Are AI Companies Warning Us About the Fire While Selling the Extinguisher?
Bryan D. Lawrence
The Gist
- More than 100 organizations – not 100 AI companies – signed an open letter warning that AI-enabled cyberattacks could threaten hospitals, water systems, and internet infrastructure.
- Several signatories are also developing defensive AI products, including OpenAI’s Daybreak, Anthropic’s Mythos, and Microsoft’s Project Perception.
- The letter contains sensible security advice, but it also makes frontier AI companies look indispensable to solving a crisis their industry is helping intensify.
- Government collaboration could produce useful public investment – or help taxpayers finance a new layer of private vendor dependency.
More than 100 organizations have warned that AI-enabled cyberattacks could soon threaten critical infrastructure. I have a bad habit when a system throws a security warning: I assume the worst, then discover I was the person who left the test rule enabled.
That is the feeling I had reading this letter. The warning is serious. The underlying risks are real. But the companies delivering the message are also building increasingly capable AI systems and selling the tools they say we will need to defend ourselves.
Sometimes the upgrade is necessary. Sometimes it is the same fire extinguisher with a new logo.
Why are AI companies warning about cyberattacks now?
The letter, published August 27, was signed by more than 100 organizations across artificial intelligence, cybersecurity, finance, cloud infrastructure, telecommunications, and technology. OpenAI, Anthropic, Google, Microsoft, CrowdStrike, Okta, Fortinet, and major financial institutions were among the participants. [TechCrunch’s report describes the signatories and the letter’s main demands.][1]
That distinction matters. The original shorthand—“100 AI companies”—makes the story sound like a unified AI-industry confession. It was broader than that. The signatories represent many of the companies that build, secure, operate, and depend on modern digital infrastructure.
Their warning is straightforward: as AI models become more capable, attackers may be able to automate more reconnaissance, vulnerability discovery, code generation, and intrusion work. The letter says the coming months could bring attacks that are more widespread and sophisticated, putting hospitals, water treatment plants, and internet infrastructure at risk.[2]
The problem is not that every AI system will suddenly become an independent supervillain. The more ordinary problem is that attacks may become cheaper, faster, and easier to scale. That is plenty dangerous when the target is running old software, weak authentication, excessive permissions, inherited configurations, and at least one machine nobody wants to reboot because nobody remembers what it does.
What does the letter actually ask organizations to do?
The letter’s practical recommendations are not especially exotic. It calls for stronger access controls, least privilege, defense in depth, patching, continuous testing, verified fixes, and compensating controls when essential systems cannot be taken offline.
In other words, much of the first response to AI-enabled attacks is still the same response required for ordinary attacks: know what you own, reduce unnecessary access, fix the dangerous weaknesses, monitor what happens, and test whether the repair actually worked.
That part is difficult to dispute.
The letter also says organizations should use lower-cost models for broad coverage and reserve more advanced systems for harder security problems. It urges cybersecurity companies to share threat intelligence and tested playbooks. Governments are asked to fund under-resourced essential services and expand access to defensive capabilities.
Those are reasonable proposals. They also reveal the letter’s central tension. It is both a security appeal and an argument for a much larger role for AI vendors in the security ecosystem.
Why are the companies warning us also selling defense products?
Because the contradiction is also a business opportunity.
OpenAI describes Daybreak as a defensive cybersecurity initiative for finding, validating, and fixing vulnerabilities. It promotes governed workflows, partner integrations, security testing, and access to more capable cyber models.[3] Anthropic’s Mythos program and Microsoft’s Project Perception occupy similar territory, although their approaches and product structures differ.
Microsoft describes Project Perception as a workforce of specialized AI agents that can expose gaps, investigate threats, and remediate them continuously. The company’s own description divides the work among red, blue, and green agents—offensive testing, investigation, and hardening.[4]
That could be genuinely useful. Security teams are already overloaded. A system that can inspect a large codebase, prioritize vulnerabilities, propose a patch, and help verify the result may save organizations time they do not have.
But “useful” and “self-interested” are not opposites.
The same companies warning that AI will reshape cybersecurity are also trying to establish themselves as the companies best positioned to respond. The message is not simply “this threat is coming.” It is also “this threat is coming, and fortunately, we already have the platform.”
Is this really self-regulation?
Not in the narrow sense. The letter does not ask governments to stay out of the way. It asks governments to coordinate cyber defense, fund essential services, expand trusted access programs, and provide hospitals, water utilities, and local governments with defensive AI and hands-on support.[2]
That is not “trust us and leave us alone.”
It is closer to: “This problem is too large for us to solve alone, but make sure we are deeply involved in solving it.”
That distinction matters. The companies are asking governments to help create the conditions under which their technology becomes part of the security infrastructure of entire countries. They want public agencies involved, but they also want frontier AI companies treated as essential technical partners.
There is a practical reason for that. Many local governments and utilities do not have enough staff to manage basic security, much less defend against automated attacks. A small water authority is not going to develop its own frontier cyber model.
But once private AI vendors become part of the operational machinery of hospitals, utilities, and public agencies, they stop being ordinary software suppliers. They become infrastructure dependencies.
That creates procurement pressure. It creates lock-in. It creates a powerful argument for public money.
And it raises a question nobody should treat as impolite: Who gets to define the emergency?
What does “government collaboration” usually mean in practice?
It can mean shared threat intelligence, emergency funding, common standards, coordinated incident response, and technical assistance for organizations that cannot afford a serious security team.
It can also mean that the public absorbs much of the cost while private companies retain control of the platforms, models, data, and intellectual property.
The open letter asks frontier AI companies to provide funding, training, observability tools, traceable agent identities, threat assessments, authorized testing, and hands-on support. Those are reasonable expectations. They are also expensive expectations—especially when the companies building the systems may benefit commercially from making those systems central to public defense.
Who pays for the deployment? Who audits the models? Who handles the incident when the defensive agent makes a bad decision? Who can replace the vendor if the price changes, access is restricted, or the company is acquired?
I don’t know the answer. I do know that “human in the loop” is not a complete safety plan. Someone still has to identify the human, give that person authority, provide reliable information, and ensure they are available when the system starts doing something expensive at three in the morning.
Does the warning still matter if it is also marketing?
Yes. That is what makes it uncomfortable.
A warning can be accurate even when the people delivering it have a financial interest in the public response. Oil companies can accurately describe climate risks. Pharmaceutical companies can accurately describe disease. Security vendors can accurately describe cyber threats.
The conflict is not necessarily in the facts. It is in the incentives surrounding the facts.
The AI companies have a reason to emphasize the urgency of the threat. They also have a reason to make their products appear central to the solution. Those two goals fit together almost perfectly.
The sensible response is not to dismiss the warning. It is to separate the warning from the sales pitch.
Critical infrastructure needs strong authentication, least privilege, segmentation, patching, tested backups, logging, recovery plans, and competent people whether or not it adopts a frontier AI platform. AI might improve those processes. It might also make them more complicated, more expensive, and more dependent on external vendors.
The first question should remain boring: What is exposed, who owns it, what can be fixed, and how do we know the fix worked?
Are we watching the beginning of an AI security market—or a new dependency?
Probably both.
The arsonist-and-fire-department comparison is unfair if it implies that every AI company wants the fire to spread. These companies are responding to a real threat, and defensive AI may become genuinely valuable.
But the comparison becomes fairer when the same companies insist that the threat requires their models, their platforms, their partnerships, their access programs, and their expertise.
That is not self-regulation in the old-fashioned sense. It is something more sophisticated: an industry helping define the emergency, the vocabulary, the standards, and the acceptable solutions.
Maybe that is unavoidable. Maybe the people who understand the technology best really are the people we need in the room.
I keep thinking about that imaginary security dashboard showing a newly discovered vulnerability, an automated attack already in progress, and a vendor recommendation waiting beside it. The recommendation may be exactly right. It may even save the day.
But who installed the dashboard?
And what happens when the company selling the extinguisher becomes the only company allowed to decide how hot the room is?
References
- TechCrunch — “OpenAI, Anthropic, Google, and 100 other companies call for action to defend against rogue AI”
- OpenAI — “A call for collective action on cyber defense”
- OpenAI — Daybreak
- Microsoft Security — Project Perception
Artificial Intelligence, Cybersecurity, Critical Infrastructure, Big Tech, Government Regulation, Technology Industry
Leave a Reply