100+ companies sign AI cyber defense letter: read the list
OpenAI, Anthropic, Google, Visa and 100+ others signed an AI cyber defense letter. The exposures it names are a small-business patch backlog.
Industry open letters are usually a way to say nothing at length. This one has a paragraph worth stealing. On August 27 more than 100 companies — OpenAI, Anthropic, Google, Microsoft, CrowdStrike, Okta, Fortinet, Visa, Mastercard, Capital One, Adobe, Oracle, IBM — signed a call for collective action on cyber defense, and buried in the framing is a list of what actually gets exploited. It is not exotic. It is your backlog.
What actually happened
The letter, hosted by OpenAI and covered by TechCrunch, opens with a prediction: AI-enabled cyber attacks will get more widespread and more sophisticated in the coming months as models everywhere get more capable. It then sets out five principles — status quo security is not enough, put cyber-capable AI in defenders' hands, mobilize a collective response, treat defense as a leadership priority, and coordinate at local, national and international levels.
The specific asks land on the frontier labs: give responsible model access to defenders, fund and train under-resourced teams, invest in authorized security testing, and share threat assessments and defensive tooling with governments, security firms and open-source maintainers.
Then the sentence that matters to anyone running a 12-person company. The exposures named are longstanding bugs, excessive permissions, misconfigurations, insecure and unpatched software, weak authentication, and technical debt in legacy systems. Not zero-days. Not nation-state tradecraft. The stuff that has been on your list since 2023.
Why AI cyber defense matters for your business
The threat model change is not that attackers get smarter. It is that reconnaissance gets cheap. Probing 10,000 small businesses for a stale admin account used to cost attacker hours; an agent does it for the price of tokens. The floor of "not worth attacking" is rising to meet you.
So take the letter's list literally and work it in that order:
- Excessive permissions. Every service account, API key and OAuth grant you issued and never revoked. Pull the list. Most of it is dead.
- Weak authentication. MFA on every admin console — hosting, DNS, payment processor, email. DNS and email first; both are recovery paths for everything else.
- Unpatched software. Not everything. The things reachable from the internet.
- Misconfigurations. Public storage buckets, default credentials, staging environments with production data.
- Technical debt. The one legacy box nobody wants to touch is exactly the one an automated scan will find.
None of this needs an AI security vendor. It needs an afternoon and a written inventory. The signatories are right about the direction and slightly self-serving about the remedy — a lot of what they propose selling you is defense against attacks their own models make cheaper.
Key takeaways
- 100+ companies including OpenAI, Anthropic, Google, Microsoft, Visa and Mastercard signed the letter on August 27, 2026
- Five principles, with asks aimed mostly at frontier labs: model access, funding, testing, threat sharing
- The exposures it names are ordinary — stale permissions, weak auth, unpatched software, misconfigs, legacy debt
- AI lowers the cost of reconnaissance, which raises the floor of who is worth attacking
- Start with permissions and MFA on DNS, email and payments — not a new security product
We inventory before we harden. Rush Commerce audits the accounts, keys and integrations your business actually has — including the ones nobody remembers issuing — and closes what should never have stayed open. See how we scope a security pass or send us your stack.
Sources: OpenAI, TechCrunch.
- #cybersecurity
- #ai-agents
- #openai
- #anthropic
- #patching
Tommy Rush — Founder, Rush Commerce
Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More
Get The Rush Report weekly — one email, zero fluff.
Keep reading
Okta Agent SSO is GA: your AI agents get real logins
Okta shipped Agent SSO to all core SSO plans at no extra cost. AI agents get short-lived, governed tokens instead of pasted API keys. Here's what to do with it.
Read itNvidia's $12.9B Hugging Face bid: your registry picks a side
Nvidia is reportedly closing in on a $12.9B Hugging Face acquisition. If your deploy pulls weights from the Hub, your model registry now belongs to a chip vendor.
Read it