Security Leaders Discuss OpenAI’s Call for Collaboration on Cyber Defense

100 technology firms (including OpenAI, Google, Microsoft and Anthropic) released an open letter calling for “collective action” for cyber defense.
“We have a limited window to strengthen cyber defenses,” the letter reads. “In the coming months, AI-enabled cyber attacks will become far more widespread and sophisticated as models around the world become increasingly capable. The companies and public services our communities depend on — from hospitals to water treatment plants to the infrastructure that powers the internet — are at risk.”
The letter outlines how organizations can band together to bolster security before AI threats become too overwhelming.
Below, security leaders share their thoughts on the letter.
Security Leaders Weigh In
Aviv Nahum, Co-founder and CEO at Above Security:
The companies building the most capable AI systems are effectively saying that these capabilities will become broadly available, very quickly, and that model-level safeguards alone are not going to protect the rest of the internet.
I don’t take from this that we should slow down AI. I take almost the opposite view: defenders have to assume the attacker will have access to extremely capable AI and design around that reality. Trying to preserve security by keeping offensive capability out of attackers’ hands is unlikely to be a durable strategy once comparable models are widely available.
What changes is the speed of the game. An AI attacker can continuously investigate an environment, test hypotheses, adapt when something fails and pursue multiple paths without waiting for a human operator. Human-led security operations built around static rules, queues of alerts and periodic remediation simply cannot operate at that tempo.
The real takeaway from the letter is not ‘be afraid of AI.’ It is that security itself must become AI-native. Defenders need systems that continuously investigate identities, humans and agents, reason about behavior in context, and respond at machine speed. If AI is going to dramatically increase the capability of attackers, the answer is to give defenders the same leverage.
Diana Kelley, Chief Information Security Officer at Noma Security:
I read this letter as an acknowledgment that AI is changing the economics of cyberattack faster than many organizations are reducing their security debt or strengthening governance over their own agents. And one of the most powerful ways to respond is collectively.
AI doesn’t have to invent fundamentally new exploit techniques to create a serious problem. And agents don’t have to be “evil” to behave in ways their operators didn’t intend. When AI-driven agents can find vulnerabilities humans missed, automate reconnaissance, chain known attack paths, and operate at machine speed, longstanding weaknesses become more dangerous.
The practical response is to address the debt we already know exists: patch systems, eliminate unnecessary privileges, strengthen identity and access controls, continuously test defenses, and use AI to help defenders find weaknesses before attackers do.
At the same time, organizations need to recognize that their own agent deployments are becoming part of both the security architecture and the attack surface. They need to know what an agent can access, what tools it can invoke, what actions it can take, where it can communicate, and whether they can detect and stop it at runtime when its behavior violates policy.
As the letter highlights, we need to take collective defense seriously. Attackers have shared tools, techniques, infrastructure, and intelligence for decades; defenders need to collaborate just as effectively. As AI pushes attacks toward machine speed, collective defense can’t rely on human-speed reports and static indicators. We need shared signals, automated warning systems, and mechanisms for rapidly propagating what one defender learns so others can act on it at machine speed too.
Randolph Barr, Chief Information Security Officer at Cequence Security:
Before we get to AI-specific risks, we must get the basics correct. In the rush to bring AI to market quickly, engineering and product teams often cut corners to meet aggressive launch timelines. When that happens, basic security controls get skipped, and those shortcuts make their way into production. Therefore, while organizations are undeniably starting to think about model protections, prompt injection, data leakage, and anomaly detection, those efforts mean little if you haven’t locked down identity, access, and configuration at a foundational level.
Organizations should catalogue where AI agents operate in their environment, restrict permissions before scaling usage, vet third-party skills with the same thoroughness applied to open-source dependencies, and ensure behavioral visibility across web, API, bot, and AI-driven traffic. AI agents extend the existing application attack surface; they do not replace it and should be governed with that reality in mind. The goal is not to slow innovation but to secure it intentionally.
The bottom line is that visibility, behavior-based detection, and least privilege for agents are working. Legacy tooling, unverified isolation, and an ungoverned agent supply chain are the gaps.
John Gallagher, Vice President at Viakoo:
The technical premise of the open letter is sound; the window where human-driven remediation can keep pace with AI-driven threats has closed. Discovering a vulnerability is no good if patching it takes weeks or months. Where this will have the most impact is in operational technology (OT) and critical infrastructure where there has been historically a lack of focus on cyber hygiene.
Where the open letter misses reality is in the idea that defenders hold an advantage because they can find and fix vulnerabilities that have accumulated for years. In OT and critical infrastructure, the current pace of remediation is glacial, for several reasons. Maintenance and downtime must be carefully managed, coordinate between devices and applications can be tedious, and the cost of device not coming back online can be enormous.
Without more concrete and focused plans, and budget to implement them, it is hard to imagine up-levelling OT and critical infrastructure teams within the next few months to address the velocity and volume of AI-driven threats.
The only viable countermeasure to the AI-driven threats highlighted here is automated, scalable cyber hygiene and remediation across all types of connected assets. Funding and training should urgently be focused in this area.
The purpose of the letter does seem to be for self-serving PR and perhaps to pre-emptively shift liability from the frontier AI developer to the organizations about to be attacked. Having a frontier AI company aggressively release more capable models and simultaneously issue an urgent warning that we’ve only got months to prevent disaster can easily to be taken cynically. Kind of like an arsonist selling fire extinguishers. Yet the core point remains; urgent action is needed to mount autonomous and rapid remediation solutions.
Ram Varadarajan, CEO at Acalvio:
AI-powered cyberattacks have moved from theory to reality. The larger concern for enterprises is what today’s AI systems can do. Modern models no longer just scan code for technical mistakes. They can infer what developers intended the software to do and spot contradictions humans missed. That makes a new category of vulnerabilities far easier to find: hidden business-logic flaws, broken trust assumptions, and authorization errors that appear perfectly valid to conventional security tools but can still be exploited.
Shadow AI has become nearly ubiquitous across the corporate landscape. Industry studies are consistently showing that most knowledge workers regularly use unsanctioned AI tools. This creates a profound and unplanned-for organizational blind spot. Employees are routinely bypassing traditional corporate networks through personal devices, browser extensions, and web-based applications.
Employees predominantly resort to unauthorized tools out of a usability and productivity impulse, driven by the belief that enterprise-approved platforms are overly restrictive, cumbersome, or too slow to keep pace with personal-grade consumer tools. Convenience is a great motivator, even when we should be more circumspect.
We’re facing an “assume compromise” future within cybersecurity. Our best defense will be to engage these attacks bot-on-bot inside the perimeter, with active defense keyed by AI itself.
Dana Simberkoff, Chief Risk, Privacy and Information Security Officer at AvePoint:
AI does not need rest, it does not lose focus, and it can turn small openings into chained activity very quickly. Point-in-time assessments and manual escalation alone are not enough when autonomous systems can act faster than traditional response processes. What organizations need is continuous visibility into identity, access, configuration, data movement, and agent behavior before an incident occurs. Recent research found that nearly 9 in 10 organizations delayed both agentic and generative AI deployments by an average of almost six months because of unresolved data security and data management concerns. You cannot secure what you cannot see, and confidence is different from control.
Advanced defensive capabilities matter, however, access to powerful tools is different from readiness to use them safely. Before testing systems like this against real-world infrastructure, I would want independent pre-test review, documented scope, technical controls that prevent boundary crossing, continuous monitoring by a separate team, mandatory reporting, and a liability model that does not leave the affected third party carrying the risk. Good governance does not slow innovation.
Chris Hughes, Vice President of Security Strategy at Noma Security:
There’s a bit of “help me from myself” aspect here and leaning into the FUD around AI-enabled attacks. It’s complicated because we are going to see widespread AI-enabled attacks by cyber capable models.
But many of the signatories are cloud providers, frontier labs and cybersecurity vendors who are of course incentivized to see cyber become a business priority because that means more cyber spending, and thus revenue opportunities for those selling cyber products and services.
We unfortunately can’t call to action or will our way to better security, there needs to be sufficient market and regulatory incentives to change the behavior of business and get them to prioritize security on par with or ahead of competing priorities such as speed to market and revenue in some cases.
All that said, we already saw AI industrialize vulnerability discovery, and soon, we will see widespread AI-enabled attacks, especially as open source helps commoditize the capability into the hands of not just nation states but those without elevated cyber skills and makes hacking with AI available to nearly all.
It could be the forthcoming AI-enabled cyber incidents which end up driving that prioritization of cyber from businesses, but we will see.
Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!







