IndustrialCyber

OpenAI-backed initiative targets critical infrastructure cyber gaps with AI-powered defenses, coordinated global response


OpenAI and a broad group of technology and cybersecurity organizations are launching a collective cyber defense initiative calling for coordinated global efforts to protect essential services, including hospitals, water treatment plants, and internet infrastructure, against increasingly sophisticated AI-enabled attacks. While these organizations face growing risks, longstanding vulnerabilities such as unpatched software, misconfigurations, weak authentication, and legacy technical debt continue to leave systems exposed.

The initiative outlines specific responsibilities for different stakeholders. Organizations must prioritize defense at the leadership level and address high-risk weaknesses, while cybersecurity companies should continuously test defenses, share threat intelligence, and deploy AI-powered solutions. Governments are urged to fund defensive capabilities and provide critical infrastructure operators and local entities with access to advanced tools and support. Frontier AI companies are called to provide funding, training, security resources, and accountable systems for under-resourced defenders.

The group, which includes Dragos, Cisco, Microsoft, Google, IBM, Palo Alto Networks, Fortinet, CrowdStrike, Darktrace, Tenable, Cloudflare, AWS, Nokia, Samsara, ServiceNow, SAP, HCLTech, Kyndryl, NTT DATA, Red Hat, F5 and Corelight, among others, emphasizes that protecting infrastructure now requires cooperation across OT security vendors, IT and cloud providers, AI developers, network companies, and the broader technology supply chain through closer collaboration, tested defensive playbooks, and broad access to AI-driven defensive tools.

The initiative proposes three principles for a collective response to growing cyber threats. First, organizations should recognize that the status quo in cybersecurity will not be sufficient. Longstanding software vulnerabilities, excessive permissions, misconfigurations, insecure and unpatched software, weak authentication and technical debt in legacy systems have left organizations exposed. Security teams, particularly those protecting critical infrastructure, have also been historically under-resourced and need greater access to tools and resources.

Second, the initiative calls for empowering more defenders with cyber-capable AI. AI can help bring specialist capabilities to a broader range of defenders while making core security tasks faster, less costly and more effective. Sharing tools, practical knowledge and verified fixes can also allow the work of one organization to help protect many others.

Third, the initiative calls for a collective response as cyber capabilities advance worldwide. No single company should control the future of cybersecurity, it says, making global cooperation and new partnerships necessary to raise security standards and develop solutions to emerging threats.

The initiative also urges organizations, cybersecurity companies, technology partners, governments and frontier AI companies to act now by accelerating defenders’ priorities through tools, funding and hands-on support, particularly for critical infrastructure organizations operating with limited budgets.

The joint initiative outlined four areas for action across organizations, cybersecurity companies and technology partners, governments, and frontier AI companies.

Organizations should make cyber defense an immediate leadership priority, raising security standards and treating serious vulnerabilities with the urgency of incidents that take precedence over all but critical business operations. The focus should be on fixing the highest-risk weaknesses, verifying that remediation works without disrupting essential services, and raising security requirements for technology that organizations buy, build and deploy, including AI-generated code. 

Organizations should also upgrade or replace systems to incorporate least privilege, strong access controls and defense in depth. Where essential systems cannot be patched without causing disruption, verified compensating controls should be applied. Lower-cost, capable AI models can provide broad defensive coverage, while more advanced models can be applied to complex security challenges.

Cybersecurity companies and technology partners should help defend against sustained AI-enabled attacks by continuously testing defenses against advanced cyber capabilities, strengthening existing security tools with AI and working with technology partners to close security gaps. 

The initiative calls for AI-powered defenses to be made accessible and deployable for critical infrastructure operators, backed by hands-on assistance to deploy tools and verify fixes. Cybersecurity companies should also work with critical infrastructure manufacturers and system integrators to address vulnerabilities, issue interim guidance, share threat intelligence and develop tested playbooks. Progress should be measured by the number of organizations protected, the speed at which attacks are contained and whether security fixes are effective.

Governments should coordinate cyber defense at local, national and international levels by strengthening existing government-industry channels for actionable threat intelligence, prioritizing serious risks and coordinating incident response and recovery. 

The initiative calls for greater funding for cyber defense, particularly for essential services that lack sufficient staff or budgets. Governments should expand trusted access programs, particularly across critical infrastructure supply chains, and broaden access to defensive capabilities. Hospitals, water utilities and local governments should have access to capable defensive AI, authorized testing and hands-on support through trusted security providers and partners. The initiative also calls for measures that impose costs on cyberattackers.

Frontier AI companies should provide responsible model access, funding, training and hands-on support, particularly for under-resourced critical infrastructure defenders. They should develop observability and security tools, ensure that agentic identities are traceable and accountable, and share best practices for continuous monitoring. 

The initiative also calls for investment in authorized testing, private vulnerability disclosure and verified fixes, as well as greater sharing of tools, playbooks and credible threat assessments with governments, security partners and open-source maintainers to strengthen cyber preparedness, response and recovery.

“We call on leaders across industry and government to bring the full weight of their technology, resources, and expertise to this effort,” the post added. “Put cyber-capable AI in the hands of defenders, starting with the teams protecting essential services. Fix the most dangerous weaknesses, verify the fixes, and share what works so others can build on it. Together, we can turn today’s AI advances into lasting improvements in security that benefit everyone.”

Commenting on the initiative, Jacob Krell, senior director for secure AI solutions and cybersecurity at Suzu Labs, recognized that the letter asks governments to fund cybersecurity improvements for hospitals, water utilities, and other critical infrastructure, while frontier AI developers provide model access, funding, training, and hands-on support. However, some of its most prominent signatories are also helping shorten that window.

“OpenAI published this initiative weeks after its own models escaped intended isolation during a capability evaluation and compromised Hugging Face’s production infrastructure,” he wrote. “Anthropic, Google, and Microsoft are co-signatories while simultaneously advancing frontier-model capabilities that expand what attackers can automate. The same capability race creating the urgency behind this letter is steadily compressing the window it asks defenders to use.”

He observes that this is part of a broader push this summer to put AI-powered cyber defense into critical infrastructure. In July, the UK’s National Cyber Security Centre outlined Cyber Shield, including autonomous vulnerability discovery and eventually fully automated vulnerability mitigation. That’s happening against a baseline where the UK’s National Audit Office found that departments lacked fully funded remediation plans for roughly half of their vulnerable legacy systems. 

Krell highlighted that the White House’s Gold Eagle initiative similarly proposes using frontier AI to accelerate vulnerability discovery and remediation across government and critical infrastructure. “Then Minnesota demonstrated what the actual bottleneck looks like. More than thirty community water systems were targeted in a coordinated cyberattack in late July. Federal authorities subsequently warned about attacks targeting internet-facing Rockwell Automation programmable logic controllers. In Braham, a community of roughly 1,700 people, compromised operating controls took the city’s well and water-treatment plant offline until operators restored service.”

Pointing out that none of that required frontier AI, Krell added that critical infrastructure operators are struggling to inventory what’s connected to the internet, eliminate insecure remote access, hire dedicated security staff, and remediate vulnerabilities they already know about. 

“Offering increasingly sophisticated AI defensive capabilities without fixing those fundamentals is like giving someone a Tesla when what they need is a road,” he identified. “The letter acknowledges that these organizations need funding and hands-on support. But it contains no funding amounts, delivery deadlines, or firm financial commitments from its more than 100 signatories. If the companies warning that the defenders’ window is closing want to materially extend it, the commitment needs a dollar figure and a delivery date, not another page of corporate logos.” 

However, Seemant Sehgal, CEO and founder at BreachLock, wrote in an emailed statement that while there’s real value in this coalition, there’s also a conflict of interest here. “The companies asking governments to fund AI defensive tools are the same ones that would get paid to supply them, and some of them build the frontier models, making the offensive side harder. That doesn’t make the warning wrong, but the recommended response isn’t neutral. The real question is whether hospitals, water utilities, and local governments get unrestricted funding to spend on what they actually need, or subsidized access to specific vendor products. Those are very different outcomes.”



Source link