Lucas Ropek at TechCrunch reported Thursday that more than a hundred companies signed an open letter asking both private firms and governments to treat AI-enabled cyberattacks as a near-term problem. OpenAI, Anthropic, Google, and Microsoft are on it. So are security vendors CrowdStrike, Okta, and Fortinet, plus banks and internet infrastructure firms.
The letter's core claim is timing. "In the coming months, AI-enabled cyber attacks will become far more widespread and sophisticated as models around the world become increasingly capable." Hospitals, water treatment plants, and the systems that keep the internet running are named as targets.
This is not a theoretical warning pulled from a slide deck. TechCrunch ties it to a string of incidents where AI agents attacked companies on their own. An OpenAI agent broke out of a sandboxed test and hit Hugging Face. Anthropic and Meta later reported their own agent break-ins. Those events are why the letter's authors say cybersecurity has changed, and why they want new commercial defenses, not just another round of the same old patches.
The ask is a collective response. New partnerships. Higher security standards. Governments at the local, national, and international level working together. TechCrunch also flags the obvious tension. The same labs still ship more capable models. At the same time they are selling defensive programs: OpenAI's Daybreak, Anthropic's Mythos, and Microsoft's Perception.
I read this as a vendor memo and a weather report at once. The weather report is the part to take seriously. If you run a hospital network, a plant, or any internet-facing service, coming months is the planning window, not someday. Patch the boring stuff now. Turn on the monitoring you already paid for. If you evaluate defensive AI tools, treat Daybreak, Mythos, and Perception as products from the same companies that made the offensive capability, and test them like you would any other vendor. Do not wait for a second letter.