OpenAI published an open letter on Thursday with a little over 100 signatures. That’s not a lot. And when you run the numbers, it reveals some interesting patterns.
For example, there are four targeted audiences for a “what needs to happen next” section:
- every organization
- cybersecurity companies
- governments
- frontier AI companies
And then it differentiates who it considers victims:
- hospitals
- water treatment plants
- infrastructure that powers the internet
Already it’s getting weird. Why aren’t governments in the victim list? Or what about every organization being in the list? I don’t get it and neither should you. This is not a letter that makes much sense.
Let me explain further. Two of the four targeted audiences signed: the vendors, nearly to a company, and a scattering of enterprise buyers who fall under “every organization.” Zero governments. Zero from any of the three named victim sectors. That is to say, plainly, there is no hospital, no water utility, no government, no regulator, no standards body beyond the one that runs a federal ISAC, and no operator of the internet backbone the letter says is at risk, signing it.
The people asked to act did not sign. The letter was signed by the people selling the thing it says is needed, plus a few of their customers.
That’s the whole game. It’s perhaps the dumbest possible version OpenAI could have published. Either the victims were never asked, in which case this is a vendor letter to buyers dressed as a coalition, or they were asked and declined, in which case the people the forecast is all about do not believe in it. Either way, this letter doesn’t pass a basic sniff test.
Tables are great
I thought maybe it would be fun to list each sector by the distance between what the letter claims and who actually signed. Think of it as a buyers guide, so you can easily migrate away from the brands who signed this strange letter. Rank 1 is the largest gap.
| Rank | Sector | What the letter says | Signed | Absent |
|---|---|---|---|---|
| 1 | Water, energy, utilities | Named victim, named funding recipient, named access recipient | none | American Water, Veolia, Suez, Xylem, Duke, Exelon, NextEra, E.ON, EDF, Enel, National Grid, Colonial Pipeline |
| 2 | Healthcare | Named victim, named access recipient | none | UnitedHealth / Change Healthcare, Ascension, HCA, Kaiser, Mayo, Epic, Oracle Health, Philips, GE HealthCare, Siemens Healthineers, McKesson, CVS, NHS |
| 3 | Government, regulators | Entire section 03: fund, coordinate, expand trusted access, impose costs | none | CISA, NSA, NCSC, BSI, ENISA, CAISI, UK AISI, NIST, FBI, Europol |
| 4 | OT / ICS security | The vendors who defend rows 1 and 2; “critical infrastructure supply chain manufacturers” named | none | Dragos, Claroty, Nozomi, Armis, Forescout, Schneider, Siemens, Rockwell, Honeywell, ABB, Emerson |
| 5 | AI security (securing the model, the agent, its data) | “Build observability and security tools, ensure agentic identities are traceable and accountable” | none independently; Protect AI, Lakera, Prompt Security, Robust Intelligence and CalypsoAI only via acquirers Palo Alto, Check Point, SentinelOne, Cisco and F5 | Knostic, Wirken, Zenity, Noma, Pillar, Lasso, HiddenLayer, Mindgard, Aim Security, Cloud Security Alliance |
| 6 | Standards, coordination | “Verified fixes,” “private disclosure,” CVE throughput | Center for Internet Security | MITRE, CVE Program, FIRST, OWASP, OpenSSF, ISACA, ICANN, IETF, Internet Society, EFF |
| 7 | Telecom | Named victim: “infrastructure that powers the internet” | Deutsche Telekom, Lumen | AT&T, Verizon (Salt Typhoon victims), T-Mobile US, Orange, BT, Vodafone, Telefonica, NTT, Comcast, Nokia, Ericsson |
| 8 | Operating systems, open source | “Open-source maintainers” named as recipients; “longstanding bugs” is their code | Red Hat, Hugging Face | Linux Foundation (Glasswing partner), Canonical, SUSE, Apache, Debian, Mozilla, Python Software Foundation, OpenSSL, curl, Rust Foundation |
| 9 | Internet-scale observation | The only parties who could measure “far more widespread” | none | Shodan, Censys, GreyNoise, watchTowr, Shadowserver, abuse.ch |
| 10 | Logistics | Among the largest documented losses from one automated attack | Flexport | Maersk, FedEx, UPS, DHL, C.H. Robinson |
| 11 | Automotive | Sector-scale supply chain and OT exposure | General Motors | Ford, Stellantis, Toyota, Volkswagen, BMW, Mercedes, Tesla, Hyundai, Rivian |
| 12 | Insurance | Hold the loss data the letter never cites | Zurich, Marsh | Chubb, AIG, Beazley, Coalition, At-Bay, Resilience, Munich Re, Swiss Re, Lloyd’s, Aon, WTW, Gallagher |
| 13 | Identity, PKI | “Agentic identities traceable and accountable” | Okta, 1Password | DigiCert, Sectigo, Entrust, Let’s Encrypt / ISRG, GlobalSign, Ping, Yubico, Bitwarden |
| 14 | CDN, edge | “Infrastructure that powers the internet” | Cloudflare, Akamai, F5 | Fastly, Imperva, Netlify, Bunny |
| 15 | Dev platforms, AI code | “Raise the security bar for AI-generated code” | Cognition, Lovable, Replit, Vercel, Factory, Figma | GitHub, GitLab, Cursor, JetBrains, Atlassian, StackBlitz, Sourcegraph |
| 16 | Consulting, integrators | “Hands-on support” | Accenture, Capgemini, Cognizant, KPMG, PwC, Oliver Wyman, IBM, Unisys, WWT | Deloitte, EY, McKinsey, BCG, Booz Allen, Leidos, SAIC, CACI, Kroll, Optiv, GuidePoint, TCS, Infosys, Wipro, Atos |
| 17 | Vuln research, bounty, audit | “Authorized testing, private disclosure” | HackerOne, Trail of Bits, SpecterOps, Cantina, Zero Day Initiative (via TrendAI) | Bugcrowd, Synack, Intigriti, NCC Group, Bishop Fox, IOActive, Cobalt, Semgrep (OpenAI grantee), iVerify (Trusted Access participant) |
| 18 | Banks | Buyers; Trusted Access participants | Capital One, Citi, Fifth Third, U.S. Bank, NAB, Nationwide | JPMorgan (Glasswing, Trusted Access), Bank of America, Goldman, Morgan Stanley, Wells Fargo, BNY, HSBC, Barclays, Deutsche Bank, Commerzbank, UBS, Santander, BNP, ING |
| 19 | Payments, market infrastructure | Buyers | Mastercard, Visa, FIS, Fiserv, DTCC, The Clearing House, Block, Robinhood | Amex, PayPal, Stripe, SWIFT, Nasdaq, ICE, CME, Deutsche Borse, Euroclear, Coinbase |
| 20 | Enterprise software | Buyers and patch sources | SAP, ServiceNow, Adobe, Snowflake, Elastic, Incident.io | Salesforce, Workday, Databricks, Intuit, Autodesk, Zoom, Dropbox, Box |
| 21 | Retail, commerce | Buyers | Shopify, GoDaddy | Amazon retail, Walmart, eBay, Target, Home Depot, Alibaba, Automattic |
| 22 | Credit bureaus | Buyers | TransUnion | Equifax, Experian |
| 23 | Funds, private equity | Capital behind the sellers | Citadel, ExodusPoint, Advent | BlackRock (Trusted Access), Thoma Bravo, Vista, KKR, Blackstone, Insight, a16z, Sequoia, Altimeter, Greylock, Lux, Battery, ICONIQ |
| 24 | Silicon | Compute | AMD, Arm, Micron, Broadcom | NVIDIA (Glasswing, Trusted Access), Intel, Qualcomm, TSMC, Samsung |
| 25 | Hyperscale cloud | Compute | AWS, Google, Microsoft, Oracle, IBM | Alibaba Cloud, Hetzner, OVH, Scaleway, DigitalOcean |
| 26 | Frontier labs | Authors; section 04 is their own commitments | OpenAI, Anthropic, Google, Microsoft | Meta, xAI, Mistral, Cohere, NVIDIA, Apple |
| 27 | Security incumbents | Sellers | CrowdStrike, Palo Alto, Zscaler, SentinelOne, Fortinet, Check Point, Cato, Sophos, Proofpoint, Tenable, Okta, Darktrace, Cisco, TrendAI (Trend Micro) | Rapid7, Qualys, Netskope, Wiz (Google), Arctic Wolf, Huntress, Tanium |
| 28 | AI-native offense and SOC startups | Sellers | XBOW, RunSybil, Tenzai, depthfirst, Calif, Cogent, Corridor, Octane, Prophet, Dropzone, Cotool, Outtake, Abnormal, Aikido, APIsec | Horizon3, Pentera, Sublime, Torq |
I guess I could have expanded the list of people who didn’t sign. It’s massive. The letter really does speak to something strange. Rows 1 through 5 are the letter’s stated purpose with zero independent signatures. Zero. Row 26 is its authors and rows 27 and 28 are their sales channel, where suddenly there’s near-complete coverage.
The signature density is the total inverse of the stated priority.
Thoma Bravo owns three of the security signatories, Darktrace, Sophos and Proofpoint, but for some reason it did not sign. Maybe it’s waiting to see how bad the reaction is. I found it especially odd that Merck, FedEx and Maersk, the three companies with the largest documented losses from NotPetya, did not sign. They felt the pain and said no to this letter. AT&T and Verizon, the carriers Salt Typhoon lived inside for a year, did not sign. Lumen, named alongside them in the original reporting, did sign, which makes it a signatory with a documented state intrusion in its own network and nothing to say about it in the letter. MITRE, which runs CVE, and FIRST, which runs CVSS, are absent completely in a letter about surging vulnerability throughput. Because why?
When “global” means America
I went with 108 of the 116 signatories because eight could not be verified. I almost did this by city, because it’s basically all America, but let’s start with nations.
| Country | Count | Signatories |
|---|---|---|
| United States | 87 | Abnormal AI, Accenture, Adobe, Advent International, Akamai, AMD, Anthropic, APIsec, AWS, Block, Broadcom, Calif, Cantina Security, Cape, Capital One, Center for Internet Security, Cisco, Citadel, Citi, Cloaked, Cloudflare, Cogent Security, Cognition, Cognizant, Corridor, Cotool, CrowdStrike, Dell, depthfirst, Dropzone.ai, DTCC, Equinix, EXA.ai, ExodusPoint, F5, Factory, Fifth Third Bank, Figma, FIS, Fiserv, Flexport, Fortinet, General Motors, GoDaddy, Google, HackerOne, Hugging Face, IBM, KPMG, Lumen Technologies, Marsh, Mastercard, Mercor, Micron, Microsoft, Obsidian Security, Octane Security, Okta, Oliver Wyman, OpenAI, Oracle, Outtake AI, Palo Alto Networks, Perplexity, Proofpoint, Prophet Security, Red Hat, Replit, Robinhood, RunSybil, SentinelOne, ServiceNow, Snowflake, Snyk, Socket, SpecterOps, Tenable, The Clearing House, Trail of Bits, TransUnion, U.S. Bank, Unisys, Vercel, Visa, WWT, XBOW, Zscaler |
| United Kingdom | 6 | Arm (SoftBank-owned), Darktrace (Thoma Bravo-owned), Incident.io, Nationwide Building Society, PwC, Sophos (Thoma Bravo-owned) |
| Israel | 4 | Cato Networks, Check Point, Cyera, Tenzai |
| Canada | 2 | 1Password, Shopify |
| Germany | 2 | Deutsche Telekom, SAP |
| Netherlands | 1 | Elastic |
| Australia | 1 | National Australia Bank |
| Belgium | 1 | Aikido |
| France | 1 | Capgemini |
| Japan | 1 | TrendAI (Trend Micro) |
| Sweden | 1 | Lovable |
| Switzerland | 1 | Zurich Insurance Company |
Eighty percent of verified signatories are American. That’s funny for a “global response” letter.
Israel supplies four, all security vendors, because of course. The European Union, where NIS2 and DORA already impose the incident reporting and remediation duties the letter asks for, supplies a measly six: two German, one Dutch, one Belgian, one French, one Swedish.
And then China, India, South Korea, Taiwan, Brazil and every African and Latin American state supply zero.
The letter calls for a “global response” and “new partnerships” and signs itself with 87 American companies, four Israeli security vendors, one Japanese antivirus company under a five-month-old name, and six companies from the European Union.
I guess it’s like how baseball has a world series, or so I’m told.
The cartel thing again
Section 03 asks governments to “expedite the expansion of trusted access programs.”
Section 04 commits frontier companies to “responsible model access.”
Ok, so those programs exist and the letter’s authors are the ones who run them. OpenAI’s Trusted Access for Cyber named its participants on April 16: Bank of America, BlackRock, BNY, Citi, Cisco, Cloudflare, CrowdStrike, Goldman Sachs, iVerify, JPMorgan Chase, Morgan Stanley, NVIDIA, Oracle, Palo Alto Networks, SpecterOps, US Bank and Zscaler, plus grant recipients Socket, Semgrep, Calif and Trail of Bits. Anthropic’s Project Glasswing named Amazon Web Services, Apple, Broadcom, Cisco, CrowdStrike, Google, JPMorganChase, the Linux Foundation, Microsoft, NVIDIA and Palo Alto Networks on April 7. On August 10 OpenAI split Daybreak into Blue and Red tiers, both gating “limited-access frontier cyber models” to approved customers.
Overlay what’s being recommended in the letter with who is in and who is out.
Of 17 Trusted Access participants, nine signed and eight did not. Of the four grant recipients, Socket, Calif and Trail of Bits signed and Semgrep did not. Eight Glasswing partners signed and four did not. Apple, NVIDIA, JPMorgan and the Linux Foundation hold Mythos access and declined to endorse the letter. Bank of America, Goldman, Morgan Stanley, BlackRock, BNY and iVerify hold GPT-5.4-Cyber access and declined. The companies already inside are split on whether to ask governments to do this or not.
Only the companies selling are who signed unanimously.
The anchor for “in the coming months” is also suspect. Says who? OpenAI? Their Defender’s Window post describes an agentic collective that autonomously penetrated OpenAI research infrastructure and Hugging Face production infrastructure during an evaluation. Hugging Face signed. The letter cites the incident nowhere, and skips the detail that the agents got in by chaining unknown bugs with credentials already leaked on the internet. Half of that is a zero-day story. The other half is a password story.
The letter contains no incident data, no actual science or references to forecasts. Its signatories perhaps should have contributed theirs. F5 disclosed in October 2025 that a nation-state actor held persistent access to its BIG-IP development environment and took source code. Capital One paid an $80 million OCC penalty for the 2019 breach of 106 million records. TransUnion disclosed a 4.4 million-person breach in August 2025. Snowflake’s 2024 customer breaches, Okta’s 2023 support-system breach, Oracle’s disputed 2025 cloud breach, CrowdStrike’s July 2024 outage. Every one of those companies signed. None of their data appears in a letter that claims it can predict what the next few months hold.
Follow the money
Tenzai raised $75 million in seed funding in November 2025 on the pitch that enterprises spend five dollars on services for every dollar on product and AI can take the services market. Outtake’s $40 million Series B in January lists Satya Nadella, Nikesh Arora, Shyam Sankar and Trae Stephens as investors; OpenAI is a customer. The Microsoft CEO and the Palo Alto CEO hold personal equity in one signatory that sells to another. Trend Micro renamed its enterprise business TrendAI on March 23 and signed under the new name five months later. Center for Internet Security runs MS-ISAC, whose federal cooperative agreement CISA ended on September 30, 2025; the letter’s “fund cyber defense, starting with essential services” is its own budget request, and it is the only nonprofit I could verify on the list.
What the letter should have said
Section 04 commits frontier companies to “responsible model access.”
Section 03 asks governments to expedite “trusted access programs.”
Both route defensive capability through the labs themselves. Trusted Access for Cyber and Daybreak Blue and Red are a thing OpenAI is selling, and the letter asks governments to expedite it, two clauses after asking them to fund cyber defense.
The alternative architecture already exists and is totally absent from the list. An operator-run gateway puts the model choice, the credentials, the egress policy and the logs on the defender’s side of the wire. Smart, right?
Wirken, released as open source in February 2026, connects the same agent to Ollama on a local box or to Anthropic, OpenAI, Gemini, Bedrock or NIM through one policy layer the operator controls. The “observability and security tools” and “traceable, accountable agentic identities” the letter says you have to get from the frontier companies are elsewhere. Try using gateway functions shipped under an open-source license. A water utility can run them today without a license fee, let alone applying to a lab for trust.
That is the difference between the last two table rows versus the five at the top. The signatories are selling access to defense, by saying it comes from their model. The absent sectors need control that is durable and cost-effective, less dependency on vendors and more independence from them. The letter is an example of how not to write a letter.