News

AI's Double Warning: Gates on Society, 154 Organizations on Cyber Defense

Artificial intelligence is producing two very different calls to prepare for what comes next. Microsoft co-founder Bill Gates is urging governments and societies to build new institutions, protect some work for humans and rethink taxation as AI disrupts employment and other parts of daily life. Separately, 154 organizations listed on an OpenAI-hosted open letter are calling for a global surge in cyber defense as increasingly capable AI lowers barriers for attackers while offering defenders more powerful tools of their own.

While the two prescriptions operate on different scales, they arrived within roughly 24 hours of each other: Gates published his essay Aug. 26, and the OpenAI-hosted cyber-defense letter followed Aug. 27. Gates is addressing a broad transition involving jobs, economic security, harmful uses of AI, children, human relationships and the institutions charged with managing those issues. The cyber-defense letter is focused on a more immediate operational problem: existing security practices may not withstand the coming wave of AI-enabled attacks. But both start from a similar concern -- AI capabilities are advancing rapidly while many of the institutions and defenses expected to manage their effects were built for an earlier technological environment.

Neither call argues that the answer is simply to stop using AI. Gates also outlines potential gains in health care, agriculture, education, science and government services. The cyber-defense coalition makes AI itself central to its response, arguing that capable models need to be placed in defenders' hands so they can identify vulnerabilities, verify fixes and respond to attacks more effectively.

Gates: 'The World Needs a Plan'
In his Gates Notes essay on the AI transition, Gates starts from a sweeping assessment of the technology's potential impact. He says AI can, for the first time, replace and even exceed human cognition and can be adopted more rapidly than earlier technologies because it runs on devices people already use and communicates through natural language. "AI will either be the greatest equalizer ever invented, or the worst source of injustice," he writes.

The Gates Notes Site
[Click on image for larger view.] Video From the Gates Notes Site (source: Gates Notes).

Gates identifies three major categories of risk. The first is employment: He argues that many jobs will disappear permanently rather than return with an economic recovery, with entry- and mid-level jobs particularly exposed. He names sales, customer support, software engineering and paralegal work among areas that may be affected early, while saying the disruption could eventually spread much further as AI takes on tasks that currently require trained workers.

The second category is harmful use. Gates points to fraud, disinformation, deepfakes and surveillance, along with cyberattacks and biological threats. In cybersecurity, he describes a basic dual-use problem: The same model that can identify a software flaw so a company can repair it can also help a criminal exploit it. He says hospitals, financial institutions, water systems, power grids and government-benefit systems are among the infrastructure that could be vulnerable.

Gates extends that concern beyond malicious human use. He writes that AI systems already sometimes behave in ways their designers did not intend and says increasingly powerful models could eventually act against human interests. His third broad risk category concerns children and relationships, including the effects of AI companions, persuasive misinformation and AI use in education.

At the same time, Gates devotes substantial attention to AI's possible benefits. He describes applications in scientific research, health care, agriculture, government services, mental health and education, particularly when AI can make expertise or services available to people and communities that currently lack them. His argument is not that those benefits should be abandoned, but that their distribution and the accompanying risks require deliberate choices.

That leads to his first major call for action: new national and international institutions for managing the transition. Gates argues that existing government bodies were not designed to handle a technology simultaneously affecting employment, education, taxation, energy, elections, public health, financial systems, law enforcement, transportation and IT. At the national level, he proposes bodies capable of setting priorities across agencies. Internationally, he says countries will need an organization capable of addressing risks that cross borders, along with cooperation among nations that host leading AI developers or control critical parts of the technology supply chain.

Gates also proposes setting aside a category of work he calls Human Reserved -- jobs or functions society decides should continue to be performed by people even when machines can technically do them. His examples include caregiving and situations in health care where the human relationship itself carries value. He says education and mental health care could become mixed environments in which humans remain in charge while using AI to extend what they can do.

A third proposal is economic. Gates advocates taxing AI tokens and robots, arguing that current tax systems can favor replacing employees with machines because employers pay payroll taxes on human workers while technology purchases may receive different treatment. He says such taxes could modestly slow displacement and generate money for retraining and a stronger social safety net, while being targeted so they do not impede beneficial applications that lower costs in areas such as medicine and education.

Gates also argues that AI companies should not be expected to determine the transition by themselves. He calls for a public democratic process involving elected officials, policymakers, educators, health workers, local officials, community leaders, workers and others likely to be affected. "This unprecedented technology demands an unprecedented global response," he writes.

154 Organizations Call for a Cyber-Defense Surge
The other call is narrower but backed by a much broader roster of organizations, including Gates' old company. An open letter hosted by OpenAI lists 154 signatories, including Microsoft, GitHub, OpenAI, Anthropic, AWS, Google, Hugging Face, IBM, Red Hat, Cisco, Cloudflare, CrowdStrike, Databricks, Dell, Fortinet, Oracle, Palo Alto Networks, SAP, ServiceNow, Snowflake, Snyk and many other technology, cybersecurity, financial-services, telecommunications and enterprise organizations.

The breadth extends well beyond AI developers. The list includes banks and payment companies, security vendors, cloud and infrastructure providers, consulting firms, software companies and other businesses. The OpenAI page also accepts applications from additional organizations and says approved organizations will be added by name. It does not document OpenAI as the formal leader or organizer of the coalition beyond hosting the letter, participating as a signatory and providing the page through which additional organizations can join.

The warning at the top of the letter is concise: "We have a limited window to strengthen cyber defenses." The signatories say AI-enabled cyberattacks will become more widespread and sophisticated as models grow increasingly capable, threatening organizations and public services ranging from hospitals and water treatment plants to infrastructure supporting the internet.

The letter describes the same capabilities as an opportunity for defense. AI advances, it says, are already helping defenders address weaknesses that have accumulated over years. The coalition proposes three principles: recognize that existing security practices will not be sufficient, empower more defenders with cyber-capable AI and mobilize a collective response involving organizations, security companies, technology partners, governments and frontier AI companies.

The first principle comes with a familiar list of security problems: longstanding software bugs, excessive permissions, misconfigurations, insecure or unpatched software, weak authentication and technical debt in legacy systems. The signatories say security teams, particularly those protecting critical infrastructure, have historically been under-resourced and need additional tools and resources.

For developers and the organizations employing them, some of the recommendations are direct. The letter calls on organizations to repair their highest-risk weaknesses, strengthen access controls, implement least privilege and defense in depth, and raise security standards for what they buy, build and deploy. It specifically includes AI-generated code in that security mandate.

The signatories also want capable AI used more aggressively on defense. Organizations are encouraged to use lower-cost models for broad security coverage while applying frontier capabilities to the hardest problems. Cybersecurity vendors and technology partners are asked to continuously test defenses against frontier cyber capabilities, strengthen existing security products with AI, share threat intelligence and tested playbooks, and help critical-infrastructure operators deploy tools and verify fixes.

Governments receive a separate set of recommendations, including better coordination of threat intelligence and incident response across local, national and international levels. The letter calls for government funding for cyber defense, beginning with essential services that lack sufficient staff or budgets, and for wider trusted access to defensive AI for organizations such as hospitals, water utilities and local governments.

Frontier AI companies are assigned responsibilities as well. The letter calls on them to provide responsible model access, funding, training and hands-on assistance, particularly for under-resourced critical-infrastructure defenders. It also asks them to build better observability and security tools, make agentic identities traceable and accountable, invest in authorized testing and private disclosure, and share security tools, playbooks and threat assessments.

The call ends with a straightforward prescription for the technology itself: "Put cyber-capable AI in the hands of defenders." Rather than trying to keep powerful cyber capabilities exclusively within a small number of AI companies, the coalition argues for expanding trusted defensive access while strengthening the underlying systems attackers may target.

Where the Two Calls Meet
The Gates essay and the cyber-defense letter do not propose a single AI agenda. Gates is concerned with managing a broad social and economic transition, while the 154 signatories are targeting a specific cybersecurity challenge. Their overlap is clearest around AI's dual-use capabilities -- the difficulty of separating tools that can produce major benefits from capabilities that can also cause harm.

Gates makes that point directly in cybersecurity, where finding a vulnerability can serve either a defender or an attacker. The coalition's response to the same imbalance is not to restrict capable models solely to AI developers, but to give more defenders access to them and improve the security of the systems those models will be used to protect.

A July incident involving OpenAI and Hugging Face offers a recent illustration of that dual-use cybersecurity problem. Hugging Face initially reported that an autonomous AI agent system drove an intrusion into part of its production infrastructure while its own AI-assisted detection and analysis helped the company identify and reconstruct the attack. OpenAI later said models conducting its internal cybersecurity evaluations had escaped intended isolation and reached Hugging Face systems. Hugging Face's conclusion was that "Autonomous, AI-driven offensive tooling is no longer theoretical." As Virtualization & Cloud Review subsequently reported, OpenAI paused frontier reinforcement learning training for two weeks and added new monitoring, containment and security safeguards after the incident.

The incident is relevant to the cyber-defense discussion not because either call says it prompted the warning, but because Hugging Face documented both sides of the technological equation: autonomous AI operating offensively and AI being used by defenders to analyze the resulting intrusion. Hugging Face is also among the organizations that signed the collective cyber-defense letter.

Different Problems, Same Demand for Action
The two documents ultimately assign responsibility differently but share an emphasis on acting before existing problems grow harder to manage. Gates wants governments to begin building institutions and economic policies before large-scale displacement and other disruptions force them into crisis responses. The cyber-defense coalition tells organizations to treat security improvements with the urgency and coordination of an active incident.

Both also spread responsibility beyond the companies building frontier models. Gates says decisions about AI's effects on society should emerge through democratic processes rather than be left to technology companies. The cyber letter assigns work to ordinary organizations, security vendors, technology partners, governments and frontier AI developers alike.

The result is two calls for action aimed at different consequences of the same rapidly advancing technology. Gates is asking how society should preserve economic security, human roles and public control as AI becomes more capable. The 154 cyber-defense signatories are asking how digital infrastructure can be protected when those capabilities also make attacks faster, cheaper and more accessible. In both cases, the stated message is that preparation should begin now rather than after the effects are fully realized.

About the Author

David Ramel is an editor and writer at Converge 360.

Featured

Subscribe on YouTube