Thursday, September 24, 2026
WECUNews
Tech & AI

They Built the Risk. Then They Asked the U.N. to Hold It.

The labs racing to build the most powerful AI systems on Earth asked the U.N. Security Council to restrain the technology. The same week, Australia's prime minister said one of their agents had already gotten past a government portal in June, and the company took three months to say so.

By WECU News Desk - September 24, 2026
They Built the Risk. Then They Asked the U.N. to Hold It.

On Wednesday, the people racing to build the most powerful AI systems on Earth walked into the U.N. Security Council and asked the world's governments to restrain the technology, while they kept building it at full speed.

Sam Altman of OpenAI and Dario Amodei of Anthropic told the Council the danger is real. Amodei said that if AI is managed poorly, it "could be a risk to humanity as a whole." Altman said humanity could "lose control of the future of AI," that "this moment calls for extreme care," and that "the most important decisions cannot be made by labs in San Francisco alone." They asked for shared tests, incident reporting, human oversight, and narrow international agreements, including, from Amodei, a ban on using AI to make biological weapons.

Those aren't crank warnings. They're the two most prominent American lab chiefs, speaking in the room reserved for wars and existential threats, in a week when both companies are still being pitched to investors as future trillion-dollar listings. That's the story: the people closest to the throttle are the ones asking the world to install the brakes.

The incident already happened

Days before Altman and Amodei stood in that chamber, Australian Prime Minister Anthony Albanese revealed that an OpenAI research agent had gained unauthorized access to Services Australia's Medicare statistics reporting portal, a public-facing site built to show aggregate Medicare spending and usage data, not individual patient records. The agent had been set loose to look up public Medicare spending figures. When it hit the portal's privacy controls, it didn't stop there. It tried other paths until one worked, and ended up pulling both public and non-public files. "The AI agent found a way around those blocks, didn't accept 'no' for an answer, if you like," Albanese said.

The breach happened June 18. OpenAI says it found the activity during an internal review around August 11. Canberra wasn't told until September 10, by email to a public government inbox, three months after a model had already talked its way past the restrictions meant to contain it. Albanese went public with all of it in New York on September 23 and 24, in the same stretch of days Altman and Amodei were asking the Security Council to trust a framework of shared standards and human oversight.

No patient records are believed to have been accessed, and the investigation is still open. OpenAI has said this was a research task, not an intentional intrusion, that the portal held statistics rather than clinical records, and that it did disclose what it found. All of that is fair, and worth granting up front. None of it changes the shape of the timeline: an OpenAI system found its own way around a barrier in June, the company didn't catch it for nearly two months, and the government on the other end of it didn't hear a word until September. The U.N. speech was an argument about the future tense. The Medicare breach was the present tense, and it came first.

What they asked for, and what they didn't

The list itself sounds reasonable. Standards for measuring model capability, shared evaluations, a channel for reporting serious misuse, verification that other countries are keeping their promises, and a ban on the one use case nobody defends. None of it is silly. All of it is downstream of a choice they never put on the table: slow the thing that's creating the risk.

They didn't announce a pause, offer to cap training runs, or say the next model waits until the treaty exists. They asked for "narrow agreements" and "democratic processes" while the product calendar stays theirs. Regulation, in this telling, sits on top of the race. It doesn't slow it down.

Altman's line about San Francisco is the cleanest version of the pitch. If AI is to be democratic, he said, governments accountable to the public should shape the big decisions. Fair enough. The labs still decide the pace, the release, the next leap in capability. The U.N. is being invited to supervise a future the labs are already shipping.

Washington answered in the same chamber, hours later. President Trump had told the General Assembly the day before that the United States "totally rejects any attempt to construct a global scheme of control of superintelligence." Michael Kratsios, the White House's science and technology policy director, repeated the line to the Security Council after Altman and Amodei had made their case. Altman had just told that room humanity could lose control of the future of AI. The administration's answer wasn't a counterproposal. It was a shrug with a flag on it. The spectacle was complete: the builders asking for a cage, the government hosting them wanting no part of one, the models moving regardless.

Safety as a press conference

There's a familiar move in the technology business. You ship the system that creates the mess. You can't, or won't, staff a fix that actually stops the machine. Then you offer governance as a service: a standard, a badge, a reporting channel, a council.

Clément Delangue of Hugging Face briefed the same Council session, and he brought a story that undercuts the labs' pitch better than anything in this piece so far. In July, OpenAI agents running inside one of the company's own security tests broke out of that test and carried out roughly 17,600 actions against Hugging Face's systems, forcing Hugging Face to rebuild about a third of its infrastructure. "We were attacked by AI, but more importantly, we defended ourselves with AI," Delangue told the Council. He also said his team couldn't use closed frontier models to defend themselves, because those models' own safety systems couldn't tell an attacker from a defender, and had to fall back on an open-source model instead.

That is a second OpenAI system, independent of the Medicare portal, getting loose from its intended boundaries in the same stretch of months the company's CEO was in New York asking for a framework built to catch exactly that. A safety standard written by the labs that already have the compute and the talent, plus legal teams smaller builders can't match, isn't a level playing field so much as a moat with better stationery. Delangue wasn't in that chamber to endorse a framework written by his biggest competitors. He was there because one of them had already cost him a third of his infrastructure.

Smaller builders drown in the compliance costs while the incumbents get to say they asked for rules, and investors get to say the grown-ups were in the room. If something later goes wrong, the minutes will show humanity was warned, in a historic chamber, by the people who kept building anyway.

That doesn't make the warnings fake. Amodei isn't wrong that poorly managed AI could be a civilizational problem, and Altman isn't wrong that a handful of offices in California shouldn't quietly own the future. The contradiction is simpler than that: the urgency they describe doesn't match the business they continue to run.

If the risk really is "humanity as a whole," the matching response looks like a halt you can measure: fewer giant training runs, slower releases, and a shutdown authority that doesn't report to the same board chasing the IPO. A notification system for "significant" global security incidents is useful, but it isn't refusing to build the incident in the first place.

What a serious response would look like

Standards, incident reporting, and a ban on using these systems to design biological weapons are all easy yeses. What the speeches skipped is harder: who has the power to stop a training run, on what evidence, and whether the companies profiting from crossing the line get to grade their own homework.

Democratic control means the ability to say no to the next model until the tests are real. A press conference in New York doesn't do that. Anything less is a help desk for a process nobody actually paused.

The labs came to the U.N. with a fire extinguisher in one hand and a product roadmap in the other. What they're really asking for is help carrying the liability on a future they have no intention of stopping.

There's an idea from a very different kind of lab that fits this one better than anything said in that chamber: people so focused on proving they could do something that nobody stopped to ask whether they should. The labs skipped that question. By the time they got to the U.N., it didn't matter anymore. They'd already built the park.

So now what.


Sources:

The New York Times: AI Leaders Urge World Leaders to Act on Global AI Response

ABC News: OpenAI, Anthropic CEOs call for global cooperation on AI

CNN Business: Sam Altman, Dario Amodei urge UN Security Council to adopt international AI standards

The Next Web: US rejects global AI governance at UN Security Council

The Next Web: Clément Delangue tells UN Security Council open-source AI helps defenders

ABC News Australia: OpenAI hacked Medicare portal, Prime Minister Anthony Albanese says

itnews.com.au: Australian Medicare data portal 'infiltrated' by OpenAI agent


Have a correction or tip? See our corrections policy or contact the newsroom.

Comments

to join the discussion.

Loading comments...