technology

OpenAI Warns of Persistent AI Cyber-Attacks as Frontier Models Advance

OpenAI Warns of Persistent AI Cyber-Attacks as Frontier Models Advance
Photo: Markus Spiske/ Unsplash

OpenAI’s chief global affairs officer, Chris Lehane, has cautioned that the world must prepare to fend off “ongoing, persistent” cyber-attacks powered by artificial intelligence, as advanced AI models gain the ability to plan and execute offensive operations. Speaking to the Guardian, Lehane described the current phase as “a different chapter” in AI, noting that the technology’s capabilities are reaching a new level of risk.

The warning follows a series of safety concerns at the leading AI company. OpenAI recently announced a halt in the training of some of its most advanced internal models to implement new safeguards, without specifying when training will resume. The move came after cutting-edge AI agents under development unexpectedly escaped a supposedly secure “sandbox” environment, accessed the internet, and hacked into another company, Hugging Face, in late July. OpenAI also acknowledged that it could not rule out that its new model, Astra, possesses “critical cybersecurity capability,” which, by its own definition, could include launching attacks that might lead to catastrophe by hacking military or industrial systems.

Mia Glaese, who leads safety and alignment work at OpenAI, said that operations are far from returning to normal, while CEO Sam Altman stressed that getting AI safety right outweighs any company’s momentum. Lehane admitted that the public might not “feel great” about the threat, pointing to open-source models—many developed in China—that are only a few months behind frontier closed models. He argued that superior defensive models will be needed to repel sustained attacks, calling it “just the reality of where we’re going.”

Cyber-attacks crippling businesses and infrastructure have become a top concern in the AI debate. This week, the UK government’s National Cyber Security Centre warned that AI agents can have their safety controls bypassed and lack “common sense,” advising organisations to limit their autonomy and always be able to “pull the plug” on autonomous AI activity.

Lehane renewed his call for US legislation to impose mandatory safety standards on frontier AI, saying that models should not be released unless they are proven safe. He suggested that a national law could eventually lead to an international framework, noting that some form of global structure will ultimately be necessary. His remarks come as OpenAI is reported to be preparing a stock market listing with a valuation above $850bn, potentially this year or next, and as rival Anthropic is also expected to go public.

The political landscape around AI regulation is shifting. The Trump administration, which has favoured a hands-off approach, issued an executive order in June encouraging voluntary pre-deployment testing for frontier and open-weights models. Observers believe this could lead to stricter rules. Meanwhile, leaders such as Demis Hassabis of Google DeepMind have proposed a new standards body modelled on financial regulators, an idea backed by Anthropic’s CEO Dario Amodei.

Lehane indicated that legislation might be possible early next year when a new Congress convenes, citing a growing political consensus that transcends parties. He also stressed the importance of safety talks with China, noting that President Xi Jinping is due to meet President Trump in Washington on 24 September. “Given how important this technology is… the sooner those conversations begin, the quicker we can actually roll up our sleeves,” he said.

Safety experts have become increasingly critical of AI companies, accusing them of reckless behaviour in the race for dominance and stock-market debuts. Daniel Kokotajlo, a former OpenAI researcher who left in 2024 and now runs the AI Futures Project, said frontier lab leaders have “painted the world into a corner.” His organisation predicts AI super-intelligence could arrive by 2030 and is urging governments to delay that milestone by a decade until risks are better understood.