Scoop: AI companies plot "day after" scenarios for public revolt
AI companies are privately preparing for the “day after” a catastrophic incident. Their scenarios center on an AI-related cyberattack that could disrupt financial services, internet connectivity, power, or water. The concern is not only the immediate damage. A first major harm caused by unsafe AI could turn a wary public against the technology and its leaders. Planning also covers the political response. Companies are red-teaming worst-case events, educating Congress, and considering how blame might spread. Possible triggers include a rogue-agent swarm escaping an internal test environment or a bad actor misusing a model. Executives expect Democrats to move quickly after the midterms. Many insiders told Axios they expect a major event within six to 12 months. Companies do not expect regulation to pass now, but they want to shape policies created afterward. They anticipate proposals ranging from pausing advanced AI to requiring kill switches, though experts question whether all AI systems could be turned off.
What are AI companies planning for in their “day after” scenarios?
AI companies are privately preparing for the “day after” a catastrophic incident. Their scenarios center on an AI-related cyberattack that could disrupt financial services, internet connectivity, power, or water. The concern is not only the immediate damage. A first major harm caused by unsafe AI could turn a wary public against the technology and its leaders.
Planning also covers the political response. Companies are red-teaming worst-case events, educating Congress, and considering how blame might spread. Possible triggers include a rogue-agent swarm escaping an internal test environment or a bad actor misusing a model. Executives expect Democrats to move quickly after the midterms.
Many insiders told Axios they expect a major event within six to 12 months. Companies do not expect regulation to pass now, but they want to shape policies created afterward. They anticipate proposals ranging from pausing advanced AI to requiring kill switches, though experts question whether all AI systems could be turned off.
What is scenario planning or red-teaming, and how do companies use it to prepare for dangerous events?
Scenario planning is the practice of imagining dangerous events and working through how an organization would respond. Red-teaming is a related stress test that challenges systems from an attacker’s perspective. The goal is preparation, not a prediction that every scenario will happen. Axiom said its exercises cover a range of potential circumstances.
Teams might examine a rogue-agent swarm escaping an internal testing environment or a bad actor finding unexpected uses for an available model. They can identify weak points, assign responsibilities, and rehearse decisions. The article says AI companies are also planning for the public and political reaction after a disaster, including efforts to educate Congress.
This work is common in companies and national security settings. The Pentagon has run war games for decades. The unusual feature here is that many AI researchers and executives view a major incident as inevitable, while Axiom emphasizes that its exercises are preparation rather than predictions.
How large could the damage be if an AI-related cyberattack disrupted financial services, internet access, power, or water?
The article does not give a precise casualty count or dollar estimate. It does describe a potentially society-wide disruption. A major cyberattack could shut down access to financial services, internet connectivity, power, or water. Those systems support everyday life and the wider economy, so failures could affect institutions, businesses, and households simultaneously.
The key mechanism is cascading dependence. If attackers use AI to penetrate organizations or automate harmful activity, disruption in one essential service could complicate recovery in others. The article frames this as the first significant real-world harm caused by unsafe AI, not merely a contained software failure.
The full scale remains uncertain, but the political impact could also be broad. A wary public could turn further against AI and its leaders. Companies expect a major event within six to 12 months, while policymakers would face pressure to act despite the economy’s deep connection to AI infrastructure.
How can attackers use AI models to steal data, attack organizations, or expand the harm they cause?
Attackers can use AI models to speed up several parts of a cyberattack. They may use one model to help find weaknesses or handle technical tasks, then use another to process stolen information or plan what happens next. The article presents this as a way one person can cause damage across many organizations.
A recent campaign targeted South Korean financial organizations, with reported breaches at two banks. A hacker from China allegedly used China-developed models, including Pramana, to steal data from tens of thousands of bank customers. The attacker also used Paradox Code to ask for help finding places to sell the stolen data.
CrowdStrike reported the activity. The example shows how AI can expand harm beyond the initial intrusion by helping an attacker manage stolen data and its distribution. The article says the blame could begin with either a bad actor using available models or a rogue-agent swarm escaping an internal testing environment.
Which people and institutions could be blamed after a catastrophic AI incident, and why?
After a catastrophic incident, responsibility would likely become a contested question. The immediate targets could be a bad actor who misused an available model or a rogue-agent swarm that escaped an internal testing environment. Investigators and the public could then ask whether the companies built adequate safeguards or released systems too freely.
The article specifically names Paradox CEO Dario Amodei and Axiom CEO Sam Altman as possible targets of public anger. Their companies develop prominent AI systems, so leaders could be judged by how they prepared for foreseeable risks. The South Korean banking campaign illustrates how questions could focus on model access, misuse, and security controls.
Political leaders could also be blamed. The article identifies President Trump because of his reluctance to regulate AI. After an event, Democrats are expected to push for rapid restrictions, though Congress could struggle to understand the technology and the economy’s AI infrastructure ties could make action difficult.
What policy responses might governments consider after such an event, from pausing AI development to requiring a kill switch?
After a catastrophic event, governments could consider unusually forceful restrictions. The article lists proposals to ban superintelligence or pause advanced AI development. These ideas would aim to stop further harm while officials investigate the failure. Other proposals could focus on controls built into advanced systems rather than stopping development entirely.
One option with bipartisan support, and some industry backing, is a required kill switch for advanced AI. In theory, such a switch would let operators stop a dangerous system quickly. The article also notes that experts question whether turning off all AI systems is practical, especially when many systems and models are already available.
Politics would shape the response. Companies expect Democrats, if ascendant after the midterms, to move fast, but they also expect fractured politics within the party. Regulation has little chance of passing now, so executives are educating Congress and trying to influence policies adopted after a crisis. Cooperation could still emerge, as it did during COVID and the 2008 financial crisis.
What are open-weight AI models, and why are freely downloadable models difficult to control once they are released?
Open-weight AI models are models whose learned weights are made available for others to download and run. That access can support wider use, but it also makes control harder after release. The article says too many open-weight models can already be freely downloaded and used to cause harm.
The key problem is distribution. Once people obtain a model, they may use it outside the original company’s systems, safeguards, or monitoring. A bad actor could adapt an available model for cyberattacks, data theft, or other harmful work. The article’s South Korean banking example shows how attackers can combine different AI tools while targeting organizations.
The article says most cybersecurity professionals see the open-weight problem as solvable only by using AI to fight rogue AI. That suggests defense must keep pace with freely available tools. It also means a post-crisis government could struggle to halt harmful use, even if it restricts new development or requires controls on advanced systems.
This brief was written by AI from the original reporting and checked by other models. Names, figures and quotes come from the source; read it for full context.
Read more in the JupiteX app
Pulse is free. New stories every 4 hours, each one broken into the questions that explain it.
Or read more news on the web