More than 100 technology, cybersecurity and financial services companies signed a public letter published yesterday calling for a global surge in cyber defense, warning that AI-enabled attacks will become more widespread and sophisticated in the coming months as models grow more capable.
The letter, posted to OpenAI’s website, names hospitals, water treatment plants and internet infrastructure among the systems at risk. Signatories include OpenAI, Anthropic, Google, Microsoft, Amazon Web Services, Oracle and IBM, along with cybersecurity firms CrowdStrike, Palo Alto Networks, Cloudflare, Fortinet, Zscaler, Okta and Proofpoint. Financial services signatories include Visa, Mastercard, Capital One, Citi, U.S. Bank, Fifth Third Bank, FIS, Fiserv, TransUnion, The Clearing House, DTCC and Zurich Insurance.
The letter sets out four principles:
- That existing security practices will not be sufficient
- That AI tools should be placed in the hands of more defenders
- That the response must be coordinated globally rather than controlled by any single company, and
- That every organization can reduce risk immediately
It then directs specific actions at four groups. All organizations are told to treat cyber defense as an immediate leadership priority, fix the highest-risk weaknesses, and raise security standards for what they buy, build and deploy, including AI-generated code. Cybersecurity companies and technology partners are asked to test their defenses continuously against frontier AI capabilities, make AI-powered defense deployable for critical infrastructure operators, and share threat intelligence and playbooks. Governments are asked to fund cyber defense for essential services that lack staff or budget, expand trusted access programs, and impose costs on attackers. Frontier AI companies are asked to provide model access, funding, training and hands-on support to under-resourced defenders, and to ensure agentic identities are traceable and accountable.
The letter follows several warnings from government agencies. In June, the Five Eyes intelligence agencies said AI is lowering barriers for malicious actors while increasing attack complexity. In July, the FBI and Environmental Protection Agency warned that hackers were targeting internet-connected programmable logic controllers at water and wastewater facilities, with utilities in at least seven states reporting incidents. The National Security Agency and other U.S. agencies subsequently reported attackers using AI-generated exploitation scripts disguised as legitimate monitoring tools against Siemens controllers.
Anthropic previously reported that a Chinese state-sponsored group manipulated its Claude Code tool in an attempt to compromise 30 global targets, breaching several. OpenAI, Anthropic, Google and Microsoft did not respond to requests for comment from multiple outlets.




