
In late August, more than 100 of the largest technology and security companies published a joint open letter on AI and cybersecurity. The signatories include OpenAI, Anthropic, Google, Microsoft, and Amazon Web Services, alongside security vendors such as CrowdStrike, Okta, and Fortinet. Their message is direct: current security practices will not hold against AI-enabled attacks, and organizations should respond with the urgency of a serious incident.
For a public entity or a mid-market organization, the letter can read like confirmation of what a risk manager has been telling the board for years. As such, it might feel tempting to forward the letter on as validation. But, if you take a closer look, the most useful parts of the document are the questions it raises, not the solutions it suggests.
The letter rests on the idea of a defenders' window: the argument that AI, used well, favors defenders provided they act quickly. This is a genuine position, but it is not a settled one. Research from CSET and CNAS treats the balance between attack and defense under AI as an open question, and a credible body of work argues that AI helps attackers more. The reasoning is simple. An attacker needs one successful exploit; a defender must close every gap. AI removes constraints from the attacker, including change control, compliance review, and uptime requirements, more cleanly than it removes them from the defender. A security budget built on the assumption that defense wins deserves scrutiny before it is approved.
The letter encourages organizations to share tools, playbooks, and verified fixes so that one organization's work protects many. The efficiency is real, and so is the concentration it creates. When many organizations rely on the same defensive tools and the same tested procedures, a flaw in that shared layer reaches all of them at once. This is aggregation risk, the same dynamic that concerns any insurer when too many policyholders sit behind a single point of failure. Before adopting a shared defensive posture, an organization should understand how correlated its defenses have already become.
One line asks organizations to ensure that agentic identities are traceable and accountable: “Build observability and security tools, ensure agentic identities are traceable and accountable, and share best practices in continuous monitoring.” Written as a task still to be done, it concedes that this is not the case today. Autonomous AI agents are already operating on enterprise networks. They authenticate, hold credentials, and take actions without a person approving each step, ahead of the logging and accountability needed to govern them. An agent operating with valid credentials and no audit trail is a real exposure for forensics, compliance, and coverage. The companies building these agents have now said so themselves.
It is also worth noting what the letter does not contain. As Axios reported, the signatories made no commitments, set no deadlines, and pledged no specific investment. The document coordinates and signals; it does not obligate. The diagnosis is largely sound, but the absence of any commitment is a useful tell. Expect compliance expectations and budget requests to follow the narrative well before any signatory changes its own behavior.
The letter works best as a prompt. A short agenda for the next risk discussion:
Much of what the letter recommends will grow cheaper and more standardized over time, including for the under-resourced public entities and smaller organizations it names. What does not standardize is the judgment behind it: deciding what is truly critical, confirming that a control actually compensates for a given risk, and understanding how correlated an organization's defenses have become.
We advise and assess exposure rather than sell the tools or place the coverage, which is why our reading of this letter does not depend on who profits from it. For organizations that want the cyber execution alongside the risk assessment, our affiliate CyberSure carries it forward.
Corporate Office
1435 Vine Street, Suite 326
Cincinnati, Ohio 45202
513-644-1085
Charlotte Office
525 N Tryon Street, Suite 1600
Charlotte, NC 28202