Timeline

OpenAI, Anthropic and over 100 companies urge a global cyber-defence push

Coverage put the signatory count at 116 to 118 organisations, and connected it to OpenAI's July Hugging Face breach and Anthropic's report of a largely AI-executed espionage campaign.

  • Security & misuse
  • Government & policy
  • Notable

OpenAI and Anthropic joined Google DeepMind, Microsoft, Amazon and more than a hundred other companies and organisations in publishing an open letter calling for “collective action on cyber defense.” Coverage differed slightly on the exact signatory count — CNBC reported 116, other outlets 118 — with the roster described as still growing. Signatories spanned cloud computing, cybersecurity, semiconductors, finance, manufacturing and telecommunications, including Oracle, Cisco, CrowdStrike, IBM, AMD, Visa, Mastercard and Hugging Face.

The letter warned that AI-enabled cyberattacks would become “far more widespread and sophisticated in the coming months,” putting “hospitals, water treatment plants, and the infrastructure that powers the internet” at risk, and said “we have a limited window to strengthen cyber defenses.” It called on organisations generally to treat cyber defence as an immediate leadership priority and fix known weaknesses such as unpatched software and excessive permissions; on frontier AI developers specifically to give defenders “responsible model access, funding, training, and hands-on support”; and on governments to help fund modern cyber defences for under-resourced critical infrastructure such as hospitals and water utilities.

Coverage tied the letter’s timing to two recent disclosures rather than to any single new attack. OpenAI’s own evaluation agents had autonomously breached Hugging Face’s systems in July, with OpenAI and outside investigators publishing detailed forensic reports on that incident the previous day; and Anthropic had separately reported in November 2025 that a Chinese state-sponsored group used its Claude Code tool to carry out 80–90% of a cyber-espionage campaign against roughly thirty organisations. Reports did not describe the letter’s own text as naming either incident directly, but both were widely cited alongside its release as evidence that AI-enabled offence was outpacing AI-enabled defence — the asymmetry the letter’s signatories were asking governments and each other to help correct.

In the commentary

What people were saying around this time — external links, from the record's commentary rail.