Back to News & Insights
Security September 9, 2026 4 min read

A Hundred Companies Warned You. The Fix Is Boring.

More than 100 firms signed an August 27 letter warning that AI-enabled attacks are coming fast. The weaknesses they named have been on every audit since 2015.

On August 27, more than 100 companies published a joint open letter calling for what they describe as a defensive surge against AI-enabled cyberattacks.

The signatory list is the interesting part. OpenAI, Anthropic, Google, Microsoft, and Amazon, which is expected. Then Cisco, Cloudflare, CrowdStrike, IBM, Oracle, and Palo Alto Networks, which is also expected. Then Capital One, Mastercard, Visa, General Motors, and Shopify, which is less expected and matters more. Companies that sell nothing in this category signed a document saying the threat model is changing.

The core claim: "In the coming months, AI-enabled cyber attacks will become far more widespread and sophisticated as models around the world become increasingly capable."

Read the forecast as a forecast

That sentence is a prediction, and we are going to treat it as one. Nobody published a dataset alongside it. There is no incident count, no measured increase, no named campaign. It is a statement of expectation from a group of companies, several of which sell security products and several of which build the models in question.

That does not make it wrong. It makes it a specific kind of evidence. The organizations with the clearest view of where frontier model capability is heading put their names on a document saying the window to prepare is short. You can weigh that without treating it as measurement.

What we would not do is act on the forecast by buying something. The letter does not actually ask you to.

What the letter asks of a company your size

Strip away the sections aimed at governments and AI labs, and what remains for an ordinary organization is short. Make cybersecurity an immediate leadership priority. Fix the highest-risk weaknesses. Raise the security bar for what you build and buy, including AI-generated code.

Then there is the line that does the most work, which is the instruction to "apply compensating controls where systems can't be patched without disrupting essential services."

That sentence was written by people who know that the machine you cannot patch is usually the machine you cannot turn off.

The list underneath is the actual story

Here is what the letter names as the sources of exposure: longstanding bugs, excessive permissions, misconfigurations, unpatched software, weak authentication, and technical debt in legacy systems.

Read that list again. Nothing on it is new. Nothing on it is AI-specific. Every item has been on standard security assessments for a decade, and most small organizations have known about their own version of each one for years.

The letter's argument is not that AI creates new categories of weakness. It is that AI collapses the time and skill required to find and exploit the ones you already have. An excessive permission that sat unexploited for six years because nobody bothered to go looking becomes worth going looking for when looking costs almost nothing.

That is a much more useful claim than a general warning, and it points somewhere specific. The thing that changes is not your defenses. It is the economics of being a small, unremarkable target.

Small organizations have been protected mostly by obscurity and by attacker labor costs. Neither of those is a control. Both are assumptions, and this letter is a hundred-odd companies saying one of the two is about to stop holding.

What we would actually do

None of this requires a new line item. It requires closing things that are already open.

Find the machine you cannot patch and write down what protects it. Every small organization has at least one. The old server running the practice management software, the workstation tied to a piece of equipment whose vendor is out of business, the appliance nobody has logged into since the person who installed it left. It is not going to get patched. So the answer has to be what sits around it: network segmentation, restricted access, monitoring on the traffic in and out. If the honest answer is nothing sits around it, that is your first project.

Pull the permission list and cut it. Excessive permissions made the letter's list because they are nearly universal and nearly free to fix. Who has administrator rights they no longer need. Which former employee accounts are still live. Which third-party integration was granted broad access during a project that ended in 2023. This is an afternoon of work and it is the single highest-value afternoon available to most small organizations.

Turn on multifactor authentication everywhere it is not already on, starting with email. Weak authentication is on the list because it remains the most common way in. If you have exceptions carved out for convenience, those exceptions are the attack surface.

Ask what your AI tools can reach. The letter's line about AI-generated code applies to a software company. The version that applies to you is a coding assistant, an automation tool, or an agent that was given credentials during setup and has been holding them ever since. Whatever a tool can reach, an attacker who reaches the tool can reach.

The part worth sitting with

A hundred companies with every commercial reason to tell you the answer is a product told you the answer is patching, permissions, and authentication.

We think that is the most credible thing about the letter. When the people selling the sophisticated response point at the boring work instead, the boring work is probably where the risk actually is.

The letter's own framing is that "each of us can reduce risk now." That is true, and the version of it available to a twelve-person company this month is unglamorous and mostly free.

If you want a clear-eyed read on where your own exposure actually sits, without a product recommendation attached to the answer, that is a conversation we are glad to have.

Join the conversation

Straight talk welcome. Comments are moderated, no pitches, no spam.

Comments load once the Hyvor Talk Website ID is set in article.html.