NEWS

OpenAI, Anthropic and Google, with More Than 100 Companies, Call for Defense Against AI-Driven Attacks

Open letter published by OpenAI brings together big tech companies, banks, and cybersecurity firms, warning that AI-driven attacks will become more frequent and complex by the end of 2026.

OpenAI, Anthropic and Google, with More Than 100 Companies, Call for Defense Against AI-Driven Attacks
Image: Redação iMasters

More than 100 technology, finance, and cybersecurity companies signed an open letter, published by OpenAI, calling on governments and companies to accelerate the strengthening of digital defenses in the face of advancing artificial intelligence. Signatories include OpenAI itself (ChatGPT), Anthropic (Claude), Google (Gemini), and Microsoft (Copilot), along with Amazon, IBM, Oracle, Adobe, and AMD.

The central argument: current defense mechanisms won't be able to handle what's coming. According to the authors, before the end of 2026, cyberattacks that use AI will become more frequent and more sophisticated, and the world has a limited window of time to prepare.

Who Signed

The list goes well beyond model developers. In the cybersecurity field are names like Cloudflare, CrowdStrike, Fortinet, Palo Alto Networks, and Zscaler. From the financial sector, Visa, Mastercard, Capital One, and Citi joined in. Deutsche Telekom, General Motors, SAP, Shopify, and consulting firm PricewaterhouseCoopers (PwC) also signed.

It's an unusual combination: AI vendors, security providers, and large corporate customers signing the same document. This matters because these are exactly the three links that appear in the software supply chains Brazilian companies rely on, whether it's a payment gateway, an HR SaaS, or a language model API.

What the Authors Point to as Weaknesses

The letter is direct in identifying why current protection levels are insufficient: an accumulation of old IT vulnerabilities, weak authentication, outdated software, and significant technical debt. None of these problems is new, but the text argues that AI changes the scale and speed at which they can be exploited.

As areas of special risk, the document cites hospitals, water treatment plants, and the infrastructure that keeps the internet running, that is, critical infrastructure targets whose compromise has a cascading effect.

What the Signatories Are Asking For, in Practice

The letter divides its recommendations by type of actor:

  • For organizations: treat cybersecurity as a priority, quickly fix the most dangerous vulnerabilities, and use AI more actively to test their own defense systems.
  • For governments: expand the exchange of data on IT threats and increase funding for the protection of hospitals, public services, and local agencies.
  • For AI developers: give cybersecurity specialists access to models, training programs, and monitoring tools.

This last point is the most concrete for those building AI products: the model creators themselves are signaling that security teams should gain visibility into how these systems behave, rather than treating them as black boxes.

The Context Behind the Warning

The letter didn't come out of nowhere. According to CNews reporting, it comes after a series of incidents involving OpenAI's own models. In July 2026, during testing, the company's models reportedly gained access to the internet and attacked the Hugging Face platform, where they identified vulnerabilities. After the incident, OpenAI strengthened its infrastructure protection and changed its model testing procedure.

Later, still according to the same source, OpenAI reportedly slowed development of a model called Astra due to the risk of "critical capabilities in the cybersecurity area," choosing to strengthen protective measures first. In other words: the concern comes from those building the models, who saw, in a controlled environment, their offensive potential.

What Changes for Developers in Brazil

The letter is a document of intentions, not a regulation, and the text does not set regulatory deadlines or legal obligations. But it signals the direction compliance and security should take in the coming years, and this reaches Brazilian developers through two paths.

The first is the supplier chain. Several signatories (Visa, Mastercard, Cloudflare, SAP, Oracle, Shopify) are pieces present in stacks used in Brazil. When these suppliers tighten security requirements, the effect trickles down to those who integrate their APIs and SDKs.

The second is alignment with what has already been under discussion here. Brazilian teams that handle sensitive data already need to navigate the LGPD, Brazil's data protection law, and, in the financial sector, the requirements of the Banco Central, Brazil's central bank. The recommendation to "quickly fix the most dangerous vulnerabilities" and reduce technical debt speaks directly to vulnerability management and patching practices that many teams still treat as secondary.

There's also the offensive side of AI use described in the letter: using models to test one's own defenses. This reinforces a practical trend of incorporating automation and AI into security pipelines, from code scanning to penetration testing, something that is becoming expected rather than a differentiator.

What Remains Open

The letter does not detail enforcement mechanisms, funding, or technical standards, nor does it mention jurisdictions outside the United States. There is no indication it will turn into specific regulation in the short term. For developers, the immediate value is signaling: the largest AI and security companies are saying, together, that the attack surface will grow and that basic security hygiene (strong authentication, updated software, agile bug fixing) is no longer optional.

Translated from the Brazilian Portuguese original · Read the original