, communicates with each other and moves, companies also need to be ready to respond to cyber threats in an agentic way."
OpenAI's view is that rather than replacing existing cybersecurity solutions with AI, it is preferable to combine AI agents with existing systems.
Tun said, "Attackers are already moving at machine speed." She added, "Companies need to rapidly shift security workflows not by stopping at vulnerability discovery, but by verifying real-world exploitability and generating patches in an automated way."