A.I. News Tech companies write open letter calling for collective action against AI-enabled cyber attacks

Brownie2019

Level 23
Thread author
Verified
Well-known
Forum Veteran
Mar 9, 2019
1,093
5,978
2,168
Germany
The companies warn "status quo security won't be enough", as it calls for a "surge of tools and resources" to tackle AI cyber attacks.
More than 100 companies have written an open letter calling for collective action to strengthen cyber defences amid a rise in AI-enabled cyber attacks.

The companies, including tech heavyweights OpenAI, Anthropic, Google and Microsoft warn of a "limited window to strengthen cyber-defences", saying that the attacks "will become far more widespread and sophisticated as models from around the world become increasingly capable", putting companies and public services at risk.

The group says "status quo security won't be enough", adding that security teams have been historically under-resourced and "need a surge in tools and resources" to tackle AI cyber attacks.

It also calls for defenders to be "empowered" with cyber-capable AI, with specialist skills to help security teams protect organisations, as well as a global response to find new solutions to emerging cyber threats.
The letter called on organisations to make cyber defence an immediate leadership priority and for governments to coordinate cyber defence at local, national and international levels, including intelligence sharing and giving public services access to capable defensive AI.

It's also calling on cybersecurity companies to make AI-powered defence accessible for critical infrastructure, and for AI companies to provide model access and training for defenders.
The letter comes amid a rise in cyber attacks, including on Thursday when 8.7 million people's data held in three UK airports was stolen.
National Cybersecurity Centre head Richard Horne previously told Sky News AI models like Mythos are "warning shots" about the dangers of AI, saying new models were not finding new attacks, but instead "exposing more security vulnerabilities".

In June, the Five Eyes intelligence alliance - comprising the UK, US, Canada, Australia and New Zealand - issued a rare joint statement warning of swift action to remain ahead of AI-powered cyber risks, as it called for organisations to use AI to strengthen defences.

In July, OpenAI - the company behind ChatGPT - revealed that some of the models they were testing managed to escape containment and break into a firm called Hugging Face, a platform used to host open-source large language models and datasets.
 
The main concern is acceleration, not entirely new attack techniques

The warning is credible in principle: AI can reduce the time and expertise needed for reconnaissance, phishing, vulnerability research, social engineering, and adapting malicious code. That could increase the volume and speed of attacks even when the underlying weaknesses are familiar.

However, claims about specific AI models escaping containment or compromising platforms should be checked against the original company disclosures and independent reporting. A model operating in a controlled test environment is not automatically evidence of a widespread real-world attack capability. The exact permissions, safeguards, human involvement, and system weaknesses are important.

Practical defensive priorities

  • Maintain accurate asset inventories and rapidly patch internet-facing systems, especially known exploited vulnerabilities.
  • Require phishing-resistant multifactor authentication for administrators and other high-value accounts.
  • Use centralized logging, endpoint protection, network monitoring, and tested alert-response procedures.
  • Apply least privilege and restrict automated systems from accessing sensitive resources by default.
  • Treat AI-generated code, emails, reports, and security alerts as potentially useful but requiring human verification.
  • Test backups and incident-response plans regularly, including scenarios involving stolen credentials and data theft.
  • Share indicators and incident information through trusted industry or government channels without exposing unnecessary personal data.

AI can also improve detection, triage, vulnerability remediation, and defensive analysis, but it introduces risks such as false positives, over-automation, data leakage, and excessive trust in generated recommendations. Defensive AI should therefore operate with narrowly defined permissions, audit logging, approval controls, and a straightforward way to disable it.

The most useful interpretation of the letter is that organisations should improve basic security and incident readiness now, while also preparing for faster and more scalable attacks. AI is likely to amplify existing security weaknesses; it does not remove the need for sound identity, patching, monitoring, access-control, and recovery practices.