News
OpenAI, Google and Microsoft Among 116 Companies Calling for Joint Defense Against AI Cyberattacks

OpenAI, Anthropic, Google, Microsoft and more than a hundred other companies have signed a joint open letter warning that only months remain to strengthen defenses against AI-powered cyberattacks.
OpenAI, Anthropic, Google, Microsoft, Amazon Web Services and dozens of other technology, financial and insurance companies signed a joint open letter on Thursday, August 27, 2026. The signatories warn that defenders of computer systems have only a few months left before AI-powered attacks become effective enough to overwhelm the security teams responsible for stopping them.
Who signed the letter
The letter was initiated by OpenAI, which published it on its own website under the title of a call for collective action on cyber defense. Nearly all the biggest players in the language model and cloud computing markets joined in: Anthropic, Google, Microsoft and Amazon Web Services. The signatories also include specialized cybersecurity firms Cisco, Cloudflare, CrowdStrike, IBM and Oracle, as well as Hugging Face and Perplexity.
The document was also signed by institutions outside the technology sector that manage clients' cyber risk on a daily basis: banks Citi and Capital One, and insurers Marsh and Zurich. In total, 116 companies and organizations signed the letter, making it one of the broadest joint industry declarations on AI-related threats in recent months.
A narrowing window
The letter's central message is a warning that AI-based offensive capabilities are advancing faster than the defensive capabilities of the organizations that must guard against them. The authors stress that today's AI advances also give defenders new tools to fix gaps that have built up over years, but only if action is fast and coordinated.
We have a limited window to strengthen cyber defense - from the open letter of signatories of the call for collective action on cyber defense
The letter explicitly names which institutions are most exposed to the consequences of this timing gap. Hospitals, water treatment plants and other critical infrastructure facilities rarely have budgets and staffing comparable to large corporations, yet they are increasingly becoming targets of attacks that AI has made cheaper and easier to carry out than just a few years ago.
Specific demands
The letter sets out separate demands for four groups of addressees. Organizations are urged to prioritize cybersecurity investment, replace outdated systems and strengthen their security teams. Cybersecurity companies are called on to continuously test their defenses against evolving attacker capabilities and to share threat intelligence and proven incident response procedures.
The signatories ask governments to coordinate action at the local, national and international levels and to fund providers of essential public services that lack the staff or budget for adequate protection. Companies developing the most advanced AI models, meanwhile, are asked to build monitoring and observability tools, ensure traceability and accountability for autonomous agents' actions, and give defenders access to their most advanced models during major incidents, along with substantial funding, training and direct support.
If we act decisively, we can use the defenders' window to make our digital world significantly safer - from the open letter of signatories of the call for collective action on cyber defense
Context and doubts
The letter comes after a string of high-profile AI security incidents in recent weeks, including an attack in which an autonomous OpenAI agent gained unauthorized access to Hugging Face's systems. Some commentators have pointed out the paradox of the situation: companies that develop and sell the technologies enabling increasingly effective attacks are now calling for collective defense against the consequences of their own products.
The signatories also cite CrowdStrike data showing that the number of AI-powered attacks rose 89 percent in 2025 compared with the previous year. That figure differs from the previously cited 56 percent increase in an IBM report, showing that different companies measure the scale of the phenomenon differently, even though the direction of the trend is consistent.
For Polish companies and public institutions that are still building their AI incident response procedures, the letter signals that the problem is not limited to the largest corporations. Hospitals, water utilities and local governments in Poland typically have much smaller cybersecurity budgets than their Western counterparts, and it is precisely these kinds of entities that the letter identifies as most exposed to AI-powered attacks.