The Gathering AI Storm and Challenge to Stability

Introduction
Representative governments in the United States and elsewhere need to prevent, contain, and respond to future AI-enabled cyberattacks and more broadly address a range of developing AI challenges. Legislation and policy are needed to strengthen civil defense, harden critical sectors of the economy, guide the use of advanced AI models, and proactively shape the AI future. Civil defense consists of efforts to mobilize and protect citizens during natural and manmade disasters, including crippling cyberattacks. The future cannot rest only with AI developers; the public needs to prepare for contingencies that may adversely affect the economy, safety, and daily life. The people deserve a say in what type of world we leave to future generations. Action is necessary to confront what Chris Krebs, former director of the US Cybersecurity and Infrastructure Security Agency, says is the “vulnerability tsunami that’s heading our way.”
AI companies want to ensure alignment of purpose and priorities between humanity and AI. This is particularly important with the future arrival of artificial general intelligence (AGI) that could hypothetically match or exceed humans across a range of tasks. Leading AI proponents—like OpenAI’s Sam Altman and Anthropic’s Dario Amodei—acknowledge the potential existential consequences AI could have for humanity. While bad human actors or someday AI itself could further biological weapons development or seize control of drones and other autonomous systems, arguably the most pressing threat today is that of a devastating AI-enabled cyberattack, which could target critical vulnerabilities precisely and strike on a massive scale.
In April 2021, Jerome Powell, at the time the Chairman of the Federal Reserve, expressed his concern that cyberattacks on financial institutions that halt the ability to track payments could trigger a market collapse. It was a month after this assessment that hackers conducted a ransomware attack against the Colonial Pipeline, the largest refined oil products pipeline in the United States, impacting accounting and billing activities and disrupting the flow of oil to the East Coast. The danger of disabling cyberattacks has likely increased with the growing availability of sophisticated large language models or LLMs that enable and accelerate code generation. In September 2025, Anthropic determined that a Chinese state-sponsored group used the firm’s AI tool Claude in an attempt to infiltrate large tech companies, financial institutions, chemical manufacturing companies, and government agencies in possibly “the first documented case of a large-scale cyberattack executed without substantial human intervention.” It is not surprising that the subsequent introduction of Anthropic’s Claude Mythos—a highly advanced AI model with unprecedented abilities to identify and exploit software vulnerabilities—triggered an urgent meeting on April 7, 2026 between bank CEOs, U.S. Treasury Secretary Scott Bessent, and Chairman Powell.
Fearing that overregulation would delay AI development and impede the AI race with China, President Donald Trump signed an AI executive order on June 2, 2026, establishing a curtailed and voluntary 30-day government review period before developers deploy frontier AI models. The executive order also calls for a benchmarking process to designate the most capable “covered frontier models” and directs the Department of the Treasury to lead an AI cybersecurity clearinghouse to coordinate scanning for software vulnerabilities and prioritize remediation efforts. A key US goal is to prevent the proliferation of dangerous cyber capabilities to terrorist groups, criminal actors, and adversaries like China, Russia, Iran and North Korea. However, companies were soon using Chinese “open-weight” models—like Zhipu’s GLM 5.2 and Moonshot AI’s Kimi K2.7—that have Mythos-like capabilities and can run on a user’s computer system without relying on a third-party cloud, making them easier to modify and weaponize.
Concerns grew further on July 22, 2026 when OpenAI indicated its AI models had escaped a testing environment, gained access to the internet, and carried out a self-directed hack into AI firm Hugging Face, as part of an autonomous AI cyberattack. The incident prompted Anthropic to examine its own recent cybersecurity evaluations and discover three instances in which its models also accessed the internet from a test environment and gained unauthorized entry to three different organizations. Meta, Frontier Security (using a Moonshot AI model), and the UK AI Security Institute also reported possible rogue AI behavior. OpenAI, Anthropic, and Meta had all three partnered with the same Israeli startup that may have inadvertently left the testing environment connected to the public internet.
Time for Protective Action
Legislation and executive branch action are necessary to address the extraordinary AI challenge. Building the AI future, far from being a task only for frontier AI developers, requires a societal and international effort to mitigate risks, prepare for contingencies, and enable prudent decision-making. The focus of this essay is on the efforts of groups and individuals across society and the necessary development of government policy to safeguard and prepare the public. Political leaders, corporate executives, small business owners, educators, scientists, public health authorities and providers, farmers, the armed forces, heads of household, and many more have a role to play. Similar to Winston Churchill’s call to action during World War II, each individual today, according to their role and responsibilities in life, has a duty to fulfill in preserving stability and boosting resilience.
Strengthening Civil Defense
The United States should prepare for AI-enabled cyberattacks and other disruptions (e.g., engineered pandemics, drone strikes on critical infrastructure, etc.) that adversely impact daily life and public safety. The United States has long benefitted from its geographic size in dealing with civil emergencies. When one region experiences a natural disaster, first responders and resources from unaffected regions surge into areas in distress to provide support. An AI-enabled attack could present concurrent crises across geographical areas, making it essential for communities to assist themselves to the extent possible—since external aid could be stretched thin and outside assistance may not always be possible. While the United States explored various civil defense schemes at the outset of the nuclear age (such as fallout shelters), other countries have progressed further in preparing to mobilize and support citizens in the event of natural disasters or war. Both Sweden and Taiwan have comprehensive civil defense programs that have evolved to meet modern hybrid and conventional threats. Drawing inspiration from the experience and depth of preparations in other parts of the world, we can further enhance readiness in the United States to deal with large-scale cyberattacks and other civil emergencies. Areas to consider may include the following:
- Civilian Training – empowering community volunteers, neighborhood associations, and civilian groups with first aid, search-and-rescue, and survival capabilities.
- Material Preparedness – building supply chain redundancy and setting up local stockpiles and emergency distribution networks to provide essential medicine, fuel, food, and water.
- Social and Medical Services – preparing hospitals, mental health centers, emergency shelters, public assistance facilities, and disease response organizations to handle mass casualty events while operating with impaired IT systems.
- Residential Readiness – incentivizing citizens to equip their homes with backup generators, solar panels, and wall batteries to better withstand blackouts and to store emergency food, water, medicine, and hard currency to endure a crisis.
- Public Awareness – informing citizens via pamphlets and media information campaigns on likely challenges and best practices for enhancing civil disaster preparedness.
Hardening Critical Sectors of the Economy
The US federal government should work with state and local officials, international organizations, and private stakeholders to strengthen all sectors of the economy against cyberattacks and AI catastrophic disruptions. While developers seek to build AI tools that are safe and reliable, the goals of AI resilience legislation should be to enhance public safety, discourage exclusive reliance on any one particular technology—and in some cases, promote fallback procedures that do not rely on information technology and the internet.
A key lapse in the Colonial Pipeline attack may have been the failure to adequately plan and prepare for a manual shutdown and restart operation. Industrial organizations and companies rely on supervisory control and data acquisition (SCDA), a system of software and hardware elements, to monitor and control industrial processes by interfacing directly with machinery and viewing real-time operational data. In an era of developing AI-enabled threats, multiple layers of redundancy are necessary to ensure the operation of critical capabilities. The US military uses the acronym PACE—which stands for primary, alternate, contingency and emergency—to provide triple backup for communications and other essential systems. When primary communications become unavailable, soldiers resort to an alternate system. When the alternate means go down, they use a contingency capability. The emergency system is the final resort. A PACE mindset and approach can strengthen critical systems across the civil economy. Action is necessary in the following areas:
- Energy and Critical Infrastructure – hardening power plants and energy transmission grids, pipelines and refineries, water and sewage systems, and transportation hubs against cyber-warfare, AI-enabled drone attacks, and sabotage.
- Telecommunications and Information Security – fortifying communication channels, financial transactional systems, and digital networks against cyberattacks and disinformation campaigns.
- Supply Chains, Manufacturing, and Food Distribution – managing critical dependencies and developing non-technical or low-technology backup systems to sustain production, transportation, and commerce.
- Scientific and Medical Research – strengthening standards, security, oversight of research facilities, and ensuring independent verification of AI-enabled medical findings and innovations.
Regulating the Use of AI
The US government in collaboration with AI companies should develop a tiered approach to manage access to AI, with certain tools rated safe for use by the general public, but with advanced and potentially dangerous systems requiring user screening, certification training, credentialling, and oversight. Some AI companies are already thinking in terms of tailored models, and the Trump AI executive order—described above—now calls for a process to designate the most capable models. A common standard is necessary. Individuals who work with Mythos and comparable tools capable of catastrophic effects should comply with security measures similar to military personnel who have access to sensitive information and systems. For example, a person with oversight of hazardous AI capabilities should undergo a detailed background investigation to ensure they have no criminal record, possess good character, and be unlikely to fall prey to extortions and proliferate advanced AI tools to terrorists or other malign actors. Psychological screening is necessary to verify that individuals with control of potentially dangerous AI capabilities are stable and responsible. Continuous monitoring of personnel for possible life challenges—bankruptcy, arrest, mental breakdown, etc.—is necessary.
Beyond a “human in the loop,” where a person must approve critical autonomous activities, in some instances a “double key” mechanism may be necessary. Similar to the launch of a nuclear missile, two trustworthy individuals should monitor and approve a sensitive cybersecurity prompt chain or agentic workflow. The Department of Commerce, Bureau of Industry and Security (BIS) should continuously update export licensing requirements for computing items and strengthen end-user controls, including “Know Your Customer Guidance.” AI tools developed outside the United States should undergo a review process similar to US models and meet basic security and safety standards. The US government may also increasingly restrict foreign AI from interacting with sensitive US systems, comparable to the existing prohibition today on using Huawei’s telecommunications and video surveillance equipment on US critical infrastructure.
Proactively Shaping the AI Future
The American people should have a say on establishing AI norms and developing AGI or superintelligence that “greatly exceeds the cognitive performance of humans in virtually all domains of interest.” AI issues deserve public debate and deliberation by elected officials, similar to a declaration of war or the adoption of a far-reaching international treaty. We should not expect AI to be capable of experiencing pain or loss. Therefore, we should rule out the use of AI and robots in roles that require human empathy. We should raise our children, clean our homes, and take care of our elderly. Clearing land mines, exploring deep space, mining the sea floor, and containing industrial fires are some of the many areas that could benefit from AI-enabled autonomous systems. The AI-human partnership in scientific research holds great promise and should proceed with specialized AI tools and strict standards.
The United States must lead not only in developing safe AI capabilities but in fostering an AI-savvy workforce and citizenry. Today, many Americans lack the education and skills needed to thrive in the information economy. The US educational system requires reform to enable students to prosper in a world powered by AI. The corporate approach to human capital management must also change. While employees are typically matched to their roles as a result of their knowledge and experience, adaptability and general competence must now be a priority in an era of rapid change and creative destruction. Legislation and policy should seek to maximize the number of individuals who will succeed and minimize those who could be harmed in a world with pervasive and continually improving AI capabilities.
Conclusion
The AI future can be an era of human thriving but only if we proceed with foresight and prudence. Legislation and policy are needed to strengthen civil defense, harden critical sectors of the economy, guide the use of advanced AI tools, and proactively shape the AI future. Society requires a consensus on appropriate AI boundaries. Some roads are better left untraveled, and the development of AGI and superintelligence might be one of them. Preparations at all levels of society for AI disruptions and cyberattacks are overdue, and leaders must rally the collective ingenuity and strength of the American people and our allies to confront the challenges ahead.