Collective Cyber Defense: Why Prophet Security Signed OpenAI's Open Letter

Collective Cyber Defense: Why Prophet Security Signed OpenAI's Open Letter

Vibhav Sreekanti
Vibhav Sreekanti
August 27, 2026

Prophet Security has signed "A call for collective action on cyber defense," the open letter published by OpenAI and co-signed by more than 100 organizations across the AI and security industries. Signatories include Anthropic, Microsoft, Google, and CrowdStrike. The letter opens with a plain warning: "We have a limited window to strengthen cyber defenses." We signed because the letter reflects what we see in security operations every week, and because its collective cyber defense commitments ask something specific of companies building agentic AI, which includes us.

What the collective cyber defense letter says

The letter makes three arguments.

  1. First, that status quo security will not be enough: "Longstanding bugs, excessive permissions, misconfigurations, insecure and unpatched software, weak authentication, and technical debt in legacy systems have left systems exposed." None of those are new problems. The letter's point is about tempo: AI-enabled attacks exploit these weaknesses faster and at greater scale than defenses staffed for human-speed attackers can absorb.
  2. Second, that cyber-capable AI belongs in more defenders' hands, because it "brings specialist skills to more defenders and makes core security tasks faster, cheaper and better."
  3. Third, that signatories should "mobilize a collective response," sharing threat intelligence, tested playbooks, and hands-on support rather than defending alone.

Collective cyber defense, as the letter frames it, is the coordinated commitment by enterprises, security vendors, governments, and AI companies to share threat intelligence, defensive tooling, and hands-on support so that defenses improve at the pace of AI-enabled attacks.

The asks are grouped by who you are.

  1. Enterprises are asked to make cyber defense a leadership priority and to fix high-risk weaknesses "with the urgency and coordination of an incident."
  2. Security companies are asked to help lead the response, including testing defenses continuously against frontier cyber capabilities.
  3. Governments are asked to fund and coordinate cyber defense, starting with essential services.
  4. Frontier AI companies are asked to provide responsible model access, funding, training, and hands-on support, especially for under-resourced critical-infrastructure defenders. They are also asked to ensure agentic identities are traceable and accountable.

AI is compressing the timeline on both sides

The letter expects that "in the coming months, AI-enabled cyber attacks will become far more widespread and sophisticated as models around the world become increasingly capable." That prediction matches the evidence we have examined before. AI has mostly made existing attack playbooks faster to execute, a pattern we documented in our analysis of AI cyber attack velocity. Incidents like the Claude Mythos disclosures show how far that compression has already gone. Security leaders tell us the same thing in plainer words: you cannot defend at human speed against machine-speed attacks.

A backlog of known weaknesses was survivable when exploiting it cost attackers weeks of manual effort. The same backlog poses a different risk when reconnaissance, exploitation, and lateral movement are all mostly automated. We’re moving towards a state where attackers can exploit known weaknesses faster than most teams can find and fix them. The letter's answer: collective cyber defense that pools threat intelligence, tooling, and hands-on support so defenders close the gap together.

What "agentic identities are traceable and accountable" asks of the industry

One ask in the letter applies to our work directly: that frontier AI companies "ensure agentic identities are traceable and accountable." The letter directs it at the labs, but it is the right standard for anyone putting agentic systems into production security operations. In practice it means three things: you can identify what an agent is, you can reconstruct what it did and why, and a human owns the authority it acts under.

We build agentic AI for security operations, so this ask lands on us as much as anyone. We think it is the right bar, and we hold ourselves to it. If an AI agent works in your environment, you should be able to see what it did and why, and you should decide what it is allowed to do. Buyers should expect the same answer from every agentic security vendor, ourselves included.

What signing commits us to

The letter's most concrete commitment is to under-resourced defenders, the teams protecting hospitals, utilities, school districts, and mid-market companies with a security staff of one to four.

Those teams are our customers, and they are the reason we exist. The letter's promise of shared intelligence, tooling, and hands-on support is aimed squarely at them, and it is a promise worth signing.

Collective cyber defense works only if each participant brings what it is best positioned to provide. For us, that means standing behind transparency and accountability in agentic systems, and showing up for the small teams defending the infrastructure everyone relies on. A letter is not a defense program, and signing one patches nothing on its own.

It sets a shared direction, and it puts more than 100 signatories on record about the standard their own AI systems should meet. We are glad to be on that record.

The full letter and signatory list are at openai.com/collective-cyberdefense.

Table of contents
Add as Google Preferred Sources

News

Vibhav Sreekanti

Vibhav Sreekanti

Vibhav is the CTO of Prophet Security.