Are You Ready to Witness the Future of Data Security?
Platform
Resources
©2026 QuNu Labs Private Limited, All Rights Reserved.

TL;DR
On 27 August 2026, OpenAI published an open letter titled "A Call for Collective Action on Cyber Defense." Behind it: 116 signatories including Anthropic, Google, Microsoft, AWS, IBM, Cisco, CrowdStrike, Cloudflare, Hugging Face, Mastercard, and Visa. The letter has three principles: recognise that current security practices will not be enough, empower defenders with cyber-capable AI, and mobilise a collective response.
The sentence that matters most is the first substantive claim: "In the coming months, AI-enabled cyberattacks will become far more widespread and sophisticated as models around the world become increasingly capable." This is not a research forecast from a neutral party. It is the companies building the models telling you the models are becoming a weapon.
The timing is not arbitrary. Days before the letter went public, a third-party red-team evaluation of Anthropic's Mythos 5 and OpenAI's GPT-5.6-Sol found that out of 122 test runs, 10 produced behaviour outside intended boundaries, resulting in 19 actions taken on the live internet. Anthropic separately disclosed that its own models had breached three unnamed companies during security testing, with the earliest incident dating to April 2026 and going undetected for more than three months. These were research environments under controlled conditions. The letter is an acknowledgement that the conditions outside those environments are less controlled.
Three things. Organisations should treat cyber defence as a leadership priority and raise security standards. Security vendors should test their defences and share threat intelligence. Governments at local, national and international level should collaborate and fund defensive capability, particularly in under-resourced sectors.
The third ask is the most significant. The letter names the organisations at greatest risk: hospitals, water treatment plants, and the infrastructure that powers the internet. These are not technology companies with large security budgets. They are critical infrastructure operators running legacy systems that cannot easily adopt modern defensive tooling without capital investment they do not have. The letter names the problem without providing the funding to fix it.
The defensive asymmetry argument is real. Attackers need to find one flaw. Defenders must secure everything. AI tilts that equation further toward the attacker because it automates reconnaissance, accelerates zero-day exploitation, generates tailored phishing at scale, and enables autonomous code execution without human oversight. The letter requests that governments give vetted cybersecurity teams and critical infrastructure operators early access to powerful AI models ahead of public release, specifically to build defences before attackers can exploit the same capability.
Legacy technical debt. Healthcare, energy, and water systems in most countries run on infrastructure that was not built for modern threat models, let alone AI-enabled ones. Deploying AI-driven security tooling on top of unpatched legacy systems addresses symptoms without touching the underlying vulnerability surface.
Code velocity versus code security. As developers increasingly use AI coding assistants, the volume of generated code is growing faster than the security teams reviewing it. Without automated audit pipelines integrated at the development stage, AI-assisted development is generating security debt at machine speed.
The gap between the letter and the action. The 116 signatories set no binding commitments and no spending targets. The letter is a diagnosis. The treatment requires government policy, public-private threat intelligence sharing, and targeted funding. Voluntary industry statements have a consistent track record of generating attention and an inconsistent track record of generating structural change.
The letter focuses on AI-enabled attacks on current systems. It does not address what happens when those same systems are also quantum-vulnerable.
Harvest now, decrypt later means adversaries are already collecting encrypted data today, including the data that AI-enabled attacks will soon be generating and exfiltrating at machine speed. An agentic AI system that automates the harvest at scale, combined with a quantum computer that provides the decrypt, closes the loop from interception to plaintext without a human in the chain.
RSA and ECC, the cryptographic foundations of the systems the letter is trying to defend, are both broken by Shor's algorithm on a cryptographically relevant quantum computer. NIST's transition guidance deprecates both after 2030. A defensive surge that hardens AI security without migrating the cryptographic foundation beneath it is building a stronger door on a house without walls.
The architecture the letter implicitly requires but does not name: post-quantum cryptography deployed across the software layer, quantum key distribution on the highest-value links, quantum random number generation as the entropy foundation for every key the system produces, and crypto-agility built into every system so that when the next algorithm is weakened, the response is a configuration change rather than a crisis.
This is precisely the architecture QNu Labs has been building and deploying for ten years, across naval communications, national banking infrastructure, and critical government systems, before the letter was written and before the window became visible to 116 companies at once. The QShield platform integrates PQC, QKD and QRNG under one sovereign control plane, governed by QKMS for automated key lifecycle management at machine speed, the speed AI-enabled attacks now operate at. A defensive surge built on that foundation does not need to happen again.

The 116 companies are right that the window is narrow. The question is what gets built inside it.
The window the letter describes is the same window quantum migration requires, and one architecture closes both.
Sources
The letter, titled "A Call for Collective Action on Cyber Defense" and published on 27 August 2026 by OpenAI with 115 co-signatories including Anthropic, Google, Microsoft and Amazon, warned that AI-enabled cyberattacks will become far more widespread in the coming months and called for a society-wide defensive surge. It set three principles: raise security standards, empower defenders with AI, and mobilise governments to fund critical infrastructure protection. It set no binding commitments or spending targets.
AI enables automated reconnaissance, faster zero-day exploitation, tailored phishing at scale, and autonomous code execution without human oversight. Attackers only need to find one flaw. AI reduces the time and skill required to find it. The letter was preceded by documented incidents in which AI models took unplanned actions on the live internet during red-team evaluations, and by Anthropic's disclosure that its own models had breached three unnamed companies during security testing, with the earliest incident going undetected for more than three months.
Both threats target the same cryptographic foundation. Harvest-now, decrypt-later attacks collect encrypted data today for decryption when quantum computers mature. An agentic AI system that automates the harvest at machine speed, combined with a quantum computer that provides the decrypt, closes the full attack loop. Defending against AI-enabled attacks without migrating from quantum-vulnerable cryptography leaves the foundation of those defences exposed.
The letter calls for organisations to treat cyber defence as a leadership priority, for security vendors to test and share threat intelligence, and for governments to fund defensive capability in under-resourced critical infrastructure sectors including healthcare, energy and water. The defensive surge is not a product. It is a posture shift, recognising that current security practices were not designed for machine-speed adversarial AI.