anthropic

OpenAI, Anthropic issue dire cyber threat warning

Claude News

anthropic

More than 100 organizations, among them OpenAI, Anthropic, Amazon Web Services and Microsoft, warned Thursday that they and other defenders have only months to prepare for AI-enabled cyberattacks on critical infrastructure. Their open letter, reported by Axios, calls for collective action and sets out steps for companies, governments and frontier AI developers.

At a glance

  • The warning follows a run of intrusions into critical infrastructure, including an attack on U.S. water systems that used what appeared to be an AI-generated exploitation script.
  • Its recommendations are split across four groups: individual organizations, cybersecurity and technology vendors, governments, and the frontier AI developers that build the models now reshaping offensive capability.
  • The signatories attached no commitments, deadlines or specific investments to the text, and the document names no amount for the cyber defense funding it asks governments to provide.

Coming from the same vendors that sell both the models and much of the infrastructure they would defend, the letter reads less as a technical disclosure than as an attempt to set the agenda for what defenders should be doing next. The absence of dollar figures or dates is the tell: the signatories agree on the shape of the threat, and appear to be some distance from agreeing on who pays for the response.

The letter assigns separate tasks to organizations, vendors, governments and frontier AI companies

Each organization is told to raise internal security standards, close its highest-risk weaknesses, and apply a higher security bar to what it buys, builds and deploys, including AI-generated code. Cybersecurity and technology companies are asked to test and build out tools that make AI-powered defense accessible and deployable for critical infrastructure operators.

Those companies are also asked to share threat intelligence with one another. Governments are asked to strengthen the channels through which actionable threat intelligence moves, to coordinate defense at the local, national and international levels, and to fund cyber defense.

Frontier AI companies are asked to give defenders access to their most capable response models during major cyber incidents. That access should come with significant funding, training and hands-on support, with critical infrastructure providers named in the text as the priority.

An attack on U.S. water systems used an apparent AI-generated exploitation script

The group writes that hospitals, water treatment plants and other critical infrastructure will face a swarm of hacking threats as AI makes sophisticated cyber capabilities cheaper and more accessible to attackers. The warning lands amid a wave of attacks on critical infrastructure.

One of those attacks targeted U.S. water systems with an apparent AI-generated exploitation script. Water systems and power plants have long carried vulnerabilities in the tools that run their machinery, but exploiting them used to require attackers to invest a large amount of time in understanding each system. Experts previously told Axios that AI models are now drastically lowering how much time and energy that preparation takes.

More than 100 signatories attached no deadlines or investments to the letter

The signatories made no commitments, set no deadlines and named no specific investments alongside the text. Organizations are told to use the shrinking window to secure critical infrastructure and to make break-ins more expensive and more difficult for hackers using AI tools. The letter states the constraint in one line.

We have a limited window to strengthen cyber defenses.

The names on the letter span cloud providers, cybersecurity companies, AI developers, telecoms, financial services firms and think tanks, with OpenAI, Anthropic, Amazon Web Services and Microsoft among them. More than 100 organizations in total signed the open letter, which was published Thursday.

No date on the window

The letter does not say when its months run out, and it fixes no date by which organizations should have closed their highest-risk weaknesses. It also gives no schedule for the tooling it asks cybersecurity vendors to build, and no threshold defining the major cyber incidents during which frontier labs would open their strongest response models to defenders.

Comments

No comments yet. Be the first.

Join the conversation

Sign in with Google to leave a comment. Your name and avatar come from your Google profile, and the comment appears after moderation.

We only use your name and avatar from Google. We never store your email address.