
For many years, warnings in the distant future have included experts speaking of automated hacking, intelligent malware, rapidly generated phishing campaigns, and attacks that could adapt faster than human defenders.
Many organisations listened politely, put the matter on their risk register and then went on to deal with more pressing issues.
It is becoming harder to justify that attitude.
OpenAI, Google, Anthropic, Microsoft, Amazon Web Services, cybersecurity companies, financial institutions, and several other technology organisations have issued a public appeal for immediate action on AI-powered cyber threats. Over a hundred companies have stated that governments and businesses have only a limited time frame to improve their defenses before AI-enabled attacks become much more difficult to handle.
This warning should be taken seriously, not passively. It does not mean that disaster is certain. This means the conventional approach to cybersecurity is no longer sufficient.
Attackers are becoming faster, broader in scope, and more adaptable as a result of AI, so defenders need to use the same technology to enhance their ability to detect, respond to, maintain resilience, and recover from attacks. Once organisations wait until AI-powered attacks have become the norm, they might find that the most critical systems they have were never built to withstand such attacks.
The Security Gap Is Growing
The main issue isn’t merely that artificial intelligence can make attacks more powerful; the real problem is that defenders are already dealing with fundamental security flaws.
Many organisations continue to use old software, operate systems that are no longer supported, have weak controls over identity, offer internet services that are exposed, have cloud environments that are not well protected, and involve complicated networks of suppliers. Security teams are usually short-staffed and overwhelmed by the volume of alerts.
AI can amplify these weaknesses.
An attacker doesn’t have to develop a wholly new method, since it might be sufficient to use AI to speed up the process of identifying vulnerable systems, produce believable messages, translate communications, automate reconnaissance, or carry out quicker modifications to malicious code.
It can reduce the time interval between the discovery and the exploitation.
A person carrying out an attack could take hours to research an organisation, identify its employees, write tailored messages, and try out various methods. AI can help with a great deal of this preparatory work by analysing publicly available information, producing highly personalised communications, and modifying its approach if the target does not reply.
The outcome is that more attacks are carried out at a lower cost.
What worries me most is this. Although cybersecurity has always been a struggle between attackers and defenders, AI might make it easier for less-skilled people to carry out attacks that previously required a great deal of expertise.
What AI Changes for Attackers
AI can assist attackers through various stages of a cyber campaign.
It can be used to obtain information about a particular organisation, identify employees likely to be involved, map the systems accessible to the public, and analyse technical documents. It is also capable of producing believable phishing emails, messages, false support requests, or fake social media interactions.
It can also be useful to attackers for writing or altering scripts, explaining unfamiliar software, translating instructions, and troubleshooting failed attempts.
No single one of these capabilities will ensure a successful intrusion; skilled defenders can still stop such attacks. Strong authentication, network segmentation, endpoint protection, secure software development, monitoring, and well-trained employees remain effective.
The worry is that AI will decrease friction.
Someone with only limited technical experience might be able to carry out more attacks, learn from their failures, and adapt rapidly. Criminal organisations could use AI to split their campaigns into tasks and automate routine work. Actors who are more capable might combine AI with existing tools for espionage, extortion, disruption, or sabotage.
This may result in a volume problem, as security teams may encounter more activity than they can investigate manually.
An organisation can be secure against a well-planned attack but will struggle when it receives thousands of automated attacks each day.
The Most Vulnerable Sectors
The organisations involved in the public appeal have highlighted sectors including hospitals, water utilities, local governments, and power infrastructure. Although these organisations offer essential services, they usually do not have the resources that are available to big technology companies.
Hospitals are especially vulnerable because they operate without interruption, handle sensitive personal data, use specialised medical equipment, and cannot readily shut down in the event of an incident.
Water utilities can rely on industrial control systems, remote monitoring, and outdated technology. Local governments usually provide public services with small budgets and a limited number of security staff. Power companies operate complex networks because a disruption to them can affect entire communities.
The issue extends beyond data theft.
An AI-assisted attack might be directed at the availability or integrity of a service, for example, by disrupting a hospital’s scheduling systems, altering a public website, interfering with a utility’s monitoring system, or flooding a government authentication service.
The organisation in question might at first realise if it is being targeted by ransomware, espionage, sabotage, fraud, or a mix of these objectives.
The greater the uncertainty, the more pressure it places on those who have to make decisions.
Why Critical Infrastructure Needs Special Help
Large technology companies are often able to employ specialist security teams, use advanced monitoring tools, subscribe to threat intelligence services, and enter into dedicated incident response contracts.
A little water authority or a rural hospital might not have those resources.
The results of an attack on those organisations can be serious though. Their significance is not based on the size of their technology budgets; it is based on the services they provide.
Which is why it is important to call on the public for support. The signatories have asked governments to coordinate and provide funding for cyber-defence programmes, to enlarge the sharing of threat intelligence, and to assist less-resourced operators in obtaining defensive AI tools.
I agree with the principle underlying that request, namely that critical infrastructure should not rely solely on market forces to defend itself.
Governments currently promote public safety through emergency services, health systems, disaster planning, and the protection of infrastructure; cybersecurity should be given equal treatment.
It doesn’t imply that the government has to manage all defensive systems, merely that public institutions should help establish the conditions that will allow smaller organisations to obtain expertise, tools, training, and emergency support.
The Defensive Opportunity
AI is not merely a threat; it could also be one of the most valuable tools defenders have.
Security teams can use artificial intelligence to spot unusual network behaviour, analyse large volumes of log data, summarise alerts, compare threat indicators, detect suspicious identity-related activity, and assist with incident investigations.
It can help analysts prioritise events that need immediate attention and assist with vulnerability management, configuration reviews, secure code analysis, and employee training.
During an incident, AI may help answer questions such as:
- Which systems are affected?
- At what time did the suspicious activity start?
- Which accounts were used?
- Has the attacker carried out lateral movement?
- Which indicators should be blocked?
- Which backups remain safe?
- Which services should be restored first?
- What kind of evidence should be kept?
The value is speed.
Human analysts can take hours to gather information from various systems, while AI can put those details together more quickly, enabling experts to concentrate on their judgment and decision-making.
Organisations should not regard defensive AI as magic, since a model might misinterpret certain activity, fail to notice crucial evidence, or give an answer that seems confident but is in fact incorrect.
AI should assist trained professionals rather than take away accountability.
The Importance of Early Access
The open letter from the companies has also requested the establishment of trusted programmes that allow defenders to access advanced AI models, including in the event of serious cyber incidents.
There is a significant imbalance here, since attackers may already be experimenting with powerful models, while smaller defenders might not have access to similar tools or the necessary expertise to use them safely.
Early access would enable security teams to test defensive applications before the tools become widely available, and it would also allow researchers to identify weaknesses, assess safeguards, and develop incident-response methods.
Access must be controlled.
Organisations should have clear rules stating who is allowed to use advanced models, what data may be submitted, how activity is to be logged, and how sensitive information is to be protected. It should not be necessary for a hospital to make confidential patient data available to an external system to obtain cyber assistance.
Trusted access should include:
- Strong authentication.
- Data-protection safeguards.
- Defined use cases.
- Human oversight.
- Audit logging.
- Emergency activation procedures.
- Clear legal responsibilities.
- Independent evaluation.
The aim is to provide defenders with useful capabilities without creating another uncontrolled source of risk.
AI-Generated Code and Software Security
A major area of concern is software.
AI tools are now being used increasingly to produce, modify, test, and explain code; while this can boost productivity, it also raises new security issues.
Code produced by AI can have vulnerabilities, insecure dependencies, weak authentication, inadequate input validation, or make unsafe assumptions. Developers might accept the suggested changes without fully understanding the consequences. Organisations may find that they deploy code more quickly than their testing and review procedures can keep up with.
Attackers can also employ artificial intelligence to spot vulnerabilities in software or to produce different versions of malicious code.
It therefore means that software security should become more, not less, disciplined.
Organisations should require:
- Secure development practices.
- Code review.
- Automated testing.
- Dependency scanning.
- Secrets management.
- Vulnerability disclosure.
- Software bills of materials.
- The distinction between development and production.
- The level of human approval for significant changes.
- Monitoring after deployment.
While AI can assist in writing code, it cannot be held responsible for the consequences of that code.
The Human Factor Remains Central
The idea that AI-powered attacks could only be counteracted by even better AI is a mistake.
Many successful incidents still begin with familiar weaknesses: reused passwords, unpatched systems, excessive privileges, poor backups, unverified suppliers, or employees. While technology can help to reduce risk, it is the organisation’s culture that determines how quickly problems are identified and contained.
Employees need clear, practical guidance. They should know how to recognise suspicious messages, handle AI-generated content, determine which information must not be entered into public tools, and report concerns.
Managers need to understand that cybersecurity is not only the responsibility of the IT department. They must support training, fund improvements, and avoid creating incentives that encourage employees. Senior managers should as well engage in making decisions when incidents occur. In the event of a cyber crisis, decisions may need to be made regarding service disruption, public communication, legal reporting, customer notification, and business continuity.
Those decisions are easier when leadership has already discussed them.
Why Information Sharing Matters
An attacker can use the same infrastructure, techniques, malicious code, or social engineering methods when targeting multiple organisations. Should the first victim quickly provide some useful information, other organisations will then be able to stop the campaign.
Information sharing must be both timely and practical; rather than issuing general warnings, organisations should receive actionable details.
Useful information may include:
- Indicators of compromise.
- Malicious domains.
- Suspicious file characteristics.
- Attack patterns.
- Exploited vulnerabilities.
- Defensive controls.
- Recommended detection queries.
- It is necessary to have legal protection and to enjoy trust, since companies might be reluctant to share information if they fear being sued, facing regulatory fines, or suffering reputational harm.
Governments and industry groups should create safe channels that encourage early reporting and protect sensitive information.
A National and International Responsibility
An attack can be launched from one country, directed at another, use facilities in a third country, and impact companies whose supply chains span the globe.
That makes international cooperation essential.
Governments should coordinate on threat intelligence, law enforcement, technical standards, emergency response, and responsible AI development. Technology companies should share information about misuse while protecting legitimate users. Researchers should be able to study vulnerabilities without creating unnecessary operational risk.
The private sector also has responsibilities. Companies that develop powerful AI systems should invest in safeguards, testing, monitoring, abuse detection, and defensive partnerships.
They should not treat security as a public-relations issue that appears only after an incident.
The Risk of Overstatement
Although I believe the warning deserves urgent attention, it should be communicated responsibly.
Predictions about AI-powered cyberattacks can generate fear if presented as certainties. Organisations may react by purchasing tools without improving basic security. Citizens may become confused about urgency; it should be aimed for, but not overstated.
The goal should be urgency without exaggeration.
We already know enough to act. Organisations do not need to wait for a fully autonomous cyberattack to improve identity protection, patch systems, segment networks, and strengthen security. The most effective form of preparation could simply be the continual use of normal security measures.
AI will make some attacks faster and more adaptive, but it will not eliminate the value of strong fundamentals.
A Practical Agenda for Organisations
The most important aspect is identity; it is possible to prevent many attacks through strong authentication, effective management of privileged access, and the quick deletion of unnecessary accounts.
The second is exposure. Organisations should identify internet-facing systems, unsupported software, remote-access tools, and vulnerable suppliers.
The third is resilience. Backups must be protected from attackers and tested regularly. Critical services should have recovery priorities and alternative operating procedures.
The fourth is monitoring. Organisations need enough visibility to identify suspicious activity before it becomes a major incident.
The fifth is AI governance. Employees should know which AI tools are approved, what information may be entered, how outputs must be verified, and when human approval is required.
The sixth is incident preparation. Organisations should practise responding to realistic scenarios involving phishing, ransomware, cloud compromise, supply-chain intrusion, and disruption of essential services.
These steps may not sound revolutionary, but they create the foundation on which more advanced defensive AI can operate.
The Real Meaning of Urgency
When more than 100 technology and business organisations call for immediate action, their message should not be interpreted solely as a request to purchase more products. AI companies are creating tools which can boost productivity, speed up research, and enhance digital services; the same technological advances can also make cyber threats more scalable and accessible.
Governments should coordinate, regulate effectively, fund protection for the most vulnerable sectors, and promote international cooperation. Technology companies should create safer systems and offer defensive help. Large organisations should improve their own security and assist in protecting their suppliers and partners. Small operators, on the other hand, need access to practical resources, not just expectations.
The Window Is Narrow, but Action Is Possible
The warning from OpenAI, Google, and more than 100 other organisations should be treated as a call to prepare rather than a prediction of an unavoidable disaster. The companies have urged businesses and governments to fix existing weaknesses, expand intelligence sharing, improve defensive tools, and provide greater support to critical infrastructure operators.
It is no longer possible for organisations to expect to have weeks to investigate a suspicious event or months to prepare for a new type of attack. Because of automated tools, attackers can act more quickly, target more organisations, and adjust as defenders respond.
AI can assist analysts with data processing, anomaly detection, incident investigation, software protection, and aiding in recovery. It allows smaller organisations to gain access to capabilities which have hitherto been available only to large security teams.
The technology will not solve the problem by itself. Strong leadership, secure architecture, trained personnel, responsible governance, and cooperation will remain essential.
The best time to prepare is before advanced AI-powered attacks become ordinary. That means fixing known vulnerabilities now and protecting organisations that cannot defend themselves alone.
The future won’t be guaranteed by waiting for certainty; instead, it will be secured by taking action while there is still time to make improvements.




