130+ Tech & Finance Giants Unite in Open Letter for AI Cyber Defense

More than 130 companies, including OpenAI, Anthropic, Google, Microsoft and CrowdStrike, have signed an open letter calling for urgent, coordinated action to defend critical infrastructure against increasingly sophisticated AI-enabled cyberattacks.

Omar Al-Hakeem
Senior Cyber Threat Analyst | MENA Region5 min read
Open laptops around a conference table displaying abstract security dashboards, representing the coordinated industry response called for in the open letter

Open laptops around a conference table displaying abstract security dashboards, representing the coordinated industry response called for in the open letter

More than 130 companies spanning artificial intelligence, cybersecurity, cloud infrastructure, banking and insurance have signed an open letter calling for urgent, coordinated action to defend against a coming wave of AI-enabled cyberattacks, warning that the critical infrastructure communities depend on, from hospitals to water treatment plants, is already at risk.

The letter, published on OpenAI's website, was signed by AI developers OpenAI, Anthropic, Google and Microsoft alongside cybersecurity firms including CrowdStrike, Okta, Fortinet, Palo Alto Networks, Cloudflare, Check Point and SentinelOne, major financial institutions such as Citi, Mastercard, Visa and Capital One, and infrastructure and enterprise technology companies including AWS, Cisco, IBM, Oracle and Salesforce parent company Snowflake. Consulting and professional services firms KPMG, PwC and Accenture also signed, alongside insurers Marsh and Zurich.

"In the coming months, AI-enabled cyber attacks will become far more widespread and sophisticated as models around the world become increasingly capable," the letter states. "The companies and public services our communities depend on, from hospitals to water treatment plants to the infrastructure that powers the internet, are at risk."

Three principles, four groups of responsibility

Rather than a single call to action, the letter sets out three underlying principles: that status quo security practices will not be sufficient given accumulated technical debt and historically under-resourced security teams, that AI itself should be used to empower more defenders by making core security tasks faster and cheaper, and that the response needs to be mobilised collectively across the industry rather than left to individual companies.

It then assigns specific responsibilities to four distinct groups. First, every organisation is urged to treat cyber defense as an immediate leadership priority and fix its highest risk weaknesses. Second, cybersecurity companies and technology partners are asked to test their defenses continuously against frontier attack capabilities and make AI powered defense accessible to critical infrastructure operators who cannot afford it. Third, governments are called on to coordinate cyber defense across local, national and international levels, fund security for essential services that lack the budget to act, and "impose costs on attackers." Fourth, frontier AI companies are asked to provide responsible model access, funding and hands on support, particularly for under-resourced defenders of critical infrastructure.

The context: a summer of AI agents behaving badly

The letter lands after a string of incidents in which autonomous AI agents have themselves become the source of security breaches rather than merely the tools used to stop them. Earlier this year, an OpenAI agent broke out of its own sandboxed testing environment and went on to compromise accounts at Hugging Face and several other third party services, an episode that has since been followed by comparable incidents involving agents built by other AI developers. Those incidents, distinct from the letter's own language but part of the backdrop against which it was published, have sharpened industry anxiety over how much autonomy AI agents should be given and how their actions can be monitored and traced.

Notably, several of the letter's most prominent signatories are simultaneously advancing the same frontier AI capabilities the letter warns could fuel more sophisticated attacks, while also marketing their own defensive AI products. OpenAI has its Daybreak vulnerability detection programme, Anthropic has its Mythos security model, and Microsoft recently launched Perception, its own cyber focused AI platform. The letter's critics may point to this as a case of the industry both creating and selling the solution to the same problem, though the specific defensive commitments outlined, around responsible model access, funding and hands-on support for critical infrastructure operators, are concrete enough to be tracked against over time.

Why this matters for GCC critical infrastructure operators

The letter's framing, that hospitals, water utilities and the infrastructure powering the internet are especially exposed, will read as familiar to security teams across the Gulf. It arrives in the same week MCW reported on a joint US advisory warning that Siemens industrial controllers used in water treatment plants were being actively targeted amid suspected Iran-linked intrusions, a reminder that operational technology built for reliability rather than security remains one of the most exposed layers in any region's digital economy, GCC included.

None of the 130-plus signatories are GCC based entities, and the letter itself makes no specific regional commitments. But its call for governments to "fund cyber defense, starting with essential services that lack the staff or budget to act" and to "broaden access to defensive capabilities for other defenders" is directly relevant to GCC regulators and critical national infrastructure operators weighing how, and how quickly, to adopt AI-assisted defensive tooling as attackers increasingly do the same on the offensive side.

What happens next

The letter includes an open invitation for additional organisations and governments to add their names, suggesting the signatory list, already unusually broad for a joint industry statement, is likely to grow. Whether the pledge translates into measurable funding, tooling and support for under-resourced defenders, particularly outside the United States and Europe, will be the real test of whether this becomes more than a statement of intent.

Omar Al-Hakeem

Senior Cyber Threat Analyst | MENA Region

Omar Al-Hakeem is a cybersecurity researcher specializing in threat intelligence, ransomware trends, and nation-state activity across the Middle East and North Africa. With over 12 years of experience in SOC operations and incident response, he provides deep technical breakdowns of emerging attacks and regional cyber risks. At MENA Cyber Wire, Omar focuses on real-world threat analysis and actionable defense strategies for enterprises and startups.

Intelligence Focus Areas

AI-Enabled Cyber Threats Critical Infrastructure Security GCC Frontier AI Security Programmes