I have been an enterprise operations leader and implemented many clinical and biomedical device systems in my career. I consider strengthening our cybersecurity defenses for critical systems important at all times. In my work twelve years ago, we thought AI would be changing the game very seriously even then, and indeed it has over the years.
A week ago lots of companies started publishing open calls raising awareness of increasing risks with the sophistication of AI-enabled attacks (triggered in part by the Hugging Face incident). I remember raising this in a call with a group of top engineers 6 years ago who didn’t understand the scale of the complexity healthcare orgs with 500,000 biomedical devices face. I had led the inventory and risk assessment of every layer of the stack on 20,000 devices the year prior, and one person asked, “is this risk real?” And I didn’t know if to laugh or cry, and I could only think: 👀 The risk of AI-enabled attacks is not new; it is just accelerating in breadth and blast radius.
Some of the recent articles are listed below.
(1) World governments have been warning about this for months in light of the capabilities of systems like Anthropic’s Mythos system. The UK Government had issued a warning five months ago on 22 April 2026: AI cyber threats: open letter to business leaders – see link here – They wrote, “Open letter to businesses on AI cyber threats. We are writing to you because the threat your business faces in cyber space is changing, and the way we respond must change with it. For years, the most serious cyber attacks have relied on a small number of highly skilled criminals. That is now shifting. A new generation of AI models are becoming capable of doing work that previously required rare expertise: finding weaknesses in software, writing the code to exploit them, and doing so at a speed and scale that would have been impossible even a year ago.”
(2) On the OpenAI blog Aug 26, 2026 : A call for collective action on cyber defense – OpenAI lists a series of recommendations to secure existing systems in the facing of increasing cybersecurity threats – see link here – “An open letter for a global surge in cyber defense. We have a limited window to strengthen cyber defenses. In the coming months, AI-enabled cyber attacks will become far more widespread and sophisticated as models around the world become increasingly capable. The companies and public services our communities depend on—from hospitals to water treatment plants to the infrastructure that powers the internet—are at risk.”
(3) On the BBC: Time is running out for cyber security, warn top tech firms by Zoe Kleinman and Kali Hays on Aug 26, 2026 – see link here – “A group of 100 firms, including Google, Microsoft, Anthropic and OpenAI, have signed an open letter calling on countries and organisations around the world to beef up their cyber defences before AI grows powerful enough to override them. The letter warns cyber-attacks which use AI will become both more widespread and more sophisticated in a matter of months as the technology rapidly improves.”
(4) On TechCrunch: OpenAI, Anthropic, Google, and 100 other companies call for action to defend against rogue AI by Lucas Ropek on Aug 27, 2026 – see link here – “The letter — which was also signed by prominent cyber firms like CrowdStrike, Okta, and Fortinet, as well as prominent financial institutions and internet infrastructure firms — calls for the adoption of new forms of cyber defense, while also encouraging governments at the “local, national, and international levels” to collaborate on security… The problem AI poses to traditional cybersecurity defenses has been thrust into the spotlight lately by a string of bizarre incidents in which AI agents have attacked companies. The Hugging Face incident — in which one of OpenAI’s agents autonomously broke out of its sandboxed environment and attacked the tech company — has been followed by a trail of other reported break-ins involving agents developed by other AI companies, including Anthropic and Meta. These incidents have bolstered the argument that the field of cybersecurity has been fundamentally altered and that bold new commercial solutions are necessary to mitigate them.”
(5) At Inside Cybersecurity: AI firms’ open letter on cybersecurity draws civil society criticism for ‘hypocrisy’ by Mariam Baksh / Sept. 1, 2026 – see link here (there is a paywall here and you need to sign up for a free 30-day account or purchase a subscription)
