Key facts
- OpenAI and over 100 organizations issued a collective warning about the growing threat of AI-enabled cyberattacks.
- The letter specifically called on governments and organizations globally to prioritize cybersecurity.
- Experts believe AI is making phishing attacks more efficient and scalable for criminal organizations.
- Deepfakes are highlighted as a significant risk for individuals and small businesses.
- Recommendations for personal cyber defense include multi-factor authentication, strong passwords, and verifying requests.
OpenAI, along with over 100 other organizations, has issued a stark warning about the rapidly closing window to bolster cyber defenses against increasingly sophisticated AI-enabled attacks. The collective open letter emphasizes the urgent need for global action from organizations, tech companies, and governments to address this escalating threat.
Experts like Kevin Powers from Boston College Law School view the letter not as a marketing ploy but as a genuine concern, urging policymakers to treat cybersecurity as a matter of national security. The letter specifically points to the potential for AI to disrupt critical infrastructure, including hospitals, water treatment facilities, and the internet itself.
For individuals and small businesses, the primary risk lies in AI-powered deepfakes and more advanced phishing attacks. Dominic Sellitto, a professor at the University at Buffalo, explained that AI makes these scams more cost-effective, faster, personalized, and easier to scale. The FBI's 2025 Internet Crime Report indicated over 22,000 complaints related to AI, resulting in more than $893 million in reported losses.
Peter Swire, a professor at the Georgia Institute of Technology, noted that AI can now convincingly impersonate individuals in phone or video calls, making it harder for victims to detect fraud. To combat these threats, security professionals like Cliff Steinhauer of the National Cybersecurity Alliance recommend fundamental security practices. These include enabling multi-factor authentication, keeping software updated, using strong passwords or passkeys, and always verifying unusual requests through a separate channel.
Swire suggests that for urgent calls from trusted contacts, hanging up and calling back directly can circumvent spoofed caller IDs. He also proposed establishing family codewords as a private verification method. Additionally, consumers should ensure that security features are activated on all their digital tools and understand how their data is handled by AI services.
