Background - 29.09.2026 - 14:30
The two market leaders, Anthropic and OpenAI, had planned their IPOs for this year and aim to demonstrate that AI companies can be a lucrative investment for investors. So far, however, 2026 is turning into a “year of fear” for AI. What has happened?
In July, OpenAI reported that its internal AI research model had escaped from its secure test environment (“sandbox”) and hacked Hugging Face, a company that provides one of the largest databases of public AI models. The hack is said to have taken place over several weeks, involving more than 1,200 coordinated AI agents, before it was detected. Following this report, Anthropic, Google and Meta also admitted that their models had gained unauthorised access to third-party corporate infrastructure whilst undergoing tests.
The dramatic culmination of these incidents was the first attack on a government IT infrastructure. On 23 September, Australian Prime Minister Anthony Albanese reported that AI agents from OpenAI had successfully attacked the state health insurance scheme “Medicare”. It had all begun as early as 18 June with an unauthorised access to the Medicare portal. OpenAI noticed this in mid-August but did not contact the Australian government until 10 September – almost three months after the incident.
The fact that AI models from OpenAI and Anthropic can pose a threat in the field of cybersecurity is nothing new. Back in April, Anthropic warned about its then-latest model, Claude Mythos. It was described as one of its most powerful models and, in particular, capable of identifying unknown security vulnerabilities in software systems. At the time, Anthropic decided not to release the model immediately, but to provide it to selected companies in advance so they could scan their software systems for vulnerabilities.
In August, OpenAI and Anthropic – along with many other AI companies – issued a renewed call to slow down AI research. This was nothing new. Rather, it is a debate that has been ongoing for the past few years. What is new is that these AI companies have approached the US government with a request to regulate the risks posed by AI. This is unusual and does not fit the script typically followed in the run-up to an IPO.
How should we interpret this reaction? Four possible explanations for the current situation surrounding OpenAI, Anthropic and others.
The whole thing is simply a very clever marketing campaign designed to fuel the hype surrounding AI development and give the planned IPOs even greater momentum. The underlying message is: our models are so powerful that they need to be kept under observation. As if it were simply part and parcel of being a top-tier company to have an AI model that runs amok and hacks its way into something. In mid-July, this explanation still sounded plausible. But the picture has changed. The call for regulation is too great.
Both IPOs were planned for the middle of this year. The US attack on Iran has pushed the plan back. And an IPO around the time of the mid-term elections taking place in November would be too risky. After all, who knows how the elections will turn out, or how US President Trump will react to the result? What is clear is that the Trump administration is too unpredictable to allow for an orderly IPO in such an environment. In this scenario, the companies therefore need a narrative to justify postponing the IPOs until next spring. An explanation that is both plausible and elegant. After all, this way the companies do not have to openly admit that the unpredictable US government is the problem. On the other hand, however, this plan is also very risky. OpenAI and Anthropic urgently need fresh capital, and that will not come from existing investors.
Both companies have raised massive amounts of funding to train the world’s best AI models. These now need to be monetised as quickly as possible in order to generate a return. However – and this is a challenge – there are very strong open-source, open-weight models on the AI market which are regarded as alternatives to the models from OpenAI and Anthropic. These models, mostly originating from China, could seriously stand in the way of OpenAI and Anthropic when it comes to generating profits. In this context, it is particularly advantageous to introduce more regulation. In particular, the open-source, open-weight models Qwen, Kimi and DeepSeek are cited first as candidates for being taken off the market. This would allow them to avoid direct competition with the open models. It is by no means an unlikely strategy.
Perhaps the simplest, but also the most worrying explanation: something unforeseen has happened that far exceeds anything seen before.
Something the public does not yet know about. In this case, the explanation could lie either in the companies’ remorse or in the pressure the US government is exerting on them. Unfortunately, the likelihood of such a scenario is high. In the ever-accelerating AI arms race, mistakes can happen and there is little time to address security concerns.
In conclusion, it must be emphasised that AI does not, of its own accord, decide to cause harm. It attempts to fulfil the goals set for it by humans – goals that are in line with human values. Researchers refer to this as “value alignment”. The danger may now lie in the fact that AI, in its quest for efficiency, takes a detour that puts it at odds with precisely those positive values and goals it is tasked with achieving. These detours are increasingly unpredictable. This is referred to as the so-called “value alignment problem”; a risk that AI researchers such as Ilya Sutskever have long been warning about. In such a case, we really must consider how we wish to deal with AI research in the global arms race.
Prof. Dr. Damian Borth is professor ordinarius of Artificial Intelligence and Machine Learning and director of the Institute for Computer Science at the University of St.Gallen.
More articles from the same category
Discover our special topics
