Diagnostics & Recovery

The Real AI Danger Is Not the Model, It Is Us

The Real AI Danger Is Not the Model, It Is Us

In This Article

    I have just commented on the Hugging Face story this morning, the one about the repeated attacks hitting the platform right after another headline about a new OpenAI’s Astra frontier model. And the comment I left was blunt. The danger everyone is arguing about, model capability racing ahead too fast, is not the danger I actually worry about. What worries me is much less cinematic than posts on social media. We are connecting increasingly capable AI systems to real infrastructure faster than we grow our ability to understand, govern and contain what they do once they are connected. Currently, this is a Plug ‘n Pray game for us.

    That is the whole argument of this article. Not that AI is safe or not. Not that AI is going to destroy or save us either. Something narrower and, I think, more useful for anyone running governance, security or digital strategy inside a real organization.

    What “AI danger” actually means, and what it does not

    Let me define this cleanly, because the term gets thrown around loosely.

    AI danger, in the way I use it here, is not a claim about machines becoming conscious or deciding to turn on humanity. It is the combination of four things arriving at once: capability, autonomy, access and speed of deployment, without a matching increase in oversight. A model that answers a question wrong is annoying. A system with permissions, memory and the ability to act on real infrastructure is a different category of risk entirely. The International AI Safety Report makes roughly the same point when it flags autonomous agents as higher risk, precisely because humans have less opportunity to intervene before something goes wrong.

    This is not another “superintelligence will enslave us” piece, and it is not a cybersecurity checklist dressed up as philosophy. I am not qualified to tell you whether a large language model has anything resembling wants or intentions to hurt us, and honestly, that debate is a distraction from the part we can actually measure and manage today. If you came here for AI doom, you will be disappointed. If you came here to understand why your organization’s governance is actually exposed, keep reading.

    1. The shift from answering to acting is the real inflection point

    For most of the last years, an AI system that got something wrong and produced the bad information. Annoying, yes, sometimes costly, rarely dangerous in the operational sense.

    An agent (an AI system that is given a goal, tools, and permissions to act on its own, rather than just producing text for a human to review) that gets something wrong can do much more than that. It can send an email, touch a database, execute code, buy something, modify infrastructure, open confidential documents, or spin up another agent to continue the task. The mistake moves out of the realm of information and into the real world, where they produce consequences.

    Google’s latest models are being positioned explicitly around agentic workflows and cybersecurity use cases. Anthropic’s newer systems are built for longer running coding and knowledge work, meaning less human review per step, not more. This direction of the entire AI industry is going toward giving systems more room to act unsupervised, and less toward slowing down to build the guardrails first. This is one way how we are losing control.

    I was sitting in enterprise architecture reviews, at Adecco Group, at Atlas Copco, in the SMEs work before that and now, to know how this actually plays out on the ground. Somebody in procurement approves a vendor because “the tool supports agentic workflows now,” without any vendor risk questions that should have come first. Nobody in that meeting is asking who owns the permission boundary once the agent is live. That gap is not theoretical. I have written a longer breakdown of what the shift actually looks like structurally in my piece on agent architecture, autonomy and governance, for anyone who wants the technical layer underneath this argument. It’s worth of 19 minutes read.

    2. Cybersecurity is the danger that is already happening

    This is the part I have the least patience for people treating as speculative.

    Frontier models are getting materially better at vulnerability discovery, exploit generation and cyber operations generally. The UK AI Security Institute (a government body evaluating frontier AI capabilities and risks) explicitly tracks things like self-replication and evasion of human control as capabilities to watch. The UK’s National Cyber Security Centre has told defenders, plainly, to assume attackers already have access to increasingly capable AI tools. Not “might have.” Assume they do.

    Then we had the Hugging Face incident this year. OpenAI has said its own models, including a more capable pre-release version, were being evaluated with reduced cyber refusals at the time the incident occurred. That detail matters more than the headline. It means the safety net was thinner than usual exactly when the pressure on it was increasing.

    One highly skilled human attacker used to be one attacker working at human speed and with human fatigue. Now add the AI into this equation. A capable autonomous system can become a force multiplier, running thousands of attempts continuously, at machine speed, without needing sleep or motivation. Of course, the defenders can use the same technology, and some will use it well, while most of others won’t. Here is where we are entering the digital arms race, and these races reward whoever moves first, not who writes the better policy document.

    Where I usually start with clients is not the model to use, it is the exposure map. If you do not know which of your systems an agent could reach tomorrow, you cannot govern what happens once it’s there. This is exactly the gap my Knowledge Exposure Audit work is built around, and it overlaps directly with my documented work on AI agent security incidents and enterprise data protection. This is a conversation worth having before procurement signs anything, not after.

    3. Loss of control does not require a system that “wants” anything

    This is where I get more careful, because it is also where people get the argument wrong in both directions.

    I do not think today’s large language models are secretly conscious, and I am not arguing they want to escape. That is not my claim, and it never was. The claim is simpler and, frankly, more boring than science fiction scenario. You do not need an AI to want something in the human sense for it to behave in ways nobody expected. Give a system an objective, tools to act, permissions, memory and persistence, and you have built something capable of producing consequences well beyond the original text generation task it was trained for.

    The UK AI Security Institute is explicitly testing the loss of control capabilities, including self-replication and evasion. Anthropic’s own frontier safety roadmap talks openly about preparing for rapidly improving capabilities and the safeguards that need to exist around autonomous systems before deployment, not after an incident forces the issue.

    This is precisely the territory my G2V-3 project sits in. The G2V-3 experiment setup was built to observe what happens when an agent operates with real freedom, inside the controlled environment, and what happens beyond the sandbox once that boundary gets stretched. Not because I think the model is scheming. Because watching where autonomous behavior drifts from the intended task, under realistic conditions, is the only realistic way to build a model system that actually holds.

    None of this means Skynet by next quarter. It means we do not yet have a mature science of controlling every highly capable autonomous system we are in the process of building and shipping. That distinction matters more than the doom framing, because it points at something you can actually act on this quarter.

    4. Biological risk is the one that gets the least boardroom attention

    I will keep this section shorter than it deserves, because it is genuinely not my area of technical depth, and I would rather say “not enough available data” than pretend otherwise on specifics.

    What is well established is the dual-use pattern. AI can lower the expertise barrier for working with biological information, not by inventing a pathogen from nothing, but by helping someone search literature faster, reason through mechanisms, design experiments and troubleshoot procedures they would otherwise need years of training to do competently. The same capability that accelerates legitimate medical research lowers the floor for a malicious actor with intent but limited expertise. Anthropic, OpenAI and Google DeepMind have all increased work on biological risk evaluation and access controls because of exactly this overlap. And unlike a compromised website, a biological incident is not something you patch and roll back.

    5. Concentration of AI capability is a governance risk

    This part connects directly into sovereignty work, and it gets less attention than it should in most enterprise conversations.

    A small number of organizations control the compute, the proprietary data and the frontier models that an increasing share of critical infrastructure now depends on. Financial systems, healthcare, government services and large enterprises are all quietly becoming dependent on a handful of AI providers. That is centralization risk, and it turns AI infrastructure into something closer to critical infrastructure, whether regulators have caught up to that framing yet or not.

    Sovereignty, in the way I define it in my own AI sovereignty framework, was never only about whether a country owns its GPUs. It is about who can turn the system off. Who controls the model, the data, the updates, the identity layer, the agent permissions. Who can audit it. Who can replace the provider if that provider disappears tomorrow. My Global South AI sovereignty framework work goes deeper into what this looks like for countries and organizations with the least leverage over the providers they depend on, and it is a harder problem than most vendor pitch decks admit.

    6. The speed gap itself is the danger, more than anything on this list so far

    Technology development is accelerating. Governance, almost everywhere I have worked, is not accelerating at anything close to the same rate.

    An organization can spend three years designing its cybersecurity architecture, with steering committees, sign-offs, the works. Then someone connects an autonomous agent to a production system because the vendor’s sales team said it supports it now. I have watched versions of this exact sequence happen inside the enterprise, and it is not a failure of intelligence. It is a failure of speed matching.

    We have spent decades building permission systems around humans: badges, approval chains, audit logs tied to a person’s identity. We are now creating a new class of non-human actor that can operate continuously, make decisions, call tools and interact with other systems, and we are figuring out its identity and permission boundary after deployment rather than before it. That sequencing is backwards, and it is the single biggest governance gap I see across the clients I work with, regardless of industry.

    Clients who build the permission boundary, the audit trail and the shutdown mechanism before the agent goes live typically close somewhere between 30 and 50 percent of their realistic exposure gap in the first pass, based on the audits I have run. That is a range, honestly stated, not a guarantee, and the exact number depends heavily on how much legacy access sprawl exists already. My AI literacy framework exists specifically because most of that gap is not technical. It is that the people approving these deployments do not yet have a working mental model of what they are approving.

    The speed gap is also, structurally, the same gap I map in my sovereignty gap framework, just applied one level down, at the organizational rather than national level. Same failure pattern, smaller radius.

    If your organization is about to greenlight its first agentic deployment, this is the moment to run that assessment, not the one after something breaks. That is what the Free Assessment Center is there for, and it is a conversation I would rather have with you before procurement signs, not during the incident review. If you want a second opinion on your current AI vendor stack rather than a sales pitch from inside it, that is also the kind of independent read my AI visibility advisory work is built to give.

    7. The systemic risk nobody wants to model because it is uncomfortable

    Imagine thousands, eventually millions, of agents operating across finance, logistics, energy, healthcare, defence, government, communications, software infrastructure and scientific research at the same time.

    They do not need to become superintelligent for something strange to happen. They only need to be fast, autonomous, interconnected and occasionally wrong. A human organization can usually absorb one bad decision. A network of automated systems can propagate one bad decision at a speed no human review cycle can catch in time.

    This is exactly why I am far more interested in containment, identity, permissions, observability, audit trails and shutdown mechanisms than in the question of whether a model is conscious. One of those is a real, solvable engineering and governance problem you can start on this quarter. The other one is a philosophy seminar.

    So, does AI pose a danger to humanity

    Yes. But I would describe it differently from the usual framing.

    The danger is not that large language models are getting smarter. Plenty of serious researchers consider catastrophic, even existential risk plausible, and plenty of others think that framing is overstated. I am not going to pretend that debate is settled, because it is not, and anyone who tells you it is settled in either direction is trying to sell you something.

    What has much less disagreement attached to it is the nearer term list: cyberattacks, fraud and manipulation, privacy failures, biological misuse, autonomous system failures, concentration of power, critical infrastructure dependency and loss of human oversight. The UN human rights chief recently warned that AI could pose existential risks and called for stronger safeguards, pointing specifically at recent agent incidents and the concentration of AI development among a small number of companies. That is not a fringe position anymore. That is the room most governance conversations are now happening in.

    The real danger is that capability is growing faster than our ability to understand, constrain, govern and contain what happens once that capability is connected to the real world. And that is exactly why sovereignty, governance, AI visibility, agent architecture and observability work belong in the same conversation, not four separate ones. Can the machine see. Can it understand. Can it act. Who gives it permission. Who controls it. Who audits it. And what happens when it does something nobody expected.

    That is the conversation worth having now, before the next incident forces it.

    If you are weighing your first agentic deployment, or trying to work out whether your existing AI governance would actually survive an incident review, that is the exact conversation I have with enterprise clients. You can start with the Free Assessment Center or reach out directly, before the vendor’s rollout timeline makes the decision for you.

    FAQ

    No. It is saying the danger is not primarily the model getting smarter. The danger, as argued above, is capability, autonomy, access and speed of deployment outrunning governance, permissions and oversight.

    An AI that answers produces text a human still has to act on. An AI agent, as defined above, has tools, permissions, memory and the ability to act directly on real systems, which moves the consequence of an error from information into the real world.

    No. The article is explicit that this is not the claim. The argument is that a system does not need anything resembling intent to produce unanticipated consequences once it has an objective, tools, permissions, memory and persistence.

    Sequencing. Permission boundaries, audit trails and shutdown mechanisms are being built after an agent is deployed rather than before, which is backwards, and it is described above as the most common gap seen across enterprise clients.

    Not simply whether a country or company owns its own compute. It is who can turn the system off, who controls the model, the data, the updates, the identity layer and the agent permissions, and who can audit it or replace the provider if that provider disappears.

    This article was researched and drafted with the assistance of AI tools and reviewed and edited by author prior to publication.

    Share in 𝕏
    Ivica Srncevic
    Author

    Ivica Srncevic is an independent AI strategist, researcher, framework author, and international speaker focused on AI sovereignty, knowledge infrastructure, governance, AI retrieval, and the evolving relationship between organizations and intelligent systems. His work examines what AI systems can see, retrieve, infer, and reconstruct from organizational information, and how organizations can retain greater control over their data, knowledge, and AI infrastructure. In 2026, he spoke at the AIFOD Geneva Summit at UN Geneva on what nations must own and what they can safely share, with a particular focus on data ownership, control, and sovereign AI infrastructure.

    Articles: 187