A broad coalition of artificial intelligence developers, cybersecurity companies, financial institutions, technology providers, and other organizations has issued an open letter calling for a coordinated effort to strengthen cyber defenses.

“We have a limited window to strengthen cyber defenses.”

The letter warns that AI-enabled cyberattacks have become more widespread and sophisticated. At the same time, it argues that advances in AI can help defenders identify vulnerabilities, remediate weaknesses, and respond to incidents more efficiently. Importantly, the letter points to several industries facing significantly higher levels of risk for organizations in those industries and the sometimes many thousands or millions of people they serve, e.g., critical infrastructure, manufacturing, supply chain, utilities (water), health care.

The signatories propose three overarching principles:

  1. Recognize that existing security practices may no longer be sufficient;
  2. Expand access to AI-enabled defensive capabilities; and
  3. Build a collective response involving businesses, technology providers, governments, and frontier AI companies.

While not a new recommendation, the letter calls for cybersecurity to become an “immediate leadership priority.” It advocates that particular attention be given to high-risk vulnerabilities, least-privilege access, strong authentication, layered defenses, and security standards for technology that organizations purchase, develop, or deploy. In short, the letter suggests that the measures for achieving the standard of “reasonable safeguards” may have changed as the threat landscape rapidly evolves, and so too must the measures for safeguarding assets from those threats.  What constitutes “reasonable safeguards” is now a fast-moving target.

For those responsible for cybersecurity preparedness and incident response, the letter reinforces an important point: Organizations should not view AI defense as simply a technology-acquisition project. It is a governance, legal-risk, and operational-resilience issue. New tools will not compensate for unclear responsibility, incomplete asset inventories, weak vendor oversight, or incident-response plans that have never been tested. Organizations also should evaluate AI security tools carefully, including what data the tools collect, where that data is stored and how it is safeguarded, how model outputs are validated, and whether contracts appropriately allocate responsibility for security incidents.  

Taking these steps, among others, will help organizations make the best use of this limited window to strengthen their cyber defenses, positioning them as less vulnerable targets for AI-powered cyberattacks and to defend themselves against the class action lawsuits that are likely to become even more prevalent as these attacks gain steam. 

Print:
Email this postTweet this postLike this postShare this post on LinkedIn
Photo of Joseph J. Lazzarotti Joseph J. Lazzarotti

Joseph J. Lazzarotti is a principal in the Tampa, Florida, office of Jackson Lewis P.C. He founded and currently co-leads the firm’s Privacy, Data and Cybersecurity practice group, edits the firm’s Privacy Blog, and is a Certified Information Privacy Professional (CIPP) with the…

Joseph J. Lazzarotti is a principal in the Tampa, Florida, office of Jackson Lewis P.C. He founded and currently co-leads the firm’s Privacy, Data and Cybersecurity practice group, edits the firm’s Privacy Blog, and is a Certified Information Privacy Professional (CIPP) with the International Association of Privacy Professionals. Trained as an employee benefits lawyer, focused on compliance, Joe also is a member of the firm’s Employee Benefits practice group.

In short, his practice focuses on the matrix of laws governing the privacy, security, and management of data, as well as the impact and regulation of social media. He also counsels companies on compliance, fiduciary, taxation, and administrative matters with respect to employee benefit plans.

Photo of Damon W. Silver Damon W. Silver

Damon W. Silver is a principal in the New York City, New York, office of Jackson Lewis P.C. and co-leader of the firm’s Privacy, AI & Cybersecurity practice group. He is a Certified Information Privacy Professional (CIPP/US).

Damon helps clients across various industries—with…

Damon W. Silver is a principal in the New York City, New York, office of Jackson Lewis P.C. and co-leader of the firm’s Privacy, AI & Cybersecurity practice group. He is a Certified Information Privacy Professional (CIPP/US).

Damon helps clients across various industries—with a focus on financial services, healthcare, and education—handle their data safely. He works with them to pragmatically navigate the challenges they face from cyberattacks, technological developments including AI, a fast-evolving data privacy and security legal compliance landscape, and an active and innovative plaintiffs’ bar.

Damon recognizes that needs vary from one client to the next. Large, mature organizations, for instance, may need assistance managing multi-jurisdictional and multi-faceted compliance obligations. Others may be in a stage of development where their greatest need is to triage what must be done now and what can more safely be left for later. Damon takes the time to understand each client’s circumstances and priorities and then works with it to develop tailored approaches to effectively managing risk without unnecessarily hindering business operations.