OpenAI acquires Promptfoo to strengthen AI security as enterprise agents enter production

Reviewed byNidhi Govil

2 Sources

Share

OpenAI has acquired Promptfoo, a two-year-old AI security startup that helps Fortune 500 companies find and fix security vulnerabilities in AI models. The acquisition will integrate Promptfoo's open-source red-teaming technology into OpenAI Frontier, the enterprise agent management platform launched in February. The move signals OpenAI's commitment to making AI agents safe and reliable as they gain access to production systems with real-world consequences.

OpenAI Acquires Promptfoo to Bolster Enterprise AI Security

OpenAI announced Monday it has agreed to acquire Promptfoo, an AI security startup that enables large businesses to identify and fix security vulnerabilities in AI models during development

1

. The acquisition marks OpenAI's most direct move yet into AI application security, bringing aboard a company that counts more than 125,000 developers and over 30 Fortune 500 companies among its users

2

. Terms of the deal were not disclosed, though Promptfoo had raised approximately $23.4 million in total funding, including an $18.4 million Series A led by Insight Partners in July 2025

2

.

Source: The Next Web

Source: The Next Web

The ChatGPT maker will integrate Promptfoo's technology into OpenAI Frontier, the enterprise agent management platform launched just over a month ago in early February

1

. Frontier is designed to help organizations build and manage AI agents—what OpenAI calls "AI coworkers"—with appropriate guardrails and data access controls

1

. Early customers include Uber, State Farm, Intuit, and Thermo Fisher Scientific, organizations for whom a misbehaving agent represents significant liability rather than mere inconvenience

2

.

Why This Acquisition Matters for Enterprise AI

"OpenAI acquiring Promptfoo signals a clear commitment to making enterprise AI not just powerful, but safe and reliable at scale," said Ganesh Bell, managing director at Insight Partners

1

. The timing reflects a critical shift as AI agents move beyond experimental deployments into production systems with real-world consequences. Frontier gives these agents access to CRM platforms, data warehouses, internal ticketing tools, and the ability to execute workflows autonomously, creating a correspondingly enlarged attack surface that demands robust security testing

2

.

Source: Bloomberg

Source: Bloomberg

OpenAI and its rivals are racing to develop more advanced AI agents that can handle complex tasks on a user's behalf with limited human intervention

1

. At the same time, the company is working to convince a broader mix of businesses to pay for the technology by ensuring these products are both efficient and safe

1

. The acquisition addresses a gap that Promptfoo co-founder Ian Webster identified while leading the LLM engineering team at Discord: traditional vulnerability scanners cannot reason about prompt injection, and static analysis tools have nothing to say about models that promise users things they have no authority to deliver

2

.

How Promptfoo's Open-Source AI Red-Teaming Tool Works

Two-year-old Promptfoo makes open-source tools for testing AI security and helps companies attack their own products to find vulnerabilities through a process known as red-teaming

1

. The San Francisco-based startup counts roughly a quarter of Fortune 500 firms as customers across retail, telecoms, financial services, and media—sectors with acute exposure to regulatory and reputational risks of AI failures

1

2

.

The platform works by acting as an automated adversary, talking directly to a customer's AI application through its chat interface or APIs using specialized models and agents that behave like attackers . When an attack succeeds, the platform records it, analyzes why it worked, and iterates through an agentic reasoning loop to refine the test and expose deeper vulnerabilities

2

. Risks the platform targets include prompt injection, data leakage, jailbreaks, and what Webster has called "application-level" failures—AI systems that reveal database contents to customer service queries or stray into political opinion in homework tutors

2

.

What Frontier Gains from the Acquisition

As part of the deal, OpenAI Frontier will receive automated security testing and red-teaming features, along with capabilities to help organizations monitor changes and track testing to keep up with risk and compliance needs

1

. OpenAI pledged that Promptfoo would remain open-source under its current license, with continued support for existing customers

2

. The company said it will keep building out Promptfoo's open-source work while adding the technology to Frontier

1

.

Since launching Frontier on February 5, OpenAI has announced Frontier Alliances with Accenture, Boston Consulting Group, Capgemini, and McKinsey, enlisting these consulting firms to drive enterprise deployment . Separately, the company has been rolling out Codex Security, an AI-powered application security agent for software repositories that entered wider availability on the same day as the Promptfoo acquisition announcement

2

.

The Emerging Battleground in AI Cybersecurity

Promptfoo is one of several startups developing cybersecurity products that use AI to guard against hackers even as bad actors turn to similar technology to probe for ways into critical networks

1

. OpenAI has moved to imbue its AI products and agents with security features, including introducing an AI agent last week meant to help security teams find and patch vulnerabilities in large databases, similar to a tool from rival Anthropic

1

. Anthropic launched Claude Code Security in February, targeting similar vulnerability scanning use cases

2

.

The convergence suggests that as AI agents move into production at scale, the question of who secures them and how is becoming one of the defining commercial battlegrounds in enterprise AI

2

. For organizations deploying AI agents with access to sensitive systems, the ability to safeguard AI agents against prompt injection, data leakage, and application-level risks will determine whether these tools deliver value or create new vectors for catastrophic failures. As Promptfoo's technology becomes embedded in Frontier, businesses will be watching whether OpenAI's commitment to open-source development holds and how effectively integrated security testing can reduce the regulatory and operational risks that have kept many enterprises cautious about AI adoption.

Today's Top Stories

TheOutpost.ai

Your Daily Dose of Curated AI News

Don’t drown in AI news. We cut through the noise - filtering, ranking and summarizing the most important AI news, breakthroughs and research daily. Spend less time searching for the latest in AI and get straight to action.

© 2026 Triveous Technologies Private Limited
Instagram logo
LinkedIn logo