ai-security

Cyber defenders have months, says 100-company letter

Promtime

ai-security

More than 100 companies, including OpenAI, Anthropic, Amazon Web Services and Microsoft, warned on Thursday that organizations have only months left to prepare for AI-enabled cyberattacks. The letter, reported by Axios, sets out what companies, governments and AI labs should each do before that window closes.

At a glance

  • The letter argues that AI makes sophisticated intrusion capability cheaper and more accessible, exposing hospitals, water treatment plants and other critical infrastructure to a swarm of hacking attempts.
  • Signatories split the work four ways: every organization fixes its highest-risk weaknesses, security vendors build deployable AI defense, governments fund and coordinate response, and frontier labs open their strongest models to defenders.
  • No signatory attached a commitment, a deadline or a specific investment to the text, so the document sets out shared priorities without binding any signatory to them.

Joint statements from cloud providers, telecoms, banks and competing AI labs are rare, and the timeline here is what stands out: a warning measured in months rather than years. The practical weight of the document likely rests on the frontier labs, since access to their strongest response models during an incident is something no one else can grant. For hospitals and water utilities running old control systems, that offer appears to matter more than the warning itself.

The letter puts AI-generated code inside the security bar for what companies buy and build

"We have a limited window to strengthen cyber defenses," the letter says. The baseline ask applies to every organization rather than to signatories alone: raise internal security standards and fix the highest-risk weaknesses first. Organizations are also told to raise the security bar for what they buy, build and deploy, with AI-generated code named inside that category.

The signatory list spans cloud providers, cybersecurity firms, AI developers, telecoms, financial services companies and think tanks. The group frames the response as collective action and urges organizations to use the shrinking window to secure critical infrastructure and to harden it against AI-assisted intrusion.

Frontier labs are asked to open their strongest response models during major incidents

Frontier AI companies, a group that includes signatories OpenAI and Anthropic, are asked to give defenders access to their most capable response models during major cyber incidents, along with significant funding, training and hands-on support. Critical infrastructure providers are named as the intended recipients.

Cybersecurity and technology companies are given a separate task: quickly test and build out tools that make AI-powered defense accessible and deployable for critical infrastructure operators. The same group is asked to share threat intelligence with one another, which the letter treats as part of the same effort.

Governments are asked to strengthen the channels through which actionable threat intelligence moves, to coordinate defense at local, national and international levels, and to fund cyber defense. The letter addresses those three items to states rather than to the companies that signed it.

A U.S. water system attack used an apparent AI-generated exploitation script

Hospitals, water treatment plants and other critical infrastructure will face a swarm of hacking threats as AI makes sophisticated cyber capabilities cheaper and more accessible, the signatories write. The letter arrives during a wave of attacks on critical infrastructure, among them one targeting U.S. water systems that used what appeared to be an AI-generated exploitation script.

Water systems and power plants have long carried vulnerabilities in the tools that run their machinery. Attackers previously had to spend a large amount of time understanding the intricacies of those environments before they could act on the weaknesses they found.

AI models are drastically lowering the amount of time and energy that hackers must put into that preparation, experts told Axios earlier. The letter ties its central claim, that defenders have months rather than years, to that reduction in the effort an intrusion requires.

How many months is not stated

The letter puts no figure on the window beyond the word months, and the signatories attached no commitments, deadlines or specific investments to the text. It names no funding amounts for the government role and no date by which AI-powered defense tools should reach critical infrastructure operators, and it sets no schedule for the threat intelligence sharing it asks for.

Comments

No comments yet. Be the first.

Join the conversation

Sign in with Google to leave a comment. Your name and avatar come from your Google profile, and the comment appears after moderation.

We only use your name and avatar from Google. We never store your email address.