NEWS

OpenAI and Anthropic Lead a 116-Firm Warning on AI Cyberattacks

Logos of major technology and finance companies gathered under a single shield against an AI-driven cyberattack
OpenAI, Anthropic, and 116 companies in total signed an open letter warning that AI is outpacing cyber defenses. Source: Santage
TLDR

A joint alarm from the companies building the tools

More than 100 of the largest names in technology and finance put their names to a single warning on Wednesday. Artificial intelligence is making cyberattacks more capable, they said, and defenders have a narrow window to catch up. The open letter drew 116 signatories in total, led by the AI developers OpenAI and Anthropic and including Google, Microsoft, Amazon Web Services, Cisco, IBM, CrowdStrike, Cloudflare, Capital One, Mastercard, Visa, and Hugging Face, according to reporting from CNBC and Bloomberg.

The letter frames the stakes in terms of essential services rather than corporate networks.

The companies and public services our communities depend on, from hospitals to water treatment plants to the infrastructure that powers the internet, are at risk.
Excerpt from the August 27, 2026 open letter on AI and cyber defense

Its central argument is that AI has begun to favor attackers, who can use models to find vulnerabilities and generate working exploit code at machine speed, and that defenders must move while the advantage is still contestable. The signatories set out three broad principles and a set of actions. Organizations should treat cyber defense as a leadership priority and raise their security standards, security vendors should test their defenses and share threat intelligence, governments should fund protection for essential services, and AI developers should supply models, training, and incident support to defenders.

The letter at a glance
116signatories in total, spanning AI labs, cloud providers, banks, and card networks
Led byOpenAI and Anthropic, with Google, Microsoft, and AWS among the names
The aska coordinated "defensive surge" across four groups
Missingno commitments, deadlines, spending pledges, or measurable targets
Backdropa year of AI-driven attack disclosures, from autonomous agents to AI-written exploit scripts
Source: CNBC, Bloomberg, NBC News, August 2026.

Strong on alarm, light on commitments

What the letter does not contain is any binding pledge. It carries no deadlines, no spending commitments, and no measurable targets, a gap that security professionals were quick to flag. Practitioners including Diana Kelley and John Gallagher welcomed the attention but questioned the value of a call to action, issued in part by the makers of the models that are sharpening the attacks, that commits none of the signatories to anything specific.

The companies whose models are making cyberattacks faster are now asking everyone, themselves included, to hurry up on defense. The alarm is real. The commitments are not yet.

The letter lands on top of a year of escalating disclosures. US agencies have warned that attackers are using AI to write exploit scripts against industrial controllers, CrowdStrike has described AI as both weapon and target, and OpenAI paused one of its own systems this month over cyber-risk concerns. Wednesday's letter is the industry's attempt to answer that record collectively. Whether it becomes more than a statement will depend on what its signatories fund and ship, not on what they signed.

In short: OpenAI, Anthropic, and 116 companies in total signed an open letter on August 27, 2026 warning that AI is outpacing cyber defenses and calling for a coordinated defensive surge, though it sets no binding commitments.
Quick quiz
What did security practitioners flag as the main limitation of the 116-firm cyber defense letter?

Santage is committed to independent, transparent journalism. This article is produced in accordance with Santage's Editorial Standards and aims to provide accurate and timely information. Readers are encouraged to verify information independently.