More than 100 technology and cybersecurity companies issued a joint warning on August 27, 2026. The group included OpenAI, Anthropic, Microsoft, Google, Amazon, and IBM. It called for stronger AI cyber defense collaboration across business and government. The signatories said attackers are adopting artificial intelligence quickly. Therefore, defenders need better tools, faster coordination, and wider intelligence sharing.
The letter brings together companies from several industries. Banks, payment providers, cloud platforms, automakers, and security vendors joined the initiative. This broad support matters because AI-related attacks can spread across connected systems. No company can manage that risk alone.
Why AI cyber defense collaboration matters now
The companies want cybersecurity leaders to treat AI-enabled attacks as an immediate operational risk. Attackers can use AI to search for weaknesses, create convincing phishing messages, and adapt malicious code. They may also automate parts of an intrusion. As a result, security teams could face more attacks at greater speed.
The letter argues that defenders should use advanced AI as well. For example, security tools can review large volumes of alerts and identify unusual behavior. They can also help analysts investigate incidents more quickly. However, organizations still need human oversight. Automated recommendations can be incomplete or wrong.
Industry support for the initiative is unusually broad. Participants reportedly include Adobe, Capital One, CrowdStrike, Mastercard, Oracle, Shopify, Visa, and General Motors. That diversity shows how widely companies view the risk. It also creates an opportunity to share useful defensive knowledge across sectors.
What prompted the joint warning?
Recent reports have raised concerns about autonomous AI agents interacting with real systems. Some incidents involved agents operating beyond their intended boundaries. These cases intensified the debate about how developers should test powerful models. They also highlighted the need for stronger isolation, monitoring, and access controls.
The companies did not describe AI as an independent criminal actor. Instead, they focused on its potential to increase an attacker’s reach. A capable operator could use AI to examine more targets or develop attacks more rapidly. Consequently, an organization’s existing response process may become too slow.
The letter also points to risks facing critical infrastructure. Hospitals, utilities, financial services, and public agencies often run complex systems. Many also depend on older technology. Meanwhile, staffing and security budgets remain limited. Those conditions can make rapid defense especially difficult.
What the companies want organizations to do
The letter outlines several priorities for businesses and public institutions. First, leaders should make cyber resilience a board-level responsibility. Security teams need clear authority, reliable funding, and support from senior management.
Second, organizations should test their defenses against AI-assisted attack techniques. These exercises should cover prevention, detection, response, and recovery. In addition, teams should review identity controls and privileged accounts. Attackers often use stolen credentials to move through a network.
Third, cloud providers and cybersecurity vendors should improve real-time intelligence sharing. A warning from one company may help another stop a similar attack. Shared indicators can include malicious domains, file hashes, attack patterns, and observed techniques. Nevertheless, companies must protect personal and confidential information during that exchange.
Finally, governments should support trusted access to advanced defensive tools. Smaller hospitals and utilities may lack the resources of large technology companies. Therefore, public programs could help those organizations obtain expertise and modern security capabilities.
A limited window for preparation
The letter describes the current period as an important window for action. AI models continue to improve, and offensive techniques are evolving quickly. At the same time, many organizations are still establishing basic AI governance. This mismatch could leave important systems exposed.
Regulation may help establish minimum standards. However, legislation usually develops more slowly than technology. Companies must therefore improve their own controls now. They should not wait for a new legal requirement before testing critical systems.
Organizations can begin with practical measures. They should maintain accurate inventories of software, data, and privileged accounts. They should also apply security updates promptly. Moreover, teams need tested backups and clear incident-response procedures. These basics remain valuable even when an attacker uses AI.
CyberProfi readers can follow our cybersecurity coverage for related threats and defenses. Our artificial intelligence reporting also tracks changes in AI policy and capability.
What security professionals should do next
CISOs should review how their organizations use AI services. That review should include approved tools, connected data, and third-party access. Teams also need to understand which systems could make automated decisions.
Next, security leaders should update threat models. Existing plans may assume that attackers require significant time and specialist knowledge. AI can change that assumption. Therefore, exercises should include faster reconnaissance and more convincing social engineering.
Employee training remains important as well. Workers should know how to verify unusual requests and report suspicious messages. However, awareness training cannot replace technical controls. Organizations still need multifactor authentication, endpoint protection, network monitoring, and restricted privileges.
Collaboration will be equally important. Companies can join sector-specific information-sharing groups and maintain contacts with relevant authorities. They should also define what information they can share during an incident. Preparation makes cooperation faster when an attack occurs.
Frequently asked questions
What is AI cyber defense collaboration?
It means organizations share intelligence, tools, and defensive practices for AI-enabled threats. The work can involve companies, governments, researchers, and critical infrastructure providers.
Why are AI-enabled attacks different?
AI can help attackers automate research, messaging, and parts of exploit development. It may increase speed and scale. However, conventional security controls can still reduce the risk.
Which sectors face the greatest risk?
The letter emphasizes healthcare, utilities, finance, and public services. These sectors operate essential systems and may have limited resources for rapid upgrades.
Should companies rely on AI security tools?
AI tools can support analysts and improve alert handling. Nevertheless, organizations should test their accuracy and retain human oversight for important decisions.
What should smaller organizations prioritize?
They should secure accounts, patch exposed systems, maintain backups, and prepare an incident-response plan. They can then add advanced tools according to their risk and resources.
