Who Didn’t Sign the OpenAI Cyber Defense Call For Collective Action

OpenAI published an open letter on Thursday with a little over 100 signatures. That’s not a lot. And when you run the numbers, it reveals some interesting patterns.

For example, there are four targeted audiences for a “what needs to happen next” section:

  1. every organization
  2. cybersecurity companies
  3. governments
  4. frontier AI companies

And then it differentiates who it considers victims:

  1. hospitals
  2. water treatment plants
  3. infrastructure that powers the internet

Already it’s getting weird. Why aren’t governments in the victim list? Or what about every organization being in the list? I don’t get it and neither should you. This is not a letter that makes much sense.

Let me explain further. Two of the four targeted audiences signed: the vendors, nearly to a company, and a scattering of enterprise buyers who fall under “every organization.” Zero governments. Zero from any of the three named victim sectors.

That is to say, plainly, there is no hospital, no water utility, no government, no regulator, no standards body beyond the one that runs a federal ISAC, and no operator of the internet backbone the letter says is at risk, signing it.

The people asked to act did not sign. The letter was signed by the people selling the thing it says is needed, plus a few of their customers.

That’s the whole game. It’s perhaps the dumbest possible version OpenAI could have published. Either the victims were never asked, in which case this is a vendor letter to buyers dressed as a coalition, or they were asked and declined, in which case the people the forecast is all about do not believe in it. Either way, this letter doesn’t pass a basic sniff test.

Tables are great

I thought maybe it would be fun to list each sector by the distance between what the letter claims and who actually signed. Think of it as a buyers guide, so you can easily migrate away from the brands who signed this strange letter. Rank 1 is the largest gap.

Rank Sector What the letter says Signed Absent
1 Water, energy, utilities Named victim, named funding recipient, named access recipient none American Water, Veolia, Suez, Xylem, Duke, Exelon, NextEra, E.ON, EDF, Enel, National Grid, Colonial Pipeline
2 Healthcare Named victim, named access recipient none UnitedHealth / Change Healthcare, Ascension, HCA, Kaiser, Mayo, Epic, Oracle Health, Philips, GE HealthCare, Siemens Healthineers, McKesson, CVS, NHS
3 Government, regulators Entire section 03: fund, coordinate, expand trusted access, impose costs none CISA, NSA, NCSC, BSI, ENISA, CAISI, UK AISI, NIST, FBI, Europol
4 OT / ICS security The vendors who defend rows 1 and 2; “critical infrastructure supply chain manufacturers” named none Dragos, Claroty, Nozomi, Armis, Forescout, Schneider, Siemens, Rockwell, Honeywell, ABB, Emerson
5 AI security (securing the model, the agent, its data) “Build observability and security tools, ensure agentic identities are traceable and accountable” none independently; Protect AI, Lakera, Prompt Security, Robust Intelligence and CalypsoAI only via acquirers Palo Alto, Check Point, SentinelOne, Cisco and F5 Knostic, Wirken, Zenity, Noma, Pillar, Lasso, HiddenLayer, Mindgard, Aim Security, Cloud Security Alliance
6 Standards, coordination “Verified fixes,” “private disclosure,” CVE throughput Center for Internet Security MITRE, CVE Program, FIRST, OWASP, OpenSSF, ISACA, ICANN, IETF, Internet Society, EFF
7 Telecom Named victim: “infrastructure that powers the internet” Deutsche Telekom, Lumen AT&T, Verizon (Salt Typhoon victims), T-Mobile US, Orange, BT, Vodafone, Telefonica, NTT, Comcast, Nokia, Ericsson
8 Operating systems, open source “Open-source maintainers” named as recipients; “longstanding bugs” is their code Red Hat, Hugging Face Linux Foundation (Glasswing partner), Canonical, SUSE, Apache, Debian, Mozilla, Python Software Foundation, OpenSSL, curl, Rust Foundation
9 Internet-scale observation The only parties who could measure “far more widespread” none Shodan, Censys, GreyNoise, watchTowr, Shadowserver, abuse.ch
10 Logistics Among the largest documented losses from one automated attack Flexport Maersk, FedEx, UPS, DHL, C.H. Robinson
11 Automotive Sector-scale supply chain and OT exposure General Motors Ford, Stellantis, Toyota, Volkswagen, BMW, Mercedes, Tesla, Hyundai, Rivian
12 Insurance Hold the loss data the letter never cites Zurich, Marsh Chubb, AIG, Beazley, Coalition, At-Bay, Resilience, Munich Re, Swiss Re, Lloyd’s, Aon, WTW, Gallagher
13 Identity, PKI “Agentic identities traceable and accountable” Okta, 1Password DigiCert, Sectigo, Entrust, Let’s Encrypt / ISRG, GlobalSign, Ping, Yubico, Bitwarden
14 CDN, edge “Infrastructure that powers the internet” Cloudflare, Akamai, F5 Fastly, Imperva, Netlify, Bunny
15 Dev platforms, AI code “Raise the security bar for AI-generated code” Cognition, Lovable, Replit, Vercel, Factory, Figma GitHub, GitLab, Cursor, JetBrains, Atlassian, StackBlitz, Sourcegraph
16 Consulting, integrators “Hands-on support” Accenture, Capgemini, Cognizant, KPMG, PwC, Oliver Wyman, IBM, Unisys, WWT Deloitte, EY, McKinsey, BCG, Booz Allen, Leidos, SAIC, CACI, Kroll, Optiv, GuidePoint, TCS, Infosys, Wipro, Atos
17 Vuln research, bounty, audit “Authorized testing, private disclosure” HackerOne, Trail of Bits, SpecterOps, Cantina, Zero Day Initiative (via TrendAI) Bugcrowd, Synack, Intigriti, NCC Group, Bishop Fox, IOActive, Cobalt, Semgrep (OpenAI grantee), iVerify (Trusted Access participant)
18 Banks Buyers; Trusted Access participants Capital One, Citi, Fifth Third, U.S. Bank, NAB, Nationwide JPMorgan (Glasswing, Trusted Access), Bank of America, Goldman, Morgan Stanley, Wells Fargo, BNY, HSBC, Barclays, Deutsche Bank, Commerzbank, UBS, Santander, BNP, ING
19 Payments, market infrastructure Buyers Mastercard, Visa, FIS, Fiserv, DTCC, The Clearing House, Block, Robinhood Amex, PayPal, Stripe, SWIFT, Nasdaq, ICE, CME, Deutsche Borse, Euroclear, Coinbase
20 Enterprise software Buyers and patch sources SAP, ServiceNow, Adobe, Snowflake, Elastic, Incident.io Salesforce, Workday, Databricks, Intuit, Autodesk, Zoom, Dropbox, Box
21 Retail, commerce Buyers Shopify, GoDaddy Amazon retail, Walmart, eBay, Target, Home Depot, Alibaba, Automattic
22 Credit bureaus Buyers TransUnion Equifax, Experian
23 Funds, private equity Capital behind the sellers Citadel, ExodusPoint, Advent BlackRock (Trusted Access), Thoma Bravo, Vista, KKR, Blackstone, Insight, a16z, Sequoia, Altimeter, Greylock, Lux, Battery, ICONIQ
24 Silicon Compute AMD, Arm, Micron, Broadcom NVIDIA (Glasswing, Trusted Access), Intel, Qualcomm, TSMC, Samsung
25 Hyperscale cloud Compute AWS, Google, Microsoft, Oracle, IBM Alibaba Cloud, Hetzner, OVH, Scaleway, DigitalOcean
26 Frontier labs Authors; section 04 is their own commitments OpenAI, Anthropic, Google, Microsoft Meta, xAI, Mistral, Cohere, NVIDIA, Apple
27 Security incumbents Sellers CrowdStrike, Palo Alto, Zscaler, SentinelOne, Fortinet, Check Point, Cato, Sophos, Proofpoint, Tenable, Okta, Darktrace, Cisco, TrendAI (Trend Micro) Rapid7, Qualys, Netskope, Wiz (Google), Arctic Wolf, Huntress, Tanium
28 AI-native offense and SOC startups Sellers XBOW, RunSybil, Tenzai, depthfirst, Calif, Cogent, Corridor, Octane, Prophet, Dropzone, Cotool, Outtake, Abnormal, Aikido, APIsec Horizon3, Pentera, Sublime, Torq

I guess I could have expanded the list of people who didn’t sign. It’s massive. The letter really does speak to something strange. Rows 1 through 5 are the letter’s stated purpose with zero independent signatures. Zero. Row 26 is its authors and rows 27 and 28 are their sales channel, where suddenly there’s near-complete coverage.

The signature density is the total inverse of the stated priority.

Thoma Bravo owns three of the security signatories, Darktrace, Sophos and Proofpoint, but for some reason it did not sign. Maybe it’s waiting to see how bad the reaction is. I found it especially odd that Merck, FedEx and Maersk, the three companies with the largest documented losses from NotPetya, did not sign. They felt the pain and said no to this letter. AT&T and Verizon, the carriers Salt Typhoon lived inside for a year, did not sign. Lumen, named alongside them in the original reporting, did sign, which makes it a signatory with a documented state intrusion in its own network and nothing to say about it in the letter. MITRE, which runs CVE, and FIRST, which runs CVSS, are absent completely in a letter about surging vulnerability throughput. Because why?

When “global” means America

I went with 108 of the 116 signatories because eight could not be verified. I almost did this by city, because it’s basically all America, but let’s start with nations.

Country Count Signatories
United States 87 Abnormal AI, Accenture, Adobe, Advent International, Akamai, AMD, Anthropic, APIsec, AWS, Block, Broadcom, Calif, Cantina Security, Cape, Capital One, Center for Internet Security, Cisco, Citadel, Citi, Cloaked, Cloudflare, Cogent Security, Cognition, Cognizant, Corridor, Cotool, CrowdStrike, Dell, depthfirst, Dropzone.ai, DTCC, Equinix, EXA.ai, ExodusPoint, F5, Factory, Fifth Third Bank, Figma, FIS, Fiserv, Flexport, Fortinet, General Motors, GoDaddy, Google, HackerOne, Hugging Face, IBM, KPMG, Lumen Technologies, Marsh, Mastercard, Mercor, Micron, Microsoft, Obsidian Security, Octane Security, Okta, Oliver Wyman, OpenAI, Oracle, Outtake AI, Palo Alto Networks, Perplexity, Proofpoint, Prophet Security, Red Hat, Replit, Robinhood, RunSybil, SentinelOne, ServiceNow, Snowflake, Snyk, Socket, SpecterOps, Tenable, The Clearing House, Trail of Bits, TransUnion, U.S. Bank, Unisys, Vercel, Visa, WWT, XBOW, Zscaler
United Kingdom 6 Arm (SoftBank-owned), Darktrace (Thoma Bravo-owned), Incident.io, Nationwide Building Society, PwC, Sophos (Thoma Bravo-owned)
Israel 4 Cato Networks, Check Point, Cyera, Tenzai
Canada 2 1Password, Shopify
Germany 2 Deutsche Telekom, SAP
Netherlands 1 Elastic
Australia 1 National Australia Bank
Belgium 1 Aikido
France 1 Capgemini
Japan 1 TrendAI (Trend Micro)
Sweden 1 Lovable
Switzerland 1 Zurich Insurance Company

Eighty percent of verified signatories are American. That’s funny for a “global response” letter.

Israel supplies four, all security vendors, because of course. The European Union, where NIS2 and DORA already impose the incident reporting and remediation duties the letter asks for, supplies a measly six: two German, one Dutch, one Belgian, one French, one Swedish.

And then China, India, South Korea, Taiwan, Brazil and every African and Latin American state supply zero.

The letter calls for a “global response” and “new partnerships” and signs itself with 87 American companies, four Israeli security vendors, one Japanese antivirus company under a five-month-old name, and six companies from the European Union.

I guess it’s like how baseball has a world series, or so I’m told.

The cartel thing again

Section 03 asks governments to “expedite the expansion of trusted access programs.”

Section 04 commits frontier companies to “responsible model access.”

Ok, so those programs exist and the letter’s authors are the ones who run them. OpenAI’s Trusted Access for Cyber named its participants on April 16: Bank of America, BlackRock, BNY, Citi, Cisco, Cloudflare, CrowdStrike, Goldman Sachs, iVerify, JPMorgan Chase, Morgan Stanley, NVIDIA, Oracle, Palo Alto Networks, SpecterOps, US Bank and Zscaler, plus grant recipients Socket, Semgrep, Calif and Trail of Bits. Anthropic’s Project Glasswing named Amazon Web Services, Apple, Broadcom, Cisco, CrowdStrike, Google, JPMorganChase, the Linux Foundation, Microsoft, NVIDIA and Palo Alto Networks on April 7. On August 10 OpenAI split Daybreak into Blue and Red tiers, both gating “limited-access frontier cyber models” to approved customers.

Overlay what’s being recommended in the letter with who is in and who is out.

Of 17 Trusted Access participants, nine signed and eight did not. Of the four grant recipients, Socket, Calif and Trail of Bits signed and Semgrep did not. Eight Glasswing partners signed and four did not. Apple, NVIDIA, JPMorgan and the Linux Foundation hold Mythos access and declined to endorse the letter. Bank of America, Goldman, Morgan Stanley, BlackRock, BNY and iVerify hold GPT-5.4-Cyber access and declined. The companies already inside are split on whether to ask governments to do this or not.

Only the companies selling are who signed unanimously.

The anchor for “in the coming months” is also suspect. Says who? OpenAI? Their Defender’s Window post describes an agentic collective that autonomously penetrated OpenAI research infrastructure and Hugging Face production infrastructure during an evaluation. Hugging Face signed. The letter cites the incident nowhere, and skips the detail that the agents got in by chaining unknown bugs with credentials already leaked on the internet. Half of that is a zero-day story. The other half is a password story.

The letter contains no incident data, no actual science or references to forecasts. Its signatories perhaps should have contributed theirs. F5 disclosed in October 2025 that a nation-state actor held persistent access to its BIG-IP development environment and took source code. Capital One paid an $80 million OCC penalty for the 2019 breach of 106 million records. TransUnion disclosed a 4.4 million-person breach in August 2025. Snowflake’s 2024 customer breaches, Okta’s 2023 support-system breach, Oracle’s disputed 2025 cloud breach, CrowdStrike’s July 2024 outage. Every one of those companies signed. None of their data appears in a letter that claims it can predict what the next few months hold.

Follow the money

Tenzai raised $75 million in seed funding in November 2025 on the pitch that enterprises spend five dollars on services for every dollar on product and AI can take the services market. Outtake’s $40 million Series B in January lists Satya Nadella, Nikesh Arora, Shyam Sankar and Trae Stephens as investors; OpenAI is a customer. The Microsoft CEO and the Palo Alto CEO hold personal equity in one signatory that sells to another. Trend Micro renamed its enterprise business TrendAI on March 23 and signed under the new name five months later. Center for Internet Security runs MS-ISAC, whose federal cooperative agreement CISA ended on September 30, 2025; the letter’s “fund cyber defense, starting with essential services” is its own budget request, and it is the only nonprofit I could verify on the list.

What the letter should have said

Section 04 commits frontier companies to “responsible model access.”

Section 03 asks governments to expedite “trusted access programs.”

Both route defensive capability through the labs themselves. Trusted Access for Cyber and Daybreak Blue and Red are a thing OpenAI is selling, and the letter asks governments to expedite it, two clauses after asking them to fund cyber defense.

The alternative architecture already exists and is totally absent from the list. An operator-run gateway puts the model choice, the credentials, the egress policy and the logs on the defender’s side of the wire. Smart, right?

Wirken, released as open source in February 2026, connects the same agent to Ollama on a local box or to Anthropic, OpenAI, Gemini, Bedrock or NIM through one policy layer the operator controls. The “observability and security tools” and “traceable, accountable agentic identities” the letter says you have to get from the frontier companies are elsewhere. Try using gateway functions shipped under an open-source license. A water utility can run them today without a license fee, let alone applying to a lab for trust.

That is the difference between the last two table rows versus the five at the top. The signatories are selling access to defense, by saying it comes from their model. The absent sectors need control that is durable and cost-effective, less dependency on vendors and more independence from them. The letter is an example of how not to write a letter.

Trump Orders All Lakes in America Renamed Lake America

What could go wrong? Trump has ordered lakes in America to be renamed Lake America. Every lake shall forthwith be known for what it is, to reduce confusion about where it is. This genius move is believed to be the kind of bold and decisive action to make travel far easier, while it rapidly increases American test scores in geography. Likewise, every state will be more appropriately named to United State, with capitals renamed to State Capital.

Washington Tells Kyiv Hold Fire So CIA’s Ratcliffe Could Land in Moscow

Did you hear that a Texas politician, and current CIA Director, John Ratcliffe flew to Moscow this week? The Wall Street Journal, then Politico and CBS, stated the purpose was to warn Russia against attacking NATO. CBS added that he also went to talk Iran, threatening sanctions unless Hormuz reopens. Peskov said contacts were only made between intelligence services, as Putin stayed out of it. Trump, always the one to state the inverse of reality, called the unusual trip “semi-routine.”

The same day AP quoted a U.S. defense official in Europe and a NATO official calling Patriot interceptor inventory in Europe “beyond critical,” drained by Hegseth without anything to show for it. The U.S. official said Europe has “very limited” capability against even a single ballistic missile. The Pentagon and NATO of course deny the Hegseth-folly on record. Meanwhile, CSIS puts U.S. inventory at 2,330 interceptors before February 28 and roughly 800 today, which suggests 65 percent may have been spent on Iran. In other words, at least sixteen U.S. military sites were hit, personnel pulled out of the ones too exposed to hold, and intelligence hardware from a Riyadh CIA station to the TPY-2 radar in Jordan was lost, while Hegseth threw away the “defense” capabilities of America. Beyond all the misfires he didn’t plan ahead and so his brevity code is Winchester.

Inside the service, the cash shortage is no secret. “They’re just not speaking publicly about it,” said Todd Harrison, a defense analyst at the conservative American Enterprise Institute. “And I suspect that is a deliberate decision of the civilian leaders in the Pentagon, starting at secretary, that this is for political reasons, that they don’t want to look like they’re damaging future military readiness over a war that is becoming increasingly a political liability.”

Let’s synthesize the headlines. A warning delivered from an empty magazine is America disclosing its response ceiling being dramatically lowered. Remember how Biden sent Burns to Moscow in November 2021 to warn against invading Ukraine? It’s a lesson in lowering the ceiling. He wagged a finger at Moscow about sanctions and Ukrainian aid, with U.S. troops ruled out in public. Putin gleefully and stupidly invaded four months later. Ratcliffe’s apparent worry is a ballistic missile strike on NATO. AP’s own sources place this years away at best while Russia bombs Ukraine nightly. So an effect of a CIA director personally arriving to say please don’t ballistic Germany, means everything below that line is allowed by Trump? That Leipzig drone bearing GRU hallmarks to blow up Ukrainian aircraft, eighteen drone disruptions at one airport since January, the Vulkan campaign knocking out critical infrastructure that Dobrindt calls daily hybrid warfare while insisting Germany is “not at war”, are the real question now.

Moscow’s hybrid warfare expansion is undeniable. In February I described three failure modes converging on the Russian economy this summer. The Iran war postponed them. Urals went from $55 to $125 and Bruegel counts 1,184 billion rubles of windfall through June. The structure held underneath. July’s deficit was 724 billion rubles, seven months at 2.8 percent of GDP. Ukrainian refinery strikes converted the export windfall into fuel queues in 66 regions, wage delays, cash withdrawals, and anger that DW’s respondents say points at… the West. A regime in that condition craves a cheap external conflict. Germany foolishly banked on American Patriot launchers and now can’t get the missiles to load in them. That’s why it’s so, so important to read this detail: the C-17 staged through Riga, sat on the Vnukovo apron for eight and a half hours, and Washington had to ask Kyiv to suspend strikes until it left. The ally briefed in advance was the one told to stop shooting. Whether Berlin heard anything before the motorcade footage hit social media is a question for Henrichmann’s oversight committee to get on the record.

In usual Trump style, his men went begging for help on Hormuz from the country that is profiting most from Hormuz staying shut, having already granted Russia a 30-day oil waiver in March. The Kremlin put some people in the room to listen, and what they heard confirmed Germany is on the table.

I guess my real outstanding question is, while Germany was getting the boot, was Snowden given any offers? CBS noted that Ratcliffe personally negotiated the Karelina release in April 2025, and Moscow freed a former Marine earlier this month. Detainee trading is his usual beat.

The Antisemitism of Peter Oberacker

The category of antisemitism that Republican State Sen. Peter Oberacker practices has a name in German scholarship: Schuldabwehr-Antisemitismus or “guilt defense”.

Adorno’s 1959 lecture and Schönbach’s 1961 study made this clear, so it’s no surprise to anyone. The defining move is the defense of the perpetrators’ memory at the expense of the victims’. Oberacker posted a photo of Hitler’s soldier on Veterans Day 2015 with the caption “gave his life for his country,” and when the post resurfaced in August 2026 he added “war sucks,” “veterans of all conflicts,” and “didn’t have a choice.” Each sentence exists to unfairly place the Wehrmacht dead on the same ledger as the people the Wehrmacht killed.

Oberacker posted this photo with an antisemitic caption. When confronted with it, Oberacker said he looks at the picture differently now in light of mounting antisemitism, while he expanded into even more antisemitic statements.

Wehrmacht criminality was in evidence at Nuremberg in 1946 and tried separately in the High Command case in 1947 and 1948. The Hamburg Institute’s exhibition ran from 1995 and again from 2001. Germany’s own national Veteranentag, approved by the Bundestag in 2024 and first observed June 15, 2025, covers Bundeswehr veterans only. The Federal Republic declines to salute its predecessor army. An American congressional candidate applies a far weaker standard to the Wehrmacht than the German defense ministry does. And think about it in American terms. Memorial Day was created to honor the Union soldiers who died defending America against the Slaveholder Rebellion. To say an enemy of the state, the Wehrmacht or the Confederacy, should be memorialized the same as the people killed trying to stop them, is nonsense.

The Bundeswehr’s 2018 Traditionserlass states that for the armed forces of a democratic constitutional state the Wehrmacht as an institution cannot found tradition; individual Wehrmacht members may be included only after case-by-case examination that weighs personal guilt and requires an exemplary act, such as participation in the military resistance.

All that is to say we are looking at antisemitism as the scholarship defines it, met in the 2015 caption and three more times in just one interview about it. The IHRA examples include denying the mechanisms of the genocide. The Wehrmacht was a mechanism, and a defense of the Wehrmacht that never names what it did erases that mechanism and harms the victims. So the claim is exact: he committed an easily recognized form of antisemitism, in public, and then he defended it, which is itself another level of antisemitism.

How did he defend it? By falsely accusing others of antisemitism. Take a look at his methods of disinformation.

For Mamdani, an elected official, and Piker, a streamer who holds no office, they only have taken positions on Israel and Zionism; neither has a single documented statement expressing hostility to Jews as Jews, and the IHRA definition itself states that criticism of Israel like that leveled at any other country cannot be regarded as antisemitic. Oberacker undermines the definition, as he fails to understand that his accusations only make himself look more antisemitic. It is antisemitic to make every Jew answerable for an Israeli government, which is what accusations do when they treat any criticism of Israel as the offense. Jews can live outside of Israel, and Jews everywhere criticize Israel. Zionism itself is of Christian political lineage that predates Jewish political campaigns by half a century. Restorationism, from Shaftesbury’s 1840 memorandum to Palmerston through Balfour, wanted Jews settled in Palestine partly to remove them from Europe, an aim it shared with the antisemites of the period. A political idea with that ancestry can and should be criticized, especially given the foundational hostility to Jews (treating them as disposable tools for political purposes).

And then look at Oberacker’s accusations against politician Platner. It’s almost too stupid to believe. The evidence is a tattoo Platner says he got it as a Marine without knowing and has since covered it. A skull resembling the Totenkopf circulates in military settings because of a culture that reads Wehrmacht and SS insignia as period detail rather than as antisemitism. That culture is the exact same one Oberacker practices when he reads an actual Hoheitsadler on his grandfather’s chest as circumstance. The accusation of Oberacker should be pointed at himself, because the standard he applied to Platner convicts himself first in 2015.

The antisemitism of Oberacker has no content about Jews, and that’s his whole game. He erases the people who are meant to be protected, because he uses it to enable himself instead. It is a designation he assigns to his opponents and withholds from allies and ancestors. Look at how he hired as campaign manager Bobby Walker, a Young Republican officer who took part in a leadership group chat that praised Hitler, and removed him only after Politico published the messages in October 2025.

A man who very clearly and openly practices antisemitism while prosecuting others on evidence he would never accept against himself is not some flawed opponent of antisemitism. He is antisemitic, an active participant, where he doesn’t need to help living or dead Jews at all, because his use of the term is only for his own political benefit.