Skip to content
Tech News
← Back to articles

What the AI Warning Letter Completely Missed

read original more articles
Why This Matters

This article highlights that while AI poses real cybersecurity threats, the industry's focus on AI-driven attacks may overlook the persistent, more traditional methods criminals use for profit. Recognizing this balance is crucial for developing effective defenses and understanding where resources should be allocated. It underscores the importance of pragmatic cybersecurity strategies over alarmist narratives, ensuring both consumers and industry players are better protected.

Key Takeaways

OPINION

Recently, more than 100 technology companies — OpenAI, Anthropic, Microsoft, and Google among them — published an open letter warning that AI is about to make sophisticated cyberattacks far cheaper and far more common, and that "we have a limited window to strengthen cyber defenses."

I read it twice. The first time as the head of a security organization, nodding along to very nearly every line. The second time hunting for the part about who actually does the work. I did not find it.

Before I get to the argument you can feel coming, I must acknowledge there is much this letter gets right. The threat is not hypothetical. On Aug. 19, five US federal agencies documented threat actors using AI-generated exploitation scripts, disguised as legitimate monitoring tools, against exposed Siemens S7 controllers, the sort that run water treatment plants, power stations, and chemical plants. Building such a tool once demanded specialist protocol knowledge. That knowledge was, in practice, the moat around a great many small utilities — that, and the hope of isolation from the Internet. But the moat has been drained, and the people wading across know that.

Related:Large Enterprises Targeted in Fake Merger & Acquisition Scams

However, I confess to some skepticism about the premise, and I'm in good company. The same day the letter appeared, analysts at RUSI, Britain's oldest defense think tank, published an assessment of AI and cybercrime that's also worth reading. Their argument: "Criminal innovation is a response to a revenue stream closing, not to a new technology opening a window." Adversaries focus on what pays and not what impresses. Phishing, pilfered credentials, and machines left facing the Internet that never should have been still pay handsomely and at scale. Threat actors are not incurious. They are curious about money, a rather more disciplined curiosity than the one our industry tends to practice.

That is exactly what the recent water-sector campaign actually is: by the agencies' own assessment, it's reconnaissance and pre-positioning. Patient staging and not smash-and-grab. Tellingly, they decline to name who is behind it, even as a sister advisory this summer pinned a parallel wave of programmable logic controller (PLC) attacks squarely on Iran. Whoever it is, they needed no frontier model to stroll through a door that's been left open. Siemens itself conceded the point in its response: no new flaw in the controllers, merely new techniques aimed at old misconfiguration. AI has changed who can write the exploit. It has not changed what stops them.

Related:AI 'Machine Speed' Cuts 2-Week Attack Down to 10 Hours

The evidence points both ways; others report criminal adoption speeding up as open-weight models improve. Which way the next 12 months break, I can't tell you. Nor, and this is the point, do I need to. However it breaks, the assignment does not.

Read the plan closely. Fix your highest-risk weaknesses. Raise the bar on what you buy, build, and deploy. Scrutinize AI-generated code. Deploy AI-powered defense. Share intelligence.

... continue reading