Over 100 Tech Companies Sign Open Letter Warning of Imminent AI-Powered Cyber Attacks

OpenAI, Google, Anthropic, and more than 100 other companies have signed an open letter titled "A call for collective action on cyber defense," published August 27, 2026, at openai.com/collective-cyberdefense. The letter calls for "a global surge in cyber defense" and warns that "In the coming months, AI-enabled cyber attacks will become far more widespread and sophisticated as models around the world become increasingly capable." TechCrunch reported the total signatory count exceeds 100 companies.
The signatory list spans AI labs, major cloud providers, and the cybersecurity establishment. Named signatories include Anthropic, AWS, Cisco, Cloudflare, CrowdStrike, Google, Hugging Face, IBM, Microsoft, OpenAI, Oracle, Perplexity, and HackerOne, among others. Engadget confirmed the core signatories, with additional names verified against the original source.
The letter lays out three core principles: "Recognize that status quo security won't be enough," "Empower more defenders with cyber-capable AI," and "Mobilize a collective response." It then prescribes specific actions for organizations, governments, the cybersecurity and tech industry, and AI businesses, all aimed at preventing a surge in attacks powered by artificial intelligence.
For organizations, the letter urges making cybersecurity a high priority. For frontier AI companies specifically, the proposed actions include building observability and security tools, ensuring that agentic identities are traceable and accountable, and sharing best practices in continuous monitoring. The letter also calls for strengthening open-source maintainers as part of the broader cyber defense effort, and for forming "new partnerships" to "raise security standards."
The breadth of the signatory list is itself worth noting. Having AWS, Cisco, Cloudflare, and CrowdStrike alongside OpenAI, Anthropic, and Google on the same document means the infrastructure layer and the model layer are publicly aligning on a shared threat model. The inclusion of HackerOne brings the offensive-security community, those who find vulnerabilities by probing systems, into the tent. Hugging Face's participation ensures the open-source machine learning ecosystem is represented.
The prescriptions directed at frontier AI companies are the most technically substantive part of the letter. The call for ensuring agentic identities are traceable and accountable speaks directly to the emerging architecture of autonomous AI agents, programs that take actions on behalf of users across multiple systems. If agents are to operate with elevated privileges in production environments, attributing their actions, auditing their decisions, and holding them accountable becomes a foundational security requirement, not an add-on. This is adjacent to the zero-trust access-control questions enterprises have been working through for human and service accounts, now extended to non-human, probabilistic actors.
The demand for observability and security tools, plus shared best practices in continuous monitoring, aligns with how the DevSecOps and cloud-native communities already operate. Applying those disciplines to model deployment and agent runtime environments is a logical extension. The reference to open-source maintainers acknowledges a real structural vulnerability: critical infrastructure dependencies often rely on under-resourced open-source projects, and AI-powered vulnerability discovery could accelerate exploitation of that surface area.
What the letter does not do is equally notable. It is a call to action, not a binding framework or a standards specification. The principles are directional rather than prescriptive. There is no enforcement mechanism, no certification body, and no technical specification for how agentic identity tracing should be implemented.
The broader context here is that the letter's framing of the threat timeline matters. By warning that AI-enabled attacks will become more widespread "in the coming months," the signatories are treating this as an imminent operational concern rather than a distant hypothetical. That compressed timeline is what gives the letter its urgency, and it is presumably what motivated over 100 companies to put their names on a public document.
The optimistic read, and the one the letter's structure implicitly encourages, is that the same technology enabling attacks can empower defenders. The principle of empowering defenders with "cyber-capable AI" is an acknowledgment that AI-driven threat detection, automated response, and vulnerability research are the tools that will be needed. If the industry follows through on the information-sharing and partnership commitments, the defensive advantage of collective intelligence could outweigh the offensive advantage of individual capability. That outcome is not guaranteed, but the alignment on display in this letter is a necessary precondition for it.


