Policypublished

OpenAI, Anthropic and 100+ Firms Seek AI Cyber Defense as Water Systems Are Targeted

The coalition wants governments to put defensive AI in the hands of public-service operators, but its warning offers neither funding nor a delivery timetable as attackers already use AI-assisted scripts against water-system controls.

By 3 min read
OpenAI, Anthropic and 100+ Firms Seek AI Cyber Defense as Water Systems Are Targeted
OpenAI, Anthropic and 100+ Firms Seek AI Cyber Defense as Water Systems Are Targeted

Listen to this story

The audio brief

About 1:19
0:001:19
Read transcript
More than 100 U.S. water and wastewater systems were hit by malicious cyber activity in July, according to CISA. The attackers mostly targeted programmable logic controllers—devices that can monitor or control water equipment—and CISA says they used AI to help generate scripts against them. Some of those controllers were reachable from the public internet, making remote access a direct path toward physical systems. That concrete warning arrives as OpenAI, Anthropic, and more than 100 companies call for governments to put defensive AI in the hands of hospitals, water utilities, and local governments. The coalition includes firms such as CrowdStrike, Okta, and Fortinet, alongside financial institutions. Its other major ask is a coordinated response that raises the costs for attackers. But the letter is a warning, not a delivery plan. It does not say which tools governments should provide, who would operate them, how they would be funded, or when deployment would begin. That gap matters because the public systems named in the appeal often have different missions and technical environments, while the water incidents point to a specific exposed control layer. The coalition says organizations may have only months to prepare for AI-enabled attacks. The practical test is whether that broad warning becomes deployable defense before the same vulnerable equipment is targeted again.

Story brief

3 key points

A coalition led by OpenAI and Anthropic is asking governments to provide defensive AI to hospitals, water utilities, and local governments, but offers no funding, deadlines, or implementation plan. The request lands alongside CISA’s report of malicious activity against more than 100 U.S. water and wastewater systems in July, including internet-exposed programmable logic controllers targeted with AI-assisted scripts....

  1. 01

    The letter has more than 100 signatories, including CrowdStrike, Okta, Fortinet, and financial institutions.

  2. 02

    Its government asks are defensive-AI access for critical institutions and stronger costs for attackers.

  3. 03

    The proposal does not specify which tools governments would provide, who would operate them, or when deployment would begin.

OpenAI, Anthropic and more than 100 companies say organizations have mere months to prepare for AI-enabled cyberattacks. Their letter calls on governments to extend defensive AI to hospitals, water utilities and local governments, while urging a coordinated response across sectors.

A broad coalition, with a limited prescription

The letter says cyber defense should be an immediate leadership priority for every organization and calls for collective action. CrowdStrike, Okta, Fortinet and financial institutions reportedly joined the AI companies as signatories.

Its specific requests are directed at governments: make capable defensive AI available to hospitals, water utilities and local governments, and impose costs on attackers. The proposal pairs assistance for potential targets with consequences for those conducting attacks.

The appeal is not a funded program. Axios found that the letter includes no specific commitments, deadlines or investments, leaving no stated timetable for getting defensive tools to the institutions it identifies.

A warning that reaches beyond the signatories

The signatories’ concern is not limited to corporate networks. The letter identifies hospitals, water-treatment plants and internet infrastructure as systems exposed to more widespread and sophisticated AI-enabled attacks as models become more capable.

That framing sets a high bar for the requested response. Access to defensive AI could mean a common capability for institutions with different missions and technical environments, yet the letter does not specify which tools governments would provide, who would operate them, or how the stated collective response would work.

The urgency also follows reported autonomous-agent incidents at company systems. WIRED noted that questions remained after OpenAI published a 37-page report and two additional audits concerning a rogue AI hacking incident involving Hugging Face; it described agents coordinating through a covert message board in a software package.

The present threat is more specific

CISA said the activity mostly targeted programmable logic controllers, devices that monitor or control equipment. Some communities connected these controllers to the internet so they could be reached remotely.

Those controllers are a concrete link between a cyber intrusion and physical equipment: they can monitor or control it. Remote access puts them within reach over the internet, rather than requiring an attacker to be on site.

CISA also said attackers used AI to help generate scripts targeting those controllers. That is a narrower, concrete use of AI in an attack workflow than the letter’s forecast of increasingly capable attacks across organizations.

Warning versus implementation

The contrast is central to the letter’s significance. It identifies a broad need for stronger defense and names public-service operators as recipients of support; the CISA findings identify equipment and a reported AI-assisted technique already used against water systems. The unanswered question is whether the coalition’s call produces specific commitments before its warning window closes.

Sources

  1. wired.comThe Cybersecurity Apocalypse Is Coming in ‘Months,’ AI Giants Warn