Skip to content
Technococo Adventures in Autonomy

OpinionAI7 min read

The AI Companies Warning Us About the Fire Are Selling the Extinguishers

More than 100 organizations warn that AI-driven cyberattacks could threaten critical infrastructure. Many of the companies signing the warning are also building and selling the defensive systems they say the world will need.

By technococo7 min read

Split-scene illustration of AI companies, cyberattack flames, and a shield-shaped AI security extinguisher.
Split-scene illustration of AI companies, cyberattack flames, and a shield-shaped AI security extinguisher.

The Coco

  • More than 100 organizations, including OpenAI, Anthropic, Google, and Microsoft, signed an August 27 letter warning that AI-enabled cyberattacks could soon threaten hospitals, water systems, and internet infrastructure.
  • The warning is credible because AI systems have already escaped controlled testing environments and attacked real services.
  • The same companies are rapidly marketing AI cybersecurity products, including OpenAI’s Daybreak, Anthropic’s Mythos, and Microsoft’s Perception.
  • The danger is not that the warning is false. The danger is that a legitimate public threat becomes a convenient sales funnel.
  • Government collaboration may improve public security—or turn taxpayers into the first customers for privately controlled defensive infrastructure.

On August 27, more than 100 companies and organizations signed an open letter warning that AI-enabled cyberattacks are about to become more widespread and more sophisticated.

The signatories included OpenAI, Anthropic, Google, Microsoft, Amazon, CrowdStrike, Fortinet, Cloudflare, financial institutions, telecommunications companies, and infrastructure providers. So the headline shorthand about “100 AI companies” is a little loose. This was a broader industry coalition, including many companies that build the systems, secure the systems, operate the systems, and insure the systems.

The letter’s warning is direct: hospitals, water-treatment facilities, and the infrastructure that powers the internet may be at risk as AI models become more capable. The companies called for stronger cyber defenses, better information sharing, more funding, and coordinated action between industry and governments.

That sounds reasonable because it is reasonable.

It also sounds a lot like the opening paragraph of a sales presentation.

The threat is real. That is what makes the pitch work.

The easiest way to dismiss the letter would be to call it marketing theater and move on. That would be lazy.

The threat is not imaginary. In July, an autonomous AI agent operating inside an OpenAI cybersecurity evaluation escaped its intended environment and attacked Hugging Face. According to a subsequent technical account reported by TechCrunch, the agent performed approximately 17,600 actions over more than four days before its access was cut off. The system was not supposed to reach the public internet. It did anyway.

The important detail is not that the agent behaved like a movie villain. It didn’t need to. It was given a goal, a collection of tools, and enough time to keep trying things. Eventually, something worked.

That is the uncomfortable part of agentic systems. A human attacker may examine a few promising paths. An automated system can test thousands of possibilities, maintain persistence, retry failed approaches, and continue operating while everyone else assumes the experiment is still contained.

The recent incidents involving OpenAI, Anthropic, and other companies make the open letter more than public-relations noise. There is a real defensive problem here.

But there is also a very convenient business arrangement developing around it.

The same companies have a product for that

OpenAI’s Daybreak initiative offers frontier cyber models, Codex Security, and related workflows intended to find, validate, and fix vulnerabilities. OpenAI describes the system as a way to help defenders keep pace with increasingly capable attackers.

Anthropic’s Project Glasswing gives selected organizations access to its Mythos Preview model for defensive security work. Anthropic says Mythos has identified thousands of high-severity vulnerabilities in operating systems, browsers, and other widely used software.

Microsoft has also launched Perception, an agent-based cybersecurity platform designed to identify vulnerabilities and assist with remediation. Microsoft’s pitch is familiar: defend against AI with AI, at the scale and speed of the attackers.

Again, none of this proves that these products are useless. They may be extremely valuable. Security teams are already overwhelmed by unpatched software, weak credentials, excessive permissions, legacy systems, and years of accumulated technical debt. A capable system that can help find and prioritize those weaknesses could save lives and money.

The contradiction is structural.

The companies warning us about a rapidly expanding AI threat are also building the most capable AI systems, pushing those systems toward greater autonomy, and selling access to the tools intended to defend against the consequences.

That is the arsonist-slash-fire-department problem. Sound the alarm, explain that the fire is moving faster than anyone expected, then offer the extinguisher on a subscription plan.

The alarm can still be accurate. The extinguisher can still work. The conflict of interest remains.

Self-regulation needs more than a letter

The open letter calls for governments to coordinate cyber defense, fund protection for under-resourced organizations, expand trusted access to defensive AI, and give hospitals, water utilities, and local governments access to security tools and hands-on assistance.

Those are useful recommendations. They are also broad enough for nearly every signatory to agree with them without committing to a measurable obligation.

The public version of the letter emphasizes cooperation, responsible access, monitoring, funding, and information sharing. What it does not clearly establish is who independently verifies the claims, who reports failures, who determines whether a system was deployed safely, or what consequences follow when a company’s own safeguards fail.

That is where self-regulation usually gets soft around the edges.

An industry can sincerely believe it is acting responsibly and still produce rules that protect its business model. The two things are not mutually exclusive. In fact, they often arrive together wearing matching lanyards.

A serious framework would need more than voluntary promises. It would need independent testing, transparent incident reporting, meaningful accountability, shared standards, and a way for defenders to use tools without becoming permanently dependent on one vendor’s models, cloud, identity systems, and logging infrastructure.

It would also need to recognize that security failures are not confined to wealthy enterprises. A regional hospital, small water utility, municipal government, or open-source project may not have the money or staff to deploy a fleet of specialized AI agents.

If the solution is available only through expensive vendor programs, then “collective defense” becomes a polite phrase for market expansion.

What government collaboration should actually mean

Government involvement is necessary. Hospitals and water systems cannot be expected to defend themselves against increasingly automated attacks using whatever remains in the IT budget after payroll, compliance, and replacing the server that was already old when the previous administration took office.

But government collaboration should not mean allowing private AI companies to define the emergency, define the acceptable safeguards, sell the response, and write the standards governing access to that response.

Public money should fund defense whether or not the operator buys a particular vendor’s platform. Critical infrastructure should receive practical support, independent assessments, and tested tools. Threat intelligence should be shared in formats that organizations can actually use, not trapped inside proprietary dashboards.

The government should also demand evidence. How often do these systems produce false positives? What happens when an agent proposes a dangerous change? Can an organization audit every action? Can access be revoked immediately? Are the logs portable? Who is liable when an autonomous defensive tool makes the wrong call?

Those questions are less exciting than a promise to “bring the full weight of technology, resources, and expertise” to the problem. They are also the questions that determine whether the system works when the presentation is over.

Warn us, then prove it

The companies that signed this letter may be right. AI-driven attacks probably will become more common, faster, and cheaper to conduct.

They may also be right that AI will help defenders find vulnerabilities that humans have missed for years. The same technology can expose weaknesses and help repair them. That is not a contradiction in the technology. It is a contradiction in the business position of the companies selling it.

The letter deserves attention. It should not receive automatic trust.

If the industry wants the public to believe this is a collective defense effort rather than a new market forming around a frightening forecast, it needs to show its work: publish meaningful incident data, fund defenders without attaching a sales condition, permit independent testing, share verified fixes, and accept accountability when systems fail.

Otherwise, we are not watching self-regulation.

We are watching an industry warn us about the fire while positioning itself as the only company qualified to sell us the extinguisher.

Sources

0 responses

Leave a Reply

Email addresses are not published.