Skip to content
by InfinyAI ES

IA en un minutoNewsSecurity

Security

OpenAI and Anthropic prepare for a possible AI attack on critical infrastructure

IA en un minuto newsroom · Editor: Jon Elgezabal

In 30 seconds

OpenAI, Anthropic and other industry players are privately simulating a serious blow caused by AI, probably a cyberattack on banks, networks, electricity or water, and what would come next. Axios reports that much of the industry expects it within six to 12 months and that the priority is getting Congress ready. OpenAI speaks of preparedness exercises; Anthropic declined to respond.

Executives at OpenAI, Anthropic and other AI companies are privately gaming out what the public and political backlash would look like after a catastrophic AI event, according to an Axios scoop published on October 9.

According to Axios, they anticipate a large-scale event, most likely a cyberattack, that shuts down access to financial services or internet connectivity, or even power and water. Many people in the industry told Axios they believe something like this will happen in the next six to 12 months. The outlet adds that many top AI researchers and executives believe a major incident is inevitable.

The planning involves red-teaming worst-case scenarios, but it focuses mainly on racing to educate members of the US Congress. The executives know regulation has no chance of passing right now, but they want to shape the legislation and policies the country's leaders would turn to after a first catastrophic event.

OpenAI confirmed to Axios that it runs "preparedness exercises" in which its teams work through a range of scenarios, and added that it does not treat them as inevitable. Anthropic declined to comment.

Axios cites as an example a recent campaign against South Korean financial organisations, including reported breaches at two banks. A hacker from China allegedly used AI tools from China-developed models, including DeepSeek, to steal data from tens of thousands of bank customers. According to cybersecurity firm CrowdStrike, cited by Axios, the attacker also used Claude Code to ask for help finding places to sell the stolen data.

According to Axios, the people doing this planning assume that Democrats, ascendant after the midterm elections, will move fast to rein in AI but will face major obstacles: a Congress the outlet describes as out of touch with the AI revolution, an economy heavily tied to the AI infrastructure buildout, and many open-weight models that can already be freely downloaded. The toughest Democratic proposals include banning superintelligence or pausing advanced AI development. Others, such as requiring a kill switch on advanced AI, have support from both parties, although some experts doubt that all AI systems can be switched off.

Why it matters · analysis and opinion

That the very companies building the models are rehearsing the day after says a lot about how they see the risk: they no longer debate whether there will be a serious incident, but who will set the rules when it comes. That political calculation matters, because a law written in a hurry after a crisis tends to be harsher and less precise than one drafted calmly. For companies that use AI, the South Korean case teaches more than any simulation: a single attacker, with tools within anyone's reach, got to bank customers' data. Reviewing now who has access to what, keeping offline backups and having a plan to keep working for a few days without the internet or the bank costs little compared with improvising it afterwards.

Source: Axios · Written with the help of AI: how we make the news

Is your website up to scratch? We will audit it for free

AI in your inbox, every day or every Friday

The stories that matter, each one in a minute. With the source for every one.

Choose one or both:

Sign up and you are in: the daily arrives every night and the weekly on Friday mornings. You can unsubscribe from any email.