The people who built the most powerful AI systems on the planet just published an open letter warning that those same systems could soon be used to devastate hospitals, banks, and critical infrastructure. They say we have a window of months to do something about it. They are also the ones who opened the window.
The Letter, and the Spectacular Irony Behind It
On Thursday, the leaders of OpenAI, Anthropic, Google, and Microsoft joined dozens of other signatories on an open letter warning that AI-enabled cyberattacks pose an imminent and serious threat to public services and technology infrastructure. Also signing on: CrowdStrike, Citi, and Capital One, which is a fun group of institutions to see banding together to express alarm about a crisis their industry helped create.
The letter, as CBS News reports, says there is a "limited window" to strengthen cyber defenses. That window, they warn, may last only months. Not years. Months. This is the part where you set down your coffee.
To be clear about what is happening here: the companies at the absolute frontier of building increasingly powerful AI tools are now publishing urgent warnings that increasingly powerful AI tools are dangerous. This is not subtle. This is the cigarette companies funding lung cancer research, except the cigarettes are sentient and learning new tricks every six weeks.
The Numbers Are Not Comforting
A recent CrowdStrike report found that AI-enabled attacks increased by 89% in 2025 compared to 2024. Eighty-nine percent. In one year. That is not a trend line you want to extrapolate.
The open letter puts the blame for existing vulnerabilities squarely on institutional neglect: "Longstanding bugs, excessive permissions, misconfigurations, insecure and unpatched software, weak authentication and technical debt in legacy systems have left systems exposed." Which is a very polished way of saying that the hospitals and power grids and financial systems that an adversary might want to destroy are currently held together with digital duct tape.
The institutions most at risk from sophisticated AI-driven attacks are, predictably, the ones that have spent the least on keeping their systems current. A county hospital running software from 2011 is not going to fare well against an AI-assisted intrusion campaign designed by a nation-state with unlimited patience and a grudge.
What They Are Actually Asking For
The letter calls for several things. Security teams need more funding and better tools. Organizations should share threat intelligence and tested response playbooks with each other rather than hoarding information out of liability paranoia. Specialized cybersecurity firms need to continuously test defenses against evolving AI capabilities, not just the capabilities from two years ago when they last ran a serious audit.
Governments, the letter says, have a key role to play through coordinated action and by funding cyber defense at the local, national, and international levels. Given that the current U.S. federal government has spent the better part of this year gutting the agencies responsible for exactly that kind of coordination, the timing of this call is either extremely optimistic or quietly desperate.
The letter also puts a specific obligation on the AI companies themselves: fund training, provide responsible access to their models, and secure those models adequately. That last part is doing some heavy lifting, given that the same models being offered through consumer-facing products are the ones sophisticated attackers are already probing for weaknesses.
The Defenders' Window — If It's Real
The letter is not entirely doom. "If we act decisively, we can use the defenders' window to make our digital world much more secure," it says. The idea is that the same AI capabilities that make attacks more powerful can also help defenders identify and patch vulnerabilities faster than any human team could alone. That is a real argument. Security researchers have been making it for a couple of years now.
The catch is that it requires acting decisively, which is historically not something that large institutions, governments, or corporate boards do when the threat feels abstract and the fix requires upfront spending. The track record here is not encouraging. Critical infrastructure operators spent years being warned that ransomware attacks on hospitals were coming. Then the ransomware attacks came. Then the hospitals paid the ransoms and went back to running the same unpatched systems.
The window these companies are describing is real. Whether anyone with actual power over budgets and policy decisions will treat it as real is an entirely different question.
The Dingo Take
You are supposed to read a letter like this and feel reassured that serious people are taking a serious problem seriously. The trouble is that the serious people taking this problem seriously are the exact same people who sprinted to deploy this technology as fast as commercially possible, argued loudly against any regulatory slowdown, and are now, having arrived at the destination they were racing toward, looking around and saying: hm, this place seems dangerous.
That is not cynicism for its own sake. The warning in this letter is almost certainly accurate. AI-enabled cyberattacks are genuinely getting more sophisticated, genuinely faster, and hospitals and water treatment facilities and financial systems are genuinely under-defended. CrowdStrike's 89% year-over-year figure should be front-page news every day until someone in Washington decides it warrants the same energy as, say, arguing about which transgender athletes can compete in the Olympics.
But the companies signing this letter profit from the race they are now asking everyone to slow down and defend against. They are not wrong that we need to act. They are just maybe not the most credible voices to be leading that particular charge. What we actually need are governments with functioning cybersecurity agencies, adequately funded and staffed, that are not being dismantled in real time. We need that more than we need another open letter. The clock these companies are describing does not care about the politics.


Comments