OpenAI Brings Together 116 Companies in Letter Against Upcoming Wave of Attacks Powered by Generative AI

Anthropic, Google, Cisco, CrowdStrike, Palo Alto Networks, Visa, and Capital One join OpenAI in a document highlighting a narrow window before the next wave of AI-driven attacks.
OpenAI, Anthropic, Google, Microsoft, Amazon, Cisco, Oracle, Cloudflare, CrowdStrike, Palo Alto Networks, Okta, and Fortinet signed a public letter this Thursday discussing a narrow window for companies to bolster cyber defenses ahead of a new wave of attacks driven by generative AI. Alongside the 116 companies listed in the document are Capital One, Mastercard, Visa, General Motors, and Shopify, an unusual mix that brings together rival labs, cloud providers, and financial institutions within the same message.
"In the coming months, cyberattacks using AI are expected to become much more widespread and sophisticated as models around the world become more capable," states the letter, according to excerpts published by CNBC and SiliconANGLE. The group calls for what it terms a defensive surge: governments prioritizing cybersecurity urgently, companies closing known serious vulnerabilities, and tightening security requirements on software suppliers and AI-generated code.
Why This Specific Coalition Matters
Coalitions around AI in the past three years have typically focused on existential risk and model transparency. This one is different. The axis is operational, and the signatory list reveals that the CISO areas of major tech firms, security vendors, and payment processors have reached the same conclusion. When OpenAI, Anthropic, and Google Cloud Security sign alongside CrowdStrike, Palo Alto Networks, and Okta, the four largest independent providers of endpoint and identity defense, the message to the board is that the signature is in the memo preceding the next incident report, not in a public policy piece devoid of consequence.
The presence of Capital One, Mastercard, and Visa underscores this point. All three have been repeated targets of BEC attacks and synthetic identity fraud, and they have publicly modeled the anticipated aggressiveness of deepfake and code-as-a-service campaigns. Signing a public letter projecting attacks "in the coming months" shifts the risk line from compliance to the security budget for 2027 and serves as cover for CIOs who need to return to committees requesting bolstered security outside the annual budgeting cycle.
What the Letter Specifically Requests
The document is structured around four requests. The first is that companies immediately close already mapped vulnerabilities and prioritize what the signatories call "crown-jewel remediation," rather than spending cycles on the long tail of low-impact CVEs. The second is a contractual requirement: software and AI product vendors must demonstrate a secure supply chain, and the enterprise customer should incorporate this into RFPs. The third is intergovernmental and public-private cooperation, focused on near-real-time sharing of indicators. The fourth point is the most delicate: the proposal that standards for AI-generated code undergo automated validation before merging into production databases.
How This Reads Outside the United States
The document is American in its call, but the effect is global and uneven. In the European Union, ENISA and the relevant authorities of each member state received full regulatory power of the AI Act on August 2, and the proposal for mandatory validation of AI-generated code aligns with Article 15, concerning robustness and cybersecurity of high-risk systems. The letter provides political cover for Brussels to make this requirement less abstract than it is today.
In the United Kingdom, the NCSC has been slowly pushing the Cyber Security and Resilience Bill through Parliament, and local signatories will provide ammunition for this agenda. In Japan, METI has maintained a voluntary guidelines program since 2024 that may now become a requirement, driven by companies like Toyota and SoftBank that are acquiring Palo Alto and CrowdStrike. In the shared services and BPO geographies, especially India and the Philippines, the concern is different: the cost of blocking unauthorized use of LLMs by junior analysts rises, and contracts with American and European clients will start requiring controls that are not currently included in SLAs.
What the Letter Does Not Say
A less generous reading is an honest ask. By requesting more spending on security and greater control over AI-generated code, the signatories are also asking for more revenue for their own sector. CrowdStrike, Palo Alto Networks, Okta, Fortinet, and Cloudflare thrive on this budget expansion; OpenAI, Anthropic, Google, and Microsoft sell the models that the letter describes as both a problem and a solution. This does not invalidate the diagnosis, which is empirically based on already released reports from Anthropic and Google DeepMind on the operational use of LLMs in offensive campaigns, but a CISO reading the text should separate the alert from the pitch before signing the next check.