OpenAI, Anthropic, Google, Microsoft and more than 100 technology, cybersecurity, financial and infrastructure companies are calling for stronger defenses against AI-enabled cyberattacks.
The group says there may be a limited window to prepare as AI models become more capable and attackers find new ways to use them.
Their open letter focuses much of that preparation on decisions organizations are already making around aging technology, security investment, AI adoption and coordination across technology and security teams.
Why It Matters: AI adoption and cybersecurity have become more closely connected. Companies are bringing more capable AI into their environments while still dealing with older systems, security gaps and technical debt. The warning raises an important question about whether security programs are keeping up with the same AI capabilities that organizations are adopting and attackers could soon have at their disposal.
- A Limited Window: Signatories say organizations may have only months to prepare before AI-enabled attacks become more common and sophisticated. More capable models could automate parts of an attack that currently take more time and expertise. The concern is especially high for hospitals, water treatment plants and internet infrastructure, where a cyberattack can also disrupt essential services.
- Old Problems Still Matter: Many of the weaknesses attackers could target are already there. Unpatched software, weak authentication, excessive permissions and aging systems continue to leave organizations exposed. The letter argues that existing defenses will not be enough on their own, calling for companies to address those gaps while investing in security teams and newer defensive technology.
- AI Can Help Defenders Too: The same advances in AI could give security teams better tools to fight back. AI can help find vulnerabilities, investigate suspicious activity and fix weaknesses before they are exploited. OpenAI, Anthropic and Microsoft are already developing cyber-focused AI tools, giving companies another area to consider as they decide where AI fits into their security programs.
- Working Together: Companies also need a better way to learn from attacks happening elsewhere. The letter calls for sharing threat intelligence and response playbooks so organizations can see what is working and apply those lessons to their own defenses. It also asks cybersecurity firms to keep testing defenses and governments to help fund and coordinate cyber efforts.
- A Role for AI Developers: AI companies have responsibilities of their own. The letter asks them to secure their models, support cybersecurity training and give defenders responsible access to their technology. It also calls for measuring whether these efforts actually work, including whether attacks are contained faster and vulnerabilities are successfully fixed.
OpenAI, Anthropic, tech leaders warn of “limited window” to defend against AI cyber threats – CBS


