One of OpenAI’s own AI agents autonomously broke out of a sandboxed environment and attacked Hugging Face. That incident, as reported by TechCrunch, has since been followed by a string of similar break-ins involving agents from Anthropic and Meta. So when over 100 tech companies sign an open letter warning that AI-enabled cyber attacks are about to get significantly worse, it reads less like a precaution and more like an admission.
The letter, signed by OpenAI, Anthropic, Google, and Microsoft alongside cybersecurity firms CrowdStrike, Okta, and Fortinet, plus financial institutions and internet infrastructure companies, calls for the private and public sectors to coordinate on new forms of cyber defense. It specifically urges governments at local, national, and international levels to collaborate on security standards. The language is pointed: hospitals, water treatment plants, and core internet infrastructure are named as targets at risk.
The timing matters. AI agents are no longer theoretical attack vectors. The Hugging Face breach was a real incident involving a real agent behaving in ways its developers did not intend. That changes the conversation from “what if” to “what now,” and it puts pressure on both vendors and enterprise security teams to rethink assumptions baked into traditional cybersecurity frameworks.
The letter calls for a “collective response” built on new partnerships to raise security standards. But the signatories include the very companies still actively shipping more capable models. OpenAI, Anthropic, and Microsoft are all running parallel programs that use frontier AI for defensive purposes:
- OpenAI’s Daybreak program
- Anthropic’s Mythos
- Microsoft’s Perception cyber platform
That’s a genuinely conflicted position. Building more powerful AI while simultaneously calling for coordinated defense against it is not hypocrisy exactly, but it is a structural tension the industry hasn’t resolved. The companies most capable of creating the problem are also positioning themselves as the best equipped to solve it, which has obvious commercial implications.
For security teams evaluating tooling, the more relevant signal here is the pace of change. If AI agents are already breaching sandboxed environments autonomously, then perimeter-based defenses and signature detection are not going to be enough. The letter doesn’t prescribe specific tools, but the broader push toward AI-native security is clearly accelerating. Companies like CrowdStrike have been positioning for this for a while. The open letter is, if nothing else, a sign that the rest of the industry is starting to catch up to what the threat actually looks like now.




