Leading Tech Companies Issue Call for 'Collective Action' on Cyber Defense

Combating the realities of threats spawned from AI advancements will take a village.

Peach Istock Ai Cyber

A group of 100 technology firms, including Google, Microsoft, Anthropic and OpenAI, have signed an open letter calling on countries and organizations around the world to beef up their cyber defenses before AI grows powerful enough to override them. The letter warns that cyberattacks that use AI will become both more widespread and more sophisticated in a matter of months as the technology rapidly improves.

The group says current status quo security measures "won't be enough" and criticizes the "historic under-resourcing" of security around critical infrastructure.

"We have a limited window to improve cyber defenses," the letter begins. Other firms that have signed the letter include banks such as Capital One, payment processors MasterCard and Visa, and other major tech firms including Adobe, Oracle, and IBM.

The letter outlines three broad principles: 

  1. Existing security practices will not be sufficient.

  2. AI should be used to equip more defenders with specialized capabilities. 

  3. A coordinated global response is necessary. 

It calls on every organization to make cyber defense an immediate leadership priority, fix high-risk weaknesses, and raise standards for software it buys, builds, or deploys. For governments, the letter urges coordination at the local, national, and international levels, funding for essential services with limited budgets, and expanded access to defensive AI tools for hospitals, water utilities, and local governments. 

Frontier AI companies are asked to provide funding, training, and hands-on support, with a focus on critical infrastructure operators that lack the resources to act on their own. The industry, to no one's surprise, had some thoughts to share.

Aviv Nahum, Co-founder and CEO at Above Security

"The companies building the most capable AI systems are effectively saying that these capabilities will become broadly available, very quickly, and that model-level safeguards alone are not going to protect the rest of the internet.

"I don’t take from this that we should slow down AI. I take almost the opposite view: defenders have to assume the attacker will have access to extremely capable AI and design around that reality. Trying to preserve security by keeping offensive capability out of attackers’ hands is unlikely to be a durable strategy once comparable models are widely available.

"What changes is the speed of the game. An AI attacker can continuously investigate an environment, test hypotheses, adapt when something fails and pursue multiple paths without waiting for a human operator. Human-led security operations built around static rules, queues of alerts and periodic remediation simply cannot operate at that tempo.

"The real takeaway from the letter is not ‘be afraid of AI.’ It is that security itself must become AI-native. Defenders need systems that continuously investigate identities, humans and agents, reason about behavior in context, and respond at machine speed. If AI is going to dramatically increase the capability of attackers, the answer is to give defenders the same leverage."

Diana Kelley, CISO at Noma Security

"I read this letter as an acknowledgment that AI is changing the economics of cyberattack faster than many organizations are reducing their security debt or strengthening governance over their own agents. And one of the most powerful ways to respond is collectively.

"AI doesn’t have to invent fundamentally new exploit techniques to create a serious problem. And agents don’t have to be “evil” to behave in ways their operators didn’t intend. When AI-driven agents can find vulnerabilities humans missed, automate reconnaissance, chain known attack paths, and operate at machine speed, longstanding weaknesses become more dangerous.

"The practical response is to address the debt we already know exists: patch systems, eliminate unnecessary privileges, strengthen identity and access controls, continuously test defenses, and use AI to help defenders find weaknesses before attackers do.

"At the same time, organizations need to recognize that their own agent deployments are becoming part of both the security architecture and the attack surface. They need to know what an agent can access, what tools it can invoke, what actions it can take, where it can communicate, and whether they can detect and stop it at runtime when its behavior violates policy.

"As the letter highlights, we need to take collective defense seriously. Attackers have shared tools, techniques, infrastructure, and intelligence for decades; defenders need to collaborate just as effectively."

Randolph Barr, CISO at Cequence Security 

"Before we get to AI-specific risks, we must get the basics correct. In the rush to bring AI to market quickly, engineering and product teams often cut corners to meet aggressive launch timelines. When that happens, basic security controls get skipped, and those shortcuts make their way into production.  

"Organizations should catalogue where AI agents operate in their environment, restrict permissions before scaling usage, vet third-party skills with the same thoroughness applied to open-source dependencies, and ensure behavioral visibility across web, API, bot, and AI-driven traffic. AI agents extend the existing application attack surface; they do not replace it and should be governed with that reality in mind. The goal is not to slow innovation but to secure it intentionally."

John Gallagher, Vice President at Viakoo

"The technical premise of the Open Letter is sound; the window where human-driven remediation can keep pace with AI-driven threats has closed. Where the open letter misses reality is in the idea that defenders hold an advantage because they can find and fix vulnerabilities that have accumulated for years.  

"In OT and critical infrastructure, the current pace of remediation is glacial, for several reasons. Maintenance and downtime must be carefully managed, coordinate between devices and applications can be tedious, and the cost of device not coming back online can be enormous.  

"Without more concrete and focused plans, and budget to implement them, it is hard to imagine up-levelling OT and critical infrastructure teams within the next few months to address the velocity and volume of AI-driven threats. The only viable countermeasure to the AI-driven threats highlighted here is automated, scalable cyber hygiene and remediation across all types of connected assets.  Funding and training should urgently be focused in this area."

Ram Varadarajan, CEO at Acalvio

"AI-powered cyberattacks have moved from theory to reality. The larger concern for enterprises is what today’s AI systems can do. 

"Modern models no longer just scan code for technical mistakes. They can infer what developers intended the software to do and spot contradictions humans missed. That makes a new category of vulnerabilities far easier to find: hidden business-logic flaws, broken trust assumptions, and authorization errors that appear perfectly valid to conventional security tools but can still be exploited.

"Shadow AI has become nearly ubiquitous across the corporate landscape.  Industry studies are consistently showing that most knowledge workers regularly use unsanctioned AI tools. This creates a profound and unplanned-for organizational blind spot. 

"We're facing an "assume compromise" future within cybersecurity.  Our best defense will be to engage these attacks bot-on-bot inside the perimeter, with active defense keyed by AI itself."

Chris Hughes, VP of Security Strategy at Noma Security

There's a bit of "help me from myself" aspect here and leaning into the FUD around AI-enabled attacks. It's complicated because we are going to see widespread AI-enabled attacks by cyber capable models.

We unfortunately can't call to action or will our way to better security, there needs to be sufficient market and regulatory incentives to change the behavior of business and get them to prioritize security on par with or ahead of competing priorities such as speed to market and revenue in some cases.

All that said, we already saw AI industrialize vulnerability discovery, and soon, we will see widespread AI-enabled attacks, especially as open source helps commoditize the capability into the hands of not just nation states but those without elevated cyber skills and makes hacking with AI available to nearly all.

It could be the forthcoming AI-enabled cyber incidents which end up driving that prioritization of cyber from businesses, but we will see.

More in Software