When we released WeWorm, we wanted to raise awareness and called for greater collaboration among governments, technology companies, and security researchers to address the risks created by AI-powered cyberattacks.
Today, The New York Times published a second article about WeWorm, exploring this perspective in greater depth:
This discovery adds fuel to warnings from researchers that A.I. hacking capabilities are advancing faster than defenses can keep up, with tech leaders like Bill Gates warning that addressing risks from A.I. should be “the world’s top priority.”
That urgency could shape talks between President Trump and China's leader, Xi Jinping, that are expected on Sept. 24 in Washington, where the two sides are expected to discuss A.I. security as well as trade and other issues.
The article also features perspectives from China:
WeWorm and Anthropic's report about abuses of its models are yet more evidence that the world's two largest A.I. powers need a way to share information about bad actors or to clarify their intentions, experts say.
At the same time, few expect the summit to result in limits on the technology itself. Neither government is likely to agree to anything that restricts its own development of A.I. capabilities. But experts say there is value in at least establishing a channel of communication in the event of a crisis.
“This is an alarm, a wake-up call,” said Jiang Tianjiao, an associate professor at Fudan University focusing on emerging technologies, referring to WeWorm.
“Everyone needs to sit down and discuss how A.I. raises safety and security risks that are very different from traditional issues, and whether we need new frameworks of cooperation,” he said.
One of the popular reader comments echoes our concerns, although we probably wouldn't put it as strongly:
This arms race, unlike the nuclear one, is not just a few governments trying to outpace each other while keeping the technology out of the hands of the rest of the world. AI is already in the hands of the rest of the world. Maybe not yet in equal measure, and maybe not everyone has equal access to all the technology or physical components, but the situation is a far, far cry from the original difficulty of enriching uranium and building a bomb. AI, in one form or another, is already in the hands of every bad actor on the planet. That can only get worse. This is not about two powerful countries holding all the cards and keeping everyone else away from the table. This is about the possibility of worldwide guerilla warfare on a scale previously unimaginable. The fact that the US and China are still incapable of treating this existential crisis in unison, in tandem, without conflict solely because of their own separate self interests says everything we need to know about our collective hope for the future. There is none. The astounding progress of AI is also the astounding progress of terrorism and mayhem. It's just a question of time now.
International cooperation is not our area of expertise, so we will leave that discussion to those better qualified. But there are concrete steps the private sector can take now:
Build stronger defenses against zero-click attacks. This includes memory safe languages and better sandboxing facilities. We need more open research and sustained collaboration among platform owners, app developers, and researchers.
Expand investment in defensive security engineering. OpenAI's Patch the Planet and Anthropic's Defender Advantage Fund are strong starting points. They should become sustained, long-term initiatives and expand to cover the full range of critical software, including critical SAAS and closed-source products.
Proactively red-team critical infrastructure. Think Project Zero, but for banks, hospitals, and utility providers: a sustained effort to find and eliminate attack paths and improve detection capabilities in systems that everyone depends on.
Build open, infrastructure-level defenses. Organizations should assume breached and treat agentic AI as a potential insider threat. That means deploying honeypots and honeytokens; using AI-assisted monitoring to detect suspicious behavior; and developing stronger access-control models for an agentic world. The tools, frameworks, and reference architectures we build must be open source so that every organization, not just the largest or best-funded, can use them.
Helping operators of critical infrastructure is the founding idea behind Calif, and we have committed our entire team to this mission. We are pairing the world's best security researchers with the most capable AI models to make the Internet safer for everyone.
We are working with the Signal Foundation and Android Security to design and build frameworks for processing video, audio, and images more securely. We are part of OpenAI's Patch the Planet, and have helped triage and disclose thousands of vulnerabilities through the Anthropic CVD program. We have also directly red-teamed many banks and hospitals, and significantly improved their security posture.
This is the work Calif was built to do. The threats are advancing quickly, and defenders must move faster. We will continue doing our part, and we hope more AI labs, technology companies, and critical infrastructure operators will join us.

