The next major test for artificial intelligence may take place far from the technology industry’s traditional centers of attention. Hospitals, water utilities, government systems and other critical infrastructure could become the proving ground for whether AI ultimately makes the digital world more vulnerable or more secure.
That question is at the heart of a new cybersecurity initiative from OpenAI. Palo Alto Networks, Mate Security, and ServiceNow are among the first-day signatories of the company’s open letter, “A Call to Action on Cyber Defense,” supporting a coordinated effort to put AI capabilities in the hands of organizations responsible for defending essential services.
The initiative arrives at a time when many of those organizations face a difficult reality: their security problems are often longstanding, while the capabilities available to attackers are evolving quickly.
The Weaknesses Are Already There
OpenAI’s warning does not suggest that AI is creating every vulnerability from scratch. Many of the weaknesses facing organizations today have existed for years.
The letter points to insecure and unpatched software, excessive permissions, misconfigurations, weak authentication and technical debt in legacy systems. Critical infrastructure organizations can be particularly exposed because they may lack the staff, budgets or operational flexibility required to modernize systems quickly.
“We have a limited window to strengthen cyber defenses,” OpenAI states.
The concern is that increasingly capable AI could allow attackers to discover and exploit these weaknesses more efficiently. That creates pressure on defenders to improve their ability to identify and remediate problems at a comparable pace.
Turning AI Into Defensive Infrastructure
OpenAI’s proposed response is to make cyber-capable AI broadly available to defenders.
The company is calling on organizations to use AI for broad security coverage while applying more advanced capabilities to the hardest defensive problems. It also wants organizations to verify that fixes actually work and to incorporate stronger security requirements into the software and systems they purchase, build and deploy.
For cybersecurity companies, the expectations are even more expansive.
OpenAI is asking vendors to continuously test defenses against advanced cyber capabilities, enhance existing products with AI, share threat intelligence and tested playbooks, and help critical infrastructure operators deploy and validate defensive technologies.
Three Different Models Of Leadership
The inclusion of the companies as first-day signatories highlights three distinct approaches to this transformation.
Palo Alto Networks comes from the established cybersecurity market, where AI can be integrated into a broad portfolio of security technologies used by large organizations.
Mate Security is approaching the problem from a different direction. The company is building an open foundation for agentic cyber defense, where AI agents can conduct investigations and respond to changing evidence rather than simply execute static automation.
Its Gamebooks technology is designed to give those agents structured procedures while retaining the flexibility to reason, pivot and act as an investigation unfolds.
ServiceNow occupies a third position, in the enterprise systems where security work is assigned, coordinated and closed out. That part of the process carries particular weight for the organizations at the centre of the letter, where patching often depends on maintenance windows that essential services can rarely afford and where remediation has to move across teams well beyond the security function. OpenAI’s insistence on verifying that fixes actually work makes how reliably that work is tracked a security question in its own right.
Those models reflect a broader change taking place inside security operations. As AI becomes more capable, the industry’s objective is moving beyond automating individual analyst tasks toward building systems capable of carrying out larger portions of defensive workflows.
The Trust Question
That transition comes with its own challenge: autonomy is useful only if security teams can trust it.
An agent that can investigate and act without constant human intervention can dramatically expand a security team’s capacity. But organizations also need visibility into what those agents are doing, clear accountability and safeguards that prevent autonomous systems from operating outside approved processes.
OpenAI’s letter recognizes this requirement, calling on frontier AI companies to build observability and security tools and ensure that “agentic identities are traceable and accountable.”
For companies such as Mate Security, that issue is central to the future of agentic defense.
From Statement To Action
OpenAI’s proposal ultimately calls for coordinated action rather than another technology cycle.
“Each of us can reduce risk now,” the letter says, calling on organizations, cybersecurity companies, technology partners, governments and AI companies to contribute tools, funding and hands-on support.
Palo Alto Networks, Mate Security, and ServiceNow joining as first-day signatories places all three companies among the market leaders publicly supporting that objective. More importantly, it reflects an emerging view within cybersecurity that AI cannot be treated solely as a new source of risk.
The technology is also becoming part of the answer, and the companies building the next generation of defensive systems will increasingly be measured by how effectively they can turn that potential into protection for the infrastructure organizations depend on every day.

