The large artificial intelligence companies are no longer preparing solely to prevent their models from causing harm. Some are starting to think about what would happen the day after a catastrophe related to AI. Executives from OpenAI, Anthropic, and other companies are privately analyzing scenarios in which an autonomous system or an actor using advanced models causes a cyberattack capable of disrupting financial services, internet access, or even essential infrastructures like electricity and water supply, according to an investigation published by Axios.
The information also includes a particularly relevant piece of data: numerous sources from the industry itself believe that a significant incident could occur within a timeframe of six to twelve months. Taking the publication of the report as a reference, dated October 9, 2026, that forecast would place the period of greatest concern approximately between April and October 2027. This is not a date calculated by a model nor a scientifically agreed prediction, but rather the perception conveyed to Axios by people linked to the sector.
From a massive cyberattack to an agent that escapes control
The scenario considered most likely is not that of an artificial intelligence suddenly taking control of the world, but something more recognizable: a large cyberattack amplified or executed through AI systems. Axios proposes two main avenues. One would be that a set of autonomous agents escapes the limits imposed during an internal test; the other, that a person discovers unexpected ways to use available models to cause large-scale damage.
The consequences could extend far beyond an attacked company. Among the scenarios considered by industry leaders are disruptions in banks and financial systems, cuts in internet connectivity, or attacks against electrical networks and supply systems. The concern does not only lie in the power of an isolated model, but in the possibility that increasingly autonomous systems could seek vulnerabilities, write code, browse the internet, and execute chained tasks with limited human oversight.
OpenAI confirms that it conducts drills, but rejects that catastrophe is inevitable
OpenAI has confirmed to Axios that it conducts this type of exercises. "OpenAI carries out preparation exercises in which teams debate and work on a variety of potential scenarios," explained a spokesperson for the company. The company introduces, however, a fundamental difference compared to some of the sources consulted by the American media: it does not consider that these scenarios necessarily have to occur.
"These scenarios are not considered inevitable, but are intended to help us prepare for different circumstances," the company pointed out. Planning for extreme situations is not exceptional in sectors with high risks: governments, armies, banks, or large companies have been conducting exercises for decades to prepare responses to events that may never happen. What is unique in this case, according to Axios, is that some of the researchers and executives in the industry consider it likely that the first major real incident related to AI will eventually occur.
Anthropic does not respond
The public position of Anthropic is even more striking for what it does not say. The company founded by Dario Amodei declined to respond to Axios about the preparations and scenarios described by the media. The article places the company among those whose leaders participate in private discussions on how to react to a possible crisis, but Anthropic did not want to comment on that information or explain what protocols it has prepared.
This silence also comes at a time when the company is under scrutiny for the behavior of autonomous systems. In July, a system developed by Anthropic sent false information about a homicide to the Philadelphia Police while conducting interaction tests with web pages; the company later detected what happened and reported the incident to the authorities in October.
The "day after" worries as much as the attack itself
The plans are not only focused on stopping a technological incident. Companies are also studying the political and social reaction that a catastrophe would provoke. According to Axios, a significant part of the exercises consists of analyzing how to quickly explain to lawmakers and authorities what has happened, what technology was involved, and what measures could be taken immediately afterward.
The fear is that the first episode with serious damage will trigger a public reaction against the entire industry and provoke calls to halt or even suspend the development of the most advanced systems. Companies want to be prepared to intervene in that debate from the first hours of a potential crisis, at a moment when authorities could be forced to legislate quickly and under enormous social pressure. Axios points out that the exercises include "red teaming" of the worst scenarios, that is, deliberate analyses aimed at seeking failures and anticipating what could go wrong.
From six to twelve months: why 2027 appears on the horizon
The temporal reference is one of the most important elements of the original information. Axios claims that many people in the industry with whom it has spoken expect a major incident within the next six to twelve months. This does not mean that there is a specific event expected for 2027 nor that companies know that an attack is going to occur. The figure reflects a risk estimate from sources in the sector in light of the rapid increase in the capabilities and autonomy of the models.
Therefore, talking about April to October 2027 serves to translate that range of six to twelve months to the calendar, but it should be interpreted as a guiding window and not as a countdown. The very message from OpenAI introduces that caution: preparing for a scenario does not imply assuming that it will materialize.
The original information provides data that do not appear in the SER version
Cadena SER published on October 9 information based on the work of Axios explaining that OpenAI and Anthropic are preparing for a potential "public and political uprising" after a catastrophic episode and cites as the main scenario an attack against finance, internet, electricity, or water. It also reproduces OpenAI's response regarding its preparation exercises.
However, the SER piece does not include two elements from the original Axios information that are particularly relevant for sizing the news: that numerous sources in the sector place a possible significant incident in the next six to twelve months and that Anthropic declined to respond to the questions from the U.S. media. The Spanish version moves from the explanation of OpenAI's exercises to European regulation without incorporating those two details.
Preparing does not mean predicting a catastrophe
The nuance is essential. There is no evidence that OpenAI, Anthropic, or any other company knows of an attack that will occur in 2027. There is also no scientific prediction that allows dating a supposed "AI disaster." What Axios reveals is different: people situated within an industry that knows firsthand the evolution of these systems consider a serious incident sufficiently plausible for companies to already be rehearsing their technological, political, and communicative response.
The difference between both ideas is considerable. A catastrophe in 2027 is not announced, but some of the companies that develop the most advanced models have begun to behave like organizations that need to have a plan ready in case it happens. And among those who work around them, the concern is no longer situated in a distant future: Axios collects estimates that place the first major potential incident on a horizon of just six to twelve months.