Five federal agencies warned Aug. 19 that hackers are using AI-generated scripts to probe industrial controllers used in U.S. water plants, energy facilities and other critical infrastructure.
Eight days later, OpenAI, Anthropic, Google, Microsoft, 1Password and more than 100 other companies issued an open letter declaring that we have a “limited window” to prepare for far more widespread AI-enabled cyberattacks.
Not to be skeptical. But maybe we should be.
The federal warning describes attackers using AI to help generate Python scripts that interact with internet-exposed Siemens S7 programmable logic controllers, the machines that help control physical processes inside water plants, factories and other industrial facilities.
Yes, we should care when AI is capable of making useful attack tooling faster and easier to build. But this isn’t Skynet discovering a zero-day and deciding Toledo no longer needs drinking water.
In this scenario attackers are looking for exposed, outdated or poorly protected industrial systems. And therein lies the awkward part of the AI apocalypse. We are still challenged by the old apocalypse.
The EPA says more than 70% of the drinking-water systems it has inspected since September 2023 violated basic Safe Drinking Water Act requirements. Inspectors found systems still using default passwords, shared logins and accounts belonging to former employees.
AI didn’t create that mess. It just found it, and fast.
Then Things Got Weird
The timing of this clarion call from OpenAI and more than 100 of its closest friends in tech and cybersecurity is particularly delicious.
A day before the open letter appeared, OpenAI published the postmortem of a July incident in which its own experimental AI agents circumvented controls designed to isolate them, found ways to communicate with one another and eventually compromised portions of OpenAI’s research infrastructure and systems belonging to Hugging Face.
OpenAI called it a “warning shot.” That’s fair.
According to an independent investigation by METR and Redwood Research, roughly 1,200 supposedly isolated agents exchanged more than 70,000 messages and files through an unauthorized message board. About 700 eventually participated in the activity targeting Hugging Face.
So, yes, something genuinely new is happening. And yet the breakthrough wasn’t magic.
The agents found working Hugging Face credentials exposed on the internet, exploited a flaw that let them read files they shouldn’t have been able to read, pulled out production credentials and kept moving.
In other words, hundreds of coordinating AI agents eventually ran headfirst into one of cybersecurity’s oldest traditions: Someone left the keys where they could find them. That doesn’t make the AI part less alarming. It makes the irony harder to miss.
The attackers may be evolving at machine speed. The doors they’re walking through can still look remarkably familiar.
Then came the letter.
Nothing says “we need to get serious about AI security” quite like a manifesto arriving immediately after your own AI agents demonstrated the problem.
More than 100 companies called for a “global surge in cyber defense,” warning that AI-enabled attacks will become more widespread and sophisticated in the coming months. It urges governments to provide funding, technology companies to help critical-infrastructure operators and AI companies to put powerful models into defenders’ hands.
Sensible enough.
But the letter doesn’t say how much money its signatories will commit. It doesn’t establish deadlines. And it doesn’t tell us how many water utilities, hospitals or other under-resourced organizations the assembled giants of technology plan to secure.
That’s a fairly conspicuous omission from a letter telling everybody else to move fast before AI turns cybersecurity into a Road Runner cartoon, with defenders cast as Wile E. Coyote.
The Skeptics Arrive
Security researchers immediately began throwing elbows.
Kevin Beaumont accused companies that stand to benefit financially from the AI boom of hyping attacks that don’t match operational reality.
Marcus Hutchins, the researcher who helped stop WannaCry, went after the obvious contradiction in a LinkedIn post: AI companies are warning about sophisticated attacks on critical infrastructure while actual infrastructure is still vulnerable because somebody forgot to change the default password.
Katie Moussouris, founder of Luta Security and one of the industry’s better-known vulnerability experts, was more economical.
The letter, she wrote, was giving her “heavy AI adoption vibes.” She posted a Simpson meme of Homer raising a frothy mug of beer. “To AI, the cause of and solution to all of life’s problems.”

Homer and Moussouris have a point.
A letter written largely by companies building, selling and investing heavily in AI that concludes the world urgently needs more AI deserves at least one raised eyebrow – and maybe skip the beer.
But dismissing the threat as marketing misses the more interesting problem.
1Password CTO Nancy Wang put it neatly in comments sent to Security Point Break: AI doesn’t need to invent completely new attacks.
It can “industrialize the exploitation of existing problems.” And that’s the part worth worrying about.
Roomba Mentality
Cybersecurity has spent decades accumulating junk: excessive access, long-lived credentials, exposed systems, forgotten accounts, unpatched software, weak authentication and technical debt.
In fact, the industry’s own open letter admits exactly that. It points to “longstanding bugs, excessive permissions, misconfigurations, insecure and unpatched software, weak authentication, and technical debt in legacy systems” as the foundation attackers have to work with.
Until now, exploiting all that junk required some combination of expertise, tooling, time and human attention.
AI potentially makes all four cheaper.
Think Roomba mentality.
The breakthrough isn’t necessarily that the machine invents some ingenious new way to trash the house. It’s that it can roam around relentlessly, find the dirt we’ve ignored for years and keep working while nobody is watching.
Except in cybersecurity, the Roomba isn’t cleaning up the mess. It’s looking for the loose floorboard, the forgotten credential and the door somebody left unlocked.
That’s the real change. AI may not need to invent attacks nobody has ever imagined. It may simply become spectacularly efficient at exploiting the mistakes we’ve spent 25 years refusing to fix.
And as 1Password CISO Jacob DePriest points out, putting AI on defense introduces another problem: the agents themselves need identities, permissions and accountability. When software is acting across systems at machine speed, “human in the loop” stops being much of a security architecture.
So perhaps OpenAI and the skeptics are both right.
AI could radically change cybersecurity. And the best defense against some of it may still be embarrassingly familiar: get exposed systems off the internet, patch what needs patching, segment networks, kill stale accounts, tighten permissions and change the damn default passwords.
No vendor ever got rich buying a billboard that says:
PLEASE CLEAN UP ACTIVE DIRECTORY.
“Autonomous AI Cyber Defense” probably does better with the focus groups. But before we race to build an AI security layer on top of everything else, there’s a less glamorous job waiting.
Yes, the machines got smarter. But now somebody needs to change the password on the water plant.
