
Artificial intelligence is making cyberattacks faster, cheaper and easier to scale. Now a broad group of technology, finance and security companies is calling for a coordinated defensive response before automated attacks become even harder to contain.
More than 100 organisations—including major cloud providers, AI developers, cybersecurity firms, banks and payment companies—have backed a joint push for stronger digital defences. The central idea is that the same automation helping attackers search for weaknesses can also help defenders detect, patch and contain them.
The proposal is not a new law or a binding global treaty. It is an industry commitment and a warning: conventional security practices may not move quickly enough for an era in which AI systems can test thousands of targets, tailor phishing messages and adapt attack methods at machine speed.
What is the AI cyber-defence pledge?
The initiative asks governments and businesses to put more technology, expertise and resources into cyber defence. Reuters reported that the signatories include AI labs, cloud companies, financial institutions and security vendors.
Its practical focus is on making widely used software and infrastructure harder to exploit. That includes faster vulnerability discovery, automated patching, secure-by-default products, better identity controls and more rapid sharing of threat information.
The pledge does not claim every AI-enabled attack can be stopped. Its argument is that defenders need their own automation advantage instead of relying mainly on humans to investigate alerts one by one.
How is AI changing cyberattacks?
AI does not eliminate the need for technical skill, but it can reduce the time and effort required for several stages of an attack.
Attackers can use generative systems to:
- Produce convincing phishing emails in many languages
- Personalise messages using public information
- Rewrite malicious code to avoid simple detection
- Scan large numbers of systems for known weaknesses
- Summarise stolen documents and identify valuable data
- Automate conversations in social-engineering attacks
The biggest change may be scale. A criminal once limited by the number of messages they could write or targets they could research can now automate much of that work.
AI can also make low-quality attacks more convincing. Perfect grammar is no longer a reliable sign that an email is legitimate, and a voice message that sounds familiar may still be synthetic.
How can defenders use AI?
Security teams already use machine learning to identify unusual logins, suspicious network activity and malicious files. More capable AI agents could extend that work by connecting signals across multiple systems and proposing a response.
A defensive system might notice that an employee account logged in from a new location, downloaded an unusual volume of data and created a new access token. Instead of generating three separate alerts, it could combine them into one incident and automatically restrict the account while a human investigates.
AI could also help developers find vulnerable code before release, prioritise patches by real-world risk and explain complex security findings to smaller organisations that lack large specialist teams.
Automation needs safeguards. A system allowed to block accounts, isolate servers or change firewall rules can also disrupt a business if it makes a mistake. High-impact actions should remain logged, reversible and subject to appropriate human approval.
Why identity security matters
Passwords are already one of the most common weak points in online security. AI-generated phishing and realistic impersonation make them even less reliable.
Organisations can reduce that risk by adopting phishing-resistant sign-in methods such as passkeys and hardware security keys. These methods verify the real website or service, making it much harder for a fake login page to steal a reusable credential.
Read our guide to how passkeys replace passwords for a practical explanation.
Businesses also need to secure non-human identities. Automated agents, software services and cloud workloads often hold powerful access tokens. If those credentials are poorly controlled, an attacker may gain more access through a forgotten service account than through an employee password.
What should businesses do now?
Companies do not need to wait for a new AI security product. The most effective steps begin with fundamentals:
- Patch internet-facing systems quickly. Known vulnerabilities remain a common entry point.
- Require phishing-resistant multi-factor authentication. Prioritise administrators, email and cloud accounts.
- Limit access. Users and automated agents should receive only the permissions they need.
- Keep offline or isolated backups. Test that critical systems can actually be restored.
- Monitor unusual behaviour. Focus on identity changes, large downloads and unexpected data transfers.
- Prepare an incident plan. Decide who can isolate systems, contact customers and preserve evidence.
- Check suppliers. A trusted software vendor or service provider can become the route into multiple customers.
AI defence works best when built on these controls. Automation cannot compensate for unsupported software, shared administrator passwords or backups that have never been tested.
What individual users should change
The industry pledge is aimed mainly at organisations, but individuals face many of the same AI-assisted threats.
Users should be sceptical of urgent requests involving money, passwords or account recovery—even if the message appears to come from someone they know. Confirm unusual requests through a second channel rather than replying directly.
Other useful steps include:
- Use a unique password or passkey for every important account
- Turn on multi-factor authentication
- Keep phones, browsers and computers updated
- Never share one-time security codes
- Check website addresses before signing in
- Set a verbal family code for urgent financial requests
The family code can help when a caller uses a cloned voice and claims to be a relative in distress. The correct response is to end the call and contact the person through a known number.
Will AI favour attackers or defenders?
The answer is not settled. Attackers often move faster because they do not need permission, compliance reviews or perfect reliability. Defenders, however, control the systems, identity records and telemetry needed to detect abnormal behaviour.
If organisations share threat signals and automate routine fixes, defence could gain an important advantage. If security tools remain fragmented while attackers automate reconnaissance and social engineering, the gap may widen in the other direction.
That is why the new pledge emphasises collective action. A vulnerability in one popular product can affect thousands of organisations, while information from one attempted attack can help protect many others.
The bottom line
The cyber-defence initiative is a recognition that AI security cannot be solved by a single company. Governments, cloud providers, software makers, banks and users all control different parts of the digital chain.
AI will amplify attacks, but it can also shorten the time between detection and protection. The outcome will depend less on dramatic promises than on whether organisations patch faster, secure identities, share useful information and keep humans accountable for high-impact automated decisions.
Explore more guides in the Technology section or learn how undersea internet cables keep countries online.

