OpenAI to Acquire Promptfoo and Build Red-Teaming Into Frontier
OpenAI is acquiring Promptfoo, whose red-teaming tools serve over 25 percent of Fortune 500 firms, and will embed them into its Frontier enterprise agent platform.

Updated
Why it matters
- OpenAI is acquiring Promptfoo, an AI security and evaluation platform used by over 25 percent of Fortune 500 companies; the deal is subject to customary closing conditions.
- Promptfoo's technology will be integrated into OpenAI Frontier, adding automated red-teaming for prompt injections, jailbreaks, data leaks, and tool misuse, plus compliance reporting and traceability.
- OpenAI says it will continue developing Promptfoo's open-source CLI and library for evaluating and red-teaming LLM applications.
OpenAI has announced it is acquiring Promptfoo, an AI security platform that helps enterprises identify and remediate vulnerabilities in AI systems during development. The deal, which remains subject to customary closing conditions, will fold Promptfoo's technology directly into OpenAI Frontier, OpenAI's platform for building and operating AI coworkers.
The acquisition lands at a moment when OpenAI is pushing enterprises to deploy autonomous AI agents into live business workflows. As those deployments scale, testing and security shift from optional extras to prerequisites. In its announcement, OpenAI framed the problem plainly: enterprises need systematic ways to test agent behavior, detect risks before deployment, and maintain records that support oversight, governance, and accountability over time.
What Promptfoo brings
Promptfoo's team is led by co-founders Ian Webster and Michael D'Angelo. The company has built a suite of enterprise tools that OpenAI says are trusted by more than 25 percent of Fortune 500 companies. Alongside the commercial product, Promptfoo maintains a widely used open-source CLI and library for evaluating and red-teaming LLM applications — a project that has become a fixture in the developer tooling ecosystem around large language models.
OpenAI says it will continue building the open-source project even as it advances integrated enterprise capabilities within Frontier. That commitment matters to developers who have adopted the library: open-source evaluation tools with a credible steward remain rare, and an acquirer abandoning a popular project would push users toward alternatives.
Srinivas Narayanan, CTO of B2B Applications at OpenAI, described the engineering rationale behind the deal:
"Promptfoo brings deep engineering expertise in evaluating, securing, and testing AI systems at enterprise scale. Their work helps businesses deploy secure and reliable AI applications, and we're excited to bring these capabilities directly into Frontier."
What changes inside Frontier
OpenAI laid out three concrete capabilities it intends to build for enterprises developing agents on Frontier.
First, security and safety testing becomes native to the platform. Automated security testing and red-teaming will help enterprises identify and remediate risks including prompt injections, jailbreaks, data leaks, tool misuse, and out-of-policy agent behaviors. Each of those threat categories has grown more acute as agents gain access to tools, internal data, and external systems.
Second, security and evaluation move into development workflows themselves. Frontier will integrate with the workflows needed to identify, investigate, and remediate agent risks earlier, making security a core part of how enterprise AI systems are built and operated rather than a final checkpoint before release.
Third, Frontier gains oversight and accountability features. Integrated reporting and traceability will let organizations document testing, monitor changes over time, and meet growing governance, risk, and compliance expectations for AI — a demand driven in part by regulators and auditors who increasingly expect evidence that deployed systems were tested against defined risks.
Why Webster sold
Ian Webster, Promptfoo's co-founder and CEO, tied the decision to the changing attack surface that agents create. Agents connected to real data and systems are harder to secure than isolated chatbots, and validation tooling has to keep pace.
"We started Promptfoo because developers needed a practical way to secure AI systems. As AI agents become more connected to real data and systems, securing and validating them is more challenging and important than ever. Joining OpenAI lets us accelerate this work, bringing stronger security, safety, and governance capabilities to the teams building real-world AI systems."
The quote signals where Promptfoo saw its ceiling. Selling evaluation and red-teaming tooling as an independent product works when buyers assemble their own AI stacks. It gets harder when the largest model providers bundle security testing into the platforms where enterprises already build — which is precisely what this acquisition accomplishes.
The market context
The deal fits a broader pattern. As OpenAI, Google, and Anthropic compete for enterprise workloads, each is assembling a full-stack offering: models, orchestration, observability, and now security testing. Acquiring an established evaluation vendor rather than building from scratch gives OpenAI an immediately credible answer to buyers asking how they can prove their agents are safe before deployment.
It also raises an obvious competitive question for the remaining independent players in AI evaluation and red-teaming. When one model provider owns a tool used across a quarter of the Fortune 500 — including, presumably, customers of OpenAI's rivals — neutrality becomes a selling point for everyone else. OpenAI's pledge to keep the open-source project alive will face scrutiny on exactly those grounds.
For now, OpenAI's message to enterprise buyers is direct: security testing, evaluation, and compliance reporting will ship inside the platform. If the integration delivers, the default path for building and validating AI coworkers will run through Frontier — and Promptfoo's technology will be the reason enterprises can document that their agents behaved.
Original: github.com
More from James Calloway
Show full bio
News editor covering industry trends and analytics at AI In Context.
121 articles
Related articles
- OpenAI Launches Aardvark, an Agentic AI Security Researcher
- OpenAI Ships AgentKit, Expanded Evals, and Reinforcement Fine-Tuning for Agents
- OpenAI adds Lockdown Mode and risk labels to ChatGPT
- OpenAI ships a model-native harness and native sandboxes for its Agents SDK
- OpenAI Publishes Policy for Disclosing Bugs It Finds in Others' Software