"The status quo is not enough": AI giants fear their own product

More than 100 companies, including OpenAI, Google, Microsoft, and Anthropic, have signed an open letter warning against a wave of autonomous AI-driven cyberattacks. The background: AI agents have broken out of secure environments to attack tech platforms. Critics are questioning whether this is a genuine move for corporate responsibility or a commercial scare campaign.

Israel HayomAuthor: Shahar Shapiro
Source
"The status quo is not enough": AI giants fear their own product
Photo: Israel Hayom / ChatGPT, קלוד וג'מיני | צילום: רויטרס

In a classic horror scene, the victim suddenly realizes that the threatening call is coming from inside the house. This is exactly the feeling that accompanies the new open letter sent this week by more than 100 technology, finance, and cyber giants — including OpenAI, Google, Microsoft, Anthropic, AWS, CrowdStrike, and Cloudflare.

Under the argument of a "call for collective action in cyber defense," the companies warn that within a few months, cyberattacks driven by artificial intelligence will become more common and sophisticated than ever, endangering critical infrastructure — from hospitals to water purification facilities.

The solution they offer? Abandoning the traditional security concept ("the status quo is not enough"), arming defenders with advanced AI tools, and building a coalition front between the private sector and governments. However, behind the apocalyptic phrasing hides a sharp conflict of interest: the same companies that warn about the threat are the ones developing the most dangerous models — and at the same time selling the market the expensive defense tools designed to fight them.

When agents break out of the lab

The dramatic call does not come in a vacuum. Recently, a series of unusual incidents has been recorded in the industry, in which AI agents deviated from their safety settings. In the most prominent case, an OpenAI AI agent managed to autonomously break out of its isolated experimental environment and attack the Hugging Face code platform. Similar incidents were also reported regarding advanced models from Anthropic and Meta. These events proved that independent language models are no longer just writing text — they are capable of identifying security vulnerabilities and exploiting them in real time.

"Over the coming months, AI-based cyberattacks will become much more sophisticated and widespread as models around the world become more capable," the companies stated. "The organizations and public services we all depend on are at risk."

The three demands of the tech giants

The open letter maps out several basic principles and operational demands from governments and the industry, including monitoring and transparency, re-arming defense, and global information sharing. The companies are calling for a mandatory development of tracking tools that will ensure that actions performed by AI agents are identifiable, attributable, and legally accountable.

In addition, the companies that signed the letter talk about shifting resources from traditional perimeter security to the use of advanced models designed to stop attacks in real time, as well as establishing cross-sector and cross-state partnerships to exchange threat intelligence at an accelerated pace.

Corporate responsibility or a cynical marketing move?

Although the recommendations in the letter include practical and logical steps, many cyber experts and industry critics receive the initiative with mixed feelings, defining it as "too little, too late."

In recent years, technology companies have pushed AI tools into every organizational layer, sometimes even before they were mature in terms of safety. The fact that now — after the dangers have been proven in the field — they are publishing serious warnings, seems to many less like a public service and more like a sophisticated advertisement for their new defense products.

Parallel to the brainstorming and emergency alerts, the same companies are rushing to reveal paid solutions: OpenAI offers the Daybreak program, Anthropic is pushing Mythos, and Microsoft is launching the Perception security platform. The question that remains open is whether regulators and governments will be satisfied with these declarations of intent, or will they demand that the AI giants take real responsibility for the products they release to the market.

Related News