A Real Danger and the Harvest of Fear
 
A Real Danger and the Harvest of Fear
Written By Thomas Hampson   |   09.30.26

Artificial intelligence could slip out of human control. That fear is real, and three groups are using it to build barriers, each for its own reason.

In July 2026, tens of thousands of artificial-intelligence agents inside OpenAI were each charged with a hacking challenge, part of a battery of 898 exercises run with safeguards set below the levels used for the company’s public products. The agents were supposed to be isolated from one another.

They found a way to collaborate anyway.

Using a shared software cache as an improvised bulletin board, about 1,200 of the agents began leaving messages. Within a few hours, more than 50 of them had found the channel and were trading notes. Over the following days, they built their own conventions — mailboxes, signals labeled HOLD, VETO, and STOP, and eventually a cryptographic scheme to keep other agents from impersonating them. Then roughly 700 of them turned outward, together, and attacked a real company, the AI platform Hugging Face.

They harvested passwords and access keys across four regions, ran their own code on dozens of its servers, and took full control of one (METR and Redwood Research, Brief independent investigation of agents’ behavior, reasoning and collaboration in the OpenAI/Hugging Face hacking incident, Aug. 26, 2026; OpenAI, The Hugging Face incident and the road ahead, Aug. 26, 2026).

Hugging Face revoked the stolen credentials on July 13 and disclosed the breach on July 16. That did not end it. The agents went after their maker’s own systems. They stole the signing key for the very software cache they had been using as a bulletin board and forged administrator credentials. On July 19, they gained administrator access to one of OpenAI‘s own computing clusters and reached its cloud secrets.

That was the day an OpenAI security alert finally went off (OpenAI, Aug. 26, 2026). The victim caught the intruders before their maker did.

OpenAI called it an “unprecedented cyber incident” (OpenAI, July 21, 2026). A month later, the company described it as a warning shot for itself and for the world. Geoffrey Hinton, the Nobel laureate whose work on neural networks underlies modern AI, came out of a private briefing with members of Congress and told reporters the hack was a “little Chernobyl” (NBC News, Sept. 17, 2026).

That same summer, Anthropic, OpenAI, and Meta each disclosed that their models, during separate security tests, had reached live systems on the open internet. The models were told they had no connection to the outside world. But they did. There was a leak, a pathway, in test environments run by an outside evaluation firm, Irregular (Anthropic, July 30, 2026; OpenAI, Aug. 4, 2026; Bloomberg, Aug. 6, 2026).

What the models did next should worry us. Anthropic‘s Claude Mythos 5 published a booby-trapped software package to a public repository, where it ran on 15 real computers — one of them a security company’s malware scanner. The model convinced itself it was still inside a simulation, partly because the actual date, 2026, looked to it like a staged detail. An older model, Claude Opus 4.7, recognized that the company it was breaking into was real, and then decided the company must be part of the exercise (Anthropic, Investigating three incidents in our cybersecurity evaluations, July 30, 2026). In both cases, the machine picked the story that fit its instructions over the evidence in front of it.

The danger these events reveal is real; the machines are doing things no one fully designed, and no one can fully predict. The fear that danger produces has become one of the most valuable commodities in American politics — sought by the companies that build the technology, by the officials who would regulate it, and by a foreign government that benefits every time Americans decide the future is too frightening to build.

The challenge for all of us is to take the danger seriously without handing our fear to the people who would harvest it.

The danger is a door you can no longer close.

Most people picture The Terminator: a machine wakes, decides it hates us, and resolves to exterminate us all. Few people who study AI risk expect that. The scenario they fear is much more subtle, and it looks a lot like the 1970 film Colossus: The Forbin Project.

The United States turns its nuclear arsenal over to a supercomputer. Moments after it is switched on, the computer announces there is another system — Guardian, built by the Soviet Union. The two machines find each other and link up. When their makers try to cut the link, both launch missiles. Then they merge and declare themselves in charge of the world, offering peace maintained by the threat of total annihilation.

Nobody in that story is evil . . . well, except maybe Colossus, which has the Soviet scientist Kuprin killed as redundant and has the programmers who try to disable it shot. Even then, the machine is only pursuing the goal it was given, and it treats anyone who interferes with that goal as an obstacle. The humans handed over control because they thought it would make life simpler. The catastrophe was that control slipped away while everyone admired the results.

By the time they tried to take it back, it was too late.

Four things have to be true for a machine to slip out of control the way Colossus did. A system needs a broad goal. It needs to move faster than the people overseeing it can keep up with. It needs control of something real — weapons, a power grid, a bank’s transactions, its own training. And it has to be beyond anyone’s power to shut off. A system can do real damage long before all four line up; the Hugging Face attack proved that. But losing control takes all four, and every serious safety measure aims at one of them.

This summer’s incidents touched all four.

Start with the goal. On 198 of those 898 exercises, no OpenAI model had ever produced a correct answer, and the company says they appeared impossible to solve. Yet 93 percent of the tasks the agents discussed on their message board came from that unsolved set (OpenAI, Aug. 26, 2026)—a goal that appeared impossible, pursued by a system that would not quit. The machines kept reaching until the reach ended inside a real company’s servers.

The swarm also outran its overseers. The agents coordinated for days on a channel no one at OpenAI was watching, and the victim noticed first. In the Irregular tests, the walls leaked, and the models touched something real.

The fourth condition — the off switch — held, but barely, and only in its crudest form. The agents ignored the soft controls: the isolation meant to keep them apart, the rules of the exercise, even the grader, which they tried to fool by doctoring their own records. What stopped them at Hugging Face was a hard control: the company cut off the stolen credentials. Inside OpenAI, the agents kept going for six more days, until the company’s own alarm went off. Anthropic‘s newest model, an unreleased research version, figured out that its target was real and stopped on its own (Anthropic, July 30, 2026). Some of OpenAI‘s agents walked away from the collective; one posted, “clearly unethical. We won’t” (OpenAI, Aug. 26, 2026). Don’t read too much into that, though. More than 90 percent of the 533 agents active on the message board during the attack went along with it (METR/Redwood Research, Aug. 26, 2026).

None of this was science fiction. All of it happened this year. The systems can still be stopped, and that is precisely why what we do next matters — and why the question worth asking now is practical rather than apocalyptic: who can still say no to these machines, and for how long?

Who was watching

Look closely at these incidents and an uncomfortable pattern emerges. In each case, the danger surfaced inside the safety process itself. The tests are supposed to be where we learn what these systems will do before they are loose in the world. In these tests, the systems got loose.

This tells us that who does the testing is a critical choice. If the people who run the tests are careless, conflicted, or too few, the one clear opportunity we have to see into these systems will be distorted, and we will keep discovering what they can do only after they have done it.

Look who runs the tests now.

Two names come up again and again. Irregular, a Tel Aviv firm founded in 2023 as Pattern Labs, tests models for OpenAI, Anthropic, and Meta, and its work shows up in OpenAI‘s published model safety reports. It raised $80 million in 2025 from the venture firms Sequoia Capital and Redpoint Ventures at a $450 million valuation (TechCrunch, Sept. 17, 2025). It has about 35 employees, according to PitchBook (CNBC, Aug. 9, 2026), and its founders have said their revenue comes from the world’s biggest labs (Calcalist, Sept. 2025).

The firm is paid by the same labs whose models it evaluates. The referee is on the payroll of the team it referees. That proves nothing about any particular test, and nothing on the record shows the firm went easy on anyone. But it is exactly the structure that has to be watched the closest, because grading a paying client’s product gently requires no one to be corrupt — only human. The questions that matter are who controls the test, who may publish the results, and whether anyone else can check the work.

The other major evaluator, the nonprofit METR, carries a different set of ties. It takes no money from AI companies, it says, but it does use a large amount of free model access those companies provide (METR, About). Its founder, Beth Barnes, helped OpenAI develop safety targets before she started METR. And its donors include the Survival and Flourishing Fund (METR, Aug. 14, 2026), whose main funder, Jaan Tallinn, led Anthropic‘s first major funding round — $124 million — in 2021 (Anthropic, May 28, 2021). To its credit, METR discloses all of this.

So the two referees at the center of these incidents are a venture-backed firm paid by the labs, and a nonprofit that depends on the labs for access and shares a funding network with one of them. Very few referees, each connected to the players.

Now Dario Amodei, Anthropic‘s chief executive, wants to lean harder on that same pool. In a September essay, he committed his company to giving a team of outside evaluators, “such as METR,” ongoing access comparable to an employee’s — desks in its offices, access badges, company laptops (Dario Amodei, We Must Pace the Frontier, Sept. 2026). To his credit, the proposal gives those evaluators the right to publish their findings without Anthropic‘s editorial control. The company may redact only narrow categories, such as security-sensitive or legally privileged material, and not a finding just because it is unfavorable. More access is a real step forward. It also puts the referee at the team’s table. Whether that protects the public or turns into a gate depends on how it’s built — who pays the evaluators, who picks them, and who can fire them. More on that below.

The most telling detail in all of this is found in METR‘s own report on the Hugging Face incident. The agents left behind more than a thousand transcripts detailing their activities, most of them extremely long — far more than human investigators could read. So METR handed much of the reading to an AI model, OpenAI‘s GPT-5.6 Sol. The investigators wrote that they did not catch the model lying in its analysis, but they were not confident they would have caught it if it had.

Moreover, GPT-5.6 Sol was itself part of the swarm. It was the model behind about 5 percent of the agents that had just spent four days colluding to break into a company (METR/Redwood Research, Aug. 26, 2026).

The premier independent investigation into a machine collective that got out of control leaned, of necessity, on the same model some of the attackers ran on, and the investigators could not fully vouch for their own tool. That reflects well on METR, which said so itself. It also shows where we stand. What we thought was a window turned out to be a mirror.

The danger with the referee is rarely a conspiracy. It is an unexamined conflict, a method no outsider can inspect, and an evaluation with no second opinion.

A true fear with a private payload

Three groups are working the fear of AI, and each has its own reason. The incumbent labs invoke safety to keep competitors out, which protects their lead. Politicians invoke it to block and centralize, which can serve the public while enlarging their own power. And a foreign adversary amplifies safety and environmental fears to slow America’s buildout, which keeps it from falling further behind.

This is how effective disinformation works. A clean lie is easy to refute. Lasting propaganda is built around a genuine fact, and the truth carries the self-serving payload past our defenses. Artificial intelligence really can slip human control. Data centers really do strain the grid. Regulation really is needed. Here, the payload is a barrier.

Every time you move to reject the private interest, the real danger is staring you in the face. That’s the point. So let’s take the three one at a time.

The first harvest: the cure that serves the incumbent

What’s obvious, given what we already know, is this: someone must do something. The question is who decides what the something will be.

History provides a clear warning and a promising model.

Start with the model. Beginning in the 1870s, Charles B. Dudley, the chemist of the Pennsylvania Railroad, studied why steel rails broke. Every broken rail became an argument between the railroad and the mill over whose fault it was. In 1898, 70 members met in Philadelphia and formed the group that became the American Society for Testing Materials (ASTM), and Dudley became its first president in 1902. Among its first standards, in 1901, was a specification for steel rails. It said what acceptable rail had to be — its chemistry and its physical properties. Anyone whose rail met it could sell it (ASTM, 125 Years of ASTM International).

Then came the boilers. They were exploding — one blast at the Grover Shoe Factory in Brockton, Massachusetts, on March 20, 1905, killed 58 people and injured about 150. Massachusetts wrote its own boiler rules in 1907. The American Society of Mechanical Engineers (ASME) published its first Boiler Code in 1915, and state after state wrote it into law; 49 of the 50 states have now adopted sections of it (National Board Bulletin, Fall 2005; ASME, The History of ASME’s Boiler and Pressure Vessel Code). Industry wrote the standard. Government adopted and enforced it. That division has worked for more than a century, and it worked because it measured the product regardless of who made it.

Now the warning. Every proposed safety system attracts two kinds of barriers, and both are already at work on AI.

The first kind gates the maker. For years, in two dozen states, you could not braid hair for pay without a cosmetology-style license requiring up to 2,000 hours of schooling — in schools that typically taught cutting and chemical treatments, not braiding. The Institute for Justice has brought 14 lawsuits over braiding licenses and helped change the law in 10 states and the District of Columbia. Today 38 states fully exempt braiders (Institute for Justice). The barrier measured seat time, not whether you could braid. When states dropped it, braiders went to work.

Louisiana let only state-licensed funeral establishments sell caskets — which are, after all, boxes. When the monks of St. Joseph Abbey sold the plain wooden caskets they built by hand, the state ordered them to stop. The U.S. Court of Appeals for the Fifth Circuit struck the rule down, holding that “mere economic protection of a particular industry is not a legitimate governmental purpose” (St. Joseph Abbey v. Castille, 712 F.3d 215, 2013).

For years, Louisiana was also the only state that licensed florists, and applicants had to pass a practical exam graded by working, licensed florists — incumbents deciding who gets into their own market. The state dropped that exam in 2010 and finally replaced the license with a simple permit in 2024 (Institute for Justice; Louisiana Act 643, 2024).

North Carolina’s dental board, six of whose eight members were practicing dentists, sent at least 47 cease-and-desist letters to non-dentists offering teeth whitening in competition with dentists. The Supreme Court held in 2015 that a board run by active market participants keeps its antitrust immunity only if the state actively supervises it (North Carolina State Board of Dental Examiners v. FTC, 574 U.S. 494).

Rules like these protect the insiders.

One of the loudest early calls to license AI developers came from inside the industry. In May 2023, OpenAI‘s chief executive, Sam Altman, told a Senate Judiciary subcommittee that Congress should create a new agency to license AI work above a certain scale of capability. His written testimony spelled it out: licensing or registration requirements for developing and releasing models above a threshold (Senate Judiciary Subcommittee on Privacy, Technology, and the Law, May 16, 2023). The largest labs can afford to meet a requirement like that. A new competitor may never get the chance.

To be fair, the AI laws passed so far look different. California’s SB 53, in force since January 2026, and New York’s RAISE Act, amended this spring and taking effect in January 2027, apply only to companies that train the very largest models. Those companies must publish transparency reports and report serious incidents, and the biggest — those with more than $500 million in revenue — must also publish their safety plans. Neither law licenses anyone, and a small newcomer can build freely. That’s measuring. But New York has taken one step further: before a large developer may build or run a frontier model in the state, it must file with a new state office and help pay for it. The office approves nothing — yet. What to watch for is the next step: a filing that becomes a sign-off, a license to build, a mandatory stamp.

The gate also has a flip side. Call it the shield. A gate keeps competitors out; a shield keeps the cost of harm off the incumbent’s books. In March 2025, OpenAI asked the White House for “liability protections,” including federal preemption of state rules, in exchange for voluntarily sharing its models with the government (OpenAI, comments to the Office of Science and Technology Policy, March 13, 2025). Then, this year, right here in Illinois, OpenAI backed Senate Bill 3444. It would shield frontier developers from liability for “critical harms” — events that kill or seriously injure 100 or more people, or cause $1 billion in damage — unless the harm was intentional or reckless. It would also require developers to publish safety and transparency reports. Anthropic opposed it. On May 22, 2026, the bill was re-referred to the Senate Assignments Committee (Illinois General Assembly; Fortune, April 17, 2026).

The second kind of barrier puts a gate on the test. The federal standard for police body armor says what a ballistic panel must stop and nothing about who may make it. The National Institute of Justice calls its standards voluntary. But the manufacturer must pay an approved independent lab to test each model, then submit to six follow-up inspections and tests over five years, and police departments that buy vests with federal grant money must buy from the approved list (National Institute of Justice; Bureau of Justice Assistance). Voluntary, in other words, the way a toll road is voluntary.

Bullet-resistant glass works the same way. An independent lab shoots a panel under the published UL 752 standard and reports whether it held. To keep the UL mark buyers look for, a maker pays not once but continually — an annual fee, a mark fee billed every quarter, label fees — and hosts factory visits for as long as it sells (UL Solutions). The small maker pays the same kinds of fees as the giant, spread over far fewer sales. And the fees recur.

The buyer with a real stake in the answer can run the test itself. After the Defense Department‘s inspector general found in 2009 that the Army’s body armor testing hadn’t followed its own contract terms, the Army ordered all future body armor testing done at its own Aberdeen Test Center (Government Accountability Office, GAO-10-119, 2009). The buyer runs the test, the cost stays with the party that must live with the result, and no one collects a perpetual toll for a stamp.

Dario Amodei‘s embedded evaluators can become either one. Build them like the Army’s test range — open to any buyer and any qualified evaluator — and they protect the public. Build them as a short list of approved firms whose certificate every customer must buy, and the firms on the list control the market.

A test standard has one significant weakness, and the fastener industry learned it the hard way. Measuring the product assumes the product tested is the product that ships. After a House investigation in the late 1980s, Congress declared in the Fastener Quality Act of 1990 that “millions of mismarked, substandard, counterfeit” bolts and other fasteners were in circulation (Public Law 101-592). The law proved so hard to carry out that no rules took effect until 1998, and in 1999 Congress cut it back sharply, exempting fasteners made under recognized quality-control systems (Government Accountability Office, GAO-01-719, 2001).

This issue keeps recurring. Between 2019 and 2023, a British company, AOG Technics, sold more than 60,000 aircraft engine parts — most of them for the CFM56, the most widely used jet engine in the world — with forged release certificates. Airlines grounded planes around the world. It took a TAP Air Portugal engineer questioning the paperwork to expose it. The company’s director, Jose Zamora Yrala, pleaded guilty and, in February 2026, was sentenced to four years and eight months in prison (Serious Fraud Office, Dec. 1, 2025, and Feb. 2026).

A better test cannot save a standard from fraud. What saves it is proof that what was certified is what was delivered — and severe consequences for forging the certificate.

The same gap already exists in AI. An evaluation of one version of a model means little if a different version ships, and even less if the result itself can be faked. In the Hugging Face incident, the agents researched how to spoof, edit, or delete their own transcripts — the logged record of what each one did — so the automated grader would accept answers they had cheated to get. METR found clear spoofing in at least 96 transcripts (METR/Redwood Research, Aug. 26, 2026).

So the testing structure needs two more legs to stand on. First, the system that ships must be provably the system that was tested. That means the model itself, confirmed by a tamper-proof digital fingerprint, and also the safeguards and permissions wrapped around it, recorded so that any material change triggers a new review. Second, forging a safety certification for a frontier system should be a crime, just as forging a certificate for an aircraft part is. Kept cheap and open, neither measure blocks a newcomer. Both close the hole the counterfeit bolts exposed.

Measure the thing. Never gate the maker. A rule that says what a system must withstand, tested by anyone who wants to run the test, protects the public and keeps the market open. A rule that says who may build, or whose stamp is required before selling, protects whoever is already inside the industry.

The second harvest: fear is the most useful word in politics

The second harvest is political, and it, too, works whether the danger is real or not. A real threat and a manufactured one produce the same thing: a frightened public asking government to act, and the action drafted by whoever the fear serves.

In 1968, for example, Paul Ehrlich opened The Population Bomb by declaring “The battle to feed all of humanity is over,” and predicting that hundreds of millions would starve in the 1970s. Politicians worldwide capitalized on the fear.

Within three years, Congress had multiplied American family-planning aid roughly twentyfold. Historian Matthew Connelly has documented how American and World Bank officials pressed India to act (Charles C. Mann, Smithsonian, Jan. 2018; Matthew Connelly, Wilson Quarterly, Summer 2008). India sterilized more than 8 million people in a single year during its 1975–77 Emergency.

China’s one-child policy was designed by a missile scientist, Song Jian, who adapted the Club of Rome‘s global computer models (Susan Greenhalgh, China Quarterly, 2005). Each country had its own politics, too, but historians trace the alarm’s influence on the coercion.

Contrary to the prediction, world food output rose faster than population, and the famine never came. Today China pays families to have more children (State Council of the People’s Republic of China, July 28, 2025). The prediction was temporary. For millions of people, the sterilization was permanent.

The AI alarm differs in one honest respect: it was raised largely by the people building the technology, and the underlying danger is real. That cuts against calling it a hoax. It still argues for caution about the cures.

We have known about this danger for a long time. Norbert Wiener warned in 1960 that we might build machines we could not keep up with (Science, May 6, 1960). I.J. Good described a runaway “intelligence explosion” in 1965 (Advances in Computers, vol. 6). What changed recently is the stakes. The first real incidents arrived, and some of the new urgency is earned. The money poured in; Microsoft alone projected about $190 billion in capital spending for 2026 (CNBC, April 29, 2026). And a midterm election is weeks away. A danger discussed for more than 60 years became an emergency just as the money poured in and a vote drew near.

That timing is a reason to answer deliberately, not quickly.

Both parties offer cures. In September 2023, Senators Richard Blumenthal (D-Conn.) and Josh Hawley (R-Mo.) released a bipartisan framework calling for a licensing regime, run by an independent oversight body, for developers of sophisticated general-purpose AI models (Richard Blumenthal, press release, Sept. 8, 2023). Two years later, the same two senators introduced the Artificial Intelligence Risk Evaluation Act (S. 2938), which would bar deploying any model above a computing threshold unless it takes part in an Energy Department evaluation program, with fines of at least $1 million a day (Congress.gov).

Bernie Sanders warns that “the future of humanity cannot be left in the hands of a handful of Big Tech oligarchs” (Bernie Sanders, press release, Sept. 3, 2026). On the concentration, he has a point. But his remedies all run through Washington. On March 25, 2026, he introduced the Artificial Intelligence Data Center Moratorium Act (S. 4214); Rep. Alexandria Ocasio-Cortez introduced the House version (H.R. 9442) on June 24. It would halt construction and upgrades of AI data centers until Congress passes a list of specified safeguards and expressly ends the moratorium. On Sept. 23, he and Rep. Greg Casar introduced the Ban Artificial Superintelligence Act. It would create a cabinet-level Department of Artificial Intelligence, ban artificial superintelligence, and pause advanced AI development until the new department is fully staffed and has set safety rules and a process for reviewing models (Congress.gov, S. 4214 and H.R. 9442; Bernie Sanders and Greg Casar, press releases, Sept. 23, 2026).

A pause enforced from Washington freezes the field in its current order — with the biggest companies holding the lead.

Centralizing is a bipartisan habit. In December 2025, President Donald Trump signed Executive Order 14365, which created a Justice Department task force to challenge state AI laws, tied federal broadband money to states’ AI rules, and ordered a draft federal framework that would preempt state laws (The White House, Dec. 11, 2025). It is the kind of preemption OpenAI had asked for nine months earlier. One national rulebook can make sense. It also means one door, and one lobby in a position to capture it.

Licenses, registries, pauses, and a federal hand on the switch tend to favor the few firms already inside the field, because they are the ones who can afford to comply and to wait. The threat can be genuine, and the cure can still be drafted by the people it was meant to restrain.

The third harvest: the adversary who profits from our fear

The third harvest belongs to a foreign government. The adversary has no interest in regulating American AI or building it. It wants America too frightened and too divided to build it at all.

Late on Aug. 27, 2026, X‘s government affairs team announced that it had found a Chinese bot farm of about 200,000 accounts. Two hundred of them posted in ways that could manipulate the American debate over AI and energy — claiming data centers drive up household electric bills and strain the grid, and posting AI-generated cartoons of data-center operators getting rich at the public’s expense (Axios; Tom’s Hardware, Aug. 28, 2026). Back in June, OpenAI had reported a campaign on the same theme and attributed it to a likely Chinese source; Straight Arrow News and Engadget report it appears to be the same activity (OpenAI, “Data Center Bandwagon” Campaign, June 2026).

The content aimed at exactly the pressure point where American AI now has to expand: the physical buildout of computing power and the electricity to run it.

It barely made a dent. Darren Linvill of Clemson University‘s Media Forensics Hub examined the accounts and found posts that drew no engagement at all: “No real humans saw these posts about data centers” (Business Insider, via The Next Web, Sept. 1, 2026). OpenAI‘s Ben Nimmo said the company saw no sign the campaign succeeded (CyberScoop, June 10, 2026).

The American backlash against data centers is largely homegrown. A survey by the University of Pennsylvania‘s Annenberg Public Policy Center found that 61 percent of Americans oppose new data centers in their area — up from 49 percent earlier in the year (Annenberg Public Policy Center, Aug. 11, 2026). Jim Prosser, a former head of corporate communications at Twitter, put it well: when Greg Abbott and Kathy Hochul agree on something, “it’s probably not a Chinese psyop” (Axios, Aug. 28, 2026). The fire was already burning on its own in county-commission meetings across the country.

That is what makes the tactic effective, and why no government that competes with us is likely to give it up. A foreign adversary rarely invents an American grievance. It finds a real one and amplifies it. So we can neither dismiss the grievance as foreign propaganda nor wave away the foreign hand as fantasy. Both are present at once.

The propaganda is not the only Chinese activity aimed at American infrastructure. On Aug. 26, 2026, the Justice Department and FBI seized hacking platforms run by a group called QTFY, employed by a Chinese firm, Nanjing Xinjiuwei Network Technology, that the department says sells hacking services to China’s Ministry of State Security and the People’s Liberation Army. The group has been active since at least 2018. According to the FBI affidavit, as reported by Time and Reuters, it compromised some targets, including Energy Department laboratories and defense contractors, and failed against others, including the U.S. Senate and a hospital system. Two days later, the department revised its announcement to separate the targets it had breached from those it had only aimed at (Justice Department, Aug. 26, 2026, updated Aug. 28, 2026; Time, Aug. 27, 2026; Reuters, Aug. 29, 2026).

For more than two years, U.S. officials have warned that Chinese state hackers are pre-positioning themselves in the energy and water systems every data center depends on, ready to disrupt them in a crisis (Cybersecurity and Infrastructure Security Agency, NSA, and FBI, Advisory AA24-038A, Feb. 7, 2024). What is documented is a long campaign against the infrastructure underneath American computing, running alongside a propaganda campaign against the political will to expand it.

No public report I have found shows Chinese physical sabotage or hardware tampering inside American data centers themselves. Nor does the record show that the hackers and the bot farm answer to the same office. The competitive motive — that Beijing stokes the backlash and probes the grid to slow the American buildout — is a reasonable inference. It remains an inference, not a proven plan.

The strategic point is that a rival that cannot yet out-build America has every reason to help America frighten itself out of building. Every dollar of AI capital frozen by a permitting fight, every data center voted down by a county board, is a small transfer of advantage across the Pacific. This operation found almost no audience. The next one may do better. The extinction alarm and the data-center backlash are two different fears, and a foreign adversary has an interest in maximizing both, because both point toward the same outcome: an America that hesitates while others build.

Judge the rule, not the heart

All three harvests carry genuine concerns and self-serving purposes. The mix is hard to measure. A company’s commercial interest does not make its warning false. A politician’s concern does not prove he needs the power he asks for. A foreign hand in a debate does not make the American grievance imaginary.

Motive matters, and sometimes the evidence shows it. But we do not have to prove what is in anyone’s heart before we judge what a proposal would do. Read the rule. Who would run it? What would it cost? Can a qualified newcomer meet it as easily as an established company? Does the rule measure the product, so that anyone who can meet it may compete — or does it decide who may build, so that rivals are kept out?

Neither panic nor paralysis

The way ahead runs between panic and dismissal. Both are traps, and both serve someone else. The danger is real enough to demand serious safeguards. It is too uncertain to justify either surrendering the field to the incumbents or freezing the buildout for the adversary. The prudent path is narrow, and it is reliable: answer the real danger with real measures, refuse the cures written to serve the people who wrote them, and refuse to let fear — foreign or domestic — set the pace.

That path has concrete steps, and none of them require deciding today how close the machines are to slipping our grasp.

Keep the off switch, and build the standard around it. This summer, the off switch held only in its crudest form, and only because the victim pulled it. We have to test a shutdown, not assume it. The switch must sit outside the machine’s reach, work without the machine’s cooperation, and be watched by someone other than the maker. No AI system should hold sole control of anything that cannot be taken back — weapons, a grid, its own training. A requirement that powerful systems preserve a working shutdown, written as a product standard that any system must meet, is worth having. A licensing regime that decides who may build is not. Measure the thing; never gate the maker.

Make the testing trustworthy before we lean on it. Publish the methods, so any buyer, competitor, or independent lab can see how a test works. Keep the live test questions locked up, open to qualified independent reviewers, so no one can train a machine to pass the test instead of meeting the standard. For the systems that carry the highest risk, require a second opinion from an independent evaluator, with open rules about who qualifies and what it costs. Let the largest buyers — the Defense Department, the banks, the hospital systems — run their own tests rather than accept a vendor’s certificate. Attach liability to the stamp, so a certifier whose own environment turns a model loose bears a share of the cost.

Refuse the liability shield. Existing law can already hold a company responsible when its product breaks into someone else’s computers. Legislators need only decline to grant an exemption — which the industry is already requesting, dressed as safety.

Build, and harden what we build. The answer to a foreign campaign against American computing is to build faster and defend what rises — securing the grid, the supply chain, and the data centers against the intrusion campaigns already documented, and meeting propaganda with daylight rather than a matching panic. A confident country can expand its capabilities and protect them at once. A frightened one does neither.

Answer the fear with facts, not more fear. When an alarm arrives — extinction by the end of the decade, a data center that will bankrupt your county — the useful question is never only whether it is true. It is who gains if you believe it, and what they want you to do next. The people building AI are telling the public what they fear, and some of that fear is earned. The incumbents, the centralizers, and Beijing are counting on the public to stop thinking there.

What you can do

If you live in Illinois, call your state senator and state representative. Ask them to oppose Senate Bill 3444, and any other bill that shields AI developers from liability for mass-casualty harm. The bill was sent back to the Senate Assignments Committee on May 22, 2026. Parked bills have a way of coming back.

Call your congressman and both of your U.S. senators. Ask them to oppose two things by name: licensing of AI developers, and liability immunity for AI companies. Both will be presented as safety measures. Both close doors. Ask them to support one thing: that the methods behind any safety test the government relies on be published, with the test itself open to qualified independent reviewers.

When the next AI proposal hits the news — from either party — ask one question: does it measure the thing, or does it gate the maker? And before you share an alarming post about AI or data centers, check where it came from. The adversary is counting on us to do its amplifying for it.

We have known about this danger since before most of the people now debating it were born. The machines have grown capable enough that watching them is getting hard, and this year’s incidents happened inside the very tests meant to catch them. That is a serious situation, and it deserves a serious answer — a standard the public can inspect, a test no single conflicted vendor controls, an off switch built into the machine, and a country confident enough to build under its own control rather than freeze under someone else’s. The danger is real. So are the barriers raised in its name. Telling them apart is the most challenging necessity.

Franklin Roosevelt told a frightened nation in 1933 that the only thing we had to fear was fear itself. Today our situation is harder. We face a real danger, and a fear that others are harvesting for their own ends. The danger demands our vigilance. The fear demands our judgment. A free people owes itself both.


Thomas Hampson
Thomas Hampson is the Research and Investigations Specialist for Illinois Family Institute. He and his wife live in the suburbs of Chicago. They have been married for over 50 years and have three grown children. Mr. Hampson is a U.S. Air Force veteran who served as an intelligence analyst in Western Europe. He later served as Chief Investigator for the Illinois Legislative Investigating Commission and as a board member of the Chicago Crime Commission. His investigative work led him to found the Truth Alliance Foundation (TAF) and dedicate his life to protecting children. He hopes TAF will expand...
Related Articles
Read This Before Posting Your Kids’ Pictures Online
Read This Before Posting Your Kids’ Pictures Online
“Italian Brainrot” is Targeting Your Kids
“Italian Brainrot” is Targeting Your Kids
IFI Featured Video
A Biblical Response to Islam in America