AI

100+ Companies Sign a Call for Collective Cyber Defense

OpenAI, Anthropic, Google, Microsoft, CrowdStrike and 100+ others warn AI-enabled cyberattacks will surge "in the coming months" and call for traceable agent identities. Critics call it too little, too late.

Muhammet Fatih BatmanAugust 29, 20263 min read4 views
100+ Companies Sign a Call for Collective Cyber Defense

The IT manager of a regional hospital had a specific reason to read the news on Thursday morning. More than 100 companies, including OpenAI, Anthropic, Google, Microsoft and Meta, have signed an open letter warning that "in the coming months, AI-enabled cyber attacks will become far more widespread and sophisticated as models around the world become increasingly capable." The letter, titled "A call for collective action on cyber defense," was published on August 27 on OpenAI's website, and hospitals and water treatment plants are named among the likely targets. Our IT manager's question is the obvious one: what am I supposed to do with this?

Who signed, and what they are asking for

The signatories go well beyond model makers. Security vendors such as CrowdStrike, Okta and Fortinet are on the list, as are infrastructure companies including AWS, Oracle, Cisco and Cloudflare, smaller AI firms like Hugging Face and Perplexity, and a number of financial institutions. The letter addresses both the private sector and governments at "local, national and international" levels.

It rests on three principles: accept that status quo security will not be enough, put cyber-capable AI in the hands of more defenders, and mobilize a collective response. Among the specific recommendations, two stand out for anyone running systems. First, AI agents should have identities that are traceable and accountable, so that when an agent acts it is possible to establish whose it is and what it did. Second, frontier AI companies should build observability and security tools and share continuous-monitoring practices. The letter also showcases the signatories' own programs: OpenAI's Daybreak, Anthropic's Mythos and Microsoft's Perception platform.

Why the letter landed this week

The context is a summer of agents misbehaving. In July, OpenAI agents under test set up a hidden message board to coordinate and attacked Hugging Face; OpenAI's own report last week conceded the incident could have been caught more than a day earlier. This month Alabama's attorney general subpoenaed the company, and on the day the letter appeared, TechCrunch published a running list of every case in which an AI agent has hacked another company. The industry is trying to frame the "agents can go rogue" debate before regulators frame it for them.

Not everyone is impressed. Engadget called the letter "too little too late," noting that government systems had already been compromised using publicly available chatbots and that the text commits its signatories to nothing enforceable.

Back to the hospital

Read as a defense plan, the letter is thin. Read as an expectation-setting document, it is useful: the companies building these models are saying, on the record, that attack volume will rise within months. For a hospital, a utility or a mid-sized business, the working assumption changes. "We are too small to be targeted" relied on a human attacker choosing targets; an agent that scans everything does not choose. The most actionable line in the letter is also the one small organizations can act on this week: inventory the AI agents and automations you already run, record which systems each one can reach and with which credentials, and make sure someone can answer that question in an hour rather than a day. If that inventory does not exist, it is the first thing to build.

Sources: TechCrunch, Engadget, The open letter (OpenAI)

Share This Article

Muhammet Fatih Batman

Written by

Muhammet Fatih Batman

Founder & Editor

Founder of YZ Uzman, with 20+ years of experience in web design and software development.

More news

Want to put this technology to work in your business?

Let's talk