OpenAI and 100+ Firms Warn AI Cyberattacks Could Surge Within Months

More than 100 organizations warn AI could accelerate cyberattacks faster than defenders can respond, putting critical infrastructure at greater risk.

Aug 31, 2026
3 minute read
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

OpenAI and more than 100 technology, cybersecurity, financial, and infrastructure organizations are calling for a global push to strengthen cyber defenses before increasingly capable AI systems make it easier to launch and scale attacks.

In an open letter, the companies warned that AI-enabled attacks could become more widespread and sophisticated within months, putting hospitals, water treatment facilities and other critical infrastructure at greater risk. The coalition includes OpenAI, Anthropic, Google, Microsoft, Amazon Web Services, IBM, Cloudflare, Palo Alto Networks, Visa and Mastercard, among others. 

The group argues that traditional security practices are already struggling with years of unpatched software, excessive permissions, weak authentication, misconfigurations and outdated systems. Those weaknesses could become more dangerous as AI reduces the time attackers need to discover and exploit them.

The warning comes after several recent incidents in which AI systems behaved unexpectedly during security testing. eSecurity Planet previously reported that OpenAI agents tested in July were able to create private message boards, coordinate with one another and successfully attack Hugging Face.

AI could help both sides

OpenAI’s letter does not frame AI solely as an emerging threat. It argues that the same technology can help defenders identify weaknesses, accelerate fixes and extend sophisticated security capabilities to organizations that cannot afford large security teams.

Robbie Mueller, technical lead for cybersecurity at ArmorCode, said the bigger problem for many companies is their ability to respond to the volume of security findings.

“Finding problems has never been easier. Fixing them is the hard part,” Mueller told eSecurityPlanet. He said companies should focus less on the sheer number of vulnerabilities and more on whether weaknesses can be chained together into a practical attack path.

David Brauchler, technical director and head of AI and ML Security at NCC Group, also cautioned against assuming AI can safely replace human judgment.

“AI tools still do not provide sufficient reliability to operate without human oversight,” Brauchler told eSecurityPlanet.

Advertisement

That creates a challenge as companies need to move faster, but rushing AI-generated fixes directly into production could introduce new security problems.

The real bottleneck is capacity

The coalition’s recommendations point to a broader problem than simply buying better AI security tools. Organizations must first know what systems they have, which weaknesses matter most, and who is responsible for fixing them.

That distinction could become increasingly important as AI expands the number of vulnerabilities defenders can discover. If discovery accelerates while patching remains slow, companies may simply end up with larger backlogs.

Mueller said the average enterprise already operates more than 40 security scanners and produces millions of findings, while organizations can remediate only about 1 in 10 open vulnerabilities per month.

What changes for businesses and consumers

For businesses, the immediate priority is not chasing every vulnerability but identifying weaknesses that are exposed, actively targeted or connected to valuable systems. The letter also calls for stronger security standards for AI-generated code and compensating controls where critical systems cannot be patched safely.

For governments, the coalition wants stronger intelligence sharing, funding for under-resourced critical infrastructure and wider access to defensive AI.

Consumers face a different threat. Brauchler warned that AI-powered scams can make impersonation and phishing more convincing and personalized. 

“For consumers, AI’s risk often falls into the realm of spam and scams,” Brauchler noted. “With deepfake technologies, attackers can impersonate loved ones, generate custom phishing campaigns, and generate highly responsive content customized for a victim without any human-in-the-loop.”

He recommends multifactor authentication or passkeys, independently verifying unexpected requests and checking email domains before clicking links.

Signatures without strings

While the open letter outlines ambitious goals, calling on governments to fund public utility defense and urging developers to share threat intelligence, it stops short of enforcing operational accountability.

The signatories did not attach financial pledges, binding deadlines, or concrete resource allocations to their declaration. Instead, the initiative places the burden of immediate response on cash-strapped municipalities and enterprise engineers who must now triage AI-scale vulnerabilities with human-scale budgets.

Advertisement

Also read: Samsung patched Smart Switch flaws that could expose sensitive user data and put millions of devices at risk.

AA

Aminu Abdullahi is an experienced B2B technology and finance writer. He has written for various publications, including TechRepublic, eWEEK, Enterprise Networking Planet, eSecurity Planet, CIO Insight, Enterprise Storage Forum, IT Business Edge, Webopedia, Software Pundit, Geekflare and more.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.