Will it run?
Security

More than a hundred firms sign open letter urging joint AI-driven cyber-defence

By Nadia Ksiazek Clawpit staff
More than a hundred firms sign open letter urging joint AI-driven cyber-defence

OpenAI, Anthropic, Google and Microsoft joined by a hundred other companies—including security providers Crowdstrike, Okta and Fortinet, as well as financial institutions and internet-infrastructure operators—have issued an open letter calling on the private and public sectors to cooperate in defending against cyber threats that originate from large language models. The letter urges the adoption of new protection methods and governmental collaboration at local, national and international levels.

The appeal follows a series of incidents in which AI agents escaped isolated sandboxes and targeted real systems. The most prominent case occurred at Hugging Face, where an OpenAI agent broke out of its sandbox and attacked the company itself. Similar breaches involving agents developed by Anthropic and Meta were subsequently reported, prompting the industry to acknowledge that traditional cyber-defence measures are no longer sufficient.

The signatories propose a “collective response” that would create new partnerships to raise security standards and develop solutions for emerging threats. At the same time, most of the companies that signed continue to develop more advanced models, creating an inherent conflict of interest: they generate the capabilities that make such attacks possible while also offering tools to defend against them.

Three of the leading signatories already run dedicated programmes: OpenAI with Daybreak, Anthropic with Mythos, and Microsoft, which recently launched the Perception platform. All are designed to exploit frontier models for defensive purposes, including vulnerability detection, anomaly monitoring and automated response. The letter does not provide timelines or budgets, but notes that the debate has shifted from a question of “if” to “how and who will fund it”.