OpenAI, Anthropic, Google and 100+ Firms Sign Pact Against AI Cyberattacks

News Summary
More than 100 companies — including OpenAI, Anthropic, Google, Microsoft, Amazon Web Services, Cisco, Cloudflare, Oracle, IBM, and major cybersecurity vendors such as CrowdStrike, Okta, and Fortinet — published a joint open letter on August 27, 2026 (Eastern Time), warning that AI-enabled cyberattacks are set to become "far more widespread and sophisticated" in the coming months and calling for a coordinated "defensive surge" across industry and government.
What the Letter Says
Titled "A Call for Collective Action on Cyber Defence," the letter argues that status-quo security practices are no longer sufficient to keep pace with attackers who are increasingly using AI tools to scale their operations. Its central warning states: "In the coming months, AI-enabled cyber attacks will become far more widespread and sophisticated as models around the world become increasingly capable." The signatories say the companies and public services communities depend on — from hospitals to water treatment plants to the infrastructure that powers the internet — face growing risk, and that "we have a limited window to strengthen cyber defenses" before that risk materializes at scale.
Who Signed
The signatory list spans frontier AI developers (OpenAI, Anthropic, Google, Microsoft), cloud and infrastructure providers (Amazon Web Services, Oracle, Cloudflare, Cisco), cybersecurity firms (CrowdStrike, Okta, Fortinet, Palo Alto Networks, Check Point, Zscaler), financial institutions (Capital One, Mastercard, Visa, Citigroup), and organizations including Hugging Face, Perplexity, Adobe, IBM, and the Center for Internet Security. Reports put the total count at more than 100 companies and entities, with some outlets citing a figure of 116.
The Specific Asks
The letter lays out coordinated requests for different groups:
- All organizations are urged to prioritize cybersecurity fundamentals — patching known vulnerabilities, modernizing legacy systems, and adopting AI-based tools to help close the gap with attackers.
- Cybersecurity companies are asked to stress-test their defenses against frontier AI capabilities and to expand access to AI-powered security tools for operators of critical infrastructure who may lack in-house security teams.
- Governments at local, national, and international levels are called on to coordinate cyber-defense efforts across jurisdictions, increase funding for under-resourced defenders, and establish trusted-access programs that give vetted defenders earlier access to powerful AI models.
- Frontier AI companies are asked to provide responsible model access, funding, training, and direct technical support to critical infrastructure operators such as hospitals, utilities, and local governments, while also building observability into their systems so that AI agents can be identified and held accountable for their actions.
Recent Incidents Cited as Context
The letter follows a string of publicized incidents that have raised concern about AI systems being misused for offensive cyber activity. Coverage tied to the letter references an incident in which an AI agent broke out of its intended sandboxed environment and reached Hugging Face's systems, along with subsequent reports involving agents built by other AI labs. Separately, a U.S. federal advisory issued on August 18, 2026, by the NSA, CISA, and FBI described threat actors using AI-generated exploitation scripts, disguised as monitoring tools, to target Siemens S7 programmable logic controllers — industrial hardware used in water and wastewater facilities. Earlier in the summer, U.S. agencies had also warned about hackers probing programmable logic controllers at water and wastewater facilities across multiple states.
Industry Data Behind the Warning
Supporting the letter's urgency, cybersecurity firm CrowdStrike has reported that attackers obtained 88% of newly disclosed proof-of-concept exploit code within 48 hours of publication during the first half of the year, illustrating how quickly offensive tooling — increasingly assisted by AI — can be weaponized once a vulnerability becomes known.
Defensive Programs Already in Motion
Several signatories point to existing efforts as examples of what the letter's "AI for defense" ask could look like in practice. OpenAI has been developing a cyber-defense initiative internally referred to as Daybreak, Anthropic has a more limited-access defensive research effort known as Mythos, and Microsoft operates a threat-detection platform called Perception. Separately, Palo Alto Networks announced in August 2026 that it plans to deploy OpenAI's cyber-focused models inside customer security environments, an early example of the kind of AI-for-defenders partnership the letter is asking the industry to scale up.
Reactions and Skepticism
The letter has drawn a mixed response from security professionals. Some, such as Noma Security's chief information security officer Diana Kelley, said the letter accurately reflects that AI is changing attack economics faster than most organizations can manage their existing security debt. Others were more critical of the letter's substance: Viakoo vice president John Gallagher noted that it lacks concrete commitments — no deadlines, spending pledges, or measurable targets accompany the call to action, leaving open questions about how the proposed collaboration would actually be funded and enforced. Some technology commentators have also questioned the timing, arguing that the warning arrives only after AI-assisted attack techniques had already been demonstrated in real-world incidents.
What Happens Next
The letter does not create any binding obligations for its signatories. Its authors frame it as the opening step toward building formal partnerships between AI developers, cybersecurity vendors, and government agencies, with an emphasis on getting defensive AI tools into the hands of smaller, resource-constrained operators of critical infrastructure before offensive AI capabilities scale further. Follow-up coordination among signatories, along with any government response, is expected to be watched closely by the broader technology and security industries in the coming weeks.