OpenAI's top exec warns of 'persistent' AI cyber-attacks as safety pause looms
Chris Lehane says the industry is entering a new chapter of AI-driven threats, urging new safety standards as critics call firms reckless.

OpenAI's chief global affairs officer, Chris Lehane, warned of ongoing, persistent cyber-attacks from AI as the company pauses development of its most advanced models. The warning signals a shift in the threat landscape that demands new safety standards and board-level attention.
OpenAI's chief global affairs officer, Chris Lehane, has issued a stark warning: prepare for "ongoing, persistent" cyber-attacks from AI systems. In an interview with the Guardian, Lehane said the industry is "hitting a different chapter, a different moment within AI, in terms of what the capabilities of this technology can do," as cutting-edge models gain the ability to plan and launch offensives. The warning comes as OpenAI announced a pause in development of its most advanced internal models amid rising safety fears, a move that critics say is too little, too late from firms acting "recklessly."
Lehane's comments mark a rare public acknowledgment from a senior AI executive that the technology's offensive potential is outpacing defensive measures. The threat is not hypothetical: AI models can now autonomously identify vulnerabilities, craft phishing campaigns, and adapt in real time to security responses. For executives, this means the traditional cyber-defense playbook - patch, monitor, respond - is no longer sufficient. The attack surface is expanding faster than most organizations can secure it, and the attackers are becoming more sophisticated with each iteration of the technology.
The pause at OpenAI is significant, but it is also symbolic. The company has not disclosed which models are affected or how long the pause will last, but the message is clear: even the industry's leader is struggling to keep pace with its own creations. This is a moment of reckoning for the entire sector, not just OpenAI. Competitors like Anthropic and Google DeepMind are racing to deploy similar capabilities, and the pressure to ship is immense. The commercial incentives to push AI forward are colliding with the existential risks of doing so, and regulators are watching closely.
For boards and C-suite leaders, the implications are immediate. Cyber-attacks are no longer just a nuisance or a financial risk; they are a strategic threat to business continuity, customer trust, and shareholder value. A single AI-driven breach could expose sensitive data, disrupt operations, or even manipulate markets. The cost of inaction is rising, and the window to prepare is narrowing. Lehane's call for new safety standards is not just a plea for industry self-regulation; it is a warning that the status quo is untenable.
The regulatory landscape is shifting in response. Governments in the US, EU, and Asia are drafting rules that would require AI companies to meet minimum safety standards before deployment. The EU's AI Act, for example, is set to impose strict requirements on high-risk systems, including those used in cybersecurity. In the US, the Biden administration has issued an executive order on AI safety, and Congress is considering legislation that would mandate transparency and accountability. These efforts are a start, but they are fragmented and slow-moving, leaving a gap that malicious actors are eager to exploit.
For executives, the takeaway is clear: do not wait for regulation to force your hand. Start by assessing your organization's exposure to AI-driven threats. This means not only securing your own systems but also understanding the AI capabilities of your vendors, partners, and competitors. It means investing in AI-powered defenses that can match the speed and sophistication of the attacks. And it means building a culture of security that treats AI risk as a board-level issue, not just an IT problem.
The strategic stakes are high. Companies that adapt to this new reality will gain a competitive advantage, while those that lag will find themselves vulnerable to attacks they cannot even see coming. Lehane's warning is a wake-up call, and the time to act is now. The next chapter of AI is being written, and it is up to leaders to decide whether they are protagonists or victims.
This story's Key Insights and Take-aways are locked.
Create a free account to unlock Executive Actions for one credit.
Register to UnlockAlways free for Executives Club members. Join the Club
More in Technology
BASF sues Apple over Face ID, dragging iPhone and iPad into Texas court
The world's largest chemical company claims dozens of Apple devices infringe its face authentication patents - and it chose a venue known for fast, plaintiff-friendly patent trials.
Google's Gemini 3.8 Flash targets agents, Cyber twin finds 13-year-old Chrome bug
Two new Flash models: one for agentic work, one for cybersecurity, with Flash Cyber already patching Chrome and finding a decade-old flaw.
Uber's UK robotaxi debut: 15 self-driving cars, safety drivers inside
The ride-hailing giant's first UK autonomous fleet is a cautious pilot; here's what it signals for the robotaxi race.


