BlackTree Security · Infrastructure · Automation · AI

130 Tech Companies Say We Have Months to Prepare. Their Letter Includes No Deadlines

More than 130 technology, cybersecurity, finance and infrastructure organisations have backed an OpenAI-led call for a global surge in cyber defence. The letter warns that AI-enabled attacks will become far more widespread and sophisticated in the coming months. It contains strong principles, but no binding deadlines or minimum investment commitments.

Signatories include OpenAI, Anthropic, Microsoft, Google, AWS, Cisco, Cloudflare, CrowdStrike, banks, payment firms and critical-infrastructure suppliers. The breadth makes the warning difficult to dismiss. It also makes accountability harder when every organisation can endorse the same goal without accepting the same obligation.

The letter says the window is measured in months

The signatories argue that hospitals, water-treatment plants and internet infrastructure face growing risk as models around the world gain stronger cyber capabilities. They describe a limited window in which defenders can use the same advances to fix long-standing weaknesses before attack capacity spreads more widely.

The letter calls out technical debt, excessive permissions, weak authentication, insecure and unpatched software and chronic under-resourcing. None of those problems is new. AI increases the speed at which attackers can find and exploit the backlog.

Four groups receive four sets of responsibilities

Every organisation is asked to make cyber defence a leadership priority, fix the highest-risk weaknesses and verify the results. Cybersecurity companies and technology partners are asked to strengthen tools with AI, test continuously and help critical-infrastructure operators deploy defences.

Governments are asked to fund defence, expand trusted-access programmes, share intelligence and impose costs on attackers. Frontier AI companies are asked to provide responsible model access, significant funding, training, observability and hands-on support.

These are useful directions. The letter does not specify how much funding qualifies as significant, which organisations must receive help first or when signatories will report progress.

Voluntary alignment is not an implementation plan

An open letter can create political and market pressure. It can also establish common language for programmes that already exist. What it cannot do alone is patch a hospital, segment a water plant or give a local government enough staff to respond.

The absence of deadlines matters because the warning itself is time-bound. If the expected capability shift is months away, the response needs milestones measured in weeks, not general commitments measured in intention.

What meaningful follow-through would look like

  • Public funding totals and eligibility rules for under-resourced critical-infrastructure defenders.
  • Named programmes that deliver tools, staff and verified remediation rather than model access alone.
  • Deadlines for identity, patching and segmentation improvements in high-consequence environments.
  • Independent reporting on how many organisations received help and whether fixes worked.
  • Clear safeguards and auditability for agentic identities used in defensive systems.
  • Shared playbooks and machine-readable threat intelligence that smaller teams can use.
  • Disclosure of where AI-generated code or remediation introduced new defects.

The danger of a defence gap

Large signatories can hire experts and integrate frontier models quickly. The hospitals, municipalities and utilities named in the letter often cannot. If capability is distributed faster than safe deployment support, the organisations facing the greatest consequences may receive the least benefit.

That is why hands-on assistance and verified fixes matter more than access announcements. A model can suggest a firewall rule. Someone still has to understand the plant, test the change and own the risk.

The BlackTree view

The letter’s urgency is credible. Its accountability is incomplete.

A coalition this broad can change defender capacity if it publishes resources, deadlines and measured outcomes. Without them, the document risks becoming a warning signed by the companies best positioned to know the danger but least required to prove what they did about it.

Sources

Leave a Reply

Your email address will not be published. Required fields are marked *