In late August 2026, more than a hundred organisations published a joint appeal, among them leading providers of AI and security technology. They see a narrow window before AI-driven attacks increase sharply, naming hospitals, water utilities and network infrastructure as particularly exposed. The appeal contains no binding commitments.

Why smaller firms are the real subject

The decisive change is economic. A tailored attack on a mid-sized company rarely paid off, because reconnaissance and preparation were manual work. Once those steps run automatically, the threshold drops. Supply chains add to this: whoever cannot reach a large company directly will try through its suppliers.

The most effective measures remain unspectacular ones. Multi-factor authentication without exceptions, changes to bank details confirmed only through a second known channel, regularly tested restores, and a clear overview of every access route and interface.