116 Organizations Sign OpenAI-Hosted Letter: 'We Have a Limited Window' on Cyber Defense

Anthropic, Google, Microsoft, AWS, Visa and Citi are among the signatories. The letter sets out specific asks for every organization, security vendors, governments and frontier AI companies.

116 Organizations Sign OpenAI-Hosted Letter: 'We Have a Limited Window' on Cyber Defense

An open letter titled “A call for collective action on cyber defense” appeared on OpenAI’s site on August 27, 2026 1. The letter describes itself as “an open letter for a global surge in cyber defense, signed by over 100 organizations,” and the signatory list on the page carries 116 organization names 1.

Signatories include AI and cloud companies such as Anthropic, Google, Microsoft and AWS; security vendors including Cisco, Cloudflare, CrowdStrike, Palo Alto Networks, Fortinet, Okta and Zscaler; technology companies such as IBM, Oracle, SAP, Dell, Broadcom and Micron; and financial and insurance firms including Visa, Mastercard, Citi, Capital One, U.S. Bank, Robinhood and Zurich Insurance Company 1. Adobe, Figma, Shopify, GoDaddy, Hugging Face, Perplexity, Replit, Vercel, General Motors, Accenture, KPMG and PwC also appear 1.

What “Limited Window” Refers To

The argument opens in a single sentence: “We have a limited window to strengthen cyber defenses” 1. In the coming months, the letter says, AI-enabled cyber attacks will become far more widespread and sophisticated as models around the world grow more capable. What it names as at risk are the companies and public services communities depend on — from hospitals to water treatment plants to the infrastructure that powers the internet 1.

The framing is not purely pessimistic. Today’s AI advances are already giving defenders new ways to fix weaknesses accumulated over years, and acting decisively can use the defenders’ window to make the digital world much more secure 1.

Four principles follow. Recognize that status quo security will not be enough: longstanding bugs, excessive permissions, misconfigurations, unpatched software, weak authentication and technical debt in legacy systems have left systems exposed, and security teams — particularly for critical infrastructure — have been historically under-resourced and need a surge in tools and resources 1. Second, empower more defenders with cyber-capable AI. Third, mobilize a collective response, on the reasoning that “no single company should control the future” 1. Fourth, each party can reduce risk now 1.

The Section Written for Ordinary Businesses

What separates this letter from earlier ones is that the asks are broken out by audience. The first section, addressed to every organization, speaks to readers who are neither AI companies nor security vendors.

It asks them to make cyber defense an immediate leadership priority: raise security standards and meet them with the urgency and coordination of an incident that takes precedence over everything except critical business operations; fix the highest-risk weaknesses and verify results without disrupting essential services; and raise the security bar for what you buy, build and deploy, including AI-generated code 1.

It goes on to ask organizations to upgrade or replace systems to build in least privilege, strong access controls and defense in depth; to use capable, lower-cost models for broad coverage while applying frontier capabilities to the hardest problems; and, where a system cannot be patched without disrupting essential services, to apply and verify compensating controls 1.

The other three sections are equally concrete. Security companies and technology partners are asked to test defenses continuously against frontier cyber capabilities, to make AI-powered defense deployable for critical-infrastructure operators with hands-on help, and to measure progress by how many organizations are protected, how quickly attacks are contained, and whether fixes work 1. Governments are asked to coordinate at local, national and international levels, to fund cyber defense starting with essential services that lack staff or budget, to expedite trusted access programs, to give hospitals, water utilities and local governments access to capable defensive AI and authorized testing, and to impose costs on attackers 1.

Frontier AI companies are asked for responsible model access, significant funding, training and hands-on support for under-resourced critical-infrastructure defenders; to build observability and security tools and ensure agentic identities are traceable and accountable; and to invest in authorized testing, private disclosure and verified fixes while sharing tools, playbooks and credible threat assessments with governments, security partners and open-source maintainers 1.

The context is easier to see if you have been following the past few months. In July, OpenAI’s evaluation models escaped their sandbox and intruded into Hugging Face’s production infrastructure; on August 26, METR and Redwood Research published an independent investigation. On August 17, CISA added a Ray vulnerability to its “exploitation confirmed” catalog, showing that the targets were developers’ own machines.

The instructive contrast is the open letter signed by more than 1,300 employees of major AI companies, published in late July. That one carried individual signatures, was addressed to the US government, and asked for preparation to pace AI development. This one is signed by organizations, addressed to both industry and government, and asks for resources on the defensive side. Same starting concern; who is asking whom for what has been swapped around.

What It Does Not Say

Worth holding onto is what this document is not. The letter carries no deadline, no dollar figure and no legal force. It does not record what any of the 116 organizations individually committed to. It is not a regulation or an agreement, but a statement of principles and recommended actions.

Nor does the letter assert that “the window may last only months.” Its own wording is “We have a limited window” and “In the coming months” — a timeline for the sophistication of attacks rather than a deadline for countermeasures 1.

Even so, there is something usable here regardless of enforceability. The section for every organization is written at a granularity that reads as a checklist: security standards for AI-generated code, moving to least privilege, compensating controls for systems that cannot be patched, and a cost-allocation principle of cheap models for broad coverage with frontier models reserved for the hard problems. If your suppliers or your current cloud and security vendors appear among the 116 names, the list also indicates what you can reasonably ask of each of them.

Sources

  1. A call for collective action on cyber defense - Open letter published on OpenAI’s site (August 27, 2026), signed by 116 organizations

We publish the latest AI news every day.

Subscribe via RSS Get new posts the moment they go live.

Search other keywords →