116 companies signed an open letter calling for a global surge in cyber defense — signed by the same industry that spent the year racing model capabilities.

OpenAI, Anthropic, Google and more than 100 other companies published an open letter on August 27 calling for collective action to strengthen cyber defenses before AI-enabled attacks outpace them.
The letter — led by OpenAI and signed by ~116 companies including Microsoft — warns of a “limited window” to reinforce defenses, and calls for a global surge in defensive tools and resources.
It references existing frameworks such as the EU’s NIS2 and urges treating cyber defense as an immediate priority across industry and government.
The same industry spent 2026 racing capabilities; this letter is the first coordinated acknowledgment that the attack surface is growing just as fast.
Security teams get a shared framing — and, more concretely, a signal that AI vendors see defending as their problem too.
The 116 names span an unusual cross-section: frontier labs that normally compete on safety messaging, cloud providers who sell the infrastructure, defense contractors, and a bloc of financial institutions that have lived with cyber escalation longest. Getting companies with competing interests to co-sign anything is hard; agreeing that the threat curve is bending the wrong way was apparently easier.
Three concrete commitments rather than slogans: shared threat-intelligence pools covering AI-accelerated attacks, funded red-team programs specifically for AI systems, and a joint framework for disclosing incidents without competitive penalty. None of it is voluntary-sounding fluff — each item has an owner and a timeline, according to people familiar with the draft.
The letter lands amid a documented rise in AI-assisted attacks — phishing at near-perfect localization, vulnerability discovery at machine speed, and deepfake-enabled fraud moving from novelty to line item. Security teams describe an asymmetry problem: defenders need to be right everywhere, attackers need to be right once, and AI has changed the economics on the attacker side first.
StackHK verified the details above against primary sources — official announcements, release notes and on-record statements — before publishing, and every figure carries its original attribution. Where coverage differed, we noted the discrepancy rather than picking a side. Quotes are attributed to their original context; paraphrases are marked as such. We exclude unverified rumors even when they circulate widely, and if a material claim changes, we update and date-stamp the correction.
The immediate checkpoint is the next vendor update cycle, where follow-through becomes measurable. Competitive responses typically land within a quarter, and pricing or packaging shifts are the usual first tell. StackHK tracks the follow-through as standing coverage — and where hands-on testing can verify or contradict specific claims, we publish that separately with methodology attached.
The industry that built the new attack surface is asking to help defend it — before the window closes.
“There is a limited window to strengthen cyber defenses before AI grows powerful enough to overwhelm current protections.”
“OpenAI, Anthropic, Google and 100 other companies call for action to defend against rogue AI.”