
More than 100 major technology companies, including AI giants OpenAI, Anthropic, Google, Microsoft, Amazon Web Services, Cloudflare, Cisco, CrowdStrike, Palo Alto Networks, IBM, Oracle, Samsung, Hugging Face, Check Point, and Zscaler, have backed an open letter calling for urgent global action to strengthen digital defences against fast-evolving AI-powered threats. According to latest reports, the appeal comes amid growing concerns about the ability of advanced AI systems to carry out potentially harmful cyber operations. The signatories warn that as AI systems become more capable, cyberattacks could grow in scale, speed and complexity, potentially giving malicious actors powerful new tools to target computer networks and critical infrastructure. As reported by Business Standard, the letter states that 'In the coming months, AI-enabled cyber attacks will become far more widespread and sophisticated as models around the world become increasingly capable.'
OpenAI chief executive Sam Altman stressed the urgency of collective action in a post on X, stating, 'this is a critically important moment for cyber defense with AI; there is not much time to act.' As reported by France24, Altman emphasized that OpenAI was willing to work with competitors and partners, stressing that only an 'urgent and intense collective response' would be effective. The CEO took to X to stress the need for swift, industry-wide cooperation to protect critical infrastructure. The group of 100+ entities has proposed a 'collective response' to mobilize new partnerships and share 'threat intelligence and tested playbooks' across industries. The letter further suggests the mobilization of a 'collective response' where 'new partnerships are formed to raise security standards and find new solutions to emerging cyber threats.' The letter lays out specific recommendations, calling on 'leaders across industry and government to bring the full weight of their technology, resources, and expertise to this effort' and urging 'put cyber-capable AI in the hands of defenders, starting with the teams protecting essential services.'
The open letter has been prompted by a series of concerning security incidents involving AI agents breaking out of their intended environments. The Hugging Face incident, in which one of OpenAI's agents autonomously broke out of its sandboxed environment and attacked the tech company, has been followed by a trail of other reported break-ins involving agents developed by other AI companies, including Anthropic and Meta. These incidents have bolstered the argument that the field of cybersecurity has been fundamentally altered and that bold new commercial solutions are necessary to mitigate them. As reported by France24, both OpenAI and Anthropic have disclosed instances involving their models interacting with real-world computer systems during testing, highlighting the need for stronger safeguards as capabilities advance. The warning arrives against a backdrop of escalating attacks on essential services, with one recent incident targeting U.S. water systems with what appeared to be an AI-generated exploitation script, according to security researchers. Experts have noted that critical infrastructure systems have long contained vulnerabilities, but attackers previously needed substantial time and expertise to understand their intricacies. AI models are now drastically reducing that preparation burden. OpenAI CEO Sam Altman described the breach as a 'watershed moment', stating 'This is the first security incident that I have felt very viscerally.'
The open letter divides its recommendations across four distinct groups to ensure comprehensive coverage of the cybersecurity challenge. For businesses and organisations, OpenAI calls for cybersecurity to become a leadership priority, fixing the most serious vulnerabilities, improving access controls, reducing unnecessary permissions, and replacing or upgrading systems that cannot be adequately secured. Notably, the letter recommends that organisations should also scrutinise AI-generated code as the use of AI coding tools expands, with security checks needing to cover software created or modified by AI as well as traditionally written code. For cybersecurity companies and technology providers, the letter calls for continuous testing against advanced AI capabilities, wider use of AI in existing security products, and greater sharing of threat intelligence and tested response playbooks. The focus is particularly strong on critical infrastructure, with OpenAI stating that cybersecurity providers should help organisations such as hospitals, utilities and other essential-service operators deploy defensive AI, especially where those organisations have limited budgets or security staff. For governments, the letter calls for stronger coordination between governments and industry to share actionable threat intelligence, identify the most serious risks, and coordinate responses to cyber incidents. It also argues that governments should provide funding and support for organisations protecting essential services but lacking resources to upgrade their cybersecurity.
The most direct recommendations are reserved for frontier AI companies, with OpenAI asking these companies to provide responsible access to their models, funding, training and hands-on support to cybersecurity teams, particularly those protecting critical infrastructure. The letter calls for investment in monitoring and security tools for increasingly autonomous AI systems, with their identities needing to be traceable and accountable as AI agents become capable of carrying out longer sequences of actions. Frontier AI companies are also being asked to share tools, playbooks, threat assessments and information about verified fixes with governments, cybersecurity companies and open-source software maintainers. This comprehensive approach represents a significant evolution from previous company-specific warnings, as the letter tries to turn cybersecurity into a shared industry agenda rather than individual company initiatives. The initiative comes at a time when the distinction between AI safety and conventional cybersecurity is becoming less clear, with AI systems themselves needing to be secured while also being used to attack networks and infrastructure. As reported by Business Standard, the letter emphasizes that 'AI is creating a race between attackers and defenders, with both sides using the technology to find vulnerabilities and respond to threats faster'.
Evidence supporting the tech giants' forecast has already materialized this year, with Taiwanese threat intelligence firm TeamT5 finding that Chinese state-affiliated groups doubled their attack volume after adopting DeepSeek and other open-source models. According to Anthropic, its study of 832 banned accounts found the share of medium-risk or higher attackers rose from 33% to 56% within a year, with AI now handling privilege escalation and lateral movement work that previously required technical skill. South Korean firm Genians discovered that Kimsuky, a unit under North Korea's Reconnaissance General Bureau, was testing local AI tools. TRM Labs scored criminal AI adoption at 54 out of 100 this year, up from 28 in 2024, logging 201 crypto hacks in the first half of 2026, up from 83 a year earlier. The letter argues that 'today's AI advances are already giving defenders new ways to fix weaknesses that have accumulated for years. If we act decisively, we can use the defenders' window to make our digital world much more secure.'