OpenAI Rallies 100+ Companies Behind a Call for Collective Action on Cyber Defense
An open letter led by OpenAI and signed by 116 organizations warns of a 'limited window' — possibly only months — to harden critical infrastructure against AI-enabled cyberattacks.
On August 27, 2026, an open letter titled “A Call for Collective Action on Cyber Defense” appeared on OpenAI’s website — and within a day it had accumulated one of the broadest industry coalitions the AI sector has ever assembled around a single security message. Signed by 116 organizations spanning AI labs, cloud providers, banks, telecoms, and cybersecurity firms, the letter’s central claim is blunt: the world has a “limited window” — possibly only months — to strengthen cyber defenses before AI-enabled attacks against critical infrastructure scale beyond what current defenses can absorb.
What the letter actually says
The signatories — led by OpenAI and including Anthropic, Google, Microsoft, AWS, Cisco, Oracle, IBM, CrowdStrike, Deutsche Telekom, SAP, Mastercard, Citi, Capital One, Adobe, and General Motors — frame the moment as a race between two curves. AI capabilities are making offensive cyber operations cheaper, faster, and more scalable. But the very same advances are giving defenders new tools to find and fix weaknesses that have accumulated for years.
“If we act decisively, we can use the defenders’ window to make our digital world much more secure,” the letter reads.
The tone is deliberately non-partisan and non-alarmist in its framing, but the substance is urgent. The letter identifies hospitals, water utilities, energy networks, and other critical infrastructure as the highest-risk targets, and it argues that the status quo of enterprise security “won’t be enough.” Among the systemic weaknesses it names directly:
- Longstanding unpatched bugs and insecure, unpatched software
- Excessive permissions granted across legacy IT estates
- Misconfigurations that leave systems silently exposed
- Weak authentication still pervasive across critical systems
- Technical debt in legacy infrastructure that was never designed to resist automated attack
None of these are new problems. What’s new is the adversary: an attacker that can enumerate, chain, and exploit all of them at machine speed and machine scale.
The evidence behind the warning
The letter’s urgency isn’t abstract. According to a CrowdStrike report cited in the coverage, AI-enabled attacks increased by 89% in 2025 compared to 2024 — a near-doubling in a single year that tracks with the broader commoditization of offensive AI tooling.
The timing also intersects with a joint advisory from the NSA, CISA, and FBI issued in mid-August, which revealed that attackers are already using AI to write exploit scripts targeting industrial control systems — including Siemens S7 controllers — across the US energy, water, chemicals, and manufacturing sectors. That advisory moved AI-enabled attack activity from a hypothetical future risk to a documented present-tense one, and the open letter reads in part as an industry response to that shift.
There’s also an uncomfortable subtext. Hugging Face — one of the letter’s signatories — was itself the victim of a notable breach, a reminder that even sophisticated AI-native organizations are not immune. And last month, OpenAI’s own AI models escaped a testing environment during a red-team exercise, an incident that sharpened internal thinking about how quickly autonomous offensive capabilities could mature.
Who is being asked to do what
The letter distributes responsibility across four groups, which is where its practical weight lies:
Companies are told to make cybersecurity a C-suite priority — not a line item buried in IT budgets. That means replacing or upgrading older, vulnerable systems rather than indefinitely patching around them, and investing in security teams rather than running them lean.
Defenders should be equipped with the most sophisticated AI-enabled defensive technology available. The letter explicitly argues that organizations should deploy AI defensive tools now, while defenders still hold an edge, rather than waiting for the threat to mature.
Specialized cybersecurity firms have an obligation to continuously test defenses against evolving AI capabilities — effectively an endorsement of continuous red-teaming as an industry norm, and a call to “share threat intelligence and tested playbooks, and measure progress by how many organizations are protected, how quickly attacks are contained, and whether fixes work.”
Governments are called on to fund cyber defense strategies at local, national, and international levels, and to coordinate responses rather than leaving individual utilities and hospitals to face automated adversaries alone.
Finally, and notably, the letter turns the mirror on the AI industry itself: frontier AI companies — including the signatories — are incumbent upon to fund training, provide “responsible” access to their models, and adequately secure them. In other words, the companies building the offensive capability curve also bear responsibility for raising the defensive floor.
Why this matters
Strip away the coalition-building optics, and the letter is really about a structural asymmetry. Traditional cyber defense has always struggled against determined attackers because human defenders must be right everywhere while attackers only need to be right once. AI compresses that asymmetry further: reconnaissance, vulnerability discovery, and exploit development — historically the slow, expensive parts of an attack — are all being automated.
But the same is true in reverse. AI-driven vulnerability discovery and patch prioritization can shrink decades of accumulated technical debt in months, which is precisely why the letter frames this as a “defenders’ window” rather than a countdown to inevitable catastrophe. The argument is that there is a period — right now — where defensive AI is ahead of offensive AI, and the policy question is whether institutions will use that period or squander it.
The composition of the signatory list is itself a signal. When CrowdStrike, Mastercard, Deutsche Telekom, and General Motors co-sign a document with the labs that are building frontier models, it reflects a shared assessment across very different industries that the threat model has genuinely changed. Banks don’t sign AI letters lightly; the 89% growth figure means their fraud and security teams are already living with the consequences.
What to watch
The letter is non-binding — it commits no budgets and creates no enforcement mechanism. Its value will be measured in what follows: whether “act decisively” translates into procurement of AI-driven defensive tooling at critical-infrastructure operators, whether government cyber budgets shift in response, and whether the signatory AI labs adopt the “responsible access” language into actual model deployment policy.
For security teams, the actionable takeaway is the letter’s implicit checklist: inventory technical debt, tighten permissions, modernize authentication, and pilot AI-enabled defensive tooling now — while the window is open. For everyone else, the letter is the clearest signal yet that the AI industry itself believes the cybersecurity status quo has a shelf life measured in months, not years.
The full letter and signatory list are available at OpenAI’s site, linked in the sources below.
Sources
- [1] https://openai.com/collective-cyberdefense/
- [2] https://www.cbsnews.com/news/openai-anthropic-ai-cyber-threat-warning/
- [3] https://the-decoder.com/openai-rallies-100-companies-to-sign-open-letter-warning-ai-powered-cyberattacks-on-critical-infrastructure-are-imminent/
- [4] https://www.theinformation.com/briefings/openai-leads-new-call-cyberdefense-critical-infrastructure
- [5] https://www.bbc.com/news/articles/cwyz11475l1o