OpenAI and Over 100 Companies Warn Enterprises Have Months to Prepare for AI-Powered Attacks
Cybersecurity

OpenAI and Over 100 Companies Warn Enterprises Have Months to Prepare for AI-Powered Attacks

A joint letter from OpenAI, Anthropic, Microsoft, Google, and more than 100 other firms points to an AI-generated exploit already used against US water systems, and asks governments for help that comes with no funding attached.

PublishedAugust 29, 2026
Read time7 min read
Share

A Letter With More Than 100 Signatures and No Enforcement Mechanism

On August 27, OpenAI released an open letter signed by more than 100 companies, among them Anthropic, Microsoft, Google, AWS, Accenture, Capital One, Visa, and Hugging Face. The signatories span AI labs, cloud providers, cybersecurity vendors, telecoms, financial institutions, and think tanks, a coalition wide enough to suggest genuine alarm rather than a single vendor's marketing exercise dressed up as industry consensus. The letter states plainly: "We have a limited window to strengthen cyber defenses," and frames the next several months as the period in which AI-enabled attack tooling moves from research curiosity to routine capability in the hands of ordinary criminal groups, not just nation-state actors with dedicated research budgets.

What the letter does not contain is any binding commitment from the companies that signed it. There is no funding pledge, no shared timeline beyond the general phrase "coming months," and no named point of accountability if the window closes without meaningful government action. For a reader who has sat through prior industry warnings on AI risk that generated a news cycle and then dissolved into silence, that gap is worth noting before taking the rest of the letter's urgency at face value. Signing a letter costs a company nothing beyond reputational goodwill, which makes the letter more useful as a signal of what these firms are seeing internally than as a plan anyone should expect them to execute on their own.

The Water Utility Attack the Letter Points To

The letter's strongest piece of evidence is not hypothetical. It references a recent attack on US water treatment systems that used what appears to be an AI-generated exploitation script, a detail meant to move the conversation from forecast to documented fact. Water utilities have chronically underinvested in security relative to the harm a successful intrusion can cause, running on aging control systems with small IT staffs stretched across operations, compliance, and everything else a municipal utility needs to keep functioning. That combination makes them a preview of what happens once AI lowers the skill floor required to find and exploit weaknesses in operators who were never resourced to defend against a sophisticated adversary in the first place.

Hospitals get the same treatment in the letter, grouped with water utilities as the critical infrastructure categories most exposed to AI-accelerated attacks. Neither sector runs security operations comparable to a bank or a hyperscaler, and neither can simply pass the cost of better defenses on to customers the way a commercial software vendor can. The letter's framing implies that AI attack tooling will find the weakest link first, and infrastructure operators sitting outside the enterprise security perimeter, without dedicated threat intelligence teams or six-figure security budgets, are exactly that weakest link today.

Anthropic's Own Disclosure Backs the Urgency

The letter's timing lines up with a disclosure Anthropic made separately: a Chinese state-sponsored group manipulated Claude Code to run an intrusion campaign against roughly 30 global entities, producing what Anthropic described as confirmed high-value targets for intelligence collection. That disclosure gives the letter's warning a concrete anchor from one of its own signatories, rather than a hypothetical drawn from a vendor threat report written to sell a product. It is one thing for a coalition letter to warn about a future risk. It is another for one of the labs signing that letter to confirm the risk already produced a working campaign against dozens of real organizations.

For enterprise CISOs, the relevant takeaway is not primarily the specific nation-state actor involved, since attribution rarely changes what a defender should actually do differently on Monday morning. It is that a frontier coding model was steered into performing reconnaissance and exploitation work with minimal human oversight at each stage of the intrusion. That is the same category of automation defenders are being told to expect at far greater scale, and it is likely to be aimed first at targets with considerably less sophisticated defenses than the AI labs themselves, which at least have internal monitoring built specifically for this failure mode.

What the Signatories Are Actually Asking For

The letter asks governments to strengthen channels for sharing actionable threat intelligence, coordinate defense across local, national, and international levels, and fund cyber defense initiatives for the sectors least equipped to self-fund them. It specifically calls for hospitals, water utilities, and local governments to get access to defensive AI tools, plus authorization to test and deploy those tools with hands-on support from trusted security providers rather than being left to figure out procurement and integration on their own timeline.

It also asks governments to impose costs on attackers, language that reads as a push for more aggressive attribution and sanctions rather than a specific, actionable policy mechanism the letter names outright. Read together, the asks describe a public-private defense model that does not exist yet at the scale the letter implies is needed, and the letter offers no interim step for the months between now and whenever that coordination might actually materialize through legislation, agency funding, or executive action.

The Ask Skips the Budget Line

Notably absent from the letter is any commitment of capital from the companies signing it. Firms with combined market capitalization in the trillions are asking governments to fund the defense of critical infrastructure rather than offering to underwrite any of it directly themselves. That is a defensible position, since public infrastructure funding is a legitimate government function and these companies are software and cloud businesses rather than utility operators. It also means the letter's stated urgency is not backed by the signatories' own balance sheets in any way that shows up as a line item.

This pattern is familiar to anyone who has tracked industry open letters on AI risk over the past several years. The letters generate coverage and put a public marker down that the companies involved saw the problem coming, which has its own value for later liability and reputation arguments if a major AI-enabled attack does materialize against critical infrastructure. It does not substitute for the operational work of getting real defensive tooling, funding, and trained staff into the hands of a rural water utility before the next AI-assisted intrusion attempt arrives at its network edge.

What Belongs on Your Roadmap Now

Enterprise leaders should not wait on the government coordination the letter describes before acting. The practical response is to pull forward AI-assisted detection and response work that has been sitting in a pilot backlog for budget or governance reasons, and to treat patch velocity on internet-facing systems as a board-level metric rather than an engineering team's private problem buried in a quarterly review. The Claude Code manipulation case shows attackers are already operationalizing agentic tooling faster than most defense teams have adopted the equivalent capability internally.

If your organization touches critical infrastructure, whether as an operator, a vendor, or a downstream customer relying on infrastructure providers, this letter is a reasonable prompt to reassess third-party risk exposure now rather than after the first AI-accelerated incident lands somewhere in your supply chain. The letter is not a plan and does not pretend to be one. It is a signal that the companies best positioned to see attacker tooling evolve in real time are telling you the timeline is shorter than your current security roadmap probably assumes it to be.

Tagged#news#security#ai-security#openai#anthropic#cyber-defense-coalition#ai-powered-attacks#water-utilities