AI threatens to outpace enterprise security
OpenAI-led coalition warns AI will compress cyberattack timelines, exposing unfixed enterprise weaknesses.
An industry coalition led by OpenAI is pressing a stark warning: artificial intelligence will compress the time attackers need to find and exploit enterprise weaknesses, and the window for defenders to act is narrow. In an open letter signed by more than 100 technology and cybersecurity firms — including Microsoft, Google, Amazon Web Services, and Anthropic — the group argues that AI-enabled attacks will soon become more widespread and sophisticated, putting years of security debt into the crosshairs.
The letter, made public ahead of any widespread confirmation of specific incidents, reflects growing concern that AI's ability to accelerate both discovery and exploitation will outpace the ability of many organizations to fix long-standing flaws. OpenAI CEO Sam Altman underscored the urgency in a post on X, calling it a “critically important moment for cyber defense” and warning that there is little time to act.
Coalition signs on to shared warning
The signatories span a broad swath of the technology and security industry, from cloud providers to security vendors. Their collective message is that the risk is not about new categories of vulnerabilities, but about scale: AI systems will accelerate the discovery and exploitation of weaknesses that enterprises have struggled to fix for years.
According to the letter, leaders across industry and government must bring “the full weight of their technology, resources, and expertise” to the effort. It explicitly calls for putting “cyber-capable AI in the hands of defenders” and prioritizing fixes for high-risk weaknesses.
Known weaknesses, faster exploitation
The letter attributes the risk to AI's ability to accelerate the discovery and exploitation of existing vulnerabilities, citing a litany of common enterprise problems. “Longstanding bugs, excessive permissions, misconfigurations, insecure and unpatched software, weak authentication, and technical debt… have left systems exposed,” the letter added.
This framing suggests that the threat is less about novel attack techniques and more about the sheer speed at which AI can identify and chain together known issues — many of which have been sitting in enterprise environments for years.
Response from security vendors
Several signatories elaborated on why they backed the initiative. SpecterOps said it agreed with the letter's central principles, including that the weaknesses already exist, that advanced AI needs to reach more defenders, and that the response must be collective and widespread.
1Password, another signatory, highlighted the “limited window to strengthen security” and called for fixing high-risk weaknesses, enforcing least-privilege access, and verifying controls. Sophos said in a statement that AI-enabled threats increase risk to both enterprises and public services, and require coordinated action.
“Cyber defense is a shared responsibility,
— Sophos, in a statement (company name as given in source)
Capacity constraints and attack paths
Some experts argue the problem is not AI's sophistication but simple capacity. Robbie Mueller, technical lead for cybersecurity at ArmorCode, said organizations already face constraints in addressing known vulnerabilities. “This shouldn’t be framed as an AI sophistication problem. It’s a capacity problem,” Mueller said, adding that organizations “can only remediate roughly one in ten vulnerabilities in a given month.”
Mueller said risk increases when vulnerabilities form multi-step attack paths across systems. “What matters is not the number of findings but which ones chain together into a viable path… kill that path and the risk goes away,” he said.
Johnathan Hunt, chief information security officer at LogicMonitor, said many enterprise environments are not designed to operate at AI-driven speeds. “Bad actors will move at machine speed, while many legacy systems still rely on human reaction times,” Hunt said.
Operational pressure mounts
The letter warns that AI will increase both the scale and speed of cyberattacks, placing additional pressure on enterprise security operations. “In the coming months, AI-enabled cyber attacks will become far more widespread and sophisticated,” the coalition said.
Ryan McCurdy, vice president at Liquibase, noted that AI is accelerating both attack speed and development velocity. “AI is accelerating both sides of the equation,” McCurdy said, adding that security teams must determine whether changes are “authorized, safe, and expected” at speeds that exceed manual review.
The letter calls for making cyber defense an immediate leadership priority, “with the urgency and coordination of an incident.” It emphasizes execution of existing practices rather than introducing new categories of defense.
Funding and incentive questions
Not everyone is convinced the solution is straightforward. Seemant Sehgal, CEO of BreachLock, raised questions about incentives. “The companies asking governments to fund AI defensive tools are the same ones that would get paid to supply them… the recommended response isn’t neutral,” Sehgal said.
John Strand, owner of Black Hills Information Security, said the most actionable recommendation is the call for greater sharing of threat intelligence. “The one recommendation that has some teeth… is greater sharing of IOCs,” Strand said.
Why this matters to enterprises
The message from this coalition, if accurate, means enterprises face a tightening clock on security debt that has been accumulating for years. The letter's emphasis on fixing high-risk weaknesses, verifying fixes, and sharing what works suggests that defenders may not be able to rely on incremental improvements alone.
For organizations still running legacy systems and manual review processes, the implication is that AI-driven attackers could force a reckoning. The coalition's call for collective action — across industry and government — underscores the scale of the challenge, but the practical burden of patching known vulnerabilities and enforcing least-privilege access will likely fall on individual enterprises.
The coming months, as the letter warns, may determine whether that window closes before defenses can be strengthened.
Sources
- CSO Online Original source
Continue Reading
Browser extensions turn into supply chain risk
Attackers buy legitimate Chrome, Edge extensions and push malware via updates, Socket reports.
AI agents rewrite cloud security rules
Autonomous AI attackers can chain cloud misconfigurations at machine speed, forcing CISOs to rethink defense.
FulcrumSec Claims Manchester Airport Breach, 86 GB Stolen
Extortion group FulcrumSec says it stole 86 GB from Manchester Airports Group, exposing detailed travel data.