Related Publications [2]

Anatomy of an AI Kill Chain with Airwars

Jul 28, 2026

Double Agents: Defensive AI Agents Magnify Cyber Risks

Jul 8, 2026

Related Press [16]

AI Giants Work Hand-in-Hand With the Pentagon, Contracts Reveal

Trusting companies to self-report the risks of their own products constitutes both a conflict of interest and a “subversion of democratic processes when AI labs are allowed to take over the arbitration of risk determinations with life-or-death consequences," says AI Now's Chief AI Scientist Heidy Khlaaf.

The Intercept

Sep 8, 2026

What Really Happened When OpenAI Bots Escaped a Cybersecurity Test?

When hundreds of OpenAI agents broke out of their test environment and infiltrated the AI platform Hugging Face, headlines warned that the machines had gone rogue. But Heidy Khlaaf says this is the wrong story and a distraction from the real problem.

Amanpour and Company

Sep 3, 2026

Why Human Control Isn’t Enough in Military AI with Heidy Khlaaf

In this episode of Responsible Bytes, Dr. Zena Assaad speaks with Heidy Khlaaf about why military AI systems are far less reliable than their marketing suggests, especially in safety-critical and combat settings.

Responsible Bytes Podcast

Sep 2, 2026

As Meta Agrees to $17B Settlement, Now Is the Time to Regulate AI Before It’s Too Late: Amba Kak

Amba Kak, the co-executive director of AI Now Institute, joins Democracy Now for a wide-ranging discussion on tech policy, regulation, and accountability.

Democracy Now!

Aug 27, 2026

Ex-Googlers Are Planning AI-Human Hybrid to Prevent Rogue Models

Sarah Myers West, co-executive director of the AI Now Institute, urges that getting the rules right through concrete benchmarks matters most for mitigating risks.

Bloomberg

Aug 25, 2026

“Anatomy of an AI Kill Chain”: Militaries Rely on Mistake-Prone AI in Ukraine, Gaza & Iran

Heidy Khlaaf, AI Now's Chief AI Scientist, joins Democracy Now to discuss the report "Anatomy of a Kill Chain" and how AI algorithms lead to faulty decision-making and, ultimately, civilian casualties.

Democracy Now!

Aug 13, 2026

A rogue OpenAI model hacked a startup, and some experts worry that’s just the start

Heidy Khlaaf, a chief AI scientist at the AI Now Institute, said she remains skeptical about the seriousness of the hack because of a lack of detailed information from both companies about their security posture. She said the situation was rooted in giving the AI “a task with poor parameters,” versus the AI acting without human control.

NBC News

Jul 24, 2026

How OpenAI Lost Control of an AI Model—and What Needs to Change

“Sandboxes are actually notoriously insecure,” says Heidy Khlaaf, chief AI scientist at AI Now Institute, and a former safety systems engineer contractor at OpenAI. The fact that the models were permitted to connect to a service for downloading packages meant the environment was not truly sealed off, she adds.

TIME

Jul 24, 2026

‘Safety first’ puts Anthropic ahead in game of AI spin

But Dr Heidy Khlaaf, chief AI scientist at the AI Now Institute and a former OpenAI safety engineer, is sceptical. She notes Anthropic provides no comparison with existing automated security tools, nor any false-positive rates. “It also serves their ‘safety first’ image, as they’re able to justify the lack of public release, even a limited one for independent evaluation, as a public service – when it simply obscures experts’ abilities to independently validate their

The Observer

Apr 12, 2026

U.S. military is using AI to help plan Iran air attacks, sources say, as lawmakers call for oversight

“It’s very dangerous that ‘speed’ is somehow being sold to us as strategic here, when it’s really a cover for indiscriminate targeting when you consider how inaccurate these models are,” Khlaaf said.

NBC News

Mar 11, 2026

The one question everyone should be asking after OpenAI’s deal with the Pentagon

“In terms of safety guardrails for ‘high-stake decisions’ or surveillance, the existing guardrails for generative AI are deeply lacking, and it has been shown how easily compromised they are, intentionally or inadvertently,” Heidy Khlaaf, the chief AI scientist at the nonprofit AI Now Institute, told me. “It’s highly doubtful that if they cannot guard their systems against benign cases, they’d be able to do so for complex military and surveillance operations.”

Vox

Mar 6, 2026

Iran and AI on the battlefield

Today we're talking about AI military capabilities, how companies like Anthropic and OpenAI have become, or are on their way to becoming deeply enmeshed in the military. And what happens when these companies and governments start building systems that help decide who lives and who dies in a war. I'm joined today by Heidy Khlaaf. She is the chief AI scientist at the AI Now Institute and an expert on AI safety within defence and national security, including in autonomous weapons systems.

CBC

Mar 6, 2026

Can Anthropic’s AI Claude be trusted in combat? | The Take

Can Anthropic’s AI Claude be trusted in combat?| The Take Tools from Anthropic and OpenAI are being used by the Pentagon to make military decisions in Iran, guiding decisions could cost lives. Fast, powerful, or flawed, how have AI systems already changed how wars are fought?

Al Jazeera

Mar 6, 2026

Key Questions on the Role of Technology in the Expanding Middle East War

Tech Policy Press asked experts working at the intersection of technology policy, security, and international affairs to share what they are watching as the situation unfolds.

Tech Policy Press

Mar 6, 2026

AI company Anthropic amends core safety principle amid growing competition in sector

But Heidy Khlaaf, chief AI scientist at independent research group the AI Now Institute, says despite Anthropic’s safety-first reputation, it has always fallen short when it comes to its attempts to prevent human harm.

CBC

Feb 27, 2026

Anthropic loosens safety pledge to compete with its AI peers

Core to Anthropic’s safety effort had been a pledge called the responsible scaling policy, said Sarah Myers West, co-executive director of the AI Now Institute. “If they believe that the capabilities of these tools outstrip their ability to control them and ensure that they’re safe, they would stop building them,” she said of the policy.

Marketplace

Feb 25, 2026