AI labs are war-gaming the day after a catastrophe. Nobody has published the playbook
Axios reports that OpenAI and Anthropic executives are privately planning the political fallout of a catastrophic AI event. No lab has published a playbook.

Top executives at Anthropic, OpenAI and other AI companies are privately gaming out scenarios for a public and political revolt after a catastrophic AI event, per an Axios scoop published on 9 October under Maria Curi's byline. The event they expect is most likely a cyberattack large enough to cut off financial services, internet connectivity, or power and water. The first case of significant real-world harm, the reasoning goes, would turn an already wary public further against the technology and against the people who run it. OpenAI gave Axios a statement. Anthropic declined to comment.
What the labs are reportedly preparing for
Scenario planning is ordinary. Companies run tabletop exercises, and the Pentagon has war-gamed for decades; Axios makes that point itself. The distinction it draws is the belief behind the planning: many top AI researchers and executives treat a major incident as inevitable rather than hypothetical. The paper's own reporting says industry insiders expect one within six to 12 months.
OpenAI's contribution was a prepared-sounding sentence. "OpenAI conducts preparedness exercises where teams discuss and work through a range of potential scenarios," a spokesperson said. "These scenarios are not treated as inevitable, but are meant to help us prepare for a variety of circumstances." That is a description of a practice, not a document. Anthropic, per Axios, would not engage at all.
What the companies are practising for is mostly rhetorical. The planning is about red-teaming worst-case narratives and racing to educate members of Congress, not about building anything. Executives reportedly accept that regulation cannot pass today, and want to shape the legislation Washington reaches for after a first catastrophic event — on the assumption that Democrats, ascendant after the midterms, will move quickly and be out of their depth.
The blame game, and the campaign it points to
Axios frames the aftermath as a contest over causation. Either a rogue-agent swarm breaks containment from an internal testing environment, or a bad actor finds an unexpected way to use models that are already available. Both are described in the paper's earlier work on rogue agents overwhelming internet defences and on Dario Amodei's botnet warning, which experts promptly called far-fetched.
The concrete example Axios reaches for is the recent campaign against South Korean financial organizations, including reported breaches at two banks. A hacker from China allegedly used China-developed models, DeepSeek among them, to steal data from tens of thousands of bank customers, and used Claude Code to look for places to sell it, according to CrowdStrike. We covered what CrowdStrike actually found here: one operator, ordinary tooling, and scope the vendor could not confirm.
That case is doing a lot of work in the scoop. It is offered as proof that the damage one person can do has changed — which is true — and as the shape of the incident the labs expect next. It is also, notably, an incident where the AI systems behaved as directed. A human chose the targets; the models helped. Nothing in it is a containment failure.
The instruments already proposed
The policy menu Axios surveys splits into the theatrical and the testable. The testable one is a mandated kill switch on advanced AI systems, introduced by Representatives Ted Lieu and Moran, whose bill would require it. Even that has a hole in it: experts have questioned whether every AI system can in fact be turned off. A switch you cannot guarantee is a slogan with a lever attached.
The theatrical end includes proposals to ban superintelligence outright or pause advanced development, which the labs apparently treat as the real risk to their business. Axios also notes the argument that open-weight models can already be downloaded and used to cause harm, a problem most security professionals see as solvable only by deploying AI to fight rogue AI. One Democratic aide told Axios that a genuine crisis would let Washington set partisanship aside, citing COVID and the 2008 financial crisis.
What the reporting does not establish
The piece rests entirely on unnamed officials, and it shows. No lab has published a crisis playbook, a threshold for what counts as the catastrophic event, or a single named scenario. "Inevitable" is a belief attributed to researchers and executives, not a finding, and the six-to-12-month window is a sentiment, not a forecast with parameters anyone can check.
Nothing in the scoop assigns liability. It does not say which lab would be responsible for which failure mode, how a rogue swarm would be traced to its source, or what would happen to a company found negligent — questions that would define the day after far more than any press strategy. Most tellingly, nothing suggests any regulator, legislature or agency is running the same exercise from the other side. If the premise is that an incident will arrive and that Washington will legislate in response, the absence of any parallel government preparation is the more interesting fact.
Even the exercise itself is described second-hand. OpenAI's phrasing is the measure of the evidence: "preparedness exercises" where teams "discuss and work through" scenarios. That may well be exactly what it sounds like. It may also be a communications department preparing an answer for the question, which is not the same thing.
Preparing to explain is not preparing to stop it
The most important qualifier is buried in the framing. What Axios describes is a communications and lobbying plan — education of Congress, shaping of future legislation, management of a public that is already sceptical. That is a plan for what to say. It is not a plan for what to do if a model breaks containment, if a swarm spreads, or if someone needs to shut a system down at three in the morning.
Preparing the message and preparing the response are different disciplines, and only one of them reduces the chance of the event. The labs' evident eagerness to be in the room when the rules are written is understandable, and it is also an admission about priorities: they are planning to win the argument about the failure, not to prevent it. Anthropic spent the same week amending its own usage policy — rule-making on the vendor's own terms, posted on the vendor's own blog, enforceable by the vendor alone.
What would settle it
A published playbook would end most of the speculation, and its absence is the story's central gap. So would a named threshold for the catastrophic event, a scenario with stated assumptions, or evidence that a single lab had rehearsed a real technical response rather than a statement. Failing that, we have executives' beliefs, relayed by unnamed officials, about a crisis they say is coming and a political response they intend to influence.
The likeliest reading is the least dramatic. Labs game out worst cases for the same reason insurers do, because it is cheap and it protects them. The difference worth watching is not that the planning exists. It is that the people doing it believe the incident is coming, are preparing to argue about it, and have published nothing that would let anyone hold them to a specific promise.


