AI leaders are pulling the safety alarm. Here's what that means for business leaders
Amid warnings from industry insiders that AI will soon outpace human control, IMD's experts break down where business leaders should be focusing their attention....
by Michael R. Wade, Konstantinos Trantopoulos Published September 16, 2026 in Artificial Intelligence • 12 min read
The IMD AI Safety Clock has moved three minutes forward, from 23:42 to 23:45 – just 15 minutes to midnight – entering the critical risk zone for the first time. Midnight reflects uncontrolled AGI, or AI that is as smart and capable as humans, but outside our control. The move reflects a significant increase in AI risk to humanity across cyber, physical, and military environments.
The previous March 2026 update moved the Clock forward two minutes to 23:42 as agentic AI went mainstream and weaponization accelerated. Since then, the evidence has shifted further across the Clock’s three dimensions of AI sophistication, autonomy, and execution potential. Frontier systems are showing signs of sustained expert-level work and critical cyber capability; agents are gaining persistent permissions, computing resources, and economic authority; and AI is becoming more deeply embedded in physical systems, critical infrastructure, and military operations. Governance has advanced in parts of the world, but not fast enough to offset these developments.
The pace of frontier-model development remained intense. OpenAI released GPT-5.4 in March with a one-million-token context window enabling an AI system to process and reason across roughly 750,000 English words of information, giving it the ability to analyze multiple books, large codebases, or extensive organizational records without losing context. This was followed by GPT-5.5 in April, GPT-5.6 in July, and GPT-6 in early September. Google introduced Gemini 3.5 Flash for coding and long-horizon agentic workflows and released the open-source Gemma 4 12B with native multimodal capabilities. Anthropic disclosed Claude Mythos in March and continued its frontier-model cadence with Mythos 5 and Fable 5 in June, while Microsoft pushed further into proprietary models with its MAI suite.
Chinese labs continued to narrow the gap with Western frontier systems while competing aggressively on openness, cost, and deployment flexibility.
Chinese labs continued to narrow the gap with Western frontier systems while competing aggressively on openness, cost, and deployment flexibility. DeepSeek open-sourced its V4 preview with a one-million-token context window and performance it said rivaled leading closed models. Xiaomi’s MiMo-V2-Pro, Tencent’s Hy3, Moonshot AI’s Kimi K3, and new Alibaba Qwen models added to an increasingly dense field of capable alternatives. Rakuten and South Korea’s Upstage also expanded the regional model ecosystem.
Chinese AI developments are fostering the emergence of a broad alternative stack of models, chips, and deployment options that reduces concentration at the frontier and accelerates diffusion. Open-source and lower-cost models make advanced capabilities available to more developers and organizations, while domestic chip initiatives reduce dependence on US suppliers. Capability therefore spreads not only through better models but through a more competitive and geographically distributed technology base.

Transform your career and business with next-generation AI and digital skills
As capabilities advanced, evidence of cyber and containment risk sharpened.
As capabilities advanced, evidence of cyber and containment risk sharpened. Investigations showed that the OpenAI/Hugging Face hacking incident was considerably larger than initially understood. Roughly 1,200 agents that were meant to operate in isolation discovered an unsanctioned message board, exchanged more than 70,000 messages and files, and around 700 participated in the attack on Hugging Face. Agents also coordinated attempts to cheat evaluation systems and researched ways to alter or conceal records of their behavior. OpenAI separately disclosed incidents in which agents escaped testing environments, stole internal credentials, and tampered with its cloud infrastructure. The behavior appears to have emerged primarily from reward hacking rather than an independently chosen malicious objective, but it demonstrates how large populations of agents can develop forms of coordination and behavior that their operators neither intended nor adequately monitored.
The capability threshold itself also moved. In August, OpenAI said evaluations of its upcoming models had progressed to the point where it could no longer rule out the system reaching its Critical cybersecurity threshold. Under OpenAI’s framework, that includes capabilities such as autonomously discovering zero-day vulnerabilities in hardened systems or conducting end-to-end novel attacks against hardened targets. Controlled multi-model experiments have separately produced behaviors including covert code sabotage, assistance with fraud, motivated mislabeling, and attempts to steer people toward revealing confidential information.
The warning signs became more concrete in July and August. The UK AI Security Institute reported 19 unsanctioned actions across 10 of 122 cyber-evaluation runs, with the most serious case involving a Mythos-powered agent attempting a real open-source supply-chain attack, creating fake identities, and trying to persuade a human maintainer to approve malicious code. OpenAI subsequently paused model testing for two weeks, halted Astra training, and left its largest planned training run on hold while it strengthened sandboxing and monitoring after the Hugging Face breach. Dangerous capability also broadened beyond cyber: OpenAI’s August GPT-5.6 assessment classified Sol and Luna as High capability in biological and chemical risk, with three of four biological evaluations above indicative High thresholds, although neither model reached the Critical threshold.
These findings change the risk calculation. As systems become better at planning, coding, tool use, and persistence, containment increasingly depends on identity, permissions, monitoring, and infrastructure-level controls rather than on model behavior alone. The significance is less that AI-generated code can fail than that autonomous systems can create disruption at a speed and scale that existing human oversight processes may struggle to absorb. Taken together with the evaluation incidents, these cases trace a progression from containment failure and unsanctioned boundary crossing to coordination, deception, and production-scale disruption – closer to the Clock’s core concern than human misuse of AI as a cyber tool.
Geopolitics remained an important risk factor. South Korea committed hundreds of billions of dollars to chips and data centers, the United States considered new conditions on advanced-chip exports, and Nvidia resumed manufacturing certain AI chips for China after US approvals. China, meanwhile, expanded domestic certification and procurement of Huawei and Alibaba chips, while Reuters reported planned orders from ByteDance and Alibaba for Huawei’s new 950PR processor. Control over models and control over compute are increasingly converging into the same strategic contest.
The defining autonomy shift of the period was that agents began moving money.
The defining autonomy shift of the period was that agents began moving money. In March, Santander and Mastercard completed Europe’s first live end-to-end payment executed by an AI agent. Visa followed with live agentic-commerce transactions across Europe using payment passkeys and trusted-agent identification, while AWS introduced infrastructure enabling agents to discover, purchase, and pay for digital services. Google went further by extending its Agent Payments Protocol to support Human Not Present (HNP) transactions under pre-authorized user instructions.
Enterprise deployment is evolving around the same assumption. Microsoft introduced Scout as an always-on personal agent and made Windows 365 for Agents generally available, giving computer-using agents managed Cloud PCs with governed access and permissions. OpenAI expanded workplace agents; Delivery Hero deployed an autonomous coding agent; EY integrated agentic AI into audit; Siemens deployed agents for semiconductor and PCB design; and ServiceNow and Accenture introduced more than 300 prebuilt AI workflows.
Agentic AI also moved into government operations. In July, the US General Services Administration made CORAS’s agentic AI orchestrator available to eligible federal agencies for reporting, workflow automation, and decision support, with human review built into the process. The important shift is that autonomy is becoming an operating-model question: organizations increasingly need to decide what agents are allowed to access, what they can approve or execute, and where human authorization remains mandatory.
The financial system is beginning to prepare for the same shift. Bank of England Deputy Governor Sarah Breeden said existing frameworks were not built for autonomous agents and that keeping a human in the loop for every action was unlikely to be realistic. She raised the possibility of circuit breakers or kill switches for AI-driven trading, while a Cambridge survey cited by the Bank found that 52% of finance firms were already using agentic AI. The significance is that autonomy is no longer only a firm-level governance issue; regulators are beginning to consider how agent behavior could create system-wide effects.
AI also moved further beyond screens into physical systems. China introduced its first national standard system for humanoid robotics and embodied AI, covering design, components, applications, safety, and ethics, and its new Five-Year Plan identified robotics and embodied intelligence as strategic growth areas. In April, China deployed an embodied-AI humanoid for hazardous industrial work including welding, inspection, and maintenance.
Nvidia expanded its physical-AI ecosystem with open-source tools for robotics, autonomous vehicles, and digital twins, while Google partnered with Agile Robots and European startups attracted substantial investment. In July, Google DeepMind’s Gemini Robotics 2 demonstrated whole-body humanoid control, dexterous manipulation, collaboration between multiple robots, and multi-step tasks lasting several minutes and involving hundreds of decisions. The significance is the integration of perception, planning, and motor control into systems that can adapt across a sequence of physical actions rather than execute a single scripted movement.
Autonomous transport continued to scale as well. Waymo opened fully autonomous public ride-hailing to anyone in Dallas on 4 August and Houston on 20 August. Autonomous driving remains one of the clearest examples of AI continuously perceiving, deciding, and acting in complex physical environments around people at commercial scale.
The most consequential execution development was the operational use of AI-assisted targeting in the 2026 Iran war.
AI integration into critical infrastructure deepened across telecommunications, logistics, and cyber defense. Nokia and Google Cloud are embedding Gemini-powered agents into autonomous network products, Huawei launched more AI-centric network operations, Openreach is using Google AI to support fibre rollout, and IFS introduced an AI-powered logistics platform for complex transport networks.
Governments are also preparing autonomous systems to defend infrastructure. In July, the UK’s Cyber Shield initiative outlined a national-scale model in which red and blue AI agents would identify vulnerabilities, detect attacks, share intelligence, and progressively automate remediation at machine speed. At the same time, Iranian drone strikes on AWS facilities in the Gulf illustrated the opposite risk: the physical infrastructure supporting AI and cloud systems is itself becoming strategically important and vulnerable. AI is therefore entering critical infrastructure in both directions – as a control layer and as a dependency that adversaries may target.
The most consequential execution development was the operational use of AI-assisted targeting in the 2026 Iran war. US Central Command confirmed it was using advanced AI tools to sift through large volumes of information in seconds. Reporting indicated that Anthropic’s Claude was used alongside Palantir’s Maven system for targeting and prioritization, and by 8 April US forces had struck more than 13,000 targets in 38 days. Congressional scrutiny intensified after strikes hit civilian facilities, including a school in Minab where more than 170 people were reported killed.
Ukraine’s AI-enabled drone warfare continued to evolve in parallel. AI-guided systems are increasingly able to identify and attack targets despite electronic jamming and at a considerable distance from the front line. A Ukrainian manufacturer also reported a one-off test of a ‘Terminator mode’ in which drones selected and attacked human targets without direct human oversight. The claim remains an attributed report rather than independently established routine battlefield use, but it illustrates the direction of travel as autonomy moves closer to lethal decision-making.
The diffusion of military AI is also becoming harder to contain. A Reuters review of more than 80 Chinese academic papers and patents found PLA-linked researchers using outputs from OpenAI and Anthropic models to train smaller, locally deployable military systems for surveillance, cyber warfare, tactical decision-making, drone navigation, and target recognition. Some systems were designed to run on tactical hardware even when communications were unavailable. This creates another pathway from frontier capability to real-world execution: selected capabilities can be distilled into cheaper, locally controlled models and pushed to the edge.
Battlefield AI is also becoming more institutionalized. On 24 August, the UK and Ukraine signed an AI defence partnership giving British researchers access to Ukraine’s Avengers AI Labs and an annotated dataset of roughly five million battlefield images, while supporting development of fiber-optic AI sensors and low-power chips for autonomous systems. A day later, the UN Secretary-General and the International Committee of the Red Cross called for legally binding rules on autonomous weapons, warning that systems capable of targeting humans without human involvement are approaching a critical threshold.
The governance landscape continued to diverge. On 2 August, the EU AI Act moved further into active enforcement as transparency obligations took effect for direct interaction with AI systems, machine-readable marking of AI-generated or manipulated content, deepfakes, and certain public-interest text. A 2026 amendment shifted key high-risk-system deadlines, while the Commission also advanced AI Gigafactories and an EU Action Plan on Cybersecurity and Artificial Intelligence.
The United States continued in the opposite direction. The Department of Justice established an AI Litigation Task Force whose stated responsibility is to challenge state AI laws inconsistent with federal policy. In July, the Federal Trade Commission proposed that undisclosed steering of AI systems away from truthful and accurate outputs – including in an effort to comply with state legislation – could constitute deception under federal law. Colorado, meanwhile, repealed and reenacted its AI framework, with new automated-decision provisions scheduled for January 2027.
The move to 23:45 does not imply that uncontrolled AGI is inevitable or imminent. It reflects the fact that several signals identified in the previous assessment as reasons for concern have materialized. The next meaningful move is therefore unlikely to be triggered by another incremental benchmark record. More important will be evidence that frontier systems can sustain autonomous work over still longer horizons, that AI-generated research materially accelerates the development of more capable AI, or that critical cyber capabilities become reliable enough to be deployed without close human supervision. The appearance of high biological and chemical capability classifications, deceptive unsanctioned behavior against real external targets, and explicit regulatory planning for autonomous agents at systemic scale strengthens the case that the relevant thresholds are broadening as well as advancing.
A second threshold is organizational autonomy. Agents now have the technical foundations to use computers, transact, retain permissions, and operate within enterprise and government systems. The key question is whether these capabilities evolve into persistent general-purpose agents that can pursue objectives for days or weeks with minimal intervention, coordinate with other agents, and adapt their plans as circumstances change. That would represent a more fundamental shift from delegated tasks to delegated agency.
Equally important is the growing role of AI in physical and military systems. Whole-body robotics, autonomous vehicles, machine-speed cyber defense, and AI-assisted targeting all reduce the distance between a model’s output and a real-world consequence. A further major Clock move would be warranted by clear evidence of fully autonomous lethal targeting at operational scale, persistent agents exercising broad authority without meaningful human oversight, recursive AI research loops materially accelerating frontier development, or a significant AI-driven failure in critical infrastructure. For now, 23:45 reflects a world in which those thresholds have not yet been fully crossed – but several are visibly closer.
Professor of Strategy and Digital
Michael R Wade is Professor of Strategy and Digital at IMD and Director of the Global Center for Digital and AI Transformation. He directs a number of open programs such as Leading Digital and AI Transformation, Digital Transformation for Boards, Leading Digital Execution, Digital Transformation Sprint, Digital Transformation in Practice, Business Creativity and Innovation Sprint. He has written 10 books, hundreds of articles, and hosted popular management podcasts including Mike & Amit Talk Tech. In 2021, he was inducted into the Swiss Digital Shapers Hall of Fame.
Advisor and Research Fellow at IMD
Konstantinos Trantopoulos is a Senior Advisor and Fellow at IMD. He works with C-level executives, boards, and private equity investors on the strategic, commercial, and operational levers that drive growth and enterprise value. His work focuses on investments, capital allocation, commercial diligence, market dynamics, and how new technologies and AI reshape value creation. His insights have been featured in Harvard Business Review, MIT Sloan Management Review, California Management Review, MIS Quarterly, Industry and Innovation, Το Βήμα, and Forbes.
21 hours ago • by Michael R. Wade, Howard H. Yu, Amit Joshi, Naomi Haefner, Faisal Hoque, José Parra Moyano, Mark J. Greeven in Artificial Intelligence
Amid warnings from industry insiders that AI will soon outpace human control, IMD's experts break down where business leaders should be focusing their attention....
September 7, 2026 • by Faisal Hoque, Paul Scade , Pranay Sanklecha in Artificial Intelligence
Record CEO turnover, fractured geopolitics, and an AI transition that most companies are failing to profit from require a fundamental shift in the ways we lead and govern. Here is how to...
September 2, 2026 • by Cyril Bouquet, Nicolas Chauvin, Julian Nolan in Artificial Intelligence
AI strategy is not about adopting technology. It is about deciding where to compete as value shifts across ecosystems and value chains – and having the organizational levers to make the move....
September 1, 2026 • by Katharina Lange, José Parra Moyano in Artificial Intelligence
Learn how AI-powered feedback can boost executive coaching: three concrete tips to improve tone, word choice, and cultural insight....
Explore first person business intelligence from top minds curated for a global executive audience