OpenAI And Anthropic Are Planning For ‘The Day After.’ The Fear Is A Major AI-Driven Crisis.
Executives at OpenAI, Anthropic and other artificial intelligence companies are privately planning for what could happen after a major AI-driven crisis, including a cyberattack severe enough to disrupt financial services, internet access or essential infrastructure.
The internal scenario planning is focused on what some executives call “the day after.” That is, the political, regulatory and public response following the first major real-world disaster linked to advanced AI, according to Axios.
People involved in the discussions told the outlet that a large cyberattack is among the scenarios drawing the most concern. Other possibilities include an autonomous AI agent escaping a controlled environment or a malicious actor using commercially available models to carry out a damaging operation.
Some industry insiders believe a serious incident could happen within the next six to 12 months.
The planning is not focused only on containing the technical damage. Companies are also considering how lawmakers and the public could respond after an event that causes widespread disruption.
Executives expect such an incident could quickly bring demands for tougher regulation and force policymakers to act under pressure, according to the report.
Public disclosures from OpenAI and Anthropic show that both companies are already treating advanced cyber capabilities as a significant safety issue.
In September, OpenAI said its Astra model had reached what the company defines as a “Critical” cybersecurity capability threshold under its Preparedness Framework.
OpenAI said the model was capable, with the right tools and access, of finding previously unknown security flaws and developing ways to exploit them across hardened systems without a person directing each step.
The company said Astra found previously unknown vulnerabilities during testing and combined some of them into working exploit chains.
OpenAI temporarily slowed parts of Astra’s development and release while it strengthened protections against cyber misuse and unauthorized actions before allowing development to continue.
Its Preparedness Framework is designed to assess advanced models for risks that could cause severe harm, including cybersecurity threats, biological and chemical risks and the possibility of models operating with dangerous levels of autonomy.
OpenAI has also created a broader Frontier Governance Framework covering cyber offense, loss of control, incident response and security risk management.
Anthropic has separately expanded its efforts to protect systems that could become targets of AI-assisted cyberattacks.
On Thursday, Anthropic launched its Cyber Mission, including a Critical Infrastructure Defense Program focused on power grids, water systems, transportation networks and government infrastructure.
The program will give infrastructure operators access to advanced AI models, Anthropic engineers and threat research intended to help identify vulnerabilities and strengthen defenses.
Anthropic said AI-driven cyberattacks are becoming faster and less expensive, while many critical infrastructure systems rely on older technology that can be difficult to secure.
The company also launched a tool that uses its models to scan open-source software for vulnerabilities and propose fixes.
Its Responsible Scaling Policy is designed to manage potential catastrophic risks from increasingly capable AI systems.
Anthropic defines those risks as threats that could result from deliberate misuse, such as a malicious actor using a powerful model, or from systems acting in ways their developers did not intend.
The company’s latest public risk assessments say its most advanced models remain below its highest thresholds for catastrophic biological or autonomous risks, while Anthropic continues testing for emerging capabilities.
The discussions include the possibility that governments could move quickly to restrict advanced models or impose new requirements before the causes and scope of an incident were fully understood.
The companies are therefore considering how to provide lawmakers with technical information quickly during a crisis, according to the report.
One fear is that an AI-powered cyberattack could create cascading disruption rather than remain confined to a single company or network.
Financial institutions, internet providers, electricity grids and water systems are among the kinds of targets being considered in these scenarios.