# 1Password signs OpenAI open letter calling for collective action on cyber defense

> Source: <https://1password.com/blog/openai-open-letter-cyber-defense>
> Published: 2026-08-28 00:00:00+00:00

[ OpenAI’s open letter](https://openai.com/collectivecyberdefense/) on collective cyber defense warns that defenders have a limited window to strengthen security. It urges organizations to fix their highest-risk weaknesses, build least privilege and strong access controls, verify fixes, and make agentic identities traceable and accountable.

The real work is building the ecosystem that lets them act safely and earn trust in production. That is why we continue working with OpenAI on trusted access for people and their agents. 1Password integrations with [ OpenAI](https://www.1password.dev/cli/shell-plugins/openai),

Cyber defense is a leadership responsibility. AI changes who and what can act inside the most sensitive systems, so identity security can no longer stop at human login. OpenAI is right to call for urgency, coordination, and fixes that organizations can verify without disrupting essential services. The standard is simple: every agent needs an identity, a boundary, and an audit trail.”

–Nancy Wang, Chief Technology Officer, 1Password

Every security organization balances known weaknesses, technical debt, and limited time. The challenge for CISOs is deciding where to focus first and finding controls that reduce risk across the environment where AI is changing who and what can act inside an organization. Agents that work across browsers, repositories, terminals, cloud infrastructure, and production systems create a security challenge that begins before they take action.

Standing access gives an agent more authority than a specific task requires and keeps it available after the task ends. If the agent is compromised or follows untrusted instructions, that extra authority increases risk and makes containment harder.

Credential abuse appeared in 39% of breaches in the [ 2026 Verizon Data Breach Investigations Report](https://www.verizon.com/business/resources/reports/dbir/), more than any other tracked action. The report warns that service and machine accounts will require increased scrutiny as agentic workflows mature.

A June 2026 [ developer pulse survey conducted by 1Password](https://1password.com/blog/survey-ai-agent-adoption-is-outpacing-governance) found that 53% of technical employees give AI agents overly permissive access, with 40% granting persistent access to systems or credentials.

That is why high-risk workflows need access scoped to the task, limited in time, and revoked when the work is complete. [ 1Password Privileged Access](https://1password.com/product/privileged-access) applies that model to cloud infrastructure, databases, Kubernetes, and other sensitive environments.

Developers need credentials to build and ship software, including with AI-assisted coding tools, but these should not be hardcoded into source code or left in plaintext files where AI tools can find them.

GitGuardian’s [ State of Secrets Sprawl 2026](https://www.gitguardian.com/files/the-state-of-secrets-sprawl-report-2026) found 28.65 million new hardcoded secrets in public GitHub commits in 2025, a 34% year-over-year increase.

[ 1Password Environments](https://1password.com/blog/secure-developer-secrets-with-1password) gives developers a secure place to store and use secrets without saving plaintext values on disk or committing them to open-source repositories.

[ 1Password Credential Broker](https://1password.com/product/credential-broker) extends the same model to automated workloads. It authenticates machine workloads and AI agents at runtime and delivers only the credentials they are approved to receive. A workload proves its identity through Workload Identity Federation. A trust policy evaluates the request, and the approved credential is delivered with attribution to the workload and the policy that authorized it.

Together, Credential Broker and Privileged Access help organizations move away from broad, static access and toward authority that is tied to identity, context, and the work being performed.

No one company can solve the AI security problem alone. Model providers, security companies, enterprises, and policymakers need a shared understanding of what responsible deployment looks like.

To advance shared knowledge in the field, 1Password security research group [ Off-by-1 Labs](https://1password.com/blog/why-ai-generated-patches-still-require-human-review) reported that AI-generated patches failed to resolve a vulnerability, introduced a new one, or both in 53.9% of cases. The inaugural article shares the research, tooling, datasets, and methodology that help defenders test whether AI-generated fixes work before they reach production.

These findings point toward an ecosystem where agents can work across tools and systems without inheriting a human’s entire identity.

Collective cyber defense will depend on making the secure path the natural path. Organizations should be able to adopt AI faster because they know the boundaries, how to revoke access, and who remains accountable when something goes wrong.

See how 1Password Unified Access helps organizations discover, secure, and audit access.

1Password is redefining identity security for how people and AI agents work today. The 1Password Unified Access platform discovers and secures identities and credentials, establishes trusted access, and audits actions across human and AI agents. 1Password SaaS Manager helps organizations discover and secure access to SaaS applications while optimizing spend. 1Password’s enterprise vault protects more than 1.5 billion credentials and secrets and is trusted by more than 1 million developers and over 200,000 businesses, including Canva, CIBC Capital Markets, Cursor, Dust, ElevenLabs, Figma, GitHub, HackerOne, Hugging Face, MongoDB, Notion, Perplexity, Salesforce, Stripe, Vercel, Wiz, Workday, and Zscaler.
