One of the strongest warnings yet about cybersecurity in the age of artificial intelligence has come from the companies building the technology themselves.
More than 100 technology, artificial intelligence, financial and cybersecurity companies have signed a joint letter calling for a global effort to strengthen defenses against AI-powered cyberattacks.
The signatories include OpenAI, Anthropic, Google, Microsoft, Amazon, IBM, Cloudflare, CrowdStrike and many other major technology companies.
Their message is straightforward:
AI-powered cyberattacks are expected to become more widespread and sophisticated, and the world is not fully prepared for what is coming.
AI Is Changing Both Sides of Cyberwarfare
For years, artificial intelligence has been presented primarily as a defensive cybersecurity tool.
AI can analyze millions of security events, detect suspicious behavior, identify malware and help security teams respond faster.
But the same technology is becoming increasingly useful to attackers.
Modern AI models can analyze code, search for vulnerabilities, automate tasks and adapt during an operation.
That creates a new problem:
Defenders are using AI to fight attackers who are also using AI.
As models become more capable, the gap between a large human hacking operation and an automated cyber operation could become significantly smaller.
Companies Are Calling for a Global Surge in Cyber Defense
The joint letter calls for coordinated action from governments and the private sector to strengthen digital defenses.
The coalition argues that cybersecurity cannot be treated as a problem for individual companies alone.
Critical systems such as hospitals, water treatment facilities, electrical networks and internet infrastructure could become increasingly attractive targets for automated attacks.
That makes this warning different from an ordinary cybersecurity statement.
It comes from a large coalition that includes some of the world’s most powerful AI companies.
The Threat Is Bigger Than Malware
When people hear the phrase “AI-powered cyberattack,” they often imagine malware being automatically generated.
The real threat is much broader.
AI can potentially automate different parts of an operation, including:
- target discovery;
- system analysis;
- vulnerability research;
- code generation and modification;
- more convincing phishing;
- analysis of stolen data;
- automated communication with victims;
- and coordination between multiple stages of an attack.
That could allow attackers to accomplish more with fewer people.
If AI systems become capable of automating larger portions of decision-making, attacks could become not only faster but also much more scalable.
Speed Could Become the Biggest Problem
One of AI’s biggest advantages for attackers could be speed.
A human attacker may need to inspect a system, read documentation and search for vulnerabilities.
An AI system could potentially perform many of those steps much faster.
That creates a situation in which defenders have to respond at the same speed.
A company might have a cybersecurity team monitoring thousands of servers.
An attacker using AI could potentially scan large numbers of systems for weaknesses at a scale that would be difficult for humans to match.
That is why the industry is increasingly interested in automated defense.
Critical Infrastructure Is the Biggest Concern

One of the most alarming aspects of the warning involves critical infrastructure.
Hospitals.
Water systems.
Electrical grids.
Transportation.
Telecommunications.
Financial services.
Internet infrastructure.
These systems are becoming increasingly connected to digital networks.
That means a digital vulnerability can eventually produce physical consequences.
A website attack may be disruptive.
An attack against a hospital or power network can be much more serious.
The companies behind the letter argue that protecting these systems should become a priority before AI models become even more capable.
The Irony: AI Companies Are Warning About Their Own Technology
Perhaps the most interesting part of the story is the irony.
OpenAI, Anthropic, Google and Microsoft are among the companies investing enormous amounts of money into increasingly powerful AI systems.
Now those same companies are warning that the technology could also be used by malicious actors.
That does not mean AI is inherently dangerous.
It means the technology is dual-use.
The same model that can help a security team identify a vulnerability could potentially help someone else exploit it.
That makes cybersecurity one of the most important battlegrounds in the next phase of the AI race.
AI Is Creating a New Identity Problem
Another major change is that AI is no longer being used only by humans.
Companies are increasingly deploying AI agents inside internal systems.
Those agents can have access to email, documents, databases, applications and business systems.
That creates an entirely new category of digital identities.
The question is no longer only:
“Is this person authorized?”
It is also:
“Is this AI agent authorized to perform this action?”
If an AI agent is compromised, the consequences could be much greater than compromising a normal employee account.
An agent may be capable of performing many actions automatically.
That is why cybersecurity companies are increasingly focusing on protecting non-human identities.
A New Arms Race Is Beginning
In practice, this could create a new technological arms race.
AI vs. AI.
Attackers use AI to discover vulnerabilities.
Defenders use AI to detect them.
Attackers automate phishing.
Defenders use AI to identify suspicious communication.
Attackers generate code.
Defenders use AI to analyze it.
Attackers try to move faster.
Defenders have to become even faster.
In this competition, companies with more data, more computing power and better automation systems could have a significant advantage.
Why Should Ordinary Internet Users Care?
It may sound like a story for large corporations.
It is not.
Cyberattacks increasingly affect ordinary users.
Phishing emails can become more convincing.
Scams can become more personalized.
Fake social media profiles can be generated at scale.
Messages can look as if they came from someone you actually know.
As AI improves at language, translation and human-like communication, identifying scams could become increasingly difficult.
That means cybersecurity will no longer be only an IT department problem.
It will become an increasingly important skill for every internet user.
Are We Ready?
Probably not completely.
And that is the central message from the companies.
They are not saying a catastrophe is guaranteed.
They are warning that AI development may be moving faster than improvements in many existing security systems.
If that gap continues to grow, attackers could gain an advantage.
That is why the coalition is calling for:
more investment,
more cooperation,
more information sharing,
more defensive automation,
and stronger policies for protecting critical systems.
Real-World Attacks Show the Problem Is Already Here

The warning arrives at a time when cybersecurity incidents are demonstrating that the threat is not merely theoretical.
This same week, security researchers reported active exploitation of a vulnerability affecting Citrix NetScaler appliances.
CISA added CVE-2026-8452 to its Known Exploited Vulnerabilities catalog and ordered U.S. federal agencies to address the issue by August 29.
NIST’s National Vulnerability Database describes the flaw as a memory overflow vulnerability affecting NetScaler ADC and Gateway products, with potentially serious impacts on confidentiality, integrity and availability.
That illustrates an important point.
Cybersecurity is not only about what AI might do in the future.
Attackers are already targeting the infrastructure businesses depend on today.
The Future of Cybersecurity Could Be AI Against AI
A few years ago, AI in cybersecurity was largely experimental.
Today, it is becoming part of the infrastructure.
Tomorrow, it may become a necessity.
If attackers use AI to automate attacks at massive scale, manual defense will no longer be enough.
A human analyst reviewing one alert at a time cannot compete with an automated system capable of analyzing millions of signals.
That is why the warning from more than 100 companies matters.
They are not simply asking for more cybersecurity.
They are asking for a fundamental change in how the world approaches digital security.
Because in the AI era, the question is no longer simply:
“Can this system be hacked?”
The new question is:
“How quickly can an attack be discovered, automated and repeated?”
And if the answer is “within minutes,” defensive systems will have to move just as quickly.
A new technological arms race may already be beginning:
Human vs. AI.
AI vs. AI.
And this time, the battlefield is the entire internet.
