Skip to main content
Control Inbound. Protect Outbound. Train People Better.See What's Launching

Aug 27, 2026

Why We're Supporting OpenAI's Collective Call to Action on Cyber Defense

OpenAI is urging organizations to strengthen AI cyber defense. Abnormal AI explains why adaptive AI and behavioral threat intelligence will be essential.

Artificial intelligence is changing cybersecurity on both sides of the equation. Attackers are using AI to speed up reconnaissance, make social engineering more convincing, and personalize and scale attacks more easily. Defenders, meanwhile, have a narrowing window to ensure the same technology works just as aggressively in their favor.

That is why Abnormal is proud to support OpenAI’s letter on collective action in cyber defense. OpenAI makes the case clear by saying, “We have a narrowing window to strengthen cyber defenses. In the coming months, AI-enabled attacks will become far more widespread and sophisticated as models around the world become increasingly capable… Each of us can reduce risk now… Together, we can turn today’s AI advances into lasting improvements in security that benefit everyone.”

The need for collective action is clear. Keeping pace with an AI-driven threat landscape will require adaptive capabilities and a security community committed to advancing cyber defense together. That imperative is central to Abnormal’s mission to stop cybercrime with AI.

AI is Changing the Entire Threat Landscape

Most of the conversation about AI risk has focused on software vulnerabilities and malicious code. Those matter, but they're only a slice of it. AI also gives attackers new ways to exploit people, identities, trusted relationships, and business processes.

Social engineering gets easier to personalize and scale, because AI can do the reconnaissance, pull public information on a company and its employees, write polished messages, and test different approaches in minutes. 

Impersonation now reaches past email. Generative AI can mimic trusted people across text, voice, and video, which gives attackers far more convincing ways to manipulate an employee. 

Identity compromise can turn deception into legitimate access. Once an attacker gains control of a trusted account, malicious activity can come from an identity the organization already recognizes, making behavioral context increasingly important for distinguishing legitimate activity from compromise.

Supply chain compromise can exploit trusted vendor relationships. AI can help attackers convincingly impersonate suppliers and other third parties by incorporating real organizational context into fraudulent requests. Because those attacks may contain no malicious link or attachment and originate from infrastructure with no known-bad reputation, they can appear consistent with legitimate business activity and bypass traditional signature-based tooling.

AI can support infiltration through the hiring process. Abnormal research has documented DPRK-linked operatives applying under stolen or fabricated identities and using AI-generated or deepfaked faces during interviews. If hired, they can enter the organization with legitimate credentials, equipment, and permissions.

The common thread is that AI makes it easier to understand how an organization operates, imitate the people and processes it trusts, and make malicious activity look normal. Defenders can't lean on known indicators of compromise anymore. They have to understand what normal behavior actually looks like and catch when an interaction, identity, or action deviates from it.

Stopping AI-Driven Threats Requires Adaptive Defense

This is where behavioral AI becomes essential.

AI-native systems can read behavioral telemetry, understand the relationships among employees, suppliers, identities, devices, and applications, and decide based on context instead of static rules. The question stops being only whether a sender, URL, or file is known to be malicious. Does this activity make sense for this person, this organization, this moment?

Those defenses also have to keep learning as attackers change. At Abnormal, our Threat Intelligence program does exactly that. Our researchers track global campaigns, analyze attacker tactics and infrastructure, hunt emerging threats, and study the kits and operators behind them, which gives us a direct view into how attackers are adapting and where our detections hit edge cases worth digging into. Those findings feed back into detection tuning and our behavioral models, and production edge cases become the next research questions. That continuous feedback loop is what makes AI-powered defense practical. Human-led threat research improves AI-powered protection, and what the platform sees in turn informs the next hunt.

Cyber Defense Has to Evolve as Fast as Cyber Offense

AI is lowering the barrier for attackers, raising their speed, and making deception easy to produce at scale. We can't defend tomorrow's attacks with yesterday's assumptions.

That's why OpenAI's call to collective action matters, and why Abnormal is behind it. The security community has both the opportunity and the obligation to make defensive AI advance at least as fast as the offensive kind, which means building systems that learn continuously, turning new threat intelligence into stronger production defenses, and treating defense as a shared effort.

AI-enabled threats will continue to get better. AI-powered defenses must get better faster. We're glad to be working with OpenAI and other industry leaders to make sure they do.

Protect Against Evolving Email Threats

See how behavioral AI detects attacks that legacy defenses miss.