We have a limited window to strengthen cyber defenses.
In the coming months, AI-enabled cyber attacks will become far more widespread and sophisticated as models around the world become increasingly capable. The companies and public services our communities depend on — from hospitals to water treatment plants to the infrastructure that powers the internet — are at risk.
Today’s AI advances are already giving defenders new ways to fix weaknesses that have accumulated for years. If we act decisively, we can use the defenders’ window to make our digital world much more secure.
We propose the following principles for a collective response:
Recognize that status quo security won’t be enough. Longstanding bugs, excessive permissions, misconfigurations, insecure and unpatched software, weak authentication, and technical debt in legacy systems have left systems exposed. Security teams, particularly for critical infrastructure, have been historically under-resourced and need a surge in tools and resources.
Empower more defenders with cyber-capable AI. AI brings specialist skills to more defenders and makes core security tasks faster, cheaper and better. Sharing tools, practical knowledge, and verified fixes lets one organization’s work help protect many others.
Mobilize a collective response. Cyber capabilities are advancing worldwide, and that can be a net positive: no single company should control the future. It also means a global response is necessary, requiring new partnerships to raise security standards and find new solutions to emerging cyber threats.
Each of us can reduce risk now. All organizations, cybersecurity companies, technology partners, governments, and AI frontier companies have an important role: accelerate defenders’ priorities with tools, funding, and hands-on support, especially for critical infrastructure organizations with limited budgets.
Here’s what we think needs to happen next:
01 Every organization
Make cyber defense an immediate leadership priority. Raise your security standards and meet them with the urgency and coordination of an incident that takes precedence over everything except critical business operations. Fix the highest-risk weaknesses, verify results without disrupting essential services, and raise the security bar for what you buy, build, and deploy, including AI-generated code. Upgrade or replace systems to build in least privilege, strong access controls, and defense in depth. Use capable, lower-cost models for broad coverage, and apply frontier capabilities to the hardest problems. Where a system cannot be patched without disrupting essential services, apply and verify compensating controls.
