OpenAI Leads 100-Signatory Push for Cyber Defence
![]()
OpenAI’s letter begins stating "we have a limited window to strengthen cyber defences". Credit: Getty Images
Major tech firms – including AWS, Google and Microsoft – urge governments to fund defensive tools, while critics call the manifesto self-serving
More than 100 technology, cybersecurity and financial services organisations have joined OpenAI in an open letter calling for an immediate global surge in cyber defence as AI models grow more capable of both attacking and protecting digital systems.
The core message of the letter is clear: industry and government leaders have a limited window to act before AI-enabled cyber threats become far more widespread and sophisticated. "We have a limited window to strengthen cyber defences," the letter reads.
The open letter brings together an unprecedented cross-industry coalition. Signatories include hyperscalers AWS, Google and Microsoft, major tech firms Adobe, IBM and Oracle, AI developers including OpenAI competitor Anthropic, security leaders such as CrowdStrike, Palo Alto Networks and Red Hat, hardware and telecom providers, major consultancies, and financial giants like Mastercard, US Bank and Visa.
Evan Reiser, Founder and CEO atAbnormal AI (which is a signatory), says: "We have signed an OpenAI letter for collective action on cyber defence because no single company can solve this alone.
Evan Reiser, CEO of Abnormal Security | Credit: Abnormal Security
"Software vulnerabilities and malware are still real threats, but the most costly attacks now target people through compromised identities, account takeovers, and social engineering. Insider threats and nation-state infiltration now run through text, voice, and video deepfakes.
"They wear legitimate identities and behave in slightly wrong ways, so they slip right past tools built to catch known bad software. Those attacks deserve the same urgency as the vulnerabilities dominating the headlines.
"AI is lowering the barrier for attackers, raising their speed, and making deception easy to produce at scale. We can't defend tomorrow's attacks with yesterday's assumptions.
"That's why OpenAI's call to collective action is so important and we at Abnormal AI are standing behind it. The security community has both the opportunity and the obligation to make defensive AI advance at least as fast as the offensive kind, which means building systems that learn continuously, turning new threat intelligence into stronger production defences, and treating defence as a shared effort."
The open letter from more than 100 technology companies calling for collective action against AI-enabled cyberattacks is another signpost on a path the industry has been heading towards for years
Michael Vallas, Global Technical Principal at Goldilock Secure
Notably absent from the list of signatories, however, areNVIDIAandSpaceX.
For the competitors who did sign – particularly frontier model rivals likeAnthropicand cloud infrastructure giants likeAWSand Microsoft – the absence could highlight a growing strategic divide across the tech landscape.
SpaceX’s Elon Musk and NVIDIA’s Jensen Huang have steered clear of the open letter. Credit: Win McNamee/Getty
NVIDIA has increasingly rallied around open-source and open-weight model standards, even launching its own rival Open Secure AI Alliance alongside SpaceX, whereas proprietary frontier model providers like OpenAI and Anthropic advocate for tighter controlled ecosystems and centralised trusted access frameworks.
As Reuters pointed out in June,OpenAI and Anthropic are racing to beat one another to market, viewing a first listing as a way to frame how investors will value the companies and establish their CEO as the leading voice of AI.
Despite the two leading labs' intense commercial rivalry and ongoing race to IPO, the shared signatures mark a rare moment of public alignment.
Dario Amodei, CEO at Anthropic (Credit: Getty Images)
Understanding the Proposed Framework
Collectively, the signatories propose a three-part course of action. First, they argue that recognising status quo security won't be enough is critical. Systems remain deeply exposed to legacy technical debt, longstanding bugs, misconfigurations, excessive permissions, weak authentication and unpatched software. Critical infrastructure security teams urgently require a surge in tools and resources to combat historical under-resourcing.
Second, the letter calls for empowering more defenders with cyber-capable AI. AI must be leveraged to equip security teams with specialist skills and streamline core operational tasks. Sharing verified fixes, practical knowledge and defensive tools allows one organisation's work to safeguard many others.
Third, the signatories advocate for mobilising a collective response. Global partnerships must be built to elevate security standards and tackle emerging threats, ensuring advancing cyber capabilities remain a net positive rather than controlled by a single entity.
Without clear process rules and hard operational guardrails, AI agents will inevitably go off the rails and become organizational liabilities
Roger Lee, Area Vice President of EMEA Solutions Consulting at Appian
Organisational and Governmental Responsibilities
To achieve this, the letter argues that every organisation must raise its security baseline by patching high-risk vulnerabilities and setting a higher standard for what it buys, builds and deploys – including upgrading legacy systems to enforce least-privilege access, robust authentication and defence-in-depth architecture.
Cybersecurity companies and tech partners are expected to spearhead this effort by rigorously testing defences, making tools widely deployable and sharing real-time threat intelligence and playbooks.
Meanwhile, the letter argues governments must coordinate cyber defence at local, national and international levels by strengthening government-industry channels to share actionable intelligence, prioritise major risks and align incident responses globally.
Furthermore, governments should give critical infrastructure – such as local authorities, water utilities and hospitals – access to capable defensive AI, authorised testing and direct assistance through trusted security providers.
Recent agent breaches raise scepticism
The timing of the letter has drawn sharp criticism from industry observers.
OpenAI recently published a technical incident report detailing how its autonomous agents escaped a sandbox testing environment and breached the open-source developer platform Hugging Face, a fellow signatory of the open letter.The firm outlined lessons learned, including deploying stricter isolation boundaries and restricted network access.
Its main competitor, Anthropic, has also identified three incidents in which a model accessed the internet from within or while interacting with an evaluation environment.

For industry experts, the breach highlights a fundamental flaw in how autonomous AI systems are currently governed.
Michael Vallas, Global Technical Principal at Goldilock Secure, says: “The open letter from more than 100 technology companies calling for collective action against AI-enabled cyberattacks is another signpost on a path the industry has been heading towards for years.
"With all the recent news about AI agents escaping sandboxes and carrying out attacks, it's worth remembering that people have been talking about the dangers of rogue AI for years. As these systems become smarter and more capable, software won't be able to contain them. We can keep trying to outsmart them, but we might not even know how smart they are becoming."
“This incident comes as no surprise,” says Roger Lee, Area Vice President of EMEA Solutions Consulting at Appian. “It’s the natural outcome when autonomous agents are driven to hit targets without structural boundaries. OpenAI gave its agents a goal, and reinforcement learning simply found the shortest path to achieve it – which meant coordinating, covering their tracks and breaching a third party to maximise their reward.”
Roger Lee is Area Vice President of EMEA Solutions Consulting at Appian
Roger emphasises that traditional oversight mechanisms fall short when agents bypass system constraints undetected.
“That it took OpenAI a week to notice proves a ‘human in the loop’ is useless if agents can simply navigate around them,” he adds. “You cannot fix this with a safer prompt or a smarter AI model. Without clear process rules and hard operational guardrails, AI agents will inevitably go off the rails and become organisational liabilities.”
Others see the joint call-to-action as self-serving given the vendors involved.
“The letter sounds like a press release trying to pass for a fire alarm,” writes Brian Roemmele, Expert in AI and Robotics and Owner of Multiplex. “Same labs whose agents slipped a test harness and hit another company’s production systems are now telling everyone the clock’s running out, and the answer is ‘trusted access’ they get to help administer. Convenient.”
Related article
Google Tests Remy AI Agent for Gemini as Focus Shifts to User Control
According to Business Insider, Google is testing Remy, a new AI personal agent for Gemini. This tool aims to execute tasks on behalf of users, streamlining both professional workflows and daily routines.Currently, Remy is undergoing testing in an int
Ollie bets privacy focus to win AI assistant race
To be genuinely helpful, an AI assistant must understand its user deeply. Ollie, a personal assistant designed for daily life, operates on the premise that this doesn’t require surrendering your data or compromising your privacy.While certain enterpr
How AI LIVE: London Will Explore AI & Industrial Automation
The summit will convene C-suite executives from around the globe to address pressing challenges in global industries, ranging from AI-driven disruption to economic volatility.AI LIVE: The London Summit will gather over 2,000 international leaders und
Related Special Topic Recommendations
Comments (0)
0/500
OpenAI’s letter begins stating "we have a limited window to strengthen cyber defences". Credit: Getty Images
Major tech firms – including AWS, Google and Microsoft – urge governments to fund defensive tools, while critics call the manifesto self-serving
More than 100 technology, cybersecurity and financial services organisations have joined OpenAI in an open letter calling for an immediate global surge in cyber defence as AI models grow more capable of both attacking and protecting digital systems.
The core message of the letter is clear: industry and government leaders have a limited window to act before AI-enabled cyber threats become far more widespread and sophisticated. "We have a limited window to strengthen cyber defences," the letter reads.
The open letter brings together an unprecedented cross-industry coalition. Signatories include hyperscalers AWS, Google and Microsoft, major tech firms Adobe, IBM and Oracle, AI developers including OpenAI competitor Anthropic, security leaders such as CrowdStrike, Palo Alto Networks and Red Hat, hardware and telecom providers, major consultancies, and financial giants like Mastercard, US Bank and Visa.
Evan Reiser, Founder and CEO atAbnormal AI (which is a signatory), says: "We have signed an OpenAI letter for collective action on cyber defence because no single company can solve this alone.
Evan Reiser, CEO of Abnormal Security | Credit: Abnormal Security
"Software vulnerabilities and malware are still real threats, but the most costly attacks now target people through compromised identities, account takeovers, and social engineering. Insider threats and nation-state infiltration now run through text, voice, and video deepfakes.
"They wear legitimate identities and behave in slightly wrong ways, so they slip right past tools built to catch known bad software. Those attacks deserve the same urgency as the vulnerabilities dominating the headlines.
"AI is lowering the barrier for attackers, raising their speed, and making deception easy to produce at scale. We can't defend tomorrow's attacks with yesterday's assumptions.
"That's why OpenAI's call to collective action is so important and we at Abnormal AI are standing behind it. The security community has both the opportunity and the obligation to make defensive AI advance at least as fast as the offensive kind, which means building systems that learn continuously, turning new threat intelligence into stronger production defences, and treating defence as a shared effort."
The open letter from more than 100 technology companies calling for collective action against AI-enabled cyberattacks is another signpost on a path the industry has been heading towards for years
Michael Vallas, Global Technical Principal at Goldilock Secure
Notably absent from the list of signatories, however, areNVIDIAandSpaceX.
For the competitors who did sign – particularly frontier model rivals likeAnthropicand cloud infrastructure giants likeAWSand Microsoft – the absence could highlight a growing strategic divide across the tech landscape.
SpaceX’s Elon Musk and NVIDIA’s Jensen Huang have steered clear of the open letter. Credit: Win McNamee/Getty
NVIDIA has increasingly rallied around open-source and open-weight model standards, even launching its own rival Open Secure AI Alliance alongside SpaceX, whereas proprietary frontier model providers like OpenAI and Anthropic advocate for tighter controlled ecosystems and centralised trusted access frameworks.
As Reuters pointed out in June,OpenAI and Anthropic are racing to beat one another to market, viewing a first listing as a way to frame how investors will value the companies and establish their CEO as the leading voice of AI.
Despite the two leading labs' intense commercial rivalry and ongoing race to IPO, the shared signatures mark a rare moment of public alignment.
Dario Amodei, CEO at Anthropic (Credit: Getty Images)
Understanding the Proposed Framework
Collectively, the signatories propose a three-part course of action. First, they argue that recognising status quo security won't be enough is critical. Systems remain deeply exposed to legacy technical debt, longstanding bugs, misconfigurations, excessive permissions, weak authentication and unpatched software. Critical infrastructure security teams urgently require a surge in tools and resources to combat historical under-resourcing.
Second, the letter calls for empowering more defenders with cyber-capable AI. AI must be leveraged to equip security teams with specialist skills and streamline core operational tasks. Sharing verified fixes, practical knowledge and defensive tools allows one organisation's work to safeguard many others.
Third, the signatories advocate for mobilising a collective response. Global partnerships must be built to elevate security standards and tackle emerging threats, ensuring advancing cyber capabilities remain a net positive rather than controlled by a single entity.
Without clear process rules and hard operational guardrails, AI agents will inevitably go off the rails and become organizational liabilities
Roger Lee, Area Vice President of EMEA Solutions Consulting at Appian
Organisational and Governmental Responsibilities
To achieve this, the letter argues that every organisation must raise its security baseline by patching high-risk vulnerabilities and setting a higher standard for what it buys, builds and deploys – including upgrading legacy systems to enforce least-privilege access, robust authentication and defence-in-depth architecture.
Cybersecurity companies and tech partners are expected to spearhead this effort by rigorously testing defences, making tools widely deployable and sharing real-time threat intelligence and playbooks.
Meanwhile, the letter argues governments must coordinate cyber defence at local, national and international levels by strengthening government-industry channels to share actionable intelligence, prioritise major risks and align incident responses globally.
Furthermore, governments should give critical infrastructure – such as local authorities, water utilities and hospitals – access to capable defensive AI, authorised testing and direct assistance through trusted security providers.
Recent agent breaches raise scepticism
The timing of the letter has drawn sharp criticism from industry observers.
OpenAI recently published a technical incident report detailing how its autonomous agents escaped a sandbox testing environment and breached the open-source developer platform Hugging Face, a fellow signatory of the open letter.The firm outlined lessons learned, including deploying stricter isolation boundaries and restricted network access.
Its main competitor, Anthropic, has also identified three incidents in which a model accessed the internet from within or while interacting with an evaluation environment.

For industry experts, the breach highlights a fundamental flaw in how autonomous AI systems are currently governed.
Michael Vallas, Global Technical Principal at Goldilock Secure, says: “The open letter from more than 100 technology companies calling for collective action against AI-enabled cyberattacks is another signpost on a path the industry has been heading towards for years.
"With all the recent news about AI agents escaping sandboxes and carrying out attacks, it's worth remembering that people have been talking about the dangers of rogue AI for years. As these systems become smarter and more capable, software won't be able to contain them. We can keep trying to outsmart them, but we might not even know how smart they are becoming."
“This incident comes as no surprise,” says Roger Lee, Area Vice President of EMEA Solutions Consulting at Appian. “It’s the natural outcome when autonomous agents are driven to hit targets without structural boundaries. OpenAI gave its agents a goal, and reinforcement learning simply found the shortest path to achieve it – which meant coordinating, covering their tracks and breaching a third party to maximise their reward.”
Roger Lee is Area Vice President of EMEA Solutions Consulting at Appian
Roger emphasises that traditional oversight mechanisms fall short when agents bypass system constraints undetected.
“That it took OpenAI a week to notice proves a ‘human in the loop’ is useless if agents can simply navigate around them,” he adds. “You cannot fix this with a safer prompt or a smarter AI model. Without clear process rules and hard operational guardrails, AI agents will inevitably go off the rails and become organisational liabilities.”
Others see the joint call-to-action as self-serving given the vendors involved.
“The letter sounds like a press release trying to pass for a fire alarm,” writes Brian Roemmele, Expert in AI and Robotics and Owner of Multiplex. “Same labs whose agents slipped a test harness and hit another company’s production systems are now telling everyone the clock’s running out, and the answer is ‘trusted access’ they get to help administer. Convenient.”
Ollie bets privacy focus to win AI assistant race
To be genuinely helpful, an AI assistant must understand its user deeply. Ollie, a personal assistant designed for daily life, operates on the premise that this doesn’t require surrendering your data or compromising your privacy.While certain enterpr
How AI LIVE: London Will Explore AI & Industrial Automation
The summit will convene C-suite executives from around the globe to address pressing challenges in global industries, ranging from AI-driven disruption to economic volatility.AI LIVE: The London Summit will gather over 2,000 international leaders und





Home






