AI Defense Open Letter Highlights Critical Infrastructure Readiness Gap

August 31, 2026
AI Defense Open Letter Highlights Critical Infrastructure Readiness Gap
IANS News

Key Points

  • More than 100 technology, cybersecurity, and financial-services firms called for a coordinated effort to defend critical infrastructure against a coming wave of AI-enabled cyberattacks.
  • The coalition urged governments, AI labs, and security vendors to expand access to defensive AI models, threat intelligence, and cyber-defense resources for critical infrastructure operators.
  • IANS Faculty say the challenge is turning AI capabilities into operational readiness through workforce development, public-private partnerships, and stronger security fundamentals.

 

AI Defense Open Letter Highlights Critical Infrastructure Readiness Gap

More than 100 technology, cybersecurity and financial firms signed an open letter urging governments and critical infrastructure operators to prepare for a coming wave of AI-driven cyberattacks.

The signatories, including Google, Microsoft, OpenAI, Anthropic, CrowdStrike, Visa and Mastercard, issued a call for “collective action” to narrow attackers' window of opportunity and reduce opportunities for AI-enabled attacks.

Recommendations included providing advanced AI capabilities to critical infrastructure operators, developing AI-powered defensive tools, accelerating the remediation of high-risk vulnerabilities, and increasing government coordination and funding for cyber defense.

The letter did not include any financial commitments or new investments from participating companies.


Big Picture

The letter's recommendations imply that broader access to frontier AI models will unilaterally improve cyber resilience across critical infrastructure. However, many operators lack the personnel, expertise, and operational maturity needed to deploy and secure those capabilities effectively.

"First of all, all the access in the world to frontier models is not going to help critical infrastructure orgs if they don't have the staff that knows what to do with it. These are non-deterministic systems that need deterministic controls around them. Who is building that at a local water company?”  Summer Craze Fowler, IANS Faculty.

The harder question is who will provide the talent, resources, and operational support needed to make those defenses effective.

Let's stop with the open letters and actually architect some solutions," added Fowler. "We need trained defenders (e.g., an AI Defense Corps), subsidized defensive capabilities, and government- and industry-backed programs that help critical infrastructure operators actually use those tools."

Further, the lack of infrastructure operators in the letter raises questions on whether the initiative reflects the realities these organizations face.

"116 organizations warn that hospitals and critical infrastructure orgs are at risk. Not one hospital or water utility signed. Under-resourced teams, legacy debt, unpatched systems, these are problems that will take more than model access and subsidized tokens. Success requires bringing those at risk into the conversation.”  Wolfgang Goerlich, IANS Faculty.

Still, even the most sophisticated AI defenses won't compensate for weak security architectures and years of accumulated technical debt.

"Eliminating legacy systems, properly implementing micro-segmentation and ZTNA, restricting user privilege and such aren't the cool/fun security practices, but they're actually more effective than learning yet another security technology.”  Josh More, IANS Faculty.

 

IANS Faculty Recommendations

  • Reduce OT exposure: Pull SCADA/ICS systems off public-facing networks and pair that with active threat hunting.
  • Fix segmentation first: Isolate OT from IT and retire end-of-life systems before adding new tools.
  • Require phishing-resistant access controls: Replace open remote access for vendors with MFA and PAM.
  • Use AI where staffing gaps are the greatest: An AI-assisted vulnerability-prioritization tool can absorb the triage work a skeleton crew has no time for -- a realistic first use of "free model access.”


Authors & Contributors

Nuria Diaz Munoz, Author - Security Reporter, IANS News

Summer Craze Fowler, IANS Faculty

Wolfgang Goerlich, IANS Faculty

Josh More, IANS Faculty

 

Although reasonable efforts will be made to ensure the completeness and accuracy of the information contained in our News & blog posts, no liability can be accepted by IANS or our Faculty members for the results of any actions taken by individuals or firms in connection with such information, opinions, or advice.

Subscribe to IANS Blog

Receive a wealth of trending cyber tips and how-tos delivered directly weekly to your inbox.

Please provide a business email.