Over 100 organizations call for global AI cyber-defense surge

THE BRIEF
More than 100 technology, cybersecurity, financial and infrastructure organizations have signed an open letter calling for an urgent global increase in cyber defense. Signatories include OpenAI, Anthropic, AWS, Google, Microsoft, Mastercard, Visa, BBVA, Citi, U.S. Bank, Cloudflare and many security providers. The letter warns that increasingly capable models may make AI-enabled cyberattacks more widespread and sophisticated in the coming months, while also giving defenders new ways to find and fix accumulated weaknesses. It asks every organization to make cyber defense a leadership priority, urges security companies to test continuously against frontier capabilities, calls on governments to fund essential services and share actionable intelligence, and asks frontier AI companies to expand trusted defensive access. This is a joint policy commitment and risk assessment, not evidence that a specific forecast will occur on a fixed timeline. Its practical value lies in the concrete controls it prioritizes: least privilege, strong authentication, verified fixes, defense in depth and support for under-resourced critical infrastructure.
WHY IT MATTERS
The breadth of the signatory list turns AI-enabled cyber risk into a mainstream governance issue rather than a concern limited to AI laboratories. Banks, hospitals, water utilities and local governments are explicitly part of the risk and response model. Leadership teams should focus less on predicting the exact arrival of fully autonomous attacks and more on reducing known weaknesses that faster tools could exploit immediately. This also creates a useful accountability test: organizations can measure whether public concern is matched by funding, deadlines and verified improvement.
WHO SHOULD CARE
Boards, executives, CISOs, banks, technology suppliers, public-sector leaders and critical-infrastructure operators should use the letter as a prompt to fund measurable defensive improvements and verify that fixes work.
WHAT TO DO NOW
- Make cyber defense a named leadership priority with accountable owners and deadlines.
- Fix high-risk weaknesses, excessive privileges, weak authentication and exposed legacy systems first.
- Verify remediation results without disrupting essential services.
- Test controls continuously against current AI-enabled attack capabilities.
- Share tested playbooks and support smaller critical-infrastructure operators where possible.