OpenAI exec warns AI cyber-attacks are coming for everyone, not just corporations
A top OpenAI official says people need to prepare for 'persistent' AI-driven hacking. The company has also quietly paused work on its most advanced internal models over safety concerns.

Key points
- OpenAI's chief global affairs officer, Chris Lehane, warned in an interview that AI-powered cyber-attacks will be "ongoing" and "persistent", affecting ordinary people and businesses alike.
- OpenAI this week paused development of its most advanced internal AI models, citing rising safety fears.
- Lehane described the current moment as "a different chapter" in AI capability, signalling that the technology can now plan and carry out offensive operations.
- Critics say AI companies are moving "recklessly" and that new safety standards are urgently needed.
Chris Lehane, the chief global affairs officer at OpenAI, has a blunt message: start thinking about your digital defences now. Speaking to The Guardian, Lehane said AI systems are gaining the ability to plan and launch cyber-attacks, and the threat will be constant, not occasional.
"We are hitting a different chapter, a different moment within AI, in terms of what the capabilities of this technology can do," Lehane said.
What exactly is changing?
Until recently, running a sophisticated cyber-attack required skilled human hackers. Now, large language models, the technology that powers chatbots like ChatGPT and Claude, are becoming capable of handling parts of that work automatically. That shifts the economics: attacks that once needed expensive expertise can increasingly be automated and scaled up.
Lehane did not give a detailed technical breakdown, but the direction is clear. AI can now help write malicious code, scout for weaknesses in systems, and craft convincing fake messages designed to trick you into handing over passwords or money. None of that is science fiction; security researchers have been documenting these capabilities for months.
Should ordinary people be worried?
Yes, but not in a paralyse-yourself way. The people most likely to get caught are those who assume they are too small or too unimportant to be a target. AI-assisted attacks are cheap to run at scale, which means scammers no longer need to hand-pick victims.
Phishing emails, fake support calls, and deepfakes (convincing fake audio or video generated by AI that can impersonate a voice or face you trust) are all becoming harder to spot. The old advice still holds: slow down when someone asks for money or login details, verify through a separate channel, and keep software updated.
What is OpenAI doing about it?
The company paused development of its most powerful internal models this week, a notable step given how much competitive pressure the industry is under. Lehane said new safety standards are needed as capabilities grow.
Critics push back hard. Several AI safety researchers and policy advocates argue that firms including OpenAI are still moving faster than their own safety processes can handle, and that words about caution matter far less than the pace of actual releases.
That criticism is worth sitting with. OpenAI has commercial incentives to ship products quickly. A pause on internal research models is meaningful, but it is not the same as slowing deployment of products already in people's hands.
What you can do today
One honest, doable step: turn on multi-factor authentication, the extra login step that sends a code to your phone or an app, on your email and bank accounts. It is the single most effective defence against the kind of credential theft AI-powered attacks are designed to enable. Do it this week, not eventually.



