“In the coming months, AI-enabled cyber-attacks will become far more widespread and sophisticated as models around the world become increasingly capable,” the open letter signed by more than 100 tech and cybersecurity companies warned on August 27.
Who sounded the alarm and what they said
More than 100 technology and cybersecurity companies — including OpenAI, Anthropic, Google and Microsoft — published an open letter on August 27 warning that a “narrowing window” remains to act before AI-enabled attacks escalate to a level that threatens critical public services. The signatories framed the risk as imminent, saying AI will make attacks both more widespread and more sophisticated and urging collective action so defenders can use AI to secure systems.
How AI changes the attack surface
The letter specifically identifies how AI will alter attackers’ capabilities and the resulting risks to organizations. According to the text, AI tools will enable threat actors to rapidly identify and exploit a range of common weaknesses, including excessive permissions, misconfigurations, insecure and unpatched software, weak authentication, and the technical debt embedded in legacy systems. At the same time, the authors note, AI can make core security tasks cheaper and more efficient — a capability the letter wants to unlock for defenders as well as attackers.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildActions the signatories say must be taken by organizations and vendors
The open letter lays out concrete roles for different groups. For individual organizations, the signatories say cyber defense must become an immediate leadership priority: organizations should concentrate on remediating the highest-risk vulnerabilities and on upgrading or replacing legacy systems that harbor technical debt.
For cybersecurity firms, the letter asks for accelerated collaboration with technology partners to strengthen existing solutions using AI, and to make AI-powered defensive tools accessible and deployable for operators of critical infrastructure.
What the letter asks of governments and public-service operators
The authors call for governments to expand threat intelligence and incident-response partnerships and to invest in stronger defenses for public services. The letter places particular emphasis on providing capable defensive AI to hospitals, water utilities, and local governments — sectors the signatories single out as being at risk if AI-enabled attacks escalate.
Expectations placed on frontier AI companies
The letter names frontier AI companies explicitly and singles out OpenAI and Anthropic as examples. It urges those companies to provide “responsible model access” and to offer implementation support, particularly for critical infrastructure organizations. The signatories frame this as an obligation for frontier model providers to help ensure their tools are used to protect, not just to attack.
What this means for hospitals, water utilities, and local governments
- Hospitals: The signatories urge governments to ensure hospitals have access to capable defensive AI so that medical services and patient safety do not become collateral damage in escalating AI-enabled cyber campaigns.
- Water utilities: Water treatment plants are explicitly named as at-risk public services; the letter calls for governments to invest in stronger defenses and for vendors to make defensive AI deployable in these operational environments.
- Local governments: The letter urges that local governments be included in strengthened threat-intelligence and incident-response partnerships and be provided access to AI-driven defensive tools to protect municipal services.
The letter is both a warning and a blueprint: it identifies specific technical failure points that AI will help adversaries exploit, and it prescribes roles for companies, cybersecurity vendors, governments and frontier AI firms to blunt those threats. The phrasing repeatedly narrows the time available for action — “in the coming months” — and ties success to coordinated, cross-sector steps that make defensive AI both stronger and more widely available.
Whether those steps are taken with the speed the letter says is necessary remains the question the signatories leave on the table. The window they describe is shrinking; the next months will determine whether AI becomes a force multiplier for attackers or a practical tool for defenders.
https://www.infosecurity-magazine.com/news/window-ai-attacks-narrowing-tech/




