Last week, OpenAI and Anthropic signed the same letter. So did Microsoft, Google, AWS, CrowdStrike, Palo Alto Networks, Mastercard, Visa, AT&T, and more than a hundred other organizations.
The letter, A Call for Collective Action on Cyber Defense, says AI-enabled cyber attacks “will become far more widespread and sophisticated” in the coming months, and that defenders have “a limited window” to get ready.
Competitors who agree on almost nothing agreed on this.
Treat that the way you would treat a hurricane forecast that every model converges on. Not as a vendor pitch. As a signal.
What the letter actually says
The threat is speed and access. AI models are cutting the time and skill an attacker needs to find a vulnerability, build a working exploit, and use it. Axios reported that an AI-generated exploitation script has already been used against U.S. water systems.
The letter’s diagnosis is blunt: “Status quo security won’t be enough.” It names the exposure most organizations already know they carry: “Longstanding bugs, excessive permissions, misconfigurations, insecure and unpatched software, weak authentication, and technical debt in legacy systems.”
The asks are familiar. Treat cyber defense as a leadership priority with “incident-response intensity.” Fix the highest-risk vulnerabilities first and verify the fixes. Raise the security bar on everything you buy, build, or deploy, including AI-generated code. Apply compensating controls where you cannot patch.
None of this is new advice. What is new is who is saying it, how loudly, and how short they say the window is.
What the letter leaves out
This is a prevention letter, written by security and AI companies for security teams. Nearly every recommendation is about keeping attackers out. Response and recovery get a passing mention.
Nobody signed on behalf of your crisis management team.
That matters because the letter’s own premise undercuts a prevention-only strategy. If AI collapses exploitation timelines from weeks to hours, some attacks will land before your patch cycle catches up. The signatories say as much. When that happens, the binding constraint is no longer your security tooling. It is how fast your organization can decide, communicate, and recover under pressure.
Speed of response becomes the control.
| Old View | New View |
| AI-enabled cyber attacks are a security team problem | They are a leadership decision problem that the security team surfaces |
| The patch cycle is the clock | The attacker’s exploitation timeline is the clock |
| Incident response is measured in days | Decisions must be made in hours, and sustained for weeks |
We have already run this scenario
In August, we facilitated the first commercial AI-accelerated vulnerability storm exercise for a healthcare technology company.
The scenario: a fictional AI model discovers concurrent zero-day vulnerabilities, and exploitation begins within four hours of disclosure. Three moves across ten simulated days. Twenty-seven participants from technical, security, business, and support functions.
What broke was not the security stack.
Standard patching windows could not keep pace with exploitation. No one held clear authority to take production-impacting emergency action. Escalation processes had never been tested at that tempo.
The full AI Storm case study walks through what we found and what the client did about it.
Going in, the CISO’s biggest concern was not the tooling. It was whether the people could sustain the pace over an extended period. That concern was right, and the open letter does not address it anywhere.
Five moves to make while the window is open
- Fix the boring stuff, and make it a leadership item. The letter’s list is your list: unpatched software, excessive permissions, weak authentication, legacy systems nobody wants to touch. Ask your CISO for the inventory of high-risk vulnerabilities and the systems that cannot be patched. Put compensating controls and a date next to each one. Ask the same question of your cloud provider, your MSSP, and every critical SaaS vendor. The letter tells them to raise their standards too. Hold them to it.
- Pre-decide authority. Who can take a customer-facing system offline at 2 a.m. without convening a meeting? Who authorizes an emergency change that skips the normal approval path? Who calls the regulator, the board, the top ten customers? At AI speed there is no time to work this out live. Write it down now, get it signed, and make sure the people holding the authority know they hold it.
- Exercise at AI speed. Most cyber tabletops run on a timeline of days. Run one where exploitation starts four hours after disclosure and the second vulnerability drops before you have contained the first. That is the exercise that shows you whether your escalation criteria, activation thresholds, and decision rights work under compression. Our AI crisis exercises are built for exactly this.
- Plan for a marathon, not a sprint. A vulnerability storm is not a single incident. It is a sustained campaign that can run for weeks. Your incident commanders, engineers, and communicators will burn out on day three if you have not planned shifts, rest, backfill, and surge support. The people problem is the one every technical plan skips.
- Validate recovery, do not assume it. In more than one exercise this year, the honest post-exercise answer to “how fast can we recover, and in what order?” was “we do not know.” Test your restores. Map your dependencies. Know which systems you can patch without a reboot and which you cannot. And establish out-of-band communications now, because during a real event you should assume your primary environment is compromised or unavailable.
The window is the point
Months of warning is a gift most crises never give you. The companies that signed this letter are spending theirs hardening the systems they build and sell.
Spend yours making sure your organization can lead through the attack that gets past them.
Keep Going
A few ways to go deeper if this was useful.
- Read more. Resilience, crisis management, and continuity writing at Bryghtpath Insights, or the structured Ultimate Guide to Crisis Management.
- Run the AI Storm exercise. Our AI Crisis Exercises test your leadership team against vulnerability storms, deepfakes, AI system failures, and AI vendor incidents at machine speed.
- Get a maturity score. Our Resiliency Diagnosis® is a standards-based review that produces a maturity score and a prioritized roadmap.
- Talk to us. Set up a call to think through your program with us.


A Return-to-Office Mandate Is a Tell About Your Leadership, Not Your Strategy