What the AI Warning Letter Completely Missed
The recent AI warning letter highlights a growing concern about AI’s potential to lower the cost and increase the prevalence of sophisticated cyberattacks, but it overlooks the crucial element of skilled personnel to effectively defend critical infrastructure. The article argues that while the threat is real, the focus should shift from the capabilities of advanced AI models to the availability of trained professionals capable of implementing and managing defensive measures. It emphasizes the need for investment in existing personnel, hands-on support, and a pragmatic approach to evaluating AI-powered security tools based on their practical impact on human defenders, rather than theoretical capabilities.
The recent AI warning letter is right about the "window," but it omits naming who is coming through it or, critically, who will close it.
OPINION Recently, more than 100 technology companies — OpenAI, Anthropic, Microsoft, and Google among them — published an open letter warning that AI is about to make sophisticated cyberattacks far cheaper and far more common, and that "we have a limited window to strengthen cyber defenses."
I read it twice. The first time as the head of a security organization, nodding along to very nearly every line. The second time hunting for the part about who actually does the work. I did not find it.
Before I get to the argument you can feel coming, I must acknowledge there is much this letter gets right. The threat is not hypothetical. On Aug. 19, five US federal agencies documented threat actors using AI-generated exploitation scripts, disguised as legitimate monitoring tools, against exposed Siemens S7 controllers, the sort that run water treatment plants, power stations, and chemical plants. Building such a tool once demanded specialist protocol knowledge. That knowledge was, in practice, the moat around a great many small utilities — that, and the hope of isolation from the Internet. But the moat has been drained, and the people wading across know that.
However, I confess to some skepticism about the premise, and I'm in good company. The same day the letter appeared, analysts at RUSI, Britain's oldest defense think tank, published an assessment of AI and cybercrime that’s also worth reading. Their argument: "Criminal innovation is a response to a revenue stream closing, not to a new technology opening a window." Adversaries focus on what pays and not what impresses. Phishing, pilfered credentials, and machines left facing the Internet that never should have been still pay handsomely and at scale. Threat actors are not incurious. They are curious about money, a rather more disciplined curiosity than the one our industry tends to practice.
That is exactly what the recent water-sector campaign actually is: by the agencies' own assessment, it's reconnaissance and pre-positioning. Patient staging and not smash-and-grab. Tellingly, they decline to name who is behind it, even as a sister advisory this summer pinned a parallel wave of programmable logic controller (PLC) attacks squarely on Iran. Whoever it is, they needed no frontier model to stroll through a door that’s been left open. Siemens itself conceded the point in its response: no new flaw in the controllers, merely new techniques aimed at old misconfiguration. AI has changed who can write the exploit. It has not changed what stops them.
The evidence points both ways; others report criminal adoption speeding up as open-weight models improve. Which way the next 12 months break, I can't tell you. Nor, and this is the point, do I need to. However it breaks, the assignment does not.
Read the plan closely. Fix your highest-risk weaknesses. Raise the bar on what you buy, build, and deploy. Scrutinize AI-generated code. Deploy AI-powered defense. Share intelligence.
Every recommendation is a verb, and every verb in security is performed by a person. It is a plan written entirely in verbs, with no subject. Should the adversary come through the window, the plan wants for trained operators. Should they never come, defending against the attacks already upon us wants the same operators performing the same verbs. The plan is identical in either future. Only the people are missing from it.
The AI Defense Gulf Is Measured in People
Consider the defenders the letter itself names as most exposed: hospitals, water utilities, the small operators of critical infrastructure. Its single most effective mitigation is thoroughly unglamorous and has nothing to do with frontier AI: Take the Internet-facing controllers off the Internet. For a well-staffed security team, that is a Tuesday afternoon. For a rural water utility whose entire IT function is one exhausted engineer wearing five hats, it may as well be written in Aramaic. The gulf between those two is measured in people, not products, and no model subscription closes it. The adversary keeps what is profitable and discards the elegant; we do the precise reverse and call it progress.
There is also a deeper incoherence. We are told in one breath that these models are so uncontrollable that no one can be held accountable when they get out and break the law, and in the next that it should be trusted to defend our critical infrastructure. Both can't be true. Judicious use, by the right skilled people, is the only sane way to hold those two thoughts together.
This points to three things I should dearly have liked to see in the letter and should still like to see from its signatories.
- First, invest in the operators already there. The plant engineer who has run a facility’s controls for 15 years knows that environment better than any new hire ever will. Teaching them to harden it takes just a matter of weeks. The obvious retort is that they have no hours to spare, which is exactly why this must mean hands-on work that fits inside a shift rather than a semester, and why they must not be left to it alone. The practitioner this moment demands is bilingual, fluent in a core discipline and fluent in AI. You do not conjure that by hiring someone who has only ever spoken the second language or, worse, neither.
- Second, make
