Nearly 130 companies warn the window is closing to defend against AI cyberattacks
OpenAI, Anthropic and many of cybersecurity’s biggest vendors are calling for coordinated government action, broader access to defensive AI and hands-on support for under-resourced critical infrastructure.
A who's who of nearly 130 private sector companies, including top-tier cybersecurity companies CrowdStrike, Palo Alto Networks, Fortinet, SentinelOne, and others, signed an open letter pleading for a global effort to strengthen cyber defenses in the "narrow window" they have left to defend against AI-enabled cyberattacks.
The letter warns that "longstanding bugs, excessive permissions, misconfigurations, insecure and unpatched software, weak authentication, and technical debt in legacy systems have left systems exposed" and that every organization should make "cyber defense an immediate leadership priority."
The signatories, who include major technology companies such as Microsoft and Google, leading banks, consulting firms, and telecom providers, among others, urged cybersecurity and technology companies to embrace a more collaborative model to help deploy tools and verify tools for critical infrastructure companies, important supply chain manufacturers, and system integrators, among other kinds of community-oriented assistance.
They call on governments to coordinate and strengthen cyber defense at local, national, and international levels.
Finally, they ask AI companies to provide responsible model access, significant funding, training, and hands-on support, especially for under-resourced critical-infrastructure defenders.
The letter organizers say this plea is a rolling effort, with more organizations expected to join over time.
What prompted the unusually stark and urgent appeal is unclear. It follows a spate of recent high-profile, but ultimately low-impact, attacks on water companies and comes after an appeal earlier in the week from Bill Gates warning that AI is far more dangerous than tech companies realize.
But perhaps more consequentially, earlier this summer the tech sector was rocked by back-to-back reports of AI models "going rogue" when they exceeded the boundaries of controlled tests to gain unauthorized access of real-world systems, transforming autonomous cyberattacks from theory to real-world security concerns.
Notably absent from the signatory list were any government agencies, utilities, hospitals, or non-profit organizations that aim to protect the most vulnerable organizations. (Cynthia Brumfield / Metacurity)
Related: OpenAI, OpenAI, Reuters, New York Times, Bloomberg, CyberScoop, CNBC, TechCrunch, Politico, BBC, Seeking Alpha, The Decoder, Agence France-Presse, Business Insider, Tech.co, Gizmodo, Sky News, Becker's Hospital Review, Silicon Republic, Mobile Europe, Digit, BeInCrypto, Business Standard
Metacurity is the cybersecurity news, analysis, and insight you'd need hours and possibly days to assemble yourself.
Every weekday, we read the releases, filings, court documents, and reports that vendors and PR teams often don't want summarized — then tell you what actually changed and why it matters. Minimum vendor marketing, no outrage bait, no SEO filler.
A paid subscription to Metacurity delivers
- Full archive access — every newsletter and AI Watch roundup, searchable and browsable.
- Our weekly curated long-reads roundup — the best cybersecurity writing from across the industry, filtered and vetted so you're not sorting through it yourself,
- Periodic specialized reports and analyses — deep dives that go beyond our daily coverage
- Support for independent, no-spin cybersecurity journalism — funded by readers, not vendors or investors.
Reader support is what keeps Metacurity independent. It allows us to focus on serving the cybersecurity community—not advertisers, vendors, or investors—and to continue delivering the thoughtful analysis you've come to rely on every weekday.
Please consider supporting us. And thank you!