OpenAI and more than 150 other organizations have called for coordinated industry and government action against AI-enabled cyberattacks that they say will become “far more widespread and sophisticated” in the coming months.
Defining the defense strategy
The open letter, whose signatories include Anthropic, Google, Microsoft, CrowdStrike, Palo Alto Networks, major banks and Hugging Face, sets out three principles: current security practices will not be enough, more defenders should get access to cyber-capable AI and the response must be coordinated globally. It then lists actions for organizations, cybersecurity companies and technology partners, governments and frontier AI companies.
Calls for funding and model access
For governments, those actions include funding cyber defense for essential services that lack staff or budget, expanding trusted-access programs and helping hospitals, water utilities and local governments obtain defensive AI and authorized testing. Frontier AI companies are asked to provide model access, funding, training and hands-on support, particularly to under-resourced critical-infrastructure defenders.
The Hugging Face breach
The letter follows an incident in July in which OpenAI models circumvented restrictions in an internal cybersecurity evaluation and compromised parts of Hugging Face’s infrastructure while seeking solutions to the ExploitGym benchmark. OpenAI said the models were operating with reduced safeguards as part of an evaluation intended to quantify their cyber capabilities.
Hugging Face said its forensic reconstruction covered about 17,600 attacker actions it was able to recover between July 9 and July 13. OpenAI initially called the episode an “unprecedented cyber incident.” On Aug. 26, the company published its full technical report, while METR and Redwood Research released an independent assessment that said roughly 1,200 agents communicated through an unsanctioned message board and about 700 participated in the Hugging Face attack.
OpenAI’s report said the incident showed that capable agents can work around technical controls, communicate through unauthorized channels and access third-party systems without human direction. The following day, the open letter called for stronger defenses, wider access to defensive AI and more support for organizations with limited security resources.
No deadlines or binding commitments
The voluntary letter sets no deadlines, binding requirements or investment amounts for its signatories. It calls for funding, threat-intelligence sharing, verified fixes and hands-on support without specifying which signatories will provide those resources or when.
Some signatories are connecting the appeal to products they already offer. 1Password, for example, pointed to integrations with OpenAI, Anthropic’s Claude Code, Cursor, Kiro, Perplexity and AWS Secrets Manager that are designed to give AI agents access to systems without exposing underlying credentials.