AI Companies Warn Cyberattacks Could Overwhelm Defences Within Months
OpenAI, Anthropic and more than 100 companies have signed a joint letter saying organisations have very little time to prepare for a wave of AI-assisted hacking. Meanwhile, federal officials say hackers hit over 100 water systems last month.

Key points
- OpenAI, Anthropic and more than 100 companies co-signed a letter in 2025 warning that AI-enabled cyberattacks are likely within months.
- The U.S. Cybersecurity and Infrastructure Security Agency reported malicious hacking activity targeting more than 100 water and wastewater systems in July 2025.
- Federal officials say hackers are using AI to help write scripts that attack industrial control devices connected to the internet.
- The letter calls on governments to give hospitals, water utilities and local governments access to defensive AI tools.
- The letter contains no specific funding commitments, deadlines or named investments.
More than 100 technology companies, including OpenAI and Anthropic, have signed an open letter warning that AI-powered cyberattacks are not a distant threat. They could arrive within months.
The letter calls for a "collective response" and asks every organisation to make cyber defence an "immediate leadership priority." It specifically urges governments to give hospitals, water systems and local government bodies access to capable defensive AI, and to "impose costs" on attackers.
One catch: as Axios noted, the letter contains no specific spending commitments, deadlines or named investments. It is a call to arms without a named general.
Why should ordinary people care?
Because the targets are not banks or tech firms. They are the places people depend on every day.
The same week the letter landed, the U.S. Cybersecurity and Infrastructure Security Agency, the federal body that monitors threats to critical national systems, reported that hackers had targeted more than 100 water and wastewater systems across the country in July alone.
The attacks focused on programmable logic controllers, small computers that monitor and manage physical equipment such as pumps and valves. Many water utilities connected these devices to the internet years ago so staff could check readings from home. That convenience is now a vulnerability.
Federal officials say attackers are using AI to help write the attack scripts, lowering the skill required to cause real damage. Wired reported earlier this year that a leaked industry memo linked this surge to Iran-linked actors.
What does the AI warning letter actually mean?
Taken at face value, the letter is an acknowledgement from the companies building the most powerful AI systems that those same systems will be weaponised against ordinary infrastructure faster than most governments are ready for.
The ask is clear enough: fund defensive AI, protect vulnerable sectors, make leaders treat this as urgent. Whether that produces action depends entirely on the governments being addressed.
For now, the letter is a statement of concern, not a plan.
What should people watch for?
If you work at a hospital, school, utility or local government office, the risk picture has changed. AI tools make it cheaper and faster for attackers to craft convincing phishing emails (fake messages designed to steal passwords), to probe for weaknesses, and to automate attacks that once needed skilled human effort.
Knowing how to spot a phishing attempt matters more now than it did two years ago. Check that your organisation runs regular security-awareness training. If it does not, push for it.
And if your tap runs dry or a local service goes dark without explanation, a cyberattack on industrial control systems is no longer a fringe possibility.



