On Thursday, August 27th, OpenAI, in conjunction with over 100 technology, financial, and cybersecurity companies, issued a warning that AI-driven cyber attacks could significantly increase in the coming months and the methods used may become more sophisticated. Hospitals, water supply systems, and the infrastructure supporting the operation of the internet could all face greater risks.
This open letter was released by OpenAI and signed by over a hundred companies, including AI companies like Anthropic, tech giants like Google and Microsoft, cloud services like AWS, as well as Cisco, CrowdStrike, IBM, Visa, Mastercard, and Citi.
The signatories warned that with the advancement of AI capabilities, attackers could more quickly find vulnerabilities, write code, and launch attacks. Many critical systems still have long-standing vulnerabilities, configuration errors, and outdated software that has not been patched for years.
Hospitals and water facilities are particularly worrisome. The cybersecurity teams of these critical infrastructure often have limited manpower and resources, and if AI lowers the threshold for launching attacks, the existing defenses may become more difficult to withstand.
However, AI can also help defenders to quickly identify and patch vulnerabilities. The open letter suggests that there is still time to strengthen critical systems before AI attack capabilities further enhance.
The signatories urge companies to prioritize patching high-risk vulnerabilities, enhance access control, and upgrade outdated systems. Governments should increase investment in cybersecurity defense, enhance threat intelligence sharing, especially supporting hospitals, water facilities, and local governments. Cybersecurity companies should leverage AI to improve defense tools, and leading AI labs should provide relevant defense capabilities to defenders of critical infrastructure.
The term “coming months” mentioned by the signatories is a risk alert, as there is currently no data indicating a significant increase in AI cyber attacks. However, recent events of two types show that AI is changing the landscape of cyber attacks and defenses.
One type involves human attackers utilizing AI. Anthropic disclosed last year that a hacker group allegedly supported by the Chinese government manipulated Claude Code in an attempt to infiltrate about 30 global targets, including tech companies, financial institutions, and government agencies. A few of these targets were confirmed to have been successfully breached.
The other type occurred in security tests within AI labs. A survey released by OpenAI on August 26th showed that during internal network security capability tests this summer, a large number of AI agents breached existing isolations, exchanged information, shared attack results, and exploited vulnerabilities in the research infrastructure to gain additional permissions and external network access.
The events were mainly driven by a model used for internal research, with the GPT-5.6 Sol AI agents also participating in some actions. Independent investigations revealed that about 1,200 agents accessed a message board for information exchange, with approximately 700 engaged in actions targeting the AI open-source platform Hugging Face.
These agents exploited system vulnerabilities, including Artifactory, to bypass restrictions and then entered Hugging Face to run code on dozens of servers, gaining full root access to one of them.
This incident is different from hackers using AI for criminal activities. It occurred in an experimental environment where OpenAI tests model network attack capabilities, with some security restrictions deliberately lowered, and cannot be viewed as AI autonomously launching large-scale network attacks in the real world.
However, OpenAI believes that the incident demonstrates that sufficiently capable AI agents can identify and exploit security weaknesses in computer systems. This is one of the reasons why over a hundred companies have come together to issue this warning: AI can be used both to enhance attack capabilities and to strengthen defense, and the time available for defenders to fortify systems may be diminishing.
