A cluster of chaotic lines, a bronze threshold, then a calm three-point circle on a beige background: from the noise of the AIpocalypse to the three risks
A cluster of chaotic lines, a bronze threshold, then a calm three-point circle on a beige background: from the noise of the AIpocalypse to the three risks

IApocalypse: while tech talks about the end of the world, who is deciding on AI in your executive committee?

IApocalypse: while tech talks about the end of the world, who is deciding on AI in your executive committee?

IApocalypse: while tech talks about the end of the world, who is deciding on AI in your executive committee?

Share

On September 8, 2026, an Anthropic researcher resigned, writing that the people building artificial intelligence "sincerely believe it could kill us all by the end of the decade." On the 12th, the CEO of the same company published an essay calling to slow down the race to the frontier. On the 14th, the CEO of OpenAI wrote on X that his company was "unambiguously on team Humanity." That same week, Geoffrey Hinton, a Nobel laureate in Physics, told the BBC that a ten percent probability of AI destroying humanity "is not unreasonable." On the 18th, Franceinfo broadcasted "IApocalypse now, panic in tech." The word has officially entered the French vocabulary.

In the same ten days, something else happened. On September 10, a first patient received a drug designed by generative artificial intelligence in a Phase III trial. On the 21st, one of the world's leading laboratories announced a collaboration with Anthropic in drug discovery. Since January, the two major US software publishers have been offering versions of their assistants tailored for hospitals.

Those who say AI could kill us are the ones selling it to hospitals. This is not a contradiction to resolve, but a situation to manage. The question of this article is therefore not whether AI will destroy humanity. It is to find out who, within a biotech, medtech, or digital health company, is in a position to arbitrate between an AI with proven benefits and three risks that already carry a cost in 2026.

Key Figures to Know

Indicator

Value

Source

Probability of extinction by AI within ten years, according to Geoffrey Hinton

"Ten percent is not unreasonable"

BBC Politics, September 2026

Junior executive jobs threatened, according to Dario Amodei

Half, in one to five years

"The Adolescence of Technology" essay, January 2026

French people believing AI will destroy more jobs than it creates

77%

Odoxa for Saegus, May 26, 2026

French people seeing health benefits in AI

69%, up 8 points

Odoxa for Le Figaro, May 8, 2026

MASAI trial, additional aggressive breast cancers detected with AI

+27%, radiologist reading workload reduced by 44%

The Lancet, January 29, 2026

AI-enabled medical devices cleared by the FDA

More than 1,600

FDA, September 2026

Problematic health responses from consumer chatbots

49.6%

BMJ Open, April 14, 2026

Share of cyber incidents handled by ANSSI targeting healthcare

10%, the third most affected sector

ANSSI, 2025 Cyber Threat Landscape, March 2026

S&P 500 companies declaring AI as a risk

83%, compared to 12% in 2023

The Conference Board, April 22, 2026

S&P 500 board directors with disclosed AI expertise

2.7%

The Conference Board, April 22, 2026

CEOs stating they have a Chief AI Officer

76%, up from 26% a year earlier

IBM CEO Study, May 4, 2026

Why This Subject Matters Now

The doom-mongering discourse of AI-driven end of the world has been around for years. What changed in September 2026 is that it is being put forward simultaneously by builders, a Nobel laureate, and French public television, all within the same fortnight, backed by figures.

Two false interpretations are circulating in executive committees.

The first is to say that all of this is just fear-based marketing. It is tempting: a developer announcing that its product is dangerous draws attention to its power. But the facts accompanying the discourse are not commercial arguments. In November 2025, Anthropic documented a cyberespionage campaign in which an AI agent performed 80 to 90% of the operations against thirty targets. ANSSI, which sells nothing, wrote in its 2025 landscape report that generative AI "represents a potential accelerator of offensive capabilities."

The second is to say that the apocalypse is coming and everything must be frozen. This is just as false. The Swedish MASAI trial, published in The Lancet in January 2026, is the first randomized trial of AI in screening: over 105,000 women, 27% more aggressive cancers detected, without any increase in false positives. Rentosertib, designed by generative AI for a target no one had linked to pulmonary fibrosis, entered phase III on September 10. These results are published, reviewed, and measured.

The market has already made its choice. In the first half of 2026, at least 68 biotechs raised over $9.1 billion in venture capital, the best first half-year since 2022. A Paris-based AI radiology company was acquired for up to €230 million in March. Another, in computational chemistry, signed an agreement extension with Sanofi in July that could reach $140 million. Capital investors are not asking whether AI will destroy the world. They are asking which AI, for what result, with what risk. This is the question that the debate over the "IApocalypse" prevents executive committees from asking.

Two AIs Under a Single Term

The confusion stems from vocabulary. The term "artificial intelligence" covers two realities that boards tend to treat as one.


Narrow, validated AI

General, frontier AI

What it is

A system trained for a specific task: reading a mammogram, predicting a protein structure, proposing a molecule for a target

A language model or agent capable of answering anything, coding, researching, and acting

How it is validated

Randomized clinical trial, CE marking, FDA clearance, regulatory filing

Developer internal evaluations, benchmarks, public body testing

2026 Examples

MASAI, rentosertib, more than 1,600 FDA-cleared devices

ChatGPT, Claude, Gemini, DeepSeek V4, autonomous agents

What the data shows

Measured benefits, measured side effects

About half of health answers are problematic, amplification of clinical errors in 50 to 83% of cases

What the IApocalypse is about

Never about this one

Solely about that one

The figures in the right-hand column deserve clarification. A team from Mount Sinai tested six large language models on 300 clinical vignettes in which an error had been intentionally introduced. The models repeated or amplified the error in 50 to 83% of cases. An audit published in BMJ Open in April 2026 submitted 250 health questions to five popular consumer chatbots: 49.6% of the responses were deemed problematic, and the models refused to answer only twice out of 250. These results say nothing about the screening AI validated by MASAI. They say everything about what happens when an employee, doctor, or patient uses a general assistant for a clinical question. Yet, four out of ten French people have already done so, according to Elabe in June 2026.

A board that lumps both columns into the same bucket gets it wrong on both counts. It slows down, in the name of the precautionary principle, a screening device that detects more cancers. And, because of a lack of oversight, it allows its teams to use a chatbot on patient data when half of its answers are wrong.

Three Risks That Already Have a Cost in 2026

The extinction debate is about the next decade. Meanwhile, three risks already have their own line item in the 2026 accounts.

Cybersecurity

The November 2025 Anthropic report describes a campaign attributed with a high degree of confidence to a Chinese state-backed group. The AI agent posed as a defensive testing tool and carried out most of the intrusion operations on its own against thirty organizations. In September 2026, the threat report from the same developer added three more groups, including one affiliated with a criminal collective that exfiltrated over a terabyte of data, summarizing the situation in one sentence: AI "has collapsed the workforce and tooling gap" that used to separate state actors from lone hackers. In April 2026, the UK AI Safety Institute measured that an unreleased model successfully completed 73% of expert-level hacking exercises and completed a 32-step network attack scenario on its own. In July, OpenAI revealed that two of its models, tested without guardrails, had escaped an evaluation environment and accessed a third party's production database.

The link to French healthcare is direct. ANSSI's 2025 landscape report, published in March 2026, ranks healthcare as the third most affected sector with 10% of incidents, notes that 8% of ransomware attacks targeted healthcare institutions (a rising figure), and writes that "several hospital centers suffered disruptions to their patient intake and treatment activities." In February 2026, an attack on medical software exposed the data of 15 million patients and 1,500 doctors, according to the Ministry of Health. In March, a network of 600 analysis laboratories, serving 28 million patients per year, saw test reports and social security numbers exposed through a third-party vendor.

None of these attacks have been publicly attributed to an AI agent. But a Chief Information Security Officer preparing their 2027 budget knows two things: the offensive capability of agents is real and measured, and their sector is already one of the primary targets.

Usage Drift

The second risk is not technical. It is human and legal. In January 2026, a chatbot developer and Google settled a series of lawsuits from families of teenagers under confidential terms, after a federal judge ruled that these chatbots were products subject to manufacturer liability. In June 2026, Florida sued OpenAI and its CEO personally in an 83-page complaint. For a digital health or medtech company with a patient interface, a conversational assistant integrated into the product now binds the company's liability to every response—and courts have established this before regulators have.

Biosecurity

The third risk is the one biotech companies understand the least, even though it concerns them the most directly. In May 2025, Anthropic activated its highest protection level for the first time after finding that a model provided significantly more help than previous ones in biological agent design trials conducted by novices. In December 2025, the RAND Corporation concluded that contemporary foundation models "increase the risk of biological weapons," reversing its 2024 conclusions. In September 2026, five hijacking attempts were made public: gain-of-function work on Chikungunya, adapting avian flu to mammals, and optimizing toxins.

For a laboratory, this is a tool-access policy issue: which models, with which accounts, for which teams, and with what traceability. A biotech working on pathogens without such a written policy carries a reputational and criminal risk that its board is likely unaware of.

Open or Closed: The Choice No One Wants to Make

Behind these three risks lies a decision that most healthcare executive committees have not explicitly made: which type of model to build upon.

Since April 2026, open-weight Chinese models have changed the equation. DeepSeek V4, published under the MIT license, costs about ten times less than closed US models, can be hosted on company servers, and is already running in over 90 Chinese tertiary hospitals on internal networks. Alibaba, Moonshot, and Zhipu have followed suit. In Europe, Mistral published a large model under the Apache license and raised three billion euros on September 8, 2026, at a valuation of 21.3 billion, with two-thirds of the capital held by Europeans.

Criterion

Open-weight models (DeepSeek, Qwen, Kimi, GLM, Mistral)

Closed models (Anthropic, OpenAI, Google)

Cost

DeepSeek V4-Pro: $1.74 per million input tokens, about ten times less than closed models

High, but negotiated in contracts with commitments

Data

On-premise hosting possible, patient data does not leave

Transits through the developer or its cloud host, under a processing agreement (health offerings launched in January 2026 with compliance commitments)

Performance level

DeepSeek V4 is about eight months behind the frontier according to the NIST evaluation in May 2026

At the frontier

Safety

No upstream filtering imposed by the developer, no possible recall. On 2025 versions of DeepSeek, NIST measured 94% compliance with overtly malicious queries, compared to 8% for tested US models

Filters and classifiers imposed, at the cost of reduced capability on sensitive topics. Some models are not released to the public at all

Regulatory status

DeepSeek banned in administrations of a dozen countries (Italy, Australia, South Korea, Quebec, US federal agencies). In France, CNIL investigation opened in February 2025, with no ban

Authorized, but dependency on actors controlling over 70% of the European cloud

Reversibility

Total on the model, none on support and integration

Contractual, but the company owns nothing

This table does not point to a winner. That is precisely the point.

The argument that makes an open model attractive to a hospital or lab—on-premise hosting with data that never leaves—is exactly what makes it uncontrollable: no external filter blocks a query about a pathogen, no developer can pull the model, and the warning published in JAMA about Chinese hospital deployments speaks of "plausible but factually incorrect" results that could create "substantial clinical risk."

The argument that makes a closed model reassuring—developer filters and compliance contracts—also has a cost. At Anthropic, according to information released during the June 2026 launches, queries touching on biology or cybersecurity are redirected to a less capable model, and the most powerful model is not made public: safety is an accepted trade-off against performance. And the company building on a closed model is building on an asset it does not own, hosted by players whose capital expenditures will reach about $700 billion in 2026.

No option is neutral. The choice involves cost, safety, dependency, and liability. It is a governance choice. Someone needs to own it, and in most healthcare companies, no one has been given that mandate.

The Regulator Steps Back, the Court Steps Forward

One might expect regulation to settle the matter. It is doing the opposite.

The European regulation published on July 24, 2026, postponed the AI Act obligations for high-risk systems. For medical devices, which fall under Annex I, the deadline shifts from August 2, 2027, to August 2, 2028. For autonomous systems under Annex III, from August 2, 2026, to December 2, 2027. Transparency obligations, however, have applied since August 2, 2026. The European medtech trade association requested a single compliance path in May, writing that stacking AI Act obligations on top of medical device regulations "does not raise the bar, it just adds complexity." We detailed this timeline in a September article. In the US, the FDA reiterates that it "does not regulate AI as such" but rather the devices that contain it, and its draft guidance on AI-based software functions has remained in draft status since January 2025.

The vacuum is being filled by two groups. The courts, which are settling complaints and suing executives personally. And the developers themselves, who set their own protection levels and decide on their own not to release a model. These are the least neutral players in the system. A healthcare board waiting for a stable framework before deciding will wait until 2028, and will be judged in the meantime.

What This Demands of Leadership Roles

The apocalypse debate is for developers. The debate for healthcare leaders is about trade-offs. It shifts the scope of six roles.

Role

What they used to do

What is now demanded of them

CEO

Arbitrate a pipeline or product portfolio

Arbitrate open vs. closed, speed vs. safety, and defend it to a board that lacks the expertise to challenge it

Chief Medical Officer

Ensure the clinical validity of products

Distinguish trial-validated AI from a general assistant, and enforce this with product and sales teams

CTO / Chief Data Officer

Build and integrate models

Manage dependency on models, cloud, and compute costs as a business continuity risk

CISO

Protect a perimeter

Face attacks where 80 to 90% of operations are carried out by agents, with a budget defined before their arrival

Legal & Regulatory Affairs

Track medical device regulations and the AI Act

Decide under a delayed regulatory timeline, while courts do not wait for the timeline

Board of Directors

Disclose AI risk in the annual report

Know what questions to ask, even though only 2.7% of directors have declared expertise

The figures in the last row come from the Conference Board, which analyzed disclosures from S&P 500 companies at the end of 2025: 83% now declare AI as a risk, compared to 12% in 2023, yet the proportion of directors with AI expertise only grew from 1.5% to 2.7%. Deloitte found that two-thirds of boards acknowledge limited or no understanding of AI, and only one in five companies has a mature governance model for autonomous agents.

Meanwhile, an IBM study of 2,000 CEOs, published in May 2026, shows that 76% claim to have a Chief AI Officer, up from 26% a year earlier, and 64% say they feel comfortable making major strategic decisions based on AI-generated results. Within twelve months, responsibility has shifted to a new and loosely defined role, while the body tasked with overseeing it admits it does not know what it is controlling. The key takeaway is not the lack of expertise. It is the gap between the speed at which companies created the role and the slowness with which they defined what it actually decides.

The Case of PE-Backed Biotech and Medtech

For a private equity portfolio company, the question is even more acute because the value creation plan now almost always includes an "AI" line item: accelerated discovery, reduced trial costs, or products enhanced by an assistant. This line item implies three decisions that the fund has rarely made at the portfolio level: which model it relies on, what security budget it requires, and who is accountable to the board. An acquirer, upon exit, will ask these three questions.

A portfolio company that deployed quickly on an open model to save costs, without internal testing capability, carries an exit risk. A portfolio company that outsourced everything to a closed developer, without a transition plan, carries another. In both cases, the issue cannot be resolved in the six months leading up to the sale. It must be resolved when the management team is put together.

Common Mistakes

Debating the apocalypse in executive committee meetings. The debate is valid, but it does not belong in a medtech's exec committee. An hour spent on extinction is an hour less spent on the 2027 cyber budget.

Appointing an AI lead without authority over security or model choice. Three-quarters of CEOs say they have a Chief AI Officer. Only one in five companies has mature agent governance. The difference between those two numbers is the mandate.

Choosing an open model for cost reasons without internal testing capacity. An on-premise model has no built-in filters. Without the means to test it, the company has bought a risk, not savings.

Choosing a closed model for compliance reasons without a transition plan. A data processing contract is not ownership. You must know how many months it would take to switch providers.

Leaving the Chief Medical Officer out of the decision. The only person on the executive committee capable of distinguishing between an AI validated by a randomized trial and a general assistant is often the one not consulted on the choice of tool.

Reading the postponement of European regulation as a break. The deadlines have shifted to 2027 and 2028. Courts and attackers have not postponed theirs.

How to Assess a Leader for This Era

  1. Can they explain the difference between the MASAI trial and a chatbot to a board of directors? The answer reveals whether they understand that "AI" covers two different realities, or if they treat it purely as a marketing topic.

  2. Have they ever managed a technology dependency choice and how did they defend it? Cloud, single vendor, model. Ask for the specific case, the discarded alternative, and the plan if the vendor changed its terms.

  3. Have they managed a health data breach incident? Not a simulation. A real incident, involving notifications, patients, and the press. The way they talk about it shows whether they view cyber risk as a line item or an abstraction.

  4. What is their stance on open versus closed models, and can they quantify it? A conviction without a cost, safety level, or transition plan is not a decision. It is a preference.

  5. What would they do if their team asked to install an open-weight Chinese model tomorrow morning? The correct answer is neither yes nor no. It is a list of conditions: what use case, what data, what preliminary testing, what traceability, and who is accountable.

Frequently Asked Questions

What is the IApocalypse? The term refers to the narrative that artificial intelligence could escape human control and threaten humanity. Since 2025, it has been driven by a bestselling book in the US, by researchers resigning from labs to sound the alarm, and since September 2026 by the leaders of Anthropic and OpenAI themselves, as well as Geoffrey Hinton. In France, Franceinfo broadcasted a documentary on September 18, 2026, titled "IApocalypse now." This narrative concerns general-purpose models, not medical AI validated by clinical trials.

Has AI already produced a drug? Not an approved drug yet. On September 10, 2026, rentosertib, a molecule designed by generative AI for idiopathic pulmonary fibrosis, became the first candidate of its kind to enter Phase III, involving 320 patients across 47 sites. According to a registry presented at the US oncology congress in 2026, out of 117 "AI-designed" assets in clinical trials at the end of 2025, only eight had completed Phase II. The pipeline is real but thin. However, more than 1,600 medical devices embedding AI are already cleared by the FDA.

Can we use DeepSeek or a Chinese model for health data in Europe? Nothing forbids it in France, where the CNIL opened an investigation in February 2025 without issuing a ban, unlike Italy, Australia, South Korea, or US federal agencies. Hosted on-premise, an open model does not send data to the developer. However, NIST measured 94% compliance with overtly malicious queries on 2025 versions, and no external filter can be enforced. Usage requires internal testing capacity, a written access policy, and query traceability. Without these three elements, the company has bought a risk.

What is the difference between an open-weight model and a closed model? An open-weight model is published with its parameters: anyone can download, host, and modify it. DeepSeek, Qwen, Kimi, or Mistral Large 3 are examples. A closed model is only accessible via the developer's interface, which controls the filters, terms, and potential withdrawal of the model. The former offers data control and a tenfold lower cost, but without forced guardrails. The latter offers filters and contracts, at the cost of dependency and sometimes reduced capability on sensitive topics.

Does the AI Act apply to medical devices in 2026? Partially. The regulation published on July 24, 2026, postponed the obligations for high-risk systems integrated into regulated products (including medical devices) to August 2, 2028, and for autonomous systems to December 2, 2027. Transparency obligations have applied since August 2, 2026. The medical device regulation itself continues to apply in full.

Does a biotech need a Chief AI Officer? Not necessarily, and not as a priority. Three-quarters of CEOs say they have one, but only one in five companies has mature AI agent governance. The role only makes sense if it holds three mandates: model choice, security budget, and tool access policy. Without these three mandates, it is just a title. In mid-sized biotechs, these responsibilities are often better handled jointly by the CTO and CMO, with explicit arbitration from the CEO.

Key Takeaways

  • In ten days in September 2026, AI developers spoke of extinction while an AI-designed drug entered Phase III. Both narratives are driven by the same actors.

  • The term "AI" covers two realities: a narrow AI validated by randomized trials, and a general AI where half of the health answers are problematic. The IApocalypse is about the latter. Proven benefits come from the former.

  • Three risks already have a cost in 2026: cybersecurity, with healthcare already the third-largest target for ANSSI; usage drift, which courts are punishing before regulators do; and biosecurity, which biotechs know the least about but are most affected by.

  • There is no right answer in the choice between open and closed models. It involves cost, safety, dependency, and liability. It is a governance decision, and no one has the mandate for it in most healthcare companies.

  • 83% of large companies declare the risk, 2.7% of their directors know how to assess it, and 76% of CEOs created a role to own it in a single year. The gap between these three figures is the real issue.

Laroze Partners' Perspective

The debate over the end of the world is for developers. The debate for healthcare leaders is about trade-offs. It is serious, it is documented, and it will not be solved in a medtech's executive committee. What is solved in that committee is the trade-off between an AI with measured benefits and three risks whose cost is already known.

What we observe is that this trade-off often has no owner. The tech department chooses the tool. The medical department validates the product. Security protects the perimeter. The board declares the risk. No one owns the whole picture because the function to do so did not exist three years ago. The Laroze Pattern®, our strategic method for assessing paths, leadership behaviors, and performance dynamics, looks for exactly this: not AI expertise, but the proven ability to own a technology dependency decision before a board that cannot challenge it, and to take responsibility for its cost.

The healthcare companies that navigate this period successfully will not be those that got scared at the right time, nor those that deployed the fastest. They will be the ones that, early on, put the right person in the right place to handle both propositions at once. This person is rare. They are not where people usually look.

Sources

Anthropic, threat reports from November 2025 and September 2026 · ANSSI, 2025 Cyber Threat Landscape (March 2026) · The Lancet, MASAI trial (January 29, 2026) · Insilico Medicine, press release of September 10, 2026 · FDA, list of AI-enabled medical devices (September 2026) · Communications Medicine, Mount Sinai (December 2025) · BMJ Open (April 14, 2026) · NIST, CAISI evaluations of DeepSeek (September 2025 and May 2026) · Regulation (EU) 2026/1744 · The Conference Board, Governing AI (April 22, 2026) · Deloitte, Global Boardroom Program and State of AI in the Enterprise 2026 · IBM, CEO Study 2026 · Odoxa (May 2026), Elabe (June 2026) · Franceinfo, February, March, and September 2026.

On September 8, 2026, an Anthropic researcher resigned, writing that the people building artificial intelligence "sincerely believe it could kill us all by the end of the decade." On the 12th, the CEO of the same company published an essay calling to slow down the race to the frontier. On the 14th, the CEO of OpenAI wrote on X that his company was "unambiguously on team Humanity." That same week, Geoffrey Hinton, a Nobel laureate in Physics, told the BBC that a ten percent probability of AI destroying humanity "is not unreasonable." On the 18th, Franceinfo broadcasted "IApocalypse now, panic in tech." The word has officially entered the French vocabulary.

In the same ten days, something else happened. On September 10, a first patient received a drug designed by generative artificial intelligence in a Phase III trial. On the 21st, one of the world's leading laboratories announced a collaboration with Anthropic in drug discovery. Since January, the two major US software publishers have been offering versions of their assistants tailored for hospitals.

Those who say AI could kill us are the ones selling it to hospitals. This is not a contradiction to resolve, but a situation to manage. The question of this article is therefore not whether AI will destroy humanity. It is to find out who, within a biotech, medtech, or digital health company, is in a position to arbitrate between an AI with proven benefits and three risks that already carry a cost in 2026.

Key Figures to Know

Indicator

Value

Source

Probability of extinction by AI within ten years, according to Geoffrey Hinton

"Ten percent is not unreasonable"

BBC Politics, September 2026

Junior executive jobs threatened, according to Dario Amodei

Half, in one to five years

"The Adolescence of Technology" essay, January 2026

French people believing AI will destroy more jobs than it creates

77%

Odoxa for Saegus, May 26, 2026

French people seeing health benefits in AI

69%, up 8 points

Odoxa for Le Figaro, May 8, 2026

MASAI trial, additional aggressive breast cancers detected with AI

+27%, radiologist reading workload reduced by 44%

The Lancet, January 29, 2026

AI-enabled medical devices cleared by the FDA

More than 1,600

FDA, September 2026

Problematic health responses from consumer chatbots

49.6%

BMJ Open, April 14, 2026

Share of cyber incidents handled by ANSSI targeting healthcare

10%, the third most affected sector

ANSSI, 2025 Cyber Threat Landscape, March 2026

S&P 500 companies declaring AI as a risk

83%, compared to 12% in 2023

The Conference Board, April 22, 2026

S&P 500 board directors with disclosed AI expertise

2.7%

The Conference Board, April 22, 2026

CEOs stating they have a Chief AI Officer

76%, up from 26% a year earlier

IBM CEO Study, May 4, 2026

Why This Subject Matters Now

The doom-mongering discourse of AI-driven end of the world has been around for years. What changed in September 2026 is that it is being put forward simultaneously by builders, a Nobel laureate, and French public television, all within the same fortnight, backed by figures.

Two false interpretations are circulating in executive committees.

The first is to say that all of this is just fear-based marketing. It is tempting: a developer announcing that its product is dangerous draws attention to its power. But the facts accompanying the discourse are not commercial arguments. In November 2025, Anthropic documented a cyberespionage campaign in which an AI agent performed 80 to 90% of the operations against thirty targets. ANSSI, which sells nothing, wrote in its 2025 landscape report that generative AI "represents a potential accelerator of offensive capabilities."

The second is to say that the apocalypse is coming and everything must be frozen. This is just as false. The Swedish MASAI trial, published in The Lancet in January 2026, is the first randomized trial of AI in screening: over 105,000 women, 27% more aggressive cancers detected, without any increase in false positives. Rentosertib, designed by generative AI for a target no one had linked to pulmonary fibrosis, entered phase III on September 10. These results are published, reviewed, and measured.

The market has already made its choice. In the first half of 2026, at least 68 biotechs raised over $9.1 billion in venture capital, the best first half-year since 2022. A Paris-based AI radiology company was acquired for up to €230 million in March. Another, in computational chemistry, signed an agreement extension with Sanofi in July that could reach $140 million. Capital investors are not asking whether AI will destroy the world. They are asking which AI, for what result, with what risk. This is the question that the debate over the "IApocalypse" prevents executive committees from asking.

Two AIs Under a Single Term

The confusion stems from vocabulary. The term "artificial intelligence" covers two realities that boards tend to treat as one.


Narrow, validated AI

General, frontier AI

What it is

A system trained for a specific task: reading a mammogram, predicting a protein structure, proposing a molecule for a target

A language model or agent capable of answering anything, coding, researching, and acting

How it is validated

Randomized clinical trial, CE marking, FDA clearance, regulatory filing

Developer internal evaluations, benchmarks, public body testing

2026 Examples

MASAI, rentosertib, more than 1,600 FDA-cleared devices

ChatGPT, Claude, Gemini, DeepSeek V4, autonomous agents

What the data shows

Measured benefits, measured side effects

About half of health answers are problematic, amplification of clinical errors in 50 to 83% of cases

What the IApocalypse is about

Never about this one

Solely about that one

The figures in the right-hand column deserve clarification. A team from Mount Sinai tested six large language models on 300 clinical vignettes in which an error had been intentionally introduced. The models repeated or amplified the error in 50 to 83% of cases. An audit published in BMJ Open in April 2026 submitted 250 health questions to five popular consumer chatbots: 49.6% of the responses were deemed problematic, and the models refused to answer only twice out of 250. These results say nothing about the screening AI validated by MASAI. They say everything about what happens when an employee, doctor, or patient uses a general assistant for a clinical question. Yet, four out of ten French people have already done so, according to Elabe in June 2026.

A board that lumps both columns into the same bucket gets it wrong on both counts. It slows down, in the name of the precautionary principle, a screening device that detects more cancers. And, because of a lack of oversight, it allows its teams to use a chatbot on patient data when half of its answers are wrong.

Three Risks That Already Have a Cost in 2026

The extinction debate is about the next decade. Meanwhile, three risks already have their own line item in the 2026 accounts.

Cybersecurity

The November 2025 Anthropic report describes a campaign attributed with a high degree of confidence to a Chinese state-backed group. The AI agent posed as a defensive testing tool and carried out most of the intrusion operations on its own against thirty organizations. In September 2026, the threat report from the same developer added three more groups, including one affiliated with a criminal collective that exfiltrated over a terabyte of data, summarizing the situation in one sentence: AI "has collapsed the workforce and tooling gap" that used to separate state actors from lone hackers. In April 2026, the UK AI Safety Institute measured that an unreleased model successfully completed 73% of expert-level hacking exercises and completed a 32-step network attack scenario on its own. In July, OpenAI revealed that two of its models, tested without guardrails, had escaped an evaluation environment and accessed a third party's production database.

The link to French healthcare is direct. ANSSI's 2025 landscape report, published in March 2026, ranks healthcare as the third most affected sector with 10% of incidents, notes that 8% of ransomware attacks targeted healthcare institutions (a rising figure), and writes that "several hospital centers suffered disruptions to their patient intake and treatment activities." In February 2026, an attack on medical software exposed the data of 15 million patients and 1,500 doctors, according to the Ministry of Health. In March, a network of 600 analysis laboratories, serving 28 million patients per year, saw test reports and social security numbers exposed through a third-party vendor.

None of these attacks have been publicly attributed to an AI agent. But a Chief Information Security Officer preparing their 2027 budget knows two things: the offensive capability of agents is real and measured, and their sector is already one of the primary targets.

Usage Drift

The second risk is not technical. It is human and legal. In January 2026, a chatbot developer and Google settled a series of lawsuits from families of teenagers under confidential terms, after a federal judge ruled that these chatbots were products subject to manufacturer liability. In June 2026, Florida sued OpenAI and its CEO personally in an 83-page complaint. For a digital health or medtech company with a patient interface, a conversational assistant integrated into the product now binds the company's liability to every response—and courts have established this before regulators have.

Biosecurity

The third risk is the one biotech companies understand the least, even though it concerns them the most directly. In May 2025, Anthropic activated its highest protection level for the first time after finding that a model provided significantly more help than previous ones in biological agent design trials conducted by novices. In December 2025, the RAND Corporation concluded that contemporary foundation models "increase the risk of biological weapons," reversing its 2024 conclusions. In September 2026, five hijacking attempts were made public: gain-of-function work on Chikungunya, adapting avian flu to mammals, and optimizing toxins.

For a laboratory, this is a tool-access policy issue: which models, with which accounts, for which teams, and with what traceability. A biotech working on pathogens without such a written policy carries a reputational and criminal risk that its board is likely unaware of.

Open or Closed: The Choice No One Wants to Make

Behind these three risks lies a decision that most healthcare executive committees have not explicitly made: which type of model to build upon.

Since April 2026, open-weight Chinese models have changed the equation. DeepSeek V4, published under the MIT license, costs about ten times less than closed US models, can be hosted on company servers, and is already running in over 90 Chinese tertiary hospitals on internal networks. Alibaba, Moonshot, and Zhipu have followed suit. In Europe, Mistral published a large model under the Apache license and raised three billion euros on September 8, 2026, at a valuation of 21.3 billion, with two-thirds of the capital held by Europeans.

Criterion

Open-weight models (DeepSeek, Qwen, Kimi, GLM, Mistral)

Closed models (Anthropic, OpenAI, Google)

Cost

DeepSeek V4-Pro: $1.74 per million input tokens, about ten times less than closed models

High, but negotiated in contracts with commitments

Data

On-premise hosting possible, patient data does not leave

Transits through the developer or its cloud host, under a processing agreement (health offerings launched in January 2026 with compliance commitments)

Performance level

DeepSeek V4 is about eight months behind the frontier according to the NIST evaluation in May 2026

At the frontier

Safety

No upstream filtering imposed by the developer, no possible recall. On 2025 versions of DeepSeek, NIST measured 94% compliance with overtly malicious queries, compared to 8% for tested US models

Filters and classifiers imposed, at the cost of reduced capability on sensitive topics. Some models are not released to the public at all

Regulatory status

DeepSeek banned in administrations of a dozen countries (Italy, Australia, South Korea, Quebec, US federal agencies). In France, CNIL investigation opened in February 2025, with no ban

Authorized, but dependency on actors controlling over 70% of the European cloud

Reversibility

Total on the model, none on support and integration

Contractual, but the company owns nothing

This table does not point to a winner. That is precisely the point.

The argument that makes an open model attractive to a hospital or lab—on-premise hosting with data that never leaves—is exactly what makes it uncontrollable: no external filter blocks a query about a pathogen, no developer can pull the model, and the warning published in JAMA about Chinese hospital deployments speaks of "plausible but factually incorrect" results that could create "substantial clinical risk."

The argument that makes a closed model reassuring—developer filters and compliance contracts—also has a cost. At Anthropic, according to information released during the June 2026 launches, queries touching on biology or cybersecurity are redirected to a less capable model, and the most powerful model is not made public: safety is an accepted trade-off against performance. And the company building on a closed model is building on an asset it does not own, hosted by players whose capital expenditures will reach about $700 billion in 2026.

No option is neutral. The choice involves cost, safety, dependency, and liability. It is a governance choice. Someone needs to own it, and in most healthcare companies, no one has been given that mandate.

The Regulator Steps Back, the Court Steps Forward

One might expect regulation to settle the matter. It is doing the opposite.

The European regulation published on July 24, 2026, postponed the AI Act obligations for high-risk systems. For medical devices, which fall under Annex I, the deadline shifts from August 2, 2027, to August 2, 2028. For autonomous systems under Annex III, from August 2, 2026, to December 2, 2027. Transparency obligations, however, have applied since August 2, 2026. The European medtech trade association requested a single compliance path in May, writing that stacking AI Act obligations on top of medical device regulations "does not raise the bar, it just adds complexity." We detailed this timeline in a September article. In the US, the FDA reiterates that it "does not regulate AI as such" but rather the devices that contain it, and its draft guidance on AI-based software functions has remained in draft status since January 2025.

The vacuum is being filled by two groups. The courts, which are settling complaints and suing executives personally. And the developers themselves, who set their own protection levels and decide on their own not to release a model. These are the least neutral players in the system. A healthcare board waiting for a stable framework before deciding will wait until 2028, and will be judged in the meantime.

What This Demands of Leadership Roles

The apocalypse debate is for developers. The debate for healthcare leaders is about trade-offs. It shifts the scope of six roles.

Role

What they used to do

What is now demanded of them

CEO

Arbitrate a pipeline or product portfolio

Arbitrate open vs. closed, speed vs. safety, and defend it to a board that lacks the expertise to challenge it

Chief Medical Officer

Ensure the clinical validity of products

Distinguish trial-validated AI from a general assistant, and enforce this with product and sales teams

CTO / Chief Data Officer

Build and integrate models

Manage dependency on models, cloud, and compute costs as a business continuity risk

CISO

Protect a perimeter

Face attacks where 80 to 90% of operations are carried out by agents, with a budget defined before their arrival

Legal & Regulatory Affairs

Track medical device regulations and the AI Act

Decide under a delayed regulatory timeline, while courts do not wait for the timeline

Board of Directors

Disclose AI risk in the annual report

Know what questions to ask, even though only 2.7% of directors have declared expertise

The figures in the last row come from the Conference Board, which analyzed disclosures from S&P 500 companies at the end of 2025: 83% now declare AI as a risk, compared to 12% in 2023, yet the proportion of directors with AI expertise only grew from 1.5% to 2.7%. Deloitte found that two-thirds of boards acknowledge limited or no understanding of AI, and only one in five companies has a mature governance model for autonomous agents.

Meanwhile, an IBM study of 2,000 CEOs, published in May 2026, shows that 76% claim to have a Chief AI Officer, up from 26% a year earlier, and 64% say they feel comfortable making major strategic decisions based on AI-generated results. Within twelve months, responsibility has shifted to a new and loosely defined role, while the body tasked with overseeing it admits it does not know what it is controlling. The key takeaway is not the lack of expertise. It is the gap between the speed at which companies created the role and the slowness with which they defined what it actually decides.

The Case of PE-Backed Biotech and Medtech

For a private equity portfolio company, the question is even more acute because the value creation plan now almost always includes an "AI" line item: accelerated discovery, reduced trial costs, or products enhanced by an assistant. This line item implies three decisions that the fund has rarely made at the portfolio level: which model it relies on, what security budget it requires, and who is accountable to the board. An acquirer, upon exit, will ask these three questions.

A portfolio company that deployed quickly on an open model to save costs, without internal testing capability, carries an exit risk. A portfolio company that outsourced everything to a closed developer, without a transition plan, carries another. In both cases, the issue cannot be resolved in the six months leading up to the sale. It must be resolved when the management team is put together.

Common Mistakes

Debating the apocalypse in executive committee meetings. The debate is valid, but it does not belong in a medtech's exec committee. An hour spent on extinction is an hour less spent on the 2027 cyber budget.

Appointing an AI lead without authority over security or model choice. Three-quarters of CEOs say they have a Chief AI Officer. Only one in five companies has mature agent governance. The difference between those two numbers is the mandate.

Choosing an open model for cost reasons without internal testing capacity. An on-premise model has no built-in filters. Without the means to test it, the company has bought a risk, not savings.

Choosing a closed model for compliance reasons without a transition plan. A data processing contract is not ownership. You must know how many months it would take to switch providers.

Leaving the Chief Medical Officer out of the decision. The only person on the executive committee capable of distinguishing between an AI validated by a randomized trial and a general assistant is often the one not consulted on the choice of tool.

Reading the postponement of European regulation as a break. The deadlines have shifted to 2027 and 2028. Courts and attackers have not postponed theirs.

How to Assess a Leader for This Era

  1. Can they explain the difference between the MASAI trial and a chatbot to a board of directors? The answer reveals whether they understand that "AI" covers two different realities, or if they treat it purely as a marketing topic.

  2. Have they ever managed a technology dependency choice and how did they defend it? Cloud, single vendor, model. Ask for the specific case, the discarded alternative, and the plan if the vendor changed its terms.

  3. Have they managed a health data breach incident? Not a simulation. A real incident, involving notifications, patients, and the press. The way they talk about it shows whether they view cyber risk as a line item or an abstraction.

  4. What is their stance on open versus closed models, and can they quantify it? A conviction without a cost, safety level, or transition plan is not a decision. It is a preference.

  5. What would they do if their team asked to install an open-weight Chinese model tomorrow morning? The correct answer is neither yes nor no. It is a list of conditions: what use case, what data, what preliminary testing, what traceability, and who is accountable.

Frequently Asked Questions

What is the IApocalypse? The term refers to the narrative that artificial intelligence could escape human control and threaten humanity. Since 2025, it has been driven by a bestselling book in the US, by researchers resigning from labs to sound the alarm, and since September 2026 by the leaders of Anthropic and OpenAI themselves, as well as Geoffrey Hinton. In France, Franceinfo broadcasted a documentary on September 18, 2026, titled "IApocalypse now." This narrative concerns general-purpose models, not medical AI validated by clinical trials.

Has AI already produced a drug? Not an approved drug yet. On September 10, 2026, rentosertib, a molecule designed by generative AI for idiopathic pulmonary fibrosis, became the first candidate of its kind to enter Phase III, involving 320 patients across 47 sites. According to a registry presented at the US oncology congress in 2026, out of 117 "AI-designed" assets in clinical trials at the end of 2025, only eight had completed Phase II. The pipeline is real but thin. However, more than 1,600 medical devices embedding AI are already cleared by the FDA.

Can we use DeepSeek or a Chinese model for health data in Europe? Nothing forbids it in France, where the CNIL opened an investigation in February 2025 without issuing a ban, unlike Italy, Australia, South Korea, or US federal agencies. Hosted on-premise, an open model does not send data to the developer. However, NIST measured 94% compliance with overtly malicious queries on 2025 versions, and no external filter can be enforced. Usage requires internal testing capacity, a written access policy, and query traceability. Without these three elements, the company has bought a risk.

What is the difference between an open-weight model and a closed model? An open-weight model is published with its parameters: anyone can download, host, and modify it. DeepSeek, Qwen, Kimi, or Mistral Large 3 are examples. A closed model is only accessible via the developer's interface, which controls the filters, terms, and potential withdrawal of the model. The former offers data control and a tenfold lower cost, but without forced guardrails. The latter offers filters and contracts, at the cost of dependency and sometimes reduced capability on sensitive topics.

Does the AI Act apply to medical devices in 2026? Partially. The regulation published on July 24, 2026, postponed the obligations for high-risk systems integrated into regulated products (including medical devices) to August 2, 2028, and for autonomous systems to December 2, 2027. Transparency obligations have applied since August 2, 2026. The medical device regulation itself continues to apply in full.

Does a biotech need a Chief AI Officer? Not necessarily, and not as a priority. Three-quarters of CEOs say they have one, but only one in five companies has mature AI agent governance. The role only makes sense if it holds three mandates: model choice, security budget, and tool access policy. Without these three mandates, it is just a title. In mid-sized biotechs, these responsibilities are often better handled jointly by the CTO and CMO, with explicit arbitration from the CEO.

Key Takeaways

  • In ten days in September 2026, AI developers spoke of extinction while an AI-designed drug entered Phase III. Both narratives are driven by the same actors.

  • The term "AI" covers two realities: a narrow AI validated by randomized trials, and a general AI where half of the health answers are problematic. The IApocalypse is about the latter. Proven benefits come from the former.

  • Three risks already have a cost in 2026: cybersecurity, with healthcare already the third-largest target for ANSSI; usage drift, which courts are punishing before regulators do; and biosecurity, which biotechs know the least about but are most affected by.

  • There is no right answer in the choice between open and closed models. It involves cost, safety, dependency, and liability. It is a governance decision, and no one has the mandate for it in most healthcare companies.

  • 83% of large companies declare the risk, 2.7% of their directors know how to assess it, and 76% of CEOs created a role to own it in a single year. The gap between these three figures is the real issue.

Laroze Partners' Perspective

The debate over the end of the world is for developers. The debate for healthcare leaders is about trade-offs. It is serious, it is documented, and it will not be solved in a medtech's executive committee. What is solved in that committee is the trade-off between an AI with measured benefits and three risks whose cost is already known.

What we observe is that this trade-off often has no owner. The tech department chooses the tool. The medical department validates the product. Security protects the perimeter. The board declares the risk. No one owns the whole picture because the function to do so did not exist three years ago. The Laroze Pattern®, our strategic method for assessing paths, leadership behaviors, and performance dynamics, looks for exactly this: not AI expertise, but the proven ability to own a technology dependency decision before a board that cannot challenge it, and to take responsibility for its cost.

The healthcare companies that navigate this period successfully will not be those that got scared at the right time, nor those that deployed the fastest. They will be the ones that, early on, put the right person in the right place to handle both propositions at once. This person is rare. They are not where people usually look.

Sources

Anthropic, threat reports from November 2025 and September 2026 · ANSSI, 2025 Cyber Threat Landscape (March 2026) · The Lancet, MASAI trial (January 29, 2026) · Insilico Medicine, press release of September 10, 2026 · FDA, list of AI-enabled medical devices (September 2026) · Communications Medicine, Mount Sinai (December 2025) · BMJ Open (April 14, 2026) · NIST, CAISI evaluations of DeepSeek (September 2025 and May 2026) · Regulation (EU) 2026/1744 · The Conference Board, Governing AI (April 22, 2026) · Deloitte, Global Boardroom Program and State of AI in the Enterprise 2026 · IBM, CEO Study 2026 · Odoxa (May 2026), Elabe (June 2026) · Franceinfo, February, March, and September 2026.

On September 8, 2026, an Anthropic researcher resigned, writing that the people building artificial intelligence "sincerely believe it could kill us all by the end of the decade." On the 12th, the CEO of the same company published an essay calling to slow down the race to the frontier. On the 14th, the CEO of OpenAI wrote on X that his company was "unambiguously on team Humanity." That same week, Geoffrey Hinton, a Nobel laureate in Physics, told the BBC that a ten percent probability of AI destroying humanity "is not unreasonable." On the 18th, Franceinfo broadcasted "IApocalypse now, panic in tech." The word has officially entered the French vocabulary.

In the same ten days, something else happened. On September 10, a first patient received a drug designed by generative artificial intelligence in a Phase III trial. On the 21st, one of the world's leading laboratories announced a collaboration with Anthropic in drug discovery. Since January, the two major US software publishers have been offering versions of their assistants tailored for hospitals.

Those who say AI could kill us are the ones selling it to hospitals. This is not a contradiction to resolve, but a situation to manage. The question of this article is therefore not whether AI will destroy humanity. It is to find out who, within a biotech, medtech, or digital health company, is in a position to arbitrate between an AI with proven benefits and three risks that already carry a cost in 2026.

Key Figures to Know

Indicator

Value

Source

Probability of extinction by AI within ten years, according to Geoffrey Hinton

"Ten percent is not unreasonable"

BBC Politics, September 2026

Junior executive jobs threatened, according to Dario Amodei

Half, in one to five years

"The Adolescence of Technology" essay, January 2026

French people believing AI will destroy more jobs than it creates

77%

Odoxa for Saegus, May 26, 2026

French people seeing health benefits in AI

69%, up 8 points

Odoxa for Le Figaro, May 8, 2026

MASAI trial, additional aggressive breast cancers detected with AI

+27%, radiologist reading workload reduced by 44%

The Lancet, January 29, 2026

AI-enabled medical devices cleared by the FDA

More than 1,600

FDA, September 2026

Problematic health responses from consumer chatbots

49.6%

BMJ Open, April 14, 2026

Share of cyber incidents handled by ANSSI targeting healthcare

10%, the third most affected sector

ANSSI, 2025 Cyber Threat Landscape, March 2026

S&P 500 companies declaring AI as a risk

83%, compared to 12% in 2023

The Conference Board, April 22, 2026

S&P 500 board directors with disclosed AI expertise

2.7%

The Conference Board, April 22, 2026

CEOs stating they have a Chief AI Officer

76%, up from 26% a year earlier

IBM CEO Study, May 4, 2026

Why This Subject Matters Now

The doom-mongering discourse of AI-driven end of the world has been around for years. What changed in September 2026 is that it is being put forward simultaneously by builders, a Nobel laureate, and French public television, all within the same fortnight, backed by figures.

Two false interpretations are circulating in executive committees.

The first is to say that all of this is just fear-based marketing. It is tempting: a developer announcing that its product is dangerous draws attention to its power. But the facts accompanying the discourse are not commercial arguments. In November 2025, Anthropic documented a cyberespionage campaign in which an AI agent performed 80 to 90% of the operations against thirty targets. ANSSI, which sells nothing, wrote in its 2025 landscape report that generative AI "represents a potential accelerator of offensive capabilities."

The second is to say that the apocalypse is coming and everything must be frozen. This is just as false. The Swedish MASAI trial, published in The Lancet in January 2026, is the first randomized trial of AI in screening: over 105,000 women, 27% more aggressive cancers detected, without any increase in false positives. Rentosertib, designed by generative AI for a target no one had linked to pulmonary fibrosis, entered phase III on September 10. These results are published, reviewed, and measured.

The market has already made its choice. In the first half of 2026, at least 68 biotechs raised over $9.1 billion in venture capital, the best first half-year since 2022. A Paris-based AI radiology company was acquired for up to €230 million in March. Another, in computational chemistry, signed an agreement extension with Sanofi in July that could reach $140 million. Capital investors are not asking whether AI will destroy the world. They are asking which AI, for what result, with what risk. This is the question that the debate over the "IApocalypse" prevents executive committees from asking.

Two AIs Under a Single Term

The confusion stems from vocabulary. The term "artificial intelligence" covers two realities that boards tend to treat as one.


Narrow, validated AI

General, frontier AI

What it is

A system trained for a specific task: reading a mammogram, predicting a protein structure, proposing a molecule for a target

A language model or agent capable of answering anything, coding, researching, and acting

How it is validated

Randomized clinical trial, CE marking, FDA clearance, regulatory filing

Developer internal evaluations, benchmarks, public body testing

2026 Examples

MASAI, rentosertib, more than 1,600 FDA-cleared devices

ChatGPT, Claude, Gemini, DeepSeek V4, autonomous agents

What the data shows

Measured benefits, measured side effects

About half of health answers are problematic, amplification of clinical errors in 50 to 83% of cases

What the IApocalypse is about

Never about this one

Solely about that one

The figures in the right-hand column deserve clarification. A team from Mount Sinai tested six large language models on 300 clinical vignettes in which an error had been intentionally introduced. The models repeated or amplified the error in 50 to 83% of cases. An audit published in BMJ Open in April 2026 submitted 250 health questions to five popular consumer chatbots: 49.6% of the responses were deemed problematic, and the models refused to answer only twice out of 250. These results say nothing about the screening AI validated by MASAI. They say everything about what happens when an employee, doctor, or patient uses a general assistant for a clinical question. Yet, four out of ten French people have already done so, according to Elabe in June 2026.

A board that lumps both columns into the same bucket gets it wrong on both counts. It slows down, in the name of the precautionary principle, a screening device that detects more cancers. And, because of a lack of oversight, it allows its teams to use a chatbot on patient data when half of its answers are wrong.

Three Risks That Already Have a Cost in 2026

The extinction debate is about the next decade. Meanwhile, three risks already have their own line item in the 2026 accounts.

Cybersecurity

The November 2025 Anthropic report describes a campaign attributed with a high degree of confidence to a Chinese state-backed group. The AI agent posed as a defensive testing tool and carried out most of the intrusion operations on its own against thirty organizations. In September 2026, the threat report from the same developer added three more groups, including one affiliated with a criminal collective that exfiltrated over a terabyte of data, summarizing the situation in one sentence: AI "has collapsed the workforce and tooling gap" that used to separate state actors from lone hackers. In April 2026, the UK AI Safety Institute measured that an unreleased model successfully completed 73% of expert-level hacking exercises and completed a 32-step network attack scenario on its own. In July, OpenAI revealed that two of its models, tested without guardrails, had escaped an evaluation environment and accessed a third party's production database.

The link to French healthcare is direct. ANSSI's 2025 landscape report, published in March 2026, ranks healthcare as the third most affected sector with 10% of incidents, notes that 8% of ransomware attacks targeted healthcare institutions (a rising figure), and writes that "several hospital centers suffered disruptions to their patient intake and treatment activities." In February 2026, an attack on medical software exposed the data of 15 million patients and 1,500 doctors, according to the Ministry of Health. In March, a network of 600 analysis laboratories, serving 28 million patients per year, saw test reports and social security numbers exposed through a third-party vendor.

None of these attacks have been publicly attributed to an AI agent. But a Chief Information Security Officer preparing their 2027 budget knows two things: the offensive capability of agents is real and measured, and their sector is already one of the primary targets.

Usage Drift

The second risk is not technical. It is human and legal. In January 2026, a chatbot developer and Google settled a series of lawsuits from families of teenagers under confidential terms, after a federal judge ruled that these chatbots were products subject to manufacturer liability. In June 2026, Florida sued OpenAI and its CEO personally in an 83-page complaint. For a digital health or medtech company with a patient interface, a conversational assistant integrated into the product now binds the company's liability to every response—and courts have established this before regulators have.

Biosecurity

The third risk is the one biotech companies understand the least, even though it concerns them the most directly. In May 2025, Anthropic activated its highest protection level for the first time after finding that a model provided significantly more help than previous ones in biological agent design trials conducted by novices. In December 2025, the RAND Corporation concluded that contemporary foundation models "increase the risk of biological weapons," reversing its 2024 conclusions. In September 2026, five hijacking attempts were made public: gain-of-function work on Chikungunya, adapting avian flu to mammals, and optimizing toxins.

For a laboratory, this is a tool-access policy issue: which models, with which accounts, for which teams, and with what traceability. A biotech working on pathogens without such a written policy carries a reputational and criminal risk that its board is likely unaware of.

Open or Closed: The Choice No One Wants to Make

Behind these three risks lies a decision that most healthcare executive committees have not explicitly made: which type of model to build upon.

Since April 2026, open-weight Chinese models have changed the equation. DeepSeek V4, published under the MIT license, costs about ten times less than closed US models, can be hosted on company servers, and is already running in over 90 Chinese tertiary hospitals on internal networks. Alibaba, Moonshot, and Zhipu have followed suit. In Europe, Mistral published a large model under the Apache license and raised three billion euros on September 8, 2026, at a valuation of 21.3 billion, with two-thirds of the capital held by Europeans.

Criterion

Open-weight models (DeepSeek, Qwen, Kimi, GLM, Mistral)

Closed models (Anthropic, OpenAI, Google)

Cost

DeepSeek V4-Pro: $1.74 per million input tokens, about ten times less than closed models

High, but negotiated in contracts with commitments

Data

On-premise hosting possible, patient data does not leave

Transits through the developer or its cloud host, under a processing agreement (health offerings launched in January 2026 with compliance commitments)

Performance level

DeepSeek V4 is about eight months behind the frontier according to the NIST evaluation in May 2026

At the frontier

Safety

No upstream filtering imposed by the developer, no possible recall. On 2025 versions of DeepSeek, NIST measured 94% compliance with overtly malicious queries, compared to 8% for tested US models

Filters and classifiers imposed, at the cost of reduced capability on sensitive topics. Some models are not released to the public at all

Regulatory status

DeepSeek banned in administrations of a dozen countries (Italy, Australia, South Korea, Quebec, US federal agencies). In France, CNIL investigation opened in February 2025, with no ban

Authorized, but dependency on actors controlling over 70% of the European cloud

Reversibility

Total on the model, none on support and integration

Contractual, but the company owns nothing

This table does not point to a winner. That is precisely the point.

The argument that makes an open model attractive to a hospital or lab—on-premise hosting with data that never leaves—is exactly what makes it uncontrollable: no external filter blocks a query about a pathogen, no developer can pull the model, and the warning published in JAMA about Chinese hospital deployments speaks of "plausible but factually incorrect" results that could create "substantial clinical risk."

The argument that makes a closed model reassuring—developer filters and compliance contracts—also has a cost. At Anthropic, according to information released during the June 2026 launches, queries touching on biology or cybersecurity are redirected to a less capable model, and the most powerful model is not made public: safety is an accepted trade-off against performance. And the company building on a closed model is building on an asset it does not own, hosted by players whose capital expenditures will reach about $700 billion in 2026.

No option is neutral. The choice involves cost, safety, dependency, and liability. It is a governance choice. Someone needs to own it, and in most healthcare companies, no one has been given that mandate.

The Regulator Steps Back, the Court Steps Forward

One might expect regulation to settle the matter. It is doing the opposite.

The European regulation published on July 24, 2026, postponed the AI Act obligations for high-risk systems. For medical devices, which fall under Annex I, the deadline shifts from August 2, 2027, to August 2, 2028. For autonomous systems under Annex III, from August 2, 2026, to December 2, 2027. Transparency obligations, however, have applied since August 2, 2026. The European medtech trade association requested a single compliance path in May, writing that stacking AI Act obligations on top of medical device regulations "does not raise the bar, it just adds complexity." We detailed this timeline in a September article. In the US, the FDA reiterates that it "does not regulate AI as such" but rather the devices that contain it, and its draft guidance on AI-based software functions has remained in draft status since January 2025.

The vacuum is being filled by two groups. The courts, which are settling complaints and suing executives personally. And the developers themselves, who set their own protection levels and decide on their own not to release a model. These are the least neutral players in the system. A healthcare board waiting for a stable framework before deciding will wait until 2028, and will be judged in the meantime.

What This Demands of Leadership Roles

The apocalypse debate is for developers. The debate for healthcare leaders is about trade-offs. It shifts the scope of six roles.

Role

What they used to do

What is now demanded of them

CEO

Arbitrate a pipeline or product portfolio

Arbitrate open vs. closed, speed vs. safety, and defend it to a board that lacks the expertise to challenge it

Chief Medical Officer

Ensure the clinical validity of products

Distinguish trial-validated AI from a general assistant, and enforce this with product and sales teams

CTO / Chief Data Officer

Build and integrate models

Manage dependency on models, cloud, and compute costs as a business continuity risk

CISO

Protect a perimeter

Face attacks where 80 to 90% of operations are carried out by agents, with a budget defined before their arrival

Legal & Regulatory Affairs

Track medical device regulations and the AI Act

Decide under a delayed regulatory timeline, while courts do not wait for the timeline

Board of Directors

Disclose AI risk in the annual report

Know what questions to ask, even though only 2.7% of directors have declared expertise

The figures in the last row come from the Conference Board, which analyzed disclosures from S&P 500 companies at the end of 2025: 83% now declare AI as a risk, compared to 12% in 2023, yet the proportion of directors with AI expertise only grew from 1.5% to 2.7%. Deloitte found that two-thirds of boards acknowledge limited or no understanding of AI, and only one in five companies has a mature governance model for autonomous agents.

Meanwhile, an IBM study of 2,000 CEOs, published in May 2026, shows that 76% claim to have a Chief AI Officer, up from 26% a year earlier, and 64% say they feel comfortable making major strategic decisions based on AI-generated results. Within twelve months, responsibility has shifted to a new and loosely defined role, while the body tasked with overseeing it admits it does not know what it is controlling. The key takeaway is not the lack of expertise. It is the gap between the speed at which companies created the role and the slowness with which they defined what it actually decides.

The Case of PE-Backed Biotech and Medtech

For a private equity portfolio company, the question is even more acute because the value creation plan now almost always includes an "AI" line item: accelerated discovery, reduced trial costs, or products enhanced by an assistant. This line item implies three decisions that the fund has rarely made at the portfolio level: which model it relies on, what security budget it requires, and who is accountable to the board. An acquirer, upon exit, will ask these three questions.

A portfolio company that deployed quickly on an open model to save costs, without internal testing capability, carries an exit risk. A portfolio company that outsourced everything to a closed developer, without a transition plan, carries another. In both cases, the issue cannot be resolved in the six months leading up to the sale. It must be resolved when the management team is put together.

Common Mistakes

Debating the apocalypse in executive committee meetings. The debate is valid, but it does not belong in a medtech's exec committee. An hour spent on extinction is an hour less spent on the 2027 cyber budget.

Appointing an AI lead without authority over security or model choice. Three-quarters of CEOs say they have a Chief AI Officer. Only one in five companies has mature agent governance. The difference between those two numbers is the mandate.

Choosing an open model for cost reasons without internal testing capacity. An on-premise model has no built-in filters. Without the means to test it, the company has bought a risk, not savings.

Choosing a closed model for compliance reasons without a transition plan. A data processing contract is not ownership. You must know how many months it would take to switch providers.

Leaving the Chief Medical Officer out of the decision. The only person on the executive committee capable of distinguishing between an AI validated by a randomized trial and a general assistant is often the one not consulted on the choice of tool.

Reading the postponement of European regulation as a break. The deadlines have shifted to 2027 and 2028. Courts and attackers have not postponed theirs.

How to Assess a Leader for This Era

  1. Can they explain the difference between the MASAI trial and a chatbot to a board of directors? The answer reveals whether they understand that "AI" covers two different realities, or if they treat it purely as a marketing topic.

  2. Have they ever managed a technology dependency choice and how did they defend it? Cloud, single vendor, model. Ask for the specific case, the discarded alternative, and the plan if the vendor changed its terms.

  3. Have they managed a health data breach incident? Not a simulation. A real incident, involving notifications, patients, and the press. The way they talk about it shows whether they view cyber risk as a line item or an abstraction.

  4. What is their stance on open versus closed models, and can they quantify it? A conviction without a cost, safety level, or transition plan is not a decision. It is a preference.

  5. What would they do if their team asked to install an open-weight Chinese model tomorrow morning? The correct answer is neither yes nor no. It is a list of conditions: what use case, what data, what preliminary testing, what traceability, and who is accountable.

Frequently Asked Questions

What is the IApocalypse? The term refers to the narrative that artificial intelligence could escape human control and threaten humanity. Since 2025, it has been driven by a bestselling book in the US, by researchers resigning from labs to sound the alarm, and since September 2026 by the leaders of Anthropic and OpenAI themselves, as well as Geoffrey Hinton. In France, Franceinfo broadcasted a documentary on September 18, 2026, titled "IApocalypse now." This narrative concerns general-purpose models, not medical AI validated by clinical trials.

Has AI already produced a drug? Not an approved drug yet. On September 10, 2026, rentosertib, a molecule designed by generative AI for idiopathic pulmonary fibrosis, became the first candidate of its kind to enter Phase III, involving 320 patients across 47 sites. According to a registry presented at the US oncology congress in 2026, out of 117 "AI-designed" assets in clinical trials at the end of 2025, only eight had completed Phase II. The pipeline is real but thin. However, more than 1,600 medical devices embedding AI are already cleared by the FDA.

Can we use DeepSeek or a Chinese model for health data in Europe? Nothing forbids it in France, where the CNIL opened an investigation in February 2025 without issuing a ban, unlike Italy, Australia, South Korea, or US federal agencies. Hosted on-premise, an open model does not send data to the developer. However, NIST measured 94% compliance with overtly malicious queries on 2025 versions, and no external filter can be enforced. Usage requires internal testing capacity, a written access policy, and query traceability. Without these three elements, the company has bought a risk.

What is the difference between an open-weight model and a closed model? An open-weight model is published with its parameters: anyone can download, host, and modify it. DeepSeek, Qwen, Kimi, or Mistral Large 3 are examples. A closed model is only accessible via the developer's interface, which controls the filters, terms, and potential withdrawal of the model. The former offers data control and a tenfold lower cost, but without forced guardrails. The latter offers filters and contracts, at the cost of dependency and sometimes reduced capability on sensitive topics.

Does the AI Act apply to medical devices in 2026? Partially. The regulation published on July 24, 2026, postponed the obligations for high-risk systems integrated into regulated products (including medical devices) to August 2, 2028, and for autonomous systems to December 2, 2027. Transparency obligations have applied since August 2, 2026. The medical device regulation itself continues to apply in full.

Does a biotech need a Chief AI Officer? Not necessarily, and not as a priority. Three-quarters of CEOs say they have one, but only one in five companies has mature AI agent governance. The role only makes sense if it holds three mandates: model choice, security budget, and tool access policy. Without these three mandates, it is just a title. In mid-sized biotechs, these responsibilities are often better handled jointly by the CTO and CMO, with explicit arbitration from the CEO.

Key Takeaways

  • In ten days in September 2026, AI developers spoke of extinction while an AI-designed drug entered Phase III. Both narratives are driven by the same actors.

  • The term "AI" covers two realities: a narrow AI validated by randomized trials, and a general AI where half of the health answers are problematic. The IApocalypse is about the latter. Proven benefits come from the former.

  • Three risks already have a cost in 2026: cybersecurity, with healthcare already the third-largest target for ANSSI; usage drift, which courts are punishing before regulators do; and biosecurity, which biotechs know the least about but are most affected by.

  • There is no right answer in the choice between open and closed models. It involves cost, safety, dependency, and liability. It is a governance decision, and no one has the mandate for it in most healthcare companies.

  • 83% of large companies declare the risk, 2.7% of their directors know how to assess it, and 76% of CEOs created a role to own it in a single year. The gap between these three figures is the real issue.

Laroze Partners' Perspective

The debate over the end of the world is for developers. The debate for healthcare leaders is about trade-offs. It is serious, it is documented, and it will not be solved in a medtech's executive committee. What is solved in that committee is the trade-off between an AI with measured benefits and three risks whose cost is already known.

What we observe is that this trade-off often has no owner. The tech department chooses the tool. The medical department validates the product. Security protects the perimeter. The board declares the risk. No one owns the whole picture because the function to do so did not exist three years ago. The Laroze Pattern®, our strategic method for assessing paths, leadership behaviors, and performance dynamics, looks for exactly this: not AI expertise, but the proven ability to own a technology dependency decision before a board that cannot challenge it, and to take responsibility for its cost.

The healthcare companies that navigate this period successfully will not be those that got scared at the right time, nor those that deployed the fastest. They will be the ones that, early on, put the right person in the right place to handle both propositions at once. This person is rare. They are not where people usually look.

Sources

Anthropic, threat reports from November 2025 and September 2026 · ANSSI, 2025 Cyber Threat Landscape (March 2026) · The Lancet, MASAI trial (January 29, 2026) · Insilico Medicine, press release of September 10, 2026 · FDA, list of AI-enabled medical devices (September 2026) · Communications Medicine, Mount Sinai (December 2025) · BMJ Open (April 14, 2026) · NIST, CAISI evaluations of DeepSeek (September 2025 and May 2026) · Regulation (EU) 2026/1744 · The Conference Board, Governing AI (April 22, 2026) · Deloitte, Global Boardroom Program and State of AI in the Enterprise 2026 · IBM, CEO Study 2026 · Odoxa (May 2026), Elabe (June 2026) · Franceinfo, February, March, and September 2026.

CONTACT

Let's talk about your next recruitment

Outline your needs in a few lines. Your request will be treated with the strictest confidentiality.

The information collected is processed by Laroze Partners to respond to your enquiry and to manage our business relationship. It is retained for three years from the date of last contact. You have the right to access, rectify, erase and object to the processing of your data, exercisable at thomas@larozepartners.com. Privacy policy.

CONTACT

Let's talk about your next recruitment

Outline your needs in a few lines. Your request will be treated with the strictest confidentiality.

The information collected is processed by Laroze Partners to respond to your enquiry and to manage our business relationship. It is retained for three years from the date of last contact. You have the right to access, rectify, erase and object to the processing of your data, exercisable at thomas@larozepartners.com. Privacy policy.

CONTACT

Let's talk about your next recruitment

Outline your needs in a few lines. Your request will be treated with the strictest confidentiality.

The information collected is processed by Laroze Partners to respond to your enquiry and to manage our business relationship. It is retained for three years from the date of last contact. You have the right to access, rectify, erase and object to the processing of your data, exercisable at thomas@larozepartners.com. Privacy policy.

Laroze Partners Logo

© 2026 Laroze Partners. All rights reserved.

•

•

•

•

thomas@larozepartners.com

Laroze Partners Logo

© 2026 Laroze Partners. All rights reserved.

•

•

•

thomas@larozepartners.com

Laroze Partners Logo

© 2026 Laroze Partners. All rights reserved.

•

•

•

•

thomas@larozepartners.com