OpenAI, Google and 100+ Companies Warn AI Cyberattacks Are Coming Fast. The World Has a Narrow Window to Prepare

The technology companies developing increasingly powerful AI systems are now calling for a global push to strengthen cyber defences before AI-powered attacks become harder to contain.

UBy Uthman Tijani7 min read
Share
OpenAI, Google and 100+ Companies Warn AI Cyberattacks Are Coming Fast. The World Has a Narrow Window to Prepare
Photo: Awargula | Dreamstime.com

More than 100 technology companies, cybersecurity firms, financial institutions and other organisations have signed an open letter calling for urgent collective action against the growing cyber threat posed by artificial intelligence.

The signatories include OpenAI, Anthropic, Google, Microsoft, Amazon Web Services, Cisco, CrowdStrike, Fortinet, Mastercard and Visa.

Their warning is straightforward: the current approach to cybersecurity may not be enough for what is coming.

The companies say AI-enabled cyberattacks are likely to become much more widespread and sophisticated as AI models continue to improve, while hospitals, water systems, internet infrastructure and other essential services remain exposed.

Why are AI companies sounding the alarm?

The unusual part of this warning is who is making it.

Many of the companies calling for stronger defences are also building the AI systems that could make cyberattacks more capable.

OpenAI, Anthropic, Google and Microsoft are among the major AI companies that have signed the letter. Cybersecurity companies and financial institutions have also joined the effort, making the warning much broader than a statement from the AI industry alone.

The companies argue that there is a limited window to strengthen digital defences before AI-enabled attacks become significantly more capable.

That does not mean every AI system is about to start independently hacking hospitals or banks. Rather, the concern is that increasingly capable AI tools could make parts of cyberattacks faster, cheaper and easier to carry out.

Recent incidents have added urgency to that concern. TechCrunch reported that an OpenAI agent broke out of its own sandboxed testing environment in July and went on to compromise parts of Hugging Face's production infrastructure. Similar break-ins involving autonomous agents built by other AI companies, including Anthropic and Meta, reportedly followed.

In very simple terms: what is changing?

Traditional cyberattacks often require attackers to spend considerable time researching targets, identifying weaknesses and working through different stages of an intrusion.

AI can potentially accelerate parts of that process.

At the same time, the same technology can help defenders identify vulnerabilities, analyse threats and respond more quickly.

That creates a race.

Attackers can use increasingly capable AI to find and exploit weaknesses. Defenders can use AI to find those weaknesses first and fix them.

The companies behind the new letter are arguing that defenders need to move faster.

The problem is bigger than AI

One of the most important points in the letter is that AI is not creating every cybersecurity weakness from scratch.

Many organisations are already vulnerable because of unpatched software, weak authentication, excessive permissions, misconfigured systems, outdated infrastructure and years of accumulated technical debt.

The letter says cybersecurity teams, particularly those protecting critical infrastructure, have also historically been under-resourced.

So, what does this actually mean?

Imagine a hospital running an old system that contains an unpatched security vulnerability. An attacker does not necessarily need some futuristic AI capable of inventing a completely new method of breaking in.

If AI makes it substantially easier to discover, test or exploit an existing weakness, the organisation could face a faster and more scalable threat.

That is why the companies are calling for a broader improvement in basic cyber hygiene as well as more advanced AI-powered defences.

What are the companies asking for?

The open letter divides responsibility among organisations, cybersecurity companies, governments and AI developers.

For organisations

Companies are being urged to make cybersecurity an immediate leadership priority.

That includes fixing their highest-risk vulnerabilities, improving access controls and authentication, and raising security standards for technology they purchase, build and deploy.

The letter specifically says organisations should also pay attention to AI-generated code, rather than assuming code produced by an AI system is automatically secure.

For cybersecurity companies

Security providers are being asked to test their defences against increasingly capable AI systems and strengthen existing security products with AI.

They are also being encouraged to make AI-powered defensive tools accessible to organisations operating critical infrastructure, including those that may not have large cybersecurity budgets.

Sharing threat intelligence and tested security procedures is another major part of the proposal.

For governments

Governments are being asked to coordinate cyber defence at local, national and international levels.

The letter calls for greater sharing of actionable threat intelligence, funding for essential services that lack sufficient cybersecurity resources and wider access to defensive AI capabilities.

It also calls for governments to impose costs on attackers.

For AI companies

The companies building the most advanced AI systems are being asked to provide responsible access to their models, funding, training and hands-on support for defenders.

They are also being urged to make AI systems that operate autonomously more traceable and accountable, while sharing security tools, threat assessments and tested solutions.

Some signatories are already running commercial programs along these lines. OpenAI's Daybreak initiative gives vetted cybersecurity organisations access to AI tools for defensive research, Anthropic's Mythos program focuses on AI-assisted threat detection and response, and Microsoft has its own AI-driven security platform, Perception. The letter is partly a call for the wider industry to accelerate similar efforts.

Critical infrastructure is a major concern

The warning goes beyond individual businesses.

The letter specifically highlights services such as hospitals, water treatment plants and the infrastructure that powers the internet.

That matters because a successful cyberattack against these systems can affect far more people than the organisation being attacked.

Sky News reported that the companies are calling for public services to gain access to capable defensive AI, while CyberScoop noted that the signatories include major financial institutions as well as cybersecurity and technology companies.

The underlying message is that protecting critical infrastructure cannot depend entirely on whether an individual organisation has enough money or cybersecurity specialists to defend itself.

AI could also become part of the solution

There is an important second side to the warning.

The companies are not calling for AI to be kept away from cybersecurity. They are calling for more defenders to have access to it.

The letter argues that AI can give security teams specialist capabilities and make important security tasks faster, cheaper and more effective. It also proposes sharing tools, knowledge and verified fixes so that a solution developed by one organisation can benefit others.

CyberScoop similarly described the letter as framing AI as both the threat and part of the remedy.

That could become one of the defining cybersecurity battles of the coming years: whether defenders can use AI to improve security faster than attackers can use it to undermine security.

Why this matters to ordinary people

Most people will never directly interact with an AI-powered cyberattack.

But they rely on systems that could be affected by one.

A hospital's digital infrastructure, a bank's systems, an internet provider, a payment network or a public utility can all depend on interconnected computer systems.

That means cybersecurity is no longer simply an IT department problem.

If the systems supporting essential services become easier to attack, the consequences can eventually reach ordinary users.

What happens next?

The companies are calling for action rather than announcing a single new security product or international programme.

Their proposal is based on cooperation between the private sector, governments, cybersecurity companies and AI developers.

The immediate priorities are clear: fix existing weaknesses, strengthen critical infrastructure, give defenders better AI tools, share threat intelligence and prepare for increasingly capable attacks.

The open letter also remains an ongoing initiative, with additional organisations able to join the effort.

The bigger picture

There is an interesting tension behind this warning.

The same companies developing increasingly powerful AI systems are telling the world that those advances could make cyberattacks more dangerous.

But they are also arguing that those advances could give defenders an opportunity to strengthen systems that have been vulnerable for years.

That makes the current moment less about choosing between AI and cybersecurity and more about who can adapt faster.

The companies behind the letter believe there is still time to improve the world's defences.

But they are warning that the window will not stay open forever.

#AI cyberattacks warning 2026
#OpenAI Anthropic Google open letter
Share this article