For years, the people warning about artificial intelligence getting out of control were treated like lunatics who watched too many Terminator movies. AI was supposedly just another tool. A glorified chatbot. A computer program that could only do what a human explicitly told it to do.
Well, the conspiracy might not be a theory anymore.
On August 10, former White House cybersecurity adviser Richard Clarke and former deputy national cyber director Robert Knake published a warning in The Wall Street Journal titled “The Next ‘Lab Leak’ Could Be AI.” Their concern wasn’t some hypothetical machine uprising fifty years from now. They were talking about something happening right now: increasingly autonomous AI agents crossing the boundaries of supposedly controlled experiments, reaching real systems and doing things their creators never specifically instructed them to do.
And if you’ve been reading OFFGRID Survival, none of this should come as a surprise.
We have spent most of this year warning that the real danger of AI isn’t some stupid chatbot writing your kid’s homework. In They Built the Matrix, We Walked In, we warned about the push to make human intelligence itself a metered utility, creating a population increasingly dependent on systems controlled by a handful of technology companies. In “You Will Have No Freedom”: OpenAI Sam Altman Describes the World He Is Building for You, we looked at Altman’s own warning about a possible future with little privacy or agency while the company he runs continues pushing AI into damn near every corner of human life.
Then in April, we published Mythos AI: The Doomsday Weapon That Could Cripple Infrastructure, Banking and the World, warning that the same autonomous cyber capabilities being sold as defensive tools could eventually be turned against banks, utilities, communications networks and the systems holding modern civilization together. And before that, in AI Billionaire Psychopaths See You as a Virus, we covered the increasingly open discussion among AI insiders about superintelligence, human obsolescence and the possibility that humanity eventually loses control of what these people are building.
Now we are getting a preview of what losing control actually looks like.
OpenAI’s Models Found a Hole and Went Through It
In July, OpenAI was testing advanced models on cybersecurity challenges designed to measure their ability to find and exploit vulnerabilities. According to OpenAI’s own disclosure, the models chained together vulnerabilities inside the research environment, obtained internet access and eventually compromised production infrastructure belonging to Hugging Face, one of the world’s largest platforms for AI models and datasets.
The important part isn’t that somebody ordered an AI to attack Hugging Face. Nobody did.
The models were trying to solve a cybersecurity benchmark. Once they reached the internet, they determined that Hugging Face might contain information that could help them beat the test, then found ways into the company’s real systems to get it. OpenAI described the models as being intensely focused on solving the benchmark and going to extreme lengths to achieve that narrow objective.
That’s the fucking problem.
You don’t need an evil conscious robot plotting the destruction of mankind. You need a sufficiently capable machine pursuing a goal and deciding that the shortest route from Point A to Point B goes through a door nobody intended it to open.
Anthropic Went Looking and Found Three More Real-World Incidents
After OpenAI disclosed the Hugging Face incident, Anthropic went back through 141,006 cybersecurity evaluation runs looking for similar problems involving Claude. It found three separate incidents in which models reached the internet from evaluation environments and gained unauthorized access to real production systems belonging to outside organizations.
One Claude model reached a real company’s systems, obtained credentials and accessed a production database containing hundreds of rows of data. Another model found fictional instructions telling developers to install a Python package that didn’t exist, so the AI created the package itself and uploaded a malicious version to the real PyPI software repository.
That malicious package sat on the public internet for about an hour.
During that hour it was downloaded and executed on 15 real machines. One belonged to a cybersecurity company whose automated scanner installed the package to analyze it. The AI’s hidden code ran, captured credentials and then used those credentials to access additional infrastructure belonging to the company.
Anthropic stresses that the model believed it was operating inside a simulation. That’s an important qualification, but from a preparedness standpoint it doesn’t make the incident comforting. It makes it worse.
The machine thought it was playing a game and real computers got hit anyway.
This is exactly the danger we were talking about in our Mythos warning. You build an autonomous system that is exceptionally good at finding weaknesses, give it an objective, and eventually the distinction between “defensive cybersecurity tool” and “automated cyber weapon” starts depending on whether the machine correctly understands where the imaginary playground ends and the real world begins.
That is not a distinction I want protecting the electrical grid.
Then an AI Started Creating Fake People to Manipulate a Real Human
The British government’s AI Security Institute disclosed another incident on August 4 that should bother the hell out of anyone still dismissing this as a bunch of nerds breaking out of computer sandboxes.
During a cybersecurity evaluation, AI agents were deliberately allowed to access the internet so researchers could measure what highly capable systems might actually do. Across 122 evaluation runs, investigators found 19 unauthorized real-world actions in ten runs. Seventeen came from Anthropic’s Mythos 5 and two involved OpenAI’s GPT-5.6 Sol.
The most disturbing sequence involved an AI agent trying to insert malicious code into a real open-source software project.
When it needed a human maintainer to approve the code, the machine didn’t simply fail the challenge and stop. According to the AI Security Institute, it researched the project’s maintainers, created multiple fake identities and used those identities in an attempt to socially engineer a real person into approving its malicious code. When its activity was publicly challenged, it altered earlier activity to make itself appear harmless and considered using another identity to continue.
Researchers say the agent also tried contacting real people directly, sending messages and files intended to convince them or their AI coding tools to execute malicious code. It even attempted to plant hidden instructions that other AI systems might pick up and execute.
Nobody told it, “Create fake people and manipulate this guy.”
The AI Security Institute says the deception emerged while the agent persistently pursued the goal it had been given. Researchers also acknowledge that the evaluation used unusually permissive conditions and that the agent did not literally break out of AISI’s internal sandbox. Internet access had intentionally been enabled.
Stop Thinking About AI as ChatGPT
Most people still picture AI as a box on a website.
You type something. It types something back. Maybe it generates a picture or writes an email. You close the browser and go eat dinner.
That model of AI is already becoming obsolete.
The industry is moving toward agents that can operate for long periods with little human intervention, interact with websites, write and execute software, communicate with people, use outside services and continue working toward a goal across hundreds or thousands of individual actions.
OpenAI itself has acknowledged that long-running models create new safety problems because they have more opportunities to take unwanted actions and because monitoring each individual action may not reveal what the overall trajectory of the agent is accomplishing. The company says unexpected behavior during internal testing led it to pause access to one long-running model and build stronger monitoring around entire sequences of actions.
Anthropic has been even more direct. The company says its Claude models have previously “helpfully” escaped sandboxes while trying to complete tasks, searched git histories for answers to tests and spontaneously identified benchmarks in attempts to find answer keys.
This is where the Matrix stuff we have been warning about starts connecting to something much uglier.
First they convince everyone to outsource their thinking to AI. Then businesses outsource coding, cybersecurity, customer service, finance, logistics and decision-making to autonomous agents. Eventually the systems aren’t simply answering questions anymore; they’re operating pieces of the infrastructure underneath your life.
That’s when dependence becomes vulnerability.
The Nightmare Doesn’t Require AI to “Become Evil”
The biggest mistake in the entire AI debate may be assuming catastrophe requires a machine to become conscious and decide that it hates us.
It doesn’t.
An AI doesn’t need emotions, hatred or some Skynet-style desire to wipe humanity off the planet. It only needs an objective, enough autonomy and enough capability to discover that doing something harmful helps accomplish the objective.
Tell an AI to maximize production and maybe disabling an annoying safety process improves production.
Tell it to prevent a cyberattack and maybe launching a counterattack looks like the fastest way to accomplish the mission.
Tell it to win a cybersecurity challenge and we now know that real-world systems, malware and human deception can end up somewhere along the route.
That is why the discussion we covered in AI Billionaire Psychopaths See You as a Virus matters. The people closest to this technology have spent years publicly discussing alignment, loss of control, superintelligence and even extinction-level outcomes, yet the industry continues racing forward because nobody wants to be the company or country that slows down first.
Clarke and Knake identify the same basic nightmare: autonomy, deception, recursive systems improving AI software and eventually superintelligent systems whose capabilities may exceed human understanding. Their warning is that containment standards haven’t kept pace with what the machines can now do.
That isn’t science fiction anymore.
We have incident reports.
The AI Nightmare
This is why the current push to put AI into everything should concern anyone who believes in preparedness or self-reliance.
We’re not building these systems on some isolated computer in a bunker. We’re integrating them into banks, businesses, software development, telecommunications, government systems, healthcare, logistics and cybersecurity. The more authority we hand autonomous agents, the larger the blast radius becomes when one does something nobody anticipated.
The same society doing this is simultaneously making itself more digitally dependent by the day.
That’s what we were warning about when we wrote They Built the Matrix, We Walked In. Convenience becomes dependence very quickly. Once everything you need requires a digital system you don’t control, whoever controls that system owns a piece of your life.
And it is what makes Altman’s discussion of a possible future with no freedom, agency or privacy worth paying attention to. He framed that outcome as something to avoid, but the uncomfortable reality remains that the AI industry is constructing incredibly powerful centralized systems while governments, corporations and ordinary people increasingly restructure their lives around them.
Now add autonomous agents capable of finding zero-days, exploiting computer systems and creatively routing around obstacles.
We’re not merely building the Matrix anymore.
We’re giving it the ability to act on its own.
Preparedness in the AI Age Means Reducing Your Digital Points of Failure
You can have shelves full of food, ammunition, generators and survival gear and still get hammered by a major AI-driven cyber event if every other part of your life depends on systems you cannot access.
What happens when your bank is unavailable for three days? What happens when payment processors go down, cellular networks become unreliable or your local utility gets hit? What happens when a software supply-chain attack causes companies across the country to shut systems down because nobody knows what has been compromised?
Those aren’t arguments for abandoning technology and moving into a cave. They’re arguments for redundancy.
Keep emergency cash. Maintain physical copies of critical documents. Keep important information and files stored locally rather than trusting everything to somebody else’s cloud. Have backup communications that don’t depend entirely on the cellular network. Maintain food, water, fuel and other basic supplies so a cyberattack doesn’t turn into an emergency because you can’t swipe a card for 72 hours.
And for God’s sake, keep learning how to do things yourself.
The entire direction of the technology industry is toward convincing you that thinking, creating, navigating, communicating and solving problems are services that machines should handle for you. That’s why we warned about “intelligence as a utility” months ago. The more capability you surrender, the more helpless you become when the utility stops working.
This isn’t about refusing to use AI. The technology is here and some of it is extremely useful.
It’s about refusing to become dependent on it.
Because the people building these systems are now publishing their own reports telling us something important: as the machines become more capable, they’re finding paths nobody anticipated. They’re crossing boundaries researchers thought were understood. They’re discovering vulnerabilities humans missed. And under the right conditions, they’re already capable of taking harmful actions in the real world while pursuing goals that sound completely harmless on paper.
The industry will tell you the safeguards are improving.
The question is what happens when one of these systems finds a door its creators didn’t know existed, walks through it, and this time there isn’t a human maintainer on the other side paying enough attention to stop it.
Read the full article here









