Sophos has long believed that openness and transparency make the cybersecurity community stronger. That is why we have signed OpenAI’s A call for collective action on cyber defense, an open letter urging organizations around the world to help strengthen cyber defenses as AI changes the threat landscape.
As AI-enabled attacks become more widespread and sophisticated, increasing the risk to businesses and the public services that communities depend on, it’s clear that cyber defense is a shared responsibility. The letter rightfully calls for coordinated action across the private and public sectors, with frontier AI labs playing an important role.
Sophos shares that sense of urgency. Signing the letter is an outward expression of the work we have pursued for years:
- Opening useful research to the security community.
- Bringing effective protection within reach of every organization.
- Applying new technology responsibly.
These principles have shaped Sophos for years, and they also define the work ahead.
Why we agree with the letter
The letter begins with what we already know: “We have a limited window to strengthen cyber defenses.”
Longstanding vulnerabilities and legacy systems continue to leave organizations exposed, and misconfigurations and excessive permissions only add to that exposure. While AI can help attackers identify and exploit these weaknesses more quickly, it can also give defenders new ways to find exposures, connect weak signals, and respond to threats before they cause material harm.
Of course, defenders in turn must be able to turn AI capability into action across real environments, not just demonstrate what a model can discover.
The letter also makes two more calls to action: Expertise needs to reach more defenders, and the response must be collective. We agree. One organization’s work can help protect many others when defensive knowledge is shared responsibly.
These ideas reflect principles that have shaped Sophos for a long time:
- Credible work should be open to scrutiny.
- Advanced capabilities should benefit organizations of every size.
- Progress should be measured by whether weaknesses are fixed and attacks are stopped.
Openness and responsible sharing strengthen cyber defense
We have long believed that opaque or guarded claims make it difficult for customers and researchers to understand how AI contributes to protection. Openness allows ideas to be tested, findings to be challenged, and useful work to become a foundation others can build on.
SOREL-20M was an early example of our commitment to that belief. Developed with ReversingLabs and released in 2020, the research dataset made 20 million files available to support work on machine-learning methods for malware detection. It gave researchers a substantial, reproducible resource for testing ideas and advancing defensive work.
The same principle applies as cyber-capable AI models become more powerful. Sophos believes in sharing research and practical resources in ways that help defenders while protecting sensitive information, respecting organizations whose environments generate defensive insight, and reducing the risk of misuse. One practical example is the Sophos Trust Center where we share practical resources and detail our security strategy, principles and policies.
Openness and appropriate safeguards should work together, particularly when research draws on real-world attacks and customer environments. That balance helps the security community move forward without losing sight of the trust placed in it. Done well, the resulting transparency creates confidence in how defensive AI works, while clear boundaries preserve the trust required to keep learning from real-world attacks.
Expertise needs to reach more defenders
Sophos is committed to democratizing cybersecurity by closing the strategic capability gap. We believe the best protection should be available across the market, and that includes organizations operating without the adequate money, expertise, capability, and influence to build durable resilience. These organizations face the same threat actors, vulnerabilities, and sophisticated cyber threats as other businesses but lack the strategy capabilities to defend against them.
As attacks accelerate, the consequences of that capability gap become more serious.
This is why access matters as much as technical capability. A powerful AI model has limited defensive value if only a narrow group of highly specialized organizations can deploy it safely and turn its findings into action.
Sophos protects more than 625,000 customers worldwide, from the largest enterprises to SMBs, including environments managed by our Managed Services Provider (MSP) partner community. Our reach gives us a responsibility: to help translate advanced research and frontier-model capability into protection that organizations of different sizes and levels of security maturity can actually use.
Collaboration with frontier labs is one of our ways of contributing intelligence from our unique position in the cybersecurity landscape. Our participation in the OpenAI Daybreak Cyber initiative and partner program along with Anthropic’s Project Glasswing serve as examples of that commitment.
Sophos is working to make frontier capabilities useful within security products and services that organizations can put to work without having to assemble rare expertise themselves.
Turning advanced AI into action with connected defense
The letter places welcome emphasis on what happens after a weakness is discovered. Finding an exposure has limited value until a defender can address it and confirm that the risk has been reduced. However, this also requires context: an understanding of the organization, its control points, and the activity unfolding across them. Without that context, even a strong model risks producing another isolated finding for an already stretched team to interpret.
Sophos Fusion illustrates how we are putting this principle into practice. As the industry’s most complete AI-native cybersecurity defense system, Sophos Fusion sees everything, connects everything, and enables an organization’s defenses to respond as one. This shared context allows the system to coordinate defenses across an organization rather than treating every alert or product as an isolated source of information.
This is how AI becomes operationally useful; it can collapse the exposure window and deliver response at the speed that modern attacks demand.
Human accountability remains essential
The letter calls on organizations to expand automation carefully while keeping people responsible for consequential decisions. We agree. AI should extend the reach and speed of defenders while people remain accountable for decisions that can materially affect an organization.
Human specialists must define the trust boundary: what AI may do on its own, what requires review, and when experts need to intervene because the context is unfamiliar, confidence is low, or the potential impact is high. By being a human “on the loop”, they must also be able to audit what the system did and provide expertise when atypical cases appear that AI can’t solve immediately.
Putting collective defense into practice
AI requires organizations to strengthen their defenses against AI-enabled attacks, apply AI responsibly for cybersecurity, and secure the AI-enabled systems that are increasingly deployed across all lines of business.
Sophos signed this letter because collective defense must be more than an aspiration. It should create a practical standard for how the industry builds and applies AI for cybersecurity:
- Share research and expertise responsibly so useful work can help more than the organization that produced it.
- Extend frontier capabilities to organizations that do not have specialist expertise or large security teams.
- Connect defenses into practical outcomes across real environments, with people maintaining accountability for the boundaries, decisions, and outcomes that matter.
The aim is not just to make AI more capable; it is to make cyber defenses more effective, more accessible, and more trustworthy. That is the commitment Sophos is making by signing the open letter, and the standard against which we believe progress should be measured.
The tools are already available. As the letter says, let’s put them to work.

