Hospitals, water utilities, and other essential services face a limited period to improve their cyber defenses before AI-enabled attacks become more widespread and sophisticated, the signatories of a new open letter warn. They put that period at months, not years, and argue that attackers may gain from the same advances defenders can use to find and repair weaknesses.
OpenAI published the global cyber-defense letter with more than 100 company co-signers. The group spans AI developers, cloud providers, security companies, banks, and payment networks; named supporters include Anthropic, Google, Microsoft, CrowdStrike, Capital One, Mastercard, Visa, Cisco, SAP, and IBM.
The letter does not cast AI as the source of every security failure. It points instead to longstanding bugs, excessive permissions, misconfigurations, unpatched software, weak authentication, and technical debt in legacy systems. The signatories say today’s security posture will not be enough as AI capabilities improve, and fault historic underinvestment in critical-infrastructure security.
If we act decisively, we can use the defenders' window to make our digital world much more secure.
The open letter, as quoted by CBS News
The prescription is operational as well as political. Organizations are asked to make cyber defense a leadership priority, invest in security teams, test defenses continuously against frontier AI capabilities, and upgrade vulnerable older systems. The letter also calls for shared threat intelligence and tested response playbooks, with results judged by protection coverage, containment speed, and whether fixes work.
Who the letter asks to act
- Governments should strengthen and coordinate defenses at local, national, and international levels.
- Hospitals, water utilities, and local governments should receive capable defensive AI, authorized testing, and hands-on support through trusted providers and partners.
- Frontier AI companies should fund training, provide responsible model access, secure their systems, and offer critical-infrastructure operators technical help.
The coalition explicitly asks AI companies to make security tools affordable for underfunded organizations. That makes availability a central test of the proposal: the letter seeks advanced defensive tools for operators that run essential services, rather than reserving them for well-resourced security teams.
The months-long timeline remains the signatories’ forecast. But a mid-August joint warning from the NSA, CISA, and FBI said attackers were already using AI to write exploit scripts targeting Siemens S7 industrial-control systems in U.S. energy, water, chemical, and manufacturing sectors. Separately, CrowdStrike reported that AI-enabled attacks rose 89% in 2025 from 2024.
Reader comments
Newest comments first. Replies stay oldest first.