• OpenAI and more than 100 organisations are calling for faster patching, stronger access controls, shared threat intelligence and controlled access to defensive AI
  • The proposal puts more pressure on operators and security suppliers to shorten the time between finding a serious vulnerability and fixing it in production

The fact

OpenAI and more than 100 organisations have called for a coordinated approach to defending against cyber threats as increasingly capable AI tools become available to attackers and defenders. Signatories include Anthropic, Google, Microsoft, AWS, Cisco, Cloudflare, Akamai, AT&T, Deutsche Telekom, Equinix, Nokia, NTT DATA and Palo Alto Networks.

The group wants organisations to fix high-risk vulnerabilities more quickly, strengthen access controls and use temporary safeguards where systems cannot be patched immediately. Security suppliers are also being asked to share threat intelligence, test against advanced AI-enabled attacks and make defensive tools more accessible to critical-infrastructure operators.

Governments and AI developers are given separate roles, including support for under-resourced organisations and controlled access to advanced defensive models. The letter is a voluntary industry initiative rather than a binding standard, regulation or deployment programme.

The assessment

For operators, the pressure falls on the time between discovering a weakness and safely fixing it. Telecom networks, data centres and other critical systems cannot always install a patch immediately. Changes may need vendor testing, maintenance windows and checks to make sure a fix does not interrupt a live service.

If AI helps attackers identify and exploit vulnerabilities faster, those existing procedures have less time to work. Operators may need quicker testing and deployment, while using temporary controls when a permanent fix cannot be installed safely. Security suppliers can help by providing tested mitigations and clearer information about active threats, but the letter does not show that remediation times have shortened yet.

For BTW readers, the practical test is whether the initiative reduces the time serious vulnerabilities remain exposed in live infrastructure without making rushed changes that create new operational problems.

What to watch

Watch for signatories to launch concrete programmes around AI-assisted vulnerability detection, trusted model access, shared threat intelligence and support for critical-infrastructure operators. Published data on patching or containment times would provide stronger evidence than additional signatures. Funding or technical assistance for operators that cannot quickly replace or patch legacy systems would also show the initiative moving into practice.