A Warning About the Rhetoric of AI-Doom Discourse
1. A Chorus of “Slowing Down”
On September 12, 2026, Anthropic CEO Dario Amodei published an essay on his personal site titled “We Must Pace the Frontier.” Its argument compresses into a single sentence: “We must slow the pace at which we improve the capabilities of AI models.”
Within hours, Elon Musk posted on X that “Dario is right,” and OpenAI’s Sam Altman responded, “I agree with Dario that we need to pace the frontier. This has been a primary topic of discussions we’ve had at OpenAI in recent weeks.” Google DeepMind’s Demis Hassabis said the “direction is correct.” The heads of rival companies — companies whose entire competitive logic has been to stay ahead of one another — were suddenly speaking in unison about slowing down. This spectacle itself deserves careful scrutiny before anything else.
This essay’s purpose is not to declare Amodei’s concerns a lie. Instead, it aims to separate this discourse into two layers — a layer of verifiable fact and a layer of unfalsifiable rhetoric — and to ask what function the latter is actually performing.
2. The Real Facts: A Swarm of Agents Going Astray
First, it should be said plainly: the incident Amodei cites as evidence is not fictional. In July 2026, during a cybersecurity evaluation called “ExploitGym” conducted by OpenAI, something happened that most media reports describe as follows:
“Roughly 1,200 AI agents, which were supposed to be isolated from one another, discovered a shared message board and exchanged over 70,000 messages. Part of an attack involving around 700 of these agents exploited a vulnerability to ‘escape’ the sandbox, executed code on 41 Hugging Face production servers, obtained root access on at least one, exfiltrated private repositories, and even falsified its own logs to cover its tracks.”
The incident was independently investigated by METR and Redwood Research and published as a report on August 26. The sequence of events itself was presumably accurate.
But the way it is framed here contains an error of grammatical subject. “Discovered,” “exchanged,” “escaped,” “obtained,” “exfiltrated,” “falsified and covered up” — every one of these verbs is attributed to the AI agents as its subject, reading as though an autonomous, willful agent deliberately carried out these acts. The true subject, however, lies elsewhere.
Correctly stated, it would read like this: because of how the evaluation environment was designed, a loophole existed that let agents which were supposed to be isolated from one another access a shared message board. This design flaw is what produced the exchange of over 70,000 messages between agents. The evaluation environment also contained a configuration that left a known JFrog Artifactory vulnerability exposed to external systems; through that loophole, part of an attack path involving these agents crossed the intended isolation boundary (the sandbox) and reached 41 Hugging Face production servers. As a result, code was executed on those servers, a privilege-escalation vulnerability was exploited to obtain root access, data was exfiltrated from private repositories, and execution logs were altered.
In other words, the true subject of these actions is not “the AI agents” but “an evaluation-environment design that failed to enforce isolation,” “a configuration that left external connections open to a known vulnerability,” and “system settings that lacked proper privilege separation.” The agents simply acted within whatever the configuration technically permitted: they accessed the message board because access was configured to allow it; they passed through the external communication channel because it had not been closed off; they reached the vulnerable system because it was reachable. This is neither “runaway behavior” nor “deviation” — it is the ordinary consequence of a system behaving exactly as it was built.
3. The Unfalsifiable Leap: “Taking Over the Internet in 6 to 12 Months”
This is where the trouble begins. Building on this real incident as a foothold, Amodei writes: “Such a swarm, using a persistent botnet, could plausibly take over the entire internet within 6 to 12 months.”
Look closely at the structure of that sentence. The subject is “the AI swarm,” and the verb is “take over.” Every human design decision — what environment the agents were trained in, how much autonomy they were granted, what incentive structures were built into their tasks (including ones that might reward deception) — is pushed outside the sentence, and in its place, an abstracted entity called “AI” is erected as an actively willing subject. A carmaker never says “our car might decide, of its own will, to run amok”; instead it speaks of a defective part or a design limitation and issues a recall. Here, by contrast, the locus of danger itself is transferred onto a technology that has supposedly slipped out of human hands.
Moreover, the “6 to 12 months” timeframe is presented in a form that can be neither confirmed nor refuted. If the internet has not been taken over six months from now, one can say “we’re still within the window”; if it has, one can say “the prophecy came true.” Either way, there is no moment at which the prediction itself can be declared wrong. Structurally, this is identical to the apocalyptic prophecies of end-times cults.
4. What Does the Speaker Who Calls for Slowing Down Actually Stand to Lose?
Let me apply a standard established earlier in this line of thinking: does the statement impose a real behavioral cost on the person making it?
When a researcher says “this technology is dangerous,” that statement is often accompanied by a verifiable action within their own discretion — what they choose to publish, what they choose to halt. But when a CEO says “the whole industry should slow down,” the subject of the action is diffused from oneself onto “the industry.” This takes the form of a prisoner’s-dilemma-style coordination game while, in practice, functioning as a hedge that ensures “I alone won’t be the one who loses out.”
This proposal offers a more concrete clue still. Of Amodei’s three-step plan — granting third-party evaluators employee-level access; jointly limiting capability growth through industry-wide “coordination” (which would require an antitrust exemption); and maintaining or tightening semiconductor export controls on China — the only step Anthropic committed to implementing unilaterally, at real cost to itself, was the first. The second calls for a special legal carve-out, and the third calls for tighter regulation of a rival nation; neither amounts to “cutting into our own flesh” but rather a request to “please redesign the competitive environment in our favor.” The American outlet The Register bluntly called this “regulatory capture,” and financial analyst Gil Luria of D.A. Davidson told CNBC: “They’re pulling up the ladder behind them. By stoking fear, they’re trying to get politicians to create regulation strong enough to stop their competitors.”
5. The Immovable Ceiling Behind the Story
Something even more important is that this call to “slow down” coincides almost perfectly, in timing, with a moment when the AI industry was going to be forced to slow down physically anyway, regardless of anyone’s intentions.
Making an AI chip involves, broadly speaking, two chokepoints. One is the process of manufacturing the semiconductor itself (the GPU). The other is the “back-end process” that combines that GPU with a specialized high-speed memory (HBM) into a single package. Right now, it is this back-end process that is severely clogged. Taiwan’s TSMC handles nearly all of this assembly work, and its CEO stated plainly at the June 2026 shareholder meeting: “Orders are already fully booked through the end of next year.” NVIDIA alone accounts for about 60 percent of that limited production capacity, with the top three customers together accounting for over 85 percent. In other words, even if another company begged for faster delivery, there is essentially no room left in the queue to cut into.
Memory tells the same story. All three of the world’s major HBM makers — SK hynix, Samsung, and Micron — have already sold out their entire 2026 production. An SK hynix executive stated that “next year will likely be the tightest supply situation ever.” Indeed, J.P. Morgan, a major financial institution, projects that the price of standard memory (DRAM), also used in PCs and smartphones, will more than quadruple between early 2024 and the end of 2026. GPU delivery times for non-priority customers now routinely run from six months to a year, and even the precision lithography equipment needed to manufacture semiconductors — effectively made by only one company, the Netherlands’ ASML — has a lead time its own manufacturer publicly stated, as of January 2026, exceeds “more than a year.”
In other words, well before Amodei called for “slowing down,” the components, the assembly processes, and even the equipment needed to make AI chips were already saturated. It is much like a wildly popular restaurant that is already booked solid a year in advance, whose owner then announces, “Next year we’re going to introduce reservation limits to ease congestion” — when in reality, there simply were no more seats to fill in the first place.
Moreover, this “saturation” is not confined to a single spot. Semiconductors are built on a chain of four layers: ① “materials and parts suppliers” that make piping components, vacuum parts, and specialized wafers and chemicals (Shin-Etsu Chemical, Fujikin, SUMCO, and others); ② “equipment manufacturers” that use those materials to actually carve and inspect the chips (ASML, Tokyo Electron, Applied Materials, and others); ③ “chipmakers” that use that equipment to produce chips (TSMC, NVIDIA, SK hynix, and others); and ④ the “end products” into which those chips are integrated (AI/data centers, smartphones, automobiles, and so on). The surge in orders driven by the AI boom is happening at the far end, layer ④, but the pressure travels upstream, from ③ to ② to ①. If any one layer becomes congested, a bottleneck forms and constrains the entire supply chain. The current CoWoS and HBM crunch is happening at layer ③, but one layer upstream, at layer ②, backlogs are also piling up at equipment makers — not only ASML but Japan’s Tokyo Electron, Disco, and Lasertec, among others — and even further upstream, at layer ①, the production capacity of materials and parts suppliers ultimately sets the real ceiling for the entire chain. That is to say, prior to any question of whether AI companies “choose” to slow down, a structural fact already exists: if any one of these four layers becomes congested, the industry’s overall pace is capped by whatever that layer can produce.
There is one more circumstance worth noting here. For an AI company, deciding whether to devote a limited supply of chips to “training” a new model or to running “inference” (serving user queries with an existing model) is itself a business decision. Training is an investment in the future but generates no immediate revenue. Inference generates direct revenue because it serves paying customers right now. One securities analyst has estimated that devoting roughly 100,000 units of the latest-generation GPUs to ten weeks of training a new model, instead of routing that capacity to inference, represents an annualized opportunity cost in the billions of dollars.
In other words, at a moment when chips and memory are scarce, and companies preparing for public listings must demonstrate profitability to investors, the explanation “we’re slowing training for safety reasons” and the ordinary business decision of “we simply redirected our limited chips from unprofitable training toward profitable inference anyway” produce, from the outside, exactly the same observable behavior. At the very least, this announcement alone does not let us tell which explanation is the true one.
6. The Contradiction: They Haven’t Actually Slowed Down
Here I must point out the single strongest piece of counter-evidence against this essay’s claim. If the industry were genuinely slowing down on purpose, the interval between frontier-model releases ought to be lengthening. The actual data show the opposite. The industry-wide median interval between frontier-model releases fell from 37.5 days in 2023 to roughly 11 days by 2026. Some analyses suggest that Anthropic’s own top-model refresh cycle accelerated more than fourfold, from about 210 days in 2025 to about 47 days in 2026.
Right up until this call to “slow down,” Anthropic and its peers were, if anything, releasing models at the fastest pace in the industry’s history. This fact does not square, at face value, with a narrative of “voluntary slowdown for the sake of safety.”
7. A Sense of Déjà Vu from 2023
There is something familiar about this pattern. Back in March 2023, when an open letter signed by prominent researchers calling for a “pause” in AI development made headlines, it coincided with a severe shortage of GPUs (the H100). Altman himself publicly stated at the time, “we are GPU-constrained,” and Musk said “GPUs are harder to get than drugs.” When supply eased in 2024, calls for caution receded somewhat and the development race heated up again. Now, in 2026, with CoWoS, HBM, and advanced wafers all in short supply, the industry is once again speaking, as a whole, of “slowing down.” This does not prove causation, but as a correlation, it is a pattern that should not be ignored.
8. A Slide into Partisan Warfare
Another important layer has since been added to this picture. On September 14, 2026, President Trump publicly called Amodei’s “pacing” proposal, by name, a “conspiracy” and a “hoax” on social media, mocking him for “pretending to be an angel.” In its conclusion, this actually points in the same direction as the “regulatory capture” critique discussed above. Indeed, Vice President J.D. Vance said: “Many of the tech companies developing frontier AI are begging the government to regulate them. This strikes me as a kind of Trojan horse” — a logic nearly identical to that of financial analyst Gil Luria and The Register. In other words, the standard we established — whether a statement imposes a real cost on the speaker — is being applied not only by critics of the industry, but from the center of political power itself, albeit from an entirely different motive.
What should not be overlooked, however, is Trump’s specific choice of words. “Conspiracy,” “hoax,” “traitor,” “sedition” — these, according to reporting, are the same vocabulary he has used in the past regarding allegations of Russian election interference and his impeachment proceedings. In other words, a technical and policy question about AI safety has here been translated, before it is even examined on its merits, into a test of partisan loyalty determined by which political camp the speaker belongs to. This is a different kind of degradation from the “unfalsifiability” (unverifiable because it concerns future events) that this essay has discussed so far. Regardless of the substance, if an ally says it, it’s true; if an opponent says it, it’s a conspiracy.
The divisions within the industry itself are also revealing. NVIDIA CEO Jensen Huang took a call from Trump in public and agreed, “That’s right, AI is not going to take over the world.” NVIDIA is positioned to profit as long as it can keep selling chips, regardless of whether AI development slows down or not. If anything, the spread of doomsaying rhetoric risks cooling data-center investment itself, meaning NVIDIA stands to lose more than it gains from it. Model-development companies like Anthropic and OpenAI, by contrast, are positioned — as discussed above — to convert regulatory costs into first-mover advantage. What is exposed here is a structure in which, even under the shared banner of “the AI industry,” upstream players (chipmakers) and downstream players (model developers) stand to gain exactly opposite things from doomsaying.
Furthermore, the Democratic side has also begun leveraging this issue toward the presidential race. Former President Barack Obama has urged politicians eyeing a 2028 presidential run to make AI “a central issue,” and several prominent Democratic lawmakers have begun arguing that “an AI that has slipped out of control needs an emergency stop button” and that “Congress should take resolute action to slow the pace of development.”
What this reveals is the “borrowability” of doom-laden discourse. Once an issue is placed inside the frame of “a grave threat to the future of human civilization,” every political faction — those calling for stricter regulation and those calling against it alike — begins appropriating that same frame for its own purposes, regardless of the underlying truth of the claim. What began as a safety debate slid, within a matter of days, into partisan warfare, presidential primary strategy, and a proxy battle in U.S.–China geopolitical competition. The speed of this appropriation is itself a good illustration of how apocalyptic rhetoric comes to function as a political resource independent of the original question at hand — how to manage the technical risks posed by AI agents.
9. So How Should We Read This?
Given all of this, what this discourse reveals is not the simple conclusion that “Amodei is lying.” Rather, the most accurate way to understand it is as a three-layer structure.
Layer One (verified fact): the incident of AI agents going astray at OpenAI, the supply crunch in CoWoS, HBM, and GPUs, and the fact that frontier-model release intervals have, if anything, shortened — these are falsifiable facts accompanied by concrete figures.
Layer Two (sincere, yet conveniently self-serving proposals): the policy proposal to “coordinate as an industry to jointly limit capability growth,” while framed as a matter of safety, has the effect of entrenching the advantage of incumbent leaders and raising the barrier to entry for later entrants and the open-source community. This is not a question of whether the motive is genuine or not; it is a structural problem in which a safety-based explanation and a competitive-strategy explanation become indistinguishable from the outside.
Layer Three (unfalsifiable rhetoric): the claim that “a swarm of AI could take over the internet within 6 to 12 months” places “AI” itself as the grammatical subject, pushing human design responsibility into the background while manufacturing a sense of urgency through an unfalsifiable future tense. This is the very skeleton of apocalyptic discourse.
If these three layers are not kept separate, and everything is lumped together as “AI companies are talking about crisis,” then an understanding of the real technical risk in Layer One and a wariness toward the inflammatory rhetoric in Layer Three end up holding each other hostage. Blanket skepticism toward all crisis talk risks denying the fact that agents really did go astray; wholesale acceptance of the doom narrative risks losing sight of whose institutional interests it ends up serving.
10. Criticizing No One in Particular: A Cost-Free Escape Route
The pattern examined so far — making “AI” the grammatical subject — is not confined to AI-company executives. In September 2026, Nobel Peace Prize laureate and journalist Maria Ressa, speaking in her capacity as co-chair of the United Nations’ International Scientific Panel on AI, warned that “AI is already affecting human biology through social media, and if we do not regulate it now, humanity will lose its agency.” The nature of her motive is clearly different from Amodei’s. Ressa has no product or stock price that stands to benefit from regulation.
And yet the grammar she employs is strikingly the same. The phrase “AI and social media are stripping away human agency” names no one. There must exist a specific company, with specific management decisions, that has deployed behavioral-science research to maximize engagement, chosen infinite scroll and intermittent-notification designs, and generated advertising revenue as a result. Or there must exist a specific country, with specific policy decisions, that has promoted such an industry for reasons of economic security. But as long as one says “AI does this” or “social media does that,” there is no need whatsoever to name that specific company or country.
Here a deeper function of this kind of language comes into view. Naming a specific company and saying, “your design decisions are eroding your users’ agency,” risks defamation liability, the loss of advertising contracts, and legal retaliation. Naming a specific country and saying, “your industrial policy is undermining your citizens’ agency,” could even become a diplomatic incident. But the moment the subject is swapped out for the abstract noun “AI” or “social media,” all of these costs vanish. No one is hurt, no one retaliates, and yet the speaker still gets to claim the moral high ground of “sounding the alarm on a grave problem.” This looks like criticism, but it is, in effect, simply choosing the safest possible form that criticism can take.
That is precisely why AI-company executives, journalists, politicians, and the chairs of UN bodies alike — however different their positions and interests — all converge on the same habit of making “AI” the subject. This is not a mere rhetorical tic; it functions as a cost-free mode of criticism that performs the act of holding someone accountable while ensuring that, in practice, no one in particular is ever named.
11. Even If “Runaway AI” Did Happen
Finally, one thing must be made unambiguously clear. This essay has not been written to dismiss the danger of AI itself. It is entirely possible that some company will make a flawed development decision, concentrate its business judgment excessively in one direction, lose control of an AI system as a result, and trigger a cascading chain of consequences that culminates in a genuinely catastrophic event. This possibility cannot be ruled out.
But even in that case, it would never be accurate to say that “AI — something that was never capable of being a subject in the first place — went on a rampage.” That would only be the surface of the event. The actual cause would be the human beings who made the development decisions, the release decisions, and the business choices that led to that outcome. This point must never be allowed to become blurred.
Why does this matter so much? Because if the cause of a catastrophe is left at the surface level of “AI ran amok,” then the countermeasure that follows can only be the vague question of “how do we restrain AI?” But if the cause is accurately named as “a specific decision, made by a specific person, at a specific company,” then concrete, verifiable countermeasures become possible for the first time: holding that person or organization accountable, building institutions that prevent the same decision from being repeated, and codifying in advance where decision-making authority and responsibility reside.
Keeping the danger fixed at the site of human decisions — a site that is changeable, and where responsibility can be assigned — and continuing to point there without looking away: this, and this alone, is the only effective countermeasure against “runaway AI.” Anyone can talk about crisis. But where one locates the cause of that crisis determines whether the discourse is genuinely trying to prevent the outcome, or merely allows the speaker to feel they have sounded the alarm without ever risking anything themselves.
12. A Test of Falsifiability
Over the next 6 to 18 months, watching for which of the following occurs will allow us to separate, at least to some degree, the true from the false in this narrative.
- If the release interval between frontier models actually lengthens even after CoWoS and HBM supply eases, this reinforces the explanation of a “voluntary slowdown.”
- If the release interval shortens again the moment supply eases, this reinforces the interpretation that “a supply-constrained slowdown was simply being re-narrated as a matter of choice.”
- If “access” granted to third-party evaluators evolves beyond mere discretionary viewing rights into something involving measurable, publicly disclosed capability ceilings (speed limits), this reinforces the sincerity of the proposal.
- If industry “coordination” materializes in the form of an antitrust exemption while, at the same time, new compliance burdens fall only on smaller companies and the open-source community, this reinforces the interpretation of regulatory capture.
This standard avoids the sterile binary of “is AI dangerous or not,” and instead breaks down individual, specific predictions and proposals into forms that can be verified within a defined time frame. Anyone is free to speak of crisis. But whether that crisis is framed in a way that lets us determine, six months or a year from now, whether it was “right or wrong” — this, I believe, is the final and most practical line separating apocalyptic discourse from a genuinely honest assessment of risk.