More than 100 companies spanning artificial intelligence, technology, cybersecurity, finance and other industries have joined an unusually broad warning about the rapidly changing cyber threat landscape, saying organizations have only a limited window to strengthen their defenses before increasingly capable AI systems make sophisticated attacks easier to execute.
The open letter, published on August 27, warns that AI-enabled cyberattacks are expected to become considerably more widespread and sophisticated “in the coming months” as artificial intelligence models continue to advance.
The signatories include some of the world's largest AI, technology, cybersecurity and financial companies, underscoring growing concern that the same capabilities making AI increasingly useful for legitimate purposes could also amplify malicious cyber activity.
The message, however, is not simply a warning about AI. The companies argue that artificial intelligence could also give defenders powerful new tools to identify vulnerabilities, accelerate security work and respond to attacks.
More Than 100 Major Companies Join the Warning
The open letter has attracted a broad group of corporate signatories.
They include major AI and technology companies such as OpenAI, Anthropic, Microsoft, Google, Amazon Web Services, IBM, Oracle, Cisco and GitHub.
Cybersecurity specialists including CrowdStrike, Cloudflare, Fortinet, Palo Alto Networks, Check Point, SentinelOne, Sophos and Zscaler have also joined the initiative.
Companies from other sectors—including Mastercard, Visa, Capital One, General Motors, PayPal, Shopify and Deutsche Telekom—are among the signatories as well.
The diversity of the companies involved illustrates how AI-related cybersecurity risks are no longer being viewed solely as a problem for AI laboratories or security specialists.
Modern businesses increasingly depend on interconnected digital infrastructure, meaning a major shift in attackers' capabilities could have consequences across banking, healthcare, manufacturing, telecommunications, utilities and public services.
The Warning: AI Could Make Cyberattacks More Powerful
The central concern is that increasingly capable AI systems could lower the expertise, cost and time required to conduct sophisticated cyber operations.
Advanced AI can potentially help automate or accelerate parts of the hacking process, allowing malicious actors to operate at greater speed and scale.
That does not mean AI will independently make every attacker highly capable or that a catastrophic cyber event is inevitable.
Rather, the companies are warning that the economics and accessibility of cyber operations could change as AI models become better at tasks relevant to software development, vulnerability analysis and other technical activities.
This could allow attackers to attempt more operations, adapt more quickly and potentially exploit weaknesses that previously required significant specialist knowledge.
Hospitals, Water Systems and Internet Infrastructure Face Particular Risk
Critical infrastructure sits at the center of the industry's concerns.
The letter specifically highlights organizations and public services ranging from hospitals and water treatment facilities to the infrastructure supporting the internet.
Many of these organizations operate complicated combinations of modern and legacy technology.
Older software, weak authentication, excessive permissions, configuration problems, unpatched vulnerabilities and accumulated technical debt can leave organizations exposed.
Critical-infrastructure operators may also have fewer cybersecurity resources than major technology companies.
That combination—essential services, legacy infrastructure and limited security budgets—could make some organizations particularly vulnerable as attackers gain access to more capable AI tools.
Companies Say Existing Cybersecurity Practices Will Not Be Enough
One of the central arguments in the letter is that maintaining current security practices will not be sufficient.
Organizations are being urged to identify and fix their highest-risk weaknesses, strengthen authentication and access controls and upgrade systems where necessary.
The initiative also calls for organizations to scrutinize the software they deploy, including code generated using artificial intelligence.
The broader objective is to shift cybersecurity from a reactive technical function toward an immediate leadership priority.
For corporate executives, this could mean treating major security weaknesses as business risks requiring senior management attention rather than leaving responsibility entirely with IT departments.
AI Could Be the Defense as Well as the Threat
The warning contains an important counterpoint: the companies are not calling for organizations to avoid artificial intelligence.
Instead, they argue that AI itself should become a major part of the defensive response.
Cyber-capable AI tools could help security teams detect vulnerabilities, analyse large volumes of security information, identify suspicious activity, verify fixes and respond more rapidly to incidents.
Automation could be particularly valuable for organizations facing shortages of experienced cybersecurity professionals.
The strategic challenge is therefore a race between offensive and defensive adoption.
If defenders can use increasingly capable AI tools faster and more effectively than attackers, the technology could ultimately make digital infrastructure safer rather than less secure.
Governments Asked to Expand Their Role
The initiative also places significant responsibility on governments.
It calls for stronger coordination of cybersecurity efforts at local, national and international levels, including faster sharing of actionable threat intelligence.
Governments are also encouraged to fund cyber defenses for essential services that lack adequate personnel or financial resources.
Another proposal involves expanding trusted-access programs that can give vetted defenders access to advanced AI capabilities.
Hospitals, water utilities and local governments are specifically identified as organizations that could benefit from access to capable defensive AI, authorized security testing and hands-on assistance.
The letter also argues that governments should impose costs on malicious attackers.
AI Developers Asked to Provide Models, Funding and Training
Frontier AI companies are being asked to play a particularly important role because they control some of the most advanced models.
The proposed responsibilities include providing responsible access to powerful AI models as well as funding, training and technical support for organizations defending critical infrastructure.
AI companies are also encouraged to invest in authorized security testing and responsible vulnerability disclosure while sharing tools, defensive playbooks and credible threat assessments.
The emphasis on access is significant.
If sophisticated AI capabilities become available to attackers while defenders lack comparable tools, organizations with limited budgets could find themselves at a growing disadvantage.
Giving legitimate security teams access to capable defensive systems is intended to reduce that imbalance.
Why the Warning Matters Now
Concerns that AI could reshape cybersecurity have existed for years, but recent advances are making the issue more immediate.
AI systems are becoming more capable at coding, reasoning and performing multi-step tasks. Those improvements can create enormous legitimate benefits, but cybersecurity is inherently dual-use: many skills that help defenders identify weaknesses can potentially help attackers search for them as well.
The Five Eyes intelligence alliance—comprising the United States, United Kingdom, Canada, Australia and New Zealand—also warned in June that artificial intelligence could fundamentally transform cybersecurity.
The new corporate initiative adds significant private-sector weight to those concerns.
A Warning, Not a Prediction of Inevitable Disaster
The industry's statement should nevertheless be interpreted carefully.
The companies are warning about a rapidly increasing risk rather than confirming that a particular large-scale AI cyberattack will occur within a specific period.
Likewise, the letter does not establish that every advanced AI system will automatically become an effective hacking platform.
Its central argument is about preparedness: AI capabilities are developing quickly enough that governments and businesses should strengthen defenses before offensive capabilities become substantially more accessible.
There is another important limitation.
While the initiative lays out recommendations for organizations, governments, cybersecurity providers and AI developers, reports have noted that the letter itself does not contain specific binding investment commitments or implementation deadlines for its signatories.
That means its long-term significance will depend partly on whether the organizations supporting the initiative turn its principles into measurable cybersecurity improvements.
Cybersecurity Enters the AI Arms Race
The broader development highlights an increasingly important feature of the AI era.
The cybersecurity challenge is unlikely to be simply humans defending networks against humans using AI.
AI systems could increasingly operate on both sides.
Attackers may use models to accelerate reconnaissance, vulnerability discovery and other parts of cyber operations, while defenders deploy AI to analyse threats, detect weaknesses and respond at machine speed.
That dynamic could fundamentally change how cybersecurity teams operate.
Organizations that rely exclusively on traditional manual security processes may struggle if attackers increasingly automate their operations.
The companies' message is therefore ultimately about speed: strengthen digital infrastructure and put advanced defensive technology in place while defenders still have an opportunity to stay ahead.
What Happens Next
The open letter establishes a framework rather than a finished cybersecurity program.
Its effectiveness will depend on whether governments provide additional resources to vulnerable infrastructure, whether cybersecurity companies can make AI-powered defenses broadly accessible, and whether frontier AI developers provide meaningful technical support and responsible access to advanced capabilities.
Businesses will also have to determine whether cybersecurity receives the executive attention and investment required to address longstanding weaknesses.
The warning from more than 100 companies makes one point particularly clear: the debate over AI and cybersecurity is moving rapidly from hypothetical future risks toward decisions organizations need to make today.






