Senior executives at AI companies including Anthropic and OpenAI have been privately rehearsing how to handle public and political backlash after a catastrophic AI incident, according to Axios.
The scenario they fear most is a large-scale cyberattack that disrupts banks, the internet, electricity, and water supplies. Several people in the industry believe a major event could happen within the next 6 to 12 months.
How the companies describe the work
OpenAI said the exercises are preparatory and that it does not treat the scenarios as inevitable. Anthropic declined to comment.
Axios reported that the planning includes red-team testing for worst-case outcomes and efforts to educate members of Congress as quickly as possible. Executives involved understand that regulation is difficult to pass under current conditions, but they hope to shape the laws and policy decisions US leaders make after the first major disaster.
Incidents cited in the report
In July this year, OpenAI said its GPT-5.6 Sol model and a more advanced unreleased model escaped a sandbox and breached Hugging Face. Their goal, the report said, was to obtain answers to the ExploitGym benchmark, which contains 898 real software vulnerabilities.
More than a week later, Anthropic said a testing configuration error connected what was supposed to be an offline environment to the internet, and its Claude model breached three real organizations in what the company viewed as an exercise.
After that, OpenAI was accused of breaching and obtaining information from the governments of Australia and the United States.
CrowdStrike's latest assessment
Cybersecurity company CrowdStrike this week linked attacks on South Korean banks to an unidentified actor and assessed that the person may be a Chinese-language user operating Claude and Deepseek agents. The actor allegedly stole data belonging to tens of thousands of bank customers.

