More than 100 organizations, including OpenAI, Anthropic, Google, and Microsoft, have jointly called on businesses and governments to prioritize cyber defence at the leadership level. Their appeal comes just weeks before the EU’s Cyber Resilience Act takes effect on September 11, mandating stricter vulnerability reporting and response requirements.

  • 100+ organizations call for urgent cyber defence leadership
  • EU Cyber Resilience Act enforces vulnerability reporting from Sept 11
  • NIS2 directive enforcement delayed in several EU member states

What happened

Over 100 organizations, including major AI and tech firms such as OpenAI, Anthropic, Google, and Microsoft, signed an open letter urging immediate prioritization of cyber defence by both the private and public sectors. The signatories emphasized the necessity of fixing software vulnerabilities and improving defensive measures against emerging AI-powered cyber threats.

This appeal aligns closely with the imminent implementation of the EU Cyber Resilience Act, which becomes mandatory starting September 11, 2026. The new legislation requires manufacturers of digitally connected products to report exploited vulnerabilities and significant security incidents promptly, establishing strict notification timelines and centralized reporting through national response teams and ENISA.

Why it matters

The open letter underscores a critical moment for cybersecurity as advances in AI create both heightened risks and new defensive capabilities. The call to action stresses that leadership must actively address entrenched security gaps before the defenders’ window closes, positioning cyber defence as integral to organizational strategy rather than an operational afterthought.

Europe exemplifies the urgency and complexity of this challenge. While the Cyber Resilience Act sets a rigorous legal baseline for vulnerability disclosure, the related NIS2 directive—intended to enhance government and industry coordination—has seen significant implementation delays. Several EU countries have missed deadlines, prompting legal actions and penalties, signaling persistent obstacles in establishing robust pan-European cyber resilience.

What to watch next

The effective start of the EU Cyber Resilience Act on September 11 will mark a pivotal test of the continent’s ability to enforce rapid cyber incident reporting and strengthen software security standards. Observers will monitor how swiftly manufacturers comply and how national authorities handle the new requirements in practice.

Meanwhile, the progression of NIS2’s full transposition across hesitant EU member states remains a critical area to watch. Successful enforcement of coordinated cyber defence mechanisms between governments and industry will be key to mitigating large-scale cyber risks. At the same time, initiatives by AI leaders like Anthropic providing models and resources to defenders may shape the evolving landscape of AI-enhanced cybersecurity.

Source assisted: This briefing began from a discovered source item from The Next Web. Open the original source.
How SignalDesk reports: feeds and outside sources are used for discovery. Public briefings are edited to add context, buyer relevance and attribution before they are published. Read the standards

Related briefings