.png)
.png)
Somewhere in a hospital trust's IT department last month, an analyst watched an alert flash and cleared it without much thought. Legacy systems throw up noise constantly, and there is rarely time to chase every flicker. That single act of triage, repeated thousands of times a day across the NHS estate, is the quiet backdrop against which a hundred of the world's largest technology companies chose this week to issue a joint warning. Google, Microsoft, Anthropic, OpenAI, and a cluster of banks and payment processors signed a letter arguing that cyber-attacks powered by artificial intelligence are about to become both more common and more capable, and that current defences will not hold.
The letter is unusually blunt for a document with this many corporate signatories. It describes a chronic underinvestment in the security of critical infrastructure and calls on governments to fund and test defensive AI tools for hospitals and water utilities specifically. That naming of hospitals is not incidental. Health systems sit at the exact intersection the letter is worried about: institutions that hold enormous quantities of sensitive data, run on infrastructure that is often decades old, and cannot simply switch off during an incident the way a retailer or a media company might.
For the NHS, the relevance is not abstract or borrowed from a wider technology story. It is structural. NHS trusts have spent years modernising patient records, rolling out the NHS App, and centralising data through platforms built to support prevention and integrated care. Each of those moves, sound in their own right, expands the surface area available to an attacker. The 2017 WannaCry incident, which cancelled tens of thousands of appointments, offered an early demonstration of what happens when ageing NHS infrastructure meets an automated threat. What the letter describes is a version of that risk moving several orders of magnitude faster, generated and iterated by AI systems capable of finding flaws that have sat undetected for years, in some cases decades.
The political awkwardness sits in the gap between warning and access. The same companies calling for broader deployment of defensive AI tools are, in several cases, the ones restricting access to their most capable systems on the grounds that they are too dangerous to release widely. Anthropic's own Mythos model is cited in reporting around the letter as an example, a tool the company says can find vulnerabilities that have evaded human researchers, and one it has chosen to limit rather than distribute. That tension will land squarely on NHS leadership. Trusts are already navigating tight procurement rules, patchy digital maturity across the estate, and workforce shortages in cybersecurity roles that predate this letter by years. Being told that only a handful of firms hold the tools capable of matching an AI-enabled attacker, and that access to those tools remains at the companies' discretion, is not a reassuring position for anyone responsible for patient data or clinical continuity.
There is also a governance question that UK policymakers have not fully answered. NHS digital strategy has largely been framed around adoption, how quickly trusts can integrate AI into diagnostics, triage, and administrative workload. Security has tended to sit downstream of that agenda rather than alongside it. The letter's central claim, that status quo defences will not be enough within months rather than years, argues for treating cyber resilience as a first order component of the life sciences and digital health strategy, not a compliance function attached afterwards.
None of this requires panic. It requires the kind of unglamorous, sustained investment that rarely survives a spending review intact: funded training for NHS cybersecurity staff, testing regimes for AI-enabled threats built into procurement rather than bolted on, and clearer lines of responsibility between trusts, NHS England's successor bodies, and the vendors supplying the underlying platforms. The letter's authors are right that the window for doing this in an orderly way is short. Whether the NHS gets there through planning or through the next incident is, for now, still an open question.