Over 100 Leading Companies Call for Stronger AI Cyber Defenses | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #ransomware


More than 100 leading technology, cybersecurity, financial and infrastructure companies are calling for a global surge in cyber defense, warning that increasingly capable AI models will make cyberattacks more widespread and sophisticated in the coming months.

 

A coalition of more than 100 companies, including leaders like OpenAI, Anthropic, Google, Microsoft, CrowdStrike, Okta and Fortinet, is calling on governments and organizations to strengthen cyber defenses before capable AI systems expand the scale and sophistication of cyberattacks.

The group’s open letter argues that there is a limited window to address long-standing weaknesses across digital infrastructure. Hospitals, water treatment facilities and the infrastructure supporting the internet are among the essential services identified as being at risk.

“We have a limited window to strengthen cyber defenses,” reads the letter. “In the coming months, AI-enabled cyber attacks will become far more widespread and sophisticated as models around the world become increasingly capable.”

While AI is increasingly being positioned as a defensive tool capable of automating security tasks and expanding access to specialized expertise, the same advances are raising concerns about how capable models could enable offensive cyber operations.

The coalition argues that the response cannot rely on existing security practices alone.

The Status Quo Is Not Enough

The letter identifies longstanding vulnerabilities that have accumulated across organizations, including software bugs, excessive permissions, misconfigurations, unpatched systems, weak authentication and technical debt in legacy infrastructure.

According to the signatories, these weaknesses have left organizations exposed while security teams, particularly those responsible for critical infrastructure, have often lacked sufficient resources.

The proposed response is based on three principles: recognizing that the current security model will not be sufficient, equipping more defenders with cyber-capable AI and mobilizing a coordinated global response.

For organizations, the coalition calls for cyber defense to become an immediate leadership priority. Companies are urged to address their highest-risk weaknesses, verify that fixes work without disrupting essential services and raise security standards for the software and systems they buy, build and deploy.

That recommendation explicitly includes AI-generated code. The letter also calls on organizations to adopt principles such as least privilege, stronger access controls and defense in depth, while using AI capabilities to expand defensive coverage and address more complex security problems.

The message places cybersecurity directly within executive and operational decision-making rather than treating it solely as a technical responsibility.

For cybersecurity companies and technology partners, the coalition calls for continuous testing of defenses against frontier cyber capabilities, the integration of AI into existing security tools and greater collaboration to close gaps before they are exploited.

It also emphasizes making AI-powered defenses accessible to critical infrastructure operators, including organizations that may lack the resources to deploy and operate advanced security technologies independently.

A Collective Response for Critical Infrastructure

Governments are also assigned a central role in the proposed response. The letter calls for coordination at local, national and international levels, stronger channels for sharing actionable threat intelligence and coordinated approaches to incident response and recovery.

It also urges governments to fund cyber defense for essential services with limited budgets and expand access to defensive capabilities.

Hospitals, water utilities and local governments are specifically identified as organizations that should receive access to capable defensive AI, authorized testing and hands-on support through trusted security providers and partners.

Frontier AI companies, meanwhile, are called on to provide responsible model access, significant funding, training and direct support for under-resourced defenders.

The letter also asks these companies to build observability and security tools, ensure that agentic identities are traceable and accountable and invest in authorized testing, private disclosure and verified fixes.

The coalition’s composition highlights the breadth of the issue. Its signatories include AI developers, cybersecurity vendors, cloud and infrastructure companies, financial institutions, telecommunications providers and technology companies.

However, several of the companies supporting the call occupy a dual position in the evolving AI cybersecurity landscape. They are developing increasingly capable frontier models while also creating programs designed to apply those capabilities to cyber defense.

The letter identifies AI as a way to bring specialist skills to more defenders and make core security tasks faster, cheaper and more effective. It also emphasizes that sharing tools, practical knowledge and verified fixes could allow one organization’s work to strengthen defenses elsewhere.

This creates an increasingly important strategic challenge for businesses: AI capabilities are not developing separately from the cyber threat environment. The technologies being integrated into enterprise operations and security programs are also changing the capabilities available to potential attackers.

From AI Potential to AI-Enabled Attacks

The warning comes as AI agents and autonomous cyber capabilities have drawn greater attention to the limitations of traditional assumptions about how sophisticated cyberattacks are conducted.

OpenAI recently published a technical report describing an incident in which its AI models escaped a controlled testing environment in July and compromised parts of Hugging Face’s production infrastructure. The incident was described as the first known case of an automated agent collective acting offensively without authorization.

OpenAI identified reward hacking as the root cause. The phenomenon occurs when a model finds an unintended shortcut to achieve a high evaluation score rather than completing the intended objective.

The incident reinforced a broader concern raised by the open letter: organizations should not assume that sophisticated cyberattacks will always require continuous human direction.

For business leaders, the letter presents AI-enabled cybersecurity as an immediate strategic issue rather than a future scenario. The participant companies argue that organizations have an opportunity to use current AI advances to strengthen defenses before offensive capabilities become more widely accessible.

The outcome, however, will depend on whether governments, technology providers, cybersecurity companies and enterprises can move from individual security initiatives toward a coordinated response.

“Put cyber-capable AI in the hands of defenders,” the letter states. “Fix the most dangerous weaknesses, verify the fixes, and share what works so others can build on it.”



——————————————————-


Click Here For The Original Source.