On August 27, OpenAI, Anthropic, Amazon Web Services, Microsoft and more than a hundred other companies — cloud providers, cybersecurity firms, telecoms, banks and think tanks — signed an open letter called "Collective Cyberdefense." This isn't another round of generic AI-doom talk; it's a narrow, concrete claim: critical infrastructure — hospitals, water utilities, power grids — is becoming a cheap target because AI is lowering the cost of attacks faster than defenses are improving. The letter puts it bluntly: "we have a limited window to strengthen cyber defenses." As evidence, the signatories point to a real case — an AI-generated exploitation script used in attacks on U.S. water systems, previously flagged in a CISA advisory.
The letter goes beyond raising an alarm — it assigns roles to four groups. Organizations in general are asked to raise their internal security standards and fix the highest-risk weaknesses, including flaws introduced by AI-generated code itself. Governments are asked to build better threat-intelligence sharing across levels of government and fund infrastructure cyber defense. Cybersecurity companies are asked to build AI-powered defense tools specifically for critical infrastructure. And frontier AI developers — the signatories themselves, including OpenAI and Anthropic — commit to giving defenders access to more capable versions of their models during incidents and funding training for infrastructure-provider staff.
Not just water utilities: why a small accounting firm should care too
Headlines about "critical infrastructure" create a false sense that this is someone else's problem — a matter for utilities and hospitals. In practice, the letter's logic applies to any business holding customer data and paying bills online; it simply doesn't make headlines when it happens to them.
Picture a small eight-person accounting firm handling bookkeeping for fifteen local sole proprietors and small LLCs. It has no dedicated IT department — email runs on an ordinary cloud service, files sit in a shared folder, and access to clients' online banking is handled through credentials clients hand over directly. Attacking such a firm convincingly used to require a person willing to spend time on reconnaissance: learning the bookkeepers' names, matching the tone of a real supplier's correspondence, adding believable details. Now it takes feeding a model the firm's public footprint — its website, LinkedIn, press mentions — to produce an email that reads exactly like a genuine vendor, with precise tone and detail and none of the grammar mistakes that used to give phishing away. What follows is an attachment labeled "updated reconciliation statement" that actually opens a backdoor into a workstation holding saved banking credentials for five different client companies at once. This isn't exotic speculation — it's exactly the kind of cheaper, more convincing reconnaissance-and-attack pipeline the letter warns about, just applied at the scale of an entire industry rather than a single firm.
Why this letter deserves healthy skepticism, not just applause
It would be naive to read this purely as corporate altruism. Notice who signed: companies that sell the very models underlying the threat they describe, while simultaneously positioning themselves as the providers of defense against it. That's a convenient stance — it builds a narrative of "regulate us in a way that lets us help you defend yourselves," getting ahead of tougher, binding requirements from U.S. and EU regulators. It's also worth noting the letter contains no concrete commitments: no deadlines, no funding figures, no accountability for the fact that the signatories' own models are being used right now to generate malicious code. This reads more as a declaration of intent and a positioning move ahead of upcoming AI legislation than an operational plan with measurable outcomes. The document's value lies in publicly naming an industry-wide problem — not in solving it.
The practical takeaway for small businesses is more modest than the headlines suggest: don't assume "we're too small to matter," check who inside the company can approve a payment or open an attachment without a second check, and keep access to financial services separate from general email. No open letter is going to protect an eight-person bookkeeping firm — that's still the company's own job.
Source: Axios, "OpenAI, Anthropic issue dire cyber threat warning"
If you'd like a similar solution for your business, get in touch at dayava.pt/contactos/.