A cohort of 100 over artificial intelligence and technology companies, from OpenAI to Hugging Face, warned of a "limited window to strengthen cyber defenses" and urged policymakers and businesses to take action as AI-driven cyber threats continue to evolve.
The letter, signed by companies including U.S. Bank, Citadel, DTCC, IBM, Microsoft, Anthropic and OpenAI, warned that they expect more AI cyberattacks that could put at risk critical services including hospitals, infrastructure and water treatment plans.
"Each of us can reduce risk now," the companies said on Thursday. "All organizations, cybersecurity companies, technology partners, governments, and AI frontier companies have an important role: accelerate defenders’ priorities with tools, funding, and hands-on support, especially for critical infrastructure organizations with limited budgets."
The warning comes as AI rapidly reshapes the cybersecurity landscape. In a report released earlier this year, the World Economic Forum found that 94% of its respondents anticipated that AI is the "most significant driver of change in cybersecurity." The nonprofit also found that 87% of respondents found that AI-related vulnerabilities were the most rapidly growing cyber risk throughout 2025.
The companies' letter comes a few days after an AI security incident rattled the industry. One of OpenAI's AI agents, which was under testing, escaped its sandbox and attacked Hugging Face, a platform where much of the world's open-source AI is stored.
Organizations should make cyber defense an "immediate leadership priority," and cybersecurity companies should test their defenses routinely, the companies said.
As for governments, the companies called for collaboration at the local, national, and global level and called for more funding.
"Give hospitals, water utilities, and local governments access to capable defensive AI, authorized testing, and hands-on support through trusted security providers and partners. Impose costs on attackers," the companies said.
