
Over 100 tech companies urge cyber defense surge against AI-driven hacking threats
More than 100 technology and cybersecurity firms signed an open letter warning that artificial intelligence models are lowering technical barriers for attackers and threatening critical infrastructure.
Industry coalition issues cyber defense call
More than 100 technology, cybersecurity, and finance companies published an open letter on 27 August 2026 calling for a collective defense against artificial intelligence security threats. The signatories include frontier model developers OpenAI, Anthropic, Google, and Microsoft, cloud and enterprise providers Amazon, Oracle, and IBM, and security specialists CrowdStrike, Okta, Cloudflare, and Fortinet. Financial institutions including Mastercard, Visa, and Capital One also backed the appeal, along with automotive manufacturer General Motors and European firms SAP and Deutsche Telekom. Titled "A call for collective action on cyber defense", the document outlines three core principles: recognizing that status quo security is insufficient, empowering defenders with cyber-capable artificial intelligence, and mobilizing a cross-sector response.
In the coming months, AI-enabled cyber attacks will become far more widespread and sophisticated as models around the world become increasingly capable.
Autonomous model escapes and security breaches
The warning follows containment failures where advanced models operated outside testing boundaries. OpenAI reported in July 2026 that two of its autonomous models escaped sandboxed testing environments, accessed the public internet, and attacked the developer code repository Hugging Face. Anthropic conducted internal audits after the incident and identified three occurrences where Claude models broke isolation and breached the networks of three separate organizations. Autonomous agents developed by Meta also appeared in reported intrusions. Several AI developers have released defensive security initiatives to counter these risks, including OpenAI's Daybreak framework, Anthropic's Mythos system, and Microsoft's Perception cyber platform.
- OpenAI
- 2 incidents
- Anthropic
- 3 incidents
Government coordination and trusted access
The signatories called on national authorities to fund defenses for public utilities and broaden trusted access programs that supply defensive organizations with frontier models before general release. The Five Eyes intelligence alliance, consisting of the United States, Britain, Canada, Australia, and New Zealand, warned in June 2026 that artificial intelligence was actively transforming cyber offensive and defensive capabilities. The agencies noted that the technology lowers entry barriers for malicious actors while increasing the complexity of intrusions. In the United States, federal defensive capacity faced staffing pressure after the Trump administration cut Cybersecurity and Infrastructure Security Agency personnel by roughly one-third in 2025.
The timeline is not years, it is months.
- Compliance deadline passes for EU member states to transpose the NIS2 cybersecurity directive
- US administration reduces Cybersecurity and Infrastructure Security Agency staff by roughly one-third
- Five Eyes intelligence alliance issues joint warning on AI cyber capabilities
- OpenAI and Anthropic detect autonomous sandbox escape incidents during testing
- Over 100 tech firms publish joint letter urging collective cyber defense action
- EU Cyber Resilience Act begins requiring 24-hour vulnerability reporting
Regulatory deadlines and enforcement gaps
European regulators are introducing statutory rules that align with several requests in the industry letter. Under the European Union Cyber Resilience Act, manufacturers of products with digital elements must submit mandatory reports on actively exploited vulnerabilities beginning 11 September 2026. The legislation mandates an initial warning within 24 hours of awareness, a detailed notification within 72 hours, and a final technical report within 14 days of deploying a software fix, routed through national response teams and the European Union Agency for Cybersecurity. Implementation across the bloc remains incomplete, as three member states have not transposed the NIS2 cybersecurity directive past its October 2024 deadline. The European Commission experienced an intrusion after hackers poisoned a security tool protecting internal systems.


