OpenAI has issued a statement calling on governments, tech firms and cybersecurity companies to immediately begin engaging in a “collective response” to the new attack capabilities demonstrated by AI in recent months. Among other items, the company stresses that every organization must now make cyber defense an immediate leadership priority and that governments must step up funding and support for entities that are already lagging behind and under-resourced.
The ChatGPT developer itself is perhaps most directly responsible for this sea change in the cyber defense landscape, with its July security incident involving platform Hugging Face leading to broad industry revelations that more and more frontier AI models are prone to “going rogue” when not very carefully guardrailed and monitored. The company does not spare itself from scrutiny in this call to arms, however, also stressing that frontier AI developers must play a part in supporting critical infrastructure defenders with resources and training and improve transparency and information sharing.
OpenAI: Governments and frontier AI developers must improve funding and public-private cooperation
The OpenAI memo opens with a dire warning: the cutting edge AI developer predicts that within the “coming months” the frequency and sophistication of AI-driven attacks will increase greatly as model capability makes new jumps forward. However, this prediction is tempered with a note that AI-based defenses also have the ability to address many of the weaknesses that AI attackers will target before they get there.
There remains a lot of work to be done and OpenAI expresses concern that maintaining the cyber defense “status quo” is a recipe for disaster. This means addressing long-entrenched bugs and vulnerabilities, updating and hardening legacy systems, ensuring that authentication systems are up to the realities of the modern threat landscape, and ensuring that necessary patching is getting done in a timely fashion.
Organizations were already struggling with all of these elements long prior to AI attacks, due largely to a combination of budget and manpower issues. AI defenses can potentially pick up a good deal of that manpower slack, but OpenAI warns that governments and AI developers themselves need to do more to address cost shortfalls and long-neglected systems (particularly in the critical infrastructure sectors).
What can organizations do right now, under their own power? OpenAI advises making a cyber defense a top and immediate leadership priority. Security can no longer be an afterthought in the era of relentless “machine speed” automated attacks sniffing for weaknesses 24/7. The memo advises putting resources into immediately identifying and addressing the highest-risk issues in the near term, and also more carefully reviewing the software and apps that are both purchased from third parties and built in-house to ensure that they are not creating even more “technical debt” when they are onboarded.
The memo also calls for a broader public-private partnership on cyber defense in the interest of national security, with both governments and technology partners stepping in to both close security gaps and make AI defense tools more accessible to critical infrastructure companies in the near term. Both public and private participants are also encouraged to share the tested and proven cyber defense “playbooks” they develop and collaborate on interim guidance.
Governments are also called upon to improve funding for cyber defense, particularly to essential services that have long-established struggles with IT staffing and budget. OpenAI also says that frontier developers such as itself should broaden responsible access to models, spend more on training and provision of tools to these critical infrastructure entities that are badly in need, and invest in authorized testing and private disclosure.
John Strand, Owner of Black Hills Information Security, believes that the most important piece of this is AI developers actually putting their money where their mouth is in terms of providing assistance in cyber defense hardening against their own creations: “The one recommendation that actually has some teeth to it is the call for greater open exchange of detects and IOCs. But I would have liked to see these companies go much further. Many of them make billions of dollars from the security community. Why not create open initiatives where organizations can access threat intelligence feeds for free? Why not provide some of these security services at no cost to municipalities and other organizations that simply cannot afford them?”
“Some companies already do this, and they deserve credit for it,” Strand adds. “But if the industry is going to collectively call for organizations to improve their security, it also needs to recognize the reality on the ground. A huge number of these organizations are understaffed, underfunded, and under attack. Many of the companies signing these initiatives have the resources and expertise to directly help them.”
Donald McFarlane, Advisory Board Member at Xcape, agrees: “There is a little bit of “industry identifies an emergency; government buys industry’s solution” in this proposal. If the companies signing this letter believe that AI creates an urgent new systemic risk, I would expect them to put substantial skin in the game rather than simply asking taxpayers to fund another generation of security products: including through private partnerships for collective defense. Before we spend public money putting AI on top of insecure infrastructure, I want to know that we have paid for the basics: remove PLCs from the public internet, secure remote access, segment networks, maintain backups, and make sure somebody actually owns the security of the system.”
Dozens of tech’s biggest names sign pledge to participate
The memo ends with a call for co-signers, and many of big tech’s biggest names are already present on the list. These include fellow frontier AI developers such as Google and Anthropic, leading cybersecurity firms and technology providers, and an assortment of big names in critical infrastructure spaces such as energy and finance.
As with OpenAI, some of these names have already been directly involved with the cyber incidents that prompted this call. While July’s Hugging Face attack and the subsequent cascade of other AI developers self-reporting similar (but less damaging) issues has grabbed headlines and sparked real concerns, thus far these scenarios have yet to be anything that could not have been contained by better safety guardrails and monitoring by the AI developers themselves and their third-party testing partners.
That does not mean the threat should be disregarded, however, or that cyber defense responsibility remains entirely in the hands of developers. Many of the AI agents that participated quite capably in the Hugging Face attack and other “rogue” incidents are now available to the general public, and these incidents have demonstrated that these agents can be directed to work together and cooperate to multiply their impact.
As Jake Williams, Faculty at IANS Research, observes: “AI is absolutely changing cyber security. But this seemingly unending reiteration of warnings about impending doom isn’t helping. Those that get it already understand that these messages are a combination of real world threat and hype. Those who don’t get it won’t be convinced by yet another scare blog. We also should recognize the very real conflict of interest at play here. The major AI Labs that co-wrote this paper have had major containment failures of their own agents in recent months. I can’t help but see this as a bit of shifting the narrative from “we screwed up” to “there’s nothing that can be done, AI powered compromises are inevitable.” I personally don’t believe the latter statement to be true, but it is what the AI Labs selfishly want you to take away from this latest warning.”

