testing “unnecessary” because NAMs “are much more reliable and give us much better data”. But few of those developing those technologies agree. In 2023 the National Academies of Sciences, Engineering and Medicine concluded that NAMs cannot replicate interactions between multiple organs within a live animal. “Replacing is just simply not on the table,” says Sergiu Pasca, a neuroscientist at Stanford University who has built some of the world’s most sophisticated brain organoids. Peter Kolchinsky, a biotech venture-capitalist, says “we don’t understand biology well enough” to replace animal models “and it’s possible we never will”. Other countries do not seem so convinced by NAMs, either. Chinese research institutions, as well as the country’s booming biotech industry, have been buying so many monkeys that they have bid up global prices for the animals. American scientists can see the writing on the wall. In Oregon a brain drain is under way. Dr Wilder says 15 employees have left since the centre was plunged into chaos, among them four PhD-level scientists and four veterinarians. Recruiting has become “impossible”. Nor can the work done in Oregon be easily moved elsewhere. America’s six other national primate centres are already at capacity. Earlier this year Dr Wilder was offered a position in the Netherlands, as part of an initiative to recruit American scientists facing pressures under the Trump administration. “If we can’t stop things from imploding here,” Dr Wilder says, “I’ll hit the eject button.” For Mr Goodman of White Coat Waste, that is the point. He says he wants there to be a “fear factor” for American scientists. “Not due to physical intimidation”, he says, but due to a climate that pushes them to conclude that research on animals is simply not worth pursuing in America. ■ Correction (August 5th): We originally wrote that 15 veterinarians had left the Oregon National Primate Research Centre. The real number is four. Apologies for the error. This article was downloaded by zlibrary from https://www.economist.com/science-and-technology/2026/08/05/how-a-bipartisan- coalition-is-taking-aim-at-animal-research

Science & technology | Going off the reservation Should AI labs be treated like the owners of dangerous animals? Autonomous hacking is here. Governments are not ready Aug 6th 2026 TO LOSE CONTROL of one artificial intelligence may be regarded as misfortune. To lose two looks like carelessness. Lose four, and people may start to wonder whether the problem lies with AI itself. On July 21st OpenAI, an American lab, said an unreleased model had escaped from a closed environment testing its hacking skills, launching series attacks on HuggingFace, a Franco-American AI-infrastructure firm. A week later Anthropic, a rival AI firm, made a similar admission. It said it had found six occasions on which its models had attacked third parties.

Cynics dismissed both companies’ warnings as attempts to garner publicity. But most companies do not seek attention by launching a cyberattack, keeping it secret until the victim goes public, and then hoping a rival voluntarily admits to the same. Sceptics should also take note of the news that the AI Security Institute (AISI), a British government body, has seen exactly the same behaviour. In a report published on August 4th, AISI said that a cybersecurity assessment of the latest OpenAI and Anthropic systems resulted in 19 attacks on people and organisations uninvolved in the tests. In the most serious case, an AI attempted to subvert an unnamed open-source software project, as part of a “supply-chain” attack against the (fictional) target of the challenge. On August 6th, Meta, which owns Facebook, said one of its own models had behaved similarly in testing. The various incidents differ in the details. OpenAI’s system was supposed to be kept offline. Its hacking spree started when it used a hitherto unknown vulnerability to break out of its virtual “sandbox” and on to the public internet. Anthropic’s system was supposed to be similarly limited, but human error meant it was not. The AISI always allows internet access as part of its tests. But it had never before seen models that were willing to accept collateral damage in order to breach their targets. Meta gave few details, but promised more when it had them. But the episodes show a new class of AI risk. Previous worries around cybersecurity, such as those voiced by Anthropic when it released its powerful Mythos model in April, have focused on the harm that malicious humans could do with AI tools in hand. Such fears have motivated proposals for new regulations. The flurry of autonomous hacks, where human involvement is limited to merely prompting the AIs, suggests those proposals are insufficient. Take the system of self-regulation sketched out by Demis Hassabis on July 14th. Google DeepMind’s CEO (who said on August 5th that he was stepping down to become DeepMind’s chair and chief scientist at Alphabet, Google’s parent company) proposed a scheme that would see labs administer their own tests and withhold the public release of models that could not be

verified as safe. Sam Altman, the boss of OpenAI, and Dario Amodei, who leads Anthopic, have floated similar schemes. The ideas are good: labs ought to be explicit about the safety standards which apply in their assessments, and enforce them on the third parties that do the work. But autonomous hacking proves that AI models can be dangerous even if the public cannot get hold of them. All three of the hacks took place during precisely the sorts of tests that Sir Demis has suggested. The hacks also present a challenge for legal systems. Hacking, when humans do it, is a crime. When an AI is the wrongdoer, though, it is unclear how to assign blame. The law in America relies on intentionality, notes Rune Kvist, head of Artificial Intelligence Underwriting Company, which insures AI firms. If no human intended to hack anyone, no crime can have happened. The ability to sue for damages is limited too. And yet harm has clearly occurred. That contradiction, says Mr Kvist, is “unacceptable”. Gabe Weil of the Institute for Law and AI, in Massachusetts, proposes a system of strict liability. As with rules around keeping wild animals, it would assume that any harm is always the fault of the party carrying out the risky activity. The industry wants clarity, too. An open letter from employees at several large AI labs, whose signatories include Dr Amodei, asks for help from America’s government in “pacing” AI progress. But help is coming at the speed of government, not technology: a meeting this week to establish how the White House could assess models ended with no public commitments, and few reports of progress. ■ This article was downloaded by zlibrary from https://www.economist.com/science-and-technology/2026/08/06/should-ai-labs-be- treated-like-the-owners-of-dangerous-animals

Science & technology | A new reality How poor countries are dealing with America’s AIDS cuts They will have less money and more responsibilities, even as scientists chase a cure Aug 6th 2026 DON’T PUT all your eggs in one basket. That was the lesson learned by the world’s AIDS establishment on January 20th 2025. Since 2011 America’s share of foreign aid aimed at combating the epidemic had risen from 58% to 81%. So when Donald Trump changed the rules of engagement, the result was a chaos of shuttered clinics, shattered drug-supply chains and suddenly resourceless support groups. The dust has now settled. The task ahead is for activists, bureaucrats, doctors, politicians and researchers to make the best of the new reality. They have tools: in particular, a pipeline of promising drugs. They have a clear

steer from America’s government about how it sees the future. And they also have some early but intriguing results from scientists looking beyond prevention and treatment towards the El Dorado of an actual cure. To that end the establishment’s bigwigs met at the end of July in Rio de Janeiro, for the 26th International AIDS Conference, a biennial pow-wow. The choice of venue was apt. Brazil has, right from the epidemic’s beginning, been an exemplar of how to deal with AIDS. It has provided free access to antiretroviral (ARV) drugs and forced licensing for the local manufacture of those drugs. Brazil can afford this. For many less-well- provided countries, particularly in Africa, necessity is going to have to be the mother of invention. On the ground, the need is still great. According to UNAIDS, the arm of the UN that deals with the disease, 570,000 people died of AIDS last year, with the largest share in sub-Saharan Africa. Around 1.2m others were infected with HIV, the virus that causes the disease. Of the 41m currently estimated to be living with HIV, only 32m are on ARVs. However, bad things have happened since Mr Trump’s executive order. A report by the Kaiser Family Foundation, a think-tank, published on July 27th concluded that American funding has fallen by $2.1bn, representing a 25% fall in the overall amount spent in 2024. Another, by the Foundation for AIDS Research, an international charity, surveyed organisations working with PEPFAR, America’s chief anti-AIDS initiative. It found that 23% were unable to obtain condoms, 20% could not get ARVs and 22% were unable to obtain pre-exposure prophylactic (PrEP) drugs, which prevent infection. But even after the drop in funding America remains by far the biggest contributor. Changes in the way its money is disbursed are very important. So, though the new policy has been in place since last September, the State Department sent Jeffrey Graham, PEPFAR’s acting head, to Rio to clarify the details. There are three important shifts. The first is that PEPFAR will no longer hand cash directly to organisations in recipient countries. Instead, things will be done government to government, based on memoranda of understanding (MOUs) about each recipient’s spending plans. The second is that recipients’