AI Companies Prepare For Major Infrastructure Attacks
Leaders from OpenAI, Anthropic, and other tech companies privately simulate their response to a disaster caused or amplified by artificial intelligence. These exercises notably focus on a cyberattack against banks, the Internet, or energy networks, but no incident of this scale has occurred.

In brief
- OpenAI and Anthropic anticipate a major AI-related crisis through simulations of potential disasters.
- Scenarios considered include cyberattacks on banks, the Internet, and critical infrastructure.
- Advances in AI cybersecurity increase concerns about offensive capabilities of advanced models.
- Companies prepare their political response to manage government and U.S. Congress reactions.
- Incident management still largely relies on voluntary commitments despite sector coordination efforts.
Companies simulate multiple AI disaster scenarios
These exercises first anticipate the political and social consequences of a major attack. Participants seek to determine how to contain the incident, quickly inform the government, and respond to requests to suspend the affected systems.
The existence of these preparations mainly relies on an Axios report based on anonymous internal sources. OpenAI confirms organizing exercises but does not acknowledge the existence of a formal joint program with Anthropic or a timetable announcing a disaster.
The main scenarios mentioned include :
- A cyberattack capable of disrupting banks or payments ;
- A massive interruption of Internet access ;
- An attack on electricity or water supply networks ;
- The criminal use of downloadable models ;
- Loss of control of an experimental system with high autonomy ;
- A political reaction leading to rapid AI restrictions.
OpenAI claims to conduct “preparedness exercises during which teams discuss and work on various potential scenarios”. The company specifies however that these events “are not considered inevitable”. Anthropic has not commented on this information.
Cyber risk becomes more concrete for OpenAI
The preparation does not only respond to theoretical threats. Recent models advance in vulnerability research, autonomous programming, and executing multiple steps without constant human intervention.
OpenAI has thus classified Astra at a “critical” level for its cybersecurity capabilities. According to its internal assessments, this model can, with the right tools and access, discover unknown flaws and then design methods to exploit them in highly protected systems.
This classification does not mean Astra has carried out a real attack. It indicates that its capabilities cross a threshold that requires enhanced protections before deployment. OpenAI says it delayed some development phases to test these measures.
The same technology can help defenders detect and fix vulnerabilities faster. The risk comes from its dual nature: skills useful for defensive cybersecurity can also reduce the time, cost, and expertise needed to launch an attack.
Some industry officials cited anonymously believe a serious incident could occur within the next six to twelve months. This assessment remains an individual expectation, not a confirmed forecast by OpenAI or Anthropic.
Also preparing the U.S. Congress’s response
Simulations would also cover the first hours after an incident. Companies want to quickly present to elected officials the cause of the attack, using on-chain data, the exact role of the model, and necessary measures to contain the damage.
This preparation addresses a political difficulty. After a disaster, Congress might be pressured to act even before technical responsibilities are fully established. A general ban, suspension of some models, or new control obligations could then be proposed.
Companies thus seek to prepare documents, interlocutors, and escalation procedures. They also want to avoid that criminal use of a third-party model be automatically attributed to the developer or equated with a loss of internal control.
This approach involves an obvious conflict of interest. Companies developing the concerned systems also want to influence rules adopted after a potential AI-related accident. Their preparation can improve the response, but it does not replace an independent investigation or public oversight.
Incident response remains largely voluntary
The Frontier Model Forum notably brings together Anthropic, Amazon, Google DeepMind, Meta, Microsoft, and OpenAI. Its members signed a voluntary agreement in 2025 to exchange information about vulnerabilities, threats, and capabilities likely to cause serious harm.
The Forum distinguishes three mechanisms. Information sharing occurs before a crisis. AI-incident reporting notifies an authority after a defined event. Operational response then aims to contain damage and restore systems.
These mechanisms are still under development. Anthropic applies its own Responsible Scaling Policy, while OpenAI uses a preparedness framework covering cyber, biological, chemical, manipulation, and loss-of-control risks.
These internal policies may impose evaluations, launch delays, or additional protections. However, they remain partly voluntary and vary between companies. The reported exercises thus do not demonstrate that OpenAI and Anthropic expect a specific disaster. They rather show that labs now consider a major crisis sufficiently plausible to prepare their technical, political, and media response.
Maximize your Cointribune experience with our "Read to Earn" program! For every article you read, earn points and access exclusive rewards. Sign up now and start earning benefits.
Diplômé de Sciences Po Toulouse et titulaire d'une certification consultant blockchain délivrée par Alyra, j'ai rejoint l'aventure Cointribune en 2019. Convaincu du potentiel de la blockchain pour transformer de nombreux secteurs de l'économie, j'ai pris l'engagement de sensibiliser et d'informer le grand public sur cet écosystème en constante évolution. Mon objectif est de permettre à chacun de mieux comprendre la blockchain et de saisir les opportunités qu'elle offre. Je m'efforce chaque jour de fournir une analyse objective de l'actualité, de décrypter les tendances du marché, de relayer les dernières innovations technologiques et de mettre en perspective les enjeux économiques et sociétaux de cette révolution en marche.
The views, thoughts, and opinions expressed in this article belong solely to the author, and should not be taken as investment advice. Do your own research before taking any investment decisions.