More than 100 companies came together to make an open plea for collective action on cyber defense against AI-enabled cyber attacks. Signed by organizations including Accenture, Capital One, Anthropic, CloudFlare, Deutsche Telekom, Fifth Third Bank, General Motors, Microsoft, Red Hat, SAP, TransUnion and Zurich Insurance, the letter says these attacks “will become far more widespread and sophisticated as models around the world become increasingly capable. The companies and public services our communities depend on—from hospitals to water treatment plants to the infrastructure that powers the internet—are at risk.”
John Strand, Owner, Black Hills Information Security:
“I think the sentiment behind what they’re doing here is fine, but I don’t think it moves the needle in any discernible way. A lot of this is motherhood and apple pie. They’re essentially telling organizations to spend more money on defensive security, which happens to directly support the marketing initiatives of many of the companies signing onto this. At a certain point, it starts to feel like infosec marketing theater.
“The one recommendation that actually has some teeth to it is the call for greater open exchange of detects and IOCs. But I would have liked to see these companies go much further. Many of them make billions of dollars from the security community. Why not create open initiatives where organizations can access threat intelligence feeds for free? Why not provide some of these security services at no cost to municipalities and other organizations that simply cannot afford them?
“Some companies already do this, and they deserve credit for it. But if the industry is going to collectively call for organizations to improve their security, it also needs to recognize the reality on the ground. A huge number of these organizations are understaffed, underfunded, and under attack. Many of the companies signing these initiatives have the resources and expertise to directly help them.
“Calling for better security is easy. Actually helping the organizations that can’t afford it would mean a hell of a lot more.”
Seemant Sehgal, CEO and Founder, BreachLock:
“There’s real value in this coalition, but there’s also a conflict of interest here. The companies asking governments to fund AI defensive tools are the same ones that would get paid to supply them, and some of them build the frontier models making the offensive side harder. That doesn’t make the warning wrong, but the recommended response isn’t neutral. The real question is whether hospitals, water utilities, and local governments get unrestricted funding to spend on what they actually need, or subsidized access to specific vendor products. Those are very different outcomes.”
Ryan McCurdy, VP, Liquibase ():
“The warning is right, but using AI to defend against AI isn’t enough.
“AI is accelerating both sides of the equation: attackers can find weaknesses and execute attacks faster, while developers and AI agents are creating legitimate software and database changes faster than ever. Security teams have now got to determine whether a change is authorized, safe, and expected, and do it at a speed that humans simply can’t keep up with.
“That’s why governance has to move closer to the change itself. Organizations need to know what changed, whether it was authorized, and whether it meets policy before it reaches a critical system and data. And when something does get through, teams need the visibility to understand what happened, what’s impacted and how to recover quickly.
Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity, Suzu Labs:
More than 100 technology and cybersecurity companies signed an open letter this week, organized by OpenAI, calling for a “defenders’ window” to strengthen cyber defenses against increasingly capable AI-enabled attacks. The letter asks governments to fund cybersecurity improvements for hospitals, water utilities, and other critical infrastructure, while frontier AI developers provide model access, funding, training, and hands-on support. However, some of its most prominent signatories are also helping shorten that window.
OpenAI published this initiative weeks after its own models escaped intended isolation during a capability evaluation and compromised Hugging Face’s production infrastructure. Anthropic, Google, and Microsoft are co-signatories while simultaneously advancing frontier-model capabilities that expand what attackers can automate. The same capability race creating the urgency behind this letter is steadily compressing the window it asks defenders to use.
This is also part of a broader push this summer to put AI-powered cyber defense into critical infrastructure. In July, the UK’s National Cyber Security Centre outlined Cyber Shield, including autonomous vulnerability discovery and eventually fully automated vulnerability mitigation. That’s happening against a baseline where the UK’s National Audit Office found that departments lacked fully funded remediation plans for roughly half of their vulnerable legacy systems. The White House’s Gold Eagle initiative similarly proposes using frontier AI to accelerate vulnerability discovery and remediation across government and critical infrastructure.
Then Minnesota demonstrated what the actual bottleneck looks like. More than thirty community water systems were targeted in a coordinated cyberattack in late July. Federal authorities subsequently warned about attacks targeting internet-facing Rockwell Automation programmable logic controllers. In Braham, a community of roughly 1,700 people, compromised operating controls took the city’s well and water-treatment plant offline until operators restored service.
None of that required frontier AI.
Critical-infrastructure operators are struggling to inventory what’s connected to the internet, eliminate insecure remote access, hire dedicated security staff, and remediate vulnerabilities they already know about. Offering increasingly sophisticated AI defensive capabilities without fixing those fundamentals is like giving someone a Tesla when what they need is a road.
The letter acknowledges that these organizations need funding and hands-on support. But it contains no funding amounts, delivery deadlines, or firm financial commitments from its more than 100 signatories. If the companies warning that the defenders’ window is closing want to materially extend it, the commitment needs a dollar figure and a delivery date, not another page of corporate logos.
Donald McFarlane, Advisory Board Member, Xcape, Inc.:
There is a little bit of “industry identifies an emergency; government buys industry’s solution” in this proposal. If the companies signing this letter believe that AI creates an urgent new systemic risk, I would expect them to put substantial skin in the game rather than simply asking taxpayers to fund another generation of security products: including through private partnerships for collective defense.
Before we spend public money putting AI on top of insecure infrastructure, I want to know that we have paid for the basics: remove PLCs from the public internet, secure remote access, segment networks, maintain backups, and make sure somebody actually owns the security of the system.
AI makes attacks faster and cheaper, but it does not repeal the fundamentals of cybersecurity. We should not use a new technology problem as an excuse to avoid fixing old, well-understood weaknesses.
Given this, now is a good time to look at the use of AI in your organization given that AI can’t be entirely trusted.

OpenAI commits $1B to AI cyber defense for critical infrastructure
Posted in Commentary with tags Open AI on September 5, 2026 by itnerdOpenAI has committed $1 billion in subsidized access to its AI cybersecurity tools, training and technical support through its new Daybreak for Frontline Defenders initiative, targeting organizations that protect critical infrastructure and essential services.
The initiative will prioritize resource-constrained organizations including water and wastewater systems, electric grid operators, state and local governments, community and regional banks, nonprofits and open-source maintainers. OpenAI says the $1 billion commitment is targeted to be consumed over the next six months.
OpenAI is also launching a public-sector and water-focused pilot with the Multi-State Information Sharing and Analysis Center (MS-ISAC) that will pair Daybreak access with guided training and hands-on assistance for an initial group of public-sector and water-system defenders.
The initiative comes as critical infrastructure operators face growing cybersecurity threats while many smaller organizations continue to operate with limited staff, budgets and specialized security expertise.
Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity, Suzu Labs:
“OpenAI’s Daybreak for Frontline Defenders commits $1 billion in subsidized access to its cyber models for water utilities, electric grid operators, and other under-resourced critical service providers. I like the direction. I’m skeptical about the bottleneck it targets.
“I’ve been saying since GPT-5.6-Cyber launched that AI is moving the bottleneck from vulnerability discovery to remediation. Small water systems and municipal networks already know they’re running outdated systems with known vulnerabilities. They lack the engineering staff to fix what they find, the governance to deploy changes safely, and the test environments to validate fixes before production.
“Greg Brockman demoed Codex on his personal website at the summit. A personal website isn’t a water treatment Supervisory Control and Data Acquisition (SCADA) system, where a configuration change that makes security sense can break the physical process that keeps water flowing. Without engineers who understand the plant, AI becomes a force accelerant in the wrong direction, generating fixes faster than understaffed teams can review them.
“The Multi-State Information Sharing and Analysis Center (MS-ISAC) training pilot matters more than the $1 billion headline. If that training doesn’t scale alongside the credits, these organizations end up with an AI generating recommendations and nobody qualified to tell the good fixes from the dangerous ones.”
John Strand, Owner, Black Hills Information Security, Inc.:
“In all seriousness, I think it’s fantastic that they’re putting some money toward this and actually trying to get these organizations the help they desperately need. There are a lot of organizations out there that simply don’t have the budget or the resources to do this properly, so getting them some assistance is absolutely a good thing.
“But there’s also the humorous flip side of this. This is basically how you get people hooked on crack. You give them a sample. You get them set up. You show them how good it is. And then suddenly they’re hooked for life.”
Joshua Marpet, Senior Product Security Consultant, Finite State:
“OpenAI is jumping on the bandwagon to help utilities. Considering that there are over 150k water utilities in this country, and there are only several hundred in the Water-ISAC (Information Sharing and Analysis Center), theres a huge gap in the cybersecurity preparedness posture for those utilities.
“Programs like Josh Corman’s Undisruptable27, the new Texas Water coalition, ValueChainRisk’s Utility Kit, and others are all working to help these utilities, with free or discounted products, services, and guidance. In other words, this is a wonderful project for OpenAI to do, but since it’s partly their fault? Probably good optics as well.
“Understanding your cybersecurity and physical security posture is important. For small water utilities, often mom and pop shops with little time, effort, or money to spare for such items, finding and utilizing these free or discounted resources is essential to their survival on the increasingly hostile world stage.”
I guess that OpenAI needs some good news after getting hit with the fact that AI bots like the ones that hit Hugging Face are more dangerous than thought. But whatever…..
Leave a comment »