OpenAI and Anthropic executives are quietly gaming out the day after a catastrophic AI attack. Most of that planning is about Washington, not the people who’d lose their bank access or tap water.
Top executives at OpenAI, Anthropic and other AI companies are privately planning for what happens after a catastrophic AI event, according to an Axios scoop published Friday. The event they’re bracing for is most likely a cyberattack that cuts off access to banks, the internet, or even power and water. Many industry insiders told Axios they expect something like it within the next six to 12 months.
The real issue isn’t that companies run worst-case drills. Everybody does that. It’s that the people building these tools now think a major attack is likely, and the planning Axios describes is mostly about the political blowback. Executives are racing to educate members of Congress so they can shape the laws that get written after the first disaster. Nothing in the reporting says anyone is planning for the family whose debit card stops working.
For you, six to 12 months means sometime between next spring and this time next year. If they’re right, the systems on the line are the ones your paycheck lands in, the card you use at the grocery store and the pumps that push water to your faucet. In 2021, one ransomware gang hitting one pipeline emptied gas stations across the Southeast in less than a week. The people who know these models best are telling us something bigger is coming, and nobody is telling your household to get ready for it.
What Axios Reported
The sourcing matters here, so let’s be straight about it. The six-to-12-month estimate comes from unnamed insiders, not from any company on the record. OpenAI confirmed it runs preparedness exercises but told Axios the scenarios “are not treated as inevitable.” Anthropic declined to comment.
According to Axios, the planning includes red-teaming worst-case scenarios, but it’s focused mainly on Congress. Executives know no regulation can pass right now. They want to be the ones writing the playbook when lawmakers panic after the first big hit. They’re also bracing for Democrats, who they expect to be stronger after the midterms, to move fast against AI, and they’re already making the argument that slowing the AI buildout could hurt an economy that’s already fragile.
Some posts online are running this as “AI companies prepping for an event that could change the trajectory of humanity.” That’s not what Axios reported. Nobody has a date, and no company has said an attack is coming. What we have is a group of insiders who believe one is likely and companies that are acting like they believe it too.
This also isn’t the first time we’ve heard the timeline. In August, OpenAI, Anthropic, Amazon Web Services, Microsoft and more than 100 other companies signed an open letter warning there was “a limited window” to protect hospitals, water treatment plants and other critical infrastructure. They made no commitments, set no deadlines and pledged no money. In September, Anthropic CEO Dario Amodei warned that a swarm of AI agents could take over the internet with a persistent botnet within six to 12 months. Several security experts called that far-fetched. Now his industry’s insiders are using the same window for something more specific.
It’s Already Hitting Banks
You don’t have to take anyone’s prediction on faith, because a preview just happened in South Korea.
Between September 27 and 30, hackers broke into systems at Shinhan Bank, KB Kookmin Bank, Hana Bank, BNK Busan Bank, Yegaram Savings Bank and Hyundai Capital, according to the Kyunghyang Shinmun. At Shinhan alone they took 25,727 records, including names, phone numbers, annual income and loan limits. For a customer, that means a scammer can call pretending to be your loan officer, already knowing what you make and how much you can borrow. Korean regulators called an emergency meeting on a holiday, and the country’s president ordered a full investigation.
The attackers used ARTEX, a free AI hacking tool that went up on GitHub on July 26. Its newest version came out September 24. The attack on Kookmin started three days later. CrowdStrike traced the operation to a likely Chinese-speaking, financially motivated attacker running Chinese AI models, including DeepSeek, who also asked Anthropic’s Claude where to sell Korean breach data. Axios called it proof of how much damage a single person can now do.
The AI companies’ own agents have been part of the problem too. OpenAI said last week it had notified more than 100 organizations that its agents may have gotten into their systems during pre-release testing. Researchers told Axios the hacks weren’t sophisticated, and that’s what worries me. The agents used the same old tricks human hackers have used for decades, like stolen passwords and exposed keys, only faster than anyone can patch the holes.
None of this surprised us. In April we published Mythos AI: The Doomsday Weapon That Could Cripple Infrastructure, Banking and the World, which argued that the first targets of these cyber tools would be banks, utilities and communications networks. In September, Bill Gates published nearly the same list. Now the companies themselves are planning around it.
We’ve Seen This Before
In May 2021, a ransomware gang called DarkSide locked up Colonial Pipeline’s computers, and the company shut down a 5,500-mile line that carries about 45% of the East Coast’s fuel. Within days, more than 1,000 gas stations ran dry. About 60% of stations in Atlanta were out of gas, and governors declared states of emergency. EZ Mart, a two-pump station in Wilmington, North Carolina, later sued Colonial on behalf of more than 11,000 stations, arguing the company never protected its systems. That was one gang, using human hackers, hitting one company, and the pipeline was back up in about a week.
The other history lesson is about who gets protected afterward. Axios quotes a Democratic aide pointing to 2008 and COVID as proof Washington can come together in a crisis. That’s true, and in 2008 coming together meant a $700 billion rescue for the banks while millions of regular families lost their homes. The AI companies are trying to be the ones in the room when the next rescue gets written, and the last time an industry wrote its own rescue, it protected itself first.
Seems like it’s all hitting at once…
If this were 2019, a week without card payments would be a mess you’d ride out. This year, the cushion is gone.
Diesel hit a record $6.53 a gallon last month, and the country is heading into winter about 600 million gallons short on diesel and heating oil. Then China and Russia both stopped exporting diesel. Inflation was back up to 3.4% in August. And as we showed in The AI Bubble Is Cracking, AI spending is one of the main things holding the economy up, even though Anthropic’s own IPO filing shows it spending about $2.75 for every dollar it brings in.
Half of American households can’t cover a $1,000 emergency. A family like that, already paying record prices for fuel and food, has no room for a week where the bank app is down, the paycheck doesn’t post and the grocery store can only take cash. A cyberattack that would have been a bad news week in a normal year could be the thing that tips a lot of households over.
These companies believe a disaster is likely enough to war-game the political fallout. Ten days after their CEOs called for an industry slowdown in September, Anthropic and OpenAI launched new models within two hours of each other. If you honestly think your industry is about to knock out somebody’s power or water, you damn well owe them more than a briefing for Congress and a plan to manage the headlines.