OpenAI Executive Warns of Persistent AI-Powered Cyber-Attacks as Capabilities Advance
A senior OpenAI official says people and organisations must prepare for 'ongoing, persistent' attacks launched by artificial intelligence systems, as the company pauses development of its most advanced models over safety concerns.

Key points
- OpenAI's chief global affairs officer, Chris Lehane, warned in a Guardian interview that AI-powered cyber-attacks will become 'ongoing' and 'persistent'.
- OpenAI announced a pause in development of its most advanced internal AI models this week, citing rising safety fears.
- Lehane stated that current AI capabilities represent 'a different chapter' in the technology's development.
- Critics have accused AI companies of acting 'recklessly' in pushing forward without adequate safety standards.
Artificial intelligence, meaning computer systems that can learn and make decisions in ways that mimic human reasoning, has reached a point where it can help plan and carry out cyber-attacks. That is the warning from Chris Lehane, OpenAI's chief global affairs officer, who spoke to The Guardian this week.
"We are hitting a different chapter, a different moment within AI, in terms of what the capabilities of this technology can do," Lehane said.
What does an 'AI-powered cyber-attack' actually mean?
It means criminals could soon use AI systems to do the time-consuming work of breaking into computers automatically, at scale, and around the clock. Today, most cyber-attacks still require a human attacker to probe for weaknesses, write malicious software, and decide when to strike. AI can compress or replace those steps.
Lehane's specific phrase was 'ongoing, persistent' attacks, suggesting a future where AI systems do not sleep, do not pause, and do not need to be directed step by step. For a small business, a hospital, or a local government office, that changes the maths of defence considerably.
Should ordinary people be worried?
Yes, in a measured way. The threat is not yet fully here, but the policy conversation is clearly accelerating.
OpenAI's decision to pause development of its most advanced internal models is the more immediate signal. The company has not published a detailed technical explanation of what triggered the pause, but the public framing points directly to safety: the concern that models capable enough to assist researchers are also capable enough to assist criminals.
Critics, as reported by The Guardian, argue that leading AI firms have already been acting 'recklessly' by releasing increasingly powerful systems without implementing what those critics describe as adequate safety standards first.
What should organisations do right now?
Practical steps exist, even before any regulator moves. Organisations can audit which of their systems face the open internet, meaning systems that an automated attacker could probe without any human involvement. Reducing that exposed surface is the single most direct response to the 'persistent' threat Lehane describes.
Staff awareness still matters. Phishing, where criminals send fake emails to trick employees into handing over passwords or clicking malicious links, remains the most common first step in a breach, and AI makes phishing emails easier to write convincingly at volume.
From a regulatory standpoint, no specific binding rule in the United States or European Union yet directly governs AI-enabled offensive cyber capabilities in the way that, for example, the EU's NIS2 Directive (Network and Information Security Directive, which sets baseline cybersecurity rules for critical infrastructure operators) governs defensive obligations. That gap is exactly what makes statements like Lehane's worth watching closely.
Common questions
Is OpenAI being regulated?
No comprehensive AI-specific binding regulation currently governs OpenAI's development choices in the United States, though the EU AI Act sets rules for high-risk AI systems sold into European markets.
What is the pause OpenAI announced?
OpenAI paused internal development of its most advanced AI models this week over safety concerns, though the company has not published full technical details of what specifically prompted the decision.



