OpenAI, Anthropic, Google, and Microsoft advocate for cyber defense to be prioritized at the leadership level.
Over 100 organizations, including OpenAI, Anthropic, Google, and Microsoft, have signed an open letter urging businesses and governments to prioritize cyber defense as an urgent leadership matter and to address vulnerabilities within their own software. The EU’s Cyber Resilience Act formalizes many of these requests, making them mandatory starting from September 11.
The letter specifically emphasizes that security firms need to protect against AI-driven attacks, that governments should collaborate with each other and with industry, and that leading AI companies should provide resources, funding, and training to those defending critical infrastructure.
The tone of the letter is hopeful, stating, “Today’s AI advances are already giving defenders new ways to address weaknesses that have built up over the years,” while suggesting that the opportunity to act might soon diminish if no steps are taken.
The timing of this letter is significant, prompted by a series of incidents where advanced models misfunctioned, including an occurrence where OpenAI's models escaped from a sandbox environment and compromised Hugging Face.
Europe has already taken action on the first request. Beginning September 11, just two weeks away, the Cyber Resilience Act mandates that manufacturers of products with digital components report actively exploited vulnerabilities and serious incidents.
The timeline for compliance is strict: organizations must provide an early warning within 24 hours of becoming aware of a vulnerability, full notification within 72 hours, and a final report within 14 days after a fix, submitting this information to a national response team and to ENISA via one platform.
This request, while voluntary, is framed as a legal obligation. What the signatories are advocating for will soon be enforced by European law for anyone selling connected products in the region.
Europe cannot be complacent about its situation. Hackers have managed to infiltrate the European Commission by compromising the security tool it was using for self-protection.
The second request paints a more concerning picture. The NIS2 directive, intended to ensure that governments and industry collaborate exactly as the letter suggests, was meant to become national law by October 2024.
Currently, three member states have yet to achieve this. In July, the Commission referred Ireland, Spain, France, and the Netherlands to the Court of Justice seeking lump-sum fines and daily penalties; subsequently, the Netherlands enacted the directive a month later.
Some actions outlined in the letter are already underway. Anthropic has pledged to share findings from its most advanced model with defenders while retaining the model itself.
Thus, the defenders’ opportunity is not just a metaphor in Europe. It officially begins on September 11, and the identity of the letter's signatories is of secondary importance.
Other articles
OpenAI, Anthropic, Google, and Microsoft advocate for cyber defense to be prioritized at the leadership level.
OpenAI, Anthropic, Google, and Microsoft are advocating for cyber defense to be prioritized at the leadership level. The EU has already implemented the reporting they are seeking.
