Nearly 130 organizations spanning cybersecurity, cloud computing, finance and other industries have signed an open letter calling for a coordinated, global leap in cyber defense as AI makes attacks more pervasive and sophisticated.
Signatories include Anthropic, Microsoft, Google, Cisco, Check Point, Cloudflare, CrowdStrike, IBM, Oracle and OpenAI, which is leading the effort.
The a letter warns that AI attacks will become significantly more capable in the coming months, putting hospitals, sewage treatment plants and internet infrastructure at increasing risk. However, the same AI advances are giving defenders new ways to fix security weaknesses, and acting quickly can make a lasting difference.
Three principles anchor the collective response proposed by the initiative. One is that years of bugs, misconfigurations, weak authentication, and other technical debt mean that the security of the status quo will no longer be sufficient.
The second concerns AI, which extends specialized security skills to more defenders and makes shared knowledge and verified fixes more widely useful. The latter principle underscores the need for a global, coordinated response as cyber capabilities advance across many organizations.
Every organization is required to treat cyber defense as an immediate management priority, fix the riskiest weaknesses first, raise the security bar for what it builds and buys, and implement compensating controls when systems cannot be fixed without disrupting essential services.
Cybersecurity companies and technology partners are urged to continuously test defenses against AI frontier capabilities, make AI-powered defenses accessible to critical infrastructure operators with limited budgets, and share threat intelligence and playbooks that have been proven to actually work.
Governments are called upon to coordinate cyber defenses at local, national and international levels, fund essential services that lack the staff or budget to respond, and provide critical infrastructure with access to AI defense tools and authorized testing support. The letter also calls for costs to be imposed on the attackers.
Frontier AI companies are being asked to provide responsible model access, funding and hands-on support to under-resourced defenders, build tools to monitor AI systems and keep their actions traceable and accountable, and share threat assessments with governments and open source supporters.
OpenAI, as the leader of the initiative, outlined three specific commitments, including subsidized access to its Daybreak Cyber models for public sector organizations, open source non-profits and critical infrastructure operators.
The company also offers a program that allows companies to work with authorized partners to test their defenses using its models and privately report vulnerabilities. In addition, it will continue to publish security and discovery tools to help organizations find, prioritize and verify fixes for vulnerabilities.
Connected: The future of AI-driven security depends on complete data
Connected: OpenAI agents coordinated via a makeshift message board before the Hugging Face Hack
Connected: AI accelerates malware development, not its success rate
Connected: Linux Foundation to manage TRACE, an open standard for AI Runtime Attestation