More than 130 companies, including Google, Microsoft, OpenAI, Anthropic, IBM, and Cisco, have signed a joint call to strengthen cyber defenses using AI. They warn that AI attacks will become much more widespread and sophisticated in the coming months, with critical infrastructure posing the greatest risk.
The signatories argue that there is a limited window of time to get digital defenses in order. According to them, AI-driven cyberattacks will become “far more widespread and sophisticated” in the coming months as models around the world become more capable. Hospitals, water treatment plants, and the infrastructure supporting the internet are at risk.
In addition to the major AI labs, the call is backed by security providers such as CrowdStrike, Palo Alto Networks, Fortinet, Check Point, Sophos, Tenable, and Zscaler, as well as financial institutions including Visa, Mastercard, Citi, BBVA, and Zurich. Deutsche Telekom, General Motors, Uber, and Shopify also signed on.
Four principles for a collective response
The statement outlines four guiding principles. First: current security measures fall short. Old bugs, overly broad permissions, misconfigurations, weak authentication, and technical debt in legacy systems have made systems vulnerable. According to the signatories, security teams for critical infrastructure have historically been understaffed.
In addition, more defenders must gain access to cyber-capable AI, a global response is needed (“no single company should control the future”), and every party can begin reducing risk now.
The letter divides the actions into four groups. Organizations must treat cyber defense as an immediate leadership priority, fix the most dangerous vulnerabilities, and raise the bar for what they purchase, build, and deploy, including AI-generated code. Security companies must continuously test their defenses against cutting-edge capabilities and make AI-based defense accessible to critical infrastructure operators.
Governments are tasked with funding and coordinating cyber defense, and with providing hospitals, water utilities, and local governments with access to defensive AI. Frontier AI companies must provide model access, funding, and training, and ensure that agentic identities are traceable and accountable.
The signatories call on leaders in industry and government to leverage their technology, resources, and expertise and to share effective solutions with one another.