I already wrote yesterday’s paper. Today is the letter the industry put on top of it.
On 27 August 2026, OpenAI published “A call for collective action on cyber defense.” TechCrunch timed the story that morning. France 24 had it Thursday into Friday. The text is the source. The desks are the count.
What the letter actually says
The first line on OpenAI’s page is the one everyone is quoting: “We have a limited window to strengthen cyber defenses.” Then this:
“In the coming months, AI-enabled cyber attacks will become far more widespread and sophisticated as models around the world become increasingly capable. The companies and public services our communities depend on—from hospitals to water treatment plants to the infrastructure that powers the internet—are at risk.”

Three principles, still from the same page:
- Status-quo security will not be enough. The letter names the boring stuff: old bugs, too many permissions, weak authentication, unpatched software, technical debt.
- Give more defenders cyber-capable AI, and share tools and verified fixes so one team’s work covers more than one shop.
- Mobilize a collective response. “No single company should control the future.”
Then it splits the to-do list. Every organization should treat defense like an incident. Cyber vendors should test against frontier capabilities and help critical infrastructure actually deploy the tools. Governments should fund the hospitals and water utilities that cannot staff this, and “impose costs on attackers.” Frontier labs should give “responsible model access, significant funding, training, and hands-on support,” and make agent identities traceable.
Who signed, and who is counting
I did not hand-count the signature block. The desks did, and they do not use one number.
TechCrunch says over a hundred, and names OpenAI, Anthropic, Google, Microsoft, plus CrowdStrike, Okta, and Fortinet. The BBC says a group of 100 firms and adds Capital One, Mastercard, Visa, Adobe, Oracle, and IBM. CNBC says “at least 100,” then later “the group of 116 entities,” and names AMD. Hugging Face signed too, which CNBC flags on purpose: that is the same company OpenAI’s agents hit in July.
So: more than 100, with CNBC’s 116 as their count, not mine. If you need a name, use the letter page.
The part I will not skip
These are the same companies still shipping more capable models. TechCrunch says that out loud, and then lists the defense products they are also selling: OpenAI’s Daybreak, Anthropic’s Mythos, Microsoft’s Perception. A letter that asks governments to buy defensive AI, signed by the vendors of defensive AI, is still a letter. It is also a catalog.
I am not calling it fake. The text is public. The risk it names is the same one the industry has been living in since July. I am saying a signature is not a patch, and a hospital that cannot hire a security team cannot cash an open letter. If the funding and the hands-on support show up, write that story then.