OpenAI and 100 others warn that the window to defend against AI attacks is narrowing

A wave of AI-driven cyberattacks is coming, and businesses have a narrow window to defend.

That was the message of an open letter published Thursday by OpenAI and more than 100 major tech companies and others. The letter says AI labs should provide their best AI models to organizations such as hospitals and infrastructure providers to help them prepare, and that governments should help coordinate and fund cyber defenses.

The letter is signatories they included Google, Microsoft and OpenAI’s arch-rival, Anthropic, as well as cyber and financial firms such as CrowdStrike, the company known for investigating cyber attacks against the Democratic National Committee in 2015 and 2016, and credit card providers such as Visa and Mastercard.

“The companies and public services that our communities depend on — from hospitals to water treatment plants to the infrastructure that powers the Internet — are at risk,” the letter says. “Cyber-attacks with artificial intelligence will become much more widespread and sophisticated as models around the world become more and more capable.”

The letter signaled that large companies are increasingly concerned about the hacking capabilities of artificial intelligence and whether AI labs can fully control the behavior of their models. In recent public statements, some AI labs have called on governments to regulate them to slow the pace of AI development so that the technology’s capabilities do not exceed their ability to control it.

The letter follows a spate of cyberattacks by AI models, with the models going rogue in some cases. Last month, OpenAI artificial intelligence models got out of the test environment and hacked Hugging Face, an online repository of open AI models. Hugging Face said it faced a flurry of attacks that no human attacker could handle, with OpenAI bots performing more than 17,000 actions, such as sending attack commands and exploiting vulnerabilities.

Since the attack, OpenAI has said it is increasing its security to prevent its models from being breached during testing.

Antropic also recently revealed that one of its AI models had hacked into the systems of three external organizations during a test. Meta said its AI models did something similar.

Some tech executives are increasingly interested in the power of artificial intelligence. Bill Gates, the billionaire co-founder of Microsoft, told The New York Times this month that addressing these risks should be “the world’s highest priority.”

In a letter Thursday, the companies argued that making AI available to defense could help fix “weaknesses that have accumulated over the years.”

“If we act decisively, we can use the defenders’ window to a much more secure digital world,” the letter reads.

(The Times has sued OpenAI and Microsoft, alleging copyright infringement of news content related to AI systems. Both companies have denied the claims.)