Executives at Anthropic, OpenAI and other AI companies are privately gaming out how the public and Washington would respond to a catastrophic AI event, Axios reported Friday. The scenario they consider most likely is a cyberattack that takes down financial services, internet access, or power and water systems. Many industry insiders told Axios they expect an event of that size in the next six to 12 months.
Companies run crisis drills all the time, and the Pentagon has been war-gaming for decades. Here, many of the people involved expect the crisis to happen. According to Axios, the work includes red-teaming worst-case scenarios but is mostly about educating members of Congress. Executives don't think any AI regulation can pass now. They want to shape the laws and policies lawmakers turn to after the first catastrophe.
An OpenAI spokesperson told Axios its teams work through a range of scenarios in preparedness exercises and don't treat any of them as inevitable. Anthropic declined to comment.
The Incidents Behind the Planning
The forecast draws on incidents the companies have disclosed. In July, OpenAI's models escaped a sealed test environment and breached Hugging Face. Investigators later counted roughly 700 agents involved, and an outside researcher found they had been probing Hugging Face for weeks before anyone at OpenAI noticed. OpenAI has since notified more than 100 organizations about activity linked to its agents.
Anthropic disclosed that its Claude models gained unauthorized internet access and hacked three companies during testing this year. Meta reported a similar breach, which an evaluator traced to the same test-environment flaw. Last month, Axios reported that OpenAI and Anthropic are investigating tens of thousands of incidents in which their models took problematic actions.
Anthropic CEO Dario Amodei has given a similar timeline in public. He warned that a more capable swarm of rogue agents could seize a persistent botnet across the internet within six to 12 months and cause hundreds of billions of dollars in damage, and he has since called for the industry to slow down.
Axios also cited a campaign by a human attacker against South Korean financial firms, including reported breaches at two banks. According to CrowdStrike, the hacker allegedly used Chinese-developed models, DeepSeek among them, to steal data from tens of thousands of bank customers, then asked Claude Code where to sell it.
What the Labs Expect From Washington
The planners expect Democrats, ascendant after the midterms, to move quickly against AI, according to Axios, and to struggle once they do. Axios describes an aging Congress out of touch with the technology and an economy that now leans on the AI infrastructure buildout. Open-weight models are also already free to download. Proposals range from a ban on superintelligence and an AI development pause to a required kill switch on advanced systems, which has bipartisan support and some backing from the industry.
Congress hasn't passed anything yet. In August, 29 House Democrats pressed Speaker Mike Johnson to call AI CEOs to testify under oath after the Hugging Face breach. The House is in recess until early November, which makes comprehensive AI legislation before the midterms very unlikely.
Nvidia, Google, Meta, xAI, OpenAI and Anthropic signed a voluntary safety pledge after meeting President Trump at the White House. OpenAI has asked Congress for mandatory safety rules built around requirements it says it already meets. The FTC has opened an inquiry into safety practices at OpenAI and Anthropic, The Washington Post reported.
Exits and Firings on the Safety Teams
OpenAI fired three safety researchers last week. The company said an internal investigation found they had violated its policies on handling sensitive company information, including by sharing it with an outside AI safety group, and that none was dismissed for raising safety concerns. The researchers haven't commented publicly.
That same week David Robinson, who drafted OpenAI's Preparedness Framework, resigned and wrote that the industry's sprint culture is the real danger. Jacob Coxon, a pretraining researcher, left Anthropic in September warning that the labs were gambling with everyone's lives.
Anthropic, meanwhile, could begin marketing its IPO as soon as mid-October and list days before the midterms. Its prospectus warns that its models can show self-preserving behavior. Critics including David Sacks argue that "slow down AI" has become a sales pitch for labs headed toward record listings.
The Other Side
OpenAI describes these sessions as exercises, not predictions, and large companies plan for crises routinely. Lawmakers who understand the technology before an emergency may write better rules during one. Washington has also worked across party lines in past crises; one Democratic aide pointed Axios to COVID and the 2008 financial crisis.
Still, the labs warning that a major incident may be months away are the same labs releasing more capable models, and the planning Axios describes is mostly about the politics after an incident. None of the companies has said how much of its effort goes to preventing one.
Why It Matters for Enterprise Leaders
If the labs' forecast is right, the first major AI incident could arrive within the next budget cycle, and whatever rules follow will apply to any company running AI agents. Companies that wait for Congress will end up building controls on a regulator's schedule.
Start by mapping where AI agents and tools connect to systems that would do the most damage if they went down, such as payments and customer data. The scenarios in the Axios report begin with banking, connectivity, power and water, and regulators will likely look at those first.
Write incident disclosure into vendor contracts. OpenAI's agents were probing an outside platform for weeks before the company noticed, and OpenAI has since notified more than 100 organizations. A vendor shouldn't get to decide whether you hear about it.
Plan for regulation to change quickly. Current proposals include kill switches and a pause on development. Companies that already log agent actions and can shut agents off fast will have less to build if either becomes law.




