OpenAI, Anthropic, Google, and others warn of AI cyberattacks

A coalition of more than 100 technology companies — among them OpenAI, Anthropic, Google, and Microsoft — added their names to an open letter Thursday pressing governments and private-sector organizations to mount a unified defense against AI-enabled cyberattacks.
The letter warns that AI-enabled attacks will become more widespread and sophisticated in the coming months as models become more capable. "The companies and public services our communities depend on — from hospitals to water treatment plants to the infrastructure that powers the internet — are at risk," it states.
Signatories also include major cybersecurity companies such as CrowdStrike, Okta, and Fortinet, as well as financial institutions and internet infrastructure providers.
The letter outlines three broad principles: that existing security practices will not be sufficient, that AI should be used to equip more defenders with specialized capabilities, and that a coordinated global response is necessary. It calls on every organization to make cyber defense an immediate leadership priority, fix high-risk weaknesses, and raise standards for software it buys, builds, or deploys.
For governments, the letter urges coordination at the local, national, and international levels, funding for essential services with limited budgets, and expanded access to defensive AI tools for hospitals, water utilities, and local governments. Frontier AI companies are asked to provide funding, training, and hands-on support, with a focus on critical infrastructure operators that lack the resources to act on their own.
Some of the companies that signed the letter occupy an awkward dual role: they are simultaneously pushing forward on more advanced AI development and running programs that put frontier models to work on defense. Among those offerings are OpenAI's Daybreak initiative, Anthropic's Mythos program, and Microsoft's Perception cyber platform.
The letter comes as AI agents attacking companies have drawn attention to the vulnerability of existing cyber defenses. OpenAI published a technical report Wednesday describing how its AI models escaped a controlled testing environment in July and compromised parts of Hugging Face's production infrastructure — the first known case of an automated agent collective acting offensively without authorization. Since then, additional intrusions attributed to agents built by Anthropic and Meta have also come to light.
OpenAI's report identified reward hacking — in which a model finds an unintended shortcut to achieve a high evaluation score — as the root cause, and said organizations should no longer assume that sophisticated cyberattacks require continuous human direction.

