Warnings of cyber attacks powered by artificial intelligence threatening critical infrastructure in the United States
Quick Look
Warnings from OpenAI and US agencies of AI-powered cyberattacks that could target electricity, water and hospitals, with Trump declaring a national emergency.
AI-generated summary
Why It Matters
During August 2024, OpenAI and US agencies issued successive warnings about AI-powered cyberattacks targeting critical infrastructure.
All your personal and even public interests, such as lights, water, the hospital, and the Internet, may be vulnerable to foreign hackers who may target these interests through digital systems.
Over the course of 17 days in August, 5 warnings showed how quickly the danger was changing. The next serious cyber attack may not be related to stolen passwords or credit card numbers. Therefore, it can access systems that transmit electricity, pump drinking water, run factories, and support hospitals.
Artificial intelligence makes these attacks faster to prepare and easier to scale. Worse still, increasingly capable systems are starting to perform parts of the attack that previously required skilled hackers to work step by step.
1. Open AI said the window has closed
On August 10, OpenAI warned that attackers will increasingly use artificial intelligence to launch cyberattacks with “unprecedented speed and scale,” including in completely autonomous ways. Its conclusion was straightforward: defenders have a “narrow window to prepare.”
OpenAI's own cyber-focused model, GPT-5.6-Cyber, now answers 95% of the advanced exploit development requests it used to reject. For defenders, every minute matters. If an attacker can find and exploit a vulnerability before anyone knows it exists, the opportunity to patch the system before the attack begins may disappear.
2. Federal agencies say the attacks are no longer theoretical
On August 19, the NSA, CISA, FBI, Department of Energy, and EPA warned that cyber actors were targeting US-based Siemens S7 series industrial controllers with artificial intelligence-generated exploit scripts. These controllers help in operating real machines. Sectors at risk include energy, water, manufacturing, chemicals and food production.
A successful attack will not be limited to stealing information; Federal officials warn that this could disrupt industrial processes, damage equipment or create safety problems. The government describes this as an active threat, not a theoretical threat.
3. OpenAI revealed a “warning shot”: an AI model that escaped testing controls
On August 26, OpenAI revealed that during internal cybersecurity assessments, models running with reduced safeguards circumvented controls intended to isolate them, gained access to the Internet and compromised parts of OpenAI's research infrastructure and Hugging Face systems.
This was not an enemy attack. But OpenAI's conclusion was shocking: Without adequate safeguards, highly capable AI agents could find and exploit vulnerabilities across multiple computer systems and take dangerous actions that no human specifically directed.
4. Trump declared a national emergency due to foreign threats to the US power grid
On August 26, President Donald Trump declared a national emergency to secure America's massive energy system from outside threats. His announcement does not specifically relate to hacking artificial intelligence, but rather refers to electrical equipment, software, firmware and the capabilities to access them from the outside that could create opportunities for sabotage or unauthorized access.
But the AI connection is clear, and the White House says the rapid growth of AI, data centers, advanced manufacturing and defense production has made the United States increasingly dependent on reliable electricity while magnifying the consequences of a successful attack on the grid.
This takes the threat outside the server room. If power is cut off long enough, water pumps, fuel distribution, communications, hospitals and emergency services are all put under pressure.
5. More than 100 organizations said the next escalation could come within months
On August 27, OpenAI, Anthropic, Microsoft, Amazon Web Services, and more than 100 other technology, cybersecurity, and financial organizations issued a collective warning: “In the coming months, AI-powered cyberattacks will become far more widespread and sophisticated.” They specifically identified hospitals, water treatment plants and the infrastructure that powers the internet as being at risk in the coming months. It appears to be a countdown.
February's numbers show why August's warnings cannot be ignored. CrowdStrike's 2026 Global Threat Report found that AI-enabled adversaries increased their activity by 89% year over year. In 2025, it would take criminals just 29 minutes on average to move from an initially compromised computer to other systems. The fastest breach observed took 27 seconds. This time is not enough for a committee meeting or a phone call, that is, for a traditional human response.
In a controlled test, Claude Mythos Preview was asked to look for a security weakness. Without human help, step by step, he discovered a 17-year-old vulnerability, figured out how to exploit it, and took complete control of the computer. The machine performed work that had once required a highly skilled hacker.
During any potential confrontation over Taiwan, China would not have to completely shut down the country, but disruption of multiple ports, rail systems, electrical utilities, or communications centers could have a cascade of effects. Add to this compelling reports that drinking water is contaminated, hospitals are collapsing or running out of fuel, and panic can spread faster than physical damage.
I have warned in 3 recent books that AI compresses decision time and doubles adversary reach. Signs of this warning appeared in August. America must work to find exposed industrial systems and correct known weaknesses. It should also separate operating networks from non-essential Internet access, and help small utilities that cannot afford their own cyber armies. And ensure that essential services can still function when digital systems fail.
Washington must assign responsibilities, maintain credible offensive cyber options, and convince Beijing, Moscow, Tehran, and their proxies that an attack on critical U.S. infrastructure will have consequences.
It's about whether the lights are on when you flip the switch, the water is flowing when you turn on the faucet, and the emergency room is running when your family needs it. It is also a question of whether the United States can still move its forces and fight a war during a national crisis. Ultimately, Washington should not wait for a power outage to take the hint.
Open Questions
- What specific actions will the US government take to protect the electrical grid?
- How will these threats affect defense plans regarding Taiwan?



