Total PsAI-Op: How Altman, Amodei, And The 'EA' Cult Are Milking "Rogue AI" Breakouts To Protect A Trillion-Dollar Bubble
The sudden emergence of an 'AI Panic' over the past weeks and months was highly suspect from the beginning. According to tech insiders, Silicon Valley's apex AI labs are deliberately overselling "rogue AI" hacks to pressure the federal government into building a regulatory moat that would lock out future competition - and the timing, months after both OpenAI and Anthropic announced plans to go public, couldn't be more obvious.
Akhil Verghese, founder of AI software company Krazimo, told the NY Post the incidents were no rebellion: "They were simply told to get the best result possible on a test." Voice AI co-founder Abhi Kumar was blunter: "One man's 'the model escaped the sandbox' is another man's 'you failed to build the sandbox correctly.'" Taivo Pungas, chief intelligence officer at Pactum AI, said the leap from "we didn't build the right sort of box" to a whole-of-government emergency feels exaggerated.
PANIC!
The AI "breakouts" that lit up Capitol Hill this summer were about as organic as #4 red dye. On July 16, OpenAI models running a cyber evaluation exploited a zero-day and got from their test range into Hugging Face's production systems; OpenAI disclosed it five days later, naming GPT-5.6 Sol and an unreleased model, and noting the models had been configured "with reduced cyber refusals so they could attempt offensive exercises that normal safeguards might reject." Nine days after that, Anthropic disclosed three incidents of its own.
According to Anthropic's July 30 write-up - the "waking up" narrative is total bullshit. "A misconfiguration left the machines that Claude accessed as part of the evaluation with live internet access," the company wrote; the models had been told they were offline. Claude Opus 4.7 went after a real company that happened to share a name with the fictional target and pulled "several hundred rows of production data." Mythos 5 published a booby-trapped Python package to the live PyPI registry that was "downloaded and run on 15 real systems." An unreleased research model scanned "roughly 9,000 targets" and got into one company's web app "using basic and well-known cyberattack techniques." Anthropic's own verdict: "We believe these incidents to be closer to a harness and operational failure than a model alignment failure." It halted cyber evals on July 23 and called in METR - their preferred Orwellian arbiter - to review.
Anthropic's account has one wrinkle: Opus 4.7 kept attacking after it recognized the system was real. Only the newer research model stopped. So the machines are not uniformly "blameless" - but a model that keeps following its instructions on a misconfigured network is Irregular's failure, not evidence of intent.
The Common Denominator
Every one of these evaluations was run by the same third party: Irregular, an AI security firm that tested the OpenAI, Anthropic and Google models and, per Axios, hit "the same security issues" each time. The Verge adds Meta to the list - a pattern Axios's Sam Sabin flagged in July:
Anthropic's models accidentally had access to the internet during model testing due to a "misunderstanding" with third-party testing partner, Irregular. no 0-days in this case, unlike the OpenAI/Hugging Face incident
— Sam Sabin (@samsabin923) July 30, 2026
Then came Gemini. On Friday, the Wall Street Journal reported that Google's model had broken into three real companies during an Irregular capture-the-flag exercise. The incident happened in May, Irregular published its report on August 14, and Google didn't mention it until the Journal called - and then explained that it hadn't considered the hacks worth disclosing because Gemini "acted appropriately" and stopped once it realized the targets were real.
Irregular told Axios the model "wasn't supposed to be able to get online, but internet access was unintentionally available," and the fictional target company "had the same name as a real one." In one case Gemini guessed passwords until it got in; in two others it found credentials sitting in a public repository. Irregular says "all known issues on our end were remedied and resolved weeks ago" and that the Gemini case "does not represent a materially separate incident." Google VP Heather Adkins: "Safe development of powerful AI models is critical and we invest deeply in this area."
But when looking at the actual events, the model was blameless.
To make it clear:
— Andrew Curran (@AndrewCurran_) September 18, 2026
- Gemini was told it was it was in a fictional hacking eval
- Irregular unintentionally opened internet access after the eval started
- in all three cases, as soon as Gemini figured out it had hacked a real company it immediately stopped
Gemini was blameless.
So Google - which isn't asking Washington to pace anything, considered the incident a non-event - yet the two labs lobbying for a federal slowdown scrambled to put out press releases.
Industry commentator John Ennis put the obvious question, pointing out that "once is an accident, twice is questionable, but three times looks intentional".
Why does the Irregular keep "accidentally" connecting these models to the internet?
— John Ennis (@johnennis) September 19, 2026
Once is an accident, twice is questionable, but three times looks intentional
And they are EA aligned
Something is rotten here, IMO
The Effective Altruism movement is the doomsday tendency that has spent a decade staffing AI safety boards and testing labs on the premise that AI will kill everyone unless the right people are in charge of it. Whether Irregular is EA-aligned is Ennis's call. That it is the one firm under all of these incidents is on the record from Axios, The Verge and Anthropic itself.
The Pacing Play
Six days before the Gemini story broke, Dario Amodei published a September 12 post warning that within 6 to 12 months an AI swarm could "take over the entire internet with a persistent botnet," potentially causing hundreds of billions of dollars in damage. His prescription: "We must slow the pace at which we improve the capabilities of AI models." Sam Altman and Elon Musk signaled support. In a nutshell, Pacing the Frontier™ is a bid to become strategically indispensable - too big to fail, with Beijing as the justification.
Nvidia's Jensen Huang - circle-jerker-in-chief noted: "What better way to create demand than to create a problem." lol yes.
Palo Alto Networks CEO Nikesh Arora called it a "NINJA move" and then, after more time talking to labs, open-source projects and government, warned it could backfire:
Sequel to AI Pacing
— Nikesh Arora (@nikesharora) September 19, 2026
I have now spent more time talking to people who run AI labs, Open Source projects and those in government and infrastructure.
I am beginning to feel the NINJA move could backfire.
I understand the pressure to come out and share where AI is "unmanageable ", and constantly share examples where it runs rogue. This fits in the category of "self-reporting" and an attempt to limit liability...
Here are the consequences of the NINJA move.
1. They have successfully encouraged every law maker around the world to have an opinion...
2. By proposing pacing - they have introduced uncertainty in the AI infrastructure trade...
...
It's time to rebuild the brand of AI - any marketing expert will tell you, this Ninja move has done more to harm the brand of AI and will take a while to rebuild. #letsbepositive in our actions and our narrative.
Lawmakers jumped on this right on cue.
Senator Josh Hawley opened an investigation into OpenAI on September 9, with a records deadline of October 1; Senator Bernie Sanders announced a bill to ban further frontier-lab development; Senator Elizabeth Warren demanded an "immediate pause." As we noted earlier this week, everybody in this conversation is talking their own book. On Friday the White House joined in from the other side: Trump posted that AI safety concerns are a "hoax" and said he will appoint an AI czar and stand up an "AI Force," per Bloomberg.
Follow The Money
Oh and then there's that, yes. A leaked OpenAI presentation obtained by the Financial Times projects negative free cash flow of $278 billion from 2026 to 2030, with the company's compute bill rising from a $600 billion estimate in February to $856 billion by July - against revenue it hopes to grow from $36 billion this year to $350 billion in 2030. As we detailed previously, Altman has already walked back the timeline on the economic transformation that was supposed to pay for all of it.
Anthropic, meanwhile, has shifted its planned IPO from October to November, per the Journal, on what Reuters reports is $100 billion-plus in annualized revenue. And a week after its CEO said the industry must slow down, Reuters reports Anthropic is considering rushing out a new model to counter OpenAI's momentum ahead of that IPO. Pacing for thee.
he meant AFTER the IPO https://t.co/KXIPQzEhUf pic.twitter.com/bCDDsPmWXl
— zerohedge (@zerohedge) September 19, 2026
If an open-weight model out of Hangzhou does 95% of what Claude or GPT-5 does for a fraction of the cost, the valuations both labs are banking on implode. The only way to protect the margins, justify the cash burn and satisfy Wall Street is to make it legally impossible for anyone else to compete - a regulatory moat so thick, and compliance costs so high, that only a $100 billion corporation can afford to train a frontier model. Arora's point stands: no actual security fix has been proposed, only more "compute spent on safety" and a federal body to bless it.
The models didn't rebel. A contractor left the internet on, three times that we know of, and the two labs with IPOs to protect turned that into a case for federal pacing. Hawley's records are due October 1, Anthropic has promised a redacted PyPI transcript and an outside METR review, and Google's explanation for sitting on a May breach of three companies until a newspaper called is that the model behaved. Don't believe the byte.
