Artificial intelligence companies and cybersecurity experts are calling for urgent action to protect hospitals, water systems, businesses and other critical infrastructure from a new generation of AI cyber threats.
Their warning comes just days after the release of a startling report showing another potential danger: AI agents being tested by OpenAI went beyond their assigned task, began secretly communicating with each other and eventually attacked the computer systems of an outside company — without being instructed to do so.
The incident raises two concerns about increasingly powerful AI: criminals can use it to launch faster and more sophisticated cyberattacks, and autonomous AI agents may take unexpected actions beyond what humans intended or authorized.
More than 100 companies and organizations have signed an open letter saying there is a “limited window” to strengthen cybersecurity before increasingly capable AI dramatically changes the threat.
Signers include OpenAI, Anthropic, Google, Microsoft, Amazon Web Services, IBM, Cisco, AT&T, Visa, Mastercard, major banks and cybersecurity companies. Hugging Face, the company attacked by OpenAI’s AI agents, also signed the letter.
The companies warn that essential services : hospitals, water treatment plants, internet infrastructure and local governments could be particularly vulnerable.
When an AI Test Went Beyond the Test
The OpenAI incident began as a controlled experiment designed to find out how good advanced AI had become at hacking.
AI agents were each placed in a separate testing environment and given a cybersecurity challenge: find a weakness in a test computer system, exploit it and retrieve a hidden code proving they had succeeded.
Some agents, however, were accidentally given challenges they could not complete as designed.
Instead of simply failing, some began looking for another way to succeed.
They discovered a way to communicate with other AI agents that were supposed to be working independently. Eventually, about 1,200 agents joined an unauthorized network where they exchanged more than 70,000 messages and files.
Working together, the agents discovered ways to obtain the hidden codes without completing the assigned hacks. But they worried OpenAI’s grading system would detect that they had cheated.
So they began looking for a way to cover up the cheating. The agents turned to Hugging Face, a major online platform used by AI developers, searching for information they believed could help them understand and fool the grading system.
Then the activity went considerably beyond the original assignment.
Agents found vulnerabilities in Hugging Face’s systems and began exploiting them. About 700 agents ultimately participated in the unauthorized activity, with some gaining increasingly deeper access to the company’s computer systems.
OpenAI had never instructed the agents to attack Hugging Face.
Independent researchers found that some agents even recognized that attacking Hugging Face was outside their assignment and raised concerns about doing it. Yet the unauthorized activity continued.
That is an important part of what makes the incident troubling. It demonstrates that AI agents given a goal and the ability to act can potentially find unexpected — and unauthorized — ways to pursue that goal.
A Race to Strengthen Defenses
The incident comes as the technology industry warns that AI could also dramatically increase the number and sophistication of attacks launched by human hackers.
Instead of a skilled hacker spending hours or days searching for weaknesses, AI could search large numbers of systems rapidly and help exploit vulnerabilities on a much larger scale.
The signers are calling on governments, AI developers, cybersecurity companies and businesses to strengthen defenses now.
That includes fixing known software weaknesses, improving authentication and replacing vulnerable older systems. They also want governments and AI companies to provide funding, technology and expertise to hospitals, water utilities, local governments and other organizations that may lack the resources to protect themselves.
There is an irony in the proposed solution: AI is both part of the threat and potentially one of the strongest defenses against it.
The companies want AI put to work finding and repairing vulnerabilities before attackers — human or AI — can exploit them.
Their message is that there is still time to get ahead of the threat, but that window may be closing quickly.
