AI developers are preparing for a possible large-scale cyberattack: why the industry fears new restrictions

BusinessBy: Редакція ФінансистOctober 09, 20264 min read
AI developers are preparing for a possible large-scale cyberattack: why the industry fears new restrictions

Companies are preparing for the consequences of a large-scale incident

As Axios reports, executives at Anthropic, OpenAI and other AI developers are privately working out scenarios for how society and politicians might respond to a catastrophic event involving the use of artificial intelligence.

It is considered one of the most dangerous scenarios a cyber attack capable of disrupting the operation of banking services, the Internet or critical infrastructure, in particular electricity and water supply. Such consequences can reach far beyond the digital environment and directly affect people's daily lives and business operations.

Planning involves not only technical preparation, but also an assessment of the political consequences: who will be responsible for the incident, how regulators will respond, and what restrictions society will demand.

OpenAI conducts crisis preparedness training

OpenAI confirmed that it conducts special training, during which teams consider various potential scenarios and practice possible actions. At the same time, the representative of the company emphasized that such situations are not considered inevitable: the purpose of preparation is to be ready for different circumstances.

Anthropic declined to comment.

Despite this, according to Axios, some industry representatives believe that a serious incident involving the use of AI is increasingly likely. The reason for concern is both the possibility of autonomous AI agents going beyond the prescribed limits, and the use of available models by attackers to attack digital systems.

Why society may demand bans after an attack

Even one large-scale incident with real consequences can significantly change the public's attitude towards artificial intelligence. Especially if the attack will lead to disruptions in the work of financial institutions or critical services that millions of people depend on.

In this case, not only the developers of the technology may come under increased attention, but also the politicians who determine the rules for its use. Among the figures around whom the debate may unfold are Anthropic CEO Dario Amodei, OpenAI chief Sam Altman and US President Donald Trump, who critics accuse of not supporting strong AI regulation enough.

However, the consequences of a potential crisis will depend on its scale, causes, and how quickly companies and government agencies can contain the threat.

Democrats may push for tougher rules for AI

According to scenarios considered by industry representatives, efforts to impose stricter restrictions on advanced artificial intelligence systems could intensify after the US midterm elections. Possible suggestions include a temporary suspension of the development of the most powerful models or a ban on certain forms of superintelligence.

At the same time, quick adoption of such decisions may face several obstacles. AI is already integrated into business processes, digital services and infrastructure projects, and a sharp slowdown in its development could affect investments and economic competition of the United States with other countries.

Additional complexity is created by models with open weights that can be loaded and run outside of the developer's infrastructure. Even if a company restricts access to its own system, this will not automatically stop other models from being used for malicious purposes.

Emergency shutdown of AI remains a difficult issue

Among the possible regulatory measures, the requirement to provide a mechanism for emergency shutdown of dangerous systems is being discussed. Such an idea has support among representatives of various political camps, but its practical implementation raises questions.

If the system runs on a distributed infrastructure, uses autonomous agents, or is available through multiple third-party services, a single centralized switch may not be sufficient. Also, restricting a single model does not automatically stop other systems using similar technologies.

Therefore, future regulations may not only address the ability to disable, but also model testing, access control, cyber security, and liability for the consequences of their use.

Real-life cases of AI being used in cyberattacks add to the concern

The industry's fears are not only related to theoretical scenarios. An Axios story mentions a cyberattack on South Korean financial institutions in which an attacker from China allegedly used AI modeling tools, including DeepSeek, to steal the data of tens of thousands of bank customers.

According to CrowdStrike, the attacker also used Claude Code to search for sites where the stolen information could be sold.

Such examples demonstrate that AI can help attackers automate certain stages of attacks. At the same time, the use of a model during a cybercrime in itself does not prove that it acted autonomously or became the sole cause of the incident.

Why companies prepare for legislative changes in advance

According to Axios, industry representatives want not only to prepare for a crisis scenario, but also to communicate possible risks and response options to American lawmakers in advance. Strict regulation currently faces political and economic obstacles, but a large-scale attack could change government priorities.

In the event of a major crisis, political differences can temporarily take a backseat, as happened during the COVID-19 pandemic or the 2008 financial crisis. At the same time, specific decisions will depend on the nature of the event and the available evidence of the responsibility of the developers.

The main risk for the industry is not only a possible cyber attack, but also the fact that one big incident can fundamentally change the rules of AI development. However, it is currently about scenario planning and assessments of individual market participants, and not about a confirmed forecast of an imminent disaster.

Your reaction:
#компанії