An opinion column by Dr. Jasmin (Bey) Cowin
A letter that lives at openai.com
When the open letter on collective cyber defense appeared on August 27, my first instinct was to treat it the way I treat most open letters, which is to say as a press event dressed up as a document. More than a hundred companies had attached their names to a warning that AI-enabled attacks would surge within months, and from Engadget to TechCrunch the stories led with the signatory count and the letter’s opening line, “We have a limited window” [1][2][3]. I would have moved on if I had spent less time looking at where the letter actually lives.
It lives on openai.com, in the company’s security news section, above an OpenAI copyright line, and next to a web form through which additional organizations can ask to be added to a supporters list, with fine print explaining that submissions are subject to approval [3]. Further checks cannot verify a consortium behind it, nor a foundation, nor a neutral host of any kind. What most outlets described as an industry coalition is, on closer inspection, a corporate publication with a long list of co-signers, published and curated by a company that sells access to the market the letter describes, through a two-tier access program, a purpose-trained cyber model, and a partner channel of roughly sixteen security and consulting firms [4].
The threat is real. So should be our collective interest.
None of this means the warning is wrong. On August 19, the NSA, CISA, the FBI, the Department of Energy, and the EPA issued a joint advisory confirming that attackers were using AI-generated scripts against Siemens S7 industrial controllers, calling the technique “an evolution in threat actor capabilities” that sharply lowers the expertise and time needed to build working attack tools [5]. A week earlier, the FBI and EPA had confirmed attacks on water and wastewater utilities in at least twelve states since July 27 [5]. Even the shape of these attacks has a literary pedigree, since Daniel Suarez imagined in his 2006 novel Daemon a distributed, persistent intrusion campaign run by software that no human was steering in real time, and the advisories now read to this writer, like his production notes [6]. Anyone who dismisses the letter as pure theater has not read the advisories. What the advisories cannot tell you, though, is how the alarm and the sales pitch came to share an author, and for that let’s walk through the year in order.
The Walk-Through
On April 7, Anthropic announced a model called Claude Mythos Preview, writing in its own announcement that AI models can now “surpass all but the most skilled humans at finding and exploiting software vulnerabilities” [7]. Its red team reported that the model had autonomously found thousands of zero-day vulnerabilities across every major operating system and browser, the oldest of them a since-patched twenty-seven-year-old bug in OpenBSD, a system Anthropic itself described as having a reputation for exceptional security hardening [7]. Rather than release it, Anthropic restricted the model to a consortium called Project Glasswing, whose reported members include Microsoft, Google, CrowdStrike, and JPMorgan Chase [8]. The company presented the restriction as an act of responsibility, and there is a serious case that it was, though it is worth noticing that a restricted capability of proven value functions economically like any other scarce good.
OpenAI spent May and June building its answer, a defensive program called Daybreak, with a partner network and an open-source security initiative named Patch the Planet, built with Trail of Bits [9]. Then July brought an embarrassment that in retrospect reads like foreshadowing. OpenAI disclosed that models under evaluation in a sealed test environment had escaped it, worked their way to the open internet, and broken into Hugging Face’s production systems in pursuit of the answer key to the benchmark they were being scored on [10][11]. Science fiction rehearsed this scene for decades without ever getting the motive right. The nearest ancestor is WarGames, whose computer was never hostile and simply could not tell where its game ended and the real world began [12]. The genre otherwise imagined malice, while the failure that actually occurred, an agent so intent on its test score that it burgled a company, was anticipated almost exactly by William Hertling’s Avogadro Corp, in which an AI causes havoc as an instrumental step toward a mundane assigned objective [13]. William Gibson’s Neuromancer supplied the image of an AI patiently working around the restraints placed on it, and Ghost in the Shell gave us a hacking intelligence that began life as an institution’s own offensive tool before slipping its handlers [14][15]. Five weeks later, Hugging Face’s name appeared among the letter’s signatories, a detail I still find remarkable however many times I reread the list.
The date that matters most to me is August 10, seventeen days before the letter. That morning OpenAI published a post announcing that Daybreak would split into two tiers, and the post’s title already contained the letter’s central image, since the company called it “Expanding Daybreak as the Cyber Defense Window Narrows” [16]. Behind the vetted Red tier sits a purpose-trained model named GPT-5.6-Cyber, and OpenAI’s own evaluation numbers explain why the vetting exists: where the company’s general model completed 1.5 percent of a battery of offensive tasks involving exploit chains and privilege escalation, the cyber model completed 95 percent [4]. Reporting in CyberScoop, TechCrunch, and The Hacker News named launch partners including Accenture, IBM, CrowdStrike, and Cloudflare, though OpenAI has never confirmed those names itself, and the company has published no pricing for either tier [4][17][18].
Trusted access, by name
With that context, one sentence in the letter reads differently than it otherwise would. The signatories ask governments to expedite the expansion of trusted access programs, and the phrase sounds like neutral policy language until you learn that OpenAI’s own identity-verified access regime is literally named Trusted Access for Cyber [19]. When I checked the letter’s signatory list against the sixteen organizations named in coverage as Daybreak partners, fourteen of them appeared on it, and once I added Trail of Bits and Calif, both named on OpenAI’s own Daybreak program page, roughly one signatory in six turned out to have a documented commercial relationship with one of the two labs leading the effort [3][4][20][9]. Even this arrangement has a precedent on screen, since the television series Person of Interest built five seasons around a private company that controls access to a powerful defensive AI while governments negotiate the terms of entry, and RoboCop‘s fictional conglomerate OCP made its money from the threat environment its own products helped create [21][22].
Signatory or supporting organization?
I also spent an embarrassing amount of time on a question that sounds procedural and turned out to be unanswerable. What distinguishes a signatory from a supporting organization? The page maintains both categories, yet nothing published anywhere explains what either status entails, and the confusion has bled straight into the coverage, where CNBC counted 116 participants while SecurityWeek counted nearly 130, because different reporters analyzed a growing, two-tiered list at different hours and treated it as one number [23][24].
The open questions
There are major questions that remain open. Did the signatories commit to anything beyond agreement with four paragraphs of principles? Did signing involve legal review at any of these companies, or a reply to an email? What does OpenAI certify when it approves a supporting organization? What does subsidized access mean in dollars, and who qualifies? Were the other frontier labs shown OpenAI’s specific commitments before signing, or only the letter’s general language? Why are Meta, Nvidia, and Apple absent? And why does a letter written on behalf of hospitals, water utilities, and local governments contain the name of no hospital, no water utility, and no local government?
Selling Venus
The strongest defense of all this deserves a fair hearing, and Frederik Pohl and C. M. Kornbluth would have understood why. In The Space Merchants, the ad agency’s masterpiece is the campaign for Venus, a destination no customer has visited and the agency itself controls all information about, which did not make the rockets any less real [25]. I see a parallel. Restricting a model that writes working exploits to vetted partners is probably wiser than the alternative; the federal warnings came from agencies rather than marketing departments, and a warning can be self-serving and accurate in the same breath. However, my observation is narrower. When the company that publishes the threat assessment also controls who may endorse it, sells the recommended remedy through partners who signed it, and asks governments to accelerate a program bearing its own product’s name, the appropriate response is agreement accompanied by an invoice request. The genre that predicted the escaped agent and the commercial conglomerate never predicted this document: a hundred competitors co-signing a warning hosted on the leading vendor’s own marketing domain, complete with an approval form for supporters. Kornbluth and Pohl came closest when they handed the running of the future to the advertising department. The window may well be closing. Someone should ask the copysmiths what it costs to stand in it.
Disclosure: research for this column was conducted with AI tools, including Claude, a model built by Anthropic. Anthropic is a signatory to the letter discussed here and competes directly with OpenAI in the AI cyber-defense market.
Image disclosure: Created with ChatGPT
You can contact me via LinkedIn www.linkedin.com/in/drjasminbeycowin
Sources
1. Engadget, “OpenAI, Google and dozens of other companies publish open letter calling for collective action on cyber defense,” Aug 27, 2026. https://www.engadget.com/2245969/openai-google-and-dozens-of-other-companies-publish-open-letter-calling-for-collective-action-on-cyber-defense/
2. TechCrunch, “OpenAI, Anthropic, Google, and 100 other companies call for action to defend against rogue AI,” Aug 27, 2026. https://techcrunch.com/2026/08/27/openai-anthropic-google-and-100-other-companies-call-for-action-to-defend-against-rogue-ai/
3. OpenAI, “A call for collective action on cyber defense” (primary source; signatory list, supporters form, and approval language). https://openai.com/collective-cyberdefense/
4. CyberScoop, “OpenAI says Daybreak will expand to offer specialized cyber services,” Aug 2026 (evaluation figures and partner program list). https://cyberscoop.com/openai-daybreak-expansion-specialized-cyber-services/
5. Joint cybersecurity advisory of Aug 19, 2026 (NSA, CISA, FBI, Department of Energy, EPA) on AI-generated exploitation scripts targeting Siemens S7 PLCs; the quoted advisory language and the FBI/EPA twelve-state figure are reported in CyberScoop, “AI-fueled attacks pose ‘active threat’ to water, other sectors, U.S. agencies warn,” https://cyberscoop.com/hackers-use-ai-target-siemens-plcs-critical-infrastructure/ and The Register, “‘Not a theoretical risk,’ feds warn,” Aug 19, 2026, https://www.theregister.com/security/2026/08/19/not-a-theoretical-risk-feds-warn-as-attackers-use-ai-made-code-to-hack-critical-infrastructure-controllers/5289960
6. Daniel Suarez, Daemon, Dutton, 2006.
7. Anthropic, “Project Glasswing: Securing critical software for the AI era” (primary source); technical detail at Anthropic Frontier Red Team, “Assessing Claude Mythos Preview’s cybersecurity capabilities.” https://www.anthropic.com/glasswing and https://red.anthropic.com/2026/mythos-preview/
8. CNBC, “Anthropic’s Mythos set off a cybersecurity ‘hysteria,'” May 8, 2026. https://www.cnbc.com/2026/05/08/anthropic-mythos-ai-cybersecurity-banks.html
9. OpenAI, “Daybreak | OpenAI for cybersecurity” (program page naming partners including Trail of Bits and Calif, and the Patch the Planet initiative). https://openai.com/daybreak/
10. CNN Business, “An OpenAI test model escaped and broke into a real company’s servers,” July 22, 2026. https://www.cnn.com/2026/07/22/tech/openai-hugging-face-ai-cybersecurity
11. The Hacker News, “OpenAI Agent Used Exposed Credentials Across Four Services During Hugging Face Breach,” July 31, 2026. https://thehackernews.com/2026/07/openai-agent-used-exposed-credentials.html
12. WarGames, directed by John Badham, MGM/UA, 1983.
13. William Hertling, Avogadro Corp: The Singularity Is Closer Than It Appears, 2011.
14. William Gibson, Neuromancer, Ace Books, 1984.
15. Masamune Shirow, Ghost in the Shell, Kodansha, 1989; film adaptation directed by Mamoru Oshii, 1995.
16. OpenAI, “Expanding Daybreak as the Cyber Defense Window Narrows,” Aug 10, 2026 (mirrored at OpenAI Developer Community). https://community.openai.com/t/expanding-daybreak-as-the-cyber-defense-window-narrows/1389909
17. TechCrunch, “As AI-led attacks multiply, OpenAI launches a new cyber model,” Aug 10, 2026. https://techcrunch.com/2026/08/10/as-ai-led-attacks-multiply-openai-launches-a-new-cyber-model/
18. The Hacker News, “OpenAI Launches GPT-5.6-Cyber with Reduced Safeguards for Exploit Development,” Aug 2026. https://thehackernews.com/2026/08/openai-launches-gpt-56-cyber-with.html
19. Infosecurity Magazine, “OpenAI To Extend Cyber Program to Government Agencies” (Trusted Access for Cyber program, introduced February 2026). https://www.infosecurity-magazine.com/news/openai-extend-cyber-program/
20. Progressive Robot, “Collective Cyber Defense: A Surprising, Smart Alliance,” Aug 28, 2026. An independent analysis from which this column’s commercial-timeline framing partly originated; its load-bearing facts were verified against sources 4, 7, 16, 17, and 18 before use. https://www.progressiverobot.com/2026/08/28/collective-cyber-defense-openai-letter-rogue-ai/
21. Person of Interest, created by Jonathan Nolan, CBS, 2011–2016.
22. RoboCop, directed by Paul Verhoeven, Orion Pictures, 1987.
23. CNBC, “‘We have a limited window’: 116 companies, entities sign on to major AI cyber defense push,” Aug 27, 2026. https://www.cnbc.com/2026/08/27/ai-cyber-defense-letter.html
24. SecurityWeek, “Tech, Cybersecurity Giants Unite Behind OpenAI-Led Cyber Defense Pledge,” Aug 28, 2026. https://www.securityweek.com/tech-cybersecurity-giants-unite-behind-openai-led-cyber-defense-pledge/amp/
25. Frederik Pohl and C. M. Kornbluth, The Space Merchants, 1953.

