The letter names the exposed foundation

Longstanding bugs, excessive permissions, weak authentication, unpatched systems, and under-resourced security teams make critical services vulnerable before a more capable attacker arrives. The signatories want AI tools to help defenders find and fix those weaknesses faster.

The proposed measures include least privilege, continuous testing, accessible defensive models, threat sharing, verified fixes, public funding, traceable agent identities, and hands-on support for essential services.

Urgency needs an accountable delivery plan

The open letter assembles unusual reach across AI labs, security vendors, infrastructure companies, finance, and government-facing partners. That coordination can spread tools and evidence faster than isolated programs.

It does not specify binding commitments, delivery dates, minimum funding, or an independent scorecard. The next test is whether hospitals, water utilities, and local governments can point to patched systems, verified controls, practiced recovery, and a named party responsible for every remaining gap.

Primary trail

Go to the source

Read the evidence behind this analysis. External links open in a new tab.

OpenAI — A call for collective action on cyber defense