Follow Cyber Kendra on Google News! | WhatsApp | Telegram

Add as a preferred source on Google

OpenAI Cyber Defense Letter Signed by 116 Companies

OpenAI's open letter on collective cyber defense, signed by 116 companies including Anthropic, Google and Microsoft, warns of AI-enabled attacks.

OpenAI open letter on collective cyber defense signed by 116 companies including Anthropic and Google

OpenAI published an open letter today, calling for a global surge in cyber defence, and 116 organisations signed it — Anthropic, Google, Microsoft, AWS, Cisco, IBM, CrowdStrike, Palo Alto Networks, Visa, and Mastercard among them.

The argument is that defenders are, for once, ahead. Today's AI models can find and fix flaws that have sat in production code for years, and the signatories want that advantage spent before attackers catch up. They call it the defenders' window, and they think it closes soon.

"We have a limited window to strengthen cyber defenses," reads the letter published on OpenAI's site.

The letter rests on three principles. First, status quo security is not enough — longstanding bugs, excessive permissions, misconfigurations, weak authentication and technical debt in legacy systems have left organisations exposed. Second, cyber-capable AI belongs in the hands of far more defenders, because it makes core security work faster and cheaper. Third, the response has to be collective, because cyber capability is advancing worldwide and no single company should control it.

Why Does This Matter Now?

The signatories expect AI-enabled attacks to become far more widespread and sophisticated in the coming months as models everywhere grow more capable. The risk they name is not corporate data. It is hospitals, water treatment plants, and the infrastructure that powers the internet — systems run by security teams, the letter describes as historically under-resourced.

What Is Each Group Asked to Do?

The letter splits its demands into four ways.

GroupWhat the letter asks for
Every organizationTreat cyber defence with incident-level urgency, fix the highest-risk weaknesses, and build in least privilege and defence in depth
Cybersecurity companies and technology partnersTest defences continuously against frontier capabilities, help critical-infrastructure operators deploy AI defence, share threat intelligence, and test playbooks
GovernmentsFund defence for essential services, expand trusted access programmes, give hospitals and water utilities defensive AI, and impose costs on attackers
Frontier AI companiesProvide model access, funding, and training to under-resourced defenders, make agentic identities traceable, and invest in authorized testing and private disclosure

What Changes for Organisations

The most practical instruction in the letter is a budget one: use capable, lower-cost models for broad coverage and save frontier models for the hardest problems. That is a quiet admission that blanket frontier-model deployment is unaffordable for most security teams. 

Where a system cannot be patched without breaking essential services, the letter says to apply compensating controls and verify they work, rather than leave the gap open. It also asks buyers to hold AI-generated code to the same security bar as anything else they purchase — a line worth reading twice if your team ships AI-assisted code today.

There is no funding figure, no deadline and no enforcement mechanism, and every signatory sells something in this market. The diagnosis still holds. Anyone running a hospital network or a municipal utility on unpatched legacy software now has 116 of the largest technology and financial companies on record saying the window to fix it is closing.

Post a Comment