EN

AI Leaders Warn Cyber Defenses Have Only Months

Sukaina Khalid

Key Points

  1. More than 100 companies warned organizations have only months to prepare for AI-enabled cyberattacks.
  2. Signatories urged collective action across industry and government to secure critical infrastructure and improve threat sharing.
  3. AI is making sophisticated attacks cheaper and easier against hospitals, water systems and power plants.

The latest

OpenAI, Anthropic, Amazon Web Services, Microsoft and more than 100 other companies warned Thursday that organizations have only months to strengthen defenses against AI-enabled cyberattacks. In an open letter, the signatories said hospitals, water treatment plants and other critical infrastructure could face a swarm of threats as AI makes sophisticated cyber capabilities cheaper and more accessible. They called for collective action to secure essential systems and make AI-assisted intrusions harder and more expensive.

Details

  • Security baseline: Every organization should raise internal security standards, fix its highest-risk weaknesses and demand stronger safeguards in anything it buys, builds or deploys. The letter specifically includes AI-generated code, placing procurement, development and deployment choices within the broader effort to adapt to a changing threat landscape.
  • Defensive tools: Cybersecurity and technology companies were urged to test and develop tools that make AI-powered defenses accessible and deployable for critical infrastructure operators. The companies should also share threat intelligence with one another, helping defenders respond more quickly as attackers gain access to increasingly capable AI systems.
  • Government coordination: Governments should strengthen channels for distributing actionable threat intelligence, coordinate defenses at local, national and international levels, and provide funding for cyber defense. The proposed plan divides responsibility among public authorities, businesses, cybersecurity providers, technology companies and AI developers.
  • Frontier model access: Frontier AI companies should give defenders access to their most capable response models during major cyber incidents. The requested assistance also includes significant funding, training and hands-on support, particularly for providers operating critical infrastructure such as water, energy and healthcare systems.
  • Threat acceleration: Critical infrastructure has long contained vulnerabilities in the tools controlling machinery, but exploiting those weaknesses previously required hackers to spend substantial time learning complex systems. AI models are now drastically reducing the time and effort needed for that preparation, expanding access to sophisticated offensive capabilities.
  • No firm commitments: The letter did not include commitments, implementation deadlines or specific investments from the signatories. Its proposals instead outline steps for companies and governments to take during the limited preparation window, from repairing weaknesses and developing defensive tools to expanding intelligence sharing and incident support.

Background

The warning follows a wave of cyberattacks against critical infrastructure, including an attack targeting US water systems with an apparently AI-generated exploitation script. Water networks and power plants have historically carried weaknesses in the technologies that operate machinery, while their complexity once created a substantial barrier for attackers. AI is lowering that barrier by shortening the preparation needed to understand and target such systems.

What’s next

The next indicator will be whether signatories turn the appeal into defined investments, deadlines or operational commitments, including access to advanced response models during major cyber incidents.

 

What to read next