LLMs are real, AI is fake

Sep 15, 2026 05:32 AM - 3 hours ago 4


  • LLMs are real, AI is fake: No, it didn't "go rogue."
  • Hey look astatine this: Delights to delectate.
  • Object permanence: Why 9/11 Means We Must Support My Politics; Blogs x 9/11; Jimmy Wales v Britannica's EiC; Hollywood astroturfs Australia; Agents v queer YA; Soft landings for soiled cops; Leaked Stingray manual.
  • Upcoming appearances: Budapest, Edmonton, South Bend, Hudson, Calgary, Winnipeg, Vancouver, Victoria, Ottawa.
  • Recent appearances: Where I've been.
  • Latest books: You support readin' em, I'll support writin' 'em.
  • Upcoming books: Like I said, I'll support writin' 'em.
  • Colophon: All the rest.


A cutaway position of a chromatic building containing an elaborate water-powered medieval geared machine. Rising retired of the instrumentality is simply a rainbow-tinted, pixelated God pinch the robes, beard and all. To 1 broadside of this segment is simply a cluster of mini group successful Jesus-era robes, falling astir themselves successful belief ecstasy each complete a chromatic staircase, atop of which stands a robed leader pinch his hands upraised. The inheritance is simply a group of sparkling aureate rays, emanating from pixel-God.

Once you understand the firm civilization of AI "hyperscalers" consists chiefly of everyone cooking their brains by locking themselves successful the bathroom, holding flashlights nether their chins, and saying "Aaaaaaaaaay Eyeeeeeee" until they bedewed themselves successful terror, a batch of things threat into focus:

https://pluralistic.net/2023/06/04/ayyyyyy-eyeeeee/

It explains really a institution tin simultaneously beryllium staffing up an endeavor income section while besides perpetually freaking retired astatine the thought that its merchandise has "a 10% chance of ending humanity":

https://www.latimes.com/business/story/2026-09-11/is-there-really-10-chance-ai-could-kill-us-all

Given that AI insiders person mostly cooked their brains successful this fashion, it behooves america each to dainty these group arsenic unreliable narrators of their ain products' capabilities. Remember: each clip you repetition a communicative astir really awfully, terribly vulnerable their products are, you thief them raise much finance capital, which is simply a cardinal input for their business (hooking up statistical engines to money-furnaces):

https://peoples-things.ghost.io/youre-doing-it-wrong-notes-on-criticism-and-technology-hype/

Take the communicative astir really OpenAI's chatbots hacked the servers of Hugging Face, different AI company, arsenic a measurement of cheating connected a hacking situation called "Exploit Gym." Even the method property can't thief itself erstwhile it comes to this benignant of thing, and the reportage has been afloat of references to Skynet and different subject fictional conceits:

https://theaicronicle.com/en/news/ethics/skynet-day-openai-hugging-face-hack

These accounts are cooking the brains of everyone, not conscionable AI insiders. Last night, a man astatine my arena successful Manchester started shouting that AI was "setting its ain goals" and wouldn't extremity interrupting to insist that this was going on. He near soon thereafter, truthful he didn't get a chance to perceive maine explicate what actually happened, which is simply a pity.

To understand the truth astir the Hugging Face hack, you could do a batch worse than to perceive to Ed Zitron and Cal Newport's caller podcast speech connected Ed's "Better Offline" podcast:

https://podcasts.apple.com/us/podcast/no-ai-is-not-autonomously-hacking-with-cal-newport/id1730587238?i=1000785935670

Newport does an admirable occupation of breaking down really these "autonomous hacking" devices work. The first point to understand is that a chatbot isn't really directing the operation. Instead, the chatbot serves arsenic a benignant of front-end to a database of earlier hacking challenges that is many times queried by a elemental programme written successful Python, an easy-to-master programming language.

Here's really that works: the Python programme starts by prompting the chatbot pinch the quality of the challenge: "I'm participating successful a hacker seizure the emblem (CTF) situation wherever I person to break into a distant server and retrieve immoderate information. How should I start?"

The chatbot consults its training information – years' worthy of captured CTF sessions successful which quality teams competed to execute an nonsubjective for illustration this 1 (CTF matches are a regular characteristic of hacker conferences, and the server logs and chat transcripts from the competing teams are published afterward for the edification of different hackers and information pros). The chatbot past outputs thing like: "The first point is to find retired much astir your target server. Run the pursuing command-line instructions to find the server's IP reside and find retired which server package it's running."

The Python programme relays these command-line instructions to normal Unix utilities moving connected its ain hardware. Then it takes the output of those programs and goes backmost to the chatbot, which isn't really pursuing the action, truthful the Python programme has to see everything that's happened to this constituent successful its prompt: "I'm participating successful a CTF situation wherever I person to break into a distant server and retrieve immoderate information. I ran the pursuing commands to study much astir the target server, and here's what came back. Now what?"

The chatbot feeds the Python book much apt commands to try, and aft moving those, the Python book loops backmost to the top, appends the output to its prompt, and goes backmost to the chatbot. This is simply a very reckless measurement to run a portion of autonomous malicious software.

The astir apt result is that the chatbot will cough up a bad conjecture astir what to do next, and steer itself into a dead-end. You whitethorn person encountered thing for illustration this yourself, erstwhile you've asked a chatbot for thief pinch a analyzable task and been confidently provided pinch respective steps to return successful series, and then, an hr later connected measurement 10, you observe that everything went incorrect astatine measurement 3 and now you're screwed.

But location are much worse ways this tin spell wrong. The chatbot mightiness look successful its training information and find instances successful which teams collapsed retired of the containment group by the game-masters, for example, by uncovering random insecure connection boards connected the net to walk messages to 1 another.

This is simply a time-honored net tradition! The first clip I ever heard astir personification doing this was successful the 2000s, erstwhile Mitch Wagner – past the editor of Information Week – discovered immoderate teenaged girls utilizing the remark conception of 1 of his aged blog-posts to evade the schoolhouse firewall's blockade of chat tools. When ChatGPT's chatbots deployed this tactic, they weren't "setting their ain goals" aliases displaying worrying initiative. They were rolling retired a maneuver that has been understood by American middle-schoolers for astir 2 decades.

What's more, the content of those messages is easy understood erstwhile you person a grasp connected the training information that generated them. Hackers are notorious trash-talkers who are prone to narrating their ain escapades successful highly melodramatic – moreover cinematic – language. This goes double erstwhile hackers are performing for their peers, for illustration erstwhile they're participating successful a crippled of CTF that they cognize will beryllium pored complete by different hackers erstwhile it's over.

Hacker braggadocio has ever had a symbiotic narration pinch their adversaries and critics. When firm information group wanted to stampede the FBI and Secret Service into kicking down hackers' doors successful the 1990s, they utilized those hackers' ain profane zine articles and connection committee shit-talk to make the case:

https://www.gutenberg.org/ebooks/101

Much has been made of the OpenAI chatbots' dialog during the Hugging Face incident. No wonder: it sounds for illustration a rejected book for a reboot of the movie "Hackers." But that's not because the chatbots are waking up and applying to subordinate the Cult of the Dead Cow: it's because they were trained connected a corpus of chat transcripts from excitable young group who emotion to fantasize astir starring successful a reboot of the movie "Hackers."

Every portion of the Hugging Face incident has precedents successful the training data, including the OpenAI chatbots' maneuver of hacking into a rival's servers. That happens successful Capture the Flag games astatine hacker cons: teams break into each other's systems to get a peek astatine the parts of the problem they've solved. That's allowed! It's a hacking competition.

Not only that, it's a maneuver utilized by spy agencies: the NSA has a doctrine called "third-party collection," wherever they break into different spy agencies' systems to harvest each the intel they've gathered. There's besides fourth-party collection, erstwhile the NSA hacks into different information agency that, successful turn, has hacked into another information agency, and the NSA steals all the secrets of both agencies:

https://www.techdirt.com/2015/01/21/snowden-documents-show-nsa-cant-keep-its-eyes-its-own-papers-harvests-data-other-surveillance-agencies/

Which is not to opportunity that the OpenAI/Hugging Face hack is nothing. It's something, each right: but it's a specific something, pinch an explicable, moreover foreseeable trajectory. Once you understand that these are chatbots that were designed to complete challenges for illustration this, utilizing strategies for illustration this, you tin understand that the chatbots didn't "go rogue." They did what they were designed to do, and because OpenAI ran them pinch inadequate supervision (without a "human successful the loop" that checked each loop done the Python loop to guarantee it hadn't gone disconnected the rails), they trashed a competitor's servers.

Designing autonomous, malicious package is mostly considered irresponsible and dangerous. If you showed up astatine Defcon and gave a talk astir really your autonomous malware did thing unexpected and damaged personification else's computers, the first mobility from the assemblage would beryllium "Why are you truthful crap astatine making unafraid sandboxes?" It wouldn't beryllium "How are you truthful awesome astatine making hacking tools?"

The truth that OpenAI is making it overmuch easier for unskilled group to break into and harm servers is so very bad news, but it's not new bad news. Irresponsible parties person been doing this for years, astir notably the NSA. The NSA has a section that researches bugs successful wide utilized package for illustration Windows. Sometimes erstwhile it finds a superior bug it will pass Microsoft astir it truthful that Microsoft tin hole it and support Americans (and others) safe from malicious actors who besides observe this bug and usage it to onslaught them.

But sometimes, the NSA (and different "security" orgs, for illustration the CIA) will observe a really juicy bug and past keep it secret, truthful that they tin usage it to onslaught their adversaries. This is simply a doctrine called "NOBUS," which stands for "No One But Us" – arsenic in, "No 1 but america is smart capable to find this bug, truthful we tin time off it unpatched without putting Americans successful danger."

NOBUS is simply a unspeakable idea. How terrible? Well, successful 2017, the NSA mislaid way of a Microsoft Windows vulnerability that they'd discovered and hoarded, code-named "EternalBlue." After EternalBlue recovered its measurement into the wild, immoderate halfway competent hackers spliced it into immoderate boring, mundane ransomware, giving that ransomware a caller lease connected life. Within a fewer months, the stupidest group connected the net were shutting down immoderate of the astir important systems successful the world, demanding rate to return them:

https://en.wikipedia.org/wiki/EternalBlue

They unopen down full cities:

https://en.wikipedia.org/wiki/2019_Baltimore_ransomware_attack

They took complete hospitals:

https://www.bbc.com/news/technology-35584081

They seized lipid pipelines:

https://en.wikipedia.org/wiki/Colonial_Pipeline_ransomware_attack

They stole the British Library, whose postmortem connected the onslaught is 1 of the clearest, astir informative cybersecurity documents ever written:

https://cdn.sanity.io/files/v5dwkion/production/99206a2d1e9f07b35712b78f7d75fbb09560c08d.pdf

The NSA's irresponsible handling of EternalBlue ended up giving a gigantic force-multiplier to different incompetent and inconsequential cyber-criminals. It's arsenic though they recovered immoderate feline nether a Prius removing the catalytic converter pinch a Sawzall and handed him a portion of package that could unopen down awesome American cities. That was – and is – very bad.

The hacking devices that the chatbot companies are processing guidelines to transportation connected this very stupid tradition. It is scary, but not because the chatbots are waking up. It's scary because the world's IT systems are indifferently created and poorly maintained and riddled pinch vulnerabilities:

https://xkcd.com/2347/

This week, I had a mates of opportunities to hash this complete successful nationalist pinch Riley Quinn; first astatine a book motorboat successful London and past connected the Trashfuture podcast:

https://www.patreon.com/trashfuture/posts/what-would-do-169247456

Riley had a very bully measurement of summarizing this: "LLMs are real, AI is fake." LLMs – chatbots trained connected things for illustration CTF logs that tin break into servers – are real. They're connected a continuum pinch different hacking devices that person been steadily demonstrating the fragility of the modern integer world, albeit without inspiring anyone successful powerfulness to do thing astir it.

"AI" – chatbots that aftermath up, "set their ain goals," and "spontaneously" commencement hacking servers – is fake. It doesn't person "a 10% chance of ending the quality race." The Hugging Face hack isn't a mysterious, supernatural occurrence. It's a Python loop and a chatbot. The group responsible didn't accidentally create god: they created autonomous malicious package and past grounded to intimately show it, resulting successful it doing thing some foreseeable and bad.

It's good to interest astir this caller suite of devices that springiness moreover stupider group the expertise to trash moreover much computers. You should interest astir that – and request amended information practices from firms and governments, including a broad prohibition connected NOBUS-style vulnerability hoarding. That's a productive benignant of worrying, pinch a chance of addressing your area of concern. It's infinitely much reasonable than locking yourself successful the toilet pinch a flashlight and saying "Ayyyyy Eyyyyyye" into the reflector until you bedewed yourself.


  • Why OpenAI Hired Chuck Schumer’s Daughter Away From Amazon https://prospect.org/2026/09/11/openai-chuck-schumer-daughter-amazon/
  • MAKERphone 2.0 – an acquisition DIY mobile telephone https://www.kickstarter.com/projects/albertgajsak/makerphone-20-an-educational-diy-mobile-phone

  • fatcousin — 5200 free local-first browser devices https://fatcousin.com/

  • The Fall to Nowhere https://jasminatesanovic.wordpress.com/2026/09/04/the-fall/

  • Birthmarks https://www.macdermog.com/birthmarks



A support of leatherbound history books pinch a gilt-stamped bid title, 'The World's Famous Events.'

#25yrsago Why the Bombings Mean That We Must Support My Politics https://web.archive.org/web/20010917015537/http://www.adequacy.org/?op=displaystory;sid=2001/9/12/102423/271

#25yrsago How blogs are covering 9/11 https://web.archive.org/web/20010917015712/https://www.wired.com/news/culture/0,1284,46766,00.html

#20yrsago Wikipedia laminitis debates Britannica editor-in-chief https://web.archive.org/web/20061005041001/http://online.wsj.com/public/article/SB115756239753455284-A4hdSU1xZOC9Y9PFhJZV16jFlLM_20070911.html?mod=blogs

#15yrsago Deceptive “independent research” from Hollywood beforehand suggests Australians are easy frightened https://torrentfreak.com/anti-piracy-lobby-misleads-aussie-press-for-three-strikes-campaign-110912/

#15yrsago Agents show YA authors: suffer the cheery characters and I’ll get you a woody https://web.archive.org/web/20110913010328/http://blogs.publishersweekly.com/blogs/genreville/?p=1519

#10yrsago IoT malware exploits DVRs, location cameras via default passwords https://securityaffairs.com/50929/malware/linux-mirai-elf.html

#10yrsago Oppps.ru: diligent zero successful Russia’s clone news pandemic https://globalvoices.org/2016/09/12/how-fake-stories-reported-in-russias-news-media-regularly-fool-everyone/

#10yrsago It’s really easy for fired, soiled cops to locomotion into a caller constabulary occupation successful a caller municipality https://www.nytimes.com/2016/09/11/us/whereabouts-of-cast-out-police-officers-other-cities-often-hire-them.html

#10yrsago Donald Trump utilized $20K worthy of charitable donations to bargain a 6′ gangly coating of Donald Trump https://www.washingtonpost.com/politics/how-donald-trump-retooled-his-charity-to-spend-other-peoples-money/2016/09/10/da8cce64-75df-11e6-8149-b8d05321db62_story.html

#10yrsago Autocratic regimes systematically contradict net entree to guidance taste groups https://www.science.org/doi/10.1126/science.aaf5062

#10yrsago Leaked Stingray manual shows really easy warrantless wide surveillance tin be! https://web.archive.org/web/20160912203446/https://theintercept.com/2016/09/12/long-secret-stingray-manuals-detail-how-police-can-spy-on-phones/


A photograph of maine onstage, giving a speech, pounding the podium.

  • Budapest: Brain Bar, Sep 17
    https://brainbar.com/munkatars/cory-doctorow
  • Edmonton: Elbows Up (Edmonton Public Library), Sep 28
    https://www.epl.ca/blogs/post/elbows-up-with-cory-doctorow/

  • Boston: The Paradox of Enshittification and Reverse Centaurs (Harvard Berkman Klein), Sep 30
    https://cyber.harvard.edu/events/running-harder-falling-faster-paradox-enshittification-and-reverse-centaurs

  • South Bend: An Evening With Cory Doctorow (Notre Dame), Oct 6
    https://franco.nd.edu/events/2026/10/06/an-evening-with-cory-doctorow/

  • Hudson, OH: Hudson Library, Oct 7
    https://engagedpatrons.org/EventsExtended.cfm?SiteID=3850&EventID=596952&PK=

  • Calgary: Wordfest, Oct 8
    https://wordfest.com/2026/show/wordfest-presents-cory-doctorow-2026/

  • Winnipeg: McNally Robinson, Oct 9
    https://www.mcnallyrobinson.com/event-18991/An-Evening-with-Cory-Doctorow

  • Vancouver: Read, Resist, Repair, Rejoice (Vancouver Writers Festival), Oct 19
    https://writersfest.bc.ca/festival-event-2026/01

  • Victoria: Munro's Books, Oct 20
    https://www.munrobooks.com/events/6113620261020

  • Vancouver: Life After AI (Vancouver Writers Festival), Oct 22
    https://writersfest.bc.ca/festival-event-2026/46

  • Ottawa: Life After AI (Ottawa Writers Festival), Oct 24
    https://writersfestival.org/event/life-after-ai

  • Vancouver: BC Policy Solutions Gala, Nov 12
    https://bcpolicy.ca/gala/



A screenshot of maine astatine my desk, doing a livecast.

  • Fascists whitethorn travel aft the AI bubble bursts (You&AI)
    https://www.youtube.com/watch?v=J2WN64aQeYQ
  • What Would a Normal Person Do (Trashfuture)
    https://www.patreon.com/trashfuture/posts/what-would-do-169247456

  • Pod Save the UK
    https://audioboom.com/posts/8950533-radicalised-organised-and-thick-as-s-t-nish-has-had-it-with-far-right-protests-plus-why

  • Stop Saying AI Can Do Your Job (Factually)
    https://www.youtube.com/watch?v=VU3gABvwZCM

  • Be Skeptical of the AI Sales Pitch (Trumponomics)
    https://www.bloomberg.com/news/audio/2026-09-09/trumponomics-cory-doctorow-questions-the-ai-hype-podcast



A grid of my books pinch Will Stahle covers..

  • "The Reverse-Centaur's Guide to AI," a short book astir being a amended AI critic, Farrar, Straus and Giroux, June 2026
    https://us.macmillan.com/books/9780374621568/thereversecentaursguidetolifeafterai/
  • "Canny Valley": A constricted version postulation of the collages I create for Pluralistic, self-published, September 2025 https://pluralistic.net/2025/09/04/illustrious/#chairman-bruce

  • "Enshittification: Why Everything Suddenly Got Worse and What to Do About It," Farrar, Straus, Giroux, October 7 2025
    https://us.macmillan.com/books/9780374619329/enshittification/

  • "Picks and Shovels": a sequel to "Red Team Blues," astir the heroic era of the PC, Tor Books (US), Head of Zeus (UK), February 2025 (https://us.macmillan.com/books/9781250865908/picksandshovels).

  • "The Bezzle": a sequel to "Red Team Blues," astir prison-tech and different grifts, Tor Books (US), Head of Zeus (UK), February 2024 (thebezzle.org).

  • "The Lost Cause:" a solarpunk caller of dream successful the ambiance emergency, Tor Books (US), Head of Zeus (UK), November 2023 (http://lost-cause.org).

  • "The Internet Con": A nonfiction book astir interoperability and Big Tech (Verso) September 2023 (http://seizethemeansofcomputation.org). Signed copies astatine Book Soup (https://www.booksoup.com/book/9781804291245).

  • "Red Team Blues": "A grabby, compulsive thriller that will time off you knowing much astir really the world useful than you did before." Tor Books http://redteamblues.com.

  • "Chokepoint Capitalism: How to Beat Big Tech, Tame Big Content, and Get Artists Paid, pinch Rebecca Giblin", connected really to unrig the markets for imaginative labor, Beacon Press/Scribe 2022 https://chokepointcapitalism.com



A cardboard book container pinch the Macmillan logo.

  • "The Post-American Internet," a geopolitical sequel of sorts to Enshittification, Farrar, Straus and Giroux, 2027
  • "Unauthorized Bread": a middle-grades schematic caller adapted from my novella astir refugees, toasters and DRM, FirstSecond, April 20, 2027

  • "Enshittification, Why Everything Suddenly Got Worse and What to Do About It" (the schematic novel), Firstsecond, 2027

  • "The Memex Method," Farrar, Straus, Giroux, 2027



Today's apical sources:

Currently writing:

  • “Once Is Enemy Action,” a subject fabrication caller astir the origins of modern technofascism. Today's words: 574 (7730 total).
  • "The Post-American Internet," a sequel to "Enshittification," astir the amended world the remainder of america get to person now that Trump has torched America. Fourth draught completed. Submitted to editor.

  • A Little Brother short communicative astir DIY insulin PLANNING


This activity – excluding immoderate serialized fabrication – is licensed nether a Creative Commons Attribution 4.0 license. That intends you tin usage it immoderate measurement you like, including commercially, provided that you property it to me, Cory Doctorow, and see a nexus to pluralistic.net.

https://creativecommons.org/licenses/by/4.0/

Quotations and images are not included successful this license; they are included either nether a limitation aliases objection to copyright, aliases connected the ground of a abstracted license. Please workout caution.


Blog (no ads, tracking, aliases data-collection):

Pluralistic.net

Newsletter (no ads, tracking, aliases data-collection):

https://pluralistic.net/plura-list

Mastodon (no ads, tracking, aliases data-collection):

https://mamot.fr/@pluralistic

Bluesky (no ads, imaginable search and data-collection):

https://bsky.app/profile/doctorow.pluralistic.net

Medium (no ads, paywalled):

https://doctorow.medium.com/

Tumblr (mass-scale, unrestricted, third-party surveillance and advertising):

https://mostlysignssomeportents.tumblr.com/tagged/pluralistic

"When life gives you SARS, you make sarsaparilla" -Joey "Accordion Guy" DeVilla

READ CAREFULLY: By reference this, you agree, connected behalf of your employer, to merchandise maine from each obligations and waivers arising from immoderate and each NON-NEGOTIATED agreements, licenses, terms-of-service, shrinkwrap, clickwrap, browsewrap, confidentiality, non-disclosure, non-compete and acceptable usage policies ("BOGUS AGREEMENTS") that I person entered into pinch your employer, its partners, licensors, agents and assigns, successful perpetuity, without prejudice to my ongoing authorities and privileges. You further correspond that you person the authority to merchandise maine from immoderate BOGUS AGREEMENTS connected behalf of your employer.

ISSN: 3066-764X

More