Knowledge
The OpenAI Cyber Defense Letter: What 100+ Companies Just Agreed On
OpenAI published an open letter calling for a 'global surge in cyber defense,' co-signed by Google, Microsoft, Anthropic, Shopify, Visa, and a hundred others. Here's what the OpenAI cybersecurity letter says and what it means for your store.
August 28, 2026 · Confidanti · 3 min read
- news
- openai
- ai
- cyber-defense
- open-letter
- fundamentals
This week OpenAI published an open letter, A Call for Collective Action on Cyber Defense, asking for what it calls "a global surge in cyber defense." What makes it news isn't the text alone; it's the signature block. More than a hundred organizations co-signed, including companies that compete with each other daily: OpenAI alongside Anthropic and Google, Microsoft alongside AWS, plus names e-commerce stores already depend on, like Shopify, Visa, Mastercard, and GoDaddy.
When that many rivals agree on something in public, the something is worth reading. Here's the short version, and our take on what it means for an online business.
What the letter says
The core claim fits in two sentences: AI-enabled cyber attacks are about to become far more widespread and sophisticated. But the same AI advances give defenders a window to fix weaknesses that have been accumulating for years, if everyone moves now. The letter calls it "the defenders' window."
The letter then lists what has actually left systems exposed. Read this list slowly, because none of it is futuristic:
"Longstanding bugs, excessive permissions, misconfigurations, insecure and unpatched software, weak authentication, and technical debt in legacy systems have left systems exposed."
No mention of super-viruses or unstoppable AI hackers. The world's largest technology companies, asked to name the problem, named the fundamentals: unpatched software, weak logins, things exposed that shouldn't be. If you've been reading this series, that list should feel familiar. It's the same one that shows up in every case we've written about, from the ransomware agent that walked through an unpatched flaw to the majority of exploited vulnerabilities needing no click at all.
What it asks people to do
The letter addresses four groups. Governments, security vendors, and AI labs get their own homework: funding, threat-intelligence sharing, making AI-powered defense accessible to defenders with limited budgets. But the first group addressed is every organization, and that section is the one worth your attention. Condensed, it asks each business to:
- Make cyber defense a leadership priority and treat it with the urgency of an incident, not a someday project.
- Fix the highest-risk weaknesses first, and verify the fixes actually worked.
- Build in least privilege and strong access controls, so each person gets only the access they need.
- Raise the bar for what you buy, build, and deploy, including AI-generated code.
- Use AI to get broad security coverage at lower cost, saving the heavy tools for the hardest problems.
If that sounds like a to-do list written for a company with a security department, it translates cleanly to a store without one: know what you have exposed, patch what faces the internet first, put MFA on every login that matters, give people only the access they need, and have someone watching.
Our honest take
Two things can be true at once, and this letter is both.
It's self-interested. AI companies calling for AI-powered defense are also describing their product roadmap. Fair enough. We're also an AI-native security company, so the same caveat applies to us, and you should weigh our enthusiasm accordingly.
And it's correct. The threat trajectory the letter describes is the one we've been documenting from public data all year: attacks industrializing, the skill floor dropping, the window between a flaw's disclosure and its exploitation shrinking. When the companies that build the models, run the clouds, and process the world's payments jointly say the status quo won't be enough, that's not marketing consensus, because these signatories don't share marketing departments. It's the rare kind of agreement that only forms around something everyone's data already shows.
The part we'd underline for you is the letter's quiet admission: the fix for an AI-accelerated threat is not exotic. It's the fundamentals, done urgently, verified, and, for teams without a security department, done with help. That's the entire premise this series has argued one article at a time, and it's now co-signed by a hundred companies that rarely agree on anything.
For your IT team. The letter's "every organization" section is a usable checklist: prioritized remediation of highest-risk exposures with verification, least-privilege and strong-authentication rollout, procurement standards that include AI-generated code review, and compensating controls where patching would disrupt operations. We keep the technical version of this playbook for whoever owns that side of your stack. See what we'd check →
The letter says to start by fixing the highest-risk weaknesses — finding yours is the first step of every Confidanti engagement. Talk to us.