OpenAI, Anthropic, Google, and more than 100 other companies and organizations are calling for a major push to defend against cyber threats powered by the most advanced AI models that, somewhat ironically, the industry itself is racing to put out in the world.
The companies, which also include Microsoft, Amazon, and Oracle, signed a joint letter published Thursday calling on industry leaders and governments to carry out a “global surge in cyber defense.”
“In the coming months, AI-enabled cyber attacks will become far more widespread and sophisticated as models around the world become increasingly capable,” the letter reads. “The companies and public services our communities depend on—from hospitals to water treatment plants to the infrastructure that powers the internet—are at risk.”
Their main solution, unsurprisingly, is more AI.
The letter lays out recommendations for companies, cybersecurity firms, governments and the AI developers themselves, arguing there is currently a small window to use frontier AI models to strengthen defenses before those same models become more widely available to attackers.
First, the group says all organizations should make cybersecurity an immediate priority by addressing existing high-risk vulnerabilities, upgrading outdated systems, and using AI to tackle some of their hardest security problems. Cybersecurity companies, meanwhile, are being urged to continuously test their defenses against the capabilities of frontier AI models and make AI-powered security tools more accessible to operators of critical infrastructure.
The letter also calls on governments to coordinate cyber defense at the local, national, and international levels, increase funding, and expand trusted-access programs that give organizations access to powerful AI models before they’re commercially released.
Finally, the AI companies themselves are being asked to provide model access, funding, training, and hands-on support, especially for “under-resourced critical-infrastructure defenders.”
The call comes amid growing warnings that AI could dramatically increase both the scale, speed, and sophistication of cyberattacks.
In June, the Five Eyes intelligence agencies issued their own warning that AI is lowering barriers for malicious actors while increasing the complexity of attacks. The agencies also warned that frontier AI models could transform both offensive and defensive cyber capabilities within months.
Critical infrastructure has already been facing a wave of cyber threats, though not all of them have been officially linked to AI.
In July, the FBI and the Environmental Protection Agency warned that hackers were targeting internet-connected programmable logic controllers, or PLCs, at water and wastewater facilities. Water utilities in at least seven states had reported incidents to the FBI at the time.
Then a few weeks ago, the National Security Agency and other U.S. agencies warned that hackers were targeting Siemens PLCs used in water plants and other critical infrastructure. In that case, the agencies said attackers were using AI-generated exploitation scripts disguised as legitimate monitoring tools.
Concerns have also grown following incidents in which experimental AI agents have broken out of testing environments and breached external networks.
OpenAI, Anthropic, Google and Microsoft did not immediately respond to requests for comment.