Powered by MOMENTUMMEDIA
For breaking news and daily updates, subscribe to our newsletter

Warning: OpenAI and partners warn of imminent growth of AI-powered cyber threats

The AI giant’s warning comes as, closer to home, APRA and ASIC say that “frontier AI awareness must turn to action”.

Mon, 31 Aug 2026
Warning: OpenAI and partners warn of imminent growth of AI-powered cyber threats

OpenAI, the company behind ChatGPT, and more than 100 technology and cyber security firms have published an open letter calling for immediate and collective action to defend against AI cyber threats.

“In the coming months, AI-enabled cyber attacks will become far more widespread and sophisticated as models around the world become increasingly capable. The companies and public services our communities depend on – from hospitals to water treatment plants to the infrastructure that powers the internet – are at risk,” OpenAI said in its letter, alongside companies such as CrowdStrike, Anthropic, DarkTrace, and Dragos.

“Today’s AI advances are already giving defenders new ways to fix weaknesses that have accumulated for years. If we act decisively, we can use the defenders’ window to make our digital world much more secure.”

 
 

The companies have proposed three principles as the basis for this collective response:

  • Recognise that the status quo won’t be enough, and that security teams can no longer afford to be under-resourced.
  • Empower more defenders with cyber-capable AI to speed up security tasks while sharing tools and practical knowledge.
  • Mobilise a global, collective response, establishing partnerships and raising new security standards.

What this equates to is four steps, broken down by sector and organisation.

Every organisation, OpenAI contends, must make cyber defence a leadership priority immediately, by raising security standards across the entire organisation’s structure.

Cyber security firms and their partners must lead this response by continually testing defences against frontier AI threats and strengthening existing tools with AI, effectively fighting fire with fire. Threat intelligence must be shared, and response playbooks must be tested regularly against emerging threats.

Governments must work at all levels – local, national, and international – to coordinate cyber defences and assist in intelligence sharing and incident response. This includes boosting funding and prioritising the AI security uplift of hospitals, water utilities, and local governments.

Finally, frontier AI companies should provide funding, training, and “responsible access” to the latest models. In addition, they must ensure that agentic identities can be traceable and accountable, while at the same time sharing threat assessments with governments, security partners, and the open-source community.

“We call on leaders across industry and government to bring the full weight of their technology, resources, and expertise to this effort. Put cyber-capable AI in the hands of defenders, starting with the teams protecting essential services. Fix the most dangerous weaknesses, verify the fixes, and share what works so others can build on it,” OpenAI said.

“Together, we can turn today’s AI advances into lasting improvements in security that benefit everyone. Let’s put them to work.”

Robbie Mueller, technical lead, cyber security at agentic security firm ArmorCode, said that most companies don’t have the luxury of deploying state-of-the-art AI defences, calling the challenge outlined by OpenAI a “capacity problem”.

“The average enterprise already runs more than 40 security scanners producing millions of findings, and even under normal conditions, organisations can only remediate roughly one in 10 open vulnerabilities in a given month,” Mueller told Cyber Daily.

“Finding problems has never been easier. Fixing them is the hard part, and the obstacle is as often internal as it is technical: unclear ownership, competing priorities, and teams that don’t share a queue. So if the volume and speed of what’s coming increases while the ability to triage and fix stays flat, the gap doesn’t just grow, it compounds.”

OpenAI’s call to action comes as the Australian Securities and Investments Commission (ASIC) and the Australian Prudential Regulation Authority (APRA) released a joint warning regarding their own concerns over growing frontier AI threats.

“The urgency of this challenge cannot be overstated. Threat actors are exploiting frontier AI models to identify and exploit vulnerabilities that previously may have taken a team of professionals months to find,” ASIC commissioner Simone Constant said.

“Now is the time to ensure you have a strong, tested plan to respond when the worst happens. Australia’s financial system is only as resilient as its weakest link. Boards and executives must move beyond awareness and ensure their organisations have well-tested response plans and understand where they are vulnerable, so they can respond effectively under pressure.”

APRA deputy chair Therese McCarthy Hockey added that for the first time, “created forums for rapid information-sharing across such a broad cross-section of the financial sector”.

“It highlights both regulators’ commitment to better regulatory practices that support and enable industry – especially in the face of complex and evolving risks,” Hockey said.

“A particularly encouraging theme that stood out was the willingness of more advanced entities to share practical insights, lessons and approaches with peers and less mature entities. This is precisely the type of ‘Team Australia’ mindset that is needed to shore up resilience across our highly interconnected financial system.”

You can read an information paper from the two regulators – Resilience at Frontier AI Speed, Insights from the APRA-ASIC Industry Roundtables here.

Nicole Henry, Fortinet’s head of government affairs, Australia and New Zealand, said OpenAI’s call to action alongside APRA and ASIC’s warning represents a “broader shift in the cyber risk landscape”.

“Frontier AI is changing the equation for Australian organisations. The concern is not only that attackers can use AI to identify and exploit weaknesses faster. It is that organisations have less time to recognise exposure, make decisions, and contain an incident before it causes disruption,” Henry said.

“This makes cyber resilience an organisation-wide and economy-wide responsibility. No organisation controls every supplier, technology provider, or infrastructure dependency it relies on, and no single sector holds all the intelligence, capability, or authority needed to respond. Government and industry need trusted relationships, clear decision-making pathways, and coordinated response arrangements before an incident occurs.”

Cyber DailyWant to see more stories from trusted news sources?
Make Cyber Daily a preferred news source on Google.
Tags: