OpenAI, Anthropic, and over a hundred other companies just warned that we only have months to prepare for AI-powered cyberattacks.
Here's what the open letter actually says, per Axios's reporting.
Who Signed It and What They're Saying
"OpenAI, Anthropic, Amazon Web Services, Microsoft and more than 100 other companies warned Thursday that the organizations now only have months to prepare for AI-enabled cyberattacks." The letter itself states: "We have a limited window to strengthen cyber defenses." OpenAI organized and published the letter, and reporting notes more companies are still being added to the signatory list, which also includes Google.
Who's at Risk
"Hospitals, water treatment plants and other critical infrastructure will face a swarm of hacking threats as AI makes sophisticated cyber capabilities cheaper and more accessible to attackers." The underlying issue is a familiar one made worse: these systems have long had real vulnerabilities, but exploiting them used to require hackers to invest significant time learning the specifics of each system. AI models are now cutting that preparation time down sharply.
This Already Happened Once
"The open letter comes amid a wave of cyberattacks against critical infrastructure, including one targeting U.S. water systems with an apparent AI-generated exploitation script." That reference traces back to a federal advisory issued August 18 by the NSA, CISA, and FBI, warning that threat actors had used AI-generated exploitation scripts -- disguised as legitimate monitoring tools -- targeting Siemens S7 programmable logic controllers used in water and wastewater utilities and critical manufacturing. The advisory describes this as reconnaissance and capability-building activity rather than a single completed catastrophic attack, which is exactly the kind of early-warning-sign the new letter is pointing to.
What They're Actually Asking For
Every organization should raise security standards and fix its "highest-risk weaknesses." Frontier AI companies are asked to give defenders access to their most capable response models during major incidents, with "significant funding, training, and hands-on support" for critical infrastructure providers. Critical infrastructure operators, in turn, are asked to build tools that track how AI agents are actually being used inside their own systems, test for vulnerabilities proactively, fix problems responsibly once found, and share useful security information with governments and other defenders rather than sitting on it.
The Catch
"The signatories didn't make any commitments, deadlines or specific investments as part of the letter."
How Security Experts Are Reacting
Reaction has been mixed. Diana Kelley, CISO at Noma Security, described AI agents as useful for surfacing missed vulnerabilities and automating reconnaissance work at what she called "machine speed" -- a genuine capability upgrade for defenders, not just attackers. But John Gallagher, a VP at Viakoo, was far more skeptical of the letter's framing, comparing frontier AI developers issuing warnings while continuing to ship increasingly capable models to "an arsonist selling fire extinguishers."
The Bottom Line
The letter reads as a genuine, urgent warning from the companies best positioned to know what's coming, paired with an admission that nobody's actually put money or deadlines behind it yet.