More than a hundred major companies and technology organizations have signed an open letter warning governments and enterprises worldwide that AI-powered cyber-attacks are imminent — and that current defenses are not ready. Signatories include the very companies that helped build modern AI: OpenAI, Anthropic, Google, and Microsoft, alongside global enterprises such as Accenture, AT&T, Capital One, Deutsche Telekom, General Motors, KPMG, SAP, IBM, Nationwide Building Society, Oracle, PwC, and Visa.
The letter frames the threat in stark terms: AI is advancing faster than defenders can respond, and the window to shore up critical infrastructure is closing rapidly.
What does the open letter say?
"In the coming months, AI-enabled cyber-attacks will become far more widespread and sophisticated as models around the world become increasingly capable. The companies and public services our communities depend on — from hospitals to water treatment plants to the infrastructure that powers the internet — are at risk," the letter states. "We have a limited window to strengthen cyber defenses."
The signatories are not issuing a distant warning. They describe the threat as arriving in months, not years, driven by AI models that can autonomously identify vulnerabilities, craft convincing spear-phishing content, and execute multi-stage attacks at machine speed — far beyond the pace of human defenders.
Why current cybersecurity defenses will fall short
The letter identifies a catalogue of long-standing weaknesses that AI-enabled attackers will be able to exploit at scale: unpatched software, excessive permissions, misconfigurations, insecure legacy systems burdened by technical debt, and weak authentication. Security teams protecting critical infrastructure have historically been under-funded and under-staffed, leaving these vulnerabilities unaddressed for years.
Against an adversary that can scan millions of systems in seconds and auto-generate novel exploits, these accumulated weaknesses become a systemic liability. The open letter argues that the threat is not merely theoretical — nation-states with hostile intent could use AI-enabled cyber-attacks to cripple power grids, water treatment facilities, and internet infrastructure.
The call to action: coordinate, fund, and deploy AI for defense
The signatories outline three concrete demands aimed at governments and industry leaders:
Coordinate cyber defense globally. "Strengthen existing government and industry channels to share actionable threat intelligence, prioritize the most serious risks, and coordinate incident response and recovery around the world," the letter urges. Local, national, and international coordination mechanisms need to be put in place before an attack, not in the aftermath of one.
Fund cyber defense, especially for essential services. Hospitals, utilities, and public-sector organizations that lack the budget or staffing to respond must receive targeted investment. The letter calls on leaders to "fund cyber-defense, starting with essential services that lack the staff or budget to act."
Deploy AI as a defensive weapon. The letter's most striking argument is that the answer to AI-powered attacks is AI-powered defense. "AI brings specialist skills to more defenders and makes core security tasks faster, cheaper and better," it argues. "Sharing tools, practical knowledge, and verified fixes lets one organization's work help protect many others." In other words, the same technology creating the threat can, if deployed rapidly and equitably, help close the vulnerability gaps attackers will exploit.
The irony: AI's makers sound the alarm
The letter's signatories include the organizations most responsible for accelerating AI capabilities. OpenAI, Anthropic, Google, and Microsoft have collectively deployed the most powerful publicly available AI systems in history. Their willingness to co-sign a warning about AI-enabled threats carries an implicit acknowledgment: the technology they have built can and will be weaponized, and the defensive ecosystem has not kept pace.
Whether governments act on the letter's recommendations — or treat it as one more warning lost in the noise — may determine whether organizations around the world find themselves defenseless when the next generation of AI-powered attacks arrives.
