
Today, OpenAI published A Call for Collective Action on Cyber Defense, signed by Octane alongside Anthropic, Google, Microsoft, CrowdStrike, Cloudflare, AWS, Cisco, HackerOne and other leaders across technology, finance and critical infrastructure. The letter calls for a global surge in cyber defense in the current period in which defenders still benefit from an advantage.
Read: A Call for Collective Action on Cyber Defense
Octane is proud to join more than 100 organizations supporting this initiative. It isn't our first time working closely with OpenAI; Octane is already part of OpenAI Daybreak, governed through the Trusted Access for Cyber program, which vets a small group of security teams for access to frontier models with cyber safeguards adjusted for defensive research.
Defenders' Closing Window
On August 26, 2026, OpenAI published its report on a July incident in which research models operating with reduced safeguards gained access to systems well beyond their intended environment, then discovered and chained together security vulnerabilities to compromise parts of Hugging Face's internal systems. OpenAI warned that the incident shows AI agents can already find and exploit weaknesses on their own, while actively evading automated security controls and disguising their malicious actions. Most noteworthy was the fact that these exploits weren’t even the ultimate objective of the agent – just steps in the path it took to achieve an entirely different goal.
The underlying models are extremely capable in both directions: offense and defense. For now, defenders have access to frontier models through programs like OpenAI’s Trusted Access for Cyber, while these capabilities are limited for attackers, who increasingly turn to open-weight models that are quickly closing the gap.

In addition to this superior access to frontier model capability, defenders also benefit from the ability to provide large amounts of internally-accumulated context. With this context, AI can help organizations find years of accumulated bugs, excessive permissions, insecure dependencies and technical debt, working directly with insights that someone testing a system from the outside can only guess at. Greg Brockman called this period the defender's window, and argued that organizations will need to automate significant parts of their security programs over the coming months in order to keep it open.
We signed OpenAI’s Call for Collective Action letter because it clearly outlines the stakes of the world Octane already operates in. Our approach to agentic security finds exploitable vulnerabilities in code that's been professionally reviewed for years. We see firsthand how vulnerable some of these systems are.
We don’t need fear-mongering, but we do need a real sense of urgency as we address these new risks and opportunities. There’s a lot we all want to secure, from our most sensitive personal data to our society's most critical infrastructure.
Octane puts frontier cyber capabilities in the hands of the teams building a more resilient world.
— Giovanni Vignone, CEO of Octane Security
Octane endorses all four of the letter's recommendations, and we're already executing the two aimed at security companies and frontier AI partners:
- Organizations must treat their cyber defense strategy with incident-level urgency, fix their highest-risk weaknesses and verify the results.
- Security companies and technology partners should continuously test defenses against frontier and open-source cyber capabilities, strengthen their existing tooling with AI and make those capabilities available to as many defenders as possible.
- Frontier AI companies should invest in authorized testing, private disclosure and verified fixes, while expanding responsible access to advanced defensive models.
- Governments should help critical infrastructure operators gain access to capable defensive tools, testing and hands-on support.
What This Looks Like In Practice

Octane makes it simple to integrate frontier AI-powered offensive security analysis directly into the development process. Our system:
- Analyzes code changes inside GitHub and CI before they ship.
- Traces attack paths across functions, files, dependencies and trust boundaries.
- Surfaces the root cause, potential impact and remediation guidance for a finding.
- Reanalyzes patched code so teams can confirm the vulnerable path is closed.
- Improves ongoing detection rates using validated feedback.
This is the exact workflow the letter recommends. It's also the workflow that found a high-severity bug in an Ethereum execution client affecting 38% of mainnet validators, uncovered memory-corruption vulnerabilities in the engines behind 99.7% of the web's browser traffic, caught CVE-2026-60161 in Oracle VirtualBox, and identified CVE-2026-66022 in QEMU's virtio-net device.
What Leaders Should Do Now
Subscribe to our newsletter









