AI Cyberattack Warning Puts $244B Security Budgets in Focus

Over 100 tech giants including Alphabet, Microsoft, Anthropic, and OpenAI signed a joint letter on 27 August 2026 warning that AI cybersecurity spending must accelerate as AI-enabled attacks rise 89% year-on-year and adversary breakout times collapse to just 29 minutes.
By Branka Narancic -
Massive operations centre screen displaying "29 minutes" as AI cybersecurity spending alarm signals systemic threat
  • Over 100 companies including Alphabet, Microsoft, Anthropic, and OpenAI signed a joint letter on 27 August 2026 warning that AI-enabled cyberattacks will become far more widespread and sophisticated within months and that current defenses will not hold.
  • CrowdStrike data shows AI-assisted attacks have compressed average adversary breakout time to just 29 minutes, and AI-enabled cyberattacks rose 89% year-on-year with attack speed up 65% between 2024 and 2025.
  • Gartner projects global information security spending will hit $244 billion in 2026 (up 11.6%), with Forrester forecasting the broader market surpasses $300 billion by 2029; approximately 80% of CIOs plan to increase security budgets, making it the top category for increased IT spend.
  • CISA data shows 51% of scanned entities run unsupported software and 91% rely on deprecated SSL/TLS protocols left exposed for a median of 459 days, providing AI attackers a vast, catalogued attack surface that does not require novel exploits.
  • Gartner's finding that 75% of organisations will keep legacy and unmanaged systems outside zero-trust strategies through 2026 means rising total budgets may not close the infrastructure gaps the letter specifically targets, leaving allocation rather than aggregate spending as the key variable to watch.
Summarise with AI:

More than 100 of the world’s most powerful technology companies, including the builders of the leading AI systems themselves, signed a joint open letter on 27 August 2026 warning that AI-enabled cyberattacks will become far more widespread and sophisticated “within months” and that current defenses will not hold. The signatories include Alphabet, Microsoft, Anthropic, and OpenAI: the very organisations building the tools now being weaponised against defenders.

Industry-wide coordination at this scale is unusual. The letter’s signatories span technology, finance, and security, with names such as AWS, Oracle, IBM, CrowdStrike, Visa, Mastercard, and Capital One joining the four AI leaders. That breadth signals a private sector treating the threat as systemic rather than company-specific, and the letter asks governments to fund defensive AI tools, improve threat intelligence sharing, and coordinate responses nationally and internationally.

This piece unpacks what the letter actually signals about where cybersecurity budgets are heading, what the data reveals about AI-enabled attack trajectories, and what the unresolved gaps mean for anyone tracking enterprise technology spending. The headline is the easy part; the structural story underneath it is where the read is.

Why 100-plus tech companies issued a joint warning at the same moment

The letter is not advocacy theatre. It is a coordinated admission from the organisations best positioned to know exactly how capable AI-enabled attacks are becoming, and how quickly.

Its demands are specific. The signatories call on governments to do three things, and on frontier AI companies to do a fourth:

  • Fund and provide capable defensive AI tools to critical infrastructure operators
  • Improve threat intelligence sharing across sectors and borders
  • Coordinate responses at both national and international levels
  • (For frontier AI companies specifically) supply responsible model access, funding, training, and hands-on support to under-resourced defenders

The framing in the letter itself is blunt.

The signatories warn that AI-enabled cyberattacks will become far more widespread and sophisticated “within months,” and that “status quo” security measures will not suffice.

The composition of the signatory list carries a message the text does not state outright. When financial firms such as Visa, Mastercard, and Capital One sign alongside the AI developers building the models, the concern is clearly crossing sector lines rather than reflecting a narrow vendor interest in bigger security budgets.

That distinction matters for how you read the document. This is not a security-vendor campaign for budget expansion. When the companies building the most capable AI systems publicly warn that current defenses are inadequate, the reasonable interpretation is that they are disclosing a risk they believe governments and enterprises have not yet priced in, verified across BBC News, Axios, The New York Times, and POLITICO reporting.

Cyber risk in bank valuations is increasingly treated as a structural blind spot rather than an operational footnote: JPMorgan analyst Kian Abouhossein argued in June 2026 that AI tools have collapsed the time to discover exploitable zero-day vulnerabilities from months to hours, eliminating the defence window financial institutions historically relied upon.

What the data says about AI-enabled attacks right now

The letter reads as sudden alarm. The data reads as confirmation of a trend that has been building for well over a year.

The acceleration shows up across several distinct threat vectors, and it helps to separate them:

  • Speed and volume: CrowdStrike research, reported via National Technology News, found AI-utilizing cyberattacks rose 89% year-on-year, with attack speed up 65% between 2024 and 2025. Separately, CNCSO analysis recorded average weekly cyberattacks per organisation rising from 818 in Q2 2021 to 1,984 in Q2 2025.
  • Phishing: TR7’s autonomous-threats report found 82.6% of phishing emails are now created using AI language models, with generative-AI phishing achieving a 72% open rate, nearly double conventional phishing. CNCSO recorded AI-generated phishing attacks up 1,265% year-on-year, and TR7 found 87% of organisations experienced an AI-enabled attack in the last 12 months.
  • Deepfakes: There were 179 recorded deepfake incidents in Q1 2025 alone, more than all of 2024 combined, part of a 2,137% rise between 2022 and 2025.

One figure captures the speed problem more viscerally than the rest.

CrowdStrike data reports that AI-assisted attacks have reduced average adversary breakout time to just 29 minutes.

Breakout time is the window in which a defender can detect and contain an intrusion before an attacker moves laterally and entrenches. At 29 minutes, that window is now measured in minutes for many organisations, and it collapses further when attackers can automate movement across weaknesses that have been sitting exposed for years.

The AI Attack Acceleration Dashboard

The structural mechanism behind all of this is straightforward. AI lowers the skill barrier and the marginal cost of attacking, which lets less-experienced actors wield sophisticated tools at scale. CrowdStrike observed adversaries adopting generative AI throughout 2024, lowering the barrier to entry for nation-state and hacktivist operations alike.

UC Berkeley CLTC research on AI-enabled cybercrime independently documents how generative AI tools have lowered the technical barrier for social engineering and deepfake-based fraud, corroborating the trajectory that commercial threat intelligence firms have recorded across the same period.

The legacy infrastructure problem AI attackers are already exploiting

The offensive advantage is sharpest where old infrastructure meets automated attacks. CISA’s Vulnerability Review documents that 51% of scanned entities run unsupported software, and 91% rely on deprecated SSL/TLS protocols, often left unaddressed for a median of 459 days.

That is a lot of known, ageing exposure sitting open for well over a year at a time. AI-enabled attackers do not need novel exploits when they can automate discovery and exploitation of weaknesses that were catalogued long ago.

The offence-defence asymmetry runs deeper than attack volume alone: Palo Alto Networks’ internal AI scan compressed five to seven years of conventional vulnerability discovery into six weeks, setting a new baseline for how quickly the attack surface can be mapped by any sufficiently resourced adversary.

The Legacy Infrastructure Gap

Gartner sharpens the mismatch. Through 2026, it predicts 75% of organisations will exclude unmanaged, legacy, and cyber-physical systems from their zero-trust strategies, meaning defensive investment concentrates precisely where AI-enabled attackers are not probing hardest. That gap is what makes the letter’s call for defensive AI tools for critical infrastructure operators directly relevant rather than aspirational.

Where cybersecurity budgets are heading and what is driving them

Markets and enterprises have already begun pricing in this shift. The letter is not creating budget momentum so much as reflecting it, and potentially accelerating it.

The major analyst forecasts point in one direction, though they differ by scope rather than contradicting one another.

Source Publication Date Scope Key Figure
Gartner (3Q25 update) September 2025 Worldwide information security spending $244 billion projected for 2026, up 11.6% (constant currency)
Forrester October 2025 Global cybersecurity market (broader definition) $174.8 billion in 2025; over $300 billion by 2029 (~14.4% CAGR)
IDC March 2025 Worldwide security products and services $377 billion by 2028

The Gartner and Forrester figures differ because of scope and methodology, not disagreement. Gartner focuses on information security; Forrester uses a broader market definition. Both trend firmly upward.

The clearest evidence of spending resilience is what CIOs themselves say they will do.

Approximately 80% of CIOs intend to increase security investments, making security the top category for increased IT spend, with Gartner projecting double-digit growth across all enterprise security segments.

Cybersecurity ETF exposure has tracked the non-discretionary spending thesis closely: Gartner, IDC, and Forrester projections of double-digit annual growth through 2029 have supported a structural case for diversified cybersecurity holdings even as company-level competitive disruption within the sector continues to accelerate.

For anyone tracking enterprise technology spending, that 80% figure tells you something specific: cybersecurity is one of the few IT categories where even a macro slowdown is unlikely to produce meaningful cuts. That makes it structurally different from discretionary technology investment.

There is a caveat worth holding, though. Rising total budgets do not guarantee that legacy and unmanaged systems receive proportionate attention. Gartner’s finding that 75% of organisations will keep those systems outside zero-trust through 2026 suggests defensive spending may concentrate on modern, manageable assets while older infrastructure stays exposed. The spending trajectory was already established before the August letter; the letter’s role is to give procurement teams and governments a public rationale to move faster.

What the letter does not resolve and why the gaps matter

Ambition and delivery are different things. The letter names problems it cannot close on its own, and the gaps are where the nuance lives.

Three tensions remain unresolved:

  • The information-sharing gap the letter names but cannot itself fix. Voluntary threat intelligence sharing has historically been hard to sustain even with institutional backing.
  • The risk that spending outpaces capability if investment flows toward additive AI tools rather than modernising the legacy systems that Gartner shows sit outside most zero-trust strategies.
  • The new attack surface that defensive AI deployments themselves introduce, which the letter does not specifically address.

That third point is the recursive one. CISA’s own framework classifies AI risk into three distinct categories:

  1. Attacks using AI, such as automated cyber compromises and AI-enabled social engineering
  2. Attacks targeting AI systems, including poisoning training data or exploiting model weaknesses
  3. Failures in AI design and implementation, such as misconfiguration and unsafe integration

The defensive AI tools the letter calls for fall squarely into that second category as potential targets. Even if every demand is met, those tools will themselves need securing against a class of AI-targeted attacks the letter does not name.

CISA’s AI Roadmap already articulates three goals: using AI to enhance cybersecurity, protecting AI systems from cyber threats, and deterring malicious use of AI against critical infrastructure. The Roadmap’s existence underlines how long these objectives have been on the table without being fully achieved.

For anyone assessing whether rising budgets translate into proportionate risk reduction, that history matters. CrowdStrike’s evidence that adversaries adopted generative AI throughout 2024 confirms the arms race is already in motion, which means the threat trajectory and the spending trajectory can both climb at the same time.

What the August 2026 letter actually changes, and what comes next

The letter matters more as a signal than as a mechanism. It is a credibility marker and a potential procurement catalyst, not a regulatory or enforcement instrument.

Its real value is public accountability. Enterprises, governments, and investors now have an industry-wide benchmark against which coordination and allocation decisions can be measured over the coming months.

Three indicators will reveal whether it produces measurable change:

  • Government funding announcements for defensive AI tools aimed at critical infrastructure operators
  • Concrete changes to threat intelligence sharing frameworks
  • Whether frontier AI companies actually begin providing the model access, funding, and hands-on support to under-resourced defenders that the letter demands

The spending direction itself is not really in question. Gartner’s $244 billion projection for 2026 and Forrester’s path toward $300 billion by 2029 were both set before the letter appeared.

The open question is allocation. For readers tracking where enterprise technology budgets move, the issue is not whether cybersecurity spending grows but whether that growth closes the legacy and coordination gaps, or whether it keeps concentrating on modern, manageable assets while ageing infrastructure stays exposed. The next 12 months will show whether coordinated industry pressure compresses the timeline or merely restates a problem that has been visible in the data for over a year.

This article is for informational purposes only and should not be considered financial advice. Investors should conduct their own research and consult with financial professionals before making investment decisions.

Past performance does not guarantee future results, and financial projections are subject to market conditions and various risk factors. Forward-looking statements about spending trajectories and threat trends are speculative and subject to change based on market and technological developments.

Frequently Asked Questions

What is AI-enabled cyberattack breakout time and why does it matter?

Breakout time is the window defenders have to detect and contain an intrusion before an attacker moves laterally and entrenches. CrowdStrike data shows AI-assisted attacks have reduced average breakout time to just 29 minutes, meaning most organisations have minutes, not hours, to respond before an attacker establishes a foothold.

How fast is global cybersecurity spending projected to grow through 2029?

Gartner projects worldwide information security spending will reach $244 billion in 2026, up 11.6%, while Forrester forecasts the broader cybersecurity market will exceed $300 billion by 2029 at a roughly 14.4% compound annual growth rate; IDC puts worldwide security products and services at $377 billion by 2028.

Why did more than 100 tech companies sign a joint AI cybersecurity letter in August 2026?

The signatories, which include the builders of leading AI systems such as OpenAI, Anthropic, Alphabet, and Microsoft alongside financial firms like Visa and Mastercard, publicly disclosed that AI-enabled attacks will become far more widespread and sophisticated within months and that current defenses are inadequate, calling on governments to fund defensive AI tools, improve threat intelligence sharing, and coordinate responses nationally and internationally.

What share of organisations are running legacy infrastructure that AI attackers can exploit?

CISA's Vulnerability Review found that 51% of scanned entities run unsupported software and 91% rely on deprecated SSL/TLS protocols, with known vulnerabilities left unaddressed for a median of 459 days, giving AI-enabled attackers a large, catalogued attack surface to automate against without needing novel exploits.

Does rising cybersecurity spending mean legacy systems will actually get protected?

Not automatically. Gartner predicts that through 2026, 75% of organisations will exclude unmanaged, legacy, and cyber-physical systems from their zero-trust strategies, meaning defensive budget growth is likely to concentrate on modern assets while ageing infrastructure remains exposed, the exact gap AI-enabled attackers are already exploiting.

Branka Narancic
By Branka Narancic
Client Success Manager
Branka Narancic is Client Success Manager at StockWireX and Discovery Alert, and an active contributor to the News sections on both platforms, bringing more than a decade of experience across financial journalism, capital markets communications, and investor engagement. A founding contributor and former Editor of Companies and Markets at The Market Herald, she combines deep ASX market knowledge with a commercially focused approach to client success.
Learn More

Breaking ASX Alerts Direct to Your Inbox

Join +20,000 subscribers receiving alerts.

Join thousands of investors who rely on StockWire X for timely, accurate market intelligence.

About the Publisher