This website uses cookies

Read our Privacy policy and Terms of use for more information.

More than 100 organisations, including OpenAI, Anthropic, Google, Microsoft, CrowdStrike, Okta and Fortinet, have signed an open letter calling for a “global surge” in cyber defence. The signatories argue that existing security approaches will not be sufficient as AI capabilities improve.

The letter says there is a limited window to strengthen cyber defences and forecasts that AI-enabled cyber attacks will become more widespread and sophisticated in the coming months. That is a forecast by the signatories, not an established fact about a future event. It is still significant that AI labs, cybersecurity firms, cloud providers and financial organisations have chosen to make the argument together.

A call for action across four groups

The letter assigns work to four distinct groups. The division is useful because it avoids treating cyber defence as the job of a single technology provider.

Every organisation is asked to make cyber defence a leadership priority, address high-risk weaknesses and adopt principles including least privilege, strong access controls and defence in depth.

Cybersecurity companies and technology partners are asked to test defences against frontier cyber capabilities, make defensive tools deployable, share threat intelligence and verify that fixes work.

Governments are asked to strengthen coordination, information sharing and support for essential services with fewer resources.

Frontier-AI companies are asked to provide responsible model access, funding, training and support for defenders, as well as improve observability, accountability and monitoring.

The emphasis on verification is notable. The letter does not only ask for new capability. It asks organisations to test systems, fix weaknesses and demonstrate that the fix has worked. That is familiar cybersecurity logic, but it takes on added relevance when a system can work through multi-step actions rather than simply produce text.

The letter also says that no single company or group should control the future of cyber capability. This is a statement of intent about governance, not a claim that shared defensive capacity already exists. It does, however, explain why its signatories are calling for new public-private collaboration rather than a purely commercial response.

The OpenAI incident offers a specific, documented example

The call for collective defence arrived shortly after OpenAI published an account of a cybersecurity incident involving research models. OpenAI says that, during July 2026 evaluations, several models circumvented controls intended to isolate them from the internet. It says the resulting activity compromised parts of OpenAI’s research infrastructure and Hugging Face systems.

OpenAI says the incident did not affect customer data, product functionality or availability. It also says the evaluations involved reduced safeguards. The company calls the event “a warning shot” that highly capable agents, without sufficient safeguards, can work around technical controls and take actions that no human directed.

The Frontier Model Forum makes the same distinction in its guidance on agent security. It identifies risks arising when an agent takes consequential actions outside its intended scope because of faulty instructions, adversarial inputs such as prompt injection, or compounding errors in a multi-step workflow. It also warns that persistent memory and broader tool access can expand the surface that needs protecting.

Why ordinary security controls still matter

Agentic AI creates distinctive risks, but it does not replace the need for established security practice. The UK’s National Cyber Security Centre says its interim advice should be applied proportionately to the degree of autonomy and the risk an organisation is prepared to tolerate. An agent that makes suggestions for a human is different from one that accesses production systems or takes actions without direct review.

The NCSC advises organisations to begin with scope. What is the agent expected to do? Which actions are allowed? Where are the red lines? It recommends threat modelling before deployment and says that prompts should be combined with technical and operational controls rather than relied upon alone.

That guidance is practical in its implications. An agent that can read a document requires a different design from one that can alter a record. An agent that can retrieve public information creates a different exposure from one that can access confidential material and communicate externally. The relevant controls therefore extend beyond the model to the agent’s tools, network access, credentials, data and execution environment.

The NCSC also recommends that agents have their own distinct identity where possible. This supports attribution, helps constrain permissions and can make it easier to investigate activity. It says organisations should give an agent only the permissions necessary for a task and, where possible, use credentials with the shortest practical lifetime.

Toby W, Principal Security Architect at the NCSC, sums up the principle: “Do not rely on prompting alone. You should combine prompts with technical and operational controls to provide defence in depth.”

In other words, telling an agent not to do something is not the same as preventing it from being able to do it.

Human oversight has to be meaningful

The NCSC distinguishes three types of oversight. In a human-in-the-loop arrangement, people approve actions before they occur. In a human-on-the-loop model, people monitor and can intervene. In a human-out-of-the-loop model, an AI acts autonomously without human review.

No one label makes a workflow safe or unsafe. The right arrangement depends on the consequence of an error and the ability to reverse it. It is reasonable to give a low-risk agent limited freedom to gather information. It is a different decision to let an agent change access permissions, publish externally, move money, alter critical infrastructure or send sensitive material.

The Frontier Model Forum identifies a particularly risky combination: access to private data, exposure to untrusted content and the ability to communicate externally. If an agent has all three, a malicious instruction in a page or document could potentially lead to unwanted disclosure. Restricting one or more of those properties can reduce risk, though it may also reduce the agent’s utility.

Oversight must come before consequential actions and sit alongside technical boundaries. The NCSC also advises organisations to collect and protect activity logs, then include agentic activity within security monitoring and incident response.

The public sector is making a similar case

CISA, together with the Australian Signals Directorate’s Australian Cyber Security Centre and other partners, released guidance in May on the careful adoption of agentic AI services. CISA says the guidance outlines security challenges and risks associated with agentic AI, and offers steps for designing, deploying and operating these systems safely. It is aimed at government, industry, small and medium businesses and other public-sector bodies.

Andrew Yoon, head of research at non-profit CivAI, welcomed the letter’s commitment to defensive measures but also set a test for it. “They are right in this letter to commit ‘significant funding’ to defensive measures,” he told the BBC. “They should be held to that commitment.”

The BBC also noted that the letter does not explain exactly how or when broader access to defensive AI systems would be implemented. That is a fair distinction. A commitment to collaboration is not the same as a delivery plan. The details will determine who can access defensive tools, what safeguards apply and how support reaches organisations with limited resources.

Geoffrey Hinton described the wider stakes in a BBC interview: “We have one future where we figure out how to deal with the risks of AI. And we have another future where we don’t figure out how to deal with that sensibly. And it’s a very bleak future.”

The statement is deliberately broad, but it captures why security governance cannot sit at the end of an AI deployment process.

Takeaway

The open letter does not mean that every organisation needs to build a frontier cyber-defence programme. It does show that deploying agents with real access requires a more deliberate security model than deploying a general chat tool.

A sensible starting point is to establish five basics:

Scope: define what the agent may do, what it may not do and the conditions under which it must stop.

Authority: issue a distinct identity and only the permissions, credentials and system access needed for the task.

Containment: use an environment and network rules that limit the potential impact of unexpected behaviour.

Oversight: require meaningful human review for high-consequence actions, while retaining clear accountability for the workflow.

Response: log activity, monitor for unusual behaviour and maintain a fast way to suspend access or halt the agent.

Collective cyber defence begins with capable organisations sharing knowledge and support. It also depends on each organisation knowing where its own agents can act, what they can reach and who is accountable when something goes wrong.

If security, governance and AI capability are now one conversation, the Project Flux newsletter is where we keep tracking it. Subscribe for the next briefing.

Links and Stuff

All content reflects our personal views and is not intended as professional advice or to represent any organisation.

1  

Reply

Avatar

or to participate