More than 100 technology companies, cybersecurity firms, financial institutions and other organisations have joined hands to warn about the growing threat of AI-powered cyberattacks. The companies are calling for stronger cyber defences before AI makes hacking attacks more common, sophisticated and advanced .
The open letter shared by Sam Altman’s OpenAI, titled ‘Action on Cyber Defense, brings together major names including OpenAI, Microsoft, Amazon Web Services (AWS), Google, Adobe, Apple rival AMD, Cisco, Cloudflare, CrowdStrike, IBM, Mastercard, Palo Alto Networks, SAP, ServiceNow, Shopify, Snowflake, Visa and Zscaler, among others.
According to the signatories, the world has a limited window to strengthen cyber defences. The companies said there is only a short time to strengthen cyber security. They warned that as AI becomes more powerful, hackers could use it to launch more advanced and large-scale cyberattacks.
The companies said critical systems that people depend on every day could be at risk. This includes hospitals, water treatment plants and the infrastructure that keeps the internet and other essential services running.
At the same time, the companies believe AI can also become a powerful tool for cybersecurity teams.
The open letter says that new AI tools can help security teams find and fix weaknesses in computer systems that have existed for years. These weaknesses include outdated software, unpatched systems, poor authentication, incorrect configurations, excessive user permissions and old technology that has built up technical debt.
The companies said security teams, particularly those protecting critical infrastructure, have often lacked enough people, tools and resources. They are now calling for a major increase in investment in cyber defence.
One of the key recommendations is to ‘put cyber-capable AI tools in the hands of more defenders. According to the companies, AI can help security professionals perform important tasks faster and at a lower cost.
They also want organisations to share security tools, knowledge and verified fixes so that a solution developed by one company can help protect others.
The open letter calls on every organisation to make cybersecurity an immediate leadership priority.
Companies are being urged to fix their highest-risk security problems, check whether those fixes actually work and improve security standards for the software and AI-generated code they use.
They are also being asked to use stronger access controls, least-privilege systems and multiple layers of security. If an important system cannot be patched without affecting essential services, organisations should put other security measures in place and verify that they work.
Cybersecurity companies and technology partners have also been asked to continuously test their defences against increasingly capable AI-based attacks. They should also make AI-powered security tools easier for critical infrastructure operators to deploy.
Governments and AI companies have a role too
The signatories are also calling on governments to improve cyber threat intelligence sharing and coordinate responses to major attacks across countries.
Governments should also provide funding and defensive AI capabilities to organisations such as hospitals, water utilities and local governments that may not have enough cybersecurity staff or budgets.
The letter also puts responsibility on companies developing advanced AI models.
AI companies are being asked to provide responsible access to their models, funding, training and hands-on support to organisations that need help strengthening their cyber defences.
They should also make sure that AI agents have traceable and accountable identities and invest in authorised security testing, monitoring and sharing of threat assessments. The companies behind the initiative believe AI does not have to make the digital world less secure.

