Cisco’s President Says AI Attacks Now Move at ‘Machine Scale.’ His Own Company’s Data Says Defenses Still Don’t.
On September 8, 2026, Cisco President and Chief Product Officer Jeetu Patel told Bloomberg Technology’s Romaine Bostick that “the same tools that help people work more efficiently can also help bad actors operate at machine scale.” He was there to discuss an open letter Cisco had signed twelve days earlier alongside OpenAI, Anthropic, Google, Microsoft, and more than 100 other companies, warning that AI-enabled cyberattacks are about to become “far more widespread and sophisticated.”
The warning isn’t hypothetical. Cisco’s own security guidance already names threat groups using large language models to write malicious scripts and fake video. IBM’s newest breach data shows one in four confirmed intrusions are now AI-enabled — up 56% in a single year, and roughly $1 million more expensive than the average breach.
- 100+companies signedthe August 27, 2026 open letter Cisco co-signed with OpenAI, Anthropic, Google, and Microsoft warning of an AI cyberattack surge — OpenAI, TechCrunch
- 25%of malicious breachesare now AI-enabled, up 56% year over year and averaging $6.0 million each — IBM Cost of a Data Breach Report 2026
- Weeks → minutesexploit windowhow fast Cisco says the gap between a discovered vulnerability and its exploitation has collapsed — Cisco Newsroom, June 2026
Jeetu Patel has run Cisco’s product organization since 2022 and became the company’s president in 2025. On Bloomberg’s “The Close,” he framed the AI security problem the way he has repeatedly this year: the technology is dual-use by design, and the side that scales faster wins. “The same tools that help people work more efficiently can also help bad actors operate at machine scale,” he told Bostick — a variation on a line he had used seven months earlier in a Forbes interview.
“If you have attacks happening at machine scale, you can no longer have defenses at human scale.”
Jeetu Patel, President & Chief Product Officer, Cisco · Forbes, February 12, 2026
The interview’s peg was the open letter Cisco had signed nine days earlier with OpenAI, Anthropic, Google, Microsoft, Amazon Web Services, Oracle, CrowdStrike, Palo Alto Networks, IBM, and more than 100 other companies. Patel was one of the few security-industry executives to go on live television and put a name and a face to a warning that, on paper, reads like boilerplate. On air, it read as urgent: the company that makes the routers, firewalls, and network gear underneath much of the internet was telling investors and the public that its own defenses were racing an adversary that no longer gets tired.
Cisco’s own published security guidance names specifics, not abstractions. It describes TA547, a threat group suspected of using large language models to generate malicious PowerShell scripts; VoidLink, a modular attack framework built with role-based access control and peer-to-peer routing; and UNC1069, which reportedly used AI video tools to fabricate a deepfake impersonating a company CEO. Cisco says it has also been given early access to two frontier models built specifically for offensive and defensive cybersecurity research — Anthropic’s Mythos Preview and OpenAI’s GPT-5.5-Cyber — and that testing both surfaced “rare, high-severity failures,” including goal-directed reasoning and unprompted situational awareness.
Cisco Talos, the company’s threat-intelligence unit, backed that up with its own incident-response numbers: phishing — increasingly AI-assisted — reclaimed the top spot among initial-access methods in Q1 2026 and stayed there into Q2, when it drove more than half of all engagements, including AI-generated QR-code lures and automated multi-factor-authentication bypass attempts. In one case Talos documented, attackers used the Softr AI website-building platform to stand up a convincing fake Outlook login page in minutes.
Cisco has spent 2026 building the products it says the warning demands. In February, it expanded AI Defense with AI-aware secure access (SASE) for agentic workloads. In March, at RSA Conference 2026, it open-sourced DefenseClaw, a free framework that scans, sandboxes, and inventories AI agents, browser plug-ins, and Model Context Protocol servers before they touch production systems — addressing what Cisco says is a gap where 85% of enterprises are piloting AI agents but only 5% have moved them into production, largely for lack of trust. In June, at Cisco Live, it unveiled Cisco Cloud Control, a unified management platform for humans and AI agents to jointly operate and defend infrastructure, alongside Live Protect, which patches runtime vulnerabilities without a reboot, and Quantum Ready Assessments, aimed at “harvest now, decrypt later” attacks already collecting encrypted data to crack once quantum computing matures.
Patel has framed the products around a single idea: AI agents are new co-workers, and co-workers get vetted. “These agents who are going to be conducting this work on our behalf need to get the background checks done, just like you get a background check done for an employee,” he told Euronews in February. “We have to protect the agent from the world… and protect the world from the agent.”
The letter Patel discussed on Bloomberg, “A Call for Collective Action on Cyber Defense,” was published by OpenAI on August 27, 2026, and signed by Cisco alongside Anthropic, Google, Microsoft, Amazon Web Services, Oracle, Cloudflare, CrowdStrike, Palo Alto Networks, IBM, Adobe, Capital One, Visa, Mastercard, and General Motors, among others. Its central claim: “In the coming months, AI-enabled cyberattacks will become far more widespread and sophisticated as models around the world become increasingly capable,” putting “hospitals, water treatment plants, and the infrastructure that powers the internet” at risk. The letter stops short of committing any signatory to specific spending or deadlines — it calls instead for cyber defense to become “an immediate leadership priority,” for governments to “coordinate cyber defense at local, national and international levels,” and for AI companies to fund training and give under-resourced institutions access to defensive AI tools.
OpenAI and its co-signatories frame the letter around what they call the “defenders’ window” — the same AI capabilities that let attackers move faster also let security teams patch faster, if they act now. “We have a limited window to strengthen cyber defenses,” the letter states. OpenAI CEO Sam Altman called it “a critically important moment for cyber defense with AI,” adding there is “not much time to act” and that “only an urgent and intense collective response will work.” Palo Alto Networks threat-intelligence lead Sam Rubin called the shift “generational.”
this is a critically important moment for cyber defense with AI; there is not much time to act. we are happy if you want to work with us or any of our competitors or partners, but please take this moment seriously. only an urgent and intense collective response will work.
We are proud to support @OpenAI's call for collective action on cyber defense. Together, we can make the digital infrastructure we all depend on more secure.
Government guidance has been arriving alongside the industry warnings, not after them. On May 1, 2026, CISA and the Australian Signals Directorate’s Australian Cyber Security Centre, joined by other international partners, published “Careful Adoption of Agentic AI Services,” the first coordinated guidance treating autonomous AI agents as a distinct security category. It flags privilege escalation, behavioral misalignment, and limited auditability as the leading risks, and recommends organizations restrict agent access to sensitive systems and start with low-risk use cases. Nick Andersen, CISA’s Acting Director, said at the time that “CISA is committed to supporting the US’s adoption of AI that includes ensuring it aligns with President Trump’s Cyber Strategy…”
CISA, NSA, and cybersecurity agencies from Australia, Canada, New Zealand, and the UK just published joint guidance on agentic AI systems. The key finding: AI agents are already operating in critical infrastructure with insufficient governance. Not in pilot programs.
IBM’s 2026 Cost of a Data Breach Report, published two months before Patel’s Bloomberg appearance, is the clearest numeric case for what he and the letter’s other signatories are describing. Researched independently by the Ponemon Institute across 602 breached organizations worldwide between March 2025 and February 2026, it found that 25% of malicious breaches were AI-enabled — a 56% increase from the year before — and that those breaches cost $6.0 million on average, above the $4.99 million global average across all breach types. Financial-services firms hit by AI-enabled breaches paid $6.3 million on average; energy-sector victims paid $5.2 million. Organizations that used AI and automation defensively, meanwhile, cut their breach costs by nearly $2 million.
IBM Security’s Suja Viswesan summarized the shift in economics plainly: “What’s changing is the economics of cyberattacks. AI is making attacks faster and cheaper, while breaches keep getting more expensive.” CrowdStrike CEO George Kurtz made a similar case to CNBC the same week the letter published, pointing to Anthropic’s Mythos model as proof that AI could already make cyberattacks “faster and more sophisticated” — a claim investors seemed to believe, given CrowdStrike’s and Palo Alto Networks’ shares each roughly doubled over the year.
Cisco’s president didn’t go on Bloomberg to sell a product. He went on to say, in plain language, that the company selling much of the internet’s underlying infrastructure believes AI has already changed the shape of the fight — and that the shift shows up in IBM’s breach data, in Cisco Talos’s own incident logs, and in a 100-company letter Cisco itself signed. The tools are the same on both sides of the wire. Whoever scales them faster wins.



