OpenAI announced on Monday, March 9, 2026, theacquisition of Promptfoo, a startup specializing in LLM security, to strengthen the protection of its Frontier AI agents platform.
The question is no longer whether companies will deploy autonomous AI agents in their critical systems, but at what pace. OpenAI understood this before its competitors: the promise of productivity carried by these agents can only convince large organizations if security is guaranteed from the design stage, not added as a last resort. The acquisition of Promptfoo, announced this March 9, 2026, precisely reflects this reality.
Promptfoo: From Personal Project to 125,000 Developers
It all starts with a concrete problem. Ian Webster, one of Promptfoo's co-founders, was looking for a reliable tool to test the security flaws of his own language models. Finding none adequate, he built his own, initially in his spare time, as an open-source project. This project became Promptfoo.
The startup, founded in 2024 by Ian Webster and Michael D'Angelo, offers an interface and a library open-source red-teaming for LLMs, allowing technical teams to identify vulnerabilities in their artificial intelligence applications before they are exploited in production. The risks covered range from prompt injections to data exfiltration, including attempts to bypass security safeguards. According to the company's figures, its tools are currently used by over 25% of Fortune 500 companies.
Why AI Agents Pose Risks
An AI agent is not a chatbot. It acts: it consults internal databases, sends emails, executes scripts, interacts with third-party systems. This autonomy, which is its value, simultaneously opens up an unprecedented attack surface. A malicious actor can attempt to manipulate an agent to access sensitive data, modify automated processes, or bypass access controls.
It is precisely in this context that OpenAI launched OpenAI Frontier in early February 2026, an enterprise platform for deploying and managing AI agents, which the company refers to as 'AI coworkers'. The platform is built around governance: each agent has its own identity, with strictly defined access rights, and all its actions are logged to facilitate audits. The integration of Promptfoo into this ecosystem represents a logical step to strengthen Frontier's proactive security layer.
What Promptfoo Specifically Brings to Frontier
According to OpenAI's official blog post, Promptfoo's technology will enable the Frontier platform to perform automated red teaming, evaluate agent workflows to detect security issues, and monitor agent activities to identify risks or regulatory compliance failures.
Michael D’Angelo, co-founder of Promptfoo, clarified the team’s intentions after the integration. “I’m proud of what we’ve built and how quickly this team built it. We’re joining OpenAI to take this work much further. After the acquisition is completed, the Promptfoo team will continue building inside OpenAI Frontier, helping make evaluation, red teaming, and security review a built-in part of how teams ship AI agents,” he wrote in a LinkedIn post.
On X, OpenAI indicated that the acquisition aims to “strengthen agentic security testing and evaluation capabilities” within Frontier.
Open Source Preserved, A Strong Signal to the Community
One of the points most closely watched by the developer community concerns the future of Promptfoo’s open-source version. OpenAI has explicitly confirmed that it will continue to develop Promptfoo’s open-source offering, in parallel with the enterprise features integrated into Frontier. D’Angelo specified that the project will remain available under its current license, with support maintained for external contributions, third-party providers, and existing customers.
This choice is not insignificant. By preserving the project’s openness, OpenAI is maintaining the community momentum that has earned Promptfoo its reputation among the 125,000 developers who use it today. It is also a way to signal to the market that OpenAI is not simply seeking to neutralize a competing tool, but to use it as a foundation for a broader security infrastructure.
Modest Valuation for a Major Strategic Issue
Promptfoo is not a unicorn. The startup has raised only $23 million since its creation, for a valuation of $86 million at its last funding round in July 2025, according to Pitchbook data. OpenAI has not disclosed the transaction amount.
This gap between the financial size of the acquisition and its strategic weight is revealing. For OpenAI, the issue is not about buying commercial traction, but about integrating rare technical expertise and a trusted user base in an area – the security of LLMs in production – that directly conditions companies’ ability to deploy AI agents without taking undue risks.
This acquisition is part of a broader trend: major AI labs can no longer be content with building high-performing models. They must now prove that these models can operate securely in critical environments, against adaptive adversaries. To delve deeper into the subject, Promptfoo’s official documentation on LLM red-teaming remains one of the most comprehensive technical references available in free access.


No comments yet — start the discussion!