The companies behind some of the world’s most advanced artificial intelligence systems are sounding a sharper alarm: the same tools transforming business could soon help attackers launch highly sophisticated cyber operations against hospitals, tech companies, financial firms and other critical institutions.
In an open letter released Thursday, executives and representatives from OpenAI, Anthropic, Google, Microsoft and many other organizations warned that defenders have only a “limited window” to harden systems before AI-powered cyberattacks become far more damaging. That opportunity, they cautioned, may be measured in months rather than years.
The group of signatories also includes major cybersecurity firms such as CrowdStrike, along with financial institutions including Citi and Capital One.
While the letter highlights growing dangers to public services and digital infrastructure, it also argues that artificial intelligence can strengthen cyber defense by helping organizations detect vulnerabilities and “fix weaknesses” before criminals exploit them.
“If we act decisively, we can use the defenders’ window to make our digital world much more secure,” the letter said.
The warning comes as threat activity involving AI appears to be accelerating. A recent CrowdStrike report found that AI-enabled attacks rose 89% in 2025 compared with the previous year.
How to defend against attacks
According to the companies, traditional approaches to cybersecurity are no longer sufficient for the scale and speed of the emerging threat.
“Longstanding bugs, excessive permissions, misconfigurations, insecure and unpatched software, weak authentication and technical debt in legacy systems have left systems exposed,” the letter said.
Security teams need to be beefed up and invested in, while defenders against AI cyberattacks need to be equipped with the most sophisticated AI-enabled tech, it said.
The letter also called on companies and experts to share their expertise.
“Share threat intelligence and tested playbooks, and measure progress by how many organizations are protected, how quickly attacks are contained, and whether fixes work,” it added.
Call to action
Every organization needs to prioritize cybersecurity, according to the letter. That might include replacing or upgrading older tech systems that are vulnerable to attack.
Specialized cybersecurity firms have an obligation to test defenses against evolving cyber capabilities continually. Governments also have a key role to play in containing cyber threats through coordinated actions and by funding cyber defense strategies at the local, national, and international levels, it added.
Lastly, the letter said it is incumbent upon frontrunner AI companies — including those that signed the document — to fund training, provide “responsible” access to their models, and adequately secure them.
Aimee Picchi