“Only a Few Months Left.” Tech Companies Urge Preparation for AI-Powered Cyberattacks
OpenAI, Anthropic, Microsoft, Amazon Web Services, and over a hundred other companies have signed an open letter calling for an urgent strengthening of cyber defenses. They believe organizations have only a few months left to prepare for a new wave of attacks, as AI makes sophisticated hacking tools cheap and accessible.

“We have a limited window left to strengthen cyber defenses,” representatives of the technology industry write in an open letter published on August 27 on the OpenAI website. The Axios publication draws attention to it.
The signatories expect that in the coming months, AI-powered cyberattacks will become significantly more widespread and sophisticated as the capabilities of models grow. Companies and public services crucial to everyday life – including hospitals, water supply systems, and internet infrastructure – could be at risk.
The letter's authors believe that the current level of defense is already insufficient. Vulnerabilities have accumulated in information systems for years: software errors and misconfigurations, excessive access rights, weak authentication mechanisms, and outdated systems lacking necessary updates. This problem is particularly acute for critical infrastructure, where security services often lack resources.
The authors urge the use of AI's own advantages for defense. In their opinion, such tools can make the work of cybersecurity specialists faster and cheaper, and the exchange of ready-made solutions will allow the results of one organization's work to be used to protect others.
What is Proposed
The letter proposes a separate action plan for businesses, cybersecurity and technology companies, governments, and developers of the most powerful AI models.
For ordinary organizations, it is proposed to primarily eliminate the most dangerous vulnerabilities and raise security requirements for everything they purchase, develop, and implement. Separately, software code created with AI is mentioned: stricter requirements should also apply to it.
Cybersecurity and technology companies are urged to test and develop AI-based defense tools as quickly as possible, which critical infrastructure operators can use. Additionally, such companies should exchange information about cyber threats among themselves.
Governments are encouraged to improve information-sharing channels that can be used to counter threats, coordinate cyber defense at local, national, and international levels, and fund it.
Specific proposals are addressed to developers of the most powerful AI models. During serious cyber incidents, they should provide defense specialists with access to their most advanced models to respond to attacks. The letter's authors also urge such companies to provide significant funding, training, and direct technical support – especially to critical infrastructure operators.
As Axios notes, the appeal comes amidst a wave of cyberattacks on critical infrastructure. As an example, the publication mentions an attack on water supply systems in the USA, during which an AI-generated script was allegedly used to exploit a vulnerability.
Critical infrastructure objects, such as water supply systems and power plants, have long had vulnerabilities in their equipment management tools. However, previously, hackers required a tremendous amount of time to understand the complexities of these systems.
AI models now radically lower the barrier to entry, allowing hackers to spend significantly less time and energy preparing such attacks, as experts reported to Axios earlier.
However, as the publication notes, the signatories of the open letter did not make concrete commitments. The document lacks deadlines for the implementation of the proposed measures or promises of specific investments.
"I am not a saint, but I didn't have a reliable shoulder next to me": Ksyusha's mother with SMA may be deprived of parental rights, but she argues that she is capable of improving
Comments