A new work group is developing playbooks, expected by the end of the year, to help health systems respond to emerging AI cyber threats.
By Alyx Arnett
The time hospitals have to respond to a cyberattack could be shrinking dramatically as increasingly capable artificial intelligence (AI) models enter the equation. Tasks that once unfolded over days or weeks could happen in seconds, creating a problem that traditional cybersecurity processesโand human respondersโmay not be fast enough to address.
โWith the capability of these Mythos-class models … no human can respond that quickly,โ says Coalition for Health AI (CHAI) CEO and co-founder Brian Anderson, MD.
Anderson says Anthropicโs Mythos-class models, including the public Fable variant released in June 2026, have changed the cybersecurity landscape by compressing attack timelines and expanding what bad actors can do with PHI exfiltration and ransomware.
Those emerging capabilities are part of what prompted CHAI to launch its new Health AI Cybersecurity Work Group. The nearly 100-member group is developing guidance aimed at helping health systems respond to frontier model threats while also exploring how the technology can be used for cyber defense, with playbooks expected by the end of 2026.
Why Healthcare Needs Its Own Playbook
The idea for the work group grew out of what CHAI saw as a gap in broader efforts to address the cybersecurity implications of advanced AI. Anthropicโs Project Glasswing brings together technology and infrastructure organizations to find and fix vulnerabilities in critical software, while OpenAIโs Daybreak Defense Network works with cybersecurity companies and other partners to develop AI-powered defensive tools and workflows.
Anderson says CHAI supports those efforts, but health system and payer leaders were concerned that healthcare and its particular operational challenges were not represented.
โThere are no health sector leaders. There are no health sector companies,โ Anderson says. โThere was a growing chorus of health systems and payers within CHAI that were saying we need to have a health sector-specific effort that takes into consideration the unique things about the health sector.โ
To address that gap, CHAI brought together health systems, payers, and technology companies to develop guidance tailored to healthcareโs needs. The goal is not simply to identify the risks posed by more capable AI models, but to get specific about how healthcare organizations could respond.
โNo one has developed these kinds of playbooks yet,โ Anderson says. โWe need to get to that level of technical specificity.โ
What the Work Group Is Building
The work group plans to develop a defensive playbook, an offensive playbook, and a frontier AI cyber risk assessment tool, among other resources. Its leadership council will oversee the effort and work to ensure the resources reflect the threat levels hospitals and health systems are currently facing.
Anderson says the playbooks are intended to move beyond broad recommendations and provide more specific guidance on how organizations could use new defensive strategies. The goal is to develop technically specific reference implementations that account for the technologies already in use within a health system. As an example, Anderson says the guidance could distinguish between the technical steps an organization might take with a Cisco router versus another type of router.
The group is also exploring what it looks like to use AI itself as part of that defense. One area Anderson points to is agentic orchestration. As health systems deploy AI agents capable of carrying out multistep tasks, they will need ways to manage those agents’ identities, permissions, and actions in real time.
โNo human can do that,โ Anderson says. โWe need AI tools that are actually monitoring the actions and the steps that these agents are taking.โ
Exposed API endpoints are another potential use case. Anderson says AI agents could monitor those connections for unauthorized access and respond by using tools, writing code, or denying permissionsโallowing some defensive actions to happen at speeds a human analyst could not match.
Some of those capabilities are already being developed. Anderson says some of the leading technology companies CHAI is working with had early access to Mythos through Project Glasswing and have been building tools and capabilities aimed at the needs of health systems and payers.
What Comes Next
Once the playbooks are released, Anderson says the goal is for health systems to be able to use them to begin putting new defensive strategies into action with the teams and tools they already have.
Where additional capabilities are needed, technology vendors could play a role. Anderson says the hope is that technology companies participating in the effort will take the best practices that emerge from the playbooks back to their product teams and develop tools health systems can deploy and customize locally.
CHAI also wants the guidance to be usable by hospitals without the resources of a large academic medical center. Community health systems, safety net clinics, and rural health clinics are represented on the leadership council for that reason. The intent, Anderson says, is to meet healthcare organizations where they are, including those working with limited resources.
โIf we build a set of operational and defensive strategy playbooks that can only be implemented by the most well-resourced academic medical centers, this effort will be a failure,โ Anderson says.
Access to the finished materials will not be limited to CHAI members, though there will be a vetting process modeled on Health-ISAC’s approach to releasing technical guidanceโan effort to make the content broadly available without handing a roadmap to bad actors.
In the meantime, Anderson encourages HTM teams to engage with the work in progress. Additional webinars are planned between now and December, when CHAI aims to have substantive materials ready to share around the Health-ISAC convention.
โThis is all about sharing and developing insights that can only happen when we come together and develop those best practices,โ he says.
ID 432284225 | Ai Cyber Defense ยฉ Wrightstudio | Dreamstime.com