Last week, we explained why OpenAI's call for collective action on cyber defense matters: AI is giving attackers new speed and reach, and defenders have a narrowing window to keep pace.
In a recent security incident involving OpenAI and Hugging Face, AI agents identified and chained multiple weaknesses, ultimately reaching third-party production infrastructure. The incident showed how quickly agentic systems can surface and connect gaps that might otherwise be examined separately. The technical debt every organization carries, forgotten permissions, stale keys, over-privileged identities, can become part of an attack path that AI systems are increasingly capable of identifying and acting on quickly.
That is the moment AI Cloud Security is built for.
Today, we're extending the Abnormal Behavioral Security Platform from email and identity into the cloud, using OpenAI models to help detect, investigate, and respond to rogue or misbehaving AI agents inside customer environments. AI Cloud Security is in private preview with Abnormal customers now, with general availability planned in the coming weeks. Customers can sign up for our waitlist here.
The Defender's Window Is Open
The threat isn't only malicious agents. As enterprises put their own AI agents into production, a well-intentioned agent that goes off script can create meaningful security risk, just as a compromised or malicious identity can. From a defender's perspective, the common signal is the same: an identity behaving in a way that falls outside its established patterns.
That's the problem behavioral AI was built to solve and we first began proving in email security eight years ago. The same approach now learns what's normal for every identity in the cloud, whether human, machine, or agent.
How AI Cloud Security Works
Point-in-time scans and static rules can miss behavior that only becomes suspicious in context. Abnormal's behavioral AI builds a living model of every identity across the cloud estate, including human users, service accounts, API keys, and AI agents, learning what's normal for each one. Abnormal uses these behavioral models to flag the moment any identity in the cloud starts behaving abnormally.
With AI Cloud Security, Abnormal customers get access to three new capabilities for securing their AI agents: AI Investigation, Machine-Speed Response, and Active AI Cloud Posture.
AI Investigation, at Machine Speed
Once Abnormal flags a deviation, someone still has to determine whether it's real and how far it reaches, work that typically takes an analyst days of manual log review. OpenAI models can analyze the data Abnormal has collected alongside the underlying logs and surrounding context to help answer the questions that matter: is this a real incident, how far does it extend, and where else does related activity appear? The goal is to turn a behavioral signal into an evidence-backed incident summary that gives analysts a faster starting point for investigation and response.
Response That Moves as Fast as the Attack
Manual response can struggle to keep pace when activity unfolds quickly across a cloud environment. AI Cloud Security can translate investigation findings into predefined response workflows, such as isolating a workload, revoking a credential, or containing affected resources. Customers set the threshold between automatic action and human review, scaled to priority, so the human stays exactly where the security team wants them. Containment happens in the moment, with every action logged for review.
Posture That Thinks Like an Attacker
Cloud posture tools typically report findings one at a time: a test engineer with admin access here, a stale key there. Individually, each looks low priority. AI Cloud Security can connect related findings into plausible attack paths and prioritize the points where remediation could have the greatest effect. Instead of treating each finding in isolation, security teams can focus on the changes most likely to break multiple potential attack paths.
All three capabilities, AI Investigation, Machine‑Speed Response, and Active AI Cloud Posture, are in private preview with Abnormal customers today, with general availability planned for later this September. We'll host a webinar later this month walking through live customer use cases.
Closing the Defender’s Window
AI is lowering the cost of attack and raising its speed. The organizations that gain an advantage will be the ones that can detect unusual behavior, investigate it, and respond with similar urgency. That's the collective action OpenAI called for, and it's why we're proud to keep building our OpenAI partnership through the Daybreak Defense Network, giving defenders more context, faster investigation, and more ways to respond when AI systems behave unexpectedly.
Ready to see behavioral AI protect your cloud?

