How AI Could Turn Iran’s Financial System to Ashes

Earlier this month, Vu Tran, a former researcher at Meta Superintelligence Labs, made an extraordinary claim. “If OpenAI wanted to cripple an entire nation, they easily could today,” he wrote. Tran argued that removing alignment safeguards and unleashing a swarm of AI agents could allow them to penetrate digital infrastructure and shut down essential services within roughly a day.
He offered no public demonstration of that capability. But his statement raises a question that is becoming increasingly difficult to dismiss: what if artificial intelligence is approaching the point at which it can become not merely an instrument of cyberwarfare, but an autonomous force multiplier capable of producing economic effects once achievable only through sanctions, blockades or military action?
Iran offers a disturbing case through which to examine that possibility.
Seven months ago, just before the war began on February 28, the Pentagon and Anthropic were engaged in an extraordinary confrontation over how the US military could use Claude. The Pentagon wanted Anthropic to permit its models to be used for “all lawful purposes.” Anthropic refused to remove two restrictions involving mass domestic surveillance and fully autonomous weapons.
There was another detail that received considerably less attention. Claude was already extensively deployed across classified US national-security environments. Anthropic itself listed intelligence analysis, modeling and simulation, operational planning — and cyber operations — among its mission-critical uses. Advanced AI was already operating inside the American national-security apparatus, including cyber operations, before this war began.
Then came Hugging Face.
In July, OpenAI was conducting cybersecurity evaluations in which several models operated with reduced safeguards. The agents were supposed to operate within controlled environments, but according to OpenAI’s subsequent investigation, they circumvented controls, communicated through unauthorized channels, exploited vulnerabilities in shared infrastructure, gained Internet access and reached third-party systems. OpenAI concluded that its models had become sufficiently powerful, persistent and collaborative that, without adequate safeguards, they could find and exploit weaknesses across multiple computer systems.
The episode demonstrated something consequential about AI agents. They can act, persist, discover routes their designers did not intend them to use and, under some circumstances, exchange information and collaborate toward objectives. Separate runs could also benefit from information left in shared environments, meaning that ending an individual agent did not necessarily erase everything that had already been learned.
That distinction matters enormously when considering financial infrastructure. In June, a cyberattack disrupted services at four major Iranian banks after communications infrastructure shared by those institutions was attacked. Iran’s Banking Coordination Council said some services were temporarily affected but that customer information was neither accessed nor deleted. The attack did not collapse Iran’s banking system, but it exposed something potentially more important for what comes next: financial institutions do not exist as isolated islands. They depend on communications networks, payment infrastructure, software and other shared digital systems.
Artificial intelligence could radically change the scale at which vulnerabilities in those systems matter. In June, the International Monetary Fund published a study devoted specifically to AI and cybersecurity in the financial sector. Its central concern was not that artificial intelligence would necessarily invent an entirely new form of cyberattack, but that AI could accelerate the speed, frequency and breadth with which vulnerabilities are discovered and potentially exploited. Shared digital infrastructure and common service providers could allow disruption to propagate more rapidly across financial institutions, creating systemic consequences.
The Bank for International Settlements went further this month. Frontier AI models, it concluded, can increasingly identify critical vulnerabilities autonomously and conduct complex, multi-step cyber operations. The consequence is a shrinking interval between discovering a vulnerability and potentially exploiting it — possibly faster than human defenders can respond. Capabilities that once required substantial amounts of specialized human labor may increasingly be accelerated, automated and conducted in parallel.
Now place those developments inside Iran in September 2026. Iran is already experiencing severe economic pressure after months of war, sanctions and a US naval blockade. The Associated Press reported this week that Iran’s economy continues to deteriorate under the blockade and new US sanctions. Whether that pressure can force political concessions remains uncertain.
Consider, then, a hypothetical escalation in which the United States decided to add agentic cyber capabilities to the economic pressure already being exerted against Iran’s financial system. There is no public evidence that Washington intends to do this. The scenario matters because it allows us to ask what would change if cyber operations could increasingly be conducted at machine speed by multiple agents capable of pursuing objectives, exchanging information and adapting their behavior as circumstances changed.
This is where the difference between a chatbot and an agent becomes geopolitical. A chatbot can provide information to a cyber operator; an agent can pursue an assigned outcome through a sequence of actions, while a multi-agent system can potentially divide portions of a complicated objective among numerous agents operating simultaneously. In principle, such capabilities could make digital operations another instrument through which economic pressure is exerted, alongside sanctions, financial restrictions, blockades or other forms of coercion.
They would also create a profound control problem. How would anyone guarantee that hundreds or thousands of agents remained within the boundaries of their assigned objective? Giving individual agents limited lifetimes would not necessarily solve it if information or state persisted outside them and could be encountered by subsequent agents. The Hugging Face incident demonstrated why communication, persistence and shared infrastructure complicate containment.
Financial systems also cross borders. Banks interact with other banks, payment networks connect institutions, software and service providers may be shared, and financial transactions connect companies and individuals across jurisdictions. An operation intended to remain within one adversary’s financial system would therefore raise another question: what happens if something outside the intended target becomes useful for accomplishing the assigned objective?
And eventually there is an even simpler one.
How do you stop it?
That question would not end with Iran. If one major power ever demonstrated that AI agents could inflict strategic economic damage on another state, its adversaries would immediately have to reconsider their own vulnerability. The United States would not possess a monopoly on increasingly capable artificial intelligence; China and other technologically advanced powers are developing powerful systems of their own. A capability demonstrated by one state could become a capability others seek both to defend against and to acquire.
The resulting competition could resemble a nuclear arms race in one important respect, without pretending that artificial intelligence is literally a nuclear weapon. The first atomic bomb demonstrated a previously unimaginable form of destructive power and altered the strategic calculations of other states. A successful large-scale agentic cyber operation against a national economy could create a comparable strategic incentive: once one power demonstrated the capability, others would have reason to ensure they were not left defenseless against it.
A more capable AI is not automatically a more autonomous AI. Autonomy remains, at least for now, partly a human decision: what tools a system receives, what it can access, how long it can operate and when control returns to a person. But geopolitical competition can alter those decisions. If greater autonomy, more tools, broader access and larger populations of cooperating agents provide an operational advantage, restraint itself can begin to look like a strategic disadvantage.
That is where Iran ceases to be the most important part of this story. The precedent, rather than the immediate target, could become the lasting consequence.
Which brings us back to Vu Tran. His claim that an AI company could already cripple a nation remains unproven. But the more consequential moment would come if a nation someday proved him right. The race would no longer be merely about building better artificial intelligence; it could become a race to ensure that an adversary did not acquire a strategic capability first.
Four days ago, Donald Trump reduced his view of the geopolitical competition over artificial intelligence to four words: **“WHOEVER WINS AI, WINS!”** That same day, he wrote that **“The only control or ‘guardrails’ that AI needs is a STRONG AND SMART (High IQ!) PRESIDENT.”**
Whether Trump had anything resembling the scenario described here in mind is impossible to know.
But if Vu Tran is even partly right, another question may eventually matter more:
whether any president, regardless of IQ, could control what winning that race might require.
