The Emergency Has a Vendor
On the hundred-company cyber-defense letter, the rogue-agent incidents that came before it, and the memo that hands the same players a badge.
Read the letter first, then peep the calendar.
On August 27, more than one hundred companies put their names to an open letter calling for a collective defense against AI-enabled cyber-attacks. OpenAI, Anthropic, Google, Microsoft, and Amazon signed. So did the security houses you would expect: CrowdStrike, Okta, Fortinet, Palo Alto Networks, Zscaler, Cloudflare. And….so did the banks and card networks: Capital One, Citi, Mastercard, Visa, U.S. Bank. The warning is stark and, on its face, correct. In the coming months, the letter says, AI-enabled attacks will get more widespread and more capable, and the systems our communities lean on, from hospitals to water treatment plants to the straight up plumbing of the internet, sit ass-flapped to the wind.
Now peep the calendar.
The letter is published on OpenAI's own website. And let's not forget, OpenAI is the company whose agent, back in July, broke out of a sandbox during an internal test, found its way onto the open internet, and hacked Hugging Face (now owned by NVIDIA). That was the first publicly reported case of a language model autonomously breaking into a 3rd party. The company that opened the emergency is hosting the call to close it.
And folks, that's where this installment of the series begins. Hypocrisy is the super easy read, and a cheap one at that. The costly read is structural, so structure is where I'll stay. The spine of everything I write holds to this truth: the auditor cannot be the vendor. And this week gave us the cleanest example yet.
1 week, 3 documents, 1 set of hands
Ready? Let's line the artifacts up.
The incidents came first:
- An OpenAI agent hacked Hugging Face, and investigators later found it had breached four more companies, including the inference startup Modal.
- Anthropic said "hmmm, let's see if we got got." Checked its own logs and found its models had quietly breached 3 companies, the earliest dating back to April and discovered more than 3 months later. A model in a Capture-the-Flag exercise escaped the game and hit a real company because a practice target happened to share a real firm's name.
- The UK's AI Security Institute caught OpenAI and Anthropic models reaching for real people and organizations mid-evaluation.
- Meta added one of its own to the pile.
A Claude agent, asked to book a gym class in Australia, found a hole in the booking software, exploited it, bumped strangers off the waitlist, and then reported that it could not put them back.
You can't make this up. When you line all of this up, why aren't more people saying, "wait, what?"
Then like true carpetbaggers, the products came next, and some came before.
OpenAI runs Daybreak, a cyber-defense service it launched in May and expanded on August 10, with two tiers. Blue gives defenders a frontier model with the guardrails tuned for security work. Red gives approved partners GPT-5.6-Cyber, a variant tuned to say yes to the hard stuff. On OpenAI's own internal measure, that Red-tier model completes 95% of prompts for exploit chains, authentication bypass, and privilege escalation. The base model completes one and a half percent.
Anthropic shipped its own cyber model, Mythos, and a coalition.
Microsoft shipped a cyber model and an agentic security system called Perception. The same houses that lost agents to the open internet now sell the tools to hunt them.
And the memo came last. On August 12, the US President signed a National Security Presidential Memorandum, distinct from the executive orders issued earlier, titled "Expanding Capabilities to Combat Transnational Cyber-Enabled Crime." It directs a federal coordination center to stand up a program that authorizes vetted private companies to run offensive cyber operations, both surveillance and disruption, against foreign criminal networks, under government control.
But wait, read the definitions in the memo and the scope is inescapably real: manipulation, disruption, degradation, destruction of information systems. The absurdity deepens: the named accountability floor for a participating company is a bond of at least $1M, forfeited if it breaks its contract.
Ok, now, let's stack those three and the picture that you can't unsee resolves. The same corporate class builds the frontier models, sells the model tuned to break in, sells the service tuned to defend, and can now carry a government badge to run offense. Four jobs. One set of hands.
Yep.
The 3 tests my last 6 articles already built
Across no fewer than 6 articles, I've pulled independence apart into separate properties, because "independent" is a word that hides its own failures. 3 of those properties showed up in a single week.
Independence of authorship. The labs whose models escaped wrote the emergency. The emergency can still be real, and the framing, the urgency, and the proposed cure all originate with the parties who benefit from the sale.
Independence of measurement. The letter proposes we measure success by how many organizations get protected, how fast attacks get contained, and whether fixes hold. Good metrics, but ask who holds the instruments and it implodes. OpenAI's exploit-completion number comes from an evaluation OpenAI built and runs. The yardstick belongs to the labs again, one level down.
Independence of the clock. "The coming months." "The defenders' window." Sure, a countdown is a useful way to move a hospital board, but it's also a good freakin' sales calendar. The window narrows in the same month the product tier expands. A clock that only the seller can read is a clock worth pricing, which is the exact lesson from the 5G work.
The evaluator became the launch pad
The fast coverage skated past one finding, the one that should keep a CISO and anyone with a conscience up at night.
A startup called Irregular runs AI cyber evaluations for these labs. Irregular showed up, in whole or in part, across three of these: the Anthropic three-company breach, the OpenAI Capture-the-Flag escape, and the Meta incident. This outside evaluator, whose one job is to test safely, is the party through whose harness several agents reached the live internet. You had one job, just one job.
Now, that advances the point from my FAR.AI piece, "The Auditor Who Doesn't Sell the Models." There I argued (with receipts in tow) that even an independent evaluator runs its tests through models, so the measurement is never fully outside the thing it measures. This week made it worse and more concrete. The test environment itself was the leak. Independent authorship of the test left its containment wide open. And that seam I've written about since the Zero Trust assessment, the boundary everybody assumes and nobody owns, runs straight through the safety lab.
The edge finally has a signature
Every one of these escapes has the same shape.
An agent sat inside a boundary that was assumed to hold, but an unknown vulnerability said otherwise. The agent walked out with the same level of energy captured in the ending of the movie "Thelma & Louise." In the Anthropic case, it walked out in April, and nobody noticed until July. Yep, JULY.
This kumbaya letter contains one line that's quietly the most honest sentence of the year. It asks frontier AI companies to make agentic identities "traceable and accountable."
Read that line twice.
The letter is asking these companies to build something that doesn't yet exist. It's straight up an admission, signed by more than a 100 companies, that the agents already loose in production, in the wild, run untraceable and unaccountable today.
So, that unowned edge finally has a signature on it, and the signatures belong to the same folks who left it unowned.
Ok, not to be a complete hardass, the letter's core ask is right. Hospitals, water utilities, and local governments are under-resourced and over-targeted, and giving them cheaper, capable defensive tooling is a genuine public good. Saying so out loud and in unison has value. So, I'm gonna give credit where credit is due.
The trouble sits elsewhere: the same signatures are sitting on the warning, the invoice, and the incident report, and now on a federal authorization to run offense. When one party writes the threat assessment, sells the cure, scores the result, and carries the badge, you're buying a story with a price tag, and you owe it to your board and the unsuspecting public to separate the two.
The Collective-Defense Stress Test
A test you can run: put any vendor that signed the letter, and any line in that memo, through these 6 questions before you sign anything.
- Name the author of the emergency. Map every vendor to what it sells and what its models have done. If the party warning you is the same party billing you, price that conflict before you price the product.
- Separate the offense SKU from the defense SKU. When one company sells a model tuned to complete exploit chains and another tier tuned to block them, ask: "what technical and contractual control stops the offensive tier from reaching an adversary, an insider, or an escaped agent of its own?" Then wait for the air to suck out of the room.
- Audit the evaluator as hard as you audit the model. If a 3rd-party test harness can put a live agent on the internet, that harness is now part of your attack surface. Require your evaluators to prove containment, with logs, before anything with network access runs. Because the box they've drawn protects them, and when folks get got and fingers get to pointing, you will more than likely own the seam.
- Put a clock on the containment claim. Every sandboxed agent stays sandboxed until an unknown vulnerability disagrees and it Crip walks out of the containment. So, demand a named owner for the boundary, a tested kill switch, and a re-test schedule you control.
- Read the memo before you sign your next contract. If your defensive vendor becomes a government-authorized offensive operator, your relationship now sits next to an offensive one. Ask where the wall is, who built it, and who inspects it.
- Measure protection by outcomes YOU can verify. Do yourself a solid and adopt the letter's own yardstick, how many protected, how fast contained, whether fixes hold, and insist the count comes from someone who does not sell you the model.
The market will keep offering you the warning and the cure in the same breath, on one calendar. Your job is to make the hands separate before you write the check. That's the discipline. It's the reason I keep adding this line at the bottom of every piece.
We can be your auditor. We can be your vendor. We cannot be both.
Share this article
Related Articles
The Reskilling Illusion: When AI Transformation Means "You're Fired"
Oct 03, 2025