OpenAI, Anthropic, Google, Microsoft, and more than 100 other technology and financial services organizations signed an open letter this week calling for cyber defense to become “an immediate leadership priority.” Insurance Journal covered the warning on August 28, 2026, reporting that the letter asks organizations, governments, cybersecurity companies, and frontier AI labs to prepare for more AI-enabled attacks in the months ahead.

The business lesson is not that every company suddenly needs an AI security lab. The lesson is simpler and more uncomfortable: if AI agents can now help defend systems and attack systems, cyber risk is no longer a technical side room. It is an operating model question.

TL;DR

The companies that handle this well will not be the ones that buy the most security software. They will be the ones that decide who owns agent access, who approves what agents can touch, who watches the work, and what happens when something goes wrong. AI makes cyber defense faster. It also makes weak ownership louder.

The warning is really about speed

The open letter frames the next few months as a defender’s window. That phrase matters. A window is not a permanent advantage. It is a short period when action still changes the slope.

According to Bloomberg reporting republished by Insurance Journal, the signatories expect AI models to be used in a growing number of more complicated cyber attacks as the same capabilities become useful for defense. The letter also points to existing software weaknesses that have accumulated for years. That is the part leaders should sit with.

Most organizations do not have a clean environment waiting for AI. They have old permissions, forgotten tools, shared logins, vendor sprawl, unclear escalation paths, and systems nobody wants to own because they still mostly work. AI did not create that mess. It makes the mess callable.

That is the shift. A human attacker used to be constrained by time, patience, language, and research capacity. AI reduces those constraints. A defender gets the same advantage, but only if the organization knows what to fix first and who has permission to fix it.

This cannot live only with IT

The obvious response is to send the article to IT and ask whether the company is covered. That is better than ignoring it, but it is not enough.

IT can manage tools. Security can define controls. Legal can manage exposure. Operations can define process. Leadership has to decide ownership.

Who is allowed to deploy an AI agent inside the company? What systems can it access? Can it read customer records? Can it write to a ticketing system? Can it open pull requests? Can it send messages to vendors? Can it summarize internal emails? Can a department head approve that alone, or does someone else need to sign off?

Those are not model questions. They are authority questions.

This is where many companies are weak. They are not failing because nobody bought an AI tool. They are failing because AI arrived before the organization updated its permission model. Employees experiment. Vendors add AI features by default. Teams connect tools to save time. Nobody feels like they are making a security decision because each individual action feels small.

Then one day the company has ten AI-enabled workflows touching real information and no map of what exists.

The first control is inventory

There is a practical first step here, and it is not glamorous: build the inventory.

List every AI system currently used by the business. Not just approved vendors. Include browser tools, meeting note takers, customer support assistants, sales automation, internal chatbots, coding assistants, document tools, data analysis tools, and anything embedded inside software your team already pays for.

For each one, answer five questions:

  1. What can it read?
  2. What can it write or trigger?
  3. Who approved it?
  4. Who reviews its output?
  5. What is the shutdown path?

That last question is the one most teams miss. If an AI workflow behaves badly, leaks information, sends the wrong thing, corrupts a record, or starts taking actions outside its intended scope, who can turn it off immediately? If the answer is “we would figure it out,” the system is not production-ready.

This does not require a six-month governance program. It requires a one-week operational audit with the right people in the room: IT, security, operations, legal, and the department leaders already using AI.

The point is not to slow everything down. The point is to stop pretending speed and visibility are opposites. They are not. The teams that move fastest with AI usually have cleaner boundaries, not looser ones.

Agents make vague responsibility dangerous

A normal software tool waits. An agent does not always wait in the same way. It can interpret goals, chain steps together, call other tools, and keep working after the initial prompt. That is the reason agents are useful. It is also why vague responsibility becomes dangerous.

If a person makes a mistake, you can usually trace the decision. If a workflow fails, you can usually trace the process. If an agent takes action across systems with unclear instructions, weak permissions, and no review layer, the failure can move faster than the organization can explain.

That does not mean agents should be banned. It means they should be treated like operational participants, not clever add-ons.

A simple rule helps: any agent that can change a business record, message a customer, touch money, modify code, or access regulated information needs an owner, a scope, a log, and a rollback path. If that sounds basic, good. Basic controls are often what separate useful AI from expensive chaos.

The defender’s window belongs to operators

The cyber conversation will naturally focus on attackers, threat models, and lab reports. That work matters. But for most business leaders, the near-term question is more grounded: can your organization see what AI is already doing inside the business?

If not, start there.

OpenAI’s letter says AI gives defenders new ways to fix weaknesses that have accumulated for years. That is true, but AI does not decide what your company values, what risks it accepts, which systems matter most, or who is accountable when a workflow touches the wrong thing.

Leadership still has to do that part.

The defender’s window is not only a security window. It is an operations window. Clean up access. Map the workflows. Assign ownership. Decide what agents are allowed to touch before the next tool quietly adds one.

The companies that wait for this to become a formal crisis will spend the next year reacting. The companies that treat it as an ownership problem now will be able to use AI faster because they know where the edges are.