cd /news/ai-safety/openai-anthropic-and-over-100-firms-… · home topics ai-safety article
[ARTICLE · art-115072] src=startupfortune.com ↗ pub= topic=ai-safety verified=true sentiment=↓ negative

OpenAI, Anthropic and Over 100 Firms Warn AI Cyberattacks Are Months Away

OpenAI, Anthropic, Microsoft and more than 100 other organizations warned that AI-powered cyberattacks on hospitals, water systems and internet infrastructure are months away, not years, citing CrowdStrike's 2026 Global Threat Report showing AI-enabled adversary operations rose 89% year over year and average eCrime breakout time fell to 29 minutes. Anthropic reported that 33% of banned malicious Claude accounts in the first half of the year were rated medium risk or higher, rising to 56% in the second half, while CrowdStrike's fiscal Q2 revenue reached $1.47 billion, up 26%.

read5 min views2 publishedAug 29, 2026
OpenAI, Anthropic and Over 100 Firms Warn AI Cyberattacks Are Months Away
Image: Startupfortune (auto-discovered)

OpenAI, Anthropic, Microsoft and more than 100 other organizations are warning that AI-powered cyberattacks on hospitals, water systems and internet infrastructure are months away, not years.

OpenAI's cyber defense letter is trying to make one point unavoidable: the window for slow preparation is closing. The signatory list includes Anthropic, Google, Microsoft, AWS, CrowdStrike, Cloudflare, Palo Alto Networks, Okta, Fortinet, Visa, Mastercard, Capital One, Adobe, Oracle, IBM, Cisco, General Motors and Shopify. More than 100 organizations put their names on it.

The line that matters is plain. "In the coming months, AI-enabled cyber attacks will become far more widespread and sophisticated as models around the world become increasingly capable," the letter says. The examples are not remote targets buried inside a government memo. Hospitals. Water treatment plants. The infrastructure that keeps the internet running. If you run one of those systems, months is not much time.

This is not just a warning from companies with a taste for dramatic language. CrowdStrike's 2026 Global Threat Report, published in February, found that AI-enabled adversary operations rose 89% year over year. The average eCrime breakout time fell to 29 minutes in 2025, and the fastest breakout CrowdStrike observed took 27 seconds.

Twenty-seven seconds is not an incident response window. It is a blink.

OpenAI Cuts GPT-5.6 Sol API Prices After Holding the Line for Months OpenAI cut API pricing on its flagship GPT-5.6 Sol model by more than 20% starting August 21, 2026, the first price cut to its top-tier model since launch. The move follows earlier discounts to its Terra and Luna models and comes as Anthropic and Chinese labs like DeepSeek and Moonshot AI undercut OpenAI on enterprise API pricing. - OpenAI GPT-5.6 Sol API price cuts announced - when did OpenAI reduce GPT-5.6 Sol pricing

Anthropic has seen the same pressure inside its own product. In a June research report, the company said it analyzed 832 Claude accounts banned for malicious cyber activity between March 2025 and March 2026. Those accounts were tied to 13,873 observed actions across 482 unique MITRE ATT&CK techniques and all 14 ATT&CK tactics. In the first half of the year, 33% of the banned actors were rated medium risk or higher under Anthropic's scoring system. In the second half, that share rose to 56%.

The sellers are also sounding the alarm #

Here's the tension. The same companies warning that AI will make attacks faster are building the tools they say defenders now need. OpenAI has Daybreak, including cyber-focused model access for approved defenders. Anthropic has Claude Mythos 5 in Claude Security and has been expanding access through its Cyber Verification Program. Microsoft introduced Project Perception in July, an agentic security system that entered public preview on August 3.

That does not make the warning false. Someone has to build the defense, and the frontier labs do understand the offensive capability better than most buyers ever will. But let's be honest about the shape of the market. The danger is real, and it is also becoming a sales channel.

CrowdStrike's week made that point without needing much commentary. The company reported fiscal second-quarter results on August 26, with $1.47 billion in revenue, up 26% from a year earlier, and annual recurring revenue of $5.84 billion. MarketWatch reported that the stock jumped more than 20% after the results, while analysts raised price targets on the view that AI security demand is moving from a boardroom concern to a budget line.

Follow the money, but do not stop there.

The hardest part is local #

The letter's actual ask is narrower than the headline sounds. It calls on governments to coordinate cyber defense from local to international level, fund essential services that lack staff or budget, and expand trusted access programs. It also asks them to give hospitals and water utilities - along with local governments - access to defensive AI and hands-on support, as well as authorized testing, through trusted providers. It also asks governments to impose costs on attackers.

That last line is easy for every signatory to endorse. The harder work is the budget. A hospital IT team does not hire, test, approve and deploy a new defensive system in a few weeks. A municipal water authority does not suddenly gain the staff of a bank security operations center because OpenAI published a letter. Critical infrastructure is often old, underfunded and hard to patch without disrupting real services.

The EU AI Act Now Forces Every Chatbot to Admit It Is Not Human The EU's AI Act transparency rules became enforceable on August 2, 2026, and regulators began active enforcement this week, forcing every chatbot, AI agent and deepfake reaching EU users to disclose it isn't human. Fines reach €15 million or 3% of global turnover, and while 180-plus firms including Anthropic, OpenAI and Google signed onto a... - EU AI Act chatbot disclosure requirements - AI transparency rules customer service compliance

Microsoft's own Project Perception post says the first scenario is software vulnerability management, using its MAI-Cyber-1-Flash model inside MDASH. OpenAI's Daybreak materials talk about vulnerability discovery, secure code review, malware analysis, incident response and patch validation. These are useful tasks. They are also exactly the unglamorous jobs that many local systems have postponed for years because the money was never there.

Frankly, "months, not years" should scare a procurement office more than a hacker forum screenshot. The attackers do not need every model to become a perfect autonomous operator. They only need enough speed and scale - sustained for long enough - to overwhelm teams that were already short before AI entered the room.

The letter is current and specific, and it's signed by companies with real reach. It is also incomplete unless the money follows the warning. If governments and vendors want hospitals and water utilities to defend themselves at machine speed, they have to give them more than a deadline.

Also read: AI Loss of Control Incidents Nearly Doubled in July, Observatory FindsA 64GB RAM Kit Now Costs $1,118 Because AI Datacenters Are Eating The SupplyElastic Stock Soars 22% As Enterprise AI Demand Fuels Earnings Beat

── more in #ai-safety 4 stories · sorted by recency
── more on @openai 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/openai-anthropic-and…] indexed:0 read:5min 2026-08-29 ·