120 Companies Sign a Letter Saying the Cyber Window Is Closing
OpenAI, Anthropic, Google, Microsoft, Visa, and more than a hundred others warn that AI-enabled attacks on hospitals and water utilities are months away, and ask for a coordinated defensive push.
OpenAI published an open letter on Thursday calling for a collective surge in cyber defense, co-signed by more than 120 organisations. The list is unusually broad: Anthropic, Google, Microsoft, AWS, IBM, Oracle, Cisco, Cloudflare, CrowdStrike, Palo Alto Networks, Red Hat, SAP, Shopify, Figma, Hugging Face, Perplexity, Deutsche Telekom, and Zurich Insurance sit next to Visa, Mastercard, Capital One, Citi, US Bank, General Motors, and the National Australia Bank.
The core claim is a timing one. “In the coming months, AI-enabled cyber attacks will become far more widespread and sophisticated as models around the world become increasingly capable,” the letter says, naming hospitals, water treatment plants, and the infrastructure behind the internet as the systems most at risk. The other half of the argument is more hopeful: the same advances are already helping defenders fix weaknesses that have been sitting there for years, and the signatories want that window used before attackers close it.
The asks are split four ways. Every organisation should treat cyber defense as a leadership priority and raise the bar on what it buys, builds, and deploys, explicitly including AI generated code. Security vendors should make AI powered defense actually deployable for infrastructure operators, with hands on help rather than a product page, and share threat intelligence and tested playbooks. Governments should fund defense for services that cannot afford it, and expedite trusted access programmes. Frontier AI companies should give defenders model access, funding and training, and make agent identities traceable and accountable.
What’s actually going on here: open letters from the AI industry usually ask governments to do something. This one mostly asks the industry to do something, which is a meaningful difference, and the presence of banks and insurers alongside the labs suggests the people who price risk are taking the timeline seriously. It is also, unavoidably, good business for everyone who signed it, since the proposed cure is more AI security tooling sold by the signatories. Both things can be true.
There is independent support for the concern. A joint warning from the NSA, CISA, and the FBI in mid August reported that attackers are already using AI to write exploit scripts against industrial control systems in US energy, water, chemicals, and manufacturing. The letter’s plainest point is one that has nothing to do with AI: unpatched software, weak authentication, excessive permissions, and legacy technical debt are what leave systems open in the first place.
What this means for you: you are not going to defend a water utility. But the boring advice in that last paragraph is exactly the advice that applies to you, and it is the part that actually moves your risk. Turn on multi factor authentication where you have not, install the updates you have been dismissing, and be more suspicious of urgent messages, because cheap AI makes convincing phishing cheap too. If you run a small business, the letter is a reasonable thing to send to whoever handles your IT, with the observation that “we are too small to be a target” has not been true for a while.
Sources
AWS Buys the Team Behind DuckDB, and Says Agents Are Why
Amazon is acquiring DuckLabs, the thirty-person Amsterdam company behind the open-source database DuckDB. The project stays MIT-licensed, and AWS is unusually direct about the AI angle.