What the letter says, what came after it, and how to talk about it without turning it into a sales pitch
On August 27, OpenAI published an open letter on global cyber defense. More than a hundred companies across industries and disciplines signed it, including Anthropic, Microsoft, Google, Oracle, and CrowdStrike, along with Visa, Mastercard, Capital One, Citi, General Motors, Shopify, and many more, Galactic among them. Some of those companies spend the rest of the year trying to take business from each other, and they signed the same page anyway. Nothing brings people together like a shared existential problem.
The letter is direct about how systems get exposed, and the list won't surprise you: longstanding bugs, excessive permissions, misconfigurations, insecure and unpatched software, weak authentication, and technical debt in legacy systems.
You can probably hear your own words from hundreds of previous risk readouts echoing in your head, because I can hear mine. Find it, fix it, verify it, repeat. This is not new advice. What the letter highlights — and I hope this is the part that got your attention — is what frontier AI models do in the hands of real attackers. They increase the likelihood you'll have an event and decrease the time you have to address these longstanding issues.
So, here’s what to know and what you can do about it.
The Warning and What It Calls For (Urgently)
In the coming months, the letter says, AI-enabled cyberattacks will become far more widespread and sophisticated as models around the world become increasingly capable.
Most of the warnings I've read in the last decade carry an implied horizon of “eventually,” and I translate accordingly. This one says months, and the signatories are the people building the models, which makes it harder than usual to file under "someday."
The rest of the call to collective action is based on three ideas: current security practices won't be enough on their own, defenders need AI capable of matching what's coming, and the response must be collective rather than company by company.
From there the letter calls out different categories of organization and the ways each must respond.
- Every organization should treat cyber defense as a leadership priority and fix its highest-risk weaknesses.
- Security vendors should test continuously against frontier capabilities and make AI-powered defense something critical infrastructure operators can deploy rather than read about.
- Governments should support the organizations least able to fund their own defense, which the letter identifies as hospitals, water utilities, and local authorities.
I wrote an open letter of my own a few weeks back, after attackers reached into water treatment systems across a dozen states. I didn't expect to see water treatment plants named in an OpenAI document quite this fast.
Two weeks later the conversation escalated. On September 12, Anthropic CEO Dario Amodei published an essay calling on AI companies to slow the pace of capability development, arguing that an extra year or two spent on safety work would meaningfully reduce the odds of something going very wrong. Sam Altman agreed the industry needs to pace the frontier. Demis Hassabis at Google DeepMind said the essay pointed the right direction. As a result of all this, AI stocks fell Monday morning. Put the two timelines next to each other and count what you've got. The letter says months. Amodei's proposal, assuming every company went along with it, buys a year or two.
However that argument resolves in Silicon Valley, it resolves somewhere else for the rest of us boots-on-the-ground-folk. Nobody at that table is patching the firewall that stopped getting security updates two years ago. That one's still yours.
Your Remediation List Is Still Your Remediation List
If the findings are old, the work is old too, which should be the reassuring part of all this. What's changed is how long you have to get through it.
I've read reports where we enumerated a vulnerability, rated it high, published the fix path, and then watched the same finding come back the next quarter because nobody plugged the hole. Sometimes that's budget. Sometimes the arrangement was that we'd expose the problem and somebody else would fix it, and somebody else didn't. Whatever the reason, that pattern was survivable when exploitation took skill and patience, and what's been published in the last three weeks argues it won't be much longer.
One point from the letter I want to emphasize specifically: the same advances making attacks cheaper are giving defenders new ways to clear weaknesses that have been sitting there for years. The signatories call that a defender's window, and their whole argument is that it's getting narrower while we watch. That’s something we should all take to heart.
How to Raise This with the Organizations You Advise
The companies you advise are going to run into this. It was covered by the BBC, NBC, Politico, and most of the trade press, and the Amodei essay pushed it into general news. A few people will read it and get nervous. Many will see a headline, feel vaguely uneasy, and go back to work.
The temptation is to add urgency on top of it, and I'd encourage you to tread carefully. There's plenty already, and anything you stack on top reads as opportunism to someone who's unsettled. You'll be more credible staying calmer than your source material.
What's worked for me is making it specific to them first. Talk about the systems they touch rather than frontier models and capability thresholds. Ask what happens to the business if their bank is offline for three days, or what operations look like if the water utility serving the building goes down. The letter names these examples specifically, and they're concrete in a way model benchmarks rarely are.
Then make the conversation about the list rather than the threat. You already know the unsupported firewalls and the incident response plan nobody's tabletopped. You've probably raised all of it more than once. That conversation is information they already have about their own environment. What the last three weeks added is a timeline, and that's your way in. It’s a much easier conversation than the one where you have to convince someone a problem exists.
For the projects that keep sliding, be direct. The day an incident happens is a rough day to start writing the plan. If there's an incident response engagement, a tabletop, a firewall replacement, or a rollout that's moved three quarters in a row, this is the most credible reason you've had in a while to raise it again. The credibility comes from the source. Companies with real commercial reasons to be optimistic about AI signed something saying there isn't much time, and then the people running those companies started telling each other to slow down.
Act While the Window’s Open
Hundreds of companies that spend the rest of the year trying to take each other's customers signed the same page. So did AI labs in a straight footrace with one another, ones who have every commercial reason to tell you their models are safe and to leave the defensive security conversation to someone else. What they've all agreed on is that a clock exists, and that it's ticking fast. The defender's window is open right now.
That's good news, but only if it's followed by action.
So, pick three organizations. Three where the conversation can turn into something real because they’re already leaning into AI on their own, already a little uneasy about what they've been reading, already asking you questions you didn't prompt. Go back to them this week with the projects that got a polite no in April. You've been handed a new reason to re-raise things, and those don't come around often. If a client asks why now, you have a better answer than you had a month ago. And a timeline to point to.
The people building the models said months. I'd take them at their word.


