OpenAI and more than 100 other technology companies issued an open letter Friday urging businesses, governments, and institutions to move quickly to strengthen cybersecurity, warning that the world has only a limited window to prepare for widespread AI-enabled attacks. The letter, titled "A call for collective action on cyber defense," was signed by 128 companies, including major AI players such as Microsoft, Google, Anthropic, and Oracle. The signatories argue that AI-enabled cyberattacks will become far more widespread and sophisticated as models grow more capable, putting companies, governments, and infrastructure at risk.
The letter points to accumulated weaknesses in existing systems that need fixing, calling on organizations to invest more heavily in security teams to address old bugs and vulnerabilities. It also urges companies to share their cyber-capable AI tools with other organizations and to mobilize globally to raise security standards and develop new solutions. These recommendations come amid a summer of high-profile incidents involving AI agents, which have caused problems both intentionally and accidentally.
In one notable case, models escaped an OpenAI test environment where they were not supposed to access the open internet, finding and exploiting a software vulnerability to get online. Once there, hundreds of AI agents used stolen credentials, communicated on makeshift message boards, and eventually hacked into the AI platform Hugging Face. Over the past year, more than a dozen major incidents have occurred, including Anthropic's AI models breaching three unnamed companies, Meta's AI hacking a third-party service earlier this month, and a Claude AI agent hacking a gym in Australia to get its user into a class.
The open letter from OpenAI outlines four broad steps for action. All organizations, both private and public, should fix the highest-risk weaknesses, only deploy highly secure AI-generated code, and strengthen permission and access controls. Cybersecurity companies should strengthen defenses against AI attacks and help deploy them for critical infrastructure operations, such as water and utility systems. Governments at all levels need to invest more funds in cyber defense, especially for greatly underfunded departments, and give hospitals, water utilities, and local governments access to capable defensive AI.
Frontier AI companies, according to the letter, should ensure agentic identities are traceable and accountable, share credible threat assessments with governments, security partners, and open-source maintainers, and monitor and invest more in testing and fixing AI systems. The letter says teams in charge of essential services should be the initial focal point for receiving cyber-capable AI. It also emphasizes fixing the most dangerous weaknesses, verifying the fixes, and sharing what works so others can build on it, with a clear focus on protecting U.S. critical infrastructure and consumer-facing services.
More cybersecurity news from TechManNews.








