- OpenAI, Anthropic, Google, Microsoft, and 116 companies and organizations in total signed an open letter on August 27 warning that AI is strengthening cyberattackers faster than defenders can keep up.
- The letter calls for a coordinated "defensive surge" across companies, security vendors, governments, and AI developers, but sets no commitments, deadlines, or spending targets.
- Security practitioners welcomed the alarm while questioning a call issued partly by the AI makers whose own models are helping make the attacks more capable.
A joint alarm from the companies building the tools
More than 100 of the largest names in technology and finance put their names to a single warning on Wednesday. Artificial intelligence is making cyberattacks more capable, they said, and defenders have a narrow window to catch up. The open letter drew 116 signatories in total, led by the AI developers OpenAI and Anthropic and including Google, Microsoft, Amazon Web Services, Cisco, IBM, CrowdStrike, Cloudflare, Capital One, Mastercard, Visa, and Hugging Face, according to reporting from CNBC and Bloomberg.
The letter frames the stakes in terms of essential services rather than corporate networks.
The companies and public services our communities depend on, from hospitals to water treatment plants to the infrastructure that powers the internet, are at risk.Excerpt from the August 27, 2026 open letter on AI and cyber defense
Its central argument is that AI has begun to favor attackers, who can use models to find vulnerabilities and generate working exploit code at machine speed, and that defenders must move while the advantage is still contestable. The signatories set out three broad principles and a set of actions. Organizations should treat cyber defense as a leadership priority and raise their security standards, security vendors should test their defenses and share threat intelligence, governments should fund protection for essential services, and AI developers should supply models, training, and incident support to defenders.
| 116 | signatories in total, spanning AI labs, cloud providers, banks, and card networks |
| Led by | OpenAI and Anthropic, with Google, Microsoft, and AWS among the names |
| The ask | a coordinated "defensive surge" across four groups |
| Missing | no commitments, deadlines, spending pledges, or measurable targets |
| Backdrop | a year of AI-driven attack disclosures, from autonomous agents to AI-written exploit scripts |
Strong on alarm, light on commitments
What the letter does not contain is any binding pledge. It carries no deadlines, no spending commitments, and no measurable targets, a gap that security professionals were quick to flag. Practitioners including Diana Kelley and John Gallagher welcomed the attention but questioned the value of a call to action, issued in part by the makers of the models that are sharpening the attacks, that commits none of the signatories to anything specific.
The companies whose models are making cyberattacks faster are now asking everyone, themselves included, to hurry up on defense. The alarm is real. The commitments are not yet.
The letter lands on top of a year of escalating disclosures. US agencies have warned that attackers are using AI to write exploit scripts against industrial controllers, CrowdStrike has described AI as both weapon and target, and OpenAI paused one of its own systems this month over cyber-risk concerns. Wednesday's letter is the industry's attempt to answer that record collectively. Whether it becomes more than a statement will depend on what its signatories fund and ship, not on what they signed.
Santage is committed to independent, transparent journalism. This article is produced in accordance with Santage's Editorial Standards and aims to provide accurate and timely information. Readers are encouraged to verify information independently.