Skip to main content

Rival AI companies signed one warning: AI cyberattacks get far more widespread within months

A giant cream letter tilted on a dark navy ground, carrying the OpenAI mark and the headline A Call for Collective Action on Cyber Defense over rows of abstract signature strokes and a chip reading 128 signatures. Beside it, large text reads Rivals signed, nothing binds, over the line AI labs, banks, insurers, GM. A cyan-edged tag says attacks scale in the coming months.Photograph: Composition by Morning Byte · OpenAI mark shown for identification
01

Rival AI labs, banks, and an automaker signed one warning with one clock: months.

02

The letter tells employers to treat security like a live incident, before normal work.

03

The fixes route through employers, governments, and the signers; nothing is binding.

A call for collective action on cyber defense, published by OpenAI, August 27 2026

Morning Byte · weekly digest

One email a week. The stories that mattered.

What changed

Companies that compete for the same AI customers rarely put their names on one page. On August 27, 2026, they did, because the ask is collective: OpenAI published an open letter carrying more than one hundred twenty signatures beside its own. The names run from Anthropic to Google, Microsoft, Citi, Visa, General Motors, Zurich Insurance. The published record of signatories shows banks, insurers, an automaker, payment networks, beside the security vendors. The warning itself is one sentence long: in the coming months, AI-enabled cyberattacks become far more widespread and sophisticated, according to the letter, as models everywhere grow more capable. The named risk surface is ordinary life: hospitals, water treatment plants, the infrastructure that powers the internet. The letter closes with four numbered calls to action, aimed at every organization, at security and technology vendors, at governments, and at frontier AI companies, meaning the labs that build the most capable models.

128

Organizations that signed one warning that AI-enabled cyberattacks get far more widespread within months. Signing binds none of them.

One page, one clock, no commitments.Source: openai.com/collective-cyberdefense, signatories as listed · Count derived from the rendered signatory list; the letter itself states no number.

OpenAI and its rivals published one letter, the letter tells employers to act like the incident already started, it asks governments to fund the defenders who cannot pay, and, if employers follow it, it lands on the reader's own workweek.

  1. One open letterpublished by OpenAI, signed by more than one hundred twenty organizations, rivals included
  2. tells
    Every employertold to treat cyber defense like a live incident that outranks the roadmap
    and asks
    Governmentsasked to fund defense for hospitals and utilities that cannot pay
  3. and asks funding and model access from
    Frontier AI companiesasked to hand defenders model access, funding, and hands-on support
  4. which is why it lands on
    Your workweekstronger logins, more patching, review rules on AI-written code, rising value on security skills

The lit path ends on the reader: the letter is addressed to leadership, and if your employer follows it, the changes arrive as your logins, your patches, and your code reviews.

The intelligence web: who the letter tasks, and where it lands.Source: openai.com/collective-cyberdefense, the four numbered calls to action · Every link between named parties is stated in the letter's four calls to action; the final band is the article's generalization to the reader, labeled as such in the payoff.
The Pioneer Building, a brick industrial building in San Francisco's Mission District, photographed from the street in 2019, when it housed the offices of OpenAI and Neuralink.
OpenAIPublisher and host of the open letter, and one of the frontier AI companies its fourth call tasks

Delivering what the letter asks of frontier AI companies: model access for vetted defenders, funding, training, and hands-on support. As publisher, OpenAI put its own name first in line.

Photograph: HaeB, via Wikimedia Commons, CC BY-SA 4.0
The Pioneer Building in San Francisco's Mission District, which housed OpenAI's offices when this photograph was taken.Source: openai.com/collective-cyberdefense (publisher and call 04); photograph and building occupancy per its Wikimedia Commons record · The photograph is an earlier editorial image of the building its Wikimedia Commons record describes as housing OpenAI's offices; it does not depict the letter's signing or OpenAI's current headquarters.

Why it matters

Read the fine print before the headline: nothing in the letter binds anyone, and signing cost nothing. Some of the loudest signers, the AI labs and the security vendors, also sell the remedies, so their asks route demand toward their own products. That tension is our read of the signature page, not a disclosure the letter makes. That suggests the letter's real work is coordination: it converts a private security worry into a dated, public claim that boards can be measured against. For a working reader, the letter is a preview of your next few months at work, and the moves are concrete. Expect security to jump the queue if your employer takes the letter at its word, since it asks leadership to treat defense like a live incident that outranks the roadmap. Turn on the strongest login your accounts offer, because weak authentication sits on the letter's own list of exposures. If you ship code with AI, expect review rules to tighten, since the letter names AI-generated code as something to hold to a higher bar. And treat the security push as a career signal, which is our read rather than the letter's. The letter says AI now brings specialist skills to more defenders, which lowers the cost of adding security skills to your resume.

What to watch

The letter is falsifiable in both directions, which is rare for an open letter. The letter asks for model access, meaning vetted defenders getting the labs' best tools, and for wider trusted-access programs, meaning cleared channels for critical-infrastructure teams. If those appear with names and funding in the coming weeks, the coordination will have produced something real. If the first proof is a publicized wave of AI-enabled attacks, the clock will have been real the hard way. Whether governments fund any of it is not yet known, and the letter offers no figures to hold them to. Watch three things: follow-through from the frontier AI companies the letter tasks, your own employer's security posture, and whether incident-level urgency shows up in real budgets rather than repeated statements. The signers put a countdown in public. What they attached to it, so far, is signatures.

Not signed in yet — hit Post and we'll finish it together

Rival AI companies signed one warning: AI cyberattacks get far more widespread within months | Morning Byte