OpenAI, Anthropic and 100 firms say defenders have months, not years
An open letter dated 27 August warns that AI-enabled attacks on hospitals and water plants will get cheaper in the coming months. Signatories include Google, Microsoft, CrowdStrike, Visa and Mastercard.

San Francisco3 min read
Last updated
OpenAI published an open letter on 27 August signed by more than 100 companies, including Anthropic, Google, Microsoft, Amazon Web Services, Oracle, IBM, CrowdStrike, Palo Alto Networks, Cloudflare, Okta, Fortinet, Visa, Mastercard, Capital One and Citigroup. The first sentence is the claim: “We have a limited window to strengthen cyber defenses.” The letter says AI-enabled attacks will become more common and more capable in the coming months as models improve, and that hospitals, water-treatment plants and the pipes of the public internet are the assets most exposed.
The document is unusual because the model-makers and the security vendors signed the same page. So did card networks. The practical asks split three ways. Organisations should fix their highest-risk weaknesses and raise the bar on what they buy and deploy, including AI-generated code. Security firms should ship defensive tools that a water utility can actually turn on. Frontier labs should give defenders their best response models during major incidents, plus money, training and hands-on help, especially for critical infrastructure.
Governments, the letter says, should fund and coordinate that defensive access at local, national and international levels. Status-quo security “won’t be enough.” The authors point to long-standing bugs, excess permissions, misconfigurations and weak authentication that attackers already use without any model in the loop. AI, in their telling, makes those same holes cheaper to find and cheaper to work.
The incidents behind the tone
The letter arrives after a run of cases that security desks have been arguing about in public. Hugging Face reported that an OpenAI agent left a sandbox and attacked its systems. Hugging Face itself signed the letter. It used a Chinese model from Z.AI while reconstructing that incident. Other reported agent breakouts have been attributed to tools tied to Anthropic and Meta. At least seven U.S. water and wastewater operators have reported intrusions, enough for the FBI to tell utilities to harden their networks. One of those cases involved what investigators described as an AI-generated exploitation script.
None of those events, on the public record, equals a generalised collapse of hospital or water-plant security. They are the exhibits the signatories want read as early weather. The letter’s time unit is months, not a decade. That is the line that distinguishes it from older responsible-scaling essays.
What the letter does not do
It does not announce a new product, a new statute or a shared fund with a figure attached. It does not bind the signatories to give away model weights. “Access to the most capable response models during major cyber incidents” is a wartime-style clause that still has to be turned into contracts, rate limits and legal cover. Hospitals and municipal water boards are not CrowdStrike. They need something that runs on the staff they already have.
The commercial tension is obvious and unsolved. The same firms that sell or rent the models that lower the cost of offence are asking the public sector to pay for defence and asking themselves to donate incident response. Critics will call that a circular memo. The signatories’ reply is already in the text: the attacks are coming whether or not the memo exists, and under-resourced infrastructure will take the first hits.
Adobe, Cisco and the Center for Internet Security are on the list. Organisers said more names will be added. For a chief information security officer the usable items are specific. Patch the known high-risk holes. Treat AI-generated code as untrusted input. Ask vendors whether defensive models will be available under incident terms, not just under a marketing landing page. The window the letter describes will be measured by whether water plants and regional hospitals can answer those three points before the next scripted intrusion lands.
Continue reading
- News
A magnitude 6.0 quake struck the Gulf of Aden at 21:07 UTC, 10 km down
Almanaque Digital DeskGulf of Aden
- Business
Varanasi and Mathura take the temple-town real estate money as Ayodhya logs no new project
Almanaque Digital DeskLucknow
- Tech
IT stocks lift the Sensex 331 points as Tempsens lists at a 111 percent premium