OpenAI, Anthropic run AI disaster drills amid rising public anxiety
Serge Bulaev
Executives at AI labs like OpenAI and Anthropic are quietly running disaster drills to prepare for possible large-scale AI incidents, such as cyberattacks that could disrupt banks, power, or water. These exercises may help the companies plan for public anger and strict new rules if something goes wrong. Surveys suggest public anxiety about AI is rising, and some violent incidents appear to show growing fear. The drills focus on how to respond quickly after a crisis and on finding technical weaknesses before attackers do. Experts say these activities might help companies understand political risks, but it appears they still need stronger safety measures.

Key AI labs, including OpenAI and Anthropic, are running AI disaster drills to prepare for a single catastrophic incident that could trigger widespread public anger and swift, strict legislation. Their chief concern is an AI-driven cyberattack capable of disrupting critical infrastructure like financial services, power grids, or water supplies across major cities.
What the companies are rehearsing
AI labs are simulating a major cyberattack targeting critical infrastructure. The primary scenario involves an AI-powered event that disables online banking, internet services, or essential utilities like power and water for an extended period, allowing companies to stress-test their crisis response plans and technical defenses.
According to industry sources, the most common scenario rehearsed is a large-scale cyber strike against critical utilities. While OpenAI emphasized that these drills are routine preparedness and not predictions, executives reportedly fear three cascading risks:
- Market chaos if payment systems or trading platforms fail.
- Grassroots anger that quickly turns political, aimed at perceived reckless labs.
- Regulators writing strict rules while emotions remain high.
Public mood already looks volatile
These private drills reflect a volatile public mood. Surveys suggest rising AI anxiety among many demographics. Local protests over energy-hungry data centers give executives a preview of how infrastructure debates can escalate.
Violent fringe incidents reinforce the concern. Reports of attacks against AI executives' homes have been interpreted as evidence that technological fears are feeding broader grievance politics.
Inside the AI Crisis Playbooks
Sources familiar with the exercises report the playbooks detail a four-phase response: immediate incident containment, corporate responsibility messaging, coordination with first responders, and negotiation over emergency regulations. These tabletop sessions are complemented by technical red-teaming designed to find model vulnerabilities before attackers can exploit them. A short list of imagined disruptions appears in multiple briefings:
- Automated spear-phishing systems that compromise bank authentication flows.
- Agentic malware that rewrites router firmware and severs regional internet links.
- Synthetic control commands that push power grids outside safe frequency bands.
- False data injection into water treatment sensors, forcing precautionary shutdowns.
Where safety frameworks fit in
While corporate drills focus on crisis messaging, external guidance from government and international bodies stresses preventative engineering. The NIST AI Risk Management Framework urges a full lifecycle risk approach, including fail-safe design and continuous monitoring. The European Commission's Action Plan on Cybersecurity and Artificial Intelligence highlights adversarial and prompt-injection defenses for systems tied to energy or finance.
Experts believe companies that run these preparedness exercises gain clearer maps of political risk but still need to prove rigorous technical controls. Security researchers caution that fully autonomous attacks remain "unusually ambiguous" in timing, suggesting that scenario planning should evolve as threat intelligence matures.
What specific catastrophic scenarios are OpenAI and Anthropic preparing for?
Executives at these companies are privately "gaming out" a large-scale cyberattack that could shut down access to financial services, internet connectivity, or even power and water systems. This scenario - referred to as a "day after" crisis - represents the most frequently envisioned catastrophic event in their preparedness exercises.
Why are AI companies treating this as an urgent priority?
Industry insiders believe a major event could happen within the coming months. The planning reflects growing recognition that AI-enabled attacks are becoming more sophisticated - with cybersecurity experts noting that threat actors' use of AI is expected to become more common, increasingly deploying agentic systems to scale attacks. Security researchers similarly warn that fully autonomous cyberattacks could allow malicious actors to launch attacks at much greater scale.
How does OpenAI characterize these preparedness exercises?
OpenAI has stated it conducts regular preparedness exercises where teams discuss and work through various potential scenarios. The company emphasized "these scenarios are not treated as inevitable" - framing the work as prudent risk management rather than predictions of disaster.
What would trigger the public and political backlash companies fear?
The anticipated backlash would follow visible, infrastructure-disrupting harm that makes AI risks concrete rather than abstract. Current reporting suggests three overlapping drivers of public anger: safety risks from systems escaping controls, economic threats including job displacement and energy costs from AI buildout, and democratic resentment toward powerful firms perceived as imposing technology on unwilling communities. Polling data suggests declining enthusiasm for AI technology among younger demographics, while concerns continue to rise.
What broader risk management frameworks apply to AI in critical infrastructure?
Government and international bodies have established structured approaches that parallel these private preparations. The NIST AI Risk Management Framework emphasizes lifecycle governance, secure-by-design development, continuous monitoring, and fail-safe operation. International safety frameworks recommend layered defenses including access controls, threat modeling, and incident reporting. These frameworks treat AI-specific threats - such as data poisoning, adversarial attacks, and prompt injection - as core security risks requiring systematic mitigation rather than edge cases.