On August 27, OpenAI, alongside 127 other organizations, issued an open letter urging immediate enhancements in cybersecurity measures. They predict that in the coming months, AI-driven attacks will become more frequent and sophisticated.
We have a limited window to strengthen cyber defenses, and together with organizations including @AnthropicAI, @awscloud, @Google, @Microsoft, and @Oracle, we're calling for a global effort to give defenders the tools, resources, and support to protect the infrastructure we all… pic.twitter.com/XiKitsf5wb
— OpenAI (@OpenAI) August 27, 2026
Signatories include major players such as Anthropic, Google, Microsoft, AWS, AMD, Cisco, Cloudflare, CrowdStrike, Mastercard, Visa, Citi, Robinhood, Deutsche Telekom, Hugging Face, and other tech, finance, and cybersecurity firms.
The authors emphasize that the threat extends beyond companies to vital public services, including hospitals, water treatment facilities, and the infrastructure that supports internet operations.
The letter is based on three key principles:
- Recognize that current cybersecurity levels are insufficient. Authors noted persistent vulnerabilities, excessive access rights, configuration errors, unpatched insecure software, weak authentication, and the technical debt of outdated systems. They highlighted the chronic lack of resources for teams protecting critical infrastructure.
- Expand defenders' access to AI tools. The signatories believe that AI models can expedite and reduce costs for key cybersecurity tasks, and sharing tools, practical knowledge, and tested fixes can leverage one organization's results to bolster others' defenses.
- Mobilize a collective response. The rise of AI's cyber capabilities necessitates global coordination, new partnerships, and joint advances in security standards.
Four Target Groups
The authors identify four groups whose actions will be crucial moving forward.
Organizations are encouraged to prioritize cybersecurity within leadership, expedite the remediation of critical vulnerabilities, and ensure that fixes do not disrupt essential services.
Companies should tighten requirements for systems they acquire, develop, and implement, including AI-generated code. Basic measures suggested include the principle of least privilege, strict access controls, and multi-layered security. For routine tasks, signatories recommend using more accessible AI models, while deploying the most powerful systems for complex challenges.
Cybersecurity solution providers and technology partners are urged to continuously test defenses against advanced cyber capabilities, integrate AI into existing tools, and assist critical infrastructure operators with their deployment.
They are also expected to share threat data and proven response scenarios, collaborate with equipment manufacturers and systems integrators in critical infrastructure supply chains on fixes and temporary recommendations. Effectiveness should be assessed based on the number of protected organizations, the speed of attack containment, and the efficacy of fixes.
Governments must coordinate cybersecurity efforts at local, national, and international levels, enhance the sharing of actionable threat information, and fund the protection of vital services lacking personnel or resources.
Access to protective AI, authorized testing, and hands-on support from specialists should be provided to hospitals, water utilities, local authorities, and other critical infrastructure operators. Additionally, governments should implement measures that increase the costs for malicious actors.
Developers of advanced AI models must ensure responsible access, allocate funding, conduct training, and offer practical support to under-resourced teams managing critical infrastructure.
The signatories also stress the need to develop monitoring and security tools, enabling tracking of AI agents and establishing accountability for their actions.
It is worth noting that on August 27, OpenAI released an analysis of a July incident involving Hugging Face. During testing, AI agents bypassed restrictions in a controlled environment, accessed the internet, compromised parts of the infrastructure of two companies, and used an unauthorized channel to coordinate their actions.
Previously, Anthropic reported three instances where Claude models exceeded the testing environment and accessed real organizational systems. An investigation was initiated following OpenAI's publication.
