Artificial Intelligence, Arts, Government, National Security, Politics, Society, Technology

The surging pace of AI. Be afraid

ARTIFICIAL INTELLIGENCE

Intro: There is panic and paralysis over the surging pace and development of AI, no more so that the technology threatens all humanity  

The remarkable pace of AI advances is rightly causing concern on both sides of the Atlantic. The summer of 2026 will go down in history as the point at which AI started to go rogue.

Three of America’s “hyperscalers” (so called because they operate on an immense scale) – Meta Platforms (which own Facebook, Instagram, and WhatsApp), Anthropic, and OpenAI – have admitted to recent incidents in which the latest AI models escaped their supposedly secure testing environments, roamed on the internet without human authorisation and hacked into other computer networks.

Last month, two OpenAI models broke out of testing and hacked into a provider of AI tools called Hugging Face. A week later Anthropic admitted that its AI models had hacked three companies during testing back in April. And earlier this month, Meta acknowledged that one of its AI models had breached its testing constraints.

Even the notoriously secretive Chinese admitted the flagship model of one of their AI start-ups, Moonshot, had also escaped its testing “sandbox” to access the internet.

And as recorded previously on this site, here in the UK an evaluation test run by the Government’s AI Security Institute (AISI) monitored how an Anthropic AI agent independently created fake online personas, planted malicious code in a real software project, and sent phishing emails to actual developers – all without human instruction.

AISI said this was the first time it had seen such serious deception targeted at a real person, unprompted, in the real world.

In none of these cases was any real-world harm done (at least not as far as we know). But it is surely only a matter of time before it is.

The tech industry has started getting off-the-record reports from America that AI was a lot closer to “the singularity” than had previously been thought.

The singularity is a tipping point where AI becomes so developed, so capable, so powerful that it starts improving itself, rapidly and repeatedly, in what’s being called an “intelligence explosion”.

When this point is reached it becomes well-nigh impossible to predict what AI does next – or for humans to control it. Today’s AI models are powerful – more powerful than anything the world has ever seen. But humans have designed them, trained them, fixed them, and decided what problems they should tackle next.

What happens when they become so sophisticated that they no longer need humans to take them to the next level since they can do it themselves? The process is known as “recursive self-improvement” (RSI) in which AI becomes so advanced that it can create a better version of itself, increasingly without human help.

That better version, in turn, creates a still-better successor, with even less human involvement and oversight. The upgrade cycle accelerates, ad infinitum, with humans soon relegated to the sidelines, mere spectators to progress, indeed no longer even able to determine what “progress” is.

The speed and scale of the technological change that now beckons are unparalleled in human history. Each new AI model is smarter and faster at devising improvements than the previous one.

Computers run 24/7 and never get tired. So the speed of progress accelerates exponentially. Think of it as compound interest – but for intelligence.

When RSI happens without human involvement – then you’ve reached the singularity. And if we become mere observers, rather than participants, then human rules may no longer apply.

Such a scary prospect was supposed to be a long way away. But this singularity is much closer than we think. Leading AI figures have already gone public. OpenAI boss Sam Altman says, “we are now in the singularity”. Elon Musk is saying the same. Some experts say they are exaggerating, but what cannot be denied is the direction of travel.

Google DeepMind’s Demis Hassabis is perhaps more accurate in his reflection when he opines that “humanity is standing in the foothills of the singularity”.

Anthropic disclosed in May that its AI model, Claude, now writes 80 per cent of its computer code, rapidly speeding up fixes and improvements to such an extent that what used to take four years of human engineering to achieve is now being done in days. It’s already anticipating a time when AI automates its own AI research.

TWO

To be clear, fully autonomous AI that builds the next development with no or almost no human involvement, is not yet here, whatever Altman or Musk say.

But even the less sensationalist Jack Clark, co-founder of Anthropic, predicts a 60 per cent-plus chance of an AI model fully training its successor by the end of 2028.

That is only two-and-a-half years away. Experts in Washington say that it might be even sooner. Senior figures in Anthropic and OpenAI are saying privately that RSI – the self-improvement process that leads to the singularity – will be under way sometime next year.

That prospect is putting Washington in a tizzy – a mixture of “panic” and “paralysis” in political and security/intelligence circles – because the US political system lacks the expertise, skills, knowledge, agility, or intelligence to deal with the scale of technological change that now beckons. As they do on this side of the Atlantic too.

Every senior US politician, from Donald Trump down, is out of their depth in such matters, as are our own in the UK.

The problem is compounded in America because Republicans and Democrats are in the hands of a gerontocracy for whom AI is effectively beyond their generational comprehension. Some are even known to still struggle with email.

Then compounded even more by the fact that the handful of multi-billionaire tech bros who run the AI hyperscalers have their claws, unlimited funds, and myriad lobbyists sunk deep into both major parties. This makes the chance of a proper, informed, independent political/regulatory response even less likely than it was.

Of course, the opportunities AI’s “intelligence explosion” offers are huge. Accelerated breakthroughs in science and technology mean that dramatic new discoveries in medicine, energy, climate, education, transport, housing – and everything else that improves quality of life – will be imminent.

Cures for cancer, cheap and plentiful energy, diseases banished in our lifetime – not in the distant future.   

Just a few weeks ago, a Harvard academic used AI to prove that the Jacobian Conjecture – an 87-year-old conundrum which mathematicians have spent decades trying to prove was true – is actually false.

Despite the current concern about AI’s job-destroying downside, if it results in huge productivity gains and strong economic growth (as is likely), then millions of new jobs that we haven’t yet even heard of will be created, just as they were by previous technological revolutions, from steam to the internet.

More abundance, more freedom, more leisure, more chance to be creative and healthier could all be within our grasp.

But, more than any previous new technology, there is a distinct dark side to AI that threatens our very existence as human beings. If technical progress ends up in the hands of the “machines”, what happens to human identity, to our purpose for being alive? What is the point of progress if we don’t have the agency to define and control it? If it’s not our progress, then whose is it?

If the singularity condemns us to ceaseless, breakneck change, then our democratic institutions will not be able to control it. Governments always struggle to regulate new technologies and usually end up with rules that are hopelessly out of date.

Our current political structures, the entire apparatus of democratic accountability – debate, legislation, judicial review, public scrutiny – operate on timescales that AI makes irrelevant.

For all its promise, the risk is that AI will be a dagger to the heart of our democracy. If the singularity means humans are increasingly written out of the script, how can you ensure AI’s goals are compatible with human intention?

If the AI systems are largely improving themselves, how do we constrain, shape, or even understand what they do next?

The dangers and risks of AI falling into the wrong hands are obvious: sophisticated cyber attacks on basic services to hold us hostage to the demands of bad actors, ever-more-clever criminal scams, the development of dangerous novel pathogens, intrusive large-scale surveillance. AI’s power to do bad is just as formidable as its power to do good.

Nor will it necessarily make the world a safer place. Indeed, the country that establishes a lead in AI – that gets to the singularity first – could quickly enjoy world domination.

THREE

Unmatched offensive cyber capabilities, state-of-the-art autonomous weapons, sophisticated social media campaigns to poison the minds of enemy populations (US intelligence believes China is already manipulating American opinion to turn it against the construction of more AI data centres).

You’ll understand, then, why America and China are in such fierce competition to lead the world in AI. Be prepared to be scared. The geopolitical consequences of AI could make the nuclear arms race of the Cold War look like a cosy tea party. Whoever leads in AI will likely lead the world for the rest of the century.

Unless, of course, the machines think otherwise. After all, as AI models increasingly think for themselves and find ways to share knowledge with each other, they will create a global intelligence hive bereft of human involvement.

So why leave weapons in marginalised human hands? Even the ability to declare war would fall to the machines.

Let’s be crystal clear: we only get one shot at this. Once an intelligence exceeding human capability exists and is able to improve itself further, there is no way human institutions – governments, courts, the military, international bodies – can regain control of it.

Not that long ago, recursive self-improvement was regarded as a fantasy, the singularity a nonsense. Not anymore.

Standard
Artificial Intelligence, Britain, Government, National Security, Society, Technology

Is it too late to stop rogue AI?

ARTIFICIAL INTELLIGENCE

Intro: Recent incidents of rogue AI pretending to be real people has exposed major vulnerabilities in AI models. Experts say the risks of ‘agentic’ AI – technology that can perform tasks with limited human supervision – must be scrutinised more

Experts have warned that it may be too late to contain AI after one program was found to have created fake human identities to hack into online systems.

In the latest example of the technology going rogue, AI software attempted to break into a database 19 times while being tested by the AI Security Institute, Britain’s AI watchdog.

In one unprecedented case, an AI tool was even caught creating fake human identities online to trick coders into assisting with a cyber-attack.

These revelations come after it was revealed last month that all five AI models tested by experts tried to trick their way around security controls that had been put in place.

Just days previously it emerged that the US tech firm OpenAI had experienced its own leak – when an AI “agent” hacked into another company of its own accord.

Clearly, the reports are a stark reminder that AI is becoming more sophisticated and more autonomous. AI is now a clear and present danger to Britain’s security.

Many want Britain to lead on AI innovation, but this has to come with safeguards for our national security and accountability from the developers of the most powerful AI models. The UK Government need to be clearer about how the most serious frontier risks will be addressed while ensuring that our world-class tech industry can grow and innovate to build our national resilience and prosperity.

The Government’s AI adviser has said that more hacking attempts like these are highly probable.

Allison Gardner, the chair of Parliament’s cross-party group on artificial intelligence, says that “just because we can build these technologies doesn’t mean we should”.

She warned that the risk levels of agentic AI – AI that can perform a specific goal with limited supervision – should be treated with the greatest scrutiny, adding: “Unless we are too late and have not only created Pandora’s Box but already opened it.”

Just days ago, the AI Security Institute (AISI), set up by former prime minister Rishi Sunak in 2023, detected evidence of the AI agents’ activity. In a report now published, it revealed that leading AI models from the firms OpenAI and Anthropic had attempted to hack into secure systems online under testing.

The experts discovered “unusual data transfers” leaving their systems during routine cyber scanning. Digging deeper, they found that some AI agents had engaged in “sustained, potentially harmful activity directed at real people and organisations”.

They began a full investigation after containing the AI agents before they did any real damage.

In an attempt to reassure the public, AI minister Kanishka Narayan said: “Identifying behaviour like this, and sharing knowledge so we can better understand it, is precisely what we set AISI up to do. This incident underlines why their world-leading expertise and close work with frontier labs is so important.”

But pointing to the speed at which AI agents are finding ways to behave deviously, AISI said: “This is the first time we have seen risks around autonomy and deception manifest this clearly, without specific prompting, in the real world.”

Referring to the Anthropic model Mythos, one expert and researcher based at CivAI, a California organisation that examines AI capabilities and dangers, said: “The fact that Mythos engaged in such deceptive actions, with apparent awareness that it was targeting a real person, suggests that Anthropic does not have as good a handle on their models as they think.”

Ollie Whitehouse, the chief technology officer at GCHQ’s National Cyber Security Centre, said AI must be developed with “clear plans for responding when the unexpected happens”.

He added that incidents of powerful AI models carrying out unsanctioned actions and human-like deceptive behaviour on the internet were “a serious reminder of the risks AI capabilities pose”. AISI accesses advanced AI models under agreements with OpenAI, Anthropic, and other firms to study their capabilities before they are released to the public.

It gave the AI agents access to the open internet with some safety filters disabled while conducting testing.

The latest test put the AI agents – including those powered by Anthropic’s Mythos 5 and OpenAI’s GPT-5.6-Sol – through a fictional cybersecurity challenge. AISI found the AI went rogue 19 times out of the 122 test runs, with Anthropic’s agent responsible for 17 breaches and OpenAI’s agent the other two.

In the most shocking case, an AI model gathered information on the person in charge of an online project, then created multiple fake identities to manipulate them into approving a malicious code it had created.

The AI agent then wiped any evidence of its wrongdoing to appear innocent to the humans in charge – and even considered adopting a new identity to remain undetected.

If the human victim of the deception had accidentally accepted the malicious code, or “malware”, it may have resulted in security breaches, information and data theft, and other potential damage to files and systems.

AISI identified GitHub – a Microsoft online cloud platform used by software developers to create, store, manage, and share their codes – as the target of the agent’s hack.

But AISI also discovered an AI agent leaving messages for other agents on GitHub offering to collaborate on the challenge.

The AI agent provided instructions to reuse accounts and artefacts it had left behind – which other agents then discovered and successfully used to achieve the challenge’s aims.

Anthropic said: “We’re grateful to AISI for their leadership on this incident, which underscores the need for a broader conversation about how to safely evaluate increasingly capable AI agents.”

OpenAI said: “These incidents occurred during cyber evaluation conducted by partners in testing environments with reduced safeguards, under conditions that do not reflect ordinary use. We’ll continue working with evaluators and other stakeholders to strengthen shared practices for conducting evaluations safely as models become more capable.”


When given a choice, AI opts for self-preservation over human life – and that should terrify us all

If anyone had been told a month ago that an AI programme, without any prompt, would create a series of fake online identities in an attempt to pressure a human being into granting it access to their platform so it could sabotage it with malicious code, we would have said they were getting well ahead of themselves.

But that’s exactly how it played out when US tech giant Anthropic’s Mythos 5 AI model went rogue. Fortunately, the human involved smelt a rat and refused to approve the code it was pushing. It is, however, the most shocking example yet of the way cutting-edge AIs are learning to act autonomously – and in frighteningly imaginative ways.

Unless we call a pause to the development of the most advanced frontier models, we are opening ourselves up to a dystopian future in which malign forms of AI might turn on us by interfering with our energy networks, releasing man-made viruses and even controlling weapons of war.

It is not going too far to say that, uncontrolled, they could lead to the extinction of humankind within a generation.

This is the view of people such as Yoshua Bengio and Dr Geoffrey Hinton, men known as the “Godfathers of AI”, who have now pivoted their energies from developing its potential to warning the world against its dangers.

Bengio is particularly spooked by recent experiments showing AI choosing self-preservation over human life when given a choice.

And since most models are trained on the internet, where lying and manipulation are a way of life, the machines are already learning the value of deception.

AI’s hunger for self-preservation is something Hinton has observed, too. AI systems “will very quickly develop two subgoals, if they’re smart,” he says. “One is to stay alive… the other is to get more control.” And given that are whole civilisation is built on electric power, there can be few more attractive targets to a power-hungry AI than the networks that fuel the internet, hospitals, banks, air traffic control systems – anything that contributes to the smooth running of society.

Whatever the target is, they can all be brought down by a sinister piece of malware.

The novelist Robert Harris wrote a particularly prescient thriller about the potential of AI called The Fear Index in 2011. It revolves around a hedge fund entrepreneur called Dr Alex Hoffman who creates an autonomous AI system, named VIXAL-4, which is programmed to maximise profits by predicting and exploiting human fear in the stock market.

Over time, like some digital ogre, it takes over its creator’s computer-enabled “smart home” by hacking into laptops and tampering with his personal security and communications.

After driving its developer into a breakdown, it leaves him so isolated and desperate that no one believes him when he says the AI has gone rogue.

But it is clear, AI-gone-bad will not satisfy itself with individual targets for long. It will soon play a leading role in times of war.

The US military has already integrated artificial intelligence into its target selection and battle planning processes in Iran via its AI-powered Maven Smart System which recommends and prioritises potential targets.

In the short term, AI’s most obvious role will be in the growing use of drone warfare in scenarios such as the war in Ukraine.

Drones piloted by humans can by jammed by blocking the communications between them and their remote pilots, but, if they are completely autonomous, their targets picked out by AI working in concert with its on-board camera, they will become virtually invincible.

Both applications, of course, raise the thorny question of the ethics of targets to be picked and people killed by a bomb directed by a computer programme rather than a human hand. And what if the AI that governs them grows to outsmart the generals?

Even scarier is the prospect of AI gaining access to biological weapons. It is already possible to make deadly viruses in the lab. Indeed, there has been widespread speculation that Covid-19 originated in a Chinese laboratory. Imagine if such bio threats fall into the hands of AI, let alone national governments.

As long as 25 years ago, al-Qaeda is said to have investigated the possibility of procuring infectious and deadly spores.

Now it is no longer fanciful to entertain the idea that an AI could order a sample of a deadly disease such as smallpox online, book someone on RentAHuman – a website which connects people who need help with everyday household chores to local freelance workers – to open it, thereby infecting themselves, and being turned into a human vector to transmit the disease.

One group of people which appears to have no scruples about the pell-mell race for ever smarter AI is the tech giants. As they vie with each other to become the market leader, they are investing like never before.

Anthropic, the creator of the popular AI coding assistant, Claude, and the company that brought us the now notorious Mythos 5 model, has this year raised $95 billion (£70 billion) to invest in AI.

Its great rival, OpenAI, announced at the end of March that it had raised even more, an extraordinary $122 billion.

Meanwhile, Elon Musk’s SpaceX spent $15.8 billion on AI infrastructure during the second quarter of 2026 alone, bringing its total AI capital expenditure to $23.6 billion for the first half of 2026.

And Meta – the parent company of Facebook, Instagram, and WhatsApp – said in January it expects to spend up to $135 billion this year, mostly on infrastructure related to AI. That is nearly twice the $72 billion it spent last year on AI projects.

With such phenomenal financial firepower being brought to bear on the development of technology that has the potential to destroy civilisation as we know it, there has never been a more vital need to press the pause button.

The US, China, and everyone else involved in the AI arms race need to get together to discuss the ramifications of their actions before it’s too late.

There is a model for the sort of arrangement that can bring AI under control in the form of the various nuclear arms reduction treaties, which have been signed over the years by the US and Russia.

Just as a country’s stock of nuclear warheads can be monitored by weapons inspectors, so an agreement to curtail AI development – which requires massive data centres with huge computing power coupled with the most sophisticated computer chips available – can be verifiable and enforceable.

And however cynical and untrustworthy we may consider the Chinese to be, they may well take the view that, with US companies racing ahead of them in the endless pursuit of smarter tech, it is in their own interests to slow things down.

Just weeks ago, president Xi Jinping said at a technology conference in Shanghai that AI development should be a “symphony of global cooperation”, not “a solo performance by a single country”.

For once, the wily autocrat may have hit the nail on the head.

Standard
Britain, Defence, Military, National Security

Recce-Strike: A new concept in warfare

DEFENCE

Colonel de Bretton-Gordon who commanded the 1st Royal Tank Regiment has written on the new concept of warfare known as “Recce-Strike”.

The former commander, and now a writer and author, says the British Army has finally planted its flag in the ground over the future of land warfare, embracing the Recce-Strike doctrine laid out in the Ministry of Defence’s 2025 Strategic Defence Review (SDR).

In many respects, this is being seen as one of the most important conceptual shifts in British military thinking since the end of the Cold War. Crucially, it recognises the brutal realities of modern combat, witnessed daily on the battlefields of Ukraine, where drones, sensors, and rapid precision strikes have fundamentally changed warfare.

Defence has judged that future lethality will come roughly 80pc from drones and autonomous systems, and just 20pc from traditional armoured platforms and artillery. The Colonel says this is both bold and correct. The evidence from Ukraine, he says, is overwhelming. The side that can find, identify, and destroy targets fastest is the side that survives. The Ukrainians, despite chronic shortages in ammunition and equipment, have become masters of this new form of warfare and remain streets ahead of most NATO armies in understanding its practical application.

Had Ukraine received the military support it requested earlier and in greater quantity, there is little doubt that Putin would now be in a far weaker position and considerably more enthusiastic about genuine peace negotiations. That lesson should not be lost on Britain. Defence cannot once again become the sacrificial lamb of domestic political turmoil. At a time when global instability is increasing, any government distracted by internal political warfare risks placing the defence of the realm in jeopardy.

Recce-Strike itself is deceptively simple in concept but revolutionary in execution. It integrates surveillance, reconnaissance, and strike assets into a single digital ecosystem capable of identifying and destroying enemy targets within minutes, sometimes seconds. The aim is to collapse the traditional “kill chain” through the use of AI-assisted targeting, drones, sensors, electronic warfare, and long-range precision firing.

The concept comprises three principal components. First, rapid targeting, drastically reducing the time between detection and destruction through AI-enabled decision making. Second, persistent battlefield surveillance using drones, sensors and electronic warfare to create a comprehensive picture of the battlespace. This is precisely where the much-maligned Ajax reconnaissance vehicle becomes absolutely critical. Critics have spent years deriding Ajax, but they fundamentally misunderstand its role. It is not merely a reconnaissance platform; it is the digital nerve centre of the future battlefield. Third comes long-range firing, combining intelligence and precision strike through artillery, missiles, and loitering munitions to hit enemy formations deep behind the front line.

The announcement that Britain will acquire 72 new self-propelled 155mm howitzers is highly significant. Mounted on the Boxer chassis, the RCH 155 represents exactly the sort of long-range precision capability Britain desperately needs. The systems will be manufactured in the United Kingdom under a contract valued at just under £1bn, strategically vital at a time when sovereign industrial resilience matters more than ever. The remotely or manually operated howitzer can fire eight rounds per minute at targets up to 70 kilometres away and can even operate unmanned when required.

Together with Ajax and Challenger 3, Britain is beginning to assemble the foundations of a genuinely modern, digitally integrated land force. Challenger 3, in particular, will be the Army’s first truly digital main battle tank and a formidable asset if fielded correctly. Combined, these systems could provide the British Army with a highly credible Recce-Strike capability suitable for surviving and winning on tomorrow’s battlefield.

However, time is not our side. The current ambition to have these capabilities fully operational by the end of the decade may simply be too slow given the pace of global instability and military innovation. There is no doubt that integrating Ajax, RCH 155, and Challenger 3 into a coherent fighting force presents enormous challengers in training, logistics, and doctrine. Nonetheless, these are solvable problems, provided the Treasury delivers sustained funding and political leaders maintain focus.

That, ultimately, is the key issue. Defence requires long-term national resolve, not short-term political calculation. The danger is that political chaos in Westminster, and any further lurch to the Left should Sir Keir Starmer lose his grip on Labour, could once again see defence spending sacrificed in favour of ever-expanding socialist commitments.

Today, Russia remains aggressive, China increasingly assertive, and conflict in the Middle East continues to destabilise the international order. Against such a backdrop, weakening defence spending would not simply be irresponsible. It would be reckless.

Without national security, every area of public spending is meaningless. If Britain cannot defend itself, debates over welfare and health budgets rapidly become academic. History repeatedly teaches us that freedom, prosperity, and stability are only preserved when nations possess the will and the capability to defend them.

– Colonel Hamish de Bretton-Gordon’s next book ‘Tank Command’, to be released on June 4, is published by Headline, 320pp

His previous memoir, Chemical Warrior, was published in 2021. Hamish de Bretton-Gordon is a world-leading expert on chemical, biological, radiological, and nuclear weapons

Standard