A new work group is developing playbooks, expected by the end of the year, to help health systems respond to emerging AI cyber threats.
By Alyx Arnett
The time hospitals have to respond to a cyberattack could be shrinking dramatically as increasingly capable artificial intelligence (AI) models enter the equation. Cyberattack tasks that once unfolded over days or weeks could potentially happen in seconds, creating a problem that traditional cybersecurity processes—and human responders—may not be fast enough to address, says Coalition for Health AI (CHAI) CEO and co-founder Brian Anderson, MD.
Anderson points to Anthropic’s Mythos-class models, a new generation of highly capable AI models designed to perform complex tasks with greater autonomy, including the public Fable variant released in June 2026. He says these models are changing the cybersecurity landscape by compressing attack timelines and expanding what bad actors could potentially do with PHI exfiltration and ransomware.
“With the capability of these Mythos-class models … no human can respond that quickly,” he says.
Those emerging capabilities are part of what prompted CHAI to launch its new Health AI Cybersecurity Work Group. The nearly 100-member group is developing guidance aimed at helping health systems respond to threats posed by frontier AI models while also exploring how the technology can be used for cyber defense, with playbooks expected by the end of 2026.
Why Healthcare Needs Its Own Playbook
The idea for the work group grew out of what CHAI saw as a gap in broader efforts to address the cybersecurity implications of advanced AI. Several initiatives are already bringing technology, infrastructure, and cybersecurity organizations together to explore how AI can be used to strengthen cyber defenses. Among them, Anthropic’s Project Glasswing focuses on finding and fixing vulnerabilities in critical software, while OpenAI’s Daybreak Defense Network works with cybersecurity companies and other partners to develop AI-powered defensive tools and workflows.
But Anderson says health system and payer leaders were concerned that healthcare and its particular operational challenges were not represented.
“There was a growing chorus … within CHAI that were saying we need to have a health sector-specific effort that takes into consideration the unique things about the health sector,” Anderson says.
To address that gap, CHAI brought together health systems, payers, and technology companies to develop guidance tailored to healthcare’s needs. The goal is not simply to identify the risks posed by more capable AI models, but to get specific about how healthcare organizations could respond.
“No one has developed these kinds of playbooks yet,” Anderson says. “We need to get to that level of technical specificity.”
As an example, Anderson says the guidance could distinguish between the technical steps an organization might take with a Cisco router versus another type of router.
What the Work Group Is Building
The work group plans to develop a defensive playbook, an offensive playbook, and a frontier AI cyber risk assessment tool, among other resources. Its leadership council will oversee the effort and work to ensure the resources reflect the threat levels hospitals and health systems are currently facing.
The group is also exploring what it looks like to use AI itself as part of that defense. One area Anderson points to is agentic orchestration. As health systems deploy AI agents capable of carrying out multistep tasks, they will need ways to manage those agents’ identities, permissions, and actions in real time.
“No human can do that,” Anderson says. “We need AI tools that are actually monitoring the actions and the steps that these agents are taking.”
Exposed API endpoints are a potential use case. Anderson says AI agents could monitor those connections for unauthorized access and respond by using tools, writing code, or denying permissions—allowing some defensive actions to happen at speeds a human analyst could not match.
Some of those capabilities are already being developed. Anderson says some of the leading technology companies CHAI is working with had early access to Mythos through Project Glasswing and have been building tools and capabilities aimed at the needs of health systems and payers.
What Comes Next
Once the playbooks are released, Anderson says the goal is for health systems to be able to use them to begin putting new defensive strategies into action with the teams and tools they already have.
CHAI also wants the guidance to be usable by hospitals without the resources of a large academic medical center and has included community health systems, safety-net clinics, and rural health clinics on the leadership council to ensure the guidance reflects the needs and constraints of smaller and lower-resource healthcare organizations.
“If we build a set of operational and defensive strategy playbooks that can only be implemented by the most well-resourced academic medical centers, this effort will be a failure,” Anderson says.
The finished materials will be publicly available, though CHAI plans to use a vetting process modeled on Health-ISAC’s approach to releasing technical guidance to avoid providing bad actors with a roadmap.
In the meantime, Anderson encourages HTM teams to engage with the work in progress. Additional webinars are planned between now and December, when CHAI aims to have substantive materials ready to share around the Health-ISAC convention.
“This is all about sharing and developing insights that can only happen when we come together and develop those best practices,” he says.
ID 432284225 | Ai Cyber Defense © Wrightstudio | Dreamstime.com