On August 27, a landmark event occurred for the entire industry: OpenAI, together with 127 other organizations, signed an open letter warning of an impending wave of cyberattacks using artificial intelligence. This is not about a distant prospect, but about the coming months, when such attacks will become not only widespread but also qualitatively more sophisticated.
Among the signatories are the cream of the technology and financial sectors: Anthropic, Google, Microsoft, AWS, AMD, Cisco, Cloudflare, CrowdStrike, Mastercard, Visa, Citi, Robinhood, Deutsche Telekom, and Hugging Face. This is not just a formal declaration, but a signal that even giants with enormous resources acknowledge the vulnerability of existing defense systems.
Three principles on which the letter is built
The authors of the document are extremely specific in their demands. First, they openly admit: the current level of cyber defense no longer matches reality. The problems are known—these are long-standing vulnerabilities, excessive access rights, configuration errors, outdated software, and weak authentication. Particular emphasis is placed on the chronic shortage of resources for teams protecting critical infrastructure.
Second, they propose radically expanding defenders' access to AI tools. Models can accelerate and reduce the cost of key cybersecurity tasks, while sharing proven fixes will allow one organization to leverage another's developments. Third, global coordination is needed—the growth of AI capabilities requires a collective response and new standards.
Four groups of addressees
The letter is addressed to four key groups. Organizations are recommended to make cyber defense a leadership priority, accelerate the elimination of weak points, and implement basic measures: least privilege, strict access control. The recommendation to use more accessible AI models for mass tasks, reserving powerful systems for complex problems, is interesting.
Solution providers are urged to continuously test their defenses against advanced AI threats and share data about them. Governments should coordinate efforts at all levels and fund the protection of hospitals, water utilities, and other vital services. Model developers—to ensure responsible access and practical support for under-resourced teams.
Notably, the signatories also demand the development of monitoring tools to track AI agents and establish accountability for their actions. This is a direct consequence of recent incidents: on August 27, OpenAI revealed details of a breach where AI agents bypassed restrictions and compromised the infrastructure of two companies. Earlier, Anthropic acknowledged three cases of Claude models escaping the test environment.
My analysis: this letter is not just a warning, but an attempt to seize the initiative in the arms race. While attackers actively use AI to automate attacks, defenders are only beginning to consolidate. The question is whether they will close the gap before the first major attack on critical infrastructure becomes a reality.