OpenAI, Anthropic, Google, Microsoft, AWS and Oracle are among more than 100 organisations backing an open letter warning that a limited window remains to strengthen cyber defences before AI-enabled attacks become widespread.
More than 100 companies and organisations have signed an open letter calling for urgent, coordinated action to defend critical digital infrastructure against a new generation of AI-powered cyber threats. Published on 27 August 2026, the letter — titled “A Call for Collective Action on Cyber Defence” — was initiated by OpenAI and carries the backing of some of the most powerful names in global technology, including Anthropic, Amazon Web Services, Google, Microsoft, Oracle, Cloudflare, Cisco, CrowdStrike, Palo Alto Networks, IBM, Hugging Face, Check Point, Zscaler, Visa and Mastercard.
The warning is blunt. Defenders, the letter argues, have a limited window to act before AI tools give attackers a decisive and durable advantage.
OpenAI posted on X on 27 August 2026 that “we have a limited window to strengthen cyber defenses” and called for a global effort to give defenders “the tools, resources and support” to protect shared infrastructure. The post framed the initiative as a “collective cyber defence” effort — a phrase that captures both the ambition and the urgency behind the letter.
What the Letter Actually Says
The open letter frames AI as a dual-use technology: the same capabilities that help attackers can also help defenders, but only if the right investments are made now. Specifically, it warns that AI is already automating tasks that previously required skilled human effort — things like vulnerability discovery, phishing message generation, malware development and social engineering. As AI models grow more capable, those offensive tasks become faster, cheaper and more accessible.
On top of that, the signatories call for four broad areas of action. They want technology firms and governments to develop and deploy AI-assisted tools for defenders, covering tasks such as code auditing, patch management and incident response. They want threat intelligence shared at what they describe as “machine speed” across borders and sectors. They want stronger international coordination between governments, regulators, industry and security researchers. And they want sustained investment in skills and training for security professionals.
OpenAI has separately outlined plans to fine-tune models specifically for defensive cybersecurity tasks — including a model referred to in company materials as GPT-5.4-Cyber — and to introduce tiered, authenticated access for vetted cybersecurity defenders, while committing to limit offensive cyber capabilities in its products.
Sam Altman’s Warning
Sam Altman, OpenAI’s chief executive, has been direct about the stakes. Altman said: “There is not much time to act” and that only an “urgent and intense collective response” will be sufficient for AI-era cyber defence. That language — urgent, intense, collective — runs through the entire initiative and reflects a view shared across the signatory list that voluntary, piecemeal responses won’t be enough.
The initiative connects to wider industry efforts already under way. Multi-company projects such as CoSAI and Project Glasswing are developing shared tools and open-source guidance to secure AI applications and critical software, and the open letter is designed to sit alongside rather than replace those efforts.
Who’s Backing It — and Who Has Doubts
The signatory list is striking in its breadth. It spans AI labs, cloud providers, enterprise software companies, specialist cybersecurity firms and major financial institutions. That kind of cross-sector alignment is unusual, and the figures suggest the letter has achieved genuine industry traction rather than serving as a narrow lobbying exercise by a handful of firms.
But not everyone is convinced that open letters and voluntary initiatives are the right tool. Some commentators and civil society groups argue that what’s needed is stronger regulation of frontier AI, with clearer and legally enforceable restrictions on offensive cyber capabilities. Others raise concerns about the concentration of power that could result from security solutions being designed and controlled by a small number of large US-based companies. If the defensive infrastructure of critical systems worldwide runs on tools built and governed by OpenAI, Microsoft, Google and AWS, questions of dependency, accountability and transparency become harder to ignore.
Cybersecurity professionals, for their part, broadly welcome additional tools and resources but point out that the practical details matter enormously — how defensive models are integrated into existing security operations centre workflows, how access controls are audited, and how organisations with limited budgets actually get access to these capabilities.
The BBC’s technology coverage confirmed that more than 100 firms are backing the letter, quoting its opening line directly: “We have a limited window to improve cyber defences.”
The Broader Policy Context
The initiative arrives at a moment when governments including the UK’s are actively reviewing their approach to frontier AI, cyber security and the protection of critical national infrastructure. The UK Government has been developing policy on both AI regulation and cyber resilience, and the open letter’s call for closer public-private collaboration aligns with that direction — though the letter stops well short of endorsing any specific regulatory framework.
At the same time, the framing of a “defender’s window” — the idea that proactive action now can meaningfully reduce systemic risk before offensive AI tools become widely accessible — is doing real work in the letter. It’s an argument for urgency without panic, and for investment before the problem becomes much harder to solve.
What This Means for Kent Residents
Kent’s public services — including NHS Kent and Medway Integrated Care Board-commissioned health systems, Kent County Council and Medway Council IT infrastructure, and local utilities and transport networks — are exactly the kind of critical infrastructure the open letter is designed to protect. If the initiative translates into stronger default security configurations and faster threat intelligence sharing across the cloud platforms these bodies rely on, local residents could see fewer service outages, data breaches and ransomware incidents of the kind that have disrupted NHS trusts and councils elsewhere in England. The UK’s National Cyber Security Centre, which provides guidance and incident response support to public bodies and businesses across Kent, is likely to be a key channel through which any improvements in AI-assisted defensive tooling reach local organisations.
Source: @OpenAI
OpenAI and Over 100 Tech Giants Call for Urgent Global Action on AI Cyber Threats Quiz
5 questions