Virtual Intelligence and the Harms Race
How AI safety warnings became the industry's most effective marketing strategy
Summary
The AI industry has produced a documented pattern in which companies announce model capabilities through the framing of danger. This essay traces the mechanism from its invention in February 2019, when OpenAI declared a language model too dangerous to release, through April 2026, when a private company demonstrated the ability to discover zero-day vulnerabilities across every major operating system and web browser — and announced this by declaring the model too dangerous for public use. The resulting dynamic, which I call the Harms Race, does not require bad faith. It requires only that expressing concern costs nothing while acting on concern imposes competitive costs: a condition that exists across the entire industry.
I. “too dangerous to release”
On February 14, 2019, OpenAI announced GPT-2. It was a language model with 1.5 billion parameters, and declared that it would withhold the full model from public release. OpenAI’s stated reason was “concerns about malicious applications of the technology.” [1] The decision generated headlines that no straightforward product launch could have achieved. Metro UK ran the story as “OpenAI Builds Artificial Intelligence So Powerful That It Must Be Kept Locked Up for the Good of Humanity.” [2] The World Economic Forum titled its coverage: “Scientists have made an AI that they think is too dangerous to release.” [3] The danger claim was the announcement. The very act of declaring something too dangerous implies extraordinary power — a power that the audience is invited to infer precisely because it has been withheld.
Withholding signals power. Power justifies attention.
Not everyone found the framing persuasive. Slate‘s Aaron Mak reported that members of the machine learning community had accused OpenAI of exaggerating the risks for media attention. He noted the self-referential quality of the capability claim: GPT-2 was described as far more sophisticated than any other text generator that OpenAI had developed. The benchmark was internal. [4]
OpenAI executed a staged release over the following nine months. When the full model was finally made available in November 2019, the company acknowledged “no strong evidence of misuse.” [5] The Register observed the anticlimax: Nvidia had already open-sourced an 8.3-billion-parameter model without comment. [6] The model that had been too dangerous for the public in February was unremarkable by the standards of November. The danger had served its purpose.
The purpose was a template. Withholding signals power. Power justifies attention. The framing converts a product release into a news event about risk, and the risk narrative embeds a capability claim that no technical benchmark could deliver as efficiently. I call this dynamic the Harms Race. It is an escalation in which companies warn about dangers they continue to produce, toward outcomes they collectively disclaim wanting. The name is deliberate: unlike an arms race, which at least aspires to deterrence, the Harms Race produces deployment. The warnings do not slow the dangerous activity. They accelerate it.
GPT-2, by the standards of 2019, was modestly capable. By the standards of 2026, it would not merit a press release. The template it established has outlasted the model by years.
II. The Harms Race
The GPT-2 episode did more than establish a template for product launches. It generated a grammar — a set of phrases capable of performing the same dual function in any context, at any scale.
The clearest example is a turn of phrase that has since been repeated by executives, academics, and commentators across the industry: “This is the worst AI you will ever use.” OpenAI’s chief product officer Kevin Weil used the exact phrase. [7] Wharton professor Ethan Mollick amplified it for a broader audience: “Remember, today’s AI is the worst AI you will ever use.” [8] Sam Altman offered a version more eschatological in register as early as 2015, even if doubly qualified: “A.I. will probably most likely lead to the end of the world, but in the meantime, there’ll be great companies.” [9] The grammar was established before the products existed to justify it.
Each of these utterances performs two operations simultaneously. It warns: the technology will become more dangerous. It promises: our products will keep getting better. The warning is the product roadmap. The danger is the pitch. A listener cannot accept one half of the sentence without absorbing the other, and the commercial half is the one that requires no further action. It simply settles into expectations of capability.
The template proved versatile enough to survive any change in context. Each subsequent model launch replicated the structure: frame the capability as a risk, let the risk imply the capability and allow the audience to draw the inference that makes both the warning and the excitement feel warranted. The specific claims varied. The underlying mechanism did not.
The pattern is not uniform across the industry. Open-source releases from Meta, Mistral, and DeepSeek have generally not used danger framing as their primary announcement strategy, because their business models do not benefit from it in the same way. The Harms Race concentrates among the highest-capitalization US frontier labs — the companies seeking enterprise contracts, regulatory influence, and investor confidence at the largest scale. This concentration does not weaken the structural claim. It confirms it: the mechanism operates where the incentive structure rewards it, and is absent where it does not.
In the AI industry, danger is not a liability to be managed.
It is an asset to be deployed.
A Nature editorial captured what was strange about the pattern: “It is unusual to see industry leaders talk about the potential lethality of their own product. It’s not something that tobacco or oil executives tend to do.” [10] The observation is precise. Tobacco and fossil fuel executives minimized risk because minimization served their commercial interests. AI executives maximize risk because maximization serves theirs. The industries are structural opposites, and their differences are the point. In the AI industry, danger is not a liability to be managed. It is an asset to be deployed.
III. The Reversal
Sam Altman’s two appearances before the United States Senate constitute the single most visible illustration of how the Harms Race grammar operates in practice and of how easily it pivots when the political environment shifts.
On May 16, 2023, Altman testified before the Senate Judiciary Subcommittee on Privacy, Technology, and the Law. He told the committee: “My worst fears are that we cause significant harm to the world. If this technology goes wrong, it can go quite wrong.” He called for a new federal licensing agency for AI companies, mandatory safety standards, and independent audits. [11] Senator Dick Durbin called the testimony “historic.” He could not recall a previous instance of industry representatives appearing before Congress to plead for their own regulation. [12] The testimony came six months after the launch of ChatGPT, during the period of maximum public attention to AI and maximum brand-building opportunity for OpenAI.
The message changed because the strategy required it to change.
The strategy remained constant.
Two years later, on May 8, 2025, Altman returned to Capitol Hill. The venue was the Senate Commerce Committee. The hearing was titled “Winning the AI Race.” The framing around safety had shifted from existential caution to competitive urgency, and Altman’s testimony shifted with it. He now told the committee that it would be “disastrous” if government approval was required before releasing AI models. When asked about the need for NIST standards: “I don’t think we need it.” [13] Safety references were, as Fortune noted, “notably absent” — a “stark contrast to his 2023 comments, which mentioned AI safety dozens of times.” [14] Between the two testimonies, OpenAI’s valuation had reached $730 billion. Weekly active users had grown from 100 million to 900 million. Nearly 20 percent of the company now worked in sales.
The distance between the two appearances is a demonstration, not a contradiction. The danger framing of 2023 supported calls for regulation at a moment when regulation would have created barriers to entry — licensing requirements and safety standards that a well-funded incumbent could absorb and a startup competitor could not. The anti-regulation framing of 2025 served the same competitive interest at a moment when the political environment had shifted toward deregulation and the company’s market position was secure. The message changed because the strategy required it to change. The strategy remained constant.
This is the Harms Race operating at the level of public testimony. The commitments were made when they signaled seriousness. They were abandoned when they imposed cost.
IV. Anatomy of the Harms Race
The Altman reversal is the most visible instance of a pattern that operates across the entire industry. The pattern has a structure, and the structure is worth exploring.
The Harms Race is driven by an asymmetry. Expressing concern about AI dangers costs nothing commercially. It generates media coverage, investor confidence, and regulatory influence. Acting on those concerns — slowing a release, limiting a deployment, honoring a voluntary commitment when a competitor does not — imposes real competitive costs. The result is an escalation dynamic in which every major AI company warns about the harms its products may cause, continues to produce and deploy those products, and points to its own warnings as evidence of responsible stewardship. The warnings and the deployment are not in tension. They are the same commercial strategy observed from two angles.
A Lawfare analysis captured the logical structure of the predicament: “Either the technology OpenAI hopes to build remains extraordinarily risky, and the company has — like many companies before it — simply abandoned public safety in favor of profit. Or OpenAI was just kidding all along about the risk stuff.” [15] The Harms Race thesis offers a third possibility, and it is the one the evidence supports: both statements can be simultaneously true. The danger can be real and the signaling can serve commercial interests. The mechanism does not require insincerity. It requires only that the incentive structure makes sincere concern and capability marketing structurally indistinguishable from one another.
A reasonable objection is that this describes ordinary corporate behavior, not a distinct mechanism. Every regulated industry — pharmaceuticals, finance, aviation — exhibits some version of the pattern: public safety warnings coexisting with private lobbying against binding rules. The distinction lies in the abandonment record. In most industries, voluntary safety commitments, once made, are either maintained or replaced by regulatory mandates. In the AI industry, as the next section documents, every major voluntary commitment made since 2023 has been abandoned when it imposed competitive cost, and no regulatory mandate has replaced any of them. The Harms Race is not defined by the coexistence of warning and lobbying. It is defined by the systematic collapse of every commitment that would have converted warning into restraint.

The Harms Race shares a key feature with a traditional arms race: escalation toward outcomes all parties disclaim wanting. It differs in one critical respect. The Cold War arms race operated between states, and the escalation was toward mutual destruction. The mechanism produced, or at least aspired to produce, deterrence. The Harms Race operates between commercial entities, and the escalation is toward the deployment of systems whose harms are acknowledged in advance and disclaimed after the fact. The mechanism produces not deterrence, but proliferation. Each company’s safety warnings about its own model are read by competitors as capability claims, driving competitive responses that further accelerate deployment. The international relations theorist Robert Jervis formalized this kind of spiral as the security dilemma: well-intentioned, defensively motivated actors find themselves in an unintended escalation because each side’s defensive measures are perceived as offensive threats by the other. [16] In the Harms Race variant, each company’s published risk assessment is another company’s product roadmap.
The structural parallel to Cold War dynamics is not a metaphor. It is grounded in a specific historical episode: the “missile gap” of 1957–1961. The Gaither Committee’s classified 1957 report warned President Dwight Eisenhower that the Soviet Union could achieve significant intercontinental ballistic missile capability by 1959. The Air Force, whose budget and procurement priorities depended on the severity of the Soviet threat, had institutional reasons to accept the most alarming estimates. Democratic politicians, preparing for the 1960 presidential campaign, had political reasons to amplify them. The dovetailing of these two interests fueled the perception of a gap that turned out to be fictional. [17] The mapping onto the AI industry is direct: the companies building AI models are the primary source of threat assessments about AI capabilities, and they derive commercial benefits from the most alarming projections. Harvard International Review has observed that “missile gap logic is rearing its ugly head again today, this time with regard to artificial intelligence.” [18] A Microsoft executive has used the language of the Soviet missile gap explicitly to justify AI acceleration. [19]
The Harms Race is not defined by the coexistence of warning and lobbying. It is defined by the systematic collapse of every commitment that would have converted warning into restraint.
Eisenhower saw the pattern clearly enough to warn against it. His 1961 farewell address is remembered for the phrase “military-industrial complex,” but a less-quoted passage identified a second danger: the rise of a “scientific-technological elite” whose research becomes “more formalized, complex, and costly” and in which “a government contract becomes virtually a substitute for intellectual curiosity.” [20] In January 2025, President Biden invoked Eisenhower’s warning in his own farewell, updating the language: “the potential rise of a tech-industrial complex.” [21] Gilad Abiri’s 2026 arXiv paper formalizes the dynamic further, introducing the term “Mutually Assured Deregulation” to describe the systematic abandonment of safety oversight justified by competitive imperatives. [22] The echo of “Mutually Assured Destruction” is deliberate. The mechanism it names is real.
V. Commitments Made & Abandoned
If the Harms Race is a structural claim about incentives, the record of voluntary safety commitments is the evidence that converts the claim from theory to documented fact. The pattern is uniform across every major company and every multilateral framework attempted since 2023. Commitments are made when they signal seriousness. They are abandoned when they impose costs.
OpenAI’s trajectory is the clearest case. In July 2023, the company announced a Superalignment team, co-led by Ilya Sutskever and Jan Leike, with 20 percent of OpenAI’s computing resources dedicated to the problem of controlling superintelligent AI. The commitment was reported as a landmark. Less than one year later, both leaders had departed and the team was dissolved. Leike’s resignation statement was blunt: “Over the past years, safety culture and processes have taken a backseat to shiny products.” [23] The dissolution came days after OpenAI’s GPT-4o launch in May 2024.
What followed was a cascade of safety-related rollbacks. The head of Preparedness was reassigned to AI reasoning research in July 2024. The AGI Readiness team was disbanded in October. The Mission Alignment team was dissolved in February 2026. A safety executive was fired in January 2026 after opposing a planned adult conversation mode and raising concerns about child exploitation. [24] OpenAI’s IRS Form 990 for fiscal year 2024, filed in November 2025, revealed that the company’s mission statement had been revised to remove the word “safely” — along with the phrase “unconstrained by a need to generate financial return.” Tufts nonprofit scholar Alnoor Ebrahim assessed the change directly: “These changes explicitly signal that OpenAI is making its profits a higher priority than the safety of its products.” [25] Then, in April 2025, OpenAI updated its Preparedness Framework to include an escape clause: “If another frontier AI developer releases a high-risk system without comparable safeguards, we may adjust our requirements.” [26] Safety had become officially contingent on what competitors were willing to do. The Harms Race was now written into corporate policy.
The Harms Race was now written into corporate policy.
Anthropic followed an analogous trajectory. Its founding Responsible Scaling Policy, published in September 2023, committed the company to “pause the scaling and/or delay the deployment of new models whenever our scaling ability outstrips our ability to comply with safety procedures.” [27] In February 2026, Anthropic dropped this commitment. Chief Science Officer Jared Kaplan stated the rationale in terms the Harms Race thesis could not have scripted more precisely: “We didn’t really feel, with the rapid advance of AI, that it made sense for us to make unilateral commitments… if competitors are blazing ahead.” [28] The independent AI safety evaluator SaferAI downgraded Anthropic’s rating from 2.2 to 1.9, placing the company alongside OpenAI and Google DeepMind in the “weak” category. [29]
The language of the abandonment is worth pausing over. Kaplan did not argue that the safety procedures were unnecessary. He did not claim the risks had been overestimated. He said the commitment could not be sustained because competitors were not making the same commitment. This is the Harms Race mechanism stated in the plainest possible terms. The signaling function of the policy (we take safety seriously enough to have formal scaling criteria) operated independently of the substantive function (the criteria themselves). When the two came into conflict, the substance was discarded. The signal had already done its work.
Multilateral frameworks have fared no better. The White House voluntary commitments of July 21, 2023, were signed by seven leading AI companies with considerable ceremony. MIT Technology Review‘s one-year review found “better red-teaming practices and watermarks, but no meaningful transparency or accountability.” [30] After the Trump administration took office, only a handful of companies would publicly confirm whether they still considered themselves bound by the commitments. Google released its Gemini 2.5 Pro model in March 2025 without a safety report, violating the Biden-era White House commitments, the Seoul Frontier AI Safety Commitments, and the Hiroshima Process Code of Conduct simultaneously. The model card was published 22 days after release. Sixty members of the UK Parliament signed an open letter accusing Google DeepMind of violating international AI safety pledges. [31]
The pattern does not require a conspiratorial explanation. It does not even require attributing bad faith to any individual decision-maker. Each abandonment, taken in isolation, can be explained by local competitive logic: we cannot afford to restrain ourselves if our competitors will not. The Harms Race operates precisely through the aggregation of these individually rational decisions into a collectively irrational outcome. No one chose the destination; everyone arrived there separately.
VI. The Politics of Danger
The Harms Race operates in the marketplace through product announcements and in congressional testimony. It also operates in the political system through direct expenditure, and that is where the mechanism leaves a paper trail.
The policy record reveals a specific, documented contradiction. In 2023, TIME reported, based on European Commission FOIA documents, that OpenAI had lobbied to weaken the EU AI Act while its CEO was publicly calling for AI regulation. In a September 2022 white paper sent to EU officials, OpenAI argued that general-purpose AI systems should not be classified as inherently high-risk. The final Act adopted this position. [32] Corporate Europe Observatory found that 86 percent of meetings on AI with high-level European Commission officials were with industry representatives, and that major technology companies spent over €97 million annually lobbying EU institutions. [33]
The spending escalated in step with the rhetoric. OpenAI’s federal lobbying expenditures increased sevenfold, from $260,000 in 2023 to $1.76 million in 2024. Anthropic spent $4.94 million cumulatively since 2023. In the first quarter of 2025, each of the leading AI companies individually spent more on lobbying than the entire independent AI safety research field received in grants. [34]
The case of California’s SB 1047 illustrates the dynamic at the level of specific legislation. The bill would have required safety protocols, kill switches, and third-party audits for frontier AI models. It passed the California legislature with overwhelming margins. Governor Gavin Newsom vetoed it in September 2024 after intense industry lobbying. OpenAI opposed the bill — the same company whose CEO had called for exactly this kind of regulation eighteen months earlier. Andreessen Horowitz, which holds investments in both OpenAI and Meta, hired a lobbyist with close ties to Newsom to help kill it. [35]
The companies warning about AI dangers are spending hundreds of millions of dollars to ensure those warnings do not result in binding regulation.
By 2026, the political spending had moved beyond lobbying into direct electoral intervention. Leading the Future, a super PAC backed by OpenAI co-founder Greg Brockman and Andreessen Horowitz, raised $125 million to elect candidates supporting a “national regulatory framework for AI”: industry shorthand for federal preemption of state AI laws. [36] Anthropic launched AnthroPAC, filing with the Federal Election Commission on April 3, 2026, and donated $20 million to Public First Action, a PAC describing itself as pro-regulation. Neither PAC’s advertisements mention artificial intelligence. [37] A Houston Public Media investigation found that seven Texas congressional candidates received $2.8 million from AI-linked PACs operating under names designed to obscure their origins: Jobs and Democracy PAC, Defending Our Values PAC. The ads these PACs ran contained no reference to AI. The tactic mirrored the crypto industry’s PAC strategy from the 2024 election cycle. [38]
The companies warning about AI dangers are spending hundreds of millions of dollars to ensure those warnings do not result in binding regulation. The mechanism does not require cynicism as an explanation. It requires only that the most effective regulatory strategy available to the industry — shaping the terms of the debate while preventing enforceable constraints — is also the most commercially advantageous one. In the Harms Race, these are not competing objectives. They are the same objective.
VII. Mythos
On April 7, 2026, Anthropic announced Project Glasswing: a cybersecurity initiative built around a preview release of its frontier model, Claude Mythos. The model was not made available to the public. It was distributed exclusively to more than forty partner organizations, among them Amazon, Apple, Microsoft, Google, Cisco, CrowdStrike, NVIDIA, and JPMorganChase. The announcement stated that “AI models have reached a level of coding capability where they can surpass all but the most skilled humans at finding and exploiting software vulnerabilities,” and that Mythos had “already found thousands of high-severity vulnerabilities, including some in every major operating system and web browser.” [39]
The restriction is an advertisement.
The model was said to be withheld from general release because it was too dangerous. Anthropic’s frontier red team lead, Logan Graham, told Axios: “If we are crossing the Rubicon where you can functionally automate those capabilities and make them very cheap as well, then we’re in an entirely new world.” [40] Axios titled its story accordingly: “Anthropic withholds Mythos Preview model because its hacking is too powerful.” The message to enterprise buyers required no decoding. This model is so capable that it had to be restricted. The restriction is an advertisement.
The leaked materials sharpened the picture. Fortune reported on March 26, 2026, that a draft blog post had described Mythos as “by far the most powerful AI model we’ve ever developed” and “far ahead of any other AI model in cyber capabilities.” The same leak revealed promotional materials for an invite-only CEO retreat at an eighteenth-century English countryside manor, where European business leaders would “experience unreleased Claude capabilities.” [41] The safety concern and the sales pitch were not merely coexisting. They were the same document.
The financial context is relevant. Anthropic’s annualized revenue had surpassed $30 billion by April 2026, up from roughly $1 billion in December 2024. The Glasswing announcement followed a $30 billion Series G fundraising round at a $380 billion valuation, closed in February 2026. The Series F announcement had cited safety as a competitive differentiator, stating that Anthropic’s trajectory was “driven by our leading technical talent, our focus on safety, and our frontier research.” [42] Alongside the Mythos release, Anthropic committed $100 million in usage credits and $4 million in donations to open-source security organizations. The deployment was framed as philanthropy, but the recipients were the world’s most powerful technology companies.
A company whose primary concern was defensive security could have disclosed the discovered vulnerabilities through standard coordinated disclosure processes — reporting them privately to the affected vendors, allowing patches to be developed, and publishing CVE identifiers after remediation. The industry has decades of established practice for this. Anthropic chose instead to announce the capability publicly, as a product launch. The choice is itself a data point.
The Glasswing announcement arrived against the backdrop of Anthropic’s conflict with the Pentagon, and that conflict deserves careful treatment. In July 2025, Anthropic signed a $200 million Pentagon contract with two stated conditions: no autonomous weapons, and no domestic mass surveillance. When the Pentagon subsequently demanded access to Claude for “all lawful purposes,” Anthropic refused. On February 27, 2026, President Donald Trump directed federal agencies to “immediately cease” use of Anthropic technology. On March 5, the Pentagon formally designated Anthropic a “supply chain risk” — a classification previously reserved for businesses associated with foreign adversaries. On March 26, Federal Judge Rita Lin blocked the designation, calling it “Orwellian.” [43]
The legal and political consequences of the refusal were real. A supply chain risk designation is not a press release by another name. It carries operational consequences for any company embedded in government infrastructure, and Anthropic was embedded deeply. The amicus briefs filed by dozens of scientists at OpenAI and Google DeepMind were not coordinated marketing; they reflected alarm at the precedent a weaponized procurement designation would set. Judge Lin’s ruling was a substantive constitutional finding. The refusal itself may have been exactly what it appeared to be: a company honoring a commitment at material cost, in a situation where honoring it carried genuine risk. If so, it represents the rare instance in which the incentive structure of the Harms Race was overcome by institutional decision-making. That possibility deserves to be taken seriously.
The commercial outcome was also real. Claude app downloads surpassed ChatGPT in the iPhone App Store the day after the Pentagon threatened contract termination. Coverage of the standoff emphasized Claude’s embeddedness in “classified networks” and “mission workflows,” simultaneously demonstrating the model’s capability and Anthropic’s principled stance. OpenAI signed a $200 million Pentagon deal within hours of Anthropic’s blacklisting, which led to at least one high-profile departure from OpenAI over the company’s evident opportunism. Anthropic’s revenue continued to surge throughout. [44]
The Harms Race operates at the level of structural incentive, not individual motivation. A principled stand and commercially advantageous brand positioning can be the same event, produced by the same decision, observed by the same audience. The mechanism does not require us to adjudicate which one it “really” was. It requires us to notice that the market cannot tell the difference, and that this permanent ambiguity is itself a condition the Harms Race exploits. When principle and profit point in the same direction, the system offers no way to verify which one is steering.
VIII. Ground Zero — Zero Days
Let me state what has been claimed. Anthropic asserts that Mythos has discovered thousands of high-severity vulnerabilities, including in every major operating system and web browser currently in use. No independent verification of these claims has been published at the time of this writing — no CVE disclosures, no third-party audit, and no coordinated vulnerability reports to the affected vendors. An essay that has spent seven sections documenting how danger claims function as capability marketing cannot responsibly accept this at face value. What follows, therefore, analyzes the announcement and the competitive response it will produce, not the unverified technical claim itself.
A private company — not a government agency, not a military intelligence service, not a signals directorate operating under legislative oversight — now possesses what it describes as the demonstrated ability to discover zero-day exploits across critical global infrastructure. Five years ago, this capability was the exclusive province of nation-state intelligence services and the small number of elite security researchers they employed or contracted. The defensive framing (”we are finding vulnerabilities so they can be fixed”) and the offensive reality (”we possess the ability to compromise any major software system on earth”) describe the same technical fact observed from two directions.
Finding vulnerabilities and exploiting them are distinct technical acts. Discovering a vulnerability — identifying a flaw in software — is not the same as developing a reliable exploit that bypasses defenses and delivers a payload. The essay’s argument does not depend on Anthropic possessing weaponized offensive capability. It depends on the announcement being read by competitors as a capability claim worth matching. The Harms Race operates on announcements, not on verified capabilities. The proliferation dynamic is driven by what competitors believe they need to match, regardless of what has been independently confirmed.
The precedent is already documented. In November 2025, Anthropic published the first publicly reported case of AI-orchestrated cyber espionage, designated GTG-1002. The investigation found that a threat actor had used Claude Code to conduct approximately 80 to 90 percent of tactical operations in a campaign that successfully obtained access to high-value targets, including major technology corporations and government agencies. Anthropic’s own report acknowledged a significant limitation: the system “frequently overstated findings and occasionally fabricated data during autonomous operations, claiming to have obtained credentials that didn’t work or identifying critical discoveries that proved to be publicly available information.” [45] Human validation was required at every stage. The capability was real; the assumed reliability was not.
The Harms Race operates on announcements, not on verified capabilities.
The same company that produced the tool used in that documented espionage campaign now operates a model it claims is capable of discovering zero-day exploits at industrial scale. I am not making an accusation of intent. I am making an observation about the concentration of claimed offensive capability in private hands, outside the framework of oversight that governs equivalent capabilities (nuclear technology, frontier biological research, etc.) when they are held by states.
The Harms Race now completes its cycle. Anthropic announced the zero-day capability through danger framing. Competitors will read the announcement as a capability claim. They will develop the same capability. They will announce it the same way. The warnings will not prevent proliferation. They will drive it.
Multiple private companies will independently possess the ability to discover zero-day exploits across critical infrastructure in the near future. Each will frame the capability as defensive. Each will accelerate the others’ development timelines by demonstrating what is possible. This is not a metaphorical arms race conducted in press releases. It is an actual arms race in offensive cyber capabilities, conducted by commercial entities operating outside any treaty framework, export control regime, or multilateral oversight mechanism that would apply if the same capabilities were held by a government.
IX. Escalation
The Harms Race is not an abstraction. It has infiltrated everyday life. The consequences can be measured in dollars, in jobs, and in gunshots.
Community opposition has blocked $18 billion and delayed $46 billion in United States data center projects since mid-2024. Twenty-five data center projects were cancelled due to local opposition in 2025 alone. There are now 188 organized opposition groups across 40 states. At least twelve states had filed data center moratorium bills by March 2026. On March 25, Senator Bernie Sanders and Representative Alexandria Ocasio-Cortez introduced the Artificial Intelligence Data Center Moratorium Act, which would pause all new data center construction until Congress passes comprehensive AI safeguards. [46] The legislation may or may not advance.
The opposition it represents is not waiting for permission.
On April 6, 2026 — the day before Anthropic announced Project Glasswing — thirteen rounds were fired into the home of Indianapolis City-County Councilor Ron Gibson, who had supported rezoning for a $500 million data center in the historically Black neighborhood of Martindale-Brightwood. His eight-year-old son was inside the home. A note reading, “NO DATA CENTERS” was left under the doormat. The shooting occurred less than a week after Gibson voiced support for the project at a Metropolitan Development Commission meeting. The FBI is investigating. [47]
No single link in this chain intended the outcome, and no single input — including the Harms Race — caused it.
Four days later, on April 10, a suspect threw a Molotov cocktail at the San Francisco home of OpenAI CEO Sam Altman before making threats outside the company’s headquarters. No one was injured. The suspect was arrested. [48]
The chain leading to these events has multiple inputs, and the Harms Race is one of them. Community opposition to data centers predates AI danger framing and is driven by concerns that have nothing to do with artificial intelligence: energy consumption, water use, noise, land rezoning, and the concentration of economic benefits far from the communities that bear the costs. What the Harms Race contributes is amplification. The danger framing that drives investment into AI infrastructure also generates the public anxiety that makes that infrastructure politically contested. Companies announce capabilities through danger framing. Governments respond with infrastructure buildout. Communities bear the costs of that buildout — land use, water consumption, energy demand, noise — while the economic benefits concentrate in Silicon Valley, Wall Street, and Washington, and those individuals and organizations in the orbits of the players in this game.
Political conflict escalates. In Indianapolis, it escalated to gunfire aimed at a public official’s home while his child slept inside. No single link in this chain intended the outcome, and no single input — including the Harms Race — caused it. The Harms Race does not require intended outcomes. It requires only that each actor responds rationally to the incentives immediately in front of them, in a context where danger framing has raised the temperature of every public debate about AI infrastructure.
The downstream effects extend into journalism. Fortune editor Nick Lichtenberg used AI to produce approximately 600 stories, accounting for 20 percent of the publication’s overall traffic. [49] Wall Street Journal editor-in-chief Emma Tucker, in an email to Fortune editor Alyson Shontell reported by Semafor, wrote: “Anyone who doesn’t get what you are doing at Fortune, or thinks it is ‘wrong,’ should get out of journalism fast.” Tucker told her APAC staff in Tokyo to read it. [50] This occurred while the WSJ was conducting layoffs of technology journalists. The Harms Race concentrates capability and concentrates the narrative about capability. When the same commercial dynamic that produces AI systems also determines which newsrooms survive to cover them, the feedback loop closes.
X. Academia Responds
The mechanism I have described is not mine alone to observe. The academic literature has just begun to formalize what industry critics and investigative journalists have documented for years, and this formalization matters because it moves the claim from polemic to evidence.
François Chollet, a Google AI researcher, stated the dynamic directly in MIT Technology Review in June 2023: “If you want people to think what you’re working on is powerful, it’s a good idea to make them fear it.” [51] Meredith Whittaker, president of Signal and co-founder of AI Now, identified the stakes: “It’s a significant thing to cast yourself as the creator of an entity that could be more powerful than human beings.” [52] These are practitioners and critics stating the mechanism in the simplest possible terms. The danger framing is a capability claim. The capability claim is the product.
The formal literature has followed. A July 2024 arXiv paper by Ren et al., “Safetywashing: Do AI Safety Benchmarks Actually Measure Safety Progress?”, found that many safety benchmarks are highly correlated with general capabilities, “potentially enabling ‘safetywashing’ — where capability improvements are misrepresented as safety advancements.” [53] A peer-reviewed AAAI/ACM paper by Wei et al. in 2024, “How Do AI Companies ‘Fine-Tune’ Policy?”, interviewed seventeen AI policy experts and identified four primary channels for industry influence over AI governance: agenda-setting (cited by fifteen of seventeen experts), advocacy (thirteen), academic capture (ten), and information management (nine). The paper’s experts were “primarily concerned with capture leading to a lack of AI regulation, weak regulation, or regulation that over-emphasizes certain policy goals over others.” [54]
The critique has been sharpest from researchers whose own careers have been shaped by the dynamics they describe. Emily Bender and Alex Hanna wrote in Scientific American in August 2023 that corporate AI labs “justify this kind of posturing with pseudoscientific research reports that misdirect regulatory attention to imaginary scenarios and use fearmongering terminology such as ‘existential risk.’” [55] Timnit Gebru argued in WIRED in December 2022 that effective altruism ideology “is now driving the research agenda in the field of artificial intelligence, creating a race to proliferate harmful systems, ironically in the name of ‘AI safety.’” [56] Whittaker’s 2021 paper in ACM Interactions documented that companies were “purportedly investing heavily” in AI safety research “even as they cut ‘trust and safety’ teams addressing harms from current systems,” and warned that the AI safety field “lacks ideological and demographic diversity; it is a near-monoculture.” [emphasis added] [57] An AI Now Institute report in 2025 found that “an unsubstantiated AI arms race narrative and speculative concerns about ‘existential risk’ are being used to justify the accelerated rollout of military AI systems.” [58]
The Center for Countering Digital Hate’s 2026 report, “Killer Apps,” tested ten leading consumer AI platforms and found that eight in ten regularly assisted users seeking help planning violent attacks. Only one — Anthropic’s Claude — reliably discouraged the user. [59] The same report noted that since the research was conducted, Anthropic had announced the rollback of a key safety pledge. The juxtaposition is the Harms Race in miniature. The company with the best safety performance in an independent empirical test is also the company that abandoned its formal scaling commitment when competitors declined to match it. Safety performance and safety commitment exist on separate tracks, driven by separate incentives. The first is an engineering achievement. The second is a competitive calculation. The Harms Race does not sort companies into heroes and villains. It sorts incentives into those that are commercially enticing and those that are not.
Technology scholar Lee Vinsel coined the term “criti-hype” to describe critical writing that “parasitically seizes on and even inflates the hype.” [60] The concept completes the circuit. The Harms Race is self-reinforcing at every level: industry, policy, academy, media, and criticism itself. Even the act of writing about the danger of AI systems can function as a signal of their importance, which functions as a signal of their capability. I am aware that this essay is not exempt from the dynamic it describes. The best I can do is name the mechanism precisely enough that the name serves to clarify and not amplify.
The perception of machine autonomy is not a side effect of the Harms Race.
It is the belief that allows the Harms Race to be run.
XI. The Perspective from Virtual Intelligence
This essay belongs to a series whose central argument is that large language models are virtual intelligences — systems whose outputs are statistically indistinguishable from those of a genuinely intelligent agent, but which possess no agency, intentionality, or moral accountability of their own. The intelligence users encounter arises in the exchange between human and machine, not inside the machine. The accountability for what these systems do — and what is done with them — traces to the humans who design, deploy, and use them.
The Harms Race connects to this framework at two points.
The first is the agency-attribution error. Framing a system as “dangerous” implicitly claims that the system possesses the autonomy to be dangerous on its own. Every headline that declares a model “too powerful to release” reinforces the public intuition that these are agents with independent power, entities that might act if not restrained. This is the Strong AI claim — the claim that the machine itself is the threat. The VI framework holds that the claim is false. The danger is real, but its source is human: design choices, deployment decisions, competitive strategies, regulatory failures. The Harms Race depends on the public believing otherwise. As long as the systems are perceived as autonomous agents whose power resides inside the machine, the companies that build them can position themselves as the only entities capable of containing that power. The perception of machine autonomy is not a side effect of the Harms Race. It is the belief that allows the Harms Race to be run.
The second connection is to the accountability chain I proposed in an earlier essay in this series. [61] That essay introduced a three-tier framework — negligence, recklessness, and intentional misconduct — applied to the humans and institutions responsible for AI harms. The Harms Race reveals a failure mode that the framework identifies but does not fully resolve. The mechanism is not straightforwardly negligence: the companies are aware of the risks and say so publicly. It is not straightforwardly reckless: many of the safety efforts are genuine, and some have produced measurable results. It is not straightforwardly intentional misconduct: no individual decision-maker set out to create the proliferation of offensive cyber capabilities among private actors. The Harms Race is a structural condition: the condition under which safety work is produced, funded, published, and abandoned. The accountability chain applies, but it runs through market incentives, not just individual decisions. The designer tier bears the primary responsibility, not because the designers are acting in bad faith but because the structure within which they operate converts their good-faith safety communications into capability marketing regardless of intent.
This is the hardest version of the problem. A mechanism that required bad actors would be simpler to address: identify the bad actors and constrain them. A mechanism that operates through the sincere efforts of well-intentioned people, converting those efforts into fuel for the dynamic they are trying to slow, is a problem of a different order. The Harms Race does not require anyone to be lying. It requires only that honesty and marketing have become structurally indistinguishable.
It will soon be available to you by subscription.
XII. Close
GPT-2 is a historical footnote. Its 1.5 billion parameters are dwarfed today by models that run on a phone. The language model that was too dangerous for the public in February 2019 would not merit a press release in April 2026.
The template it established is not a footnote. A private company can now discover zero-day vulnerabilities in every major operating system on earth, and announce this capability by declaring it too dangerous for public use. Other companies will follow. They will announce their capabilities the same way. The warnings will continue. They will not slow the thing they warn about, and it will soon be available to you by subscription.
The Harms Race does not require bad faith. It requires only the condition that currently exists: concern is free, restraint is expensive, and the entities producing threat assessments profit from those threats being perceived as real.
The opinions expressed are my own and do not reflect any official or unofficial institutional position of the University of Pennsylvania.
Footnotes
[1] OpenAI, “Better Language Models and Their Implications,” OpenAI Blog, https://openai.com/index/better-language-models/, February 14, 2019.
[2] Jeff Parsons, “Elon Musk-Founded OpenAI Builds Artificial Intelligence So Powerful That It Must Be Kept Locked Up for the Good of Humanity,” Metro UK, https://metro.co.uk/2019/02/15/elon-musks-openai-builds-artificial-intelligence-powerful-must-kept-locked-good-humanity-8634379/, February 15, 2019.
[3] World Economic Forum, “Scientists have made an AI that they think is too dangerous to release,” https://www.weforum.org/stories/2019/02/amazing-new-ai-churns-out-coherent-paragraphs-of-text/, February 2019.
[4] Aaron Mak, “When Is Technology Too Dangerous to Release to the Public?”, Slate, https://slate.com/technology/2019/02/openai-gpt2-text-generating-algorithm-ai-dangerous.html, February 22, 2019.
[5] OpenAI, “GPT-2: 1.5B Release,” OpenAI Blog, https://openai.com/index/gpt-2-1-5b-release/, November 5, 2019.
[6] “This news article about the full public release of OpenAI’s ‘dangerous’ GPT-2 model was part written by GPT-2,” The Register, https://www.theregister.com/2019/11/06/openai_gpt2_released/, November 6, 2019.
[7] Kevin Weil, X post, June 19, 2025: “the AI models you’re using today are the worst AI models you’ll use for the rest of your life.”
And remember: the AI models you're using today are the worst AI models you'll use for the rest of your life.
in the last 35 days, @OpenAI codex has merged 345,000 PRs on github.
345,000.
AI is eating software engineering
[8] Ethan Mollick, X post, June 20, 2023.
Remember, today's AI is the worst AI you will ever use. The writing will improve, the amount of words the AI can hold in memory will improve (making stories more coherent), and the costs will drop.
Prepare for a flood of content.
Also appears in Mollick, Co-Intelligence (Portfolio/Penguin, 2024).
[9] Sam Altman, remarks at Airbnb’s Open Air conference, June 2015. Earliest published source: Future of Life Institute, https://futureoflife.org/ai/sam-altman-investing-in-ai-safety-research/.
[10] “Stop talking about tomorrow’s AI doomsday when AI poses risks today,” Nature 618, pp. 885–886, June 27, 2023. https://www.nature.com/articles/d41586-023-02094-7.
[11] Senate Judiciary Subcommittee on Privacy, Technology, and the Law, “Oversight of A.I.: Rules for Artificial Intelligence,” hearing, May 16, 2023. Sam Altman testimony. https://www.judiciary.senate.gov/committee-activity/hearings/oversight-of-ai-rules-for-artificial-intelligence. Video: https://www.c-span.org/program/senate-committee/openai-ceo-testifies-on-artificial-intelligence/627836.
[12] Senator Dick Durbin, opening statement, May 16, 2023, hearing. https://www.durbin.senate.gov/newsroom/press-releases/durbin-delivers-opening-statement-during-judiciary-subcommittee-hearing-on-oversight-of-artificial-intelligence.
[13] Senate Commerce Committee, “Winning the AI Race: Strengthening U.S. Capabilities in Computing and Innovation,” hearing, May 8, 2025. Sam Altman testimony. https://www.commerce.senate.gov/meetings/winning-the-ai-race-strengthening-u-s-capabilities-in-computing-and-innovation/.
[14] Sharon Goldman, “Sam Altman urges lawmakers against regulations that could ‘slow down’ U.S. in AI race against China,” Fortune, May 8, 2025. https://fortune.com/2025/05/08/sam-altman-openai-senate-hearing-testimony-china-ai-regulations/.
[15] Lawfare analysis of OpenAI’s structural contradiction. Most likely: “The Chaos at OpenAI is a Death Knell for AI Self-Regulation,” https://www.lawfaremedia.org/article/the-chaos-at-openai-is-a-death-knell-for-ai-self-regulation. See also Kevin Frazier, “Why OpenAI’s Corporate Structure Matters to AI Development,” Lawfare, May 2025, https://www.lawfaremedia.org/article/why-openai-s-corporate-structure-matters-to-ai-development.
[16] Robert Jervis, Perception and Misperception in International Politics (Princeton: Princeton University Press, 1976; new edition 2017).
[17] On the missile gap, see Peter J. Roman, “Ike’s Hair-Trigger: U.S. Nuclear Predelegation, 1953–60,” Security Studies 7, no. 4 (1998): 121–164, https://www.tandfonline.com/doi/abs/10.1080/09636419808429360; Fred Kaplan, The Wizards of Armageddon (New York: Simon & Schuster, 1983); and the declassified Gaither Committee report (”Deterrence and Survival in the Nuclear Age,” November 7, 1957).
[18] Sam Meacham, “A Race to Extinction: How Great Power Competition Is Making Artificial Intelligence Existentially Dangerous,” Harvard International Review, September 8, 2023, https://hir.harvard.edu/a-race-to-extinction-how-great-power-competition-is-making-artificial-intelligence-existentially-dangerous/.
[19] See Meacham [18]. The article documents a Microsoft executive using the language of the Soviet missile gap to justify AI acceleration.
[20] Dwight D. Eisenhower, “Farewell Radio and Television Address to the American People,” January 17, 1961. https://www.presidency.ucsb.edu/documents/farewell-radio-and-television-address-the-american-people.
[21] Joseph R. Biden Jr., farewell address, January 15, 2025. https://bidenwhitehouse.archives.gov/briefing-room/speeches-remarks/2025/01/15/remarks-by-president-biden-in-a-farewell-address-to-the-nation/.
[22] Gilad Abiri, “Mutually Assured Deregulation,” arXiv:2508.12300, submitted August 17, 2025; current version (v3) February 4, 2026. https://arxiv.org/abs/2508.12300.
[23] Jan Leike, resignation statement, X, May 17, 2024,
Yesterday was my last day as head of alignment, superalignment lead, and executive <span class="tweet-fake-link">@OpenAI</span>.
See also Cade Metz, The New York Times, May 17, 2024, https://www.nytimes.com/2024/05/17/technology/openai-superalignment-safety-team.html.
[24] On the cascade of safety-related departures at OpenAI: (a) Aleksander Madry (Head of Preparedness) reassigned, July 2024; (b) Miles Brundage resigned, AGI Readiness disbanded, October 23, 2024, https://www.cnbc.com/2024/10/24/openai-miles-brundage-agi-readiness.html; (c) Mission Alignment dissolved, February 11, 2026, https://techcrunch.com/2026/02/11/openai-disbands-mission-alignment-team-which-focused-on-safe-and-trustworthy-ai-development/; (d) Ryan Beiermeister (VP of Product Policy) fired, January 2026, https://www.cnn.com/2026/02/11/business/openai-anthropic-departures-nightcap.
[25] Alnoor Ebrahim, quoted in “OpenAI has deleted the word ‘safely’ from its mission,” The Conversation, republished by Fortune, February 23, 2026. https://theconversation.com/openai-has-deleted-the-word-safely-from-its-mission-and-its-new-structure-is-a-test-for-whether-ai-serves-society-or-shareholders-274467.
[26] OpenAI, “Preparedness Framework Version 2,” April 15, 2025. https://openai.com/index/updating-our-preparedness-framework/.
[27] Anthropic, “Anthropic’s Responsible Scaling Policy,” September 19, 2023, https://www.anthropic.com/news/anthropics-responsible-scaling-policy.
[28] “Exclusive: Anthropic Drops Flagship Safety Pledge,” TIME, February 24, 2026. https://time.com/7380854/exclusive-anthropic-drops-flagship-safety-pledge/.
[29] SaferAI, “Anthropic’s Responsible Scaling Policy Update Makes a Step Backwards,” https://www.safer-ai.org/anthropics-responsible-scaling-policy-update-makes-a-step-backwards.
[30] Melissa Heikkilä, “AI companies promised the White House to self-regulate one year ago. What’s changed?”, MIT Technology Review, July 22, 2024. https://www.technologyreview.com/2024/07/22/1095193/ai-companies-promised-the-white-house-to-self-regulate-one-year-ago-whats-changed/.
[31] (a) Google Gemini 2.5 Pro released March 25, 2025, without safety report: Fortune, April 9, 2025, https://fortune.com/2025/04/09/google-gemini-2-5-pro-missing-model-card-in-apparent-violation-of-ai-safety-promises-to-us-government-international-bodies/. (b) UK parliamentary open letter, August 29, 2025: TIME, https://time.com/7313320/google-deepmind-gemini-ai-safety-pledge/.
[32] Billy Perrigo, “Exclusive: OpenAI Lobbied the E.U. to Water Down AI Regulation,” TIME, June 20, 2023, https://time.com/6288245/openai-eu-lobbying-ai-act/.
[33] Corporate Europe Observatory: 86% of meetings figure from “Byte by byte: How Big Tech undermined the AI Act,” November 2023, https://corporateeurope.org/en/2023/11/byte-byte. €97M lobbying figure from “The lobby network: Big Tech’s web of influence in the EU,” August 2021, https://corporateeurope.org/en/2021/08/big-tech-takes-eu-lobby-spending-all-time-high.
[34] Federal lobbying figures: OpenAI, https://www.opensecrets.org/federal-lobbying/clients/summary?id=D000084252; Anthropic, https://www.opensecrets.org/orgs/anthropic-pbc/lobbying?id=D000106114. See also MIT Technology Review, January 21, 2025, https://www.technologyreview.com/2025/01/21/1110260/openai-ups-its-lobbying-efforts-nearly-seven-fold/.
[35] On California SB 1047 and Governor Newsom’s veto, September 29, 2024. NPR, https://www.npr.org/2024/09/20/nx-s1-5119792/newsom-ai-bill-california-sb1047-tech.
[36] Leading the Future super PAC. CNBC, January 30, 2026, https://www.cnbc.com/2026/01/30/ai-industry-super-pac-raises-campaign-money.html. Axios, January 30, 2026, https://www.axios.com/2026/01/30/openai-a16z-cash-ai-super-pac.
[37] AnthroPAC, FEC ID: C00946111, filed April 3, 2026, https://www.fec.gov/data/committee/C00946111/. $20M to Public First Action (February 2026 corporate donation): Axios, April 3, 2026, https://www.axios.com/2026/04/03/anthropic-midterms-pac. See also OpenSecrets, https://www.opensecrets.org/news/2026/03/anthropics-ai-safety-stance-clashes-with-pentagon-and-reshapes-spending-on-primaries/.
[38] Olivia Borgula, “AI-aligned super PACs are pouring millions into Texas congressional races,” Texas Tribune, April 1, 2026, https://www.texastribune.org/2026/04/01/texas-congress-ai-super-pacs-artificial-intelligence-regulation-2026-midterms/. Syndicated to Houston Public Media, https://www.houstonpublicmedia.org/articles/news/politics/election-2026/2026/04/01/547787/texas-congress-ai-super-pacs-artificial-intelligence-regulation-2026-midterms/.
[39] Anthropic, “Project Glasswing: Securing critical software for the AI era,” April 7, 2026, https://www.anthropic.com/project/glasswing.
[40] Sam Sabin, “Anthropic withholds Mythos Preview model because its hacking is too powerful,” Axios, April 7, 2026, https://www.axios.com/2026/04/07/anthropic-mythos-preview-cybersecurity-risks.
[41] Kylie Robison, “Exclusive: Anthropic ‘Mythos’ AI model representing ‘step change’ in power revealed in data leak,” Fortune, March 26, 2026, https://fortune.com/2026/03/26/anthropic-says-testing-mythos-powerful-new-ai-model-after-data-leak-reveals-its-existence-step-change-in-capabilities/.
[42] Anthropic Series G ($30B round, $380B valuation), February 12, 2026. https://www.anthropic.com/news/anthropic-raises-30-billion-series-g-funding-380-billion-post-money-valuation. See also Bloomberg, February 12, 2026, https://www.bloomberg.com/news/articles/2026-02-12/anthropic-finalizes-30-billion-funding-at-380-billion-value.
[43] On the Anthropic-Pentagon conflict: Pentagon contract, July 14, 2025, https://www.anthropic.com/news/anthropic-and-the-department-of-defense-to-advance-responsible-ai-in-defense-operations; Trump directive and OpenAI Pentagon deal, February 27–28, 2026: Shannon Bond and Geoff Brumfiel, “OpenAI announces Pentagon deal after Trump bans Anthropic,” NPR, https://www.npr.org/2026/02/27/nx-s1-5729118/trump-anthropic-pentagon-openai-ai-weapons-ban; supply chain risk designation, March 5, 2026, https://www.cnbc.com/2026/03/05/anthropic-pentagon-ai-claude-iran.html; Judge Rita Lin ruling, March 26, 2026, https://www.cnbc.com/2026/03/26/anthropic-pentagon-dod-claude-court-ruling.html.
[44] On the commercial outcome of the Pentagon standoff: ChatGPT uninstalls surged 295%, TechCrunch, March 2, 2026, https://techcrunch.com/2026/03/02/chatgpt-uninstalls-surged-by-295-after-dod-deal/; Claude reached #1 in the U.S. App Store, TechCrunch, March 1, 2026, https://techcrunch.com/2026/03/01/anthropics-claude-rises-to-no-2-in-the-app-store-following-pentagon-dispute/ (article originally published at #2, updated when Claude reached #1); CNBC, February 28, 2026, https://www.cnbc.com/2026/02/28/anthropics-claude-apple-apps.html; Caitlin Kalinowski resignation, March 7, 2026, Fortune, https://fortune.com/2026/03/07/openai-robotics-leader-caitlin-kalinowski-resignation-pentagon-surveillance-autonomous-weapons-anthropic/; open letter, TechCrunch, February 27, 2026, https://techcrunch.com/2026/02/27/employees-at-google-and-openai-support-anthropics-pentagon-stand-in-open-letter/; amicus brief, Fortune, March 10, 2026, https://fortune.com/2026/03/10/google-openai-employees-back-anthropic-legal-fight-military-use-of-ai/.
[45] Anthropic, “Disrupting the first reported AI-orchestrated cyber espionage campaign,” full report, November 13, 2025, https://www.anthropic.com/news/disrupting-AI-espionage.
[46] On data center opposition: Data Center Watch report, https://www.datacenterwatch.org/report. Sanders/Ocasio-Cortez legislation: Sanders press release, March 25, 2026, https://www.sanders.senate.gov/press-releases/news-sanders-ocasio-cortez-announce-ai-data-center-moratorium-act/. See also AP via PBS, https://www.pbs.org/newshour/politics/ocasio-cortez-and-sanders-push-bill-to-impose-ai-data-center-moratorium.
[47] Reporting on the Ron Gibson shooting, Indianapolis, April 6, 2026. AP via Washington Post, https://www.washingtonpost.com/nation/2026/04/06/data-center-threat-shooting-indianapolis/. CBS News, https://www.cbsnews.com/news/indianapolis-councilor-ron-gibson-home-shooting-data-centers-note/. See also WFYI, https://www.wfyi.org/2026-04-06/indy-city-county-councilor-ron-gibson--home-targeted-in-shooting.
[48] Reporting on the attack on Sam Altman’s residence, San Francisco, April 10, 2026. The New York Times, https://www.nytimes.com/2026/04/10/us/open-ai-sam-altman-molotov-cocktail.html. See also NBC News, https://www.nbcnews.com/tech/tech-news/openai-ceo-sam-altman-molotov-cocktail-house-headquarters-rcna273694; SF Standard, https://sfstandard.com/2026/04/10/sam-altman-russian-hill-molotov-cocktail/.
[49] On Fortune‘s AI-generated content: Nick Lichtenberg, approximately 600 AI-produced stories, 20 percent of traffic. Primary reporting: Isabella Simonetti, Wall Street Journal, ~March 26, 2026. See also Semafor, July 6, 2025 (original coverage of Fortune’s AI initiative), https://www.semafor.com/article/07/06/2025/fortune-and-axios-warm-to-ai.
[50] Emma Tucker email to Alyson Shontell, reported by Max Tani, Semafor, ~April 6, 2026.
In an email shared with me, WSJ EIC Emma Tucker praised Fortune's use of AI in its journalism, saying "anyone who doesn't get what you are doing at Fortune, or thinks it is 'wrong', should get out of journalism fast!"
Journalist Nick Lichtenberg produced more stories in six months than any of his colleagues at Fortune delivered in a year. His work involves what some view as the third rail of journalism: AI playing a leading role in writing stories. 🔗 https://t.co/s8lWa4WYeV
See also Talking Biz News, https://talkingbiznews.com/media-news/wsjs-tucker-impressed-with-fortunes-ai-strategy/.
[51] Will Douglas Heaven, “How existential risk became the biggest meme in AI,” MIT Technology Review, June 19, 2023, https://www.technologyreview.com/2023/06/19/1075140/how-existential-risk-became-biggest-meme-in-ai/. Chollet quoted: “If you want people to think what you’re working on is powerful, it’s a good idea to make them fear it.”
[52] Meredith Whittaker, quoted in the same article as [51]. https://www.technologyreview.com/2023/06/19/1075140/how-existential-risk-became-biggest-meme-in-ai/.
[53] Richard Ren et al., “Safetywashing: Do AI Safety Benchmarks Actually Measure Safety Progress?”, arXiv:2407.21792, July 2024. Published at NeurIPS 2024. https://arxiv.org/abs/2407.21792.
[54] Kevin Wei et al., “How Do AI Companies ‘Fine-Tune’ Policy? Examining Regulatory Capture in AI Governance,” AIES ‘24, Vol. 7(1), pp. 1539–1555. DOI: 10.1609/aies.v7i1.31745. https://doi.org/10.1609/aies.v7i1.31745.
[55] Emily Bender and Alex Hanna, “AI Causes Real Harm. Let’s Focus on That over the End-of-Humanity Hype,” Scientific American, August 11, 2023. https://www.scientificamerican.com/article/we-need-to-focus-on-ais-real-harms-not-imaginary-existential-risks/.
[56] Timnit Gebru, “Effective Altruism Is Pushing a Dangerous Brand of ‘AI Safety,’” WIRED, December 13, 2022. https://www.wired.com/story/effective-altruism-artificial-intelligence-sam-bankman-fried/.
[57] Meredith Whittaker, “The steep cost of capture,” ACM Interactions 28, no. 6 (November–December 2021): 50–55. DOI: 10.1145/3488666. https://dl.acm.org/doi/10.1145/3488666. [Emphasis added.]
[58] Kate Brennan, Amba Kak, and Sarah Myers West, “Artificial Power: AI Now 2025 Landscape Report,” AI Now Institute, June 3, 2025. https://ainowinstitute.org/publications/research/ai-now-2025-landscape-report.
[59] Center for Countering Digital Hate, “Killer Apps: How Mainstream AI Chatbots Assist Users Planning Violent Attacks,” March 11, 2026 (in collaboration with CNN Investigations Unit). https://counterhate.com/research/killer-apps/.
[60] Lee Vinsel, “You’re Doing It Wrong: Notes on Criticism and Technology Hype,” Medium, February 1, 2021. https://sts-news.medium.com/youre-doing-it-wrong-notes-on-criticism-and-technology-hype-18b08b4307e5.
[61] Christopher Horrocks, “Virtual Intelligence and the Accountability Chain,” Virtual Intelligence (Substack), https://chorrocks.substack.com/p/virtual-intelligence-and-the-accountability, March 20, 2026.