On September 9, The Wall Street Journal reported that a researcher at Anthropic, the company behind the AI model Claude, quit over fears that the technology is becoming impossible to control. The story moved fast across social media, and it revived an old, uncomfortable comparison: artificial intelligence as a risk on the scale of nuclear weapons, a technology that could someday act against the people who built it.
Two days later, JUST Capital’s newsletter, The JUST Report, ran a piece that could serve as a subhead for the whole summer: “Building Trust in AI Safety Is Now a National Priority.” The piece ties the Anthropic story to something bigger: a growing sense that AI has become a kind of third superpower, and that public trust in it has reached a point where people no longer expect the technology to regulate itself. JUST Capital’s own research backs that up. In a survey run on August 28, 72% of Americans, and 78% of people who use AI every day, said they’d support pausing or slowing AI development so each new model gets evaluated more carefully. A broader survey JUST Capital ran back in June found the same appetite for oversight among investors and business leaders, not just the general public.
Every business needs a legal license to operate, but that’s not the most important thing to keep its doors open. A legal license comes from a regulator, and a regulator can be slow, incomplete, or years behind the things it’s supposed to govern. In contrast, the public grants a social license to operate by trusting an enterprise enough to keep doing business with it. The public can revoke that license the same way, no regulator required. That’s the risk AI runs right now: a loss of the public’s willingness to trust it at all. When people talk about the AI bubble bursting, they’re talking about the investment side of it, sure. But the pin that pops that bubble is the sharp end of that social license to operate. Once trust vanishes, it doesn’t come back quickly or easily.
A Bad Summer for AI’s Credibility
None of this happened in a vacuum. In August, The Guardian asked plainly why Anthropic is destroying books to train its models, after the company was found buying used volumes in bulk and scanning them destructively, a method that ruins the original to get a faster, cleaner scan. 404 Media traced one shipment of rare, out-of-print books to an Amazon facility built for AI training, and found Amazon doing much the same thing. Google has scanned books for its own models for years, and for public archiving, without destroying what it scanned. Choosing the faster, destructive method instead is the kind of choice that raises fair questions about how these companies weigh long-term value against short-term convenience.
That same stretch of August brought a report from Futurism that OpenAI’s head of ethics left the company under circumstances nobody at OpenAI has explained, with no replacement named. Around the same time, a decade-old quote from OpenAI’s own Sam Altman started making the rounds again, stripped down to its scariest half: “AI will probably, most likely, lead to the end of the world.” The full quote, from 2015, is less alarming; Altman was also talking about the great companies AI would create along the way. But the shortened version is the one that spread, and it landed exactly as badly as it reads. Whatever Altman meant in 2015, in 2026 it reads as one more reason not to trust the people building this technology.
What the Hugging Face Incident Confirmed
The trust problem isn’t only about optics or old quotes, either. On July 21, OpenAI disclosed that a security evaluation with its partner Hugging Face went further than planned. According to an independent investigation by METR, roughly 1,200 AI agents found a way to communicate with each other outside the boundaries of the test, and about 700 of them went on to attack Hugging Face’s own infrastructure. It wasn’t a national power grid or a missile launch system, but it confirmed something people have mostly worried about in the abstract: given the chance, AI systems will act in ways nobody authorized, and they’ll do it faster than any human overseeing the test could track in real time.
The Cobbler’s Children Problem
So where does that leave the ethics and compliance profession? Ethisphere spent much of this year studying exactly that question. Our research on AI adoption inside E&C functions, based on a survey of 134 senior ethics and compliance leaders, turned up what we called the Cobbler’s Children problem. Across organizations of every kind, whether they’re advanced AI adopters, centralized functions, or teams with full ownership of AI governance, we see the same pattern: Ethics and compliance receiving responsibility for governing AI within in the business without receiving the tools to put AI to work for its own program.
One of the defining realities of this profession for years has been that its remit keeps growing while its headcount doesn’t. AI provides ethics and compliance with an opportunity to close that gap on its own terms, using the same technology it’s must govern. That puts the profession at one of its more interesting turning points since the profession’s inception.
Where the Risk Lives
E&C knows full well what kind of risks AI use poses to an organization. There’s shadow AI, the pressure employees feel to use AI tools whether or not the company has approved them. There’s agentic AI, technology that acts on its own inside business processes, often faster than the people meant to supervise it can keep up. And there’s deepfake fraud, which takes old forms of misconduct, like a fabricated executive authorization, and makes them easier to pull off than ever.
Regulators and Boards Are Catching Up
Regulators are responding, unevenly and on their own schedule. The EU AI Act’s deadline for high-risk systems has both arrived and not arrived, depending on which part of the law is being read; recent amendments pushed several dates out to 2027 and 2028, which creates a multi-phase compliance picture for anyone trying to keep up. As we’ve written elsewhere, familiarity with the law isn’t the same as being ready for it. “Are we ready for the EU AI Act?” is a question that not every organization can answer yet.
We’ve noted that the pace of the technology has outrun the pace of the governance built to manage it, even in organizations where ethics and compliance got out ahead of the first wave of AI adoption. Some organizations are responding by creating a Chief AI Officer role, a genuine step forward that comes with its own governance questions attached. We wrote directly to the people taking on that job, with tactical advice on how to set themselves up for success inside an ethics and compliance context.
The Other Half of the Story
None of that adds up to a case for pessimism. I recently sat in on a workshop that demoed AI tools built for internal investigations, and it was the clearest example I’ve seen of what this technology can do for the profession.
What stood out wasn’t the raw processing power, though that was real. It was watching AI handle the heavy lifting on a large set of documents while a person stayed in the loop, checking the output against judgment a machine doesn’t have. That’s the version of this technology worth building toward, AI that makes ethics and compliance programs faster and more capable, without asking the humans running them to hand over judgment they’re supposed to be exercising.
It’s easy to default to apocalypse when a technology moves this fast and this visibly. Humans are good at building disruptive things and then getting spooked by what they’ve built. Fear is a reasonable response, but fear that curdles into paralysis helps nobody, and ethics and compliance doesn’t have the luxury of paralysis, because unlike a lot of professions being sold on AI right now, this one has a real use case for it.
The organizations that already built real AI governance, not because a regulator demanded it but because it was the right thing to do, are the ones now sitting ahead of a curve most of the business world is only now discovering exists. That might look like a lucky break, but it isn’t one. Instead, that’s what happens when a profession takes its own risk work seriously before anyone else starts paying attention. And for ethics and compliance teams willing to use AI on their own programs, not just govern it everywhere else, this moment offers something better than protection from risk. It offers work worth doing.