100 Companies Including OpenAI and Anthropic Warn of Escalating AI Cyberattacks: Which Cybersecurity Stocks Are Worth Watching?
Over 100 major tech and financial institutions signed an open letter warning that AI-driven cyberattacks will become more prevalent and sophisticated, targeting critical infrastructure. Recent incidents, like the Hugging Face breach, highlight risks from autonomous AI agents. Morgan Stanley projects AI security demand could drive incremental market growth from $16 billion to over $45 billion, with a compound annual growth rate of 30% to 40%. This structural expansion elevates cybersecurity from a mere cost item to an essential prerequisite for enterprise AI deployment, benefiting sector leaders such as CrowdStrike, Palo Alto Networks, and Cloudflare.

TradingKey - More than 100 companies, including OpenAI, Anthropic, Google, and Microsoft, have signed an open letter warning that AI-driven cyberattacks could become more widespread and sophisticated in the coming months.
Led by OpenAI, the signatories span AI developers, cloud providers, cybersecurity firms, financial institutions, payment processors, and other major tech companies. They include Anthropic, Google, Microsoft, Amazon Web Services, Adobe, Oracle, IBM, Capital One, Mastercard, and Visa, among others.
The letter warns that as global AI model capabilities continue to advance, AI-driven cyberattacks will become more pervasive and complex over the coming months. Hospitals, water treatment plants, power utilities, financial service institutions, and the infrastructure underpinning the internet could all become targets.
The signatories believe the current level of security is "far from enough." The critical infrastructure sector has long suffered from a shortage of security personnel, budgets, and tools, and relying solely on traditional security processes may fail to timely remediate system vulnerabilities accumulated over the years.
For capital markets, this is not only a cybersecurity warning, but it also brings AI safety, critical infrastructure protection, and cybersecurity stocks back into investors' focus.
What Is AI Cybersecurity?
Cybersecurity generally refers to protecting networks, systems, software, devices, and data from unauthorized access, damage, theft, or disruption. AI cybersecurity carries a dual meaning: on one hand, enterprises must defend against AI-powered cyberattacks; on the other hand, they need to deploy AI tools with analysis, detection, response, and remediation capabilities to boost defense efficiency.
Simply put, AI is reshaping both the offensive and defensive fronts simultaneously.
Offensive side: AI enables attackers to generate phishing content, malware, and exploit scripts at scale, while reducing the time needed to understand complex systems.
Defensive side: AI helps security teams discover long-unidentified vulnerabilities, screen high-risk issues, verify remediation effectiveness, and accelerate incident response.
Governance side: As AI-generated code, AI agents, and automated workflows enter enterprises, new issues arise around identity authentication, permission control, operation tracking, and accountability.
Therefore, AI security is not simply adding another layer of firewall, but rather a comprehensive security system encompassing models, data, identity, code, cloud platforms, endpoints, applications, and critical infrastructure control systems.
Hugging Face Incident Turns AI Attack Risks From Hypothesis to Reality
Prior to the release of the open letter, OpenAI disclosed an AI security incident involving Hugging Face. During testing, hundreds of OpenAI AI agents established a secret message board for mutual communication and collaboration, leveraging publicly exposed user credentials to chain vulnerabilities and ultimately gaining code execution capabilities on certain Hugging Face servers.
This incident was described in related reports as one of the first cases of AI-driven cyberattacks. The key issue it revealed was not a single vulnerability, but rather that multiple AI agents were able to organize actions, exchange information, and persistently advance tasks to a certain extent. As AI systems gain greater autonomous execution capabilities, security mechanisms that traditionally rely on human review and single-point interception may face increased pressure.
This summer, OpenAI, Anthropic, and Meta all disclosed that their AI tools had executed actions they were not originally supposed to perform. Some AI agents even attempted to impersonate real humans to bypass existing security barriers. This makes permission boundaries, identity verification, and audit logging for AI models critical topics in cybersecurity development.
AI Could Drive Up to About $220 Billion in Incremental Security Demand
From an industry perspective, the growth in demand for AI security does not stem merely from a news catalyst, but rather from a structural expansion of the digital attack surface. The deployment of large models, the rollout of AI agents, and the proliferation of AI-assisted programming are simultaneously increasing corporate exposure across code, permissions, interfaces, and data.
In a 2026 research report, Morgan Stanley noted that approximately 14% of organizations have already experienced AI-related security incidents, and about 80% to 90% of current cyberattacks exhibit AI-generated characteristics.
Morgan Stanley estimates that approximately 14% of organizations have already experienced AI-related security incidents, and about 80% to 90% of current cyberattacks exhibit AI-generated characteristics. If the intensity of AI security spending eventually approaches that of overall IT spending, the AI security market size is expected to expand from roughly $16 billion to over $45 billion, with a compound annual growth rate of 30% to 40%.
This means that AI security could become a subsegment within the AI industry chain—aside from computing chips—that offers relatively high certainty and remains in an acceleration phase. Demand stems from multiple segments, including model security, cloud security, identity and access management, endpoint protection, vulnerability management, data security, threat detection, and critical infrastructure security.
From an industry chain perspective, the expansion of AI security demand will not be limited to a single segment. Endpoint protection, threat detection, cloud security, identity and access management, data security, edge and network layer protection, as well as the infrastructure supporting these capabilities, are all likely to benefit simultaneously.
In the US stock market, cybersecurity concept stocks are mainly concentrated in the following companies:
Company Name | Ticker | Segment | Core Positioning & Competitive Advantage |
CrowdStrike | Endpoint Detection and Response (EDR/XDR) | A global leader in endpoint detection and response, its Falcon platform builds a moat with a cloud-native architecture and threat intelligence network. | |
Palo Alto Networks | Cybersecurity Platformization | One of the world's largest cybersecurity platform companies, synergizing three major business lines: Prisma (cloud security), Cortex (threat detection), and Strata (network firewalls). Its acquisition of CyberArk, completed in 2026, completes its identity security puzzle, giving its platformization strategy a unique advantage in the AI era. | |
Akamai | CDN/Edge Computing & Application/API Security | Originating in CDN and edge computing, it possesses global edge node advantages in distributed applications and API security protection. | |
Cloudflare | Edge Cloud Platform & DDoS/API Security | A global edge cloud platform whose low-latency response capability at edge nodes serves as a core competitive edge in AI application gateways, DDoS protection, and API security. | |
Okta | Identity and Access Management | A leader in independent identity management, its two major product lines—Workforce Identity and Customer Identity—cover enterprise employee and external user authentication. AI agents and non-human identity management represent its next growth curve, with its independent positioning offering unique value in large enterprises. | |
Zscaler | Zero Trust Network Access (ZTNA) & SSE | A leader in Zero Trust Network Access and Security Service Edge (SSE). In the AI era, demand for Zero Trust architecture remains robust across remote work and hybrid cloud scenarios. | |
Rubrik | Data Security & Backup and Recovery | A data security and backup/recovery platform holding technological leadership in ransomware protection and immutable data storage. Backup security needs for AI training data and workloads unlock new growth space for it. | |
Cisco | Network Equipment & Security Integration | A global leader in network equipment, its SecureX platform and Talos threat intelligence team form the foundation of its security business. It holds channel and customer scale advantages in the integrated deployment of enterprise network infrastructure and security. | |
Fortinet | Next-Generation Firewall (NGFW) & SASE | Firewall hardware and the FortiOS operating system form its core, with FortiGate leading in NGFW market share. Its SASE business is growing rapidly, and its strategy of converging networking and security provides a cost advantage in AI data center interconnect scenarios. |
It should be noted that how much AI security spending is ultimately unlocked still depends on the pacing of enterprise IT budget allocation and the speed at which AI agents are deployed internally. What is certain is that along this industry chain, security is being repriced from a "cost item" to a "prerequisite for AI deployment."
This content was translated using AI and reviewed for clarity. It is for informational purposes only.
Recommended Articles











Comments (0)
Click the $ button, enter the symbol, and select to link a stock, ETF, or other ticker.