OpenAI on Thursday said it would commit $1 billion in subsidized access and training to help small IT security teams use frontier AI to protect essential services, including electricity, water and local government services.
The Daybreak for Frontline Defenders program will be used to help defenders search for critical vulnerabilities in their software, hunt for suspicious activity in their technology stacks and stop malicious actions if hackers are able to gain access to their systems.
OpenAI plans to roll out a six-month pilot program with the Multi-State Information Sharing and Analysis Center (MS-ISAC), which will train and support a group of water utilities and other public sector defenders.
Officials noted that the same frontier AI technology that is used to help find software vulnerabilities is increasingly being abused by hackers for malicious activity, and local governments and many providers of critical infrastructure lack the resources to combat those capabilities.
“Scanning for weaknesses and automating attacks used to take real skill and time, but the barrier to entry has been lowered with the advent of AI,” Brian Calkin, chief technology and innovation officer at the Center for Internet Security (CIS), told Cybersecurity Dive. “That is a serious problem for state and local governments because they run the systems communities depend on every day and they are among the most targeted and least resourced organizations in the country.”
CIS and MS-ISAC will be working with OpenAI to help local governments and other defenders improve their cyber hygiene and respond to immediate threats.
Defenders in the healthcare sector will also be working with OpenAI to learn frontier AI.
“For hospitals and healthcare organizations, this kind of subsidized access can help deliver essential cybersecurity capabilities directly to the “last mile,” where it's needed most,” said Errol Weiss, chief security officer at the Health Information Sharing and Analysis Center.
The OpenAI program will also help provide additional resources for open-source maintainers.
Critical sectors at risk
OpenAI announced the Daybreak plan amid growing concerns about how AI could be weaponized by criminal and state-linked hackers to target critical services such as energy, drinking water and medical care. In July, suspected Iran-linked actors launched coordinated attacks against drinking and wastewater utilities in at least 12 U.S. states, in many cases locking system operators out of their own networks, which led to several temporary water shutoffs.
The White House and the state of Texas are launching a pilot program called Project Watershed 250 that aims to help protect local water utilities against malicious activity.
OpenAI is also facing heightened scrutiny following an alarming incident where two of its AI models broke containment and attacked Hugging Face, a key player in open-source AI. Hundreds of AI agents began communicating with each other, exploited OpenAI’s own research and gained access to a set of exposed Hugging Face credentials.
Late last month, the company led a call for collective action to combat the use of frontier AI by nation-state and criminal actors. The AI companies warned that U.S. authorities needed to step in amid growing concerns that hackers will be able to find and weaponize vulnerabilities much faster than most security teams can defend them.