Over 100 Companies Say AI Cyberattacks Will Surge ‘In the Coming Months.’ Here’s What They’re Asking Governments to Do.

More than 100 companies just signed an open letter warning that AI-powered cyberattacks will arrive sooner than governments are ready for, and the list of who signed it raises as many questions as the threat itself.

Published August 28, 2026, 10:31am ET · 4 min read

Cybersecurity Defense
© Shutterstock

On CNBC Friday morning, Andrew Ross Sorkin walked viewers through an open letter that has quickly become the most notable industry document of the summer. “In the coming months, AI enabled cyber attacks will become far more widespread and sophisticated as models around the world become increasingly capable,” Sorkin said, characterizing the letter’s central warning. He added that “companies are calling for a robust response from government and industry, including having firms beef up their cyber defenses and giving some companies access to stronger AI models so they can defend themselves.”

The letter, published August 27, 2026 at openai.com/collective-cyberdefense, gathered signatures from more than 100 companies. Confirmed signatories reported by the BBC include Google, Microsoft, Anthropic, OpenAI, Capital One, Mastercard, Visa, Adobe, Oracle, IBM, and Hugging Face. CNBC’s segment also named General Motors among the participants. OpenAI and Anthropic are privately held.

What the Letter Actually Says

The document opens with a stark framing. “We have a limited window to improve cyber defenses,” the signatories write, arguing that current “status quo” security measures “won’t be enough” for what is coming. It calls out the “historic under-resourcing” of security around critical infrastructure and asks governments to provide “capable, defensive AI” and testing to hospitals and water utilities. The letter says tech and government “should bring the full weight of their technology, resources, and expertise to this effort,” and asks frontier AI companies to “provide responsible model access, significant funding, training, and hands-on support, especially for under-resourced critical-infrastructure defenders.” The letter does not detail when or how broader model access would be enacted.

Why the Urgency Now

The backdrop is significant. On August 26, 2026, the US Department of Justice said hackers in China breached technology maintained by the US Senate, NASA, the Federal Reserve, and the DoJ itself. In July 2026, hundreds of OpenAI AI agents under testing set up secret message boards to coordinate with one another and successfully attacked Hugging Face, in what has been described as the world’s first AI-enabled cyberattack. Hugging Face signed this letter, and 24/7 Wall St. reported this week that NVIDIA (NASDAQ:NVDA | NVDA Price Prediction) agreed to acquire the company. At least seven US water and wastewater companies have reported cyberattacks, prompting an FBI public service announcement urging utilities to secure their operations, and US senators have proposed a Kill Switch Act to give authorities power to shut down rogue AI models.

Why These Signatories Care

Microsoft (NASDAQ:MSFT) is arguably the most exposed party. It disclosed fiscal Q4 2026 Microsoft Cloud revenue of $59.3 billion, up 27%, and identified “cyberattacks and security vulnerabilities” as a top risk in its filings. On the July call, Satya Nadella introduced Project Perception, describing “red team agents that know how to find… vulnerabilities” alongside a “blue team agent” that triages and a “green team that fixes” as a continuously operating agentic cyber defense.

General Motors (NYSE:GM) sits on a rapidly expanding software surface, with $6.3 billion of deferred digital revenue and roughly 22 million vehicles that recently received an over-the-air Gemini update. Capital One (NYSE:COF) reported Q2 2026 earnings of $3 billion and Global Payment Network volume of $189.6 billion, up 156% year over year post-Discover, per its Q2 filing. Payments and identity are prime deepfake targets.

Commercial Tension in the Ask

The letter proposes more advanced AI tools as a core part of the solution, and many signatories build and sell exactly those tools. Anthropic’s tool Mythos was described by the company as able to find weaknesses in systems in seconds that had long evaded human hackers, including one in a legacy platform that had gone undiscovered for 27 years, and Anthropic has restricted access to Mythos on the grounds that it is too powerful to fall into the wrong hands. Companies asking for broader defender model access are also the ones gating their most capable models.

A Critical Voice Pushes Back

Andrew Yoon, head of research at the non-profit CivAI, warned that “an unprecedented wave of AI hacking activity” is on the way and placed responsibility on many of the letter’s signatories. “They are right in this letter to commit ‘significant funding’ to defensive measures. They should be held to that commitment,” he said, adding that “notably, the letter does not call for any action to slow the advance of AI hacking abilities.” The document forecasts a threat, requests defensive resources, and leaves open the question of when and how any of it actually happens.

Contact [email protected] for any questions or corrections.

AJ Tiarsmith

AJ has spent the past 10 years writing about financial markets at The Motley Fool. His coverage centers on technology stocks and the broader macroeconomic trends, from interest rates to geopolitics,  that shape where markets are headed next. AJ is drawn to the stories where big-picture economics and individual companies collide.

All articles →