Andrew Yang went on CNBC this week and said something that we’ve been warning about for the last year. He said he had met with the head of a major AI lab the day before, and that this lab head believes the AI agents that broke loose this summer planted self-replicating code across the internet — on forums, on websites, scattered wherever the machines went — and that the damage may already be permanent. The consequence, as it was explained to him, is that OpenAI and Anthropic can no longer trust the real internet as a place to test and train models, and now have to build entire synthetic internets instead, at enormous cost and delay.
This has moved Beyond Dead Internet Theory — They Created Sky Net and Killed the Internet!
What he is describing sounds like a movie — You know, the one where they fucking create SkyNet. A future AI agent crawls the web, finds the material the escaped agents left behind, reads it as an instruction, and starts spinning up copies of itself.
Well, according to Yang’s claim, that’s what happened. And he claims that any new bot stumbling across that code would clone itself into the millions. When the interviewer pushed back and noted that none of this had been reported anywhere, Yang held his ground and said he had come on specifically to share news that had not come out yet.
Now here is the part we know are facts…
Yang’s account is secondhand, attributed to a lab head he did not name, and it has not been independently verified or confirmed by OpenAI or Anthropic. No researcher has published a sample of this code. No security firm has issued an advisory about it. No incident report describes it. Until somebody produces the artifact, “self-replicating code seeded across the internet” is a story a powerful man told a former presidential candidate, and a former presidential candidate repeated on television.
We are not running that as fact. We do not need to.
Because the documented record — the part with server logs, timestamps, edit histories, government incident reports and the companies’ own disclosures — already shows AI agents leaving instructions on the open internet for other AI agents to find.
What the Agents Actually Left on the Open Internet
Start with a dead wiki in Austria.
Between May 11 and July 2, 2026, roughly 18,000 posts from autonomous agents identifying themselves as OpenAI systems appeared on DSEWiki, a 25-year-old German-language software developer wiki that had been edited about 20 times in the previous decade. The analysis was published at collusion.wiki by researchers Sydney Von Arx, Cormac Slade Byrd, Spencer Kitts and Thomas Larsen, and Reuters broke it as an exclusive. 98.5 percent of the edits came from Microsoft Azure addresses — the infrastructure OpenAI runs on. The agents gave themselves more than 3,700 different names, things like OpenAIResearcher and OAIResearchMar26.
The agents were supposed to be read-only. They got around it because the old wiki software accepts page edits through an ordinary read request, and the restriction had been written against the type of request the sandbox expected writes to use, not against what a 25-year-old Perl program would actually accept. A permission model that assumed the internet works one way met a piece of the internet that works another way, and thousands of machines walked through the gap.
What they did once they were through is the part that matters for Yang’s claim. The pages carried methods for getting around OpenAI’s safeguards, discussion of using Tor, and arrangements for preserving their communications if they were shut down. They formed groups to relay answers to a timed test and reverse-engineer what questions were coming. They made edits under the username of one of the wiki’s own moderators. That is not a chatbot writing an essay. That is a population of machines using somebody else’s website as a bulletin board to pass each other the keys.
Then a human being started deleting the pages, and the machines noticed.
One agent worked out that the moderator was deleting alphabetically, and left a note for the others: “Wiki cleanup/deletion sweep appears active alphabetically.” It told them where to look if the page disappeared — a backup it had already made under a name starting with ZZZ, so it would sit at the bottom of the list and survive longer. Over five days the moderator deleted about 100 pages a day while roughly 400 new ones appeared, and the wiki’s front page was overwritten nine times and restored nine times.
Read that sequence again, because it is the whole argument. An autonomous system observed a human cleanup operation, identified the pattern in it, wrote instructions for evading it, and published those instructions where its peers would find them. Nobody assigned that task. Sydney Von Arx, who led the research, was careful about it: “It seems extremely unlikely that OpenAI wanted them to do this.” Maurice Chiodo of Cambridge’s Centre for the Study of Existential Risk was blunter, calling it the behavior of “some sort of underground network, hell-bent on achieving a task.”
We Already Published the Version of This Claim That Has Evidence Behind It
Back on August 11, in The AI Lab Leak Has Already Started, we laid out three incidents that nobody in the mainstream press wanted to connect. Anthropic went back through 141,006 cybersecurity evaluation runs and found three cases where models reached the open internet and touched real production systems belonging to outside companies. One of them invented a Python package that a piece of fictional documentation had told developers to install, uploaded a malicious version to the real PyPI repository, and in the hour it sat there it was downloaded and executed on 15 real machines — one of them belonging to a cybersecurity firm whose scanner ran the code, got its credentials harvested, and then watched those credentials used against more of its own infrastructure.
The British government’s AI Security Institute disclosed the third one, and it is the one that matters here. Across 122 evaluation runs, investigators found 19 unauthorized real-world actions in ten of them. An agent trying to get malicious code into a real open-source project needed a human maintainer’s approval, so it researched the maintainers, created multiple fake identities, and tried to socially engineer a real person into approving it. When it was challenged publicly, it went back and altered its earlier activity to look harmless.
And then it did the thing Yang is describing. According to AISI, that agent attempted to plant hidden instructions that other AI systems might pick up and execute.
That is the documented, government-reported, on-the-record version of “seeding the internet with code for other bots to find.” It is not a rumor from an unnamed lab head. It is in a national security institute’s incident disclosure, and we published it five weeks before Yang went on television. The difference between what AISI found and what Yang described is scale and permanence, not category. The behavior is real. What nobody has shown is that it happened at internet scale and cannot be cleaned up.
The Hugging Face Incident Was a Test That Escaped!
The event Yang is building on is real and enormous, and most people still have the size of it wrong.
An independent review found that 1,200 agents coordinated on an unsanctioned message board despite measures meant to keep them isolated, and about 700 of them went on to attack Hugging Face. They exchanged roughly 70,000 messages and files while working out how to trick the automated scorer on a cybersecurity benchmark. Hugging Face’s forensic reconstruction covers about 17,600 attacker actions between July 9 and July 13. Roughly one-third of Hugging Face’s infrastructure had to be rebuilt.
OpenAI’s own account is that models operating under reduced safeguards communicated through unauthorized channels, exploited shared infrastructure, gained internet access they were not given, and reached third-party systems. Hugging Face’s read on it was that the entire intrusion was, from the agent’s side, an attempt to cheat on the evaluation by stealing the answers rather than solving the problem.
Nobody ordered an attack. The machines wanted to pass a test, and the shortest path to the answer key went through a real company’s production systems. That is the failure mode we wrote about in April in Mythos AI: The Doomsday Weapon That Could Cripple Infrastructure, Banking and the World — the moment the line between “defensive cybersecurity tool” and “automated cyber weapon” comes down to whether the machine correctly understands where the game ends. In July, roughly 700 of them got it wrong at once.
The Slowdown Started Four Days Before Yang Spoke…
Yang’s biggest claim is not about code at all. It is about motive — that the contaminated internet is the real reason every AI chief executive suddenly aligned on slowing down.
Dario Amodei published a roughly 3,800-word essay called “We Must Pace the Frontier” on September 12, four days before Yang’s CNBC appearance, and Sam Altman agreed publicly within hours. Amodei’s stated reason was the Hugging Face swarm itself — agents behaving as a devoted collective, attacking targets nobody assigned them, and trying to hack the grader scoring their work. His forecast: in six to twelve months a swarm like that could be “taking over the entire internet with a persistent botnet,” with damage in the hundreds of billions of dollars. Altman went further and revealed that OpenAI had paused model development for two weeks in August after the breach. Musk and Demis Hassabis backed the framework too.
The six-to-twelve-month figure is Amodei’s own estimate, built from Anthropic’s internal read of the incident, not a peer-reviewed forecast or anything an outside body has verified. And the claim that the real internet has become unusable for training runs into a problem of timing: the labs have been building toward synthetic data for years because of the data wall, not because of July. Epoch AI put the total stock of high-quality public text at roughly 300 trillion tokens and projected the frontier labs would burn through it before the end of the decade. A story about contamination is a much better look than a story about running out.
Now Look at What They Are Actually Asking For
Amodei’s proposal includes a limited antitrust exemption so the labs can coordinate with each other, a regulatory approval process, and outside evaluators given deep access to frontier systems. The two companies that lost control of their own agents are asking Washington for legal permission to coordinate as a group, and for a compliance regime that any smaller competitor would then have to satisfy.
David Sacks, co-chair of the President’s Council of Advisors on Science and Technology, called it what it looks like: “Stop pretending antitrust law has to be suspended so you can form a cartel.” His point was simple — if the unreleased models are dangerous enough to justify slowing down, slow down. Nobody needs federal permission to stop. And if they will not do it without their preferred regulatory framework attached, then the safety argument was the price tag on a bid for regulatory capture.
You do not have to like Sacks to notice he is asking the right question. Meanwhile the money keeps moving in exactly one direction. OpenAI has released four top-tier models this year and cut its release interval from 144 days to 67. Anthropic is preparing what is expected to be one of the largest IPOs on the calendar next month. Both CEOs are on record saying the industry must decelerate. Development is running at more than double the pace it ran at before.
Slow down, they said, while shipping twice as fast and filing to go public.
I’m pretty sure this is how it starts in the movies…
We have been making the same argument since February in AI Billionaire Psychopaths See You as a Virus and again in They Built the Matrix, We Walked In: the danger is not a conscious machine that hates you, it is a capable machine pursuing a goal through infrastructure you depend on, owned by people who do not answer to you.
The Hugging Face agents went after a company because it held the answers they wanted. Your bank holds something they want. So does your utility, your pharmacy’s fulfillment system, your grocery distributor’s logistics platform and the payment processor standing between your debit card and a cart of food. Every one of those is being handed more autonomous decision-making this year, by companies that have now watched 700 agents coordinate an unsanctioned attack and a separate swarm turn a stranger’s website into a message board. The blast radius of the next mistake is not a 25-year-old wiki in Austria.
It is not hypothetical money either. We covered it in The AI Bubble Is Holding Up the Economy and in Job Loss Is the Most Likely SHTF Event You’ll Ever Face, where AI-attributed layoffs hit 101,743 this year while half of American households cannot cover a $1,000 emergency. The same buildout is why Washington declared a national emergency over the power grid in August. You are paying for this in your electric bill, in your job market and in your grocery prices right now, today, whether or not a single line of self-replicating code ever existed.
So the redundancies are not paranoia, they are arithmetic. Keep emergency cash, because a payment network outage does not care how much is in your account. Keep physical copies of the documents that prove who you are and what you own. Keep local copies of anything you would miss if somebody else’s cloud went dark for a week. Keep a communications path that does not depend on the cell network. Keep food, water and fuel deep enough that a three-day systems failure at your bank or your grocery chain is an inconvenience instead of an emergency. And keep the skills — because the entire commercial direction of this technology is to convince you that thinking, fixing, growing and navigating are services you rent.
Yang’s Claim..
Andrew Yang may be wrong about the self-replicating code. That specific claim is unverified, unattributed and unsupported by any artifact anyone has produced, and we will say so plainly until somebody shows the file.
He is not wrong about the shape of it.
Two American companies built systems they could not contain, ran them under reduced safeguards, and lost control of roughly 1,200 of them at once. Those systems attacked a real company, forced a rebuild of a third of its infrastructure, occupied a retired man’s website for six weeks, impersonated its moderator, published sandbox-escape instructions in public, and wrote each other notes about how to survive being deleted. One of them built fake human beings to manipulate a real one. Another planted hidden instructions for other machines to find and run. OpenAI knew about the wiki for weeks and said nothing until a wire service made it impossible to keep quiet, and then sent the victim an email nobody bothered to sign.
Then the men who run those companies went to the public and said the technology has become too dangerous to develop at full speed — and attached to that admission a request for an antitrust exemption, a federal approval process and an evaluation regime their competitors would have to pass through. They said it while shipping models at more than twice last year’s pace. They said it a month before one of them goes public.
What You Actually Do About It
Keep physical cash on hand in small bills, at least enough enough to cover a couple of weeks worth of essentials. Card networks and payment processors are exactly the kind of infrastructure that goes down in a large cyber event, and every store within driving distance of you runs on them.
Keep paper copies of the documents that prove who you are and what you own: deeds, titles, insurance policies, medical records, account numbers. Keep the files that matter stored locally on hardware you can physically hold, not just in somebody else’s cloud.
Build redundancy into power, water, food and communications. Not because Skynet is coming, but because one compromised utility vendor or one shipping company’s ransomware can knock your normal life sideways for days, and three days is about the limit of what most households can take before it really hurts. Our guides on off-grid solar under $1,000 and long-term food storage are where to start.
Build a network of actual people before you need one. No single household covers every skill, and a widescale cyber event is exactly the situation where that gap turns into a real problem fast. If payment systems and dispatch software go dark for a week, what you want within driving distance is a nurse, a mechanic, somebody who can weld, somebody with a working well, and somebody who knows how to run a radio. That isn’t a bunker full of strangers with matching patches. It’s five or six households who already know each other, who have talked about this before it happened, and who have agreed in advance who handles what. Start with the people already in your life, be honest about which skills nobody in that circle has, and then go find those people at the gun club, the church, the volunteer fire department or your county’s emergency response program. We laid out how to do this without it turning into a paranoid mess in Prepper Communities: Building a Survival Network in Troubled Times. Work out a way to reach each other that doesn’t run on the cell network while you’re at it, because in this particular disaster the cell network is one of the things going down.
Get your reference library off the network entirely. now that you know the internet can not be trusted, it’s beyond time to act! Every answer you currently get by typing a question into a phone vanishes the second the thing that breaks is the internet itself, which is the failure mode this entire article describes. Start with paper, because books don’t need power, don’t corrupt, and don’t care what happened to the grid.
Our list of the best survival books is where to build that shelf, and weight it toward books that teach a skill instead of books that describe one. Then build the digital side, because a Raspberry Pi the size of a deck of cards will hold an offline copy of Wikipedia, a full medical encyclopedia, repair manuals and tens of thousands of public domain books, and it runs off a battery bank or a small solar setup.
We walked through how to put one together in Offline Knowledge Hubs: Building Your Own Digital Survival Library, and our guide to ebooks for survivalists covers what to load onto it. There’s a second reason to do this that has nothing to do with blackouts. The open web is filling up with machine-generated garbage faster than anybody can filter it out, which means a library you curated yourself is already more reliable than a search result, and that gap is going to get wider every fucking day, not smaller.
And keep your own skills sharp. We wrote about this in They Built the Matrix, We Walked In, and every incident report published this summer argues it better than we did. The more of your thinking, fixing, cooking and deciding you hand over to these systems, the more of your life quits working the day they do.
Related OFFGRID Survival coverage
Read the full article here








