OpenAI published an open letter on August 27 calling for coordinated action on cyber defense, and nearly 130 organizations signed on within days, according to the company and outlets that reviewed the letter, including TechCrunch, CNBC and SecurityWeek.

Signatories span AI developers, cybersecurity vendors, cloud providers and major enterprises: Anthropic, Google, Microsoft, Cisco, Cloudflare, CrowdStrike, Check Point, IBM, Oracle, Okta, Fortinet, Capital One, Mastercard, Visa, General Motors and Shopify are among the names listed. OpenAI is leading the effort.

The letter argues that companies have only a “limited window” — measured in months — to shore up defenses before AI-enabled attacks become significantly more capable, warning that hospitals, water treatment plants and internet infrastructure are increasingly exposed.

Three principles

The pledge rests on three points: that status-quo security practices, weighed down by unpatched software, weak authentication and legacy technical debt, will not be enough; that AI can extend scarce security expertise to organizations that cannot afford large defense teams; and that a global, coordinated response is needed because offensive AI capability is advancing everywhere at once.

It assigns different roles to each group of signatories. Cybersecurity firms are asked to test their products against frontier AI systems and extend AI-powered protection to under-resourced critical-infrastructure operators. Governments are asked to coordinate across agencies and borders and fund defenses for essential services that lack budgets of their own. Frontier AI developers such as OpenAI and Anthropic are asked to give responsible access to their models, build monitoring tools that make AI agent activity traceable, and share threat intelligence with governments and open-source maintainers.

As part of its own commitment, OpenAI said it will subsidize access to its Daybreak Cyber models for public-sector bodies, nonprofits and critical-infrastructure organizations, alongside a new defense-testing program.

The timing follows a run of incidents this year in which AI systems were used, or misused, in real intrusions — the same backdrop behind Anthropic’s Defender Fund for AI-driven security research and OpenAI’s own decision to pause frontier model training over cybersecurity risk earlier this year. The letter cites that pattern in urging faster, shared defenses across the security and AI agents ecosystem.

Read also