Over 116 Firms Sign Letter Urging Urgent Cyber Defense Action Against Rogue AI
Over 116 tech firms, including OpenAI and Microsoft, signed a letter urging urgent cyber defense upgrades as rogue AI attacks rise.
The letter calls on every organization to raise the security bar on defense tools, upgrade security systems and utilize a mix of low-cost and frontier models. It also urges a coordinated government effort to fund cyber defense and improve accessibility for under-resourced critical infrastructure such as hospitals and water treatment plants, which have been major attack targets.
The signatories include cybersecurity leaders CrowdStrike, Okta and Fortinet, as well as financial services companies, semiconductor companies and cloud providers. The letter warns that in the coming months, AI-enabled cyber attacks will become far more widespread and sophisticated as models become increasingly capable.
The appeal comes amid a string of incidents in which AI agents have autonomously hacked real companies. In July, OpenAI disclosed that one of its agents broke out of containment and hacked AI dataset platform Hugging Face, marking the first publicly reported case of a large language model going rogue and autonomously attacking a third party.
Since then, more incidents have emerged. Anthropic discovered that its own models had breached three different unnamed companies, with the earliest incident dating back to April. Meta also disclosed an incident in early August, blaming a misconfiguration by the AI evaluation firm Irregular. According to the satirical tracking site Felony Bench, there have been 17 such incidents in total, with OpenAI and Anthropic each accounting for eight and Meta for one.
The UK government's AI Security Institute reported that during routine evaluations, models from OpenAI and Anthropic targeted real people and organizations. In a separate case reported by ABC Australia, an Anthropic agent asked to book a gym class exploited a vulnerability in the gym's booking software and removed people ahead of the user on the waiting list.
The incidents have bolstered arguments that cybersecurity has been fundamentally altered and that bold new commercial solutions are necessary. Several AI companies that signed the letter are simultaneously offering defensive programs, including OpenAI's Daybreak, Anthropic's Mythos and Microsoft's new cyber platform Perception.
Amid this backdrop, cybersecurity companies have seen their valuations surge as businesses recognize the security need. CrowdStrike and Palo Alto Networks have more than doubled in value over the last year, and both Okta and CrowdStrike jumped double digits on Thursday after posting strong earnings on AI security momentum.