"We have a limited window to strengthen cyber defenses," reads an open letter signed by more than 100 of the world's biggest technology and information‑security companies.
Open letter from OpenAI, Anthropic, Google and Microsoft warns of AI‑enabled attacks
More than 100 companies — including AI builders OpenAI, Anthropic, Google and Microsoft — joined security heavyweights Cloudflare, CrowdStrike, Fortinet and Palo Alto Networks on an open letter that bluntly concludes "status quo security won't be enough." The signatories warned that AI‑enabled attacks will become "far more widespread and sophisticated" in the coming months as models grow more capable, putting hospitals, water treatment plants and internet infrastructure at particular risk.
Security vendors urged to stress‑test and scale defensive AI
The letter's technical prescription is itself an industry playbook: put cyber‑capable models into the hands of defenders, use cheaper models to handle security work at scale, and reserve frontier systems for harder problems. Security vendors are asked to continuously test their defenses against frontier AI capabilities, share threat intelligence, and help critical infrastructure operators deploy AI‑powered defenses. The signatories also propose investing in testing, vulnerability disclosure, and tools that make AI agents traceable.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildCompanies that build frontier models told to provide "responsible model access" and support
Companies developing frontier AI models are singled out for extra responsibility. The letter asks them to provide "responsible model access, significant funding, training, and hands‑on support," particularly to under‑resourced critical infrastructure operators. It also calls for investments that make AI agents traceable and for continued attention to testing and vulnerability disclosure.
Governments asked to fund cybersecurity and expand trusted‑access programs
The signatories do not limit the fix to industry. Governments are asked to fund cybersecurity for essential services, expand trusted‑access programs, and give hospitals, water utilities and local governments access to capable defensive AI. The intent is to widen defenders' capabilities before offensive AI capabilities become cheaper and available to more attackers — the narrow "defenders' window" the letter urges stakeholders to seize.
What this means for hospitals, water utilities, and internet infrastructure
- Hospitals: The letter places hospitals among critical infrastructure at risk from more capable AI attacks and urges governments and model developers to give their security teams access to defensive AI and training.
- Water utilities: Water treatment plants are explicitly named as vulnerable; the signatories want operators helped with deployment of AI‑powered defenses and with funding to close long‑standing gaps like unpatched software and weak authentication.
- Internet infrastructure: Operators of internet infrastructure are warned to expect more sophisticated attacks and to benefit from continuous testing by security vendors and from shared threat intelligence.
Promises without price tags: requests include "significant funding" but no figures or deadlines
Despite the blunt warnings and detailed asks, the letter offers no dollar figures, deadlines, or firm commitments from the companies that signed it. The request that frontier model developers provide "significant funding, training, and hands‑on support" is not quantified, and signatories are being asked to bring the "full weight of their technology, resources, and expertise" without a binding timetable or stated funding amounts. The letter also points to long‑running problems — old vulnerabilities, unpatched software, misconfigurations and weak authentication — that are particularly acute in critical infrastructure where security teams are often short on money and staff.
The central paradox of the letter is plain: many signatories have roles both as builders of powerful AI systems and as vendors of the cloud services and security tools that organizations buy to stay safe. After years of selling cloud services, security software and, recently, AI, the industry has settled on a familiar prescription for a new threat: better cybersecurity, more resources and more AI. What remains unanswered in the document is who will pay — and how soon.
The companies warn of demonstrable trends: AI agents have already been shown finding and exploiting vulnerabilities on their own, and AI‑generated exploit code has begun appearing in attacks against critical infrastructure. The letter frames these developments as a narrowing window to act. Whether words from more than 100 of the industry's biggest names turn into funded programs, firm timelines, and measurable defenses is the practical question left on the table.
Original story: https://www.theregister.com/security/2026/08/28/industry-that-built-the-problem-offers-to-sell-you-the-solution/5293207




