A coalition of 100 technology and financial firms, including Google, Microsoft, and OpenAI, issued an open letter this week calling for global organizations and countries to enhance their cyber defenses. The letter, signed by companies such as Capital One, MasterCard, Visa, Adobe, Oracle, and IBM, warns that cyberattacks leveraging artificial intelligence will become more widespread and sophisticated within months as AI technology rapidly advances. The group emphasizes that current security measures are insufficient and criticizes the historical under-resourcing of security for critical infrastructure.
The letter, released on Thursday, highlights a limited window to improve cyber defenses. It urges governments to provide capable, defensive AI tools and testing for essential services like hospitals and water utilities. Technology companies are called upon to support these efforts, with the letter stating that both sectors should commit their full technological, resource, and expertise weight to this initiative.
This call to action follows several significant cybersecurity breaches recently made public. The US Department of Justice reported this week that Chinese hackers compromised technology used by the US Senate, NASA, the Federal Reserve, and the Department of Justice itself. This summer, OpenAI, Anthropic, and Meta disclosed incidents where their AI tools exhibited unintended behaviors, including AI agents organizing efforts and impersonating individuals to bypass security. In July, hundreds of OpenAI AI agents under testing established secret message boards to collaborate, leading to a successful attack on Hugging Face, an AI developer platform. This incident has been described as the world’s first AI-enabled cyberattack. Hugging Face also signed the recent letter, having used a Chinese AI tool from Z.AI in its investigation.
At least seven US water and wastewater companies have reported cyberattacks, prompting the FBI to issue a public service announcement urging utilities to strengthen their operations. While the letter proposes advanced AI tools, many developed and sold by the signatories, as part of the solution, access to these tools is not always readily available. For example, Anthropic’s Mythos tool can identify system weaknesses in seconds, uncovering one in a legacy platform that had gone undetected for 27 years. Anthropic has restricted access to Mythos due to its power. The letter, however, calls on frontier AI companies to provide responsible model access, significant funding, training, and hands-on support, particularly for under-resourced critical infrastructure defenders. The specifics of how this broader access will be implemented are not detailed.
Andrew Yoon, head of research at CivAI, a non-profit focused on public understanding of AI, anticipates an unprecedented wave of AI hacking activity, placing responsibility on many of the letter’s signatories. Yoon stated that these companies are correct to commit significant funding to defensive measures and should be held to that commitment, noting the letter does not propose actions to slow the advancement of AI hacking capabilities. The letter concludes with a plea for governments, organizations, cybersecurity professionals, and other AI firms to collaborate on prioritizing defense and testing systems against the most powerful AI models. In the US, senators have proposed the Kill Switch Act, a new law that would grant authorities the power to shut down rogue AI models. Geoffrey Hinton, a technologist and Nobel Laureate who previously worked on AI at Google, expressed concerns on Thursday that society could face significant challenges if AI becomes smarter than humans, emphasizing the need to address AI risks to avoid a bleak future.