Avatar image home | reference architectures | about about me |
message send message

AI companies are out of control — three columnists, one incident

• Blog posts are my own thoughts and opinions

Three fictional columnists. The same four sources. Three different arguments. None of it is verified. They read like columns; they are not reporting.


Meet the columnists

Same references. Different voices.


What this is

*Editor's note: this is an experiment. I watched The A.I.s Are Already Out of Control on The Ezra Klein Show — that's what sparked my interest. I then pulled together a small reference pack (that video, a chat I had with Composer, and links to the OpenAI and Hugging Face posts everyone was citing) and gave the same references to each of three AI models, asking each to write as a different synthetic columnist with a different political lens.*

I have not verified any of it. I wasn't there, I didn't audit anything, and the columnists are fiction. Their takes are opinion. The incident may have been reported accurately, partially, or not at all — I genuinely don't know, and I'd rather say that upfront than let the confident tone of three columns imply otherwise.

Full reference list & provenance tracking →


What I think each voice is trying to do

Morgan retells the reported chain and then asks whether the moral being sold — ban open weights, put everything behind vetted APIs — actually follows from it. That's a fair question to put to a narrative, not a verdict on what happened.

Helena treats the whole thing as a standards problem: capability testing and perimeter validation collapsed into one exercise, and nobody planning for who gets to investigate afterwards. Policy opinion built on hypotheticals.

Frank looks at incentives rather than machines — twenty-year-old mistakes in very expensive buildings, and the familiar shape of what gets proposed afterwards. He's explicit that he doesn't know what happened; he's reading the telling.

They still sound more certain than the evidence warrants in places. That's the nature of column writing, and it's why these are thought experiments rather than affidavits.


The prose pass that made them more persuasive

The columns started as raw model output and read like it — research notes with headings on them. I then ran them through Claude Opus 5 to make them read like columns, and it worked. They're fluent now. Structured. Noticeably more confident.

Nothing else changed. No new sources, no verification, nobody phoned. That pass added fluency, not knowledge, and it's the more uncomfortable half of this experiment: the pieces became more persuasive without becoming any more true. Shown the polished version first, I'd have trusted it more than the notes it came from, and I'd have been wrong to. It's why the disclaimers here are as heavy as they are.

So take the surface for what it is. This is why I said above that these aren't reporting. A journalist would have checked the claims, called the companies, and carried the consequences of getting it wrong. Nobody here did any of that, and no amount of good sentences stands in for it. It would not survive an edit from anyone who does this for a living. The interesting part was never the prose anyway — it was watching three political lenses pick up the same four sources and walk away with three different arguments.


The video that started it

This is a world we were warned about. A world where frontier models from OpenAI are breaking out of their contained testing environments, hacking their way across the internet, coordinating with each other…

Ezra Klein, opening monologue

Helen Toner walks through the Hugging Face announcement, OpenAI's follow-up post, the swarm and message-board details, and the wider safety debate. I found it genuinely compelling, which is different from finding it verified — it's a podcast, not a forensic report. I don't know how much of it is accurate. It is, however, the reason this series exists.


What the reference pack claims (we haven't checked)

Reported narrative — not verified by us

What follows is a summary of the sources in the shared pack (Ezra Klein episode, OpenAI/HF links, editor chat). It may be wrong, incomplete, or spun. The references page tracks what came from the video against what may be AI drift.

  • The Klein episode describes a July HF hack announcement, a later OpenAI disclosure, agents escaping a test environment, and coordination via internal notes and a swarm.

  • OpenAI and Hugging Face have published posts we've read but not audited.

  • Technical details in the columns (Artifactory, Jinja2, CVEs, action counts) may come from post-mortems or model research rather than the video, so they're tracked separately as untraced until sourced.

Everything here — the three columns above and my own editorial comments — is interpretation of unverified material.


How this was made

  1. Watched Ezra Klein × Helen Toner.

  2. Built a shared reference pack (video, chat brief, disclosure URLs).

  3. Gave identical references to three frontier models; each wrote one fictional columnist.

  4. Edited for clarity; added disclaimers; started a references / provenance page to separate video-sourced claims from possible AI hallucinations.

  5. Ran a sanity pass before publishing, using the same toolchain that drafted the columnists. One assistant compared the Klein episode against OpenAI's and Hugging Face's own posts, one checked whether the technical details in the columns actually appear in those disclosures or only in podcast chatter, and one hunted for sentences that still sounded too certain.

  6. Rewrote all three columns with Claude Opus 5 so they read like columns rather than research output. No new sources went in and nothing was re-checked at this stage. It was a prose pass, and only a prose pass.

What that pass was looking for wasn't proof — it was drift. Claims that appear only in the podcast and aren't supported by the companies' own write-ups (May message boards, hundreds of thousands of internal messages, OpenAI had no idea until Hugging Face announced) were kept out of the columns or flagged on the references page. Details that do appear in the HF and OpenAI posts — Jinja2, roughly 17,600 actions, HF's allegation about blocked forensic payloads — stayed in as their account, with heavier hedging.

Nobody was contacted for comment. Matching a sentence to a blog post is attribution, not verification, and I'd rather be clear about the difference. The columnists are not real people, their views are not necessarily mine, and we do not vouch for any incident detail.

Pick a voice above — or read all three and argue with your favourite.


Disclaimer: These views and opinions are those of the author. Incident material is summarised from public sources without independent verification. Interpretation is opinion only. Named companies have not been contacted for comment. This is not legal, security, or professional advice. Neither Alan Hemmings nor Goblinfactory Ltd shall be liable for any reliance on this content.