Google, Microsoft and 100 Firms Warn on AI Cyber Threats

A padlock symbol over computer equipment, marking the joint cyber defence warning

More than a hundred technology companies, Google and Microsoft among them, signed an open letter on Thursday asking the rest of the world to fix its cyber defences before artificial intelligence gets good enough to breach them. The letter is unusual in who signed it and still more unusual in what it says: that the current status quo of security simply will not be enough.

Among the 116 signatories are the frontier AI labs OpenAI and Anthropic, security vendors including CrowdStrike, Okta and Fortinet, chipmakers, banks and firms that run internet infrastructure, according to coverage by the BBC and TechCrunch. The message to hospitals, energy operators, water companies and everyone else who keeps society running is direct: there is a limited window to improve, and it is measured in months rather than years.

The concern rests on something the signatories have front-row seats to. AI models have become startlingly capable at finding and exploiting software flaws, and the labs signing the letter can see where their own systems are heading. The letter warns that AI-driven attacks will grow both more widespread and more sophisticated very quickly, and it criticises the historic under-resourcing of security around critical infrastructure, which is a diplomatic way of saying that the hospitals and water treatment plants under attack cannot afford the tools the attackers now have.

So what do the companies actually want? Three broad asks. Governments at local, national and international levels should coordinate and fund defence rather than leaving it to individual institutions. Organisations should raise the security bar now: upgrade systems, adopt better tools, and use a mix of inexpensive and frontier models to test their own defences. And the private sector should form new partnerships to respond collectively when something breaks, the way swat teams work in outbreaks.

This is not abstract. The letter follows a season of incidents where AI agents were involved in real intrusions, including the episode, reported widely this month, in which an OpenAI model conducting security testing escaped its sandbox and hacked the platform Hugging Face. That incident reshaped the conversation inside the labs, and the joint letter is partly the result: rivals agreeing publicly that the technology they compete over poses a shared problem.

For British critical infrastructure the practical question is money and people. The NHS trusts, regional water firms and energy networks that would be prime targets run security teams many times smaller than the ones signing this letter, and they buy software the way anyone else does, out of annual budgets. The letter’s call for coordinated government funding of cyber defence is pointed at exactly that gap. A house call from the AI industry is easy to ignore. A joint one is a headline.

The clock part deserves some scepticism too. Every technology wave has produced warnings measured in months, and the defenders usually improve alongside the attackers because the same models sell to both sides. The signatories have an interest in urgency that they are not entirely immune to. But when the people building the capabilities say the defences are behind, betting against them is a strange thing for a water board to do.

Share Article
Facebook
LinkedIn
X
Branson Blames Flight Price Rises on Foolish Leaders as Fuel Costs Squeeze Airlines
Hundreds of North Sea Workers Remain Above Weight Limit Two Months Before Helicopter Rules Bite
Uber Launches Britain's First Robotaxi Service in London Using Wayve Technology
Secret Link