Nearly 130 firms unite in OpenAI-led cyber defense pledge

Almost 130 tech, security and finance firms, including Microsoft, Google and Cisco, signed an OpenAI-led letter urging a coordinated global surge in cyber defenses as AI advances expand attack risks.
Nearly 130 technology, cybersecurity and finance organizations, including Microsoft, Google, Cisco, Anthropic, Cloudflare, CrowdStrike, IBM, Oracle, Check Point and OpenAI, signed an open letter calling for a global, coordinated increase in cyber defenses as advances in artificial intelligence make attacks more widespread and more capable.
The letter warns that AI-enabled attacks will become significantly more effective in the coming months and cites rising risks to hospitals, water treatment plants and internet infrastructure. It also notes that AI can give defenders new tools to find and fix security weaknesses, but says rapid, coordinated action is needed to protect essential services.
Three principles form the backbone of the letter. First, longstanding bugs, misconfigurations, weak authentication and other technical debt mean current security practices will not be enough. Second, AI can extend specialist security skills to more defenders and make shared, verified fixes more broadly useful. Third, cyber defense must be coordinated across countries and sectors as offensive cyber capabilities spread.
The signees ask every organization to make cyber defense an immediate leadership priority, fix highest-risk weaknesses first, raise security standards for what they build and buy, and apply compensating controls where patching would disrupt essential services. Cybersecurity firms and technology partners are urged to test defenses continuously against advanced AI capabilities, make AI-powered protection available to resource-constrained critical infrastructure operators, and share threat intelligence and verified playbooks.
Governments are asked to coordinate cyber defense at local, national and international levels, fund essential services that lack staff or budgets to respond, provide critical infrastructure operators access to defensive AI tools and authorized testing support, and adopt policies that increase the cost to attackers.
Frontier AI companies are asked to provide responsible model access, funding and hands-on assistance to under-resourced defenders, build tools that make AI system behavior monitorable and traceable, and share threat assessments with governments and maintainers of widely used open source software.
OpenAI, which led the effort, outlined three commitments: subsidized access to its Daybreak Cyber models for public-sector organizations, nonprofits, open source maintainers and critical infrastructure operators; a program letting companies work with authorized partners to test defenses using its models and privately report weaknesses; and ongoing publication of security tools and findings to help organizations find, prioritize and verify fixes.
Signatories include large cloud and enterprise vendors as well as cybersecurity specialists and financial firms, reflecting a cross-industry appeal for shared, verified defenses and broader access to defensive AI as attackers adopt more advanced AI techniques.








