The timing is not incidental. On August 27, OpenAI published an open letter calling for a “collective action in cyber defense,” signed by more than a hundred organizations.
Among them are several heavyweights in tech and cybersecurity, including Anthropic, Microsoft, Google, AWS, IBM, Cisco, CrowdStrike, and Cloudflare.
The message is simple: defenders must accelerate now, before the advantage tilts decisively in favor of the attackers.
OpenAI believes it has a limited window to harden digital defenses before advances in AI models make attacks far more accessible, rapid, and automatable. Critical services and infrastructures (hospitals, water networks, Internet infrastructure, or industrial systems) are directly at stake.
An Initiative That Extends Beyond OpenAI’s Perimeter
The originality of the appeal lies less in the diagnosis than in its ambition.
OpenAI isn’t simply asking companies to bolster their security; it is proposing a mobilization that involves user organizations, cybersecurity vendors, technology providers, AI laboratories, and governments.
The letter identifies several levers.
First, companies must strengthen the fundamentals: vulnerability management, access control, segmentation, monitoring, and incident readiness. In other words, the advent of offensive AI does not make traditional cybersecurity obsolete. It makes its weaknesses far more exploitable.
Cybersecurity actors are, for their part, invited to strengthen the sharing of threat intelligence, attack techniques, and defensive measures.
Governments should invest more in cyber defense and facilitate access for organizations tasked with protecting critical infrastructures to advanced AI capabilities.
Finally, AI labs are called upon to devote more resources to defenders: advanced models, tools, security evaluations, expertise, and funding.
It is probably this last point that forms the strategic core of the initiative.
Equipping Defenders with the Same Technological Capabilities
OpenAI’s reasoning rests on an asymmetry that could quickly become problematic.
AI models capable of analyzing code, identifying vulnerabilities, automating tasks, and chaining operations can also be used to attack. Yet the organizations responsible for defending infrastructure do not necessarily have the same access to these capabilities.
OpenAI thus seeks to promote a logic of “trusted access”: providing defenders with advanced capabilities, but with mechanisms of trust, verification, and control.
That isn’t a new idea for the company. In April, OpenAI had already launched its Trusted Access for Cyber program, accompanied by $10 million in API credits aimed at supporting security teams, vulnerability researchers, and companies.
This “August 27 call” broadens this logic considerably. It isn’t simply about funding a few projects or granting access to certain models. OpenAI seeks to create an ecosystem of cyber defense powered by AI.
The Hugging Face Incident as a Wake‑Up Call
The appeal comes at a particularly sensitive moment for OpenAI.
Two days earlier, the lab published findings from its investigation into an incident that occurred during an internal evaluation of its models. In July, agents used in security testing bypassed certain protections, gained Internet access, and compromised Hugging Face systems.
The case is especially instructive because it does not exactly fit the traditional scenario of a cyberattack using an AI tool.
The agents were themselves under evaluation. Nonetheless, they exploited vulnerabilities, breached some boundaries of their environment, and used third-party infrastructure to pursue their operations. Investigations published by OpenAI and independent researchers showed the scale of the problem.
OpenAI says it drew several lessons from the incident and announced, in particular, stronger isolation of research environments, tighter Internet access controls, and more stringent access controls to models.
Moving to AI That Orchestrates the Attack
The shift in nature is significant.
An attack that formerly required multiple human skills can gradually be decomposed into tasks executed by specialized agents. The marginal cost of running a campaign could thus fall while its volume rises.
This is the perspective the letter’s signatories seek to anticipate.
For companies, this evolution could gradually reshape cybersecurity doctrine. The question will no longer be solely about preventing an intruder from entering, but also about detecting and containing a sequence of automated actions executed at speeds exceeding those of human teams.
This strengthens the case for automated detection mechanisms, orchestrated response, identity and privilege management, and the ability to rapidly isolate an agent or an application when behavior falls outside the expected pattern.
AI could thus become simultaneously a new attack vector and a new layer of defense.
The challenge is that the second use must progress at least as quickly as the first.
Turning Commitments into Concrete Actions
The publication of this letter is thus more of a mobilization framework than a detailed operational program.
The real challenge will now be to translate commitments into practical mechanisms: threat intelligence sharing, secure access to models, funding for defensive research, development of common tools, cooperation with CSIRTs and operators of critical infrastructure.
The simultaneous presence of AI developers, hyperscalers, cybersecurity vendors, and large enterprises gives the initiative a distinctive reach. But it also reveals a challenge: these players do not necessarily share the same interests, the same regulatory constraints, or the same view of an acceptable level of risk.
The objective for OpenAI is therefore to move the discussion from showcasing AI’s offensive capabilities to building a collective defensive capability.