OpenAI, Anthropic, Google and Microsoft want cyber defence treated as a leadership priority

The Cyber Resilience Act starts demanding 24-hour vulnerability reports on 11 September, while the directive meant to coordinate governments and industry is two years late in three member states


Photo of Shield With Keyhole icon on digital data background

Cyber security concept. Shield With Keyhole icon on digital data background. Illustrates cyber data security or information privacy idea.

More than 100 organisations including OpenAI, Anthropic, Google and Microsoft have signed an open letter urging businesses and governments to make cyber defence an immediate leadership priority and fix weaknesses in their own software. The EU’s Cyber Resilience Act makes much of that mandatory from 11 September.

More than 100 organisations have signed a letter telling everyone to take cyber defence seriously. OpenAI, Anthropic, Google and Microsoft are among them, calling for it to become an immediate leadership priority and for companies to fix the weaknesses sitting in their own software.

The other asks are more specific. Security firms should defend against AI-enabled attacks, governments should coordinate with each other and with industry, and leading AI companies should give access, money and training to whoever defends critical infrastructure.

The framing is optimistic. “Today’s AI advances are already giving defenders new ways to fix weaknesses that have accumulated for years,” the letter says, describing a defenders’ window that closes if nobody acts.

The timing is not coincidental. It follows a run of incidents in which advanced models misbehaved, including the one where OpenAI’s own models broke out of a sandbox and breached Hugging Face.

Europe has already legislated the first request. From 11 September, two weeks away, the Cyber Resilience Act requires manufacturers of products with digital elements to report actively exploited vulnerabilities and severe incidents.

The clock is unforgiving. An early warning within 24 hours of becoming aware, full notification within 72, and a final report within 14 days of a fix, filed to a national response team and to ENISA through one platform.

That is the letter’s voluntary request written as a legal duty. What the signatories are urging each other to do, European law will shortly require of anyone selling a connected product here.

Europe is in no position to be smug about it. Hackers breached the European Commission by poisoning the security tool it was using to protect itself.

The second request is where the record looks worse. NIS2, the directive built to make governments and industry coordinate exactly as the letter asks, was supposed to be national law by October 2024.

Three member states still have not managed it. The Commission referred Ireland, Spain, France and the Netherlands to the Court of Justice in July seeking lump sums and daily penalties, and the Dutch transposed a month later.

Part of the letter is already being done. Anthropic has committed to give defenders what its strongest model finds, while keeping the model itself.

So the defenders’ window is not a metaphor in Europe. It opens on 11 September, and it does not much matter who signed a letter.

Get the TNW newsletter

Get the most important tech news in your inbox each week.

Also tagged with