I was standing in a crowded briefing room when a table of security slides went black for thirty seconds. You felt that hollow shift — the moment when a system you thought reliable becomes suddenly negotiable. I left that room convinced we were watching a race between tools that can break things and tools that can fix them.
I’ve read the joint letter signed by OpenAI, Google, Anthropic, Microsoft, Amazon, Oracle and more than 100 other firms. They don’t mince words: AI-enabled attacks will spread and sharpen in the coming months, and the window to prepare is narrow. You’re being asked to treat the next few months as if the firewall you trust could be probed by an opponent who speaks fluent automation.
At several U.S. water plants operators reported odd PLC behavior — What went wrong where and why it matters
In July, the FBI and EPA warned that internet-connected programmable logic controllers (PLCs) at water and wastewater facilities had been targeted. A few weeks later the NSA and other agencies flagged attacks against Siemens PLCs, where intrusion scripts appeared to have been written by AI and disguised as benign monitoring tools. The Five Eyes agencies had already warned that frontier models could reshape both offense and defense in months.
Those incidents were not dramatic single-showstopper hacks; they were quiet infiltrations that changed how systems reported their own health. That’s the problem: small, automated exploits can scale with little human effort. AI is a rising tide that lifts attackers’ reach.
How will AI change cyberattacks?
AI will speed and expand the playbook. Expect automated reconnaissance, rapid generation of exploitation scripts, social-engineering content tailored to individuals, and tools that chain multiple vulnerabilities together without human trial-and-error. Attackers will outsource creativity to models such as OpenAI’s GPT family or Google’s Gemini while using cloud platforms like AWS and Azure to run campaigns at scale.
In Silicon Valley boardrooms CEOs signed a short joint letter — The industry’s plan: use frontier models to harden defenses before they slip into hostile hands
The letter calls for a global surge in cyber defense and asks AI developers to give defenders early, trusted access to powerful models, plus training, funding, and hands-on support. It pushes cybersecurity vendors to continuously test against frontier capabilities and to make AI-driven tools available to operators of critical infrastructure.
The prescription is straightforward: patch high-risk vulnerabilities, retire legacy systems that can’t be defended, and use the same advanced models to automate threat hunting and response. They’re proposing more AI because, for now, defenders can get a head start. They are trying to bottle the storm.
Can AI defend against AI attacks?
Yes, but it’s a race. AI can find subtle anomalies, simulate attacker moves, and generate mitigations faster than human analysts alone. However, models make mistakes, inherit biases, and can be manipulated if exposed. The defensive advantage depends on controlled access to high-capability models, rigorous red teaming, and defensive workflows that combine human judgment with model output.
You and I will feel the consequences if hospitals or water plants go offline — What governments and vendors are being asked to do next
The letter asks governments to coordinate across local, national and international lines, increase funding, expand trusted-access programs, and prioritize under-resourced critical-infrastructure defenders. It asks AI companies to provide model access, training, and direct support to those operators. In short: move resources and expertise to the places attackers will seek first.
What should companies do now?
Patch known high-risk vulnerabilities and phase out antiquated control systems. Adopt continuous red-teaming against frontier model behaviors. Request trusted-access programs from model providers and lean on cloud partners for hardened deployments. Train staff on model-driven playbooks and budget for hands-on vendor support for critical sites like hospitals and utilities.
There is a narrow opportunity to use frontier models defensively before they are widely repurposed by adversaries — and that is the core argument of the letter. You should watch which vendors sign up to provide trusted access, which governments expand funding, and how quickly carriers and cloud providers integrate AI-driven defenses into their offerings.
I’ll keep tracking announcements from OpenAI, Google, Anthropic, Microsoft, Amazon and Oracle as well as alerts from the FBI, NSA and the Five Eyes. Which side will win the next phase of cyber conflict: the teams that build defenses with AI or the groups that weaponize the same tools?