On August 27, 2026, OpenAI, Anthropic, Google, Microsoft, Amazon, Cisco, Oracle, Cloudflare, and more than a hundred other companies — including Mastercard, Visa, Shopify, and General Motors — signed a joint open letter warning that AI-powered cyberattacks are about to become far more common and far more effective. That's not a vendor pitch or a research paper. It's the companies building the AI telling everyone else that the threat landscape just shifted, and that "we have a limited window to strengthen cyber defenses" before it gets worse.
The signatories warned that AI-enabled attacks will grow more widespread and sophisticated as models become more capable, and that the systems communities depend on — hospitals, water treatment plants, the infrastructure that runs the internet — are increasingly at risk. They called for a "defensive surge": collective action to secure critical systems and make it more expensive and difficult for attackers using AI tools to break in. Several of the signatories are also rolling out their own defensive programs, including OpenAI's Daybreak initiative, Anthropic's Mythos program, and Microsoft's Perception cyber platform.
It's easy to read a headline like this and file it under "someone else's problem" — power grids and banks, not a 12-person accounting firm or a regional HVAC company. That reaction is understandable, but it's wrong, and there's fresh data explaining why.
On August 6, 2026, Google's Threat Intelligence Group published research on a group it tracks as UNC6671, describing how AI has changed the economics of targeting smaller businesses. Attacks that once required a skilled human to research a target, write a convincing message, and manage the follow-up now take an AI model minutes and pennies. That means a scam that wasn't worth an attacker's time when it targeted a 15-person company now pencils out — because the cost of running it dropped to almost nothing while the payout stayed the same. Small businesses aren't collateral damage anymore; they're worth targeting on their own.
The scale backs this up. Hoxhunt's 2026 Phishing Trends Report found that AI-generated phishing surged roughly 14x in a single month at the end of 2025, jumping from under 5% of detected attacks to 56%. That's not a gradual trend — it's a step change, and it happened fast enough that most small business security habits haven't caught up.
For years, the standard guidance was "watch for typos and odd phrasing." That advice is now close to useless. AI-generated phishing emails are grammatically clean, personalized with real names, vendor relationships, and recent transaction details pulled from LinkedIn, email signatures, and public filings. Voice cloning has made phone-based fraud — a "CFO" calling to urgently approve a wire transfer — sound exactly like the real person, on the first call. Attackers can also now generate this content at volume, running dozens of tailored attempts against different employees at the same company instead of one generic email to everyone.
None of this requires a security team or a big budget. It requires closing a handful of specific gaps that AI has made much more exploitable.
Any request to change payment or bank details, wire money, or share login credentials — no matter how it arrives or how convincing it sounds — gets verified through a second channel before anyone acts on it. Call a known phone number (not the one in the message) or walk over and ask in person. This single rule stops most AI-powered social engineering, because it doesn't depend on spotting a fake — it assumes every unusual request needs independent confirmation.
Banking, email, payment processors, and any system that touches customer or financial data. Start with whoever has access to money or sensitive data first, then work outward. MFA doesn't stop a convincing email from arriving, but it stops a stolen password from becoming a breach.
Update whatever security awareness training you run so it stops telling people to "look for red flags" and starts telling them to verify anything unusual before acting — even when it looks and sounds completely legitimate. Include a voice-cloning scenario in the training; most employees haven't considered that the "urgent call from the boss" might not be the boss.
Because major vendors are the ones signing this letter, some of the defensive capability is landing inside tools you already pay for — email security filters, endpoint protection, browser warnings. Ask your email provider and security software whether new AI-detection features exist and whether they're actually turned on; several of these are opt-in or require an update.
The letter itself frames the goal as making attacks "more expensive and difficult," not impossible. MFA, second-channel verification, current backups, and up-to-date patching still stop the overwhelming majority of AI-assisted attacks. Get those solid before adding new security products to the stack.
This is the flip side of the AI productivity story most small businesses are focused on right now. The same capabilities that help you draft emails faster, summarize documents, and automate busywork also lower the cost for someone else to target your business specifically. That's not a reason to slow down AI adoption — it's a reason to pair it with the same basic hygiene you'd want regardless: verify before you act, restrict who can touch what, and don't assume "that would never happen to a business our size" still holds.
DAOVA helps small businesses build practical, right-sized AI governance and security practices that keep pace with how fast this space is moving. Explore AI Governance & Operations.