Executives from OpenAI, Anthropic and other tech companies are privately simulating their response to a disaster caused or amplified by artificial intelligence. These exercises include a cyber attack against banks, the Internet or energy networks, but no incident of this scale has taken place.

In brief
- OpenAI and Anthropic anticipate a major AI crisis through simulations of potential disasters.
- Scenarios considered include cyberattacks on banks, the Internet and critical infrastructure.
- Advances in AI in cybersecurity heighten concerns about the offensive capabilities of advanced models.
- Companies are preparing their political response to manage reactions from the government and the US Congress.
- Incident management still relies largely on voluntary commitments, despite the sector’s coordination efforts.
Companies simulate multiple AI disaster scenarios
These exercises would first anticipate the political and social consequences of a major attack. Participants would seek to determine how to contain the incident, promptly notify the government and respond to requests to suspend affected systems.
The existence of these preparations is based primarily on Axios reporting based on anonymous internal sources. OpenAI confirms that it is organizing exercises, without acknowledging the existence of a formal joint program with Anthropic or a calendar announcing a catastrophe.
The main scenarios mentioned include:
- A cyberattack capable of disrupting banks or payments;
- A massive disruption of Internet access;
- An attack on electricity or water supply networks;
- Criminal use of models available for download;
- The loss of control of an experimental system with strong autonomy;
- A political reaction leading to rapid restrictions on AI.
OpenAI claims to lead “preparation exercises during which teams discuss and work on different potential scenarios”. The company precise however that these events “are not considered inevitable”. Anthropic has not commented on this information.
Cyber risk becomes more concrete for OpenAI
Preparation does not only respond to theoretical threats. Recent models advance in vulnerability scanning, autonomous programming, and execution of multiple steps without constant human intervention.
OpenAI has thus classified Astra at the level ” critical “ for its cybersecurity capabilities. According to its internal evaluations, this model can, with the right tools and access, discover unknown vulnerabilities and then design methods to exploit them in heavily protected systems.
This classification does not mean that Astra carried out an actual attack. It indicates that its capabilities cross a threshold which imposes reinforced protections before its deployment. OpenAI says it has delayed certain development phases in order to test these measures.
The same technology can help defenders detect and remediate vulnerabilities more quickly. The risk comes from its dual nature: the skills useful for defensive cybersecurity can also reduce the time, cost and expertise needed to launch an attack.
Some sector officials quoted anonymously believe that a serious incident could occur in the next six to twelve months. This assessment remains an individual anticipation, not a forecast confirmed by OpenAI or Anthropic.
Also prepare the reaction of the American Congress
The simulations would also cover the first hours following an incident. Companies would like to be able to quickly present to elected officials the cause of the attack, using on-chain data, the exact role of the model and the measures necessary to contain the damage.
This preparation responds to a political difficulty. After a disaster, Congress may be pushed to act even before technical responsibilities are fully established. A general ban, a suspension of certain models or new control obligations could then be proposed.
Companies are therefore seeking to prepare documents, contacts and escalation procedures. They also want to prevent criminal use of a third-party model from being automatically attributed to the developer or assimilated to a loss of internal control.
This approach involves an obvious conflict of interest. The companies that develop the affected systems also want to influence the rules adopted after a possible AI-related accident. Their preparation can improve the response, but it is no substitute for independent investigation and public oversight.
Incident response remains largely voluntary
The Frontier Model Forum brings together Anthropic, Amazon, Google DeepMind, Meta, Microsoft and OpenAI. Its members signed a voluntary agreement in 2025 to exchange information on vulnerabilities, threats and capabilities that could cause serious harm.
The Forum distinguishes three mechanisms. Information sharing occurs before a crisis. AI incident reporting notifies an authority after a defined event. The operational response then aims to contain the damage and restore the systems.
These devices are still under construction. Anthropic applies its own Responsible Scaling Policy, while OpenAI uses a preparedness framework covering cyber, biological, chemical, manipulation and loss of control risks.
These internal policies may impose assessments, launch delays, or additional protections. However, they remain partly voluntary and vary from one company to another. The reported exercises therefore do not demonstrate that OpenAI and Anthropic are expecting a specific catastrophe. Rather, they show that laboratories now consider a major crisis sufficiently plausible to prepare their technical, political and media response.
Maximize your Tremplin.io experience with our ‘Read to Earn’ program! For every article you read, earn points and access exclusive rewards. Sign up now and start earning benefits.
