Abnormal’s new AI Cloud Security product enables enterprises to detect and respond to risky or malicious AI-agent behavior in cloud environments. Abnormal’s behavioral AI platform delivers real-time anomaly detection with autonomous investigation and response, using OpenAI Daybreak models to power investigation.
SAN FRANCISCO–(BUSINESS WIRE)–The OpenAI-Hugging Face incident was a wake-up call for cyber defenders. During an internal cybersecurity evaluation, AI agents identified paths beyond their intended environment and accessed production infrastructure belonging to a third-party organization. The incident highlighted a challenge security teams increasingly need to prepare for: capable AI agents can identify weaknesses, connect multiple gaps and interact with cloud infrastructure faster than traditional human-led workflows can respond.
Conventional cyber defenses face new challenges when AI agents are involved: AI attacks arrive at a scale no team can staff against, some behavior may not match known signatures and move faster than any human-led response. Behavioral approaches give defenders another way to identify unusual activity by understanding what normal behavior looks like rather than relying only on known threat signatures.
Securing Cloud Environments in the Agentic Era
Today, Abnormal AI announced AI Cloud Security, extending its behavioral AI engine to the cloud to detect risky or malicious AI agent behavior inside customer environments, with OpenAI models supporting investigation and response: fighting bad AI with good AI. Announced alongside OpenAI’s Cyber Summit as part of the Daybreak Defense Network, AI Cloud Security is in private preview for Abnormal customers and features the following capabilities:
Real-Time Detection of AI-Driven Cloud Breaches: Abnormal’s behavioral engine builds a living model of every identity in the cloud estate, spanning human identities, service accounts, API keys, and AI agents, to learn what “normal” behavior looks like for each. Like human adversaries, malicious or misbehaving AI agents may create behavioral signals when their activity diverges from those established patterns. Abnormal AI identifies anomalous behavior in cloud environments to surface potential security incidents for investigation.
Autonomous AI Response at Machine Speed: AI-driven activity can unfold faster than a human analyst can investigate and respond manually. Customers can configure Abnormal to take predefined actions when specified conditions are met, including: isolate the workload, revoke the credential, and contain the affected resources. Customers can configure Abnormal AI Cloud Security for automatic action or human review, based on severity.
AI-Assisted Investigation for Incident Responders: Abnormal investigation uses OpenAI Daybreak models to help customers investigate behavioral anomalies identified by Abnormal. The system can analyze underlying logs alongside Abnormal’s behavioral analysis to help incident responders understand what happened, assess the scope of an incident and determine appropriate response actions.
As Greg Brockman, President and Co-Founder of OpenAI, recently wrote in his blog post “The Defender’s Window”: “The OpenAI-Hugging Face incident was a watershed moment for cybersecurity because it gave a peek into how the capabilities of a typical threat actor will evolve in upcoming months. I’ve spoken with many organizations over the past few weeks, and one theme is clear: they know they need to fundamentally uplevel their cybersecurity practices with unprecedented speed.”
“The Hugging Face incident was a warning shot. It showed what capable agents can already do when they go off-script, and why security teams need to prepare for similar techniques being used intentionally by attackers,” said Evan Reiser, Founder & CEO of Abnormal AI. “Our platform already detects behavioral anomalies from human and non-human identities and I’m excited for us to extend these capabilities to protect enterprise cloud environments.”
Availability
AI Cloud Security is in private preview for select Abnormal customers today, with general availability planned for Q4 2026. Abnormal will expand the waiting list and host a webinar in late September featuring live customer use cases; Learn more here.
Disclaimer
Statements regarding future product features, capabilities, or availability reflect current plans and are subject to change. Preview features may be modified, delayed, or discontinued and should not be relied upon in making purchasing decisions.
About Abnormal AI
Abnormal AI stops cybercrime with AI, protecting more than 4,500 organizations, including more than 25% of the Fortune 500, as of July 2026. The Abnormal Behavioral Security Platform spans email, identity, and insider threat, built on proprietary Behavioral AI models designed to detect the attacks legacy, rules-based tools cannot. Learn more at abnormal.ai.
Contacts
Media Contact Hanah Johnson, [email protected]

