AI News Feed
Market watch
Companies

OpenAI, Google and 100+ firms warn AI cyberattacks are about to scale

More than 100 companies including OpenAI, Google and Microsoft published an open letter on Aug. 27 warning that AI-enabled cyberattacks will become far more widespread in coming months and urging collective defense.

The letter, titled "A call for collective action on cyber defense," opens with the statement "We have a limited window to strengthen cyber defenses." It identifies hospitals, water treatment plants and internet infrastructure as the assets most at risk. The signatories argue that the status quo in security will not hold, pointing to longstanding bugs, excessive permissions, misconfigurations and weak authentication that attackers already exploit without AI assistance.

The letter proposes three core principles: recognize that status quo security won't be enough, empower more defenders with cyber-capable AI, and mobilize a collective response. It then lists actions for organizations, governments, security vendors and frontier AI developers. Organizations are urged to make cyber defense an immediate leadership priority, clear high-risk weaknesses and raise standards for AI-generated code. Security vendors should test products against current AI capabilities, get defensive tools to critical infrastructure operators and share threat intelligence. Governments are asked to coordinate responses locally and internationally and fund protection of essential services. Frontier AI developers are called on to ensure model access, fund defenders, build observability and security tools, ensure agentic identities are traceable and accountable, and support defenders during live incidents.

The warning follows a joint advisory issued Aug. 18 by the U.S. National Security Agency, Cybersecurity and Infrastructure Security Agency and Federal Bureau of Investigation. The agencies said threat actors are using AI-generated exploitation scripts for reconnaissance against Siemens programmable logic controllers, targeting water and wastewater utilities and critical manufacturing. CrowdStrike's annual threat hunting report found that attackers picked up 88% of newly public proof-of-concept exploits within 48 hours during the first six months of the year.

Security experts offered a mixed reception. Diana Kelley, chief information security officer at Noma Security, said the letter is an admission that AI is changing the economics of attack faster than organizations are paying down security debt. She noted that a company's own agent deployments now form part of its attack surface. John Gallagher, vice president at Viakoo, said the technical premise holds up but the optimism about defenders catching up does not. He called the pace of remediation in operational technology and critical infrastructure "glacial," and added that a frontier developer shipping more capable models while warning that disaster is months away "kind of like an arsonist selling fire extinguishers."

The letter contains no commitments, deadlines or measurable targets, as Axios noted. Engadget also criticized the timing, calling the effort "too little too late" and noting that many signatories have already pushed AI tools into their operations. Most of the vendors on the list sell AI security products, and OpenAI's Daybreak program is among them.