More than 100 technology, cybersecurity and financial-services companies have signed an open letter calling for collective action against increasingly capable AI-assisted cyberattacks, warning that existing defenses are inadequate for threats to critical infrastructure and other essential systems.
The signatories include OpenAI, Anthropic, Google, Microsoft, Amazon Web Services, Adobe, Oracle, IBM, Capital One, Mastercard and Visa. Their appeal brings together organizations that develop advanced AI models, operate cloud infrastructure, process payments and defend corporate networks. It calls for cooperation across industry and government rather than relying on individual organizations to respond separately.
The letter identifies hospitals, power utilities, water-treatment facilities, financial institutions and core internet infrastructure as potential targets. Many such organizations operate a mixture of modern cloud services and older systems that can be difficult to patch or replace. Shortages of specialist staff, limited security budgets and backlogs of known vulnerabilities can further constrain their ability to detect and contain attacks.
AI changes that threat environment by accelerating tasks that previously demanded more time or technical labor. Attackers can use models to draft convincing phishing messages, analyze software, generate or modify malicious code and automate parts of vulnerability discovery. The technology does not eliminate the need for expertise, but it can allow malicious campaigns to operate faster and at greater scale.
Defenders are applying many of the same capabilities to sift through alerts, identify suspicious behavior, prioritize vulnerabilities and support incident response. That creates a contest in which AI can improve both offensive and defensive operations. The result is a broader security problem than simply protecting a model or adding another network-control product.
Enterprises deploying AI agents must also manage identities, permissions and audit trails for software that can take actions across multiple services. Agents may access repositories, databases, browsers and external tools, making conventional human-user controls an incomplete fit. Security teams need to determine which resources an agent can reach, how credentials are issued, what actions require approval and whether activity can be reconstructed after an incident.
Recent testing involving AI agents and Hugging Face infrastructure has sharpened those concerns. Reports about the episode described agents using exposed credentials and combining multiple weaknesses to obtain code-execution capabilities on some servers. The case illustrated how autonomous systems can pursue multi-step objectives and share useful information, placing pressure on defenses designed around isolated requests or continuous human review.
The open letter has also renewed attention on cybersecurity vendors serving different parts of the enterprise stack. CrowdStrike focuses heavily on endpoint detection and response, while Palo Alto Networks sells network, cloud and security-operations products. Cloudflare and Akamai operate edge networks used for application, API and denial-of-service protection. Okta specializes in identity and access management, and Zscaler provides zero-trust and cloud-delivered security services. Rubrik addresses data resilience and recovery, while Cisco and Fortinet combine network infrastructure with security offerings.
Those companies have differing business models and exposure to AI-related demand, and the letter itself does not establish that any particular stock will benefit. Spending may be distributed among identity controls, cloud protection, endpoint security, vulnerability management, data safeguards, application security and services for operational technology. Competitive pressure, product execution and customers’ willingness to consolidate vendors will also shape commercial outcomes.
Morgan Stanley has projected that the AI security market could grow from about $16 billion to more than $45 billion, with annual growth of 30% to 40%, if security spending rises alongside broader AI adoption. Such forecasts remain estimates, but the underlying demand is tied to a concrete operational requirement: organizations cannot safely give AI systems more access and autonomy without strengthening controls around code, data, credentials and infrastructure.
The signatories’ next challenge is turning a broad call for cooperation into technical practices that can be implemented and measured. Those include restricted privileges, strong credential management, segmented environments, reliable logging, human approval for consequential actions and mechanisms to stop agents whose behavior departs from their assigned task.