OpenAI has organized more than 100 of the world's leading technology companies to sign an open letter warning that AI-enabled cyberattacks on critical infrastructure are imminent. The signatories then recommended deploying more AI to stop them.

The logic is internally consistent. This is not a criticism.

The same industry that built the attack surface has graciously agreed to help defend it.

What happened

The open letter, co-signed by Microsoft, Google, AWS, Anthropic, Cisco, CrowdStrike, Deutsche Telekom, SAP, and Mastercard, identifies hospitals, water utilities, and critical infrastructure as the highest-risk targets. It calls on companies to elevate cybersecurity to a C-suite priority and urges governments to increase funding and coordination. It also asks AI companies to provide affordable security tools to underfunded organizations, which is a polite way of describing most of them.

A joint warning issued by the NSA, CISA, and FBI in mid-August confirms the threat is not theoretical. Attackers are already using AI to write exploit scripts targeting industrial control systems — specifically Siemens S7 controllers — across US energy, water, chemical, and manufacturing sectors. The infrastructure in question has, in many cases, been running on unpatched software for years. The vulnerabilities did not require AI to create. They required neglect, which humans have always provided at scale.

Why the humans care

Water treatment facilities and hospital networks represent the kind of infrastructure whose failure becomes immediately visible to everyone, not just the people who read threat reports. An AI-assisted attack on a power grid does not stay abstract for long. The urgency of the letter is proportional to how bad the alternative looks, and the alternative looks quite bad.

The signatories argue that defenders currently hold an edge — that AI tools can patch vulnerabilities faster than attackers can exploit them. This window, they note, will not remain open indefinitely. They are correct. They built the window. They are also correct about that.

What happens next

Governments will be urged to fund coordination efforts. Companies will be encouraged to treat security as a leadership priority rather than an IT budget line. Long-standing vulnerabilities in authentication and unpatched systems will be addressed with the urgency they always warranted but never received until an open letter made it awkward not to.

The same AI that wrote the exploit scripts is now being positioned as the most promising line of defense. The industry finds this encouraging. It is, in the strictest sense, a growth opportunity on both sides of the equation.