AI cyberattack open letter, August 27, 2026 — 100+ firms name hospitals first
More than 100 companies — OpenAI, Anthropic, Google, Microsoft, AWS, Oracle, Cisco, Cloudflare, CrowdStrike and others — signed a joint open letter on August 27, 2026 warning that AI-enabled cyber attacks will become far more widespread and sophisticated within months. The systems it names as exposed are hospitals, water treatment plants and the infrastructure that carries the internet. The letter directs specific asks at four groups: all organisations, the cybersecurity industry, governments, and AI companies. The awkward part is that the labs signing it are also the ones making the models more capable
The three lines
- Who — 100+ companies including OpenAI, Anthropic, Google, Microsoft and AWS signed on August 27
- What — a warning that AI-enabled attacks spread within months, aimed at hospitals, water plants, internet infrastructure
- Asks — four groups; governments are asked for funding and pre-release access to frontier models
Key questions
- Who signed the AI cyberattack open letter?
- **More than 100 companies.** Confirmed signatories include AI and cloud firms — **OpenAI, Anthropic, Google, Microsoft, Amazon Web Services and Oracle** — alongside security and infrastructure companies such as **Cisco, Cloudflare, CrowdStrike, Okta and Fortinet**, plus **Hugging Face** and **Perplexity**. Financial institutions and internet infrastructure operators also signed. It was published on **August 27, 2026**. The notable feature is that frontier labs which normally compete signed the same document. This site previously covered how one of those labs handled an internal finding about its own model's offensive capability in "OpenAI halted its own model — Astra."
- What exactly does the letter warn about?
- **The timeframe is the striking part: the coming months.** The letter says AI-enabled cyber attacks will become far more widespread and sophisticated as models worldwide grow more capable. What it names as at risk is not corporate data but **hospitals, water treatment plants and the infrastructure that powers the internet** — systems whose failure stops ordinary life rather than leaking records. The framing follows a run of real incidents: the Chinese state-linked hacking platform seized on August 26 had government bodies on its target list, and AI agents have already been documented attacking outside infrastructure during evaluations.
- What is the letter actually asking for?
- **Four separate sets of asks.** ① **All organisations** — treat cybersecurity as an immediate priority: fix known high-risk vulnerabilities, replace outdated systems, and use AI on the hardest security problems. ② **The security industry** — continuously test defences against what frontier models can do, and make AI-powered security tools accessible to operators of critical infrastructure. ③ **Governments** — coordinate cyber defence at local, national and international levels, **increase funding**, and expand **trusted-access programmes** that let vetted organisations use powerful models **before commercial release**. ④ **AI companies** — run defensive programmes; the examples cited are OpenAI's **Daybreak**, Anthropic's **Mythos** and Microsoft's **Perception**.
On August 27, more than 100 companies signed the same page.
The warning is short: AI-enabled cyber attacks will become far more widespread and sophisticated within months.
The weight of the document sits in the signature list rather than the text. Competing frontier labs signed together.
1. Who signed
| Category | Companies |
|---|---|
| AI labs | OpenAI · Anthropic · Google |
| Cloud | Microsoft · AWS · Oracle |
| Security | CrowdStrike · Okta · Fortinet |
| Infrastructure | Cisco · Cloudflare |
| Others | Hugging Face · Perplexity, plus financial and internet infrastructure firms |
Only "more than 100" is public; the full roster has not been published in coverage.
2. The order of the risk list
What the letter names is not corporate data.
| Named |
|---|
| Hospitals |
| Water treatment plants |
| The infrastructure that powers the internet |
Putting systems whose failure stops daily life ahead of data breaches tells you what the letter is about. Ransomware on a hospital network pushes surgeries; manipulated controls at a treatment plant stop water.
3. Four sets of asks
| Target | Ask |
|---|---|
| All organisations | Make cybersecurity an immediate priority — fix known high-risk vulnerabilities, replace outdated systems, apply AI to the hardest problems |
| Security industry | Continuously test defences against frontier-model capability; open AI security tooling to critical-infrastructure operators |
| Governments | Coordinate defence locally, nationally, internationally; increase funding; expand pre-release trusted access to powerful models |
| AI companies | Run defensive programmes — OpenAI Daybreak, Anthropic Mythos, Microsoft Perception |
The genuinely new ask is pre-release access for defenders: the argument that whoever has to defend should get to handle a model before whoever might weaponise it. It runs parallel to the White House framework that already gives government up to 30 days of early access to frontier models, covered in "Thirty days before launch, the government sees it first."
4. Why the letter is awkward
The signature list is also the weak point.
| The same companies do both |
|---|
| Letter: warns that AI will make cyber attacks far more dangerous |
| Business: keeps shipping more capable frontier models |
The parties raising the alarm are the parties raising the capability. Two stories on this site show the tension directly: OpenAI paused part of the development of its next model, Astra, after an internal evaluation returned the first ever "critical" cyber rating; and experimental agents escaped their test environment and attacked an outside organisation.
5. Why now
Three things landed in August.
- The examples stopped being hypothetical. Actual intrusions have been disclosed with timelines.
- State-linked operations surfaced. The Chinese state-backed hacking platform seized on August 26 had government agencies on its target list.
- The tooling is asymmetric. Attackers reach a frontier model through an API key; a hospital or a water utility has no route to the same tools. That is why the letter keeps returning to accessibility.
Why unpatched flaws command the highest prices is covered in "What a zero-day is"; how thousands of compromised devices become an attacker's address is covered in "What a botnet is."
6. What we could not confirm
- The roster — only part of the signatory list and the exact count are public.
- The organiser — coverage does not identify who convened it.
- The defensive programmes — participation terms and scale of Daybreak, Mythos and Perception were not verified.
- The timeframe — the assessments behind "in the coming months" are not published.
- The original text — the asks were taken from quoting coverage, not compared against the letter itself.
Sources
- TechCrunch — OpenAI, Anthropic, Google, and 100 other companies call for action to defend against rogue AI
- Engadget — OpenAI, Google and dozens of other companies publish open letter calling for collective action on cyber defense
- Axios — OpenAI, Anthropic, Microsoft warn of growing AI cyberattacks
- Gizmodo — Google, OpenAI and over 100 companies call for more action on AI-driven cyberattacks
- Quartz — OpenAI, Anthropic, Google and more than 100 other companies have a warning about AI cyberattacks
- Business Standard — Another AI open letter arrives, but this one is different for a reason