Tech Giants Unite Against AI-Powered Cyber Threats
A coalition of 100 major technology companies, including Google, Microsoft, Anthropic and OpenAI, has signed an open letter urging governments and organisations worldwide to dramatically strengthen cyber defences before artificial intelligence becomes capable of orchestrating increasingly sophisticated attacks. The letter, titled "Collective Cyber Defense," warns that the convergence of rapid AI advancement and existing security vulnerabilities creates an urgent window of risk that may close if action is not taken soon.
The letter warns that cyber-attacks which use AI will become both more widespread and more sophisticated in a matter of months as the technology rapidly improves. This assessment is supported by recent high-profile incidents, including the US Department of Justice's disclosure this week that hackers linked to the Chinese government had breached a technology platform used by government agencies and enterprises alike.
The group argues that current "status quo" security measures "won't be enough" and criticises the "historic under-resourcing" of security around critical infrastructure. Collectively, tech and government "should bring the full weight of their technology, resources, and expertise to this effort," according to the letter. The signatories include not only the major AI labs but also banks such as Capital One, payment processors MasterCard and Visa, and other major tech firms including Adobe, Oracle and IBM.
They call on governments to provide "capable, defensive AI" and testing to hospitals and water utilities, and on technology companies to aid such efforts. The letter comes after a string of hacking and cybersecurity breaches have been made public over the past several months, ranging from ransomware attacks disrupting hospital operations to state-sponsored espionage campaigns targeting critical infrastructure.
The AI-Enabled Threat Analysis
Security experts have long warned that AI lowers the barrier to entry for would-be attackers. Tools that once required substantial technical expertise can now be generated or adapted using large language models, enabling a broader range of actors to conduct effective campaigns. Phishing emails generated by AI have been shown to achieve higher click-through rates than traditional socially engineered messages, and malware code can be obfuscated or modified in real time to evade detection.
The letter specifically highlights the threat of AI-augmented attacks targeting critical infrastructure such as hospitals, water utilities, and energy grids. These systems often rely on legacy technology that was not designed with modern threat modeling in mind, making them particularly vulnerable to AI-optimised exploit chains. The signatories argue that proactive investment in defensive AI capabilities is essential to keep pace with the accelerating threat.
The speed at which AI capabilities are advancing creates a compounding risk. Each new model generation introduces capabilities that can be repurposed for cyber operations, and the pool of actors with access to these tools continues to grow. Unlike traditional software vulnerabilities that can be patched, AI-related risks are often systemic, affecting the way entire classes of systems operate. This makes the threat particularly difficult to address through conventional patch-management approaches alone.
Government Action and Policy Gaps
The signatories are urging governments to take several specific actions. First, they request that regulatory bodies establish frameworks for testing and validating AI-powered security tools, ensuring that defensive solutions meet rigorous standards before deployment. Second, they ask governments to fund research into AI-resilient infrastructure, particularly for systems that manage public safety and economic stability. Third, they advocate for increased information sharing between the public and private sectors, noting that many threats remain undetected because organisations lack channels to report and analyse emerging patterns.
The letter also proposes that technology companies build "red team" capabilities that can simulate AI-augmented attacks against their own systems, identifying weaknesses before malicious actors exploit them. By sharing de-identified findings across the industry, the signatories believe the entire ecosystem can raise its baseline security posture. The signatories further argue that governments should consider liability frameworks that hold entities accountable for inadequate security practices when AI-augmented attacks cause widespread disruption.
The speed of legislative action rarely matches the pace of technological change. Many existing cybersecurity statutes were written before AI systems possessed the capabilities now available, creating gaps that malicious actors can exploit. The signatories warn that waiting for high-profile incidents to prompt policy reform is a losing strategy; proactive regulatory engagement is essential to keep defenses aligned with emerging risks.
Industry Best Practices
Beyond urging government action, the letter outlines best practices that technology companies can adopt immediately. These include embedding security into the software development lifecycle from the earliest stages, conducting regular adversarial testing of AI systems to identify potential misuse, and implementing strong access controls and monitoring for AI models and the data they consume.
The signatories also call for greater transparency in AI development, including documentation of model capabilities and limitations that would enable security teams to assess risk more accurately. Several companies have already begun publishing such information, and the letter suggests this practice should become industry standard rather than optional. Independent audits of AI systems, particularly those deployed in high-stakes environments such as healthcare or finance, are encouraged as a means of verifying claimed security properties.
The signatories further recommend that organisations establish clear incident-response plans that specifically address AI-augmented attack scenarios. These plans should include predefined communication protocols, data-preservation procedures, and coordination points with law-enforcement agencies. Regular tabletop exercises that simulate AI-augmented breach scenarios can help organisations test their readiness and identify gaps in their response capabilities.
A Race Against Time
The central argument of the letter is that the window for effective intervention is narrowing. As AI capabilities advance, the cost and complexity of mounting effective cyber defences increase. The signatories warn that delaying action even by a few months could mean the difference between having viable defensive tools and facing threat actors with insurmountable advantages.
This urgency is underscored by the signatories' diversity. The coalition spans multiple sectors — technology, finance, healthcare, and energy — reflecting the reality that cyber risk has no single point of origin or impact. A coordinated response, uniting the resources and expertise of these sectors, is the letter's core proposal.
The signatories note that the window for effective defence is already narrowing. Recent analyses suggest that the gap between new AI capabilities and the availability of corresponding defensive tools has shortened from several years to less than twelve months in some categories. This compression means that organisations must accelerate their own risk-assessment cycles and prioritize investments in defensive AI research to keep pace with the threat.
Looking Ahead
As the signatories note, the letter is a starting point, not a final solution. The rapidly evolving nature of both AI and cyber threats means that ongoing dialogue and adaptation will be necessary. The signatories have invited additional organisations to join the initiative, and the list of supporters is expected to grow in the coming weeks.
The coming months will be critical in determining whether the industry can translate this collective warning into concrete action. With AI-powered threats projected to increase in both frequency and sophistication, the signatories' message is clear: the time to strengthen global cyber defences is now, before the window for effective intervention closes.
Read more cybersecurity coverage
The signatories emphasize that cybersecurity is not a one-time achievement but an ongoing commitment. As AI models continue to evolve, so too must the defensive strategies that guard against their misuse. The collaborative framework established by this open letter represents an important first step, but its long-term value will depend on sustained engagement, regular reassessment of risks, and the willingness of all participating organisations to invest in the collective good against malicious actors who show no signs of slowing their operations.
The signatories also note that international cooperation must extend to norm-establishment efforts, where states and industry work together to define responsible behaviour in AI-augmented cyber operations. Without agreed-upon red lines and confidence-building measures, the risk of miscalculation increases in an already tense geopolitical situation. The open letter signatories commit to following up with concrete action items at the next global cybersecurity summit, where progress can be measured and new commitments pursued.

Cybersecurity analyst in dark room, Anonymous mask on one monitor, green-on-black terminal dashboards on dual screens, RGB keyboard, US flag on wall.
