Summary
- More than 100 organisations have backed a call for governments and industry to prepare for more capable and widespread AI-enabled cyberattacks.
- Signatories want critical-infrastructure defenders to gain greater access to defensive AI, funding, threat intelligence, authorised testing, and technical support.
- European participants include major telecoms, software, financial, consultancy, and cyber-security companies, giving the initiative direct regional relevance.
More than 100 technology, telecommunications, financial-services, and cyber-security organisations have called for a coordinated international effort to strengthen digital defences before increasingly capable artificial intelligence makes offensive cyber activity cheaper and more persistent. The initiative, published by OpenAI, argues that governments and industry have an opportunity to use the same generation of models to repair existing weaknesses before attackers can exploit them more systematically.
The signatories extend well beyond frontier AI developers. Anthropic, Google, Microsoft, AWS, IBM, and OpenAI appear alongside cyber-security companies, banks, telecommunications operators, consultancies, infrastructure providers, and insurers.
European participation gives the initiative a direct regional policy and infrastructure dimension. Arm, BBVA, Capgemini, Darktrace, Deutsche Telekom, Nationwide Building Society, SAP, Snyk, Sophos, and Zurich Insurance are among the organisations attached to the letter, representing technology estates that reach across networks, enterprise software, financial services, and critical infrastructure.
The coalition expects AI-enabled attacks to become more widespread and sophisticated as models develop stronger cyber capabilities. Its recommendations nevertheless begin with vulnerabilities that are already familiar across enterprise and public-sector technology: unpatched software, excessive permissions, weak authentication, misconfiguration, ageing equipment, and accumulated technical debt.
AI can make old weaknesses cheaper to exploit
Automation changes the economics of those vulnerabilities because work that previously required scarce specialist expertise can be repeated faster across a larger number of targets. Models capable of analysing code, examining configuration, developing exploits, or adapting after encountering defensive controls could allow smaller groups to pursue more systems simultaneously even when the underlying weakness has been known for years.
The same capabilities can assist defenders. The signatories want organisations to use lower-cost models across broad security workloads while reserving more capable systems for difficult tasks such as finding dangerous vulnerabilities, validating fixes, examining software, and testing whether controls remain effective.
Distribution is the harder problem because many organisations operating consequential infrastructure do not have large internal security teams or easy access to frontier models. Hospitals, water utilities, public bodies, manufacturers, and other essential-service providers can depend on older technology that cannot be patched quickly without interrupting physical operations.
The letter therefore calls on security companies, technology suppliers, and AI laboratories to provide practical support rather than simply expose models through ordinary commercial interfaces. Where systems cannot be patched, organisations need verified compensating controls; where suppliers maintain vulnerable products, the coalition wants stronger work through supply chains to develop fixes and usable interim guidance.
Trusted access creates a policy trade-off
One of the more consequential proposals concerns access to powerful models. Governments are being asked to expand trusted programmes giving vetted defenders, particularly those protecting critical-infrastructure supply chains, access to capabilities that might otherwise be restricted because the same models can also assist offensive cyber activity.
The trade-off is becoming central to frontier-model security policy. Restricting capable systems can reduce the number of people able to misuse them, while tight restrictions can also prevent legitimate researchers and under-resourced defenders from using the strongest tools available against attackers that may obtain comparable capabilities elsewhere.
The coalition is not proposing unrestricted access. Its recommendations include responsible model access, authorised testing, observability, traceable identities for AI agents, private vulnerability disclosure, and cooperation with governments and trusted security providers. Defensive capability would therefore be broadened within a framework intended to preserve accountability over who can use the strongest cyber functions.
European organisations face that debate alongside expanding requirements around AI governance and cyber resilience. Companies are being expected both to control risks associated with advanced AI and to improve security across supply chains, legacy systems, and essential services, leaving regulators to judge when access to more capable models reduces net risk rather than creating another powerful system that itself requires protection.
Suppliers are being asked to carry more responsibility
The recommendations do not treat cyber defence solely as a problem for the organisation under attack. Technology partners are asked to harden products, share tested playbooks, help infrastructure operators deploy AI-enabled protection, and measure progress through practical outcomes such as faster containment and verified remediation.
Frontier AI companies are asked to contribute model access, technical expertise, training, monitoring tools, and funding, placing part of the burden on the businesses developing capabilities expected to alter the threat environment. Governments receive a parallel role in supporting under-resourced essential services, coordinating intelligence, strengthening international response, and imposing costs on attackers.
Conflicts of interest remain. AI companies have commercial incentives to demonstrate defensive value, cyber-security vendors benefit from higher security spending, and governments may hesitate to distribute capabilities they believe can be repurposed offensively. The breadth of the signatory list nevertheless shows that concern over AI-enabled cyber operations now extends considerably beyond the companies training frontier models.
The near-term consequence for organisations is less dramatic than an autonomous hacking system suddenly defeating every defensive control. Existing security debt becomes more costly when attackers can inspect more targets, automate reconnaissance, adapt code, and repeat techniques at lower marginal cost. Unsupported equipment, weak access controls, poorly governed AI-generated code, and unresolved vulnerabilities provide the material on which that automation can operate.
The coalition also pushes the issue into procurement by calling for stronger security in the technology organisations buy, build, and deploy, including software generated with AI assistance. Productivity gains from automated development cannot be separated from the security properties of the code that subsequently enters production.
The open letter is a set of commitments and recommendations rather than a binding international programme, and signatories have not promised identical spending, access schemes, or disclosure practices. Its practical value will depend on how many turn a common warning into shared infrastructure, verified fixes, and support for operators unable to build frontier-level security capability themselves.
If capable AI reduces the labour required to exploit ordinary weaknesses, years of accumulated technical debt become a larger liability rather than a static one. The defensive opportunity is to apply comparable automation to finding and repairing those weaknesses first, leaving companies and public bodies with a familiar security task under much greater pressure to execute it.












