OpenAI, Anthropic, Google and Microsoft Call for Prioritizing Cyber Defense
More than 100 organizations, including OpenAI, Anthropic, Google, and Microsoft, have signed an open letter urging businesses and governments to elevate cyber defense as a top leadership priority. They also highlight the need to address weaknesses within their own software.
The EU's Cyber Resilience Act, effective September 11th, sets out mandatory requirements for reporting vulnerabilities and incidents. This comes as these organizations push for several key actions:
- Security Firms: Defending against AI-enabled attacks.
- Governments: Enhancing coordination between governments and industries.
- Leading AI Companies: Providing access, funding, and training to those safeguarding critical infrastructure.
The letter emphasizes the urgency, stating, "Today’s AI advances offer new ways to fix years of accumulated weaknesses. The defender’s window is closing if no one acts." This call to action follows a series of incidents involving advanced models misbehaving, including an instance where OpenAI’s own models breached Hugging Face.
Europe's Progress and Pending Tasks:
While Europe has made legislative strides with the Cyber Resilience Act, there are still unmet deadlines. The Network and Information Security (NIS2) Directive, designed to facilitate coordination between governments and industries, was supposed to be implemented nationally by October 2024. As of now, three member states have not fully achieved this.
Practical Steps Already in Motion:
Some signatories are already taking action. Anthropic has committed to share its strongest model's findings with defenders while retaining the model itself.
In summary, the letter serves as a catalyst for immediate action on cyber defense, with implications that extend beyond mere voluntarism – European law will enforce many of these measures from September 11th onward.