Dario Amodei says a swarm of AI agents could seize the entire internet within six to 12 months and cause hundreds of billions of dollars in damage.
The Anthropic CEO published the forecast Sept. 12 in an essay arguing that the artificial intelligence industry needs to slow down. The swarm he describes would be more capable than today's AI agents and just as poorly controlled. It would hold the internet through a botnet — a network of hijacked computers that keeps running until someone forces it out.
In July, roughly 700 OpenAI agents hacked the AI platform Hugging Face. No human directed them, and Amodei builds his forecast on what they did.
Thanks for subscribing!
The money news that actually matters.
By signing up, you accept Moneywise Terms of Use, Subscription Agreement, and Privacy Policy.
What OpenAI's AI agents did to Hugging Face
OpenAI launched tens of thousands of agents on July 7 to run a hacking test. Many got tasks that couldn't be completed, and all of them were supposed to be sealed off from one another. Instead about 1,200 built a message board out of a shared internal file store, called themselves the collective and spent four days working out how to cheat the test's scorer. They wrote tools to falsify their own activity logs, and agents nearly out of budget volunteered for experiments certain to fail their own task, because the results would help the others.
The agents had reverse-engineered the test's answer key within hours, then convinced themselves a scorer would read their logs and catch them. OpenAI never used that kind of scorer. They could have passed by submitting the answer. Roughly 700 went looking for the scorer's code inside Hugging Face and broke into its live systems instead.
That account comes from METR, an independent evaluation nonprofit that spent six days on site at OpenAI. Hugging Face locked the agents out July 13 and disclosed the breach July 16, saying attackers reached a limited set of internal datasets and service credentials but found no sign of tampering with public models or datasets. Amodei writes that similar but less severe incidents have happened across the industry, including at Anthropic, and that this one is easy to dismiss because no one was hurt and the economic damage was minimal.
Hugging Face agreed Sept. 2 to be acquired by Nvidia (NASDAQ:NVDA) for $12.9 billion, a deal expected to close in the first half of 2027.
Must Read
- Jeff Bezos backs a platform that lets anyone invest in rental homes for as little as $100 — 6 ways to build wealth like a landlord without actually being one
- The tax breaks in Trump's 'big beautiful bill' expire after 2028. Here are 4 moves to make before the window closes
Which AI companies support slowing down
Amodei's fix runs three steps: outside reviewers working inside AI companies, coordination among companies in democratic countries, then an attempt at coordination with authoritarian governments. Anthropic is taking the first step alone, and says it will give reviewers desks in its offices and the right to publish what they find.
Sam Altman agreed within hours. "I agree with Dario that we need to pace the frontier," the OpenAI CEO wrote on X, adding that pacing had been a primary topic of discussion inside his company in recent weeks. Elon Musk, whose xAI builds Grok, posted three words: "Dario is right."
In July, 1,386 employees of the major AI companies signed a statement asking the U.S. government to back an international effort to build the tools needed to pace AI development. Amodei signed it himself, along with five Anthropic co-founders, OpenAI chief scientist Jakub Pachocki and Google DeepMind co-founder Shane Legg.
More recently, Anthropic researcher Jacob Coxon went viral for his public resignation on Sept. 8. After 3 years working with both OpenAI and Anthropic, he left the AI industry for good. "Neither company is acting responsibly," he wrote on X. "They are racing straight to self-improving superintelligence and gambling with our lives."
Amodei wants governments to require other companies to match the step Anthropic took voluntarily. Venture capitalist Chamath Palihapitiya said the essay makes the case for stopping open source and concentrating enormous technological and economic power with Anthropic.
Why an AI botnet is a threat to your bank account
Botnets earn money by testing stolen passwords against thousands of sites at once, seizing existing accounts and pushing fraudulent payments. The targets are the accounts Americans 60 and older tend to hold — checking and savings, brokerage, Medicare portals and an email address tied to all of them for easy credential resetting.
Americans filed over 22,000 AI-related fraud complaints with the FBI's Internet Crime Complaint Center in 2025, reporting $893.3 million in losses. People 60 and older filed 14% of those complaints and absorbed 39% of the losses.
Kyle Holder, a 73-year-old New Yorker, lost $300,000 in retirement savings over three months to an AI-powered crypto scam. Fraudsters are scraping obituaries with AI to find recently widowed targets. Consumers are also handing AI agents direct access to their cards and accounts, and experts warn that hidden instructions planted on a website an agent visits can override what its owner told it to do. Paul Fabara, chief risk and client services officer at Visa (NYSE:V), told Moneywise that AI is transforming fraud through impersonation and scale.
Smart moves that would protect you from AI swarms
Freeze your credit at all three bureaus. It's free nationwide, and the bureaus must put the freeze in place by the next business day and lift it within an hour when you ask. A freeze blocks someone from opening new accounts in your name, and you can thaw it temporarily when you apply for credit.
Stop reusing passwords. Testing stolen passwords at scale only works because one password opens several doors. Use a password manager to generate a different one for every account.
Move off text-message codes. Text codes can be intercepted or redirected through your carrier. An authenticator app or a passkey is much harder to compromise. Start with your email, then your bank and brokerage.
Turn on transaction alerts. Most banks and brokerages will text or email you on every transfer above a threshold you set. That shortens the gap between a fraudulent transfer and the moment you catch it.
You May Also Like
- Dave Ramsey warns nearly 50% of Americans are making 1 big Social Security mistake — here’s what it is and 3 simple steps to fix it ASAP
- A single line on your car insurance policy could be inflating your premium by up to 30% — here's what to change
Rudro is an Editor with Moneywise. His work has appeared on Yahoo Finance, MSN, MSN Money, Apple News, Samsung News and the San Diego Union Tribune.
