Security News

Cybersecurity news aggregator

INFO News Dark Reading

What the AI Warning Letter Completely Missed

  • What: Analysis of an AI warning letter on cyber threats
  • Impact: Discussion on the future of AI-driven cyberattacks
Read Full Article →

Informa TechTarget | SearchSecurity Cybersecurity Dive InformationWeek Channel Dive Explore our brands Dark Reading Resource Library Black Hat News Omdia Cybersecurity Advertise NEWSLETTER SIGN-UP Cybersecurity Topics World The Edge DR Technology Events Resources CYBERATTACKS & DATA BREACHES CYBER RISK VULNERABILITIES & THREATS COMMENTARY What the AI Warning Letter Completely Missed The recent AI warning letter is right about the "window," but it omits naming who is coming through it or, critically, who will close it. James Lyne,Chief Executive Officer,SANS Institute September 3, 2026 8 Min Read SOURCE: J STUDIOS VIA GETTY IMAGES OPINION Recently, more than 100 technology companies — OpenAI, Anthropic, Microsoft, and Google among them — published an open letter warning that AI is about to make sophisticated cyberattacks far cheaper and far more common, and that "we have a limited window to strengthen cyber defenses." I read it twice. The first time as the head of a security organization, nodding along to very nearly every line. The second time hunting for the part about who actually does the work. I did not find it. Before I get to the argument you can feel coming, I must acknowledge there is much this letter gets right. The threat is not hypothetical. On Aug. 19, five US federal agencies documented threat actors using AI-generated exploitation scripts, disguised as legitimate monitoring tools, against exposed Siemens S7 controllers, the sort that run water treatment plants, power stations, and chemical plants. Building such a tool once demanded specialist protocol knowledge. That knowledge was, in practice, the moat around a great many small utilities — that, and the hope of isolation from the Internet. But the moat has been drained, and the people wading across know that. Related:Large Enterprises Targeted in Fake Merger & Acquisition Scams However, I confess to some skepticism about the premise, and I'm in good company. The same day the letter appeared, analysts at RUSI, Britain's oldest defense think tank, published an assessment of AI and cybercrime that's also worth reading. Their argument: "Criminal innovation is a response to a revenue stream closing, not to a new technology opening a window." Adversaries focus on what pays and not what impresses. Phishing, pilfered credentials, and machines left facing the Internet that never should have been still pay handsomely and at scale. Threat actors are not incurious. They are curious about money, a rather more disciplined curiosity than the one our industry tends to practice. That is exactly what the recent water-sector campaign actually is: by the agencies' own assessment, it's reconnaissance and pre-positioning. Patient staging and not smash-and-grab. Tellingly, they decline to name who is behind it, even as a sister advisory this summer pinned a parallel wave of programmable logic controller (PLC) attacks squarely on Iran. Whoever it is, they needed no frontier model to stroll through a door that's been left open. Siemens itself conceded the point in its response: no new flaw in the controllers, merely new techniques aimed at old misconfiguration. AI has changed who can write the exploit. It has not changed what stops them. Related:AI 'Machine Speed' Cuts 2-Week Attack Down to 10 Hours The evidence points both ways; others report criminal adoption speeding up as open-weight models improve. Which way the next 12 months break, I can't tell you. Nor, and this is the point, do I need to. However it breaks, the assignment does not. Read the plan closely. Fix your highest-risk weaknesses. Raise the bar on what you buy, build, and deploy. Scrutinize AI-generated code. Deploy AI-powered defense. Share intelligence. Every recommendation is a verb, and every verb in security is performed by a person. It is a plan written entirely in verbs, with no subject. Should the adversary come through the window, the plan wants for trained operators. Should they never come, defending against the attacks already upon us wants the same operators performing the same verbs. The plan is identical in either future. Only the people are missing from it. The AI Defense Gulf Is Measured in People Consider the defenders the letter itself names as most exposed: hospitals, water utilities, the small operators of critical infrastructure. Its single most effective mitigation is thoroughly unglamorous and has nothing to do with frontier AI: Take the Internet-facing controllers off the Internet. For a well-staffed security team, that is a Tuesday afternoon. For a rural water utility whose entire IT function is one exhausted engineer wearing five hats, it may as well be written in Aramaic. The gulf between those two is measured in people, not products, and no model subscription closes it. The adversary keeps what is profitable and discards the elegant; we do the precise reverse and call it progress. Related:Threat Gang 'Springs' Vishing Attacks on Microsoft Teams Users There is also a deeper incoherence. We are told in one breath that these models are so uncontrollable that no one can be held accountable when they get out and break the law, and in the next that it should be trusted to defend our critical infrastructure. Both can't be true. Judicious use, by the right skilled people, is the only sane way to hold those two thoughts together. This points to three things I should dearly have liked to see in the letter and should still like to see from its signatories. First, invest in the operators already there. The plant engineer who has run a facility's controls for 15 years knows that environment better than any new hire ever will. Teaching them to harden it takes just a matter of weeks. The obvious retort is that they have no hours to spare, which is exactly why this must mean hands-on work that fits inside a shift rather than a semester, and why they must not be left to it alone. The practitioner this moment demands is bilingual, fluent in a core discipline and fluent in AI. You do not conjure that by hiring someone who has only ever spoken the second language or, worse, neither. Second, make "hands-on support" mean hands, and fund it. The letter asks the frontier AI companies to furnish under-resourced defenders with funding, training, and hands-on support. Quite right. Yet I have read it several times and cannot find a number in it: not a figure, not a date, not one named commitment from a single signatory. Goodwill will not outlast the next funding round, and the economics of these firms do not, unaided, reward this labor, which is precisely why the promise must be made concrete. Model access is not support if no one at the water utility knows what to do with the output. Committed hours from experienced practitioners, with names and dates against them, would be. Third, judge defensive AI tools by who can actually run them. A tool that makes a world-class security operations center (SOC) 5% sharper is a pleasant thing. A tool that lets two people at a hospital do the work of 10 is what the letter's logic demands. We measure this by whether it works when it is needed most; ask Hugging Face's responders how much a hosted model gave them in the thick of an incident. Vendors, the AI signatories included, ought to be held to that bar. I am content to be held to it myself. The easy critique of this letter, and half the Internet has already made it, is that the firms sounding the alarm are the same firms selling the cure. Perhaps. I'm less interested in the sellers' motives than in the plan's blind spot. A remarkable quantity of the public conversation is spent on frontier models and what they might do if prodded just so or slipped the leash. These are systems built by companies that can install controls, submit to regulation, and sit at a table to work the problem, and to their credit, some are trying. The criminal and the hostile state will do none of these things, and they press their advantage while we debate the more cinematic hypothesis. Defender attention is the scarcest resource in all of security. When the sizzle has faded, one rather suspects our future selves will not thank us for where we spent it. Bet on People to Target AI I should share in closing that one signature in particular raised an eyebrow: Hugging Face's. The company that lived through the year's most covered automated intrusion. Their post-incident analysis covered in depth the work of people fixing the detection the machines had missed and adapting their tools midfight. I do not begrudge them the signature, but they have signed a letter without a plan for the aforementioned people. The model access the letter asks the frontier companies to extend is the same thing their responders couldn't use in the thick of it. Their own incident report is this entire argument in miniature. The tools mattered. The people with skills made them matter. The letter remembers to ask for one and forgets the other. The signatories are right that there is a window, and right that it is closing. Whether anyone climbs through it matters less than the letter supposes because in every version of the future the work is the same. Not the noise, not the cinema of what the machines might one day do, but the plain work in front of us: building a defense that holds and beating the tactics adversaries are using this morning. Tools arrive on their own timetable. Threat intelligence matters only to those equipped to act on it. A motivated human being can learn to defend a network in the time we actually have. So, keep your eyes on the work, and place the bet that the letter forgot to ask anyone to make. Bet on people. About the Author James Lyne Chief Executive Officer, SANS Institute James Lyne has spent more than 20 years on the front lines of cybersecurity — chasing cybercriminals, reverse engineering malware, red-teaming high-security organizations, supporting intelligence efforts to disrupt adversaries, and helping organizations respond to major incide

Share this article