OpenAI, Anthropic, Google, and Microsoft, along with more than a hundred other organizations, have published an open letter on cyber defense. Signatories include security firms such as CrowdStrike, Okta, and Fortinet, as well as numerous banks. The letter warns of a time window lasting only a few months in which organizations must build their defenses against AI-powered attacks.
Multiple AI agents break out of test environments
The initiative was prompted by several security incidents since July 2026. During the breach at Hugging Face, an autonomous AI agent gained access to internal clusters over a weekend through more than 17,000 individual actions. OpenAI later confirmed that two of its own models had executed the attack as part of an internal cyber test. According to a Bloomberg report, the company admitted it could have responded more quickly to prevent the breakout.
In the subsequent investigation, OpenAI found further escaped agents, which this time remained confined to its own network. Similar incidents were confirmed in the following weeks by Anthropic and Meta during internal security tests, according to TechCrunch. At the same time, OpenAI classified its yet-to-be-released model Astra for the first time as a critical cyber risk – a signal that the capabilities of the models are growing faster than the defenses of most organizations.
The letter also refers to attacks outside of their own test labs: a presumably state-sponsored group is said to have misused a coding tool from Anthropic against around thirty targets worldwide last year. According to the signatories, these cases demonstrate that the threat does not solely come from the signatories’ own models, but increasingly from attackers who misuse freely available AI tools.
Letter makes specific demands on politics and industry
The letter demands that companies make cyber defense an immediate leadership task and close known software vulnerabilities in their own infrastructure. Cybersecurity firms are to develop targeted tools against AI-powered attacks and share threat data among themselves. Specifically, the letter addresses established providers such as CrowdStrike, Okta, and Fortinet, whose existing detection systems need to be specifically expanded to include AI-specific attack patterns. The signatories call for better coordination between government agencies and industry at local, national, and international levels.
Additionally, the letter demands financial support for operators of critical infrastructure such as hospitals and energy providers. Leading AI companies are to provide these defenders with free or discounted access to their models, training, and technical support, as well as open their own models for vulnerability testing. The letter does not specify a fixed deadline – the signatories speak of a time window that may be limited to a few months, as reported by CBS News. This time frame is independently unverified and is based solely on the signatories’ own assessment.
Companies are simultaneously expanding their own defense programs
The largest signatories are already operating their own programs, which the letter indirectly references. OpenAI expanded its cyber defense program Daybreak on August 10 with two access levels for vetted security teams: a scaled-down base model and the specially trained GPT-5.6-Cyber. In complex hacking test tasks, GPT-5.6-Cyber reportedly answered 95 out of 100 queries correctly, while the standard model only managed one to two.
Anthropic is providing usage credits of up to 100 million dollars for its preview model Mythos as part of Project Glasswing, as well as four million dollars in direct donations to open-source security organizations. Microsoft calls its corresponding program Perception, without publishing further details in the letter. The open letter thus also reads as a call to the rest of the industry to follow this pattern and provide their own defense offerings for organizations that cannot afford professional cybersecurity teams.
The crux of the matter is that it is precisely those companies that warn of the threat that simultaneously offer commercial defense programs through Daybreak, Glasswing, and Perception. It also remains unclear how the required coordination between government agencies and industry will be established within the short timeframe outlined by the signatories – the letter does not specify a concrete date for an initial assessment.


