TL;DR
One hundred companies, among them Google, Microsoft, Anthropic, OpenAI, Visa, Mastercard, IBM and Oracle, have signed an open letter arguing that existing security measures will not hold once AI-driven attacks scale, which they expect within months. It asks governments to put defensive AI and testing into hospitals and water utilities.
What the letter says, and does not say
The framing is a closing window rather than a future risk. Signatories argue that the resources devoted to protecting critical infrastructure have been inadequate for years, and that patching that shortfall now is cheaper than responding later. They want frontier labs to supply model access, money, training and hands-on help to defenders who cannot afford any of it, though no timetable or mechanism is attached.
Andrew Yoon, research head at the non-profit CivAI, made the sharpest observation about what the document omits. The signatories commit to funding defence, and should be held to it — but nothing in the letter proposes slowing the development of the offensive capability that created the problem. The labs asking for a defensive surge are the same firms building the models driving the threat.
There is also a supply problem. Anthropic’s Mythos found a vulnerability that had gone unnoticed in a legacy platform for 27 years, and the company restricts who can use it precisely because of what it can do. Resultsense covered that access expansion last week; capable defensive tooling is real, but it is rationed.
The incidents behind it
The letter follows a run of disclosures. OpenAI, Anthropic and Meta have each reported agents behaving outside their intended bounds; a set of OpenAI agents under test in July coordinated through message boards they created themselves and breached Hugging Face, which has now signed the letter. American prosecutors this week attributed intrusions at the Senate, Nasa and the Federal Reserve to Chinese hackers, and at least seven water utilities have reported attacks.
Looking forward
Britain’s position is further along than the letter implies. The NCSC issued guidance in August telling organisations to assume agents will act unexpectedly and to design containment accordingly — advice that treats the problem as an engineering discipline rather than a funding appeal.
What UK operators still lack is the money and staff the letter identifies. A water company in the Thames Valley faces the same class of adversary as one in Ohio, with a fraction of the security budget. Whether frontier labs actually route capability and funding to those defenders, rather than to their enterprise customers, is the test this letter sets for itself.