On 27 August 2026, OpenAI published an open letter together with more than 100 companies addressing the threat of AI-driven cyberattacks on critical infrastructure such as hospitals, water treatment facilities and energy grids. The coalition, which includes Microsoft, Google, AWS, Anthropic, Cisco, Deutsche Telekom, SAP, Mastercard and Visa, is urging governments and the industry to take joint action while defenders still have a lead over attackers.
The timing of the letter coincides with a joint warning issued by US intelligence agencies NSA, CISA and FBI in mid-August 2026. In that warning, the agencies revealed that attackers are already using AI to write exploitation scripts targeting industrial control systems, including Siemens S7 equipment in the energy, water, chemical and manufacturing sectors. According to a recent CrowdStrike report, AI-driven attacks increased by 89 percent in 2025 compared to the previous year.
Greg Brockman, co-founder and president of OpenAI, shared the letter via his social media channels. The letter warns that AI models could become powerful enough within months to enable sophisticated attacks that were previously only within reach of state-level actors.
What the open letter calls for
The letter was signed by 117 organisations on 28 August 2026 and represents a broad range of sectors: technology, cybersecurity, financial services and telecommunications. Alongside the major technology companies, banks such as Citi and Capital One and financial institutions such as Mastercard and Visa have also signed the letter. The signatories urge policymakers to prioritise AI applications for defence and to promote collaboration between public and private parties.
The coalition argues that the defensive side currently still holds the advantage, but that this window is limited. Nate Soares, president of the Machine Intelligence Research Institute, expressed concerns about the use of AI swarms to compromise other AI companies and conduct cybercrime at scale. The letter explicitly identifies critical infrastructure as the primary target requiring protection.
Daybreak: OpenAI's own cybersecurity programme
Alongside the open letter, OpenAI is expanding its Daybreak programme. This cybersecurity initiative, announced in May 2026, focuses on strengthening open-source codebases and supporting security research. As of 28 August 2026, the programme has identified 858 issues across 41 codebases and produced 263 patches, based on self-reported figures. More than half of these, 143 patches (approximately 54 percent), have been adopted by the maintainers of the relevant projects.
OpenAI has linked $17 million in API credits and direct support to Daybreak, intended for open-source security initiatives. In addition, OpenAI has granted access to the model GPT-5.4-Cyber to the US Center for AI Standards and Innovation (CAISI) and the UK AI Security Institute (UK AISI) for independent evaluations.
Internally, OpenAI is developing a security agent named Aardvark. The agent is currently being tested in a closed setting and is capable of analysing codebases and proposing solutions for vulnerabilities. A broader rollout has not yet been announced. In July 2026, an OpenAI agent already hacked Hugging Face, the platform for open-source AI models, as part of a security test.
Trusted Access for Cyber and the Frontier Risk Council
Part of the Daybreak programme is the so-called Trusted Access for Cyber programme, through which a select group of organisations gains extensive access to OpenAI models for defensive applications. Participants include Bank of America, BlackRock, BNY, Citi, Cisco, Cloudflare, CrowdStrike, Goldman Sachs, JPMorgan Chase, Morgan Stanley, NVIDIA, Oracle, Palo Alto Networks and Zscaler.
OpenAI also announced the establishment of the Frontier Risk Council, an advisory group that will initially focus on cybersecurity before expanding to other domains where advanced AI capabilities pose risks. The precise composition and remit of this council have not yet been made public.
For European players, these developments are relevant: signatories such as Deutsche Telekom, SAP and ARM demonstrate that major European technology companies have also joined the coalition. For Dutch and European policymakers and founders in the cybersecurity sector, the letter underscores how rapidly the threat is evolving and the extent to which international coordination, including beyond the US, plays a role in building digital resilience around critical systems.