OpenAI rallies 100+ companies to warn of imminent AI cyberattacks on infrastructure

OpenAI rallies 100+ companies to warn of imminent AI cyberattacks on infrastructure

OpenAI has published an open letter on global cyber defense, co-signed by more than 100 companies. Named signatories include Microsoft, Google, AWS, Anthropic, Cisco, CrowdStrike, Deutsche Telekom, SAP, and Mastercard. The letter warns that AI-enabled cyberattacks will become far more widespread and sophisticated, with hospitals, water utilities, and other critical infrastructure at the highest risk.

The signatories argue that today's AI advances are already giving defenders new ways to fix weaknesses that have accumulated for years, and they urge organizations to deploy AI-based defenses now, while defenders still hold an edge over attackers. The letter directs three calls to action: companies should make cybersecurity a C-suite priority, governments should increase funding and coordination, and AI companies should supply affordable security tools to organizations that are otherwise underfunded. It adds that long-standing gaps, unpatched software and weak authentication among them, still need urgent attention on their own.

The letter's warning has separate, official backing. A joint alert from the NSA, CISA, and FBI, issued in mid-August, found that attackers are already using AI to write exploit scripts targeting industrial control systems such as Siemens S7, across the US energy, water, chemicals, and manufacturing sectors.

Key facts

  • OpenAI published an open letter on global cyber defense, co-signed by more than 100 companies, including Microsoft, Google, AWS, Anthropic, Cisco, CrowdStrike, Deutsche Telekom, SAP, and Mastercard.
  • The letter warns that AI-enabled cyberattacks will become far more widespread and sophisticated, putting hospitals, water utilities, and other critical infrastructure at the highest risk.
  • It calls on companies to make cybersecurity a C-suite priority, governments to increase funding and coordination, and AI companies to provide affordable security tools for underfunded organizations.
  • It also flags long-standing weaknesses, unpatched software and weak authentication among them, as still needing urgent attention on their own.
  • A joint NSA, CISA, and FBI warning from mid-August found that attackers are already using AI to write exploit scripts targeting industrial control systems such as Siemens S7, across the US energy, water, chemicals, and manufacturing sectors.

Why it matters

The letter puts more than 100 companies behind one public statement that AI-enabled cyberattacks are about to become far more widespread and sophisticated. The named signatories, Microsoft, Google, AWS, Anthropic, Cisco, CrowdStrike, Deutsche Telekom, SAP, and Mastercard, put real names behind the number. The warning also lands alongside a separate government alert: the NSA, CISA, and FBI say attackers are already using AI to write exploit scripts against industrial control systems, so the letter's central claim, that the threat is no longer theoretical, has independent backing from mid-August.

Who it affects

The letter names hospitals, water utilities, and other critical infrastructure as facing the highest risk. The corroborating NSA, CISA, and FBI warning points to specific US sectors already targeted: energy, water, chemicals, and manufacturing, where AI-written exploit scripts have been aimed at industrial control systems such as Siemens S7. The letter's calls to action reach further: companies in general are asked to treat cybersecurity as a C-suite matter, governments are asked to add funding and coordination, and AI companies are asked to make affordable security tools available to organizations that cannot otherwise afford them.

How to use it

The letter's own recommendation is to act now, while it says defenders still hold an edge: deploy AI-based defenses before attackers scale up further. It asks company leadership to make cybersecurity a C-suite responsibility rather than delegate it, asks governments to add funding and coordinate more closely, and asks AI companies to make affordable security tools available to organizations that cannot afford enterprise-grade tooling today. It also insists that the basics still matter: patching known software and strengthening authentication need urgent attention on their own, regardless of any AI-specific response. The letter does not say which specific AI tools organizations should deploy, and it puts no figure on the funding it asks governments for.

How solid is it

The claims rest on two separately verifiable sources. The open letter carries the names of more than 100 companies, and the ones named in this account, Microsoft, Google, AWS, Anthropic, Cisco, CrowdStrike, Deutsche Telekom, SAP, and Mastercard, are large, well-known organizations, which makes the letter itself easy to check. The corroborating warning comes from three US government agencies acting jointly: the NSA, CISA, and FBI, about as authoritative a source as this topic gets. That said, no exact date is given for either document, only mid-August for the agencies' warning, and the account gives no report title or link for it. The agencies' warning also describes a capability already in use, AI-written exploit scripts aimed at industrial control systems, rather than naming one confirmed, completed attack.

Risks and caveats

The letter is a statement of intent, not a binding commitment: it calls on companies and governments to act but does not commit any signatory to specific spending, timelines, or tools. The figure of more than 100 signatories is not broken down beyond the nine companies named here, so this account cannot say who else signed or from which sectors. The NSA, CISA, and FBI warning cited alongside it also describes AI-assisted attacks as a capability currently in use, not a specific completed attack on named infrastructure, so it supports the letter's premise without itself confirming a finished incident.

“AI-enabled cyber attacks will become far more widespread and sophisticated”

— the open letter, signed by OpenAI and 100+ companies