Called Out
Buried in the recent joint AI cyber defense letter, signed by OpenAI, Anthropic, Google, Microsoft, and more than 100 other companies, is a detail that deserves more attention than it's gotten: the letter specifically names hospitals, water treatment plants, and internet infrastructure as the systems facing the greatest risk from AI-accelerated attacks.
That's not a generic warning about "the cyber threat landscape." It's the companies building frontier AI models pointing directly at operational technology (OT) and healthcare systems and saying: this is where the exposure is worst. For anyone running a water utility, a hospital network, or critical infrastructure of any kind, that's worth understanding.
Why OT and healthcare are the named targets
The reasoning isn't hard to follow once you look at what makes these environments different from a typical corporate IT network.
Legacy systems that can't be patched on a modern cadence. Water treatment SCADA systems, hospital medical devices, and industrial control systems often run on hardware and software with 10-, 15-, even 20-year lifecycles. Patching isn't as simple as pushing an update. A change to a control system can carry physical, safety-critical consequences. That's part of why we've argued OT change management is your most important cyber control: the systems that are hardest to patch quickly need the most disciplined process around every change that does happen.
IT and OT convergence creates new paths in. As utilities and hospitals connect operational systems to corporate networks and the internet for efficiency and remote monitoring, they inherit IT's attack surface without always inheriting IT's security tooling. We've mapped this in detail in Exposing Invisible Links: The 6 IT-OT Bridges. Those bridges are exactly the kind of path an AI-driven attacker can find and exploit far faster than a human ever could.
The consequences of a breach are physical, not just financial. This is what separates critical infrastructure from most other regulated industries. A breach at a bank is a financial and reputational event. A breach at a water treatment plant or a hospital can be a public safety event. That asymmetry is exactly why these sectors were named specifically in the letter.
Plus… It already happened
Regular readers of this blog know we don't need to reach for a hypothetical example. The Minnesota water attack was a warning earlier this month, and the letter's warning about AI-accelerated attacks on infrastructure should be read as a direct continuation of that story, not a separate one. The tools available to attackers are evolving faster than most public works and healthcare IT budgets can respond to.
On the healthcare side, the exposure isn't limited to attacks from outside. We've also written about healthcare's shadow AI problem. Clinical and administrative staff adopting AI tools on their own, often without IT's knowledge, creating new paths for PHI to leak out of otherwise well-defended networks. The letter's warning about AI-enabled attacks is only half the picture; the AI adoption already happening inside your own walls, sanctioned or not, is the other half.
What operators should actually do with this information
Reading the letter is not a strategy. Here's where we'd point utility and healthcare leaders first.
Know what you actually have. You cannot defend an OT environment you can't fully see. If your team doesn't fully trust its own asset inventory, and most don't, that's the gap to close first, not a detail to defer.
Separate OT resilience thinking from IT resilience thinking. OT cannot simply mirror IT's approach to security and recovery because the operational and safety constraints are too different. We've laid out why in The Path to OT Resiliency: Why OT Cannot Mirror IT, a distinction that matters more, not less, as the pace of attacks accelerates.
Get a real, current assessment. Waiting for the next scheduled audit cycle is a hard posture to defend given what this week's letter describes. An accelerated OT/ICS security assessment or a healthcare cybersecurity readiness review gives you a current picture instead of a stale one.
Plan for recovery, not just prevention. Prevention will not be perfect against an accelerating threat. That's exactly why cyber resiliency for critical industries, the ability to recover fast and safely, matters as much as the controls meant to keep attackers out in the first place.
The letter is a signal, not a surprise
For the executives and boards overseeing water utilities, hospital systems, and other critical infrastructure, this week's letter should land less as new information and more as external validation of what frontline operators have suspected for a while: the systems keeping the lights on, the water clean, and patients cared for are squarely in the crosshairs of a faster, more capable class of attacker. The organizations that treat this as a prompt to act, rather than another headline to note and move past, are the ones still standing the next time an attack like Minnesota's makes the news.
Find the content useful? Subscribe to The Catch, our exclusive weekly LinkedIn newsletter focused on real-life experiences doing cyber right in the most highly regulated industries.



