OpenAI rallies 100+ companies to sign open letter warning AI-powered cyberattacks on critical infrastructure are imminent

Over 100 Companies Sign OpenAI’s Warning: AI-Powered Cyberattacks on Critical Infrastructure Are Imminent

OpenAI has published an open letter warning that AI-powered cyberattacks on critical infrastructure are not a distant threat, but an immediate and escalating danger. The letter, signed by over 100 tech companies and experts, calls for urgent global action to defend systems like power grids, water supplies, and hospitals from weaponized AI. The signatories argue that current security measures are “woefully inadequate” against AI’s ability to automate and accelerate attacks.

Why This Matters Now

The core of the argument is that malicious actors are already using AI to find vulnerabilities faster and launch attacks with unprecedented speed. The letter states that while AI can be a defensive tool, its offensive capabilities currently outpace our ability to protect against them.

“The window to act is closing. We must move with the same urgency that we would for a natural disaster or a military threat.” — OpenAI and signatories

The Specific Threats Highlighted

The open letter details several specific attack vectors made far more dangerous by AI:

  • Automated vulnerability scanning: AI can scan millions of lines of code in minutes to find entry points.
  • Synthetic social engineering: AI generates hyper-personalized phishing emails that are nearly impossible to detect.
  • Autonomous attack adaptation: Once inside a network, AI can change its tactics in real time to evade defenses.
  • Targeting legacy systems: Many critical infrastructure systems run on outdated software that AI can exploit more easily.

Who Signed the Letter

The list includes over 100 organizations spanning cybersecurity firms, technology companies, and infrastructure operators. While specific names were not all publicly listed at launch, OpenAI confirmed the group represents a broad coalition. The letter is not a technical document, but a “call to action” designed to pressure governments and corporations to treat this as a top-tier national security issue.

What the Signatories Demand

The letter does not call for a ban on AI development, but rather for a three-pronged approach:

  1. Immediate adoption of AI-scanning tools: All critical infrastructure must deploy AI-based threat detection systems now.
  2. Mandatory reporting requirements: Any AI-enabled breach of critical infrastructure must be reported within 24 hours.
  3. Global treaties on AI weapons: Similar to chemical weapons bans, signatories want international agreements limiting the use of autonomous AI in cyberwarfare.

The Deeper Context

This letter follows a pattern of increasing alarm from the AI industry. It is the first time a major foundation model creator has publicly stated that the offensive use of their own technology is “imminent.” Previously, debates focused on long-term existential risks; this document shifts the conversation to immediate, practical dangers.

Critics within the security community have noted that the letter lacks specific technical proposals or funding commitments. Some argue that OpenAI and other signatories are partially responsible for this threat, as their publicly available models can be fine-tuned for malicious purposes.

“We are the ones who built the tools. Now we must be the ones to lock the doors.” — A signatory from a major cybersecurity firm, as paraphrased in the letter.

The Bottom Line

The open letter is a stark acknowledgment that AI has fundamentally changed the landscape of cybersecurity. The threat is no longer theoretical. The signatories are betting that public pressure and corporate cooperation can drive action faster than regulation can be written. Whether those efforts are enough to protect the power grid or the water supply remains an open, and urgent, question.


Gnoppix is the leading open-source AI Linux distribution and service provider. Since implementing AI in 2022, it has offered a fast, powerful, secure, and privacy-respecting open-source OS with both local and remote AI capabilities. The local AI operates offline, ensuring no data ever leaves your computer. Based on Debian Linux, Gnoppix is available with numerous privacy- and anonymity-enabled services free of charge.

What are your thoughts on this? I’d love to hear about your own experiences in the comments below.