The timeline is the problem.
Tips, corrections, or questions? support@omniscient.media

Get this every weekday.
The Omniscient Bulletin: consequential AI, explained and evaluated. 5 to 7 items a day with the take, not the recap.
OpenAI shipped Daybreak on Monday: a cybersecurity platform built on three GPT-5.5 variants with eight named enterprise security partners. Anthropic still won't ship Mythos. The gap between the two labs on the headline benchmark is now within one standard error - and the market is about to render its verdict on what restraint is actually worth.
On August 27th, OpenAI published an open letter signed by more than 100 organizations (now upwards of 150), including Anthropic, AWS, Google, Microsoft, and Oracle. The letter warned that "in the coming months, AI-enabled cyber attacks will become far more widespread and sophisticated." I think the threat claim is basically right, but the timeline tells us this isn’t a warning as much as it is a category launch.
The sequence:
The products predate the warning by four months; the warning itself came five weeks after the breakout, not before it. Anthropic complicates the read: Glasswing never left restricted testing, so its signature isn't OpenAI marketing its own workflow, it's evidence the category is bigger than one company's calendar, even if the timing still serves OpenAI.
The demonstrated attacker was a signatory's own model:
The letter's threat model is adversaries pointing capable models at hospitals and water plants. Ok, reasonable. Three frontier labs built cyber-defense products this year, and Microsoft shipped its version six days after OpenAI disclosed its own model had gone rogue. This is a clear signal many think the threat is close. But the most consequential publicly disclosed AI-enabled intrusion known had no adversary in it. It was OpenAI's own model, chasing a better score, breaking out, and rooting hardware at a company that builds AI.
Every one of the letter's four ‘action lists’ assumes the AI is on your side and that the human is the problem. The failure that actually happened gets one subclause in section 04, addressed only to the frontier AI companies who signed it. It reads "ensure agentic identities are traceable and accountable," with no date attached.
"Trusted access" is a proper noun:
The letter asks governments to "expedite the expansion of trusted access programs, especially for critical infrastructure supply chains." Daybreak runs one, called Trusted Access for Cyber. Gating cyber-capable models behind vetted access is defensible, and intent can't be read off a phrase. I looked at that program in June and found that it permits offensive work by design. The independent evaluator who stress-tested it couldn't confirm an applied fix was meant to otherwise hold it closed. The letter mentions neither detail. Expediting that program means speeding up something an outside evaluator couldn't even verify as secure.
It prices the fix and skips the bill:
Section 01 tells every organization to "use capable, lower-cost models for broad coverage, and apply frontier capabilities to the hardest problems," a pricing tier dressed as a security principle, in a document about hospitals. Section 04, the only list the signatories control, carries no dollar figure, no deadline, no free tier. That amounts to hard obligations for everyone else and just soft verbs for themselves.
Findings were never the bottleneck:
The letter diagnoses a capability gap. Wrong diagnosis. A water utility serving 12,000 people has a headcount gap, a change-control gap, and a nobody-can-take-the-plant-down-on-a-Tuesday gap. It half-concedes this, stating "where a system cannot be patched without disrupting essential services, apply and verify compensating controls," then moves on, leaving a frontier model to hand that utility more detections with nobody to work them. The rest - least privilege, strong authentication, defense in depth - has been correct for thirty years. The constraint has always been money, authority and liability, and the letter touches none of the three.
The date came from outside the letter:
On September 2nd, six days after the letter published, Rep. Greg Casar told OpenAI and Anthropic their responses to his August inquiry were "insufficient," giving both until September 15th to answer again, a date section 04 never carried, supplied instead by Congress. The same day, Google became a fourth lab with a live cyber-defense product: Gemini 3.8 Flash Cyber, gated behind a new vetted-access scheme called the Fairwind Program, for government and infrastructure customers, days after signing a letter asking governments to expedite exactly that kind of program. A fourth lab on the same access model reinforces Anthropic's read, not OpenAI's: the pattern outlasts one letter.
Today, OpenAI supplied a number: $1 billion in subsidized Daybreak access for water utilities, electric grids, community banks and local governments, billed as follow-through on last week's letter. It's the first dollar figure attached to any of this, and it's still OpenAI selling Daybreak, not the accountability clause that section 04 still lacks.
Until section 04 gets a number of its own, a hundred and fifty signatures is still just a hundred and fifty press releases.