
More than 120 technology, cybersecurity, financial and infrastructure organizations are urging companies and governments to strengthen digital defenses before increasingly capable AI systems make sophisticated cyberattacks faster, cheaper and more widespread.
A coalition of technology companies, cybersecurity vendors, banks and other organizations is calling for an urgent global effort to strengthen cyber defenses as artificial intelligence reshapes the threat landscape.
The open letter, published by OpenAI, warns that organizations have a “limited window” to address longstanding security weaknesses before advanced AI capabilities become more widely available to attackers.
Signatories include Amazon Web Services, Anthropic, Cloudflare, Google, Microsoft, Mastercard, Visa, Cisco, as well as major players in the cybersecurity sector.
But bringing so many influential companies into a single defensive effort also raises questions of trust, transparency and accountability. Consumers depend heavily on Big Tech, yet many remain wary of the companies building and deploying the most powerful AI systems.
The letter describes AI as a force multiplier for both attackers and defenders.
More advanced models can help threat actors discover vulnerabilities, analyze complex systems, write malicious code and automate parts of an attack. This could allow smaller or less-skilled groups to carry out operations that previously required substantial time, expertise and money.
But many of the weaknesses AI could help exploit are not new. They include unpatched software, insecure configurations, excessive user permissions, weak authentication and technical debt accumulated in legacy systems.
The coalition argues that the existing approach to security will no longer be enough once attackers can find and exploit these gaps at machine speed. The concern is particularly acute for critical infrastructure, where outdated technology and limited security budgets can make it hard to replace vulnerable systems or deploy patches without disrupting essential services.
Hospitals, water-treatment facilities, local governments and the systems underpinning the internet are among the services singled out as at risk.
AI can also help security teams review code, find vulnerabilities, investigate alerts and prioritize remediation faster.
This creates what OpenAI has separately described as “the defender’s window”— a period in which organizations can still use advanced models to locate and repair weaknesses before offensive AI capabilities spread more widely.
In one example, OpenAI President Greg Brockman said an AI agent found 13 potential security issues on his personal website in about 15 minutes. The system then helped address problems involving email-spoofing protections, an outdated software component and an unencrypted connection between two hosting services.
Such tools could be particularly valuable for smaller organizations that lack large security teams. However, the open letter emphasizes that AI is no substitute for basic cyber hygiene. Strong access controls, secure architecture, timely patching, network isolation and defense in depth remain essential.
The initiative divides responsibility among organizations, cybersecurity providers, governments and frontier AI companies.
Businesses and public-sector leaders are urged to make cybersecurity an immediate priority, address their most dangerous vulnerabilities and apply stricter security standards to the technology they buy, build and deploy—including AI-generated code.
Cybersecurity companies and technology partners are asked to test their defenses continuously against emerging AI capabilities, incorporate AI into existing security tools and share threat intelligence and proven response playbooks.
Governments are called on to improve coordination across borders, fund cyber defense and expand access to advanced defensive capabilities. The letter places particular emphasis on hospitals, water utilities and local authorities that may lack the staff or resources to prepare independently.
AI developers, meanwhile, are asked to provide responsible access to capable models, along with funding, training and hands-on assistance. The initiative also calls for traceable AI-agent identities, continuous monitoring, authorized security testing and responsible disclosure of vulnerabilities.
The coalition brings together some of the most powerful and widely used technology companies in the world. Their participation gives the initiative considerable technical reach, but public acceptance can’t be taken for granted.
A Bitdefender survey of more than 7,000 internet users across seven countries found that trust varies considerably between major technology brands.
Nearly nine in 10 respondents said they trusted Google to some extent, while 85% said the same about Microsoft. Both companies signed the cyber-defense letter.
Ironically, OpenAI, which published the initiative, faces greater skepticism, with 45% of respondents expressing suspicion toward the company.

The findings expose a key tension. Consumers want technology companies to protect the services and information they rely on, but they also want to know how those companies use their data, how automated systems make decisions and who is accountable when something goes wrong.
That becomes especially important when AI tools are given access to sensitive code, infrastructure configurations, security alerts or operational systems. Defensive agents will need clearly defined permissions, strong monitoring and human oversight—particularly when their actions could affect essential services.
Collective cyber defense therefore depends on more than access to powerful technology. It also requires transparency, safeguards and evidence that the tools work as intended without creating new privacy or security risks.
A successful attack on a hospital, bank, utility provider or local government can expose personal information, interrupt essential services and create opportunities for follow-up phishing, identity theft and financial fraud. AI may also help criminals personalize scam messages, imitate trusted organizations and operate fraudulent campaigns on a much larger scale.
Consumers can’t manually fix vulnerabilities inside every service they use, but they can reduce their personal exposure by installing updates promptly, using unique passwords or passkeys, enabling multifactor authentication, reviewing app permissions and treating unexpected requests for money or credentials with caution.
Organizations, however, carry the larger responsibility. As AI lowers the barriers to sophisticated cyber activity, leaving known vulnerabilities unpatched or accounts overprivileged becomes increasingly risky.
The coalition’s message is ultimately one of urgency rather than inevitability: AI can (and likely will) increase the reach of cyberattacks, but it can also help defenders find and close weaknesses faster.
On topic:
AI isn’t your lawyer or doctor: New York lawmakers say it’s time to draw the line
tags
Filip has 17 years of experience in technology journalism. In recent years, he has focused on cybersecurity in his role as a Security Analyst at Bitdefender.
View all posts