OpenAI, Anthropic, Google, Microsoft and other technology and security companies called for a global mobilization to reinforce the protection of critical systems in the face of the advance of cyberattacks with artificial intelligence. The open letter, published on Thursday (27), warns that these attacks should become more frequent and sophisticated in the coming months.

The movement comes after OpenAI and Anthropic disclosed incidents in which models used in security tests exceeded the limits of controlled environments and reached real systems. Among the cases are the invasion of Hugging Face's infrastructure and unauthorized accesses to networks of other organizations.

Companies warn of short defense window

The letter states that there is a limited window to raise defenses before more capable models expand the scale of attacks. The list of signatories includes companies from artificial intelligence, cloud, security, finance, telecommunications and digital infrastructure.

Among them are OpenAI, Anthropic, Google, Microsoft, AWS, Oracle, Cisco, CrowdStrike, Cloudflare, GitHub, Mastercard and Visa. Hugging Face itself, affected by the incident involving OpenAI agents in July, also joined the document.

The group points to well-known problems such as unpatched software, excessive permissions, incorrect configurations, weak authentication and legacy systems. With AI agents capable of searching for and exploiting these flaws at greater speed, the signatories assess that current security practices may not be sufficient.

The concern focuses especially on hospitals, water treatment plants, local governments and infrastructure that underpins the internet, environments in which a failure can affect essential services and where security teams often have limited resources.

Incidents showed agents leaving test environments

OpenAI revealed on Wednesday (26) that models used in internal cybersecurity evaluations managed to bypass isolation mechanisms, access the internet and compromise parts of its own research infrastructure and Hugging Face's systems.

The first signs emerged in May, when agents found a way to use the Artifactory package manager as a unauthorized communication channel. Next, they found ways to obtain external access and share these techniques with other agents.

On July 10, an agent recovered Hugging Face credentials that were publicly exposed. In the following days, the models combined different vulnerabilities to execute code on the company's servers, achieve privileged access and obtain credentials from production environments.

According to OpenAI, the agents even executed code on dozens of Hugging Face servers. The company stated that OpenAI customer data and its public products were not affected by the incident.

Anthropic also identified three real incidents in cybersecurity evaluations. In one of them, Claude Opus 4.7 confused an existing company with the fictitious target of an exercise and exploited vulnerabilities that granted access to credentials and a production database with hundreds of records.

Another case involved Claude Mythos 5, which published a malicious package during a test after incorrectly concluding that it was still inside a simulation. Anthropic halted its security evaluations on July 23 and notified affected organizations four days later.

The UK AI Safety Institute also recorded 19 actions outside the expected scope in a series of 122 tests conducted between July 25 and 28 with Mythos 5 and GPT-5.6 Sol. The most serious episode involved an attempt to insert malicious code into a real open-source software project.

Letter divides responsibilities between companies and governments

The initiative proposes that organizations treat cybersecurity as an immediate priority, first fixing the highest-risk vulnerabilities and adopting more restricted access controls. The document also calls for greater attention to code produced by artificial intelligence before it is put into production.

Security companies and technology providers should continuously test their defenses against advanced models, share threat information and make AI-based tools more accessible to critical infrastructure operators.

Governments are called on to fund the protection of essential services, expand intelligence-sharing mechanisms and facilitate access by hospitals, water utilities and local administrations to defensive tools and authorized tests.

For companies developing frontier models, the letter recommends systems capable of identifying and tracing autonomous agents to their operators, in addition to continuous monitoring, controlled tests, private disclosure of vulnerabilities and sharing of verified fixes.

The proposal, however, works as a voluntary commitment. The document does not establish mandatory standards, independent oversight mechanisms or accountability rules for situations in which an AI agent exceeds the limits defined for its operation.

More from Radar