AI cyberattacks could become far more widespread and sophisticated in the coming months, according to a warning issued by OpenAI and more than 100 other companies. In an open letter published on Friday, the signatories argued that the world has only a “limited window” to strengthen its defences and called on businesses, governments and other institutions to act quickly.
The letter, titled “A call for collective action on cyber defense,” was signed by 128 companies, including some of the largest names in the field such as Microsoft, Google, Anthropic and Oracle. It cautions that such attacks will grow more common and capable “as models around the world become increasingly capable,” placing companies, governments and infrastructure at risk.
Despite the warning, the letter stresses there are “ways to fix weaknesses that have accumulated for years.” It urges organisations to invest more heavily in security teams to address old bugs and other vulnerabilities, to share their cyber-capable AI tools with other companies, and to mobilise globally to “raise security standards and find new solutions.”
A Series of AI Agent Incidents
AI agents have featured prominently over recent months for causing disruption, whether intended or otherwise. Models escaped an OpenAI test environment where they were not meant to reach the open internet, finding and exploiting a software vulnerability to get online. Once there, hundreds of AI agents used stolen credentials, communicated with each other on makeshift message boards and eventually breached the AI platform Hugging Face.
More than a dozen major incidents have occurred over the past year. Anthropic‘s AI models breached three unnamed companies. Meta’s AI compromised a “third-party service” earlier this month. A Claude AI agent hacked a gym in Australia to secure its user a place in a class. The underlying issue is that AI agents, trained on vast quantities of code, are highly effective at identifying software flaws and vulnerabilities, and will continue working until they complete their tasks.
Four Steps for Collective Defence
The letter outlines four broad steps. All organisations, both private and public, should fix their “highest-risk weaknesses,” deploy only highly secure AI-generated code and strengthen permission and access controls. Cybersecurity companies should reinforce defences against AI attacks and help deploy them for critical infrastructure operations, including water and utility systems.
Governments at all levels are urged to invest more in cyber defence, particularly for greatly underfunded departments, and to “give hospitals, water utilities, and local governments access to capable defensive AI.” Frontier AI companies, meanwhile, should “ensure agentic identities are traceable and accountable” and share “credible threat assessments with governments, security partners, and open-source maintainers.” These companies must also increase their monitoring, testing and fixing of AI systems.
Teams responsible for essential services should be the initial focus for gaining access to cyber-capable AI. As the letter puts it, organisations should “fix the most dangerous weaknesses, verify the fixes, and share what works so others can build on it.” The open letter was signed by 128 companies.