OpenAI has issued a stark warning: the world has a “limited window” to strengthen its cyber defenses before AI-enabled attacks become far more widespread and sophisticated.
More than 100 companies have signed the open letter, including Microsoft, Google, AWS, Anthropic, Cisco, CrowdStrike, Check Point and Palo Alto Networks, alongside major financial and technology companies. They warn that years of unpatched software, weak authentication, excessive permissions and technical debt have left organizations dangerously exposed. As AI models become more capable, finding and exploiting those weaknesses could become faster, cheaper and easier.
The warning is serious. But there is an interesting tension in who is delivering it.
The companies aren’t simply calling for more cybersecurity spending. They explicitly call to “empower more defenders with cyber-capable AI,” arguing that AI can make core security tasks “faster, cheaper and better.”
The letter calls on cybersecurity companies to “make AI-powered defense accessible and deployable” to critical-infrastructure operators, while urging frontier AI companies to provide “responsible model access, significant funding, training, and hands-on support.” It ends with a direct call to “put cyber-capable AI in the hands of defenders.”
In other words, the industry’s proposed answer to the threat it is warning about is, in large part, the same technology.
That doesn’t make the warning wrong. AI doesn’t need to create new vulnerabilities. It only needs to become exceptionally good at finding the thousands of weaknesses organizations have neglected for years.
But it also raises an uncomfortable question: the companies warning us about the threat are also the ones selling the solution.
There is plenty of substance behind the argument. AI could improve vulnerability discovery, alert triage, code analysis and incident response, while giving under-resourced organizations capabilities they could not otherwise afford.
But the letter also asks frontier AI companies to provide “significant funding” to under-resourced defenders, without specifying how much or setting concrete financial commitments.
And there is a second complication. Giving increasingly autonomous AI agents access to code, networks and security systems introduces risks of its own. The more authority these systems receive, the more important questions of oversight, permissions and accountability become.
The fundamental challenge, then, may not be whether AI can defend against AI. It is whether organizations can modernize their security fast enough—and whether the companies selling the technology will put enough of their own resources behind the collective defense they are calling for.
The warning deserves attention. The cure deserves scrutiny.
