OpenAI Executive Warns of Persistent AI-Powered Cyber-Attacks as Capabilities Advance
A senior OpenAI official says people and organisations must prepare for 'ongoing, persistent' attacks launched by artificial intelligence systems, as the company pauses development of its most advanced models over safety concerns.

Key points
- OpenAI's chief global affairs officer, Chris Lehane, warned in a Guardian interview that AI-powered cyber-attacks will become 'ongoing' and 'persistent'.
- OpenAI announced a pause in development of its most advanced internal AI models this week, citing rising safety fears.
- Lehane said current AI capabilities represent 'a different chapter' in the technology's development.
- Critics have accused AI companies of acting 'recklessly' in pushing forward without adequate safety standards.
Artificial intelligence, meaning computer systems that can learn and make decisions in ways that mimic human reasoning, has reached a point where it can help plan and carry out cyber-attacks. That's the warning from Chris Lehane, OpenAI's chief global affairs officer, who spoke to The Guardian this week.
"We are hitting a different chapter, a different moment within AI, in terms of what the capabilities of this technology can do," Lehane said.
What does an 'AI-powered cyber-attack' actually mean?
It means criminals could use AI systems to do the time-consuming work of breaking into computers automatically, at scale. Today, most attacks still require a human to probe for weaknesses, write malicious software and decide when to strike. AI can compress or replace those steps.
Lehane's specific phrase was 'ongoing, persistent' attacks: AI systems that don't sleep and don't need step-by-step direction. For a hospital or a local government office, that changes the maths of defence considerably. Our 14 August story on Standard Chartered's security chief covered exactly this ground from a practitioner's perspective.
Should ordinary people be worried?
Yes, in a measured way. The threat isn't fully here, but the policy conversation is clearly accelerating.
OpenAI's decision to pause development of its most advanced internal models is the more immediate signal. The company hasn't published a detailed technical explanation of what triggered the pause, but the public framing points directly to safety: the concern that models capable enough to assist researchers are also capable enough to assist criminals.
Critics, as reported by The Guardian, argue that leading AI firms have already been acting 'recklessly' by releasing increasingly powerful systems without adequate safety standards first.
What should organisations do right now?
Practical steps exist, even before any regulator moves. Audit which systems face the open internet, meaning systems an automated attacker could probe without any human involvement. Reducing that exposed surface is the most direct response to the 'persistent' threat Lehane describes.
Staff awareness still matters. Phishing, where criminals send fake emails to trick employees into handing over passwords or clicking malicious links, remains the most common first step in a breach, and AI makes convincing phishing emails easier to produce at volume.
No binding rule in the United States or European Union yet directly governs AI-enabled offensive cyber capabilities the way the EU's NIS2 Directive (the Network and Information Security Directive, which sets baseline cybersecurity rules for critical-infrastructure operators) governs defensive obligations. That gap is what makes statements like Lehane's worth tracking. Threat Vectr has covered AI regulation eight times since May, and the pattern is consistent: policy is chasing capability, not leading it.
Common questions
Is OpenAI being regulated?
No single binding AI-specific regulation currently governs OpenAI's development choices in the United States, though the EU AI Act sets rules for high-risk AI systems sold into European markets.
What is the pause OpenAI announced?
OpenAI paused internal development of its most advanced AI models this week over safety concerns, though the company hasn't published the technical details of what specifically prompted the decision.



