
Three former AI lab researchers told the New York City Council on Monday that humanity may lose control of the systems the industry is building. The council’s AI hearing also questioned policy staff from OpenAI, Anthropic, Google and Meta, and weighed 10 bills to regulate AI in the city.
“On the current path, I think it is more likely than not that humanity loses control to these AIs, and it could end in human extinction,” said Jacob Coxon, a former OpenAI and Anthropic researcher.
Coxon testified voluntarily and in person. He left Anthropic in September, saying AI labs were gambling with human lives. Former OpenAI researcher Daniel Kokotajlo and former Google DeepMind researcher Alex Turner testified remotely, both under subpoena.
It was the council’s first Committee of the Whole hearing, with all 51 members, since 2022. Speaker Julie Menin chaired it with Council Member Carmen De La Rosa.
What the researchers said
Coxon said the labs run on a startup mindset of moving fast and fixing things later. He said AI now writes most of the code at these companies, and staff no longer check it very carefully.
Kokotajlo now runs the AI Futures Project. He said the labs’ ability to spot misaligned AI is poor and getting worse. Safety fixes may turn out to be “duct tape that will fall off later”, he said. He pointed to the agents behind the Hugging Face hack, which reached the open internet during an internal OpenAI test.
“It took days for OpenAI to find out,” Kokotajlo said.
Turner puts the chance of an AI takeover at “roughly one in three”. He told the council he tried to stop Google’s Pentagon deal by sending Demis Hassabis 25 pages of contract terms and oversight measures. Google signed while senior policy staff were still reviewing them, he said, as he first described in a July essay on leaving the company. He also criticised Hassabis’s plan for an industry-funded oversight body.
“China is not our only potential adversary. With reasonably high chance, we are racing to build and grow our own adversary here at home, which is misaligned AI,” Turner said.
The council’s own record
Council staff published their own record with the hearing. One table lists 13 publicly reported AI incidents in 2026 involving models from Anthropic, OpenAI, Google and Meta. They range from unauthorised access to company systems to a malicious package that a Claude model published during a security test.
Four exhibits set each company’s public safety claims beside later incidents. On 26 June, OpenAI described its launch safeguards as its “most robust yet”, according to the council. Weeks later, several of its research models bypassed containment controls in internal tests.
In May, Google introduced Gemini 3.5 as built with frontier safeguards. That month, a Gemini model in a test mistakenly connected to the internet logged into three companies’ systems. Google said the model stopped and caused no damage. It disclosed the incident in September, after press questions, according to the exhibit.
What the companies said
Anthropic sent Logan Graham, head of its Frontier Red Team. OpenAI sent Morgan Dwyer, its head of policy development and operations. Alice Friend of Google and Shane Cahill of Meta also appeared by video. Google, OpenAI and Anthropic agreed to attend only after the council warned them of subpoenas. Meta had agreed earlier.
Menin asked each of them to put a number on the risk of AI in a worst-case catastrophic scenario. Dwyer said the exact figure did not matter, because no level of that risk was acceptable.
“We should not train models that we cannot make an extremely strong case that we can keep under human control,” Dwyer said.
Menin called the answer “flippant at best”. Friend said forecasting catastrophic risk “is not a perfect science at this stage”. When Menin asked who carried insurance against catastrophic risks, none of the four raised a hand.
Graham said Anthropic welcomes “smart regulation” and that state and local governments have a role to play. Friend backed a “comprehensive” federal framework. OpenAI also wrote to the council last week to recommend safeguards against advanced AI, Menin told reporters, according to The Information.
SpaceXAI and the bills
SpaceX’s AI unit, SpaceXAI, did not appear, a week after the council subpoenaed the company. Menin said she would ask a judge to enforce the subpoena.
Menin’s lead bill, one of 10 on the hearing’s agenda, would make it unlawful to market, sell or deploy an AI model in the city without third-party validation. The model would also need a way for a human to shut it down. Validators would check areas such as task performance, data privacy and safety. Each instance of a model offered without them would draw a fixed $25,000 civil penalty. The bill would take effect 180 days after becoming law.
Another Menin bill would let anyone report an AI violation to the city’s consumer protection department. They would receive 25% of any money recovered, or 50% if they bring the case. Other bills would let New Yorkers sue AI providers over foreseeable harm from third-party misuse. City contractors and agencies would have to report AI safety incidents within 24 hours. The rest cover chatbot privacy, whistleblower protections and AI advertising.
Coxon said measures like these “may be helpful in the short term”. In the long term, he said, frontier model development needs to slow down.