• OpenAI acknowledges its latest agentic systems, including the Atlas AI browser, create significant cybersecurity vulnerabilities, particularly from prompt-injection and data-exfiltration attacks.
  • The company has disclosed patched vulnerabilities in GPT-4o and GPT-5 that allowed data theft from memories and chat histories, highlighting systemic risks.
  • Independent cybersecurity firms advise enterprises to restrict AI browsers from sensitive environments, citing inadequate current mitigations.

OpenAI has publicly warned that its newest AI models and products, especially its agentic systems and Atlas AI browser, create heightened cybersecurity risks, chiefly from prompt-injection and data-exfiltration attacks that could let attackers steal user data, override safeguards, or weaponize the models for traditional cybercrime. According to people familiar with the matter, the company's internal assessments flag these as "major emerging risks" that are not fully solved, particularly when models control browsers or tools.

Dane Stuckey, OpenAI's Chief Information Security Officer, explained in recent briefings that the shift toward agentic AI—where models can browse the web, act on user behalf, and integrate with user data—has expanded the attack surface dramatically. "What we're seeing is a convergence of browser, OS, and cloud risks with LLM-specific exploits," Stuckey said, emphasizing that prompt injection remains a persistent threat. Efforts to reach other executives for additional comment were unsuccessful as of press time.

The warnings come amid disclosures of vulnerabilities in GPT-4o and GPT-5 that enabled attackers to exfiltrate data from memories and chat histories; some issues have been patched, but they underscore the systemic challenges. Independent cybersecurity firms like NeuralTrust and LayerX have echoed concerns, noting that Atlas and similar AI browsers have critical flaws allowing remote code execution, privilege escalation, and data theft. A recent Gartner analysis advised enterprises to keep AI browsers out of sensitive environments for now, stating risks "cannot be adequately mitigated."

OpenAI has launched new security initiatives, including Aardvark, an AI security-research agent designed to find vulnerabilities in software and AI stacks, and expanded external testing with independent experts. The company's recurring reports, such as "Disrupting malicious uses of AI," show threat actors using ChatGPT to improve conventional attacks like phishing and malware at greater speed and scale, rather than inventing new super-attacks. Without robust safeguards, experts warn, companies could face increased compliance costs and liability as regulators escalate scrutiny of AI-driven cyber risk.

In the short term, expect more disclosed vulnerabilities as researchers probe these systems, and enterprises are likely to tighten policies around agentic AI. Long-term, security-by-design for AI—including formal threat models and stronger isolation of memories and tools—will become a core differentiator among providers. OpenAI's investment in Aardvark and external testing suggests a strategy of using AI itself as a defensive tool, but consensus among analysts is that prompt injection and LLM abuse will remain evolving threats, requiring ongoing vigilance.