OpenAI, Anthropic, Google, Microsoft and more than 100 others say AI is about to widen the gap between attackers and understaffed defenders.
More than 100 companies, including model builders OpenAI and Anthropic, hyperscalers Google and Microsoft, and cybersecurity vendors that usually compete with each other, have signed the same open letter warning that AI-powered cyberattacks are about to scale within months. The first sentence of the letter frames the timing as months, not years, and names the systems most exposed: hospitals, water treatment plants, and the internet's core infrastructure.
The unusual part is not the warning. It is who is signing. The letter pulls together direct competitors across the AI stack: model developers (the companies that build the AI), hyperscalers (the cloud giants that host the workloads), and cybersecurity vendors (the firms that sell the defensive tools). Coverage from the BBC, Engadget, and Gizmodo all flag the same coalition breadth. When companies that usually sue each other over model weights, cloud contracts, and security pricing put their names on the same page, the signal is that the threat looks bigger than any of their competitive differences.
The mechanism the letter actually argues is not a novel AI malware class. It is AI as a productivity tool for attackers. Software vulnerabilities (the bugs that let attackers break into systems) have always existed in greater supply than defenders can patch. A junior attacker today has to read technical writeups, write probe scripts, and sift through noisy results. A language model can draft the probe, summarize the writeup, and rank the next target, which compresses a day of reconnaissance into minutes. The letter's core claim is that the existing attack surface (the full set of systems an attacker can try to break into) gets more expensive to defend, not because new holes appear, but because the cost of finding and using old ones drops.
That asymmetry is the months-scale claim. Defenders hire, train, and patch on a human timeline. Attackers using AI to automate reconnaissance and exploit prototyping can move on a software timeline. The letter does not need AI to invent new attacks for the gap to widen. It needs AI to keep doing the existing attack steps faster, against organizations that were already running behind.
The named targets matter because they are where the cost of a successful attack lands outside any single company. Hospitals run a mix of legacy medical devices and thin IT teams; a ransomware incident (where attackers lock a system and demand payment to restore it) on a hospital can delay surgeries. Water treatment plants operate critical infrastructure under tight margins and tight staff. The internet's routing layer (the global system that decides how data gets from one computer to another) sits on a small number of large providers whose downtime cascades into email, banking, and emergency services. Smaller institutions without large security budgets are singled out by the letter as the group least able to keep up with automated attacker speed, which is also the group the public most relies on for everyday services.
The coalition's recommendations track the mechanism. Stronger baseline security standards raise the floor across the named sectors. Wider access to defensive AI tools gives the smaller defenders the same productivity gain the attackers are about to get. Tougher rules around AI-generated code, both the code the attackers write and the code defenders increasingly ship into their own systems, target the supply side of the vulnerability pipeline.
The natural counterargument is real. Defenders also have AI tools, and many of the signatories sell them. The letter engages that by conceding the gap: the recommendations only close the asymmetry if procurement (the process of buying and deploying new tools inside an organization) and standards move faster than attacker economics. Months is a tight window for hospitals and water utilities, where budget cycles run on years and security headcount is rationed.
The piece to watch is whether the coalition's signatory list grows or shrinks as the next round of public AI cyber incidents lands. The letter is a coordination artifact, and coordination artifacts work only if the same names show up when specific policy fights begin.