
AI cyberattacks: on August 27, 2026, OpenAI, Anthropic, Google, Microsoft and more than 130 other companies published an unprecedented open letter titled "A call for collective action on cyber defense." Their message is direct: AI-powered cyberattacks will become more frequent and more sophisticated in the coming months. For an SMB, this is not an abstract warning reserved for large corporations. It is a signal to translate into concrete actions before the end of the year.
Key takeaways
- On August 27, 2026, more than 130 companies (OpenAI, Anthropic, Google, Microsoft, AWS, Cisco, Cloudflare, CrowdStrike, IBM, Oracle, Visa, Capital One) signed a joint open letter on cyber defense.
- The letter warns that AI-powered cyberattacks will become "far more widespread and sophisticated" in the coming months as models advance.
- According to CrowdStrike's 2026 report, AI-assisted attacks rose 89% in 2025 compared to 2024.
- Three weaknesses remain the classic entry point: unpatched legacy bugs, excessive permissions and misconfigurations, and weak authentication.
- The coalition calls for equipping defenders (not just attackers) with AI tools, sharing threat intelligence faster, and modernizing legacy systems.
- For an SMB, the priority is not panic but fixing known weaknesses (patches, access control, passwords) before the cost of an attack drops further.
What the open letter says
The text, published on OpenAI's website and covered by Axios, CBS News and Engadget, brings together an unusual mix of signatories: competing AI labs (OpenAI, Anthropic, Google, Perplexity), cloud giants (AWS, Microsoft, Oracle), cybersecurity specialists (Cisco, Cloudflare, CrowdStrike, Palo Alto Networks), and financial institutions (Visa, Citi, Capital One). Such a coalition of direct competitors is rare: it reflects a genuine consensus on the urgency of the issue rather than an isolated PR move.
The letter points to concrete targets: hospitals, water treatment networks and critical internet infrastructure. It explains that AI models, by lowering the technical skill required to carry out an attack, also reduce its cost for the attacker. An actor who previously needed to hire a specialized team can now rely on generative AI tools to automate reconnaissance, write exploit code, or bypass certain defenses.
What the letter does not say
The text does not cite any large-scale attack already carried out using generative AI. This is a preventive warning, based on how model capabilities are evolving, not a report of damage already observed. That distinction matters: the risk is real and documented, but it remains anticipatory.
Why the window is closing now
Three factors explain the urgency the signatories describe. First, the speed at which generative AI models are advancing, now able to handle increasingly complex tasks autonomously. Second, the continuing drop in the cost of accessing these models, which puts capabilities once reserved for sophisticated attackers within reach of far more actors. Third, the accumulation of technical debt in existing systems: unpatched software, weak passwords, misconfigured permissions.
The coalition's three principles
Recognize that the status quo is not enough
Equip defenders with AI tools
Mobilize a collective response
Weaknesses cited and what they mean for an SMB
| Weakness cited in the letter | What it means for an SMB |
|---|---|
| Unpatched legacy bugs | Software or a plugin never updated in months is an open door. |
| Excessive permissions | Too many accounts have access to too much data; a single stolen password can compromise everything. |
| Misconfigurations | A misconfigured cloud service (open storage, missing firewall) remains the most common cause of data leaks. |
| Weak authentication | The absence of two-factor authentication (2FA) remains, according to security firms cited, one of the most exploited entry points. |
| Technical debt in legacy systems | Old business software, rarely audited, often runs without active security monitoring. |
What an SMB should do within 90 days
Audit access rights
Turn on two-factor authentication everywhere
Update critical software
Set boundaries for internal AI use
None of these actions require a large-company budget. They mainly require discipline and a clearly identified owner internally, even part-time, to follow up on these points.
FAQ
What is the "A call for collective action on cyber defense" letter?
It is an open letter published on August 27, 2026 by OpenAI and signed by more than 130 companies, including Anthropic, Google, Microsoft, AWS and CrowdStrike. It calls for collective action against the rise of AI-powered cyberattacks and proposes three principles: recognizing that current defenses are insufficient, equipping defenders with AI tools, and mobilizing a coordinated response.
Is an SMB really affected by this risk?
Yes. The letter targets critical infrastructure (hospitals, water networks), but the mechanism it describes, the falling technical cost of an attack thanks to AI, affects any internet-connected organization, including SMBs, which are often less protected than large corporations.
What does the 89% figure from CrowdStrike mean?
According to CrowdStrike's 2026 report, AI-assisted attacks rose 89% in 2025 compared to 2024. It is a measure of the underlying trend that justifies the coalition's warning, not a forecast for any specific company.
Should SMBs switch AI providers because of this warning?
No. The letter does not single out any specific provider: OpenAI, Anthropic, Google and Microsoft are themselves signatories. The issue is not which AI tool to use, but how securely it is used (access, permissions, authentication).
In conclusion
This open letter marks an unusual moment: direct competitors in AI and cloud computing publicly agreeing on the same diagnosis. For an SMB, the useful takeaway is not the size of the coalition but the very concrete list of weaknesses it cites: unpatched bugs, excessive permissions, weak authentication. These are exactly the points a small organization can fix within a few weeks, without a large-company budget. To go further on securing AI tools in your business, read our article on securing AI connectors or browse all our Mag resources.


