“Each of us can reduce risk now,” the open letter reads, a blunt call to action from more than 100 companies and organizations warning that the window to shore up defenses before AI-enabled attacks proliferate is rapidly closing.
Who signed: OpenAI, Anthropic, Google, Microsoft, Amazon Web Services, and more
The letter, published Thursday, bears the names of frontier AI developers — OpenAI and Anthropic among them — and major cloud and platform providers including Google, Microsoft and Amazon Web Services. Financial institutions such as Capital One, Mastercard and Visa, and cybersecurity vendors including CrowdStrike, Palo Alto Networks and Proofpoint are also signatories. Organizers describe the effort as ongoing and said additional organizations are expected to join over time. An image accompanying the letter shows a montage of company logos representing the signatories.
Defenders’ window: longstanding bugs, misconfiguration, and technical debt
The authors frame AI as both a threat and a remedy and name a short list of concrete exposures that make systems vulnerable today: longstanding bugs, excessive permissions, misconfigurations, unpatched software, weak authentication and technical debt in legacy systems. The document calls this period a “defenders’ window,” arguing that the same AI capabilities raising alarm also give defenders new ways “to find and fix vulnerabilities that have accumulated over years.”

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleSpecific asks: what the letter urges of organizations, cyber firms, and frontier AI companies
The letter outlines clear responsibilities for different actors. Every organization is asked to make cybersecurity an immediate leadership priority, fix highest‑risk weaknesses, and raise security standards for the technology they buy, build and deploy — explicitly including AI‑generated code. Cybersecurity companies and technology partners are asked to test defenses against so‑called frontier AI capabilities and to make AI‑powered defensive tools accessible to critical infrastructure operators. Frontier AI companies are asked to provide “responsible model access, funding, training and support,” and to ensure autonomous AI systems remain traceable and accountable. Governments are urged to coordinate defense across borders, fund protection for essential services that lack staff or budget, and “impose costs on attackers.”
Palo Alto Networks: “a generational shift in cybersecurity”
The letter is accompanied by public warnings from signatories’ security teams. In a conversation with CyberScoop, Sam Rubin, senior vice president of Palo Alto Networks’ threat intelligence arm, said: “I can tell you without exaggeration that we believe that this is a generational shift in cybersecurity.” Rubin and his team said internal tests of frontier AI models and observed malicious use of commercially available AI tools in the wild have driven their concern.
What this means for critical infrastructure operators, governments, and cybersecurity companies
- Critical infrastructure operators: the letter notes security teams protecting critical infrastructure have been historically under-resourced and asks that cyber defense be rapidly resourced with tools, funding and hands‑on support, particularly where budgets are limited.
- Governments: beyond calls for cross‑border coordination and funding, the letter points to existing public actions, noting that as part of an executive order issued by President Donald Trump in June, a federal clearinghouse called Gold Eagle was stood up to share AI cyber threat information between the government and the private sector.
- Cybersecurity companies and technology partners: they are urged to stress‑test defenses against frontier AI capabilities and, crucially, to make AI‑powered defensive capabilities broadly accessible so organizations with limited staff or budget can benefit.
The letter explicitly declares that “status quo security won’t be enough,” arguing industry faces an “unprecedented two‑ to three‑year period of upheaval” in which AI systems can discover vulnerabilities far faster than defenders can currently respond. That framing drives the document’s central prescription: move rapidly to convert AI from a force that magnifies attackers’ speed into one that amplifies defenders’ reach.
For now, the signatories have offered a mix of technical requests (patch, reduce permissions, test against frontier models) and policy asks (cross‑border coordination, funding, and attacker cost imposition). The next visible steps will be whether more organizations join the letter’s coalition, whether cybersecurity vendors follow through on making AI‑based defenses broadly available to under‑resourced operators, and whether government programs such as the Gold Eagle clearinghouse expand their operational role in sharing AI‑related cyber threat intelligence.




