The number is stunning: 10 million users, enterprise seats up 9x year-over-year. OpenAI's agentic AI tools have crossed a threshold that most SaaS products only dream of. But I am not a growth analyst. I audit cryptographic protocols for a living. And the first thing I look for in any system claiming to handle enterprise workflows is verifiability.
The code reveals what the pitch deck conceals.
OpenAI's agentic AI — powered by what is likely GPT-4o or the o1 reasoning series — now orchestrates multi-step tasks: reading files, calling APIs, sending emails, updating databases. It is a digital assistant that acts, not just talks. Yet here is the uncomfortable truth: we have zero access to the code that governs its behavior. No open-source model weights. No audited execution environment. No on-chain record of actions. From my perspective, this is not a feature — it is a vulnerability.
Let me frame this in a context I understand deeply: smart contracts. When a DeFi protocol announces 10 million users and 9x TVL growth without a public audit, my first reaction is not celebration. It is suspicion. Because the history of this industry is written in exploits that followed opaque growth. The same logic applies to AI agents. If your business processes become dependent on a system whose interior is hidden, you are building on sand.

Context: The Agentic Shift
OpenAI's latest product iteration — often referred to as ChatGPT Work or Enterprise — embeds agentic capabilities directly into the workplace. Users can instruct the AI to perform complex sequences: "Analyze this spreadsheet, generate a report, format it in the company template, and email it to the team." The tool calls multiple model instances, uses function calling, and executes code. It is the evolution from chatbot to autonomous worker.
The source article, published by Crypto Briefing (a media outlet focused on digital assets), highlights two data points: 10 million active users and a 9-fold increase in enterprise seat subscriptions. No further details are provided. No technical architecture, no pricing breakdown, no security audit. This is standard for press releases, but from a risk assessment standpoint, these omissions are red flags.
As someone who spent weeks in 2017 verifying Neo's Byzantine Fault Tolerance implementation against academic papers, I recognize the pattern. The narrative leads; the code follows — or never does. In the DeFi Summer of 2020, I audited Compound's governance contract and found an oracle edge case that was dismissed until the market corrected in 2022. The lesson: theoretical elegance means nothing under stress. The same applies to AI agents.
Core: Systematic Teardown
I will dissect this announcement across the same dimensions I use for any crypto protocol: technology, economics, security, and incentive alignment.
1. Technical Transparency: Zero.
The article provides zero detail on the agent architecture. Is it a single-model call with tool augmentation, or a multi-agent orchestration layer? What is the latency profile? How does it handle context windows when chaining multiple actions? Does it use retrieval-augmented generation (RAG) for enterprise knowledge bases? These are not academic questions; they determine failure modes. In my experience auditing AI-crypto hybrids (such as the decentralized training dataset marketplace in 2025), the most dangerous vulnerabilities emerge at the interface between model decisions and external actions. Without visibility, we cannot stress-test.
Smart contracts do not care about your narrative. Neither do AI agents. If the underlying model hallucinates a step in a multi-action pipeline, the consequence is not a funny chatbot reply — it is a corrupted database, a leaked email, an unauthorized transfer. The absence of published error rates or safety evaluations for agentic tasks is alarming.
2. Commercial Lock-In: Predictable.
10 million users and 9x enterprise growth suggest strong product-market fit. But what is the switching cost? OpenAI's platform lock-in is deep: proprietary APIs, custom function calling schemas, and tight integration with Microsoft's ecosystem. For enterprises, migrating agent workflows to a competitor (Anthropic, Google, or an open-source alternative) would require rewriting every prompt, every tool definition, every security policy. This is not a bug — it is a business model.
From a crypto perspective, this centralization is the antithesis of what we build. Blockchain's value proposition is verifiable sovereignty. OpenAI's agent is a walled garden. I have seen the same dynamic in DeFi: projects that attract massive TVL with subsidized liquidity, then sunset the incentives, and the users vanish. Here, the subsidy is convenience and performance. When the price changes (and it will), where do the agents go?
3. Security: Unauditable by Design.
Let me be blunt: any system that executes code on behalf of users without public audit is a security hazard. OpenAI's agent can access files, send network requests, and manipulate data. It runs on servers controlled by OpenAI. There are no on-chain receipts, no verifiable logs, no smart contract to enforce boundaries. The only guarantee is OpenAI's internal controls — which have been breached before (remember the ChatGPT data leak in 2023?).
I audited the soul, and it was hollow.
Enterprise agents multiply the attack surface exponentially. If an agent's action can be poisoned via prompt injection, an attacker could exfiltrate internal documents. If the model's function calling is not properly sandboxed, a malicious tool invocation could trigger unintended API calls. These are not hypotheticals; academic papers have demonstrated them. Yet the announcement celebrates growth without addressing these risks.
4. Incentive Misalignment: Classic.
OpenAI's incentives are clear: maximize user engagement and lock-in to drive subscription revenue. Safety and transparency are costs, not benefits. The company has a history of releasing features first and patching later. The enterprise growth only intensifies this dynamic. Every new seat is a new dependency. Every dependency is a new lever for pricing power.
Logic is the only currency that never inflates. But here, logic is obscured by marketing.
Contrarian: What the Bulls Got Right
I am not a luddite. The bulls have a point: centralized AI agents work, and they work well. The 10 million users are not bots — they are real people finding real value. The 9x enterprise growth indicates that large organizations trust OpenAI enough to roll out agents across thousands of employees. That trust is earned through consistent performance, regular updates, and a polished user experience. No decentralized AI project has matched this scale. The open-source landscape (LangChain, AutoGPT, etc.) remains fragmented and unreliable for production workloads.
Moreover, OpenAI's decision to embed agents into the workplace may accelerate the entire AI ecosystem, including crypto projects that integrate with these agents via APIs. A workforce accustomed to AI agents will demand similar capabilities in DeFi, DAO governance, and supply chain automation. The rising tide lifts all boats — even those built on blockchain.
But here is the contrarian twist: the very factors driving OpenAI's success are the same ones that will cause the next catastrophic failure. Centralization creates single points of failure. Proprietary code prevents independent verification. Rapid growth outpaces safety processes. The history of technology is littered with platforms that dominated by ignoring these risks — until they didn't.
Takeaway: The Accountability Call
We have seen this movie before. It was called ICOs in 2017. It was called DeFi in 2020. It was called NFT projects in 2021. In every case, the narrative outpaced the code, and the code struck back. OpenAI's agentic AI is no different. It is a system of enormous power and opaque design. The market is rewarding it with capital and attention. But as a security professional, I cannot endorse a product that refuses to ship its source code, publish its audit reports, or commit to on-chain verifiability.
Reproducibility is the highest form of respect. OpenAI shows none.
So here is my forward-looking judgment: the next major AI safety incident will involve an enterprise agent executing a catastrophic multi-step action due to a hallucination or prompt injection. When that happens, the narrative will shift from growth to accountability. The demand for auditable, transparent, and decentralized AI will surge. Crypto protocols that offer verifiable agent execution — using smart contracts to enforce boundaries, on-chain logs to trace actions, and open-source models to inspect reasoning — will become the new standard. The clock is ticking.
Will you trust your workflows to a system that refuses to show its source code? We audited the soul, and it was hollow.
The question is not whether OpenAI can sustain 9x growth. It is whether that growth is sustainable without a breach of trust. 10 million users are betting that it is. I am betting on the audit trail.