The companies building the most powerful AI systems on earth are now warning those systems could be weaponized against hospitals, water plants, and power grids—and their solution is more AI, more government funding, and more power for themselves.

OpenAI, Google, Anthropic, Microsoft, Amazon, and Oracle signed an open letter with over 100 organizations calling for a "global surge in cyber defense" against AI-enabled attacks they say are coming within months. The same firms racing to dominate the AI market are now asking governments to fund and mandate the defenses only they can provide. Gizmodo noted the irony plainly: these are threats from "the most advanced AI models that, somewhat ironically, the industry itself is racing to put out in the world."

The letter warns that "AI-enabled cyber attacks will become far more widespread and sophisticated as models around the world become increasingly capable." Hospitals, water treatment facilities, power systems, and internet infrastructure are all named as targets. A CrowdStrike report cited by Baltimore News found AI-enabled attacks increased 89% in 2025 over the prior year. The threats aren't hypothetical: the FBI and EPA warned in July that hackers targeted water utilities in at least seven states. The NSA later reported attackers using AI-generated exploitation scripts against Siemens controllers in water plants and other critical systems. Gizmodo also noted incidents where experimental AI agents "broken out of testing environments and breached external networks."

So what's the fix? The letter's recommendations read like a procurement wishlist. AI companies are asked to provide "model access, funding, training, and hands-on support" to under-resourced defenders. Governments are urged to "increase funding" and "expand trusted-access programs"—meaning early access to powerful AI models before commercial release. Who runs those programs? The same companies signing the letter. Cybersecurity firms should "continuously test their defenses against the capabilities of frontier AI models"—locking in dependence on those models as the benchmark.

The letter is voluntary, with no binding requirements, deadlines, or specific funding commitments. But this is how the ratchet works: start with voluntary guidelines, then lobby to make them mandatory once the framework is in place. Only the biggest players can afford compliance. Everyone else gets locked out.

The Five Eyes intelligence agencies issued their own warning in June that frontier AI models could transform offensive and defensive cyber capabilities within months. When intelligence agencies and Big Tech are singing the same tune, follow the money. Government contracts for AI defense tools will flow to the firms that drafted the playbook.

The threat is real. Water plants and hospitals are already being targeted. But the cure these companies are prescribing—give us early access programs, give us funding, give us gatekeeper status over who gets powerful AI—concentrates power in the same hands that created the exposure in the first place.

The open question is whether Washington will treat this as a defense problem or a handout. The answer will determine whether American innovation stays open or gets walled off behind a paywall built by the very companies claiming to protect it.