OpenAI, Anthropic warn of 'limited window' for AI cyber defense
Industry leaders say organizations have only months to strengthen defenses before sophisticated AI-enabled attacks become widespread.
The companies behind the world's most advanced AI systems are issuing an urgent warning: organizations may have only months to fortify their defenses before AI-enabled cyberattacks become significantly more dangerous.
In an open letter published Thursday, executives from OpenAI, Anthropic, Google, and Microsoft joined security firms like CrowdStrike and financial institutions including Citi and Capital One to sound the alarm. The signatories argue that the same AI capabilities driving innovation also create new vectors for sophisticated attacks on hospitals, technology companies, and critical infrastructure.
According to CBS News, which first reported the letter, a recent CrowdStrike analysis found that AI-enabled attacks surged 89% in 2025 compared to the previous year.
Why it matters
This represents a rare moment of consensus among competitors who typically guard their AI capabilities closely. When industry leaders collectively warn of a threat window measured in months rather than years, it signals both the pace of AI advancement and the urgency of the defensive challenge facing enterprises. Organizations that delay cybersecurity investments may find themselves unable to catch up once attackers fully weaponize frontier AI models.
The defensive opportunity
The letter frames the current moment as a "defenders' window" where the same AI advances creating risks can also identify and remediate vulnerabilities. The signatories argue that traditional cybersecurity approaches will prove insufficient against AI-powered threats.
Legacy systems present particular exposure, according to the letter. Longstanding software bugs, excessive user permissions, misconfigurations, unpatched systems, weak authentication protocols, and accumulated technical debt have left organizations vulnerable to exploitation by AI tools that can rapidly identify and exploit these weaknesses.
What organizations must do
The letter outlines specific responsibilities across different sectors. Every organization should prioritize cybersecurity investments, including replacing or upgrading vulnerable legacy technology systems that cannot be adequately secured.
Security teams require both expanded resources and access to sophisticated AI-enabled defensive tools. The signatories emphasize that defenders need technology at least as advanced as what attackers will deploy.
Sharing intelligence becomes critical. The letter calls for organizations to exchange threat data and proven response strategies, measuring success by the number of protected organizations, attack containment speed, and fix effectiveness.
Roles for specialists and governments
Specialized cybersecurity firms must continuously test defenses against evolving AI capabilities rather than static threat models. Governments need to coordinate responses and fund defense strategies at local, national, and international levels.
The AI companies themselves acknowledge obligations to fund training programs, provide responsible access to their models for security research, and ensure their own systems remain secure against misuse.
The letter's publication represents an acknowledgment from AI leaders that the technology they're developing poses genuine risks that require collective action to manage. The emphasis on a closing window suggests these companies believe the current balance between offensive and defensive AI capabilities will soon shift unless organizations act quickly.
Details of the open letter were first reported by CBS News.
This is an original analysis by the Omega editorial team. Source reporting: AI Watch.
Want systems like this working for your business?
Book a Call