Over 100 Tech Companies Are Warning That AI Could Supercharge Cyber Attacks. Here's What They Want Done.

OpenAI, Google, Anthropic, and more than 100 other companies have signed an open letter titled "A call for collective action on cyber defense," published August 27, 2026, at openai.com/collective-cyberdefense. The letter calls for "a global surge in cyber defense" and warns that "In the coming months, AI-enabled cyber attacks will become far more widespread and sophisticated as models around the world become increasingly capable." TechCrunch reported the total signatory count exceeds 100 companies.
The signatory list includes AI labs, major cloud providers, and cybersecurity firms. Named signatories include Anthropic, AWS, Cisco, Cloudflare, CrowdStrike, Google, Hugging Face, IBM, Microsoft, OpenAI, Oracle, Perplexity, and HackerOne, among others. Engadget confirmed the core signatories, with additional names verified against the original source.
The letter lays out three core principles: "Recognize that status quo security won't be enough," "Empower more defenders with cyber-capable AI," and "Mobilize a collective response." It then prescribes specific actions for organizations, governments, the cybersecurity and tech industry, and AI businesses, all aimed at preventing a surge in attacks powered by artificial intelligence.
For organizations, the letter urges making cybersecurity a high priority. For frontier AI companies specifically, the proposed actions include building observability and security tools, ensuring that agentic identities are traceable and accountable, and sharing best practices in continuous monitoring. The letter also calls for strengthening open-source maintainers as part of the broader cyber defense effort, and for forming "new partnerships" to "raise security standards."
The range of companies on the signatory list is itself worth noting. Having AWS, Cisco, Cloudflare, and CrowdStrike alongside OpenAI, Anthropic, and Google on the same document means the companies that build AI models and the companies that run the internet's infrastructure are publicly agreeing on a shared view of the threat. The inclusion of HackerOne brings in the offensive-security community, those who find vulnerabilities by probing systems. Hugging Face's participation ensures the open-source machine learning ecosystem is represented.
The prescriptions for frontier AI companies are the most technically substantive part of the letter. The call for ensuring agentic identities are traceable and accountable speaks to a new type of software: autonomous AI agents, programs that take actions on behalf of users across multiple systems. Think of an AI agent like a digital assistant that can book flights, move money, or change settings across different apps. If these agents are going to operate with elevated access, then being able to trace who did what, audit their decisions, and hold them accountable becomes a basic security requirement, not an add-on. This is similar to how companies already control access for human employees and automated service accounts, now extended to non-human, probabilistic actors.
The demand for observability and security tools, plus shared best practices in continuous monitoring, aligns with how security teams in the cloud-native world already operate. Applying those same disciplines to model deployment and agent runtime environments is a logical extension. The reference to open-source maintainers acknowledges a real structural vulnerability: critical infrastructure often depends on under-resourced open-source projects, and AI-powered vulnerability discovery could accelerate exploitation of that surface area.
What the letter does not do is equally notable. It is a call to action, not a binding framework or a standards specification. The principles are directional rather than prescriptive. There is no enforcement mechanism, no certification body, and no technical specification for how agentic identity tracing should be implemented.
The broader context here is that the letter's framing of the threat timeline matters. By warning that AI-enabled attacks will become more widespread "in the coming months," the signatories are treating this as an imminent operational concern rather than a distant hypothetical. That compressed timeline is what gives the letter its urgency, and it is presumably what motivated over 100 companies to put their names on a public document.
The optimistic read, and the one the letter's structure implicitly encourages, is that the same technology enabling attacks can empower defenders. The principle of empowering defenders with "cyber-capable AI" is an acknowledgment that AI-driven threat detection, automated response, and vulnerability research are the tools that will be needed. If the industry follows through on the information-sharing and partnership commitments, the defensive advantage of collective intelligence could outweigh the offensive advantage of individual capability. That outcome is not guaranteed, but the alignment on display in this letter is a necessary precondition for it.


