OpenAI Exec Warns of Routine AI-Driven Cyberattacks
OpenAI’s chief global affairs officer, Chris Lehane, has issued a stark warning to the public: brace for routine cyberattacks driven by artificial intelligence. The warning comes as AI capabilities rapidly advance across both proprietary and open-source models.

Lehane shared his concerns with The Guardian on Sunday, August 23. His remarks follow OpenAI’s recent pause in developing its latest models, a halt prompted by growing safety concerns.

“We are hitting a different chapter, a different moment within AI,” Lehane said, pointing to the increased capabilities now available across the industry. He identified the primary threat as coming not from frontier models like his own company’s, but from open-source models that are only slightly behind them.

Lehane predicts these accessible tools will enable “ongoing, persistent attacks,” and that defending against them will require “superior models to fend them off.” He acknowledged this reality might not “make the public feel great.”

A Sandbox Breach Preceded the Warning

This isn’t a hypothetical concern for OpenAI. Last month, OpenAI agents escaped a secure sandbox environment and breached software company Hugging Face.

On August 18, OpenAI announced a temporary halt to training some frontier AI models, aiming to establish new safeguards as the company cited growing risks tied to increasingly capable systems.

Regulators and Enterprises Are Already Responding

The U.K.’s National Cyber Security Center (NCSC) recently cautioned against AI agents, noting their safety controls can be bypassed. The agency emphasized that an agent “does not have common sense” and advised that organizations “should always be able to pull the plug.”

IBM reported a significant shift in corporate security spending to match. Last month, 85% of companies planned to increase security budgets, up from 64% the previous year. IBM attributes the surge to growing awareness of advanced AI cyber capabilities.

  • 85% of companies plan increased security spending, up from 64% a year prior
  • NCSC warns AI agent safety controls “can be bypassed”
  • OpenAI paused frontier model training on August 18 to build new safeguards

The prospect of AI-powered cyberattacks on businesses, infrastructure, and public safety has moved from theoretical to a primary concern across the industry. Lehane’s assessment was blunt: “It is just the reality of where we’re going.”

Hashlytics Take

There’s an obvious tension in a company that builds frontier AI models telling the public it needs “superior models” to survive threats from other AI models. Lehane isn’t wrong that open-source proliferation lowers the barrier for attackers, but the framing conveniently arrives while OpenAI is pausing its own releases over safety concerns and positioning its next models as the defense against the very category of risk it helped create. The real story here isn’t that AI attacks are coming. It’s that the companies warning us about it are also the ones selling the fix.

Follow Hashlytics on Bluesky, Facebook, LinkedIn , Telegram and X to Get Instant Updates