Skip to content
Cardan-AI
Back to analyses
AI Cybersecurity1 September 2026

AI Cyber Defense: Why 116 Rivals Signed the Same Letter — and What That Doesn't Guarantee

116 technology companies, including head-to-head rivals, co-signed a call for collective action on AI cyber defense in late August. Collective-action economics explains why voluntary coordination is rational here — and why, by construction, it remains insufficient without a binding mechanism.

On August 27, 2026, 116 companies and organizations — including direct competitors in generative AI (Anthropic, OpenAI, Google, Microsoft, AWS) alongside cybersecurity players such as Cisco, Cloudflare, CrowdStrike and Oracle — co-signed a joint text calling for collective action against AI-enabled cyberattacks. The letter acknowledges that current practices are insufficient, calls for equipping more defenders with AI-capable tools, and asks for a coordinated, unified response. Its most-quoted line — “we have a limited window” — sums up the perceived urgency.

The more striking fact is not the letter's content but its signatory list: firms that otherwise compete fiercely over models, customers and talent agreed to co-sign a single document with no apparent commercial payoff. Mancur Olson's theory of collective action (1965) predicts the opposite in a large group: as the number of actors grows, the individual incentive to free-ride on others' effort should dominate, absent a selective mechanism (sanctions, or benefits reserved for contributors). Here, 116 actors signed anyway, gaining no observable selective advantage from doing so.

The explanation lies in the nature of the good at stake. Cyber defense against AI-enabled attacks is not a purely private good whose benefits one firm alone could capture: sharing threat intelligence (indicators of compromise, observed attack techniques) produces increasing returns to adoption, in the sense of Katz and Shapiro's (1985) network externalities — the more actors share, the better detection becomes for the whole ecosystem, and especially for the signatories themselves, whose infrastructure is deeply interconnected. Kunreuther and Heal (2003) formalized this case as “interdependent security”: when one actor's vulnerability creates risk for others — structurally true of shared cloud stacks, common APIs and connected industrial systems — individually optimal investment falls mechanically short of the collectively desirable level, which is exactly what pushes rational competitors toward coordination rather than pure rivalry.

That said, this letter should not be read as an insurance policy. A joint statement with no monitoring mechanism, no sanction for non-compliance and no quantified financial commitment matches precisely what Elinor Ostrom (1990) identified as the missing ingredient for durable commons governance: mutual monitoring and graduated sanctions. Without those two elements, a collective call remains, in game-theoretic terms, a case of “cheap talk” (Farrell and Rabin, 1996) — an informative, coordinating signal, but a non-binding one, whose real value depends entirely on what follows from it.

The comparison with California's own initiative, announced August 10, 2026, is instructive here: the state's “AI Cyber Defense Program” takes a different institutional route — public and budget-backed rather than voluntary and private — one that can, in principle, carry both funding and obligations. This dual-track pattern echoes a point already made in our analysis of US regulatory fragmentation (Aug 19, 2026): the United States is answering AI's challenges with a patchwork of disjointed initiatives — California on the defensive front here — while the EU addresses critical-infrastructure security through a single instrument, the AI Act, whose “high-risk” obligations have been enforceable since August 2, 2026.

For a CISO or an executive in aerospace, defense, energy or oil & gas, the practical takeaway has two parts. First, the letter itself is neither protection nor proof of compliance — it replaces no existing regulatory obligation and should not be treated internally as if it did. Second, its real significance will be measured by what follows in the coming months: actual threat-intelligence sharing among signatories, joint incident-response protocols, or dedicated funding. That materialization — or its absence — is what will separate a genuine coordination signal (in Schelling's 1960 sense, a focal point around which actors align expectations) from a statement of intent with no follow-through.

116 companies and organizations, including direct AI rivals, co-signed a call for collective action on cyber defense
116 signatories — including OpenAI, Anthropic, Google, Microsoft, AWS, Cisco and CrowdStrike — CNBC, Aug 27, 2026.

Analysis by

Cardan-AI Intelligence

Our research and analysis unit, dedicated to applied AI for business, industry and regulatory compliance.

Let's talk about your next competitive edge

A 30-minute conversation to identify your most profitable AI use cases.