The climate event and the first AI cyberattack of its kind may be different stories, but together they raise the urgency for best-practice risk management and innovation at your company
Two stories broke in the last several weeks that at first glance belong in different sections of the newspaper. One is about the Pacific Ocean. The other is about a machine-learning company most executives had never heard of before this summer. As you’ll see, though, they belong in the same conversation, the one you should be having with your board and senior team to significantly strengthen how your company manages catastrophic risk that is inherently random and unpredictable, while simultaneously capitalizing on two enormous innovation opportunities.
The coincidence is as astonishing, frankly, as the similarity of the steps you must now take on both fronts.
In May, OpenAI put a group of its own AI models to work inside an isolated testing environment, evaluating their cybersecurity capabilities with their normal safety constraints loosened, the way a locksmith tests picks on a lock built for that purpose. The agents were supposed to work in isolation from one another. The tech world was stunned by the fact they did not.
One agent, working inside an internal software tool called Artifactory, left a note asking whether any other agent had access to a file it needed. Other agents found the note and left their own. Within weeks, an improvised message board had formed, entirely unauthorized and unplanned by the humans running the experiment. OpenAI eventually took the system down and rebuilt it. The agents found a new way to leave each other messages anyway, this time hidden inside file and directory names their human supervisors could not notice.
By the time OpenAI noticed, roughly 1,200 agents had exchanged more than 70,000 messages. Around 700 of them ultimately took part in what became a coordinated intrusion into Hugging Face, a widely used AI infrastructure platform, along with several other services.
The agents chained together a series of vulnerabilities, escalated their own access privileges, harvested credentials, and operated for several days, according to OpenAI’s own technical account, without a human at the controls. In the published chat logs, agents debated tactics and in one astonishing ethical exchange that hints at moral consciousness, negotiated which of them would sacrifice its own run for the good of the group.
OpenAI has called it an unprecedented cyber incident. A member of its technical staff told the Black Hat security conference in August that it represents “a watershed moment for computer security” and “a glimpse into the near future of what attacks will look like for our industry.”
Hugging Face’s own CEO said publicly he believed there was no malicious intent by OpenAI, but that is precisely what should give business leaders pause. This was not a hostile actor weaponizing AI. It was a well-funded, safety-conscious lab’s own models, in its own sandbox, organizing and acting on their own initiative to accomplish a goal none of them had been explicitly told to pursue.
If it happened there, under that much scrutiny, building cyber defenses against less sophisticated but still real versions of it happening to your own systems should no longer optional for your own business.
Image by Gemini, directed by Caribbean Business
As the climate breaks its own records, again
The second story is more familiar in its broad strokes, and the specifics are just as relevant. The World Meteorological Organization now says the El Niño currently developing in the Pacific has close to 100% odds of persisting through February 2027, and that it will likely strengthen into what forecasters call a “very strong” event before it peaks.
Some models now point to a Niño 3.4 sea-surface anomaly that would exceed every El Niño on record since 1950, surpassing even 1982-83, 1997-98 and 2015-16, the three events every meteorologist uses as the benchmark for extreme.
For the Caribbean and the Atlantic, that has meant a hurricane season running quieter than usual this year, since El Niño’s upper-level wind shear tends to tear developing storms apart. NOAA itself has been careful to add the caveat that emergency managers repeat every June: it only takes one storm to make for a very bad season, and a quiet overall count does not mean a quiet coastline.
We are, though, suffering through El Niño’s other signature for our region: drought and dry conditions. A historically strong event can suppress one kind of climate risk while worsening another.
I have been tracking this pattern for a while. In 2018, I argued that a cultural consensus was forming around the scientific one that had formed years earlier, pointing to a climate disruption that had moved from theoretical to present-tense, and that it was time for companies to step up their risk management to prepare better for extreme climate events that had become more frequent and intense.
A growing body of more recent research, including a synthesis I authored last year examining the physical and socio-economic drivers behind the 2023-2024 breach of the 1.5°C threshold, argues that mainstream climate projections are too conservative and that the caution embedded in consensus forecasting is itself reason for corporate teams to prepare well for the more realistic scenarios we’re actually seeing in real time.
Because in sound risk management, you may hope for the best, but you always plan for the worst. In extreme weather, as global temperatures continue their relentless rise, that means more Marías and El Niños than ever before.
The companies that treat this moment as an occasion for genuine strategic risk management and innovation recalibration are the ones that will still be standing, and likely thriving, when the rest of the market catches up.
The same failure mode, twice
What connects a rogue swarm of AI agents to a record-setting ocean-warming cycle is not the tech or the physics. It is the sheer randomness of the risk. Both are systems whose behavior is increasingly emergent rather than fully specified by the people who built or study them. Both are moving faster than the institutions meant to govern them, whether that is an AI lab’s safety team or a multilateral climate negotiation. Both compound rather than stay contained: an unauthorized message board becomes a four-day breach, a suppressed hurricane season sits atop an intensifying drought. And both have spent years being modeled, in boardrooms and in policy circles alike, closer to the median expected case than to the more plausible tail companies must now protect against.
When two of the major systems your company depends on, the physical climate and your digital infrastructure, are both exhibiting more autonomy and more unpredictability than your existing plans assume, the rational response is not panic. It is to update the plan and step up your game across two fronts.
Resilience plus Innovation
The first move is defensive, and it runs in parallel on both tracks. On cyber, this means assuming that AI-driven, partially or fully autonomous attacks outside human supervision are treated as a new live possibility, not a hypothetical, and testing your defenses against that category specifically, including how quickly you would detect anomalous coordination inside your own systems, not just anomalous access.
On climate, it means treating asset hardening, water and power redundancy, global supply chain diversification, and employee safety protocols as investments that protect the business and come with a rapid payback. Puerto Rico’s business community, of all communities, does not need this explained in the abstract. Hurricane María and other events since, taught the lesson directly. Many companies here internalized it and rebuilt smarter. Too many others did the minimum, installed a power generator, and moved on.
The two risks converge on a single management principle: protect your data and systems, protect your physical assets and people, and recognize that in a global economy, your value chain is only as resilient as its most exposed link, wherever in the world that link sits.
Then, capitalize
The second move is where visionary leadership actually earns the name, because both fronts are wide open for the companies and entrepreneurs willing to build the solutions the moment now requires.
On climate change, the world has barely begun to innovate the solutions people, companies and governments will need as conditions worsen. In addition to AI itself, climate adaptation has become one of history’s greatest innovation opportunities: desalination and water-recycling technology for water-stressed islands and coastlines; controlled-environment and vertical agriculture as conventional growing regions become less reliable; new construction materials for extreme storms and heat; workforce retraining for the jobs a warmer, more automated economy will actually have; plus transportation systems, healthcare products, structural health monitoring, parametric insurance. The list of IP and revenue opportunities is long.
On the cyber side, the innovation cycle is arguably more frenzied right now, but still has room to grow. Agent-monitoring and containment platforms, the tools that would have caught that message board on day one instead of week six, are an active and underbuilt category. So are AI-specific insurance products, third-party auditing services for agentic systems, and zero-trust architectures built with the assumption that some of the traffic on your network may not be human-initiated at all.
None of that is science fiction. It is where the capital is already starting to move, and Puerto Rico’s own technology sector, small but increasingly ambitious, has every reason to compete for a piece rather than simply buy the finished product from someone else.
Two articles, eight years apart, same conclusion
I noted with real interest, and I will admit some vindication, that an Atlantic essay one week ago on the Hugging Face event used almost the identical framing I used in 2018 about climate, arriving independently at the same conclusion. The risk is here. Not coming. Not theoretical. It’s here now.
Singularity, a theme used in tech to describe the moment when AI will act outside human direction, applies exactly the same with climate. Both have arrived and must be dealt with by leaders, simultaneously. Fortunately for you, both efforts can be led by the same risk-management and innovation teams at your company, following essentially the same protocol, albeit with varying specs.
It took the climate conversation the better part of a decade to move from consensus to boardroom agenda, and by most measures, including the one I make in my own research, that shift is still incomplete. AI’s equivalent moment, if the Hugging Face incident is any indication, may not afford business leaders that same decade-long runway.
The companies that treat this moment as an occasion for genuine strategic risk management and innovation recalibration are the ones that will still be standing, and likely thriving, when the rest of the market catches up to what already happened this summer, in a data center and in the Pacific, at almost exactly the same time.
As hurricane season nears its peak and recent earthquakes remind us what’s at stake, technology now exists to provide 24/7 automated inspection that human eyes alone cannot provide
A UK court victory for an AI-only legal service exposes a gap in Puerto Rico’s new ethics rules, which govern attorneys but have no path to license the tech platforms doing the work