Keep the telemetry. Keep the hunting, the playbooks, and the tabletop exercises. That work is what makes an incident survivable, and it isn’t going anywhere. But it’s a second line of defense, and this industry has spent a decade funding it like a first one. The OpenAI letter, for all its candor, mostly proposes that we fund the second line harder.
The one recommendation the letter almost makes
Tucked into the ask aimed at cybersecurity companies is a line about layered defense and least privilege access. That is the closest the document gets to prevention, and it’s the part that deserves expanding, because layers only pay off when at least one of them is deterministic.
Deterministic means the control doesn’t need to recognize the threat to stop it. No classification, no confidence score, no waiting for a verdict. It removes the conditions the payload needs to run at all. Anything that depends on recognition inherits every blind spot of whatever is doing the recognizing, and machine-generated malware is now produced faster than any corpus can be labeled.

