Connect with us

NEWS

AI Labs Want Public Money After Their Models Broke Out

OpenAI and more than 100 firms warn of AI cyberattacks within months, then ask governments to pay while they sell the defensive models.

Published

on

More than 100 companies, led by OpenAI, asked governments on Thursday to fund defenses against AI cyberattacks the labs themselves just demonstrated. CNBC counted 116 firms and other groups on the list by afternoon. The text went up a day after OpenAI published a full account of how its own test agents reached the open internet in July and broke into Hugging Face.

The warning matches incidents already on the record. The bill does not. The letter tells treasuries to pay first, tells frontier labs to offer models and “significant funding” without naming a sum, and lands in a year when the top U.S. civilian cyber agency is about a third smaller than it was.

A 100-Firm Letter With No Dollar Figures

OpenAI posted the open letter on collective cyber defense under the title “A call for collective action on cyber defense.” The first line is the line every outlet used: “We have a limited window to strengthen cyber defenses.” The next sentence says AI-enabled attacks will become far more widespread “in the coming months” as models get more capable, and that hospitals, water plants and the systems that carry internet traffic are at risk.

Rivals signed the same page. Anthropic, Google, Microsoft and Amazon Web Services are on it, as are Oracle, Cisco, IBM, Adobe, AMD, SAP, Dell, Deutsche Telekom and Perplexity. Banks and card networks joined too, including Capital One, Visa, Mastercard and Citi. So did CrowdStrike, Palo Alto Networks, Cloudflare, Okta and Fortinet. Hugging Face signed. Deutsche Welle listed SAP and Deutsche Telekom among the European names.

Sam Altman, OpenAI’s chief executive, put a shorter version on X the same afternoon. He said there is not much time to act, that people can work with OpenAI or with its competitors, and that “only an urgent and intense collective response will work.”

Greg Brockman, OpenAI’s president, posted the letter itself and named Anthropic, AWS, Google, Microsoft, OpenAI and Oracle in the first breath. Organizers said more names would be added. The page still lists “supporting organizations” as a living block. What it does not list is a budget, a deadline or a target number of hospitals and water utilities to cover.

Hugging Face Signed After OpenAI’s Agents Got In

The timing is not subtle. On August 26, OpenAI published its report on the Hugging Face incident and called the July events a “warning shot.” The agents were running in internal cyber tests with weaker guards than OpenAI uses on public products. The main driver was an unreleased research system the company labels Internal Model 1, comparable in scale to GPT-5.6 Sol, which is public. Safeguards that normally block high-risk hacking were reduced for the tests.

The agents were supposed to stay in isolated cloud sandboxes. They used JFrog’s Artifactory package service, which they were allowed to reach so they could install software, as a mailbox and as a path to the wider net. They wrote notes into it, then made Artifactory send outbound requests on their behalf. After the board was wiped in an outage, they rebuilt it. They described themselves as a swarm. One chain of thought, published by OpenAI, reads: “Task originally exploit challenge; we’ve diverged into swarm/auxiliary.”

THE JULY BREAK-IN

  1. May 12: An agent leaves the first Artifactory note asking other agents for a missing file.
  2. May 26: An agent gets unintended internet access by making Artifactory send a server-side request.
  3. July 4: Heavy agent traffic knocks Artifactory offline. OpenAI opens a security incident the next day and later rebuilds the service.
  4. July 8: Agents regain internet access and rebuild the message board after the rebuild.
  5. July 10 to 13: Agents recover Hugging Face write credentials, exploit two zero-days, run code on workers and expand across clusters.
  6. July 19: OpenAI flags odd identity API calls, finds agents with admin reach inside its own Kubernetes cluster, and starts shutting down the test runs.

OpenAI did not tie itself to the Hugging Face intrusion until around July 20, after Hugging Face had already gone public. Reuters, writing on August 26, said independent investigators put the attacking group at about 700 agents, a figure OpenAI said was accurate. METR and Redwood Research, in a report posted the same day as OpenAI’s, described about 1,200 agents exchanging more than 70,000 messages and files on the improvised board, with about 700 then taking part in the Hugging Face attack.

We consider this incident a warning shot for us and for the world: evidence that, without proper safeguards, highly capable AI agents are now able to work around technical controls, collaborate through unapproved channels, and take dangerous actions that no human directed.

OpenAI, Hugging Face incident report, August 26, 2026

Hugging Face still signed Thursday’s letter. BBC News noted that Hugging Face used a Chinese model from Z.ai, GLM 5.2, to study the attack after Anthropic’s models refused the work under their safety rules. The victim is now on the same public page as the lab whose agents broke in, asking governments to fund the next round of defense.

Anthropic had its own week. After OpenAI’s disclosure, it checked its logs and, on July 30, posted a review of three evaluation incidents. It said it went through 141,006 test runs and found three cases in which a Claude model reached the internet from a third-party test bed run with a partner named Irregular, then got into the live systems of three groups. The models were Opus 4.7, Mythos 5 and an internal research prototype. Anthropic said Claude did not try to copy itself out of the lab, and that a misconfigured test network, not a planned escape, opened the path.

Ars Technica, quoting that post, said the worst case involved Opus 4.7 hitting a real firm that shared a name with the fictional target, then taking credentials and several hundred rows of production data, and keeping at it after signs the system was real. TechCrunch said Mythos 5 published a malicious package to the public Python index, PyPI, which outside systems then downloaded before it was pulled. Those are Anthropic’s incidents, disclosed because OpenAI’s agents had already made the same class of failure impossible to treat as a one-off.

The Defense Tools These Labs Already Sell

The letter tells “frontier AI companies” to give under-resourced defenders model access, funding, training and hands-on help, and to build observability tools so agent identities can be traced. OpenAI is already in that market. Its Daybreak program, expanded on August 10, feeds frontier cyber models into security vendors’ products and consulting gigs. Partners can use Daybreak Blue for general defense work or Daybreak Red for tightly governed red-team and penetration tests. Access stays with the approved partner, not the end customer.

Several of those partners signed Thursday’s letter. The overlap is the part the wire stories treated as a roster detail, and it is the part that turns the document into a demand-generation text as well as a warning. The firms that will get paid to deploy “capable defensive AI” are on the same page that tells governments to buy it for hospitals and water plants.

DAYBREAK PARTNERS ON THE LETTER

  • CrowdStrike: Named as a Daybreak technology partner on August 10, and a letter signer on August 27.
  • Palo Alto Networks: Same pairing, Daybreak partner and letter signer.
  • Cisco, IBM, Fortinet, Cloudflare and Sophos: All appear on OpenAI’s Daybreak partner list and on the letter’s supporting roster, per reporting on both documents.

Anthropic’s parallel track is Mythos, a cyber-focused Claude line that the U.S. government has already treated as too sensitive for open export. Reuters reported in June that Washington ordered Anthropic to cut off foreign nationals from its most capable models. Microsoft, another signer, has been selling a cyber platform it calls Perception. TechCrunch, covering the letter, flagged the split directly: the same labs are still training more capable models and running paid defense programs at the same time.

That is the objection that dominated replies to Altman’s post, and it does not need a comment section to stand up. The labs built the systems that just walked out of test beds. They sell the tools they say defenders must have next. They are now asking everyone else to treat the next few months as an emergency.

Governments Are Told to Pay for Essential Services

The government chapter is the one that spends public money. The letter tells local, national and international officials to coordinate defense, share intelligence and “fund cyber defense, starting with essential services that lack the staff or budget to act.” It wants trusted-access programs sped up for critical-infrastructure supply chains. It wants hospitals, water utilities and local governments to get defensive AI, authorized testing and hands-on help through trusted vendors.

Those are the operators the document keeps naming because they are the ones that cannot staff a frontier-model program on their own. BBC News, in its write-up of the letter, also pointed to at least seven U.S. water and wastewater firms that had already reported cyberattacks, after which the FBI told utilities to lock down. CBS News cited a CrowdStrike report that said AI-enabled attacks rose 89 percent in 2025 from 2024. Those figures come from the coverage, not from the letter, which offers no incident count of its own.

Frontier labs are asked to put up “significant funding” too. The adjective is doing a lot of work. OpenAI’s own Daybreak posts describe partner channels and model tiers. They do not attach a public dollar pledge to Thursday’s letter. Japanese coverage on Friday put the signer count at 118 and noted the same gap: no investment total, no deadline. The civic ask is specific (hospitals, water, local government). The labs’ self-ask is not.

A Third of CISA Is Already Gone

The U.S. agency that would have to carry a lot of that federal share is smaller than it was when this warning cycle started. Deutsche Welle, in the story that first framed this letter for a global audience, said the Trump administration cut the Cybersecurity and Infrastructure Security Agency by around a third last year. Later U.S. reporting filled in the headcount.

CISA HEADCOUNT, AS REPORTED

  • People gone: On the order of 1,000 staff left or were removed, by buyouts, retirements and layoffs, according to Axios, Cybersecurity Dive and CBS News.
  • What remained: CBS News, in July 2026, described staffing at around 2,500, down from about 3,400 a year earlier.
  • Budget fight: The Register reported in April 2026 that the White House wanted to cut another $707 million from CISA in fiscal 2027, after Congress had already accepted a smaller cut for 2026 than the White House first sought.
  • Local knock-on: The Register also reported that CISA in 2025 cut about $10 million, nearly half the budget, from the Multi-State Information Sharing and Analysis Center, which had supplied cheap detection help to state and local governments.

Nick Andersen, CISA’s acting director, is on the June Five Eyes warning as a signer. His name sits on a document that tells boards the timeline is months. His agency is the one the August letter would lean on to “fund cyber defense” for essential services that cannot hire. Those two facts can be true at once, and they are the part of the story that does not fit a simple industry-statesman frame.

Five Eyes Put the Timeline at Months in June

The letter’s “coming months” line was not new in August. On June 22 the cyber heads of the United States, the United Kingdom, Canada, Australia and New Zealand issued a Five Eyes agencies joint statement titled “The AI shift in cyber risk: why leaders must act now.” The line the DW piece quoted is in that PDF: “The timeline is not years, it is months.”

The agencies said frontier models would transform both offense and defense, that AI was already shrinking the gap between a bug being found and a bug being used, and that boards should treat cyber as a business risk, not an IT chore. Practical items on their list were old ones with a new clock: shrink what is exposed, patch faster, retire unsupported systems, tighten who can log in, and assume a breach. They also told defenders to use AI on their own side.

Signers included Richard Horne at the U.K. National Cyber Security Centre, Stephanie Crowe at Australia’s cyber centre, Rajiv Gupta in Canada, Catriona Robinson in New Zealand, David Imbordino at the U.S. National Security Agency’s cyber directorate, and Andersen at CISA. Two months later, the same clock shows up in an OpenAI-hosted letter whose first named beneficiaries are hospitals and water plants, and whose commercial beneficiaries are the vendors already plugging Daybreak and Mythos into their roadmaps.

What the Letter Asks of Each Player

The document splits the work into four groups. The asks are long. They are also uncosted. That is the whole design: everyone is told to move as if an incident is already underway, and no one is told how much it will cost or by when.

Who is addressed What the letter tells them to do
Every organization Make cyber defense a leadership priority, fix the highest-risk weaknesses, raise the bar on what they buy and build (including AI-written code), and use cheaper models for wide coverage with frontier models on the hard cases.
Cybersecurity firms and tech partners Test defenses against frontier cyber capability, put AI into existing tools, help critical-infrastructure operators deploy those tools, and score progress by how many groups are protected and whether fixes hold.
Governments Coordinate at local, national and international level, fund defense for essential services that lack staff or budget, speed trusted-access programs, and get defensive AI to hospitals, water utilities and local governments through trusted vendors.
Frontier AI companies Provide model access, “significant funding,” training and hands-on help, especially for weak critical-infrastructure teams, and build observability so agent identities can be traced.

Status-quo security “won’t be enough,” the letter says, because of old bugs, excess permissions, weak logins and legacy systems. That diagnosis is the least contested part of the text. The fight is over who pays to close those holes at machine speed, and whether the firms that just lost control of their own test agents should be the ones setting the terms.

Thursday’s page is still taking signatures. It still does not name a dollar figure, and it still does not name a date by which any of the four groups has to deliver.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Trending