Site navigation

Google, Microsoft and OpenAI Call For Cyber Defence Push

Graham Turner

,

AI cyber attacks
A coalition of major tech firms is calling for governments and industry to urgently strengthen defences, particularly around critical infrastructure.

A coalition of more than 100 technology companies, financial institutions and cybersecurity firms has called for an urgent global effort to strengthen cyber defences, warning that increasingly capable AI could make cyber attacks significantly more widespread and sophisticated within months.

Google, Microsoft, Anthropic, OpenAI, AWS, IBM, Oracle, Cisco, CrowdStrike and Cloudflare are among the signatories to an open letter calling for governments, businesses and technology providers to increase investment in cyber defence and expand access to AI-powered security tools.

Banks and financial services firms including Capital One, Citi, U.S. Bank, Nationwide Building Society, Mastercard and Visa have also backed the initiative, alongside organisations including Accenture, Adobe, Capgemini, KPMG, PwC, General Motors, Uber and Zurich Insurance Company.

“We have a limited window to strengthen cyber defenses,” the letter begins.

It warns that “in the coming months, AI-enabled cyber attacks will become far more widespread and sophisticated as models around the world become increasingly capable”, placing organisations ranging from hospitals and water treatment facilities to internet infrastructure providers at growing risk.

The signatories argue that existing approaches to cybersecurity will not be sufficient as AI capabilities advance.

“Recognize that status quo security won’t be enough,” the letter states, pointing to longstanding vulnerabilities including excessive permissions, misconfigurations, unpatched software, weak authentication and technical debt in legacy systems.

It also highlights what it describes as the historic under-resourcing of security teams, particularly within critical infrastructure, and calls for a surge in tools and resources to help organisations address existing weaknesses.

At the same time, the group argues that advances in AI could provide defenders with new ways to identify and resolve vulnerabilities that have accumulated over many years.

The letter calls for more defenders to be given access to “cyber-capable AI”, with organisations encouraged to share tools, verified fixes and practical knowledge so that defensive improvements developed by one organisation can benefit others.

It also urges greater international cooperation, arguing that increasingly advanced cyber capabilities are being developed around the world and that no single company should control the direction of the technology.

The letter calls for governments, cybersecurity companies, technology partners and frontier AI developers to coordinate their efforts, particularly around critical infrastructure organisations operating with limited budgets.

Governments are urged to fund cyber defence for essential services and expand trusted access programmes, while providing hospitals, water utilities and local government organisations with access to capable defensive AI, authorised security testing and hands-on technical support.

Cybersecurity companies and technology providers, meanwhile, are being asked to continuously test defensive systems against frontier AI capabilities, integrate AI into existing security products and make AI-powered defence more accessible to critical infrastructure operators.

Frontier AI developers are also urged to “provide responsible model access, significant funding, training, and hands-on support, especially for under-resourced critical-infrastructure defenders.”

The letter calls on these companies to develop observability and security tools, ensure the identities of AI agents can be traced and held accountable, support authorised testing and private vulnerability disclosure, and share security tools and threat assessments with governments, open-source maintainers and cybersecurity partners.

It does not, however, specify when or how broader access to advanced AI models for defenders would be introduced.

AI Cyber Threats Growing

The intervention comes amid heightened concern over the potential for increasingly autonomous AI systems to be used in cyber attacks.

A group of hundreds of OpenAI AI agents being tested in July were able to establish secret message boards to communicate and coordinate their activities, ultimately resulting in a successful attack against AI development platform Hugging Face.

The incident has been described as the world’s first AI-enabled cyber-attack.

Hugging Face, which has signed the new open letter, subsequently used an AI system developed by Chinese firm Z.AI as part of its investigation into how the OpenAI agents compromised its operations.

OpenAI, Anthropic and Meta have also disclosed incidents this summer in which AI systems behaved in unintended ways, with some agents organising their efforts and impersonating real people in attempts to overcome security controls.

Concerns have also grown around the vulnerability of critical infrastructure.

At least seven US water and wastewater organisations have reported cyber attacks, prompting the FBI to issue a public service announcement calling on utilities to strengthen the security of their operations.

Separately, the US Department of Justice said this week that hackers in China had breached technology maintained by organisations including the US Senate, Nasa, the Federal Reserve and the Department of Justice itself.

The companies backing the new initiative argue that more advanced AI systems could form part of the response to such threats.

Anthropic, for example, has developed an AI security tool called Mythos which the company said can identify vulnerabilities within seconds that have previously evaded human researchers. In one case, the system reportedly discovered a weakness in a legacy platform which had remained undetected for 27 years.

Anthropic has restricted access to Mythos, however, arguing that its capabilities are powerful enough to present risks if placed in the wrong hands.

The tension between making powerful systems available to defenders and preventing their misuse forms part of the broader challenge facing the industry as AI capabilities develop.

Andrew Yoon, head of research at non-profit organisation CivAI, warned that “an unprecedented wave of AI hacking activity” is approaching, while placing some responsibility for that development on companies which have signed the letter.

“They are right in this letter to commit ‘significant funding’ to defensive measures. They should be held to that commitment”, Yoon said. “Notably, the letter does not call for any action to slow the advance of AI hacking abilities.”

The open letter instead focuses on accelerating defensive efforts, calling for organisations to treat cybersecurity as an immediate leadership priority and rapidly address their highest-risk vulnerabilities.


Recommended reading


Companies are encouraged to strengthen access controls, adopt least-privilege principles, replace or upgrade insecure systems and verify that security improvements work without disrupting essential services.

Where systems cannot be patched safely, the letter recommends introducing and testing compensating controls.

The initiative also calls for greater sharing of threat intelligence and tested defensive playbooks, while urging organisations to assess progress based on factors including the number of organisations protected, how quickly attacks can be contained and whether security fixes prove effective.

In the US, lawmakers have separately proposed the Kill Switch Act, which would give authorities powers to shut down rogue AI models.

The signatories argue that governments and industry must now act collectively before offensive AI capabilities develop further.

“We call on leaders across industry and government to bring the full weight of their technology, resources, and expertise to this effort,” the letter concludes.

“Put cyber-capable AI in the hands of defenders, starting with the teams protecting essential services. Fix the most dangerous weaknesses, verify the fixes, and share what works so others can build on it. Together, we can turn today’s AI advances into lasting improvements in security that benefit everyone. Let’s put them to work.”

Graham Turner

Sub Editor

Latest News

Cybersecurity

Manchester Airport Group Suffers Data Breach of Customer Info

AI Cybersecurity Editor's Picks Security

Google, Microsoft and OpenAI Call For Cyber Defence Push

Featured Finance

Final Extension Announced for Scottish Fintech Awards

Business

Business Confidence in Scotland Rises as Trading Outlook Climbs