The industry just issued a security warning. Here's your toolkit. 

Today, OpenAI, Anthropic, Microsoft, and more than 100 other organizations issued a public call for collective action on cyber defense, warning that AI is closing the gap between a vulnerability being discovered and being exploited, at a scale and speed most defenses were never built for.

Digital.ai's CEO, Derek Holt, is answering that call. Below: his response in his own words, and the tools to act on it.

An Open Letter from Our CEO 

“The application must become part of the defense.”
Read Derek Holt's full response to the industry's call for collective action, including details on how to protect your apps even when zero days outpace your remediation efforts...

In response to "A call for collective action on cyber defense” - All Applications Must Become Part of the Defense 

An open letter from Derek Holt, CEO of Digital.ai 

Yesterday, OpenAI, Anthropic, Microsoft, and more than 100 organizations issued an urgent call for collective action on cyber defense (link). The core message is clear: the window to prepare is short—and closing—as AI enables attacks of unprecedented speed, scale, and sophistication.

The letter calls on cybersecurity companies and technology partners to test defenses continuously against frontier AI capabilities, strengthen existing tools with AI, collaborate to close critical gaps, and make advanced protection accessible to organizations with limited security resources. Meeting this challenge will require coordinated action across the entire security ecosystem—from identity, infrastructure, networks, and cloud environments to the applications operating beyond the traditional perimeter.

Digital.ai has a critical role to play at that application layer. This call reinforces a conviction that has guided our security products for more than two decades: when valuable software operates in an environment an organization does not control, that environment must be considered hostile. A mobile, web, or desktop application may not contain an enterprise’s most valuable data assets, but it provides the blueprint—and increasingly the pathways—to reach them. Its authentication flows, APIs, secrets, third-party libraries, SDKs, and connections to critical systems can expose vulnerabilities and show human and machine attackers how the enterprise works and provide a blueprint to where its most valuable assets can be found.

According to the 2026 Verizon Data Breach Investigations Report, vulnerability exploitation powered by AI has overtaken stolen credentials as the leading initial-access vector for the first time in the report’s 19-year history. Thirty-one percent of breaches now begin with exploitation of a software vulnerability surpassing stolen credentials and phishing who have long led the list.

AI is fundamentally changing the economics and scale of attacks.

Previously, reverse engineering an application required specialized expertise, sophisticated tools, and significant time. AI and Agents can now identify components, reconstruct application logic, expose APIs, analyze dependencies, locate sensitive functions, and help operationalize vulnerabilities at machine speed. This is not just for “flagship” applications. AI puts every application at risk.

While attacks are happening at machine speed, vulnerability remediation continues to happen at human speed. The defender’s workflow remains largely the same: find, prioritize, assign, patch, test, approve, release, and deploy. Patches can be generated more quickly with the aid of coding agents, but patch delivery remains a bottleneck.  And remediation often depends on an external maintainer, software vendor, library or customer installing an update.

This creates the defining cybersecurity problem of the AI era:

You will never patch faster than AI can find and exploit.

We must continue finding and fixing every vulnerability we can, and we must use AI to help accelerate that process. We also need to continue to engage in a broad set of security solutions across identity, API protection, SBOM, continuous monitoring and more.  But patching will never be enough.

Bridging the protection gap

Historically, most applications followed a straightforward security cycle:

Find vulnerabilities. Prioritize them. Patch them.

For certain “flagship” applications, the industry traditional would add hardening, anti-tamper controls, runtime protection, and other defenses to provide more runway while vulnerabilities were found and fixed.  For most applications protections are not applied, and organizations have relied on vulnerability patching to stay ahead of the attackers.
A 2025 peer-reviewed study presented at the IEEE European Symposium on Security and Privacy analyzed 2,646 popular applications available on both Android and iOS. The findings: only 4.7% of Android applications and 0.2% of iOS applications implemented every protection evaluated. Moreover, 24.1% of Android applications and 85% of iOS applications used fewer than half of the recommended techniques.

Based on this research and broader industry evidence, we estimate that perhaps one application in ten is meaningfully hardened, while only around one in forty is comprehensively protected. Because the study examined popular cross-platform applications—likely to receive greater security investment than the broader application market—the overall picture may be even worse.

This gap is no longer sustainable. In an AI and agentic world, every application must be protected.

Organizations must assume that exploitable vulnerabilities will persist, that agents will find and operationalize them at machine speed, and that remediation will increasingly arrive after it is too late. To survive this new world, applications must become active participants in their own defense—able to conceal sensitive logic, resist modification, detect hostile conditions, counter agentic attacks and respond at machine speed.

This is the shift toward Always-On, AI-Resilient Application Defense.

How Digital.ai is mobilizing

In response to this call for collective action, Digital.ai is mobilizing in three areas.

First, we are helping our existing global customers expand protection across their application portfolios. Hardening cannot remain limited to a handful of applications designated “most critical” in an earlier threat era. We are making it easier and more affordable for our customers to extend protection across all of their mobile, web and desktop applications.

Second, we are engaging organizations that have not traditionally protected the application layer. Many recognize the risk but lack the time, expertise, or capacity to harden applications at scale. We are working to make advanced application defense accessible to organizations that haven’t traditionally protected the application layer. Capabilities like our Quick Protect Agent provide application defense without sophisticated application security skills. As the Agentic threats continue to rise, we will continue to accelerate our investments and innovation in this space.

Our objective is simple: reduce the expertise, effort, and time required to move an application from exposed to defended.

Third, we will accelerate our collaborations across the cybersecurity ecosystem. No single vendor, enterprise, government, or frontier AI company can close this window alone. Progress requires shared intelligence, continuously tested defenses, responsible access to advanced AI, strong partnerships, and clear measures of whether protections work in real environments.

Digital.ai's teams have spent more than two decades preparing for a world in which applications operate beyond the traditional security perimeter and where attacks happen at machine speed. That world has arrived and the time to act is now.

We are ready to bring our technology, expertise, customer relationships, and global reach to this collective effort.

The application is now the perimeter, and it must quickly become part of the defense.

Derek Holt
Chief Executive Officer
Digital.ai

 

 

Sources

In this short video, Derek breaks down what the industry's warning means for your application portfolio — and why always-on, AI-resilient defense is no longer optional.

Find Out Where You Stand 

Most organizations don't actually know how exposed their applications are. 

Get a free assessment of your application portfolio and see exactly where your gaps are — and what it would take to close them. 

See the Data Behind the Warning 

Want the full picture of how AI is changing the attack landscape? Our latest Threat Report breaks down the tactics, trends, and techniques driving this shift.