OpenAI published an open letter titled “A call for collective action on cyber defense,” arguing that organizations have a limited window to harden systems before AI-enabled attacks become far more widespread. The letter says hospitals, water treatment plants, and the infrastructure that powers the internet are already in the blast radius.

Signatories span frontier labs, cloud providers, banks, and security vendors. The published list includes Anthropic, Google, Microsoft, Amazon Web Services, Hugging Face, CrowdStrike, Palo Alto Networks, Cisco, IBM, and more than 100 other organizations.

What the letter asks for

The text is blunt about the current security baseline. It says longstanding bugs, excessive permissions, unpatched software, weak authentication, and technical debt have left systems exposed, and that security teams for critical infrastructure have been under-resourced.

The proposed response has four audiences. Every organization is told to make cyber defense a leadership priority, fix the highest-risk weaknesses, and use cheaper models for broad coverage while reserving frontier systems for the hardest problems. Cybersecurity companies are asked to test defenses against frontier capabilities, make AI-powered tools usable for operators with thin budgets, and share playbooks. Governments are asked to fund defense for essential services, expand trusted access programs, and impose costs on attackers. Frontier AI companies are told to provide responsible model access, funding, training, and hands-on support, plus observability so agentic identities can be traced.

The letter frames the next few months as a defenders’ window: act now, and AI can close weaknesses that have piled up for years. Delay, and the same capabilities land first with attackers.

Decoded Take

This is less a product launch than a bid to set the political weather around AI security. By lining up Anthropic, Google, Microsoft, and a long list of banks and vendors on one page, OpenAI is trying to turn a lab-level containment problem into a shared industrial obligation. The missing piece is enforcement. The letter asks governments to fund hospitals and water utilities and to expand trusted access, but it does not bind signatories to ship specific defensive tools on a deadline. Watch whether Daybreak-style access programs, government credits, and named critical-infrastructure deployments follow, or whether the coalition stays a signature list while attackers keep automating the cheap work of scanning, phishing, and exploit chaining.