Technology

OpenAI, Google, Anthropic Among 100+ Firms Signing Open Letter for Collective Cyber Defense

Martin HollowayPublished 3w ago4 min readBased on 3 sources
Reading level
OpenAI, Google, Anthropic Among 100+ Firms Signing Open Letter for Collective Cyber Defense
source:openai.com

OpenAI, Google, Anthropic, and more than 100 other companies have signed an open letter titled "A call for collective action on cyber defense," published August 27, 2026, at openai.com/collective-cyberdefense. The letter describes itself as a call for "a global surge in cyber defense" and warns that "In the coming months, AI-enabled cyber attacks will become far more widespread and sophisticated as models around the world become increasingly capable." TechCrunch reported the total signatory count exceeds 100 companies.

The signatory list spans the AI labs themselves, major cloud providers, and the cybersecurity establishment. Named signatories include Anthropic, AWS, Cisco, Cloudflare, CrowdStrike, Google, Hugging Face, IBM, Microsoft, OpenAI, Oracle, Perplexity, and HackerOne, among others. Engadget confirmed the core signatories, with additional names verified against the original source.

The letter articulates three core principles its signatories want followed: "Recognize that status quo security won't be enough," "Empower more defenders with cyber-capable AI," and "Mobilize a collective response." It then prescribes specific actions categorized for organizations, governments, the cybersecurity and tech industry, and AI businesses, all aimed at cutting off a potential explosion in attacks powered by artificial intelligence.

For organizations, the letter suggests making cybersecurity a high priority. For frontier AI companies specifically, the proposed actions include building observability and security tools, ensuring agentic identities are traceable and accountable, and sharing best practices in continuous monitoring. The letter also references strengthening open-source maintainers as part of the broader cyber defense effort. The proposal further calls for forming "new partnerships" to "raise security standards" as part of the collective response.

The breadth of the signatory list is itself a signal. Having AWS, Cisco, Cloudflare, and CrowdStrike alongside OpenAI, Anthropic, and Google on the same document means the infrastructure layer and the model layer are publicly aligning on a shared threat model. The inclusion of HackerOne brings the offensive-security community into the tent, and Hugging Face's participation ensures the open-source ML ecosystem is represented.

The specific prescriptions directed at frontier AI companies are the most technically substantive portion of the letter. The call for ensuring agentic identities are traceable and accountable speaks directly to the emerging architecture of autonomous AI agents, those that take actions on behalf of users across systems. If agents are to operate with elevated privileges in production environments, attributing their actions, auditing their decisions, and holding them accountable becomes a security primitive, not a feature. This is adjacent to the zero-trust access-control questions enterprises have been working through for human and service accounts, now extended to non-human, probabilistic actors.

The demand for observability and security tools, plus shared best practices in continuous monitoring, aligns with how the DevSecOps and cloud-native communities already operate. Applying those disciplines to model deployment and agent runtime environments is a logical extension. The reference to open-source maintainers acknowledges a real structural vulnerability: critical infrastructure dependencies often rely on under-resourced open-source projects, and AI-powered vulnerability discovery could accelerate exploitation of that surface area.

What the letter does not do is equally notable. It is a call to action, not a binding framework or a standards specification. The principles are directional rather than prescriptive. There is no enforcement mechanism, no certification body, and no technical specification for how agentic identity tracing should be implemented.

Worth flagging: the letter's framing of the threat timeline matters. By warning that AI-enabled attacks will become more widespread "in the coming months," the signatories are treating this as an imminent operational concern rather than a distant hypothetical. That compressed timeline is what gives the letter its urgency, and it is presumably what motivated over 100 companies to put their names on a public document.

The optimistic read here, and the one the letter's structure implicitly encourages, is that the same technology enabling attacks can empower defenders. The principle of empowering defenders with "cyber-capable AI" is an acknowledgment that AI-driven threat detection, automated response, and vulnerability research are the tools that will be needed. If the industry follows through on the information-sharing and partnership commitments, the defensive advantage of collective intelligence could outweigh the offensive advantage of individual capability. That outcome is not guaranteed, but the alignment on display in this letter is a necessary precondition for it.