On 16 September 2026, at Sciences Po, Yann LeCun invoked James Bond to describe a scenario of a massive cyberattack carried out by AI agents. Defenders, in his view, have superior technologies and skills. He asserts that the arrival of agents favours defence. He adds that attacks and defences are becoming more sophisticated, without seeing any clear shift in the balance between them. On biological risk, he points to the resources needed to produce a pathogen, then to the motivations of specialists: they would have better prospects than working on a virus that could kill them.
In these answers, his technological optimism also rests on his confidence in people. Yet competent and well-intentioned actors can, together, allow a catastrophe to happen. LeCun does indeed work on the safety of systems. The question that remains concerns the reliability of human decisions and of the organisations responsible for making it work, in circumstances they will sometimes have poorly anticipated.
Technical safeguards, assumptions about behaviour
This confidence is explicit. In his interview with Lex Fridman published in March 2024, LeCun says he thinks people are “fundamentally good”, and links pessimism about AI to distrust of people or institutions. In a 2023 interview with The Hub, he was already arguing that well-intentioned actors would have greater resources and that users would reject dangerous machines. If the technology took a wrong turn, “we just stop”, he explained.
LeCun also proposes engineering answers. Speaking to Lex Fridman, he describes objective-driven AI with built-in guardrails, acknowledges that unforeseen behaviours will occur and expects safeguards to improve gradually. The account of his discussion at INSEAD, published on 14 September 2026, echoes this ambition: anticipating the consequences of actions through world models and building constraints into decision-making. In Fortune on 1 October, he attributes incidents to design and oversight flaws, which he considers avoidable.
This research gives his optimism a technical foundation. It leaves open the collective conditions for its success. A user may want a useful tool without knowing its dangers. A management team may hesitate to halt an activity. Several teams may share a mistaken assumption. The problem begins well before malice: sometimes it is enough for everyone to trust a safeguard whose limits no one has checked.
A catastrophe does not need to threaten humanity
Industrial history offers a scale of severity other than extinction. The AZF explosion in Toulouse in 2001 affected a city far beyond the plant. Public health studies document its consequences for residents' health and for their personal, family and working lives. A local accident can cause lasting damage that extends well beyond the perimeter of the organisation responsible for it.
At Fukushima, the analysis of human and organisational factors carried out for the IAEA report describes how the actors involved mutually reinforced their assumptions about safety. These shared convictions stood in the way of adequate preparation for the accident of March 2011. Confidence in the system was itself part of the problem.
These precedents do not measure the risk of AI. They are a reminder of what a failure of anticipation can cost, even in sectors where safety specialists work. As AI spreads, we must assume that serious accidents will occur and seek to reduce both their likelihood and their scope. The ability to correct things afterwards does not, on its own, answer the question of the damage suffered in the meantime.
Recent incidents, whose established damage remains limited, already show gaps between the safeguards as designed and how they actually work. Our articles on the reclassification of Anthropic's incidents and on six OpenAI reports detail these mechanisms. Since they occurred during training or evaluations, no risk rate in production can be inferred from them. They show that designing a rule, applying it and detecting its circumvention are three distinct tasks.
According to a CNN investigation published on 18 September 2026, the US military came close, in the spring, to intercepting a Chinese ship in the Middle East on the basis of an AI-assisted report that wrongly identified its cargo as linked to a nuclear weapons programme. The operation was reportedly called off after verification. This account rests on four anonymous sources; the Pentagon had not responded to CNN. The mechanism described is that of erroneous information fed into a human decision-making chain.
The superiority of defenders does not protect everyone
Malice adds a further difficulty. The 9/11 attacks, which were a deliberate attack and not an industrial accident, pitted profoundly unequal means against each other. The US commission of inquiry highlights the disproportion between the resources of the terrorist group and those of the country it struck. It identifies failures of anticipation, policy, capabilities and management.
Their consequences went beyond the immediate destruction: NATO's response, in particular, transformed its missions and capabilities. The defenders' material superiority did not guarantee protection against a major attack and its cascading effects.
This superiority is, moreover, unevenly distributed. In its assessment published in May 2025, the UK's NCSC anticipated a divide between systems able to keep pace with AI-enhanced threats and a large share of more vulnerable systems. The resources of the best laboratories or of the major powers therefore do not describe the actual protection of all companies and institutions.
Safety is also built within institutions
The aviation analogy often used by LeCun is illuminating. Making engines more reliable required considerable engineering work. But the history of aviation safety also includes certification, air traffic control and accident investigation. The 1956 Grand Canyon collision revealed the inadequacy of collision prevention despite growing traffic. Two years later, the United States created a new independent federal agency responsible for civil aviation safety.
Risk control was therefore built at several levels. Collective arrangements organised the flow of information, oversight and intervention. This history supports the possibility of safer technical progress. It also shows the institutional work required and the price paid when safeguards remain inadequate.
LeCun himself acknowledges a role for these institutions. At Sciences Po, he advocates independent testing for driver assistance and marketing authorisation for mammogram analysis. He nevertheless considers that existing regulations are generally sufficient and rejects the idea that AI, in its current state, poses an intrinsic danger justifying the regulation of research.
The point to examine is therefore a precise one: will these frameworks and their means of oversight actually cover the new uses? Who can check the safeguards, access the traces of an incident, warn the third parties concerned and impose a correction? These capabilities must be open to examination independently of the trust placed in developers. Our investigation into Anthropic's governance already raised this difficulty: sharing an intention to be cautious and having the power to enforce it are two different things.
Distinguishing threats, organising prevention
Public debate has become polarised around extinction scenarios. In an interview excerpt broadcast by BBC Newsnight on 10 September 2026, Geoffrey Hinton considers “not unreasonable” an estimate of a 10% risk that AI will kill all humans within ten years. This is his own assessment of the risk. At Sciences Po, LeCun, for his part, stresses the superiority of defenders and brushes aside James Bond-style scenarios. This part of his answer, which stays on the same level as his critics, gives the debate a Manichaean reading, in which security depends on the advantage of well-intentioned actors over their adversaries.
9/11 is a reminder that superior means are not enough to prevent a major attack, whose consequences can far exceed the immediate destruction. But preventing terrorism and preventing industrial accidents call for distinct analyses, even if some safeguards overlap. A design error, an ambiguous instruction or a coordination failure can cause damage without any actor having sought to do harm.
LeCun acknowledges these failures and works on preventing them. Describing them as avoidable, however, leaves entirely open the question of the real conditions for such prevention. It is becoming necessary to talk openly about the serious industrial accidents that AI could cause or amplify, to assess their likelihood and scope according to the uses, and to spell out the uncertainties. Developers, user companies and public authorities must share the lessons learned from incidents and decide together on the means of protection.
Slowing down AI development would not be enough: others would keep moving forward. Its benefits justify continuing research and deployment, with safeguards whose effectiveness can be verified. Independent testing, access restrictions, system separation and intervention procedures must reduce the likelihood of accidents and contain their consequences. This requires budgets, clearly assigned responsibilities and the effective power to halt an operation. Who receives the alert, who decides to shut things down and who warns the people exposed?
Arrangements already exist, with differing scopes and degrees of constraint, but they are still insufficient. Our overview of AI regulation compares international initiatives, national laws and the state of their implementation.
