Share:

OpenAI, Anthropic, and Microsoft don’t usually sign the same document very often.

But in February 2026, that’s exactly what happened — and alongside them, more than 100 companies joined in, including Amazon Web Services, cloud providers, fintechs, and cybersecurity firms.

The reason is an open letter with a very clear message: organizations have only a few months to prepare for cyberattacks supercharged by artificial intelligence.

And when they talk about critical infrastructure, they’re not being dramatic.

Hospitals, water treatment plants, and other essential systems are already in the crosshairs of attackers using AI models to speed up and cheapen attacks that used to take months to set up.

The landscape shifted fast — and the letter makes it clear that companies and governments have an increasingly narrow window to respond before the problem spirals out of control. 🕐

Receive the best innovation content in your email.

All the news, tips, trends, and resources you're looking for, delivered to your inbox.

By subscribing to the newsletter, you agree to receive communications from Método Viral. We are committed to always protecting and respecting your privacy.

What the open letter actually says

The letter isn’t some generic corporate manifesto full of vague promises. It includes a line that sums everything up: we have a limited window to strengthen cyber defenses. The document calls for collective action and urges organizations to use this shrinking timeframe to protect critical infrastructure, making it more expensive and more difficult for attackers using AI tools to break into systems.

Among the signatories are cloud providers, cybersecurity companies, artificial intelligence firms, telecom companies, financial institutions, and research centers. This mix of sectors isn’t random — it shows that the problem doesn’t belong to any single industry but cuts across virtually the entire modern digital economy.

The document also points out that malicious groups are already using language models to automate steps that previously required highly skilled human specialists — such as analyzing system vulnerabilities, creating custom exploitation scripts, and even running social engineering campaigns at scale. This means the barrier to entry for pulling off a sophisticated attack has dropped dramatically, and the number of actors capable of executing this kind of operation has grown at the same rate.

The proposed plan for companies and governments

One of the most interesting parts of the letter is that it doesn’t stop at sounding the alarm. The organizations lay out a plan for how companies, governments, and tech and cybersecurity firms need to adapt in the face of this new threat landscape. Each front of action is worth highlighting:

  • All organizations need to raise their internal security standards and fix their highest-risk weaknesses. Beyond that, they should raise the security bar for everything they buy, build, and deploy, including AI-generated code.
  • Cybersecurity and technology companies should rapidly test and develop tools that make AI-powered defense accessible and practical for critical infrastructure operators. They also need to share threat intelligence with each other.
  • Governments need to strengthen channels for sharing actionable threat intelligence, coordinate defense at local, national, and international levels, and fund cybersecurity initiatives.
  • Leading AI companies should give defenders access to their most capable response models during major cyber incidents, while also providing significant funding, training, and hands-on support, especially for critical infrastructure providers.

Notice how each layer has a specific role. It doesn’t help if OpenAI releases powerful defense models but governments don’t create channels to distribute that capability. And it doesn’t help if a government funds security but companies don’t fix their own internal gaps first. It’s a networked effort — and that’s exactly why the phrase collective action shows up so prominently in the text. 🤝

Why so many companies signed together

Seeing OpenAI, Anthropic, and Microsoft on the same document would already be enough to turn heads. But when you add more than 100 organizations — including cloud giants like AWS, fintechs processing billions per day, and some of the world’s top cybersecurity companies — the signal gets even louder. This level of alignment among direct competitors is rare, and it usually only happens when the problem at hand is big enough to threaten everyone equally. None of these companies win if trust in digital infrastructure collapses — and they all know it.

There’s also a strategic dimension to this move. By signing collectively, these organizations create a unified narrative that carries far more weight with regulators, lawmakers, and international bodies than any individual lobbying effort could achieve. The private sector, especially in tech, has learned over the past few decades that when it speaks in a fragmented way, public policy tends to be reactive and poorly calibrated. A letter of this size and level of representation is, in practice, an attempt to shape the debate before decisions are made without the necessary technical expertise — and without input from the people who actually understand how these systems work.

From an artificial intelligence perspective, this move also reflects the sector maturing. For a long time, the conversation around AI and risks stayed confined to futuristic and philosophical scenarios. Now, the focus has shifted to concrete, measurable threats that are already underway. The companies building the most powerful models in the world are publicly acknowledging that these tools can — and already are — being used maliciously.

What’s at stake for critical infrastructure

When the document mentions critical infrastructure, it’s talking about systems most people never think about until the moment they stop working. Power distribution networks, for example, are highly attractive targets for attackers because a successful breach can paralyze entire cities, compromise hospitals that depend on constant power, and create logistical chaos that’s hard to reverse quickly.

The problem is that many of these systems were built decades ago, in a world where internet connectivity was nonexistent or very limited. As the letter itself and experts have previously noted, critical infrastructure like water systems and power plants has always had vulnerabilities in the tools that control the machinery. The difference is that before, attackers needed to invest significant time understanding the technical details of these systems. Now, AI models are drastically reducing how much time and effort attackers need to spend on that preparation.

Water supply systems are also among the central concerns. Unlike other types of infrastructure, they tend to have smaller IT teams, tighter budgets for digital security, and a growing reliance on internet-connected control systems. It’s no coincidence that the letter comes amid a wave of attacks against critical infrastructure, including an incident targeting water systems in the United States that apparently used an AI-generated exploitation script.

Tools we use daily

What actually changes with AI on the attackers’ side

The big shift that artificial intelligence brought to the world of cyberattacks isn’t just about speed — it’s about accessibility. Before, executing a targeted attack against a large organization required a team with very specific skills, access to expensive tools, and considerable time to map out the target environment. Today, language models can be prompted to generate malicious code, identify vulnerability patterns in public-facing systems, and even craft highly personalized phishing messages based on publicly available information.

Another aspect that concerns experts is the use of AI to evade defenses. Modern security tools rely heavily on pattern recognition — identifying anomalous behavior, known malware signatures, and suspicious data flows. But when the malicious agent itself uses AI to continuously adapt the attack’s behavior, making it look more like legitimate traffic, the effectiveness of traditional defenses drops significantly. This arms race between AI-powered offensive and defensive systems is already happening. ⚠️

The detail that shouldn’t be overlooked

Despite all the weight behind the document, there’s an important caveat: the signatories didn’t commit to any concrete actions, didn’t set deadlines, and didn’t announce specific investments as part of the letter. In other words, the text works much more as an urgent call to action and an alignment of intentions than as a plan with binding goals. That doesn’t diminish the value of the warning, but it shows that the path between recognizing the problem and acting in a coordinated way still depends on many decisions that weren’t on the table at that moment.

The open letter from February 2026 isn’t a warning about the future. It’s a diagnosis of the present — and organizations that still treat digital security as a secondary expense may be underestimating a risk that’s already very real.

Artificial intelligence has transformed the field of digital security in a way that can’t be undone. And the answer isn’t going to come from a single company or an isolated government. The sheer size of the coalition that signed this letter is, in itself, a message about the scale of the problem — and the kind of response it’s going to demand. 🌐

Picture of Rafael

Rafael

Operations

I transform internal processes into delivery machines — ensuring that every Viral Method client receives premium service and real results.

Fill out the form and our team will contact you within 24 hours.

Related publications

Amazon's stock could rise following OpenAI partnership.

Amazon and OpenAI partnership could boost AI revenue and stock value, says Citi; strategic impact on AWS and infrastructure race.

Moratorium on AI Data Centers: Energy in Debate

Sanders and AOC propose moratorium on AI datacenter construction in the US to assess environmental and energy impacts.

Blockchain and AI Agents Are Changing Crypto Payments

AI agents power crypto payments with blockchain, stablecoins and x402, enabling autonomous transactions, micropayments and machine-to-machine economy

Receba o melhor conteúdo de inovação em seu e-mail

Todas as notícias, dicas, tendências e recursos que você procura entregues na sua caixa de entrada.

Ao assinar a newsletter, você concorda em receber comunicações da Método Viral. A gente se compromete a sempre proteger e respeitar sua privacidade.

Rafael

Online

Atendimento

Website Pricing Calculator

Find out how much the ideal website for your business costs

Website Pages

How many pages do you need?

Drag to select from 1 to 20 pages

In just 2 minutes, automatically find out how much a custom website for your business costs

More than 0+ companies have already calculated their quote

Fale com um consultor

Preencha o formulário e nossa equipe entrará em contato.