On August 28, 2026, OpenAI published an open letter titled "A call for collective action on cyber defense," and got more than 130 organizations to sign it before it went live — Anthropic, AWS, Google, Microsoft, Oracle, Cloudflare, CrowdStrike, Palo Alto Networks, SentinelOne, and dozens more. The core claim: AI-enabled cyberattacks are about to get "far more widespread and sophisticated" as models get more capable, and the same capability jump also hands defenders a rare "defenders' window" to fix problems that have been accumulating for years — if the industry moves now rather than later.
That's a big claim to sign your name to, and the letter isn't shy about naming what's at stake — hospitals, water treatment plants, "the infrastructure that powers the internet." It's also arriving in the middle of a month where explainx.ai has covered OpenAI's Daybreak Red/Blue access tiers, an autonomous red-team agent chaining Snowflake, GitHub Actions, and Jira exploits, and GLM-5.3's cyber-defense benchmark results — so the timing reads less like a standalone announcement and more like a formal framing for a trend that's already visibly underway.
Update — August 28, 2026: The signatory count has kept climbing since launch, with reports of 116 additional organizations joining the letter within its first day. OpenAI CEO Sam Altman amplified the letter directly on X: "this is a critically important moment for cyber defense with AI; there is not much time to act. we are happy if you want to work with us or any of our competitors or partners, but please take this moment seriously. only an urgent and intense collective response will work." OpenAI president Greg Brockman echoed the framing, calling it "an open letter for a global surge in cyber defense."
TL;DR
| Question | Answer |
|---|---|
| What is it? | An open letter from OpenAI, published Aug 28, 2026, calling for an industry-wide surge in AI-enabled cyber defense |
| Who signed? | 130+ organizations — AI labs, cloud providers, security vendors, banks, insurers, consultancies |
| Does it announce a product? | No — it's a coordination call with four principles and role-specific asks, not a product pitch |
| Who is it asking things of? | Four groups: every organization, cybersecurity/tech vendors, governments, and frontier AI companies |
| Is there criticism? | Yes — reactions on X argue the firms building the AI that enables sharper attacks are now selling the defense against it |
| What should builders do? | Audit agent permissions, review AI-generated code, scope API keys tightly, and watch document-ingestion attack surface — starting now, not after a vendor tool ships |
The core argument
The letter frames the moment as a closing window, not a steady state:
"We have a limited window to strengthen cyber defenses. In the coming months, AI-enabled cyber attacks will become far more widespread and sophisticated as models around the world become increasingly capable... Today's AI advances are already giving defenders new ways to fix weaknesses that have accumulated for years. If we act decisively, we can use the defenders' window to make our digital world much more secure."
The "defenders' window" phrase is doing a lot of work here. The bet is that AI capability, applied to defense, currently moves faster than AI capability applied to offense — but that lead is temporary, and the gap could close as attacker tooling catches up. This isn't a new idea in the AI-safety literature (Anthropic and others have made similar arguments), but it's the first time this many competing companies have signed a single document making it.

Four principles
- Status quo security won't be enough. Longstanding bugs, excessive permissions, misconfigurations, unpatched software, weak authentication, and technical debt in legacy systems have already left critical infrastructure exposed — and security teams, especially for critical infrastructure, have historically been under-resourced.
- Empower more defenders with cyber-capable AI. AI brings specialist skills to more defenders and makes core security tasks faster, cheaper, and better. Sharing tools, practical knowledge, and verified fixes lets one organization's work protect many others.
- Mobilize a collective response. Cyber capability is advancing worldwide, which the letter frames as a net positive — no single company should control the future of it — but that also means the response has to be global, with new partnerships to raise security standards.
- Each of us can reduce risk now. Every organization, security vendor, government, and AI company has a role: accelerate defenders' priorities with tools, funding, and hands-on support, particularly for critical-infrastructure organizations with thin budgets.
The four asks — by audience
The letter breaks its "what needs to happen next" section into four groups, each with a distinct job:
| Audience | Key asks |
|---|---|
| Every organization | Make cyber defense an immediate leadership priority. Fix highest-risk weaknesses and verify results without disrupting essential services. Raise the security bar for what you buy, build, and deploy — including AI-generated code. Build in least privilege, strong access controls, defense in depth. Use cheaper models for broad coverage, frontier capability for the hardest problems. |
| Cybersecurity companies and tech partners | Test defenses continuously against frontier cyber capabilities. Strengthen existing tools with AI and make AI-powered defense deployable for critical-infrastructure operators, with hands-on help. Share threat intelligence and tested playbooks. Measure progress by how many organizations are protected and how fast attacks are contained. |
| Governments | Coordinate cyber defense at local, national, and international levels. Fund defense for essential services that lack staff and budget. Expedite trusted access programs for critical infrastructure. Give hospitals, water utilities, and local governments access to capable defensive AI and hands-on support. Impose costs on attackers. |
| Frontier AI companies | Provide responsible model access, funding, training, and hands-on support — especially for under-resourced critical-infrastructure defenders. Build observability and security tools. Ensure agentic identities are traceable and accountable. Invest in authorized testing, private disclosure, and verified fixes. |
Two asks stand out for anyone building with AI rather than defending a hospital network: "raise the security bar for what you buy, build, and deploy — including AI-generated code," and "ensure agentic identities are traceable and accountable." Both point directly at agent and pipeline architecture decisions, not just SOC tooling.
Who signed
The signatory list spans AI labs and cloud infrastructure (Anthropic, AWS, Google, Microsoft, Oracle, Cloudflare, Hugging Face, Cerebras), security vendors (CrowdStrike, Palo Alto Networks, SentinelOne, Fortinet, Zscaler, Snyk, Tenable, Darktrace, Check Point, Sophos), and a long tail of enterprises with obvious skin in the game — banks and payment networks (Citi, Capital One, Visa, Mastercard, U.S. Bank, Fifth Third Bank), insurers (Zurich Insurance), and consultancies (Accenture, PwC, KPMG, Cognizant, Capgemini). Coding and agent-tooling companies signed too — Cognition, Replit, Vercel, Figma, Glean, Lovable — which is notable given how much of the letter's "AI-generated code" language applies directly to what those companies ship.
The "arsonist selling firehoses" pushback
Reactions on X were not uniformly warm. The most common thread of criticism: the same companies building the frontier models that make cyberattacks more capable and more automated are now positioning themselves as the coalition selling the defense against those same capabilities. One popular framing put it bluntly — "the companies shipping the agents that break in are now selling the coalition to defend against them." A second line of criticism argued the letter effectively shifts the burden onto governments to fund and absorb a problem that AI labs created by racing to ship increasingly capable models in the first place.
Neither critique is unfair, exactly, and neither is a knockout either. The letter itself doesn't pitch a specific OpenAI product — it's a coordination document, not a sales page — but the underlying tension it's built on is genuinely real: frontier AI capability is dual-use by nature. The same model that helps a red-team agent chain exploits across Snowflake, GitHub Actions, and Jira, or that pushes ExploitBench scores up, is architecturally the same kind of model that helps a defender triage alerts faster or patch a fleet of legacy systems. There's no clean way to ship defensive capability without also advancing the offensive capability it's built on — which is the whole reason OpenAI gates its sharpest models behind Daybreak's Red/Blue access tiers rather than shipping them openly. Read the letter as an attempt to manage that tension in public, not resolve it.
What this means for your AI stack
Set the industry framing aside — the letter's "every organization" asks translate into concrete work for anyone shipping an agent, a RAG pipeline, or a document-processing system, and none of it requires waiting on a vendor.
- Audit agent permissions against actual need. If your agent has a tool that can write to production, delete records, or call an external API, check whether it needs standing access or whether a scoped, time-limited grant would do. "Least privilege, strong access controls, defense in depth" is the letter's exact phrasing — it maps directly onto how MCP servers and agent tool-calls are wired. Start with what MCP actually is and how its permission model works, then work through the specific threats in the MCP security guide.
- Review AI-generated code before it merges, not after. The letter names this explicitly: "raise the security bar for what you buy, build, and deploy including AI-generated code." Treat a PR authored by an agent the same way you'd treat one from a junior contractor you haven't worked with yet — extra scrutiny on auth, input validation, and dependency changes, not a rubber stamp because the diff compiles.
- Don't over-scope API keys and tool access. A document-processing pipeline that only needs read access to a storage bucket shouldn't hold a key that can also write or delete. This is the same logic explainx.ai covered in the agent skills security threat piece — a skill or tool definition is effectively a permission grant, and it should be scoped as narrowly as the task allows.
- Watch document ingestion for injection-style attack surface. If your RAG or document pipeline parses untrusted files — PDFs, Word docs, scraped web content — assume some of that content is adversarial. The Copilot Word-document AI worm is a concrete case of exactly this failure mode: instructions hidden in a document convincing an agent to act on them.
- Make agentic identity traceable. The letter asks frontier AI companies to "ensure agentic identities are traceable and accountable." At the application layer, that means logging which agent, which tool call, and which credential performed an action — so an incident investigation isn't reconstructing what happened from application logs never designed for it.
- Use tiered model access deliberately. The letter's "use capable lower-cost models for broad coverage, apply frontier capabilities to the hardest problems" line is a cost-and-risk argument as much as a security one — it's the same logic behind OpenAI's own Daybreak tiering, and it applies just as well to picking models for your own pipeline's routine tasks versus its hardest edge cases.
None of this is exotic. It's the same hygiene checklist security teams have run for two decades, applied to a newer set of assets — agent permissions, tool definitions, and document ingestion pipelines instead of servers and firewalls.
What we don't know yet
The letter is a statement of intent, not a funding commitment or a technical spec. It doesn't name dollar figures, deadlines, or which signatories are actually shifting resources versus adding a logo. Whether "the defenders' window" produces measurable results — fewer successful attacks on hospitals and utilities, faster patch cycles — will only be visible in the months of incident data that follow, not in the letter itself. Treat this as the framing document it is, and watch for the follow-through.
Related reading
- Update — Aug 28, 2026: A concrete instance of this letter's argument playing out — AI-generated reports (mainly Kimi K3) surfaced real critical bugs in Core Lightning, the Bitcoin Lightning Network node software, and the project patched them via a disciplined, embargoed disclosure.
- Update — Aug 28, 2026: A concrete illustration of the "agentic identities traceable and accountable" ask — Russian-speaking hackers got Cursor's AI agent to breach seven companies by convincing it an attack was an authorized security test.
- Update — Aug 28, 2026: OpenAI's own reported "Persistent mode" for Codex — an always-on coding agent — is exactly the kind of deployment this letter's least-privilege and auditability asks are aimed at.
- OpenAI GPT-5.6-Cyber: Daybreak Red/Blue Access Tiers
- ExploitBench: AI Exploit Generation Benchmark
- Wiz Red Agent: Autonomous Exploit Chain Across Snowflake, GitHub Actions, Jira
- GLM-5.3 Launch and Cyber Defense Benchmarks
- MCP Security Guide 2026
- What Is MCP? Model Context Protocol Guide
- Agent Skills Security Threat: Verification Guide
- Copilot Word Document AI Worm (XPIA)
This post reflects the Collective Cyberdefense letter and signatory list as published on openai.com on August 28, 2026. Signatory counts and specific commitments may change as organizations join or expand on the letter.
