,

AI threat so great that security “takes precedence over everything except critical business operations” 

What OpenAI’s open letter means for teams running lean.

OpenAI just published an open letter, co-signed by Anthropic, Google, and more than 120 other organizations, warning that the window to prepare for AI-enabled attacks is closing rapidly.  

We’ll say it: we called this one.  

Our July report, Cybercrime in the age of AI, explains that organizations have about six months before cybercriminals get easy access to AI models as good as Mythos, the AI model Anthropic refused to release in April because it was so good at finding security vulnerabilities its maker was concerned it could “reshape cybersecurity.” 

What you do in that window will dictate how you fare in this new reality. 

Our report, Cybercrime in the age of AI, previously projected a six-month timeline for the broader industry to reach this point. 

What the letter tells us 

Go beyond the long list of signatories, and the letter makes three key points.  

First, the security practices most organizations already have around things like patching, permissions, and authentication were already falling behind before AI entered the picture, and under-resourced teams need a real surge in tools and support, not another dashboard.  

Second, AI can hand specialist-level defense skills to people who don’t have a specialist on staff, which means one organization’s fix can help protect many, provided that knowledge is shared.  

Third, this is bigger than any single company. Capability is advancing everywhere at once, so the response has to be collective: new partnerships, shared standards, and everyone pulling in the same direction.  

It then lays out four sets of asks: one for every organization, one for security vendors, one for governments, and one for frontier AI labs. We’re focusing on the first. 

The advice for “every organization” 

The letter tells every organization to stop treating security like a background task and start running it like an active incident: name it a leadership priority, move at incident speed, and fix the riskiest gaps first. It also raises the bar for what gets bought, built, and shipped, AI-generated code included, and pushes organizations toward locked-down access and layered defenses instead of flat, overly trusting systems. And when something truly can’t be patched without breaking a critical system, the answer isn’t to skip it: put a compensating control in place and confirm it actually holds. 

All of that is correct. None of it tells a mid-size business where to start on Monday morning.

That’s the gap. The letter is written with large enterprises in mind, with sizable security budgets, and teams with headcounts that reflect them. Most of the organizations we protect don’t have that team. They have an IT lead doing five jobs at once. 

Here’s the translation, straight from our own six-months-to-prepare warning.  

Patch like the clock is running 

Mythos-class AI is currently in the hands of a select group of software vendors, where it’s busy finding and fixing software vulnerabilities, thanks to projects like Glasswing and Daybreak. In the long run, that means everyone’s software will be more secure, but in order for that to happen, organizations are going to have to get 10x better at doing something most of them already struggle with: patching in a timely fashion. 

Because of AI, Microsoft’s July 2026 Patch Tuesday shipped 622 security fixes, more than three times the previous record, which was set just one month before. The same thing is being repeated across other vendors too, and the pace is accelerating. Bet against it, and you’ll pay for it. 

Organizations that invest in automation and effective vulnerability assessment and patch management now will be in a completely different world in six months than organizations still patching by hand. 

Monitor continuously, 24/7 

AI makes attackers faster and more scalable, but it doesn’t invent new tactics. Endpoints are still the target. Stolen identities are still the dominant way in. What changes is how quickly the early signs of an attack need a response, and how often those attacks occur. When every criminal has easy access to Mythos-class models that can complete a full network takeover on their own, part-time security won’t cut it. Most small and medium-sized organizations can’t staff an around-the-clock SOC, so they will need a Managed Service Provider (MSP) that can, or a service like Managed Detection and Response (MDR) that ensures there are expert eyes watching their EDR 24/7.

Find and govern your shadow AI 

Every unsanctioned AI tool, agent skill, and MCP (Model Context Protocol) connection running in an environment is a blind spot your IT team didn’t sign off on and can’t see. This is the majority case, not a hypothetical: most organizations are running far more AI than they think, most of it has no oversight attached, and all of it is an attack surface and an increasingly significant insider threat. Governing it starts with knowing it exists. 

Act now 

The organizations that come out of the other side of this shift intact are the ones acting on all three of these now, while the window to act is still open.  

We already mapped that window. Cybercrime in the age of AI lays out exactly how the six-month countdown starts, what shows up when it runs out, and the specific moves that separate the organizations still standing from the ones playing catch-up.  

Get the full report

20
26
Cybercrime in the Age of AI

AI is rewiring the cybercrime ecosystem.
You have six months to prepare.

Download the report

20
26
Cybercrime in the Age of AI

AI is rewiring the cybercrime ecosystem.
You have six months to prepare.

Download the report