Back to all articles
Articles Published on August 28, 2026

The cyber defense letter signed by 155 companies contains not one commitment

On 27 August 2026 an open letter convened and hosted by OpenAI called for a collective response to AI-enabled cyber attacks, and the press covered the number: more than a hundred companies. I went after the boring question — what exactly did anyone commit to doing. I pulled the four blocks of asks out of a pinned capture of the page and searched inside them for the five signals that separate a commitment from a statement of intent: an amount, a deadline, a binding verb, a named party, a verifiable target. Eighteen imperative sentences and, across twenty cells, not one hit. The amber you see in the figure is a concession I made by hand against my own argument, and I explain why. To prove the ruler measures, I ran the same test on a page by OpenAI itself, from February, which lights three of the five columns: the company writes an amount when it wants to. I also show that the list of signatories changed four times in forty-seven hours — 116, 127, 128, 155 — while the text of the four blocks did not change a single byte, that one company was removed without explanation, and that the page carries two lists whose counts collide on the same number. And I separate, carefully, what is measured from what is my own analysis.

#ia#ciberseguranca#openai#politica-de-tecnologia#verificacao
A matrix of five rows by five columns. Each of the first four rows is a block of asks from the letter — 01 Every organization, 6 imperative sentences; 02 Cybersecurity companies and technology partners, 3 sentences; 03 Governments, 6 sentences; 04 Frontier AI companies, 3 sentences. Each column is a commitment marker searched for inside the block: an amount, a deadline, a binding verb, who is accountable, a verifiable target. Of the twenty cells across the four blocks, nineteen are absent; the single exception is partial, in block 02, which names the metric but not the target. Below a dashed rule, in quarantine, sits the positive control row: the Trusted Access for Cyber page by OpenAI itself, from February 2026, which is a different document and lights three of the five columns — an amount of ten million dollars, the verb 'we are committing' and OpenAI itself as the accountable party — leaving deadline and verifiable target dark.What each block of asks actually bindsOpen letter convened by OpenAI, 27 Aug 2026 — 18 imperative sentences, four addresseesAmountDeadlineBindingverbWho isaccountableVerifiabletarget01Every organization6 imperative sentences02Cybersecurity companiesand technology partners3 imperative sentencesnames the metric,not the target03Governments6 imperative sentences04Frontier AI companies3 imperative sentencesControl: Trusted Access for Cyber,OpenAI, Feb 2026 — a different documentUS$10 million“we are committing”OpenAI itselfabsentpartialpresentNo block carries an amount, a deadline, or a verb that binds.The only digits in the body of the letter are 01, 02, 03 and 04.Letter: openai.com/collective-cyberdefense, capture of 28 Aug 2026 15:45 UTC. Control: Introducing Trusted Access for Cyber, OpenAI, 5 Feb 2026.

How to read it: each row is one of the letter's four blocks of asks; each column is something I looked for inside that block. Grey is absent, amber is partial, green is present. The row below the dashed rule is a different document, by the same company — it is there only to prove the ruler lights up when there is something to measure.

On 27 August 2026, an open letter convened and hosted by OpenAI appeared calling for a "collective response" to what it names the defenders' window: the coming months, in which AI-enabled cyber attacks would become more widespread and more sophisticated. The press covered it the same day, and covered it well — Bloomberg, CNBC, TechCrunch, Axios, CyberScoop, NBC, CBS. The angle was always the same: more than a hundred companies have joined forces.

I went to read the letter with a different question, and it is the boring one: what exactly did anyone commit to doing?

I downloaded the page, separated the four blocks of asks from the rest of the document, and searched inside them for the five signals that separate a commitment from a statement of intent: an amount, a deadline, a verb that binds, a named party, and a target you can check later.

There are 18 imperative sentences. Zero of the five markers — twenty cells, not one hit. That holds for all four blocks, including the three that address the industry itself, not only the one that addresses governments.

What the letter asks, and of whom

The letter closes with four numbered blocks, each addressed to a different party. Here is the core of each:

01 Every organization — six sentences. It opens with "Make cyber defense an immediate leadership priority" and goes on with "Raise your security standards", "Fix the highest-risk weaknesses", "Upgrade or replace systems".

02 Cybersecurity companies and technology partners — three sentences. "Help lead the response to defend against sustained AI-enabled attacks", "Make AI-powered defense accessible and deployable for critical-infrastructure operators", "Share threat intelligence and tested playbooks".

03 Governments — six sentences. "Coordinate cyber defense at local, national, and international levels", "Fund cyber defense", "Expedite the expansion of trusted access programs", "Give hospitals, water utilities, and local governments access to capable defensive AI", "Impose costs on attackers".

04 Frontier AI companies — three sentences. "Provide responsible model access, significant funding, training, and hands-on support", "Build observability and security tools", "Invest in authorized testing, private disclosure, and verified fixes".

Note that the easy accusation — "it is an AI company billing governments" — does not hold. Three of the four blocks address the industry, and the last one addresses frontier AI companies, that is, the very people who convened the letter. The problem is not who it asks. It is that nobody, in any block, promises anything measurable.

The five markers, and why those

An assertion of absence is only worth something against a declared search space. "I found nothing" without saying what you looked for is an opinion, not a measurement. That is why the figure's five columns are drawn inside it — you may disagree with my list, but you can see it.

MarkerWhat the search looks forHits across the four blocks
Amounta currency symbol with a number, a number followed by million/billion/thousand, or a percentage0
Deadlinea year, by the end, deadline, within + number, no later than, a quarter0
Binding verbmust, shall, are required, commit, pledge, undertake, binding, obligation, mandate0
Who is accountablefirst person plural with a commitment verb — we will, we commit, we are committing, we pledge0
Verifiable targetat least, no fewer than, target of, reduce … by + number, a percentage, by + year0

Twenty cells, zero hits. Not one cell by oversight: the entire set.

The amber you see in block 02 of the figure did not come from the search — it came from me, and it works against my own argument. The letter says there: "measure progress by how many organizations are protected, how quickly attacks are contained, and whether fixes work". None of my expressions match that, and even so it is honest to acknowledge that half a marker is present: the letter names the metric and does not name the target. How many organizations? By when? I marked it partial by hand, and the program records the decision in writing.

That concession is what makes the measurement defensible. Without it, an all-grey matrix is an accusation rather than a count. With it, you can see where the letter comes close — and where it does not. It is by that same rule that "significant funding", in block 04, came out absent rather than partial: an adjective is not half a number, it is a different thing. The closest a letter signed by 155 companies gets to talking about money is the word "significant".

The only digits in the body of the letter are 01, 02, 03 and 04

This is the test I did not expect to come out so clean. I ran a digit sweep over the body of the document — from the first paragraph to the last sentence, excluding the list of who signed. The only digits that appear are the numbers of the blocks themselves. No date. No percentage. No sum. No deadline.

The scope matters and I state it: this holds for the body of the letter. The signatory list has digits, because it contains "1Password" and "F5". The program that does the counting aborts if that condition stops being true, so it cannot let me publish a claim that has aged out.

The control: the same company writes an amount when it wants to

An absence can mean two things: that the author did not want to commit, or that the genre simply does not carry commitments. A manifesto has no amounts, and demanding one of a manifesto would be unfair.

That is why the figure carries a positive control, on the row below the dashed rule. It is a different document, by the same publisher, on the same subject: the Trusted Access for Cyber page by OpenAI, from 5 February 2026. I ran exactly the same measurement on it.

The control lights three of the five columns: amount ("we are committing $10 million in API credits"), binding verb ("committing") and who is accountable (OpenAI itself, in the first person). And it leaves two dark — it has no deadline and no verifiable target. A control that lit everything would calibrate nothing; this one shows that the ruler works and that it also knows how to say no.

The conclusion the control licenses is modest and sufficient: OpenAI writes an amount when it wants to. The absence of commitment in the 27 August letter is an editorial choice, not a limit of the format.

[!IMPORTANT] The ten million dollars belong to the February document, not to this letter. If you have seen that number circulating alongside the August letter, it is an improper import. The figure keeps the control in visual quarantine — below a rule and with its date in the label — precisely to block that reading.

The list moves. The text does not.

The second finding turned up when I went to check the headline number.

Moment (UTC)SignatoriesRoute
27 Aug 2026 17:13:03116Wayback, direct curl
27 Aug 2026 23:29:07127Wayback, direct curl
28 Aug 2026 15:43:35128live page, local browser
28 Aug 2026 15:45:12128Wayback, direct curl
29 Aug 2026 16:24:50155Wayback, direct curl

Four changes in about 47 hours. CNBC is the only outlet that pinned an exact number — 116, in the headline and in the body, published at 17:48 UTC on 27 August. It was right: it matches the snapshot from 35 minutes earlier. Today it is out of date. Any number about this letter has a shelf life of hours, which is why every one I cite here comes with a date and a time.

There is one more trap, and it catches anyone who goes to check: the page has two lists. One of Signatories, in text (116, then 127, then 128, then 155), and one of Supporting organizations, a wall of logos that is a subset of the first (100, 116 and 118 across the first three captures — I did not recount the wall on the last one). The number 116 appears in both series, at different moments. Citing "116" without saying which list is ambiguous, and the ambiguity is not the journalist's: it is the page's.

One company left. Between the 23:29 capture on 27 August and the 15:45 one on 28 August, Glean and Uber came in and the National Australia Bank went out — a clean removal, not a renaming, confirmed by two independent routes. Neither OpenAI nor the bank has said anything about it. The exact moment of the departure falls inside a window of some sixteen hours that I did not close, and I do not know the reason; I assert neither.

The next day the list made its biggest jump yet: from 128 to 155 between 28 Aug 15:45 and 29 Aug 16:24 UTC — twenty-seven arrivals, no departures. Among them AT&T, Atlassian, Databricks, Datadog, GitHub, Nokia, PayPal and Tailscale.

And now the contrast that gives this article its point: while the list changed four times, the text did not change a comma. The four blocks are byte-for-byte identical across the five captures between 27 Aug 17:13 and 29 Aug 16:24 UTC. What the letter asks for is settled, edited, stable. It is precisely in that stable part that there is no commitment.

Who is not there

Absences, against an enumerated list of 155 names, are a measurement: Meta, Nvidia, xAI, Mistral, Palantir, Y Combinator, Linux Foundation, Andreessen Horowitz, Apple, Salesforce.

Mozilla was on that list until the day before. It came off for a detail worth recording: the 29 Aug arrival does not read "Mozilla" — it reads Firefox, the browser. The string Mozilla is still not on the list, and I do not claim the foundation signed; I claim the name that signed is the name of its product, and that this is why Mozilla left my roll of absentees.

Almost all of the first ones signed, five weeks earlier, the letter "Open Weights and American AI Leadership" of 24 July — the one defending open-weight models against regulatory restrictions. That one, OpenAI and Anthropic did not sign.

The temptation is to read the two lists as two teams. They are not. Microsoft, IBM, Dell, Hugging Face, CrowdStrike, Palo Alto Networks, Cloudflare and Cisco signed both. Hugging Face is the most instructive case: it is the company most identified with open weights in the world, and it is on both letters.

The counter-argument, which the letter deserves

If you have read this far expecting the conclusion that this is a manoeuvre to close the market, I owe you first what works against it, because it is in the text of the letter itself.

The letter says, verbatim, "no single company should control the future". And, in block 04, it asks that "tools, playbooks, and credible threat assessments" be shared "with governments, security partners, and open-source maintainers". That is not the language of someone asking to shut the door.

The most direct published criticism of this letter comes from Engadget, by Anna Washenko, on that same 27 August: "It reads more like a somber, fear-mongering commercial for the AI-powered protections needed to fight off AI cyberattacks than a meaningful public service announcement." That is criticism of tone and of timing — the warnings should have come earlier — not of regulatory capture.

I want to keep this separate: I found no published, named criticism accusing this letter of regulatory capture. Criticism of that kind is documented against the July petition, which is a different document with different signatories. Attributing it to this letter would be a factual error, and I see it circulating.

What I do assert, as my own analysis and declared as such, is narrower and needs no theory of intent: a document that asks governments and the whole economy to "accelerate defenders' priorities" without taking on a single obligation of its own transfers the entire cost of the urgency to the reader. The urgency belongs to the text; the commitment belongs to nobody. That is observable in the figure, without my needing to know what was in the mind of anyone who signed.

What would make this letter binding

It is not an impossible ask. Each of the four blocks would take a commitment without changing the subject:

  • 04 Frontier AI companies — swap "significant funding" for an amount and a date. OpenAI's own February document shows how it is written: "we are committing $10 million in API credits".
  • 02 Cybersecurity companies — finish the metric the letter already names: how many critical-infrastructure organizations protected, by when, and who publishes the count.
  • 01 Every organization — a dated milestone in place of "an immediate leadership priority".
  • 03 Governments — the one block where "an ask without a commitment" is the right genre, because those who signed do not legislate. Here the demand is legitimate as it stands.

Notice that three of the four fixes fall to signatories of the letter. This is not a letter that only bills governments. It is a letter in which nobody, governments included, is billed for anything measurable.

How to redo this count

Nothing here was read by eye. The four blocks were extracted from a pinned capture of the page whose sha256 is 23fd95b7ba264bb9d01cd7a7f76a2b880cf65b7bb4d1a78ce1b542fa4aaf7b24, and the search for the five markers is a set of regular expressions you can read, disagree with, and re-run:

  • gerar-dados.py — extracts the blocks, applies the five markers and builds the figure. It aborts if the body of the letter stops having only the digits 01–04, or if the sentinels of the control document go missing.
  • extrair_blocos.py — hashes each block across the five captures, which is how I know the body did not change.

One trap the program avoids, recorded here for anyone repeating the work: measuring the positive control on the raw page lights eighteen false "deadlines", because the menu, the footer and the Keep reading section carry dates that do not belong to the document. The measurement is body against body, with explicit sentinels for where each one begins and ends.

Sources

Verified on 28 August 2026. The text of the four blocks was read from Internet Archive captures and from the live page, and is identical across all four. The signatory count is from 28 Aug 2026 15:45 UTC and it moves: check the date before citing any number from this page. The exact moment and the reason for the National Australia Bank's departure were not established and are declared as not established. The regulatory-capture reading, in the section that raises it, is my own analysis and is marked as such — it is not attributed to any critic.