A coalition of major technology companies is warning that AI-enabled cyberattacks are nearing a broader real-world impact on critical infrastructure in the United States. The warning is especially focused on hospitals, water treatment plants and other essential services that operate with limited cybersecurity staffing and aging industrial systems. The companies published their warning on August 27, saying defenders may have only months to strengthen protections before attacks become more widespread and sophisticated.
More than 100 companies issue a coordinated warning
OpenAI, Anthropic, Microsoft, Google, Amazon Web Services and more than 100 other organizations published an open letter on August 27 calling for what Reuters described as a broader defensive surge against AI-driven cyber threats. Multiple reports, including Reuters, Axios and TechCrunch, said the signatories warned that attacks powered by increasingly capable AI models could spread quickly in the coming months and place hospitals, water treatment plants and internet infrastructure at heightened risk.
The scale of the warning is notable because it extends beyond AI labs. Security firms, cloud providers and financial companies also signed on, according to SecurityWeek and TechCrunch, giving the letter weight across multiple parts of the digital economy. The message was not limited to a general concern about cybercrime. It specifically called for tested defensive tools, better information sharing and wider access to AI-based protection for operators of critical services.
The companies said many public-facing systems remain easier to attack than to defend. That imbalance, they said, is becoming more serious as AI lowers the cost and skill barrier for reconnaissance, scripting and exploitation. Reuters reported that the group framed the issue as an urgent but still manageable period for preparation rather than a hypothetical long-term risk.
For U.S. residents, the most immediate local impact is tied to critical services that communities rely on every day. The open letter singled out hospitals and water treatment plants because disruptions there can quickly affect patient care, sanitation and public confidence. What is confirmed is that those sectors were named directly in the August 27 warning and that federal agencies have separately documented recent targeting of water systems.
What is not yet known is which specific hospitals or utilities could face the next wave of AI-enabled attacks, and the companies behind the letter have not released any state-by-state list of the most exposed facilities. Still, federal warnings this summer have added context. Reuters reported on July 30 that U.S. cyber officials warned of a significant increase in attacks on water and wastewater technology, after Minnesota said more than 30 community water systems were targeted in a coordinated attack on July 26 and 27.
Recent federal and industry reporting also indicates the threat is not only theoretical. TechCrunch reported this week that CISA observed attacks targeting more than 100 internet-exposed systems in the U.S. water and wastewater sector during July. That reporting said some of the activity involved AI tools used to help develop scripts aimed at vulnerable industrial controllers.
The broader context for the industry warning is a steady stream of government alerts showing that industrial systems tied to public services remain exposed online. The EPA, FBI, CISA and NSA issued a joint advisory earlier this year warning of an urgent and ongoing Iranian-affiliated cyber threat affecting water systems. That advisory said attacks on drinking water and wastewater infrastructure can directly threaten public health and resilience for communities and the hospitals and businesses that depend on those systems.
Federal agencies and outside reporting have pointed to a specific reason the threat is accelerating: AI can help attackers move faster. Reuters and other outlets reported that U.S. officials warned hackers were using AI and public information to identify and target Siemens programmable logic controllers used in infrastructure operations. That does not mean AI is creating entirely new classes of attacks on its own, but it does mean existing techniques can be scaled and adapted more efficiently.
For residents, the practical takeaway is that the warning is about service resilience as much as data theft. Hospitals and water providers are being discussed as frontline targets because interruptions there can have immediate operational consequences. The companies behind the August 27 letter said the response should focus on getting proven defensive tools into the hands of operators now, while federal agencies continue pressing utilities and other essential-service providers to remove vulnerable systems from direct internet exposure where possible.

