Skip to content
Tech News
← Back to articles

Tech Companies Call for Improved Cyber Defenses After AI-Enabled Attacks

read original more articles
Why This Matters

The article highlights the urgent need for the tech industry and governments to strengthen cybersecurity defenses against increasingly sophisticated AI-enabled cyberattacks. As AI models become more capable of exploiting vulnerabilities, collective action and investment are crucial to protect infrastructure, data, and users from emerging threats. This call to action underscores the importance of proactive security measures in safeguarding the digital future.

Key Takeaways

Saying that the world has only a “limited window” to bolster its defense against widespread AI cyberattacks, OpenAI and more than 100 other companies issued a call Friday for businesses, governments and other institutions to act quickly to boost cybersecurity.

The open letter, titled “A call for collective action on cyber defense,” was signed by 128 companies, including some of the biggest players in the AI space, including Microsoft, Google, Anthropic and Oracle.

The letter warns that “AI-enabled cyberattacks will become far more widespread and sophisticated as models around the world become increasingly capable,” putting companies, governments and infrastructure at risk.

But there are “ways to fix weaknesses that have accumulated for years.” The letter says companies must invest much more in security teams to fix old bugs and other vulnerabilities, share their cyber-capable AI tools with other companies and mobilize globally and collectively to “raise security standards and find new solutions.”

The ‘nightmare’ is coming

AI agents have repeatedly made headlines this summer for wreaking havoc, whether intended or unintended. Models escaped an OpenAI test environment in which they weren’t supposed to access the open internet. They found a software vulnerability, exploited it and got online. Once there, hundreds of AI agents used stolen credentials, communicated with each other on makeshift message boards and eventually hacked into the AI platform Hugging Face.

Read more: AI Agents Are a Cybersecurity Nightmare That’s Only Just Begun

There have been more than a dozen major incidents over the past year. Anthropic’s AI models breached three unnamed companies. Meta’s AI hacked a “third-party service” earlier this month. A Claude AI agent hacked a gym in Australia to get its user into a gym class. The problem is that AI agents, trained on heaps of code, are great at finding software flaws and vulnerabilities and will keep plugging away until they complete their tasks.

‘Urgency and coordination’

In its open letter, OpenAI describes four broad steps that must be taken. All organizations — both private and public — should fix “highest-risk weaknesses,” only deploy highly secure AI-generated code and strengthen permission and access controls. Cybersecurity companies should strengthen defenses against AI attacks and help deploy them for critical infrastructure operations, such as water and utility systems. Governments at all levels need to invest more funds in cyber defense — especially for greatly underfunded departments — and “give hospitals, water utilities, and local governments access to capable defensive AI.”

... continue reading