More than 100 companies across artificial intelligence, technology, cybersecurity, cloud computing and finance have signed an open letter calling for stronger collective action against the growing threat of AI-enabled cyberattacks.
The list of signatories includes major names such as OpenAI, Anthropic, Google, Amazon Web Services, Cisco, Cloudflare, CrowdStrike, Hugging Face, Microsoft, Oracle and Perplexity, among many others.
The open letter, titled “A Call for Collective Action on Cyber Defense,” warns that artificial intelligence is rapidly changing the cybersecurity landscape and that traditional security approaches may no longer be enough to protect businesses, governments and critical infrastructure.
According to the letter, AI-enabled cyberattacks could become significantly more widespread and sophisticated as AI models continue to improve. The companies warn that essential services, including hospitals, water treatment facilities and internet infrastructure, could face increasing risks.
The Three Core Principles
The organizations behind the letter have outlined three major principles they believe should guide the global response to AI-powered cyber threats.
1. Recognize That Traditional Security Is No Longer Enough
The first principle is straightforward: the existing approach to cybersecurity may not be sufficient for the AI era.
The letter highlights longstanding security weaknesses such as:
- Unpatched software
- Misconfigured systems
- Excessive permissions
- Weak authentication
- Legacy technology
- Technical debt
- Longstanding software vulnerabilities
Many organizations have accumulated security problems over decades, and AI could make it easier for attackers to discover and exploit those weaknesses at a much larger scale.
The signatories argue that cybersecurity teams, particularly those responsible for critical infrastructure, need more resources, stronger tools and greater organizational support.
2. Give More Defenders Access to Cyber-Capable AI
The second principle focuses on using artificial intelligence as a defensive tool.
AI can potentially help cybersecurity teams identify vulnerabilities, analyze suspicious activity, respond to threats and automate repetitive security tasks.
The companies argue that advanced AI capabilities should not only benefit attackers. Security professionals and organizations also need access to AI-powered tools that can help make cyber defense faster, more efficient and more widely available.
The idea is that AI could help bring specialized cybersecurity knowledge to more defenders, allowing smaller organizations to benefit from capabilities that previously required large teams of experts.
3. Mobilize a Collective Global Response
The third principle calls for greater cooperation.
Cyber threats do not respect national borders, and AI models are being developed and deployed around the world. The letter argues that no single company, government or organization can independently solve the growing cybersecurity challenge.
The proposed response includes greater cooperation between:
- Governments
- Technology companies
- AI developers
- Cybersecurity firms
- Critical infrastructure operators
- Financial institutions
- International organizations
The signatories believe that new partnerships and greater information sharing will be necessary to improve global cybersecurity standards and respond to emerging threats.
AI Is Becoming Both the Threat and the Defense
One of the most interesting aspects of the letter is the central contradiction surrounding AI and cybersecurity.
The same companies developing increasingly capable AI systems are now warning that those technologies could dramatically increase the scale and sophistication of cyberattacks.
That has led critics to question whether the industry is reacting too late.
AI companies are simultaneously developing powerful models, warning about the risks those models may create and promoting AI-powered cybersecurity systems as part of the solution.
This creates an uncomfortable situation: the technology industry is warning the public about a threat that its own products may help accelerate.
Some critics argue that the letter sounds less like a long-term solution and more like a warning from companies that are now asking society to prepare for the consequences of increasingly powerful AI systems.
Why AI Could Change Cybersecurity
AI has the potential to automate many tasks that previously required significant technical expertise.
For defenders, this could mean faster vulnerability detection, automated code reviews, improved threat analysis and quicker incident response.
For attackers, however, the same technology could potentially make it easier to identify weak systems, automate malicious campaigns and scale attacks across thousands of targets.
That dual-use nature of AI is becoming one of the most important cybersecurity challenges of the decade.
The open letter warns that AI-enabled attacks could become more capable in the coming months, increasing pressure on governments and organizations to strengthen their defenses before major systems are compromised.
What the Companies Are Asking For
The coalition is encouraging organizations and governments to make cybersecurity an immediate leadership priority.
The recommendations include:
- Prioritizing cybersecurity at the executive level
- Fixing existing vulnerabilities and misconfigurations
- Investing in modern cybersecurity tools
- Expanding access to AI-powered defensive technologies
- Improving information sharing between organizations
- Strengthening protection for critical infrastructure
- Improving monitoring and detection systems
- Developing more secure and accountable AI agents
The letter also encourages frontier AI companies to build stronger observability and security tools, improve monitoring and ensure that AI agents can be identified and held accountable.
Critics Say the Response May Be Too Late
While the recommendations include several common-sense cybersecurity measures, critics argue that the industry is only now reacting seriously to risks that have been discussed for years.
Artificial intelligence companies have rapidly introduced increasingly powerful models and autonomous AI agents into commercial products and business systems.
Now, many of those same companies are warning that AI could create an unprecedented wave of cyber threats.
This raises an important question: should stronger safeguards have been introduced before AI systems became more widely deployed?
The open letter does not solve that debate. However, it demonstrates that some of the world’s largest technology companies now believe AI could fundamentally change the balance between cyber attackers and defenders.
The Cybersecurity Industry Faces a New AI Era
The growing use of artificial intelligence means cybersecurity may soon become an arms race between AI-powered attackers and AI-powered defenders.
Companies will need to move faster than traditional security systems were designed to operate. Governments may also face increasing pressure to develop new regulations, improve public infrastructure and coordinate more closely with private companies.
The biggest challenge may be ensuring that AI development does not move faster than the world’s ability to secure the systems affected by it.
Final Thoughts
The open letter signed by OpenAI, Google, Anthropic, Microsoft and more than 100 other organizations is an important signal that the technology industry sees AI-enabled cyber threats as an increasingly serious problem.
Its three central principles are clear: traditional cybersecurity is no longer enough, more defenders need access to AI-powered tools and the world needs a coordinated response.
However, the letter also highlights a major contradiction within the AI industry.
The companies warning about the dangers of AI-enabled cyberattacks are also among the companies building the increasingly powerful AI systems that could make those attacks possible.
Whether this collective effort leads to meaningful action, stronger safeguards and real investment in cyber defense remains to be seen.
For now, the message from the technology industry is clear: the window to strengthen global cyber defenses may be getting smaller.




























