More than 100 major technology and financial companies are calling for a rapid defensive response to the growing threat of AI-driven cyberattacks, warning that increasingly capable artificial intelligence could change the speed and scale of hacking.
The companies, including OpenAI, Anthropic, Microsoft, Alphabet and Amazon, issued a joint letter urging governments and businesses to strengthen cyber defences before AI-powered attacks become more widespread.
The coalition said the rapid development of AI creates a limited window in which organisations can improve their defensive capabilities and prepare for increasingly sophisticated cyber threats.
How AI Is Changing Cyberattacks
Traditional cyberattacks often require attackers to spend considerable time researching targets, identifying vulnerabilities, developing code and determining how to move through compromised systems.
AI can potentially accelerate several of these activities.
Large language models can analyse information, generate code and assist with complex technical tasks.
As these models become more capable, malicious actors may be able to automate portions of cyber operations that previously required considerable time or specialist expertise.
That could make sophisticated attacks cheaper and easier to scale.
The threat is no longer purely theoretical.
Reports indicate that malicious actors are already experimenting with large language models to support attempts to compromise organisations.
This has made AI both a defensive technology and an emerging offensive capability in cybersecurity.
More Than 100 Companies Join the Call
The coalition behind the warning extends well beyond AI companies.
Participants include organisations from financial services, cloud computing, cybersecurity, manufacturing and digital payments.
Companies such as Broadcom, Capital One, Cloudflare, CrowdStrike, General Motors, IBM, Mastercard, Oracle, Robinhood, Shopify and Visa are among those associated with the initiative.
The diversity of the participants highlights the breadth of the potential threat.
Modern businesses rely on interconnected digital systems, meaning an attack against one organisation can potentially affect suppliers, customers and business partners.
What the Companies Want Governments to Do
One of the central requests is for governments to accelerate trusted-access programmes that allow vetted organisations to use advanced AI models.
The companies argue that cybersecurity defenders need access to powerful AI capabilities if attackers are going to gain access to similar technologies.
Advanced AI could help security researchers identify vulnerabilities, analyse threats, develop defensive tools and respond to incidents more rapidly.
Providing trusted organisations with early access could therefore help defenders stay ahead of malicious users.
The companies also urged organisations to make cybersecurity an immediate leadership priority rather than treating it solely as an IT function.
Cybersecurity Is Becoming a Board-Level Issue
AI-driven attacks could potentially have consequences far beyond a company's technology department.
A serious cyber incident can affect operations, customer data, finances, supply chains and corporate reputation.
If AI makes attacks faster or more scalable, the potential business impact could increase.
That means CEOs, boards and senior executives may need to treat AI-related cyber risk as a strategic business issue.
Companies may need to reassess cybersecurity budgets, staffing, threat-monitoring systems and incident-response capabilities.
AI Could Also Defend Against AI
The same technology that can help attackers can also strengthen defenders.
Security teams can use AI to process huge amounts of network data, identify suspicious activity, detect vulnerabilities and prioritise threats.
AI can also help analysts understand an incident more quickly and determine which systems may have been compromised.
This creates an emerging AI-versus-AI competition in cybersecurity.
If attackers use AI to accelerate their operations, defenders will need equally fast systems capable of detecting and responding to threats.
The Five Eyes Concern
The technology industry's warning follows similar concerns raised by governments and intelligence agencies.
The Five Eyes intelligence alliance — comprising the United States, United Kingdom, Canada, Australia and New Zealand — has also warned that AI could fundamentally reshape cybersecurity.
The convergence of warnings from intelligence agencies and major technology companies indicates that AI-related cyber risk is increasingly being treated as a national-security issue.
Questions Around CISA
The warning also comes amid scrutiny of the resources available to the US government's main civilian cyber defence agency, the Cybersecurity and Infrastructure Security Agency (CISA).
Reuters has reported significant staffing and budget reductions at the agency under the Trump administration.
CISA and the White House did not immediately respond to requests for comment on the industry's joint letter.
The timing has added to concerns about whether governments have sufficient resources to deal with a rapidly evolving AI-driven threat environment.
Why Businesses Are Vulnerable
AI-driven hacking could affect virtually every sector that relies on digital infrastructure.
Banks control financial systems and valuable customer information.
Healthcare organisations store sensitive medical records.
Manufacturers operate increasingly connected industrial systems.
Retailers, telecommunications companies and cloud providers depend on complex digital networks.
A successful attack against one part of this ecosystem can have consequences beyond the original target.
AI could increase that risk if attackers are able to automate portions of their operations and target more organisations in less time.
The Race Between Attackers and Defenders
Cybersecurity could increasingly become a race between offensive and defensive AI.
Attackers may use AI to discover vulnerabilities and adapt their tactics.
Defenders can use AI to identify unusual activity, investigate incidents and close vulnerabilities.
The organisation that can process information and respond more quickly may gain an advantage.
That is why access to advanced AI models has become a central part of the industry's argument.
Defenders need powerful tools before malicious actors gain an overwhelming advantage.
Why Speed Matters
Traditional cybersecurity processes can take considerable time.
Analysts may need to examine logs, investigate suspicious behaviour, identify affected systems and determine how an attacker entered a network.
AI could potentially automate parts of that workflow.
This means defensive systems may increasingly need to operate at machine speed.
Human experts will still be essential, particularly when decisions involve significant financial, operational or safety consequences.
But AI could allow smaller security teams to analyse much larger amounts of information.
The Trusted-Access Challenge
Giving security researchers access to powerful AI models creates a difficult policy problem.
The same models that can help defenders understand vulnerabilities may also be misused by attackers.
Governments and AI developers therefore need mechanisms to distinguish legitimate security work from harmful activity.
Trusted-access programmes are one potential solution.
They can allow vetted organisations to use advanced systems while introducing additional oversight and controls.
The technology companies are urging governments to accelerate these efforts.
Is an AI Cyber Crisis Already Here?
The companies are not necessarily claiming that an unprecedented AI cyberattack is already underway.
Their concern is that the underlying capabilities are developing rapidly.
Waiting until attacks become widespread could leave organisations trying to upgrade their defenses after the threat has already changed.
The joint letter is therefore largely a call for preparation.
Strengthen defenses now, improve access to advanced defensive AI and make cybersecurity a strategic priority before the risk becomes significantly harder to manage.
AI as Both Threat and Defence
Artificial intelligence could become one of the most important technologies in cybersecurity.
It can potentially help attackers automate reconnaissance and technical tasks.
But it can also help defenders analyse threats, identify vulnerabilities and respond to incidents.
The key question is therefore not whether AI will be used in cybersecurity.
It already is.
The more important question is whether defensive capabilities can develop as quickly as offensive ones.
What Companies Need to Do
Businesses will increasingly need to incorporate AI into their cybersecurity strategies.
That includes strengthening identity and access controls, keeping software updated, protecting sensitive data, maintaining reliable backups and training employees.
Companies may also need to deploy AI-powered threat detection and automated response systems.
At the same time, organisations must ensure that their own use of AI does not introduce new vulnerabilities.
The Wider Economic Impact
The consequences of large-scale AI-assisted cyberattacks could extend beyond individual companies.
Disruption to financial systems, telecommunications networks, cloud infrastructure or industrial operations could have broader economic consequences.
This is why the technology industry's response focuses on collective defence.
No single company can protect the entire digital ecosystem on its own.
Governments, technology companies, cybersecurity providers and businesses will need to share information and coordinate their responses.
A New Era of Cybersecurity
Cybersecurity has repeatedly evolved as technology has changed.
The arrival of cloud computing, mobile devices and connected systems created new opportunities as well as new vulnerabilities.
AI could be different because it has the potential to automate parts of the reasoning involved in both attacks and defence.
That could alter the economics of cybercrime.
If sophisticated attacks become easier and cheaper to conduct, more organisations could become targets.
What Happens Next?
Governments will need to determine how quickly trusted-access programmes can be expanded and what safeguards should accompany them.
Businesses will need to decide how much to invest in AI-powered security tools.
Cybersecurity companies will need to develop systems capable of responding to increasingly automated attacks.
AI developers will also face continued pressure to prevent their models from being misused.
The technology industry's message is that all of these efforts need to move faster.
The Bottom Line
The joint warning from more than 100 major companies highlights a growing concern across the technology and business sectors: AI-powered cyber threats could develop faster than traditional defensive systems can adapt.
OpenAI, Anthropic, Microsoft, Alphabet and Amazon are among the companies calling for governments and businesses to strengthen cyber defences now rather than waiting for the threat to become more widespread.
Their recommendations include expanding trusted access to advanced AI models for vetted cybersecurity organisations and elevating cyber defence to a leadership-level priority.
The underlying message is clear.
AI is no longer simply an emerging technology issue for cybersecurity teams. It is becoming a strategic risk for governments, companies and the wider digital economy.
As AI systems become more capable, defensive capabilities will need to evolve just as quickly.
The coming period could therefore determine whether cybersecurity teams can maintain an advantage over increasingly AI-enabled attackers.












