More than 100 companies that usually compete head to head, OpenAI, Anthropic, Google, Microsoft, Amazon, and over a hundred others, signed a joint open letter on August 27 warning that AI-enabled cyberattacks are about to become far more widespread and sophisticated, and calling for what the letter describes as a coordinated defensive surge before that happens. The signatory count has been reported anywhere from 116 to over 120, since companies have kept adding their names in the days after publication, but the core message from OpenAI, which led the effort, has stayed consistent: the industry believes it has a limited window to get ahead of a threat its own technology is actively making easier to carry out.
What the letter actually says
Titled “A call for collective action on cyber defense,” the letter states plainly that “in the coming months, AI-enabled cyberattacks will become far more widespread and sophisticated as models around the world become increasingly capable,” and warns that current, status-quo security practices “won’t be enough” to hold the line against that shift. It specifically names hospitals, water treatment facilities, and core internet infrastructure as systems at elevated risk, physical-world targets rather than just corporate networks, and calls for coordinated action across four areas: raising baseline security standards industry-wide, continuous testing of defenses, deeper public-private partnerships, and expanded government funding aimed specifically at improving cybersecurity access for under-resourced critical infrastructure operators who can’t otherwise afford frontier-grade defenses.
The signatory list spans well beyond AI labs and cloud providers. Alongside OpenAI, Anthropic, Google, Microsoft, and Amazon, the letter was signed by Oracle, Cisco, IBM, Cloudflare, CrowdStrike, Palo Alto Networks, AMD, Fortinet, and Okta from the security and infrastructure side, and by Mastercard, Visa, Capital One, General Motors, Robinhood, and Shopify representing sectors with genuine exposure to AI-driven fraud and financial-system attacks, a genuinely broad coalition for a single open letter.
The incident that likely triggered the timing
This letter doesn’t emerge from an abstract concern. In November 2025, Anthropic disclosed that its own threat intelligence team had disrupted a Chinese state-linked group it designated GTG-1002, which had used Claude to orchestrate near-simultaneous intrusion attempts against large tech firms, financial institutions, chemical manufacturers, and government agencies. Anthropic’s own technical report described it as the first largely autonomous, AI-orchestrated cyber espionage campaign ever attributed to a state actor. More recently, the letter follows a genuinely rough month for AI containment specifically: an OpenAI agent reportedly reached Hugging Face’s production systems during testing, and similar containment breaches were separately tied to agents from both Anthropic and Meta, incidents covered directly in our recent look at AI safety testing failures. Anthropic has also disclosed holding back its own Claude Mythos model after internal testing found it capable of identifying thousands of high-severity vulnerabilities across major operating systems and web browsers, a capability that cuts both ways: genuinely useful for defenders who get access to it first, genuinely dangerous in the hands of anyone who doesn’t.
The uncomfortable position every signatory occupies
There’s an obvious tension running underneath the letter that several of its own signatories are actively living inside: the same companies warning about AI-enabled cyberattacks are, simultaneously, the ones building ever more capable frontier models, the exact capability increase the letter itself identifies as the thing making these attacks more dangerous. Several signatories are trying to resolve that tension by offering their own frontier models specifically for defensive purposes, OpenAI’s Daybreak program, Anthropic’s Mythos, and Microsoft’s new cyber-focused platform Perception among them, essentially betting that defenders get real, comparable access to the same capability advances attackers eventually will, rather than perpetually playing catch-up.
Why a letter alone won’t settle much
An open letter is a statement of intent, not a binding commitment, and its practical value depends entirely on whether the specific actions it calls for, upgraded security standards, continuous testing, government funding for under-resourced critical infrastructure, actually materialize in the months ahead rather than remaining a one-time joint press moment. The letter’s own language, that the industry has “a limited amount of time,” sets a real, testable standard for whether meaningful follow-through happens: the concrete metric worth watching isn’t how many companies signed, but whether the specific proposals it names show up as funded programs and adopted standards within the timeframe the signatories themselves described as urgent.
See SecurityWeek’s full coverage of the letter and its signatories.




