Breaking News

100 Leading AI Companies Are Warning Governments About a Risk They Are Still Accelerating

Written by Maria-Diandra Opre | Sep 23, 2026, 10:47:00 AM

More than 100 companies, including Google, Microsoft, OpenAI, and Anthropic, co-signed a letter asking governments to treat cyber defense as an emergency (OpenAI, 2026). Their concern is concentrated on critical infrastructure, where vulnerable software can remain in service for years because taking it offline is operationally difficult, while frontier models are already finding thousands of exploitable flaws in weeks.

The “status quo security won’t be enough”. The reasons it gives are familiar to anyone who has worked around aging technology. Unpatched software, permissive access, weak authentication, forgotten misconfigurations, and technical debt have accumulated for years. AI did not create any of them, but it is simply getting better at finding them.

AI is reducing the amount of skilled labor required to discover and investigate weaknesses, while many critical systems remain expensive to patch and even harder to modernize.

That is a lethal combination for sectors where uptime is itself part of safety.

Critical Infrastructure Enters the AI Era with Years of Security Debt

The US water sector includes close to 170,000 drinking-water and wastewater systems, many of them operating equipment spread across large geographic areas. Remote connectivity makes those systems easier to manage, but GAO has repeatedly documented that it also creates routes into operational technology that controls pumps and other physical equipment (GAO, 2026).

In July, the FBI and Environmental Protection Agency warned that attackers had remotely accessed Rockwell Automation programmable logic controllers used by water and wastewater operators in at least seven states. The attackers changed device configurations and passwords, causing some utilities to lose monitoring or control and disrupting operations in several cases.

The federal recommendations were quite basic: remove PLCs from direct internet exposure, place them behind secure gateways, and strengthen access controls (FBI, 2026).

The fact that such advice is still necessary says more about the sector than the sophistication of the attackers.

Operational technology often has a service life far longer than conventional IT. Industrial controllers may remain in use for 15 or 20 years. Some depend on unsupported operating systems or vendor-specific software that was designed before remote connectivity became routine. Replacing them is rarely a matter of scheduling an overnight update because the equipment may control pumping, treatment or another physical process.

GAO has repeatedly identified the same constraints across the US water sector. Smaller utilities often lack dedicated cyber staff, while older equipment can be difficult to retrofit with current security controls. Remote access helps operators manage geographically distributed assets, but it also extends the number of paths from public networks into operational environments.

Frontier Models Are Automating More of the Exploit Development Process

Much of the discussion around AI and cybersecurity still treats the technology as a productivity tool for existing attackers.

Anthropic’s Project Glasswing gave around 50 organizations access to Claude Mythos Preview for defensive vulnerability research (Anthropic, 2026). Within weeks, participants identified more than 10,000 high- or critical-severity vulnerabilities. Several organizations reported that their discovery rate increased by more than tenfold.

The more relevant result came after discovery, as Anthropic found that verification and remediation were becoming the slower parts of the process. Some maintainers asked for disclosures to be slowed because they could not review and patch findings quickly enough.

Vulnerability research has traditionally consumed a large amount of expert time. An analyst may have to understand unfamiliar code, reproduce a failure, determine whether it is exploitable, and work out how far access can be extended. AI systems can now perform more of that investigative work repeatedly across large numbers of targets. Anthropic’s separate exploit evaluations show the progression more clearly. Claude Mythos Preview could transform vulnerabilities into exploit primitives and combine them into working attack chains, one reason the company restricted broader access to the model (Anthropic, 2026).

The practical effect is a lower cost of curiosity. Software that once received little attention because analyzing it required specialist effort becomes more attractive when an agent can spend hours reading documentation, testing hypotheses, and revisiting failed approaches.

Critical infrastructure contains a great deal of software that has survived partly because nobody had enough incentive to examine it closely.

AI Can Find the Backlog Faster Than Infrastructure Operators Can Clear It

The obvious answer is to give defenders the same capabilities, which is exactly what the 100-company letter proposes. Frontier AI companies are being asked to provide controlled model access and direct technical support to under-resourced infrastructure operators. Governments would fund defensive programs for organizations that cannot build large security teams themselves. Hospitals and water utilities are mentioned repeatedly.

That approach has a strong case since a small utility may be able to use AI-assisted testing to find vulnerabilities that would otherwise remain invisible for years. But discovery is only the beginning of the operational problem.

A vulnerability in an industrial controller may require a vendor patch that does not yet exist. Installing it may require engineering validation before deployment. A legacy device may be so old that mitigation means network isolation or full replacement. For a system providing an essential service, organizations must manage maintenance itself as a risk.

This is why the quantity of vulnerabilities found by Project Glasswing should not automatically be read as progress. Finding 10,000 serious flaws quickly is valuable only if organizations have enough engineering capacity to act on them. The security bottleneck is moving downstream.

AI Labs Want Faster Defenses Without Slowing the Cyber Capability Race

There is an obvious conflict in a warning led by the same frontier labs pushing cyber-capable AI forward. OpenAI and Anthropic are asking governments to harden critical infrastructure quickly, while continuing to improve the models that make that urgency real. Their proposed remedy includes wider defensive access to those same systems.

Andrew Yoon of CivAI told the BBC that an “unprecedented wave of AI hacking activity” is coming (BBC, 2026). He argued that the signatories should be held to their commitments on defensive funding, while pointing out that the letter says nothing about slowing the development of AI hacking capability itself.

The industry is effectively asking public institutions to absorb the downstream security costs of a capability race they don't control. Frontier labs may well be right that hospitals, utilities and public agencies need better AI tools, but those organizations are being asked to adapt on infrastructure budgets and procurement cycles that bear little resemblance to frontier model development.

If the same companies accelerating offensive capability are best placed to see how fast it is advancing, then defensive funding cannot be treated as a voluntary add-on or a reputational gesture. The costs of securing the environments exposed by that progress are becoming part of the technology’s externalities.

AI fundamentally skews the battlefield by making vulnerability discovery and exploitation virtually frictionless all while defenders remain trapped in slow, resource-heavy remediation processes tied to legacy hardware. In the end, Frontier AI effectively accelerates a deep, pre-existing structural deficit.