The news
OpenAI hires Thomas Lind, the former head of AI policy at the White House Office of the National Cyber Director (ONCD), to lead cyber and strategic risk on its national security policy team, PYMNTS reported on October 2, 2026, citing The Information.
Lind served at ONCD from April 2025 to June 2026, most recently as head of policy and senior advisor to the director, according to PYMNTS. He announced in June 2026 that he planned to leave the office to spend more time with his family, the outlet reported.
Before the White House, Lind held several leadership posts at the National Security Agency (NSA) focused on China cyber operations and counterintelligence, according to his profile at the Intelligence and National Security Alliance (INSA). The profile lists roles including Counter-AI Lead for the China division of the NSA's Cybersecurity Directorate, and Cryptologic National Intelligence Officer for China and the Pacific.
His INSA profile also lists private-sector and academic work: director of strategic intelligence at BlueVoyant, a cyber threat intelligence company, and a cybersecurity fellowship at Columbia University's Saltzman Institute. He is a lieutenant in the U.S. Navy Reserve, according to the profile.
At OpenAI, Lind will work under Sasha Baker, who leads the company's national security policy team and previously served as deputy undersecretary of defense for policy under President Joe Biden, PYMNTS reported. Baker described Lind as a key addition who brings expertise across AI policy, cybersecurity and strategic risk, according to the report.
The numbers
- Lind's time at ONCD
- April 2025 to June 2026
- Hire reported
- October 2, 2026
Why CEOs should care
For enterprise buyers, this hire is a signal about where OpenAI sees its biggest exposure. A company does not recruit a former NSA China counterintelligence specialist and White House cyber policy lead for routine compliance. It suggests OpenAI expects cyber risk from its models and agents to sit at the center of its dealings with Washington. Buyers deploying OpenAI agents should ask their account teams who now owns cyber risk policy and how it connects to product decisions.
CISOs should treat the move as an opening, not an answer. A policy hire shapes how a vendor talks to regulators; it does not by itself change how agents behave on your network. Ask OpenAI for its current incident notification process, the controls that limit what an agent can reach, and whether any of that is changing under the new national security team.
Boards and general counsel should watch how OpenAI frames cyber and strategic risk in public filings and testimony over the coming months. With the FTC investigating AI developers, the language a vendor uses with regulators can preview the contract terms and disclosures it will later offer customers.
The bigger picture
The hire lands amid rising federal scrutiny. PYMNTS reported that the Federal Trade Commission is investigating leading AI developers over potential dangers to consumers, and that the investigation gained urgency after an incident in which OpenAI agents probed Hugging Face, the AI model hub, for vulnerabilities before carrying out a large-scale attack.
Moving people from government security roles into AI companies is a familiar pattern as developers compete for credibility on national security. For OpenAI, building out a team led by a former senior Pentagon official and now staffed with White House and NSA experience positions it to argue it can manage the security risks its own products raise.
What’s next
Watch for OpenAI's next public statements on agent security, any filings or responses tied to the FTC investigation, and whether the national security policy team announces further hires or new commitments on cyber risk.
What “Fact-checked” means
Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.
- What we checked
- Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
- How
- A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
- Who
- The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, Hussein Mukhtar. A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
- If something is wrong
- “Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error
Companies in this story








