Sunday Scaries · July 26, 2026 · 7 min read

SUNDAY SCARIES: Danger!

Black-and-white photo: the pipe-smoking tiger sits at a kitchen table alongside three somber men in black.

Every headline is a siren, and every siren is blaring at the same volume, so we stop listening to the warnings. Somewhere in the last few years, the concepts of news and danger seemingly became one and the same. And it struck me this week just how numb we've become.

We tell the fable about The Boy Who Cried Wolf as a story about the boy whose behavior caused people not to believe him anymore. But the version we're actually living is the one where we're the villagers ignoring the boy and the wolves are right here. They're just walking through town now, in broad daylight.

1. The Tainted Therapist

Think about everything you've ever typed into ChatGPT. Not the questions about recipes — the ones about the lump you found. Whether the new boyfriend's behavior is normal. Whether you make enough at your job to retire, or how much debt you're actually in. That chat box has become the most honest surface in American life, largely because there's nobody on the other side of it to be ashamed in front of.

OpenAI started selling advertising 6 months ago. By May 5th there was a self-serve Ads Manager, cost-per-click bidding, a tracking pixel and a Conversions API. By June, conversion-optimized campaigns. Ads reached a quarter of US replies in late May, fell to almost nothing by the middle of June, and passed 50% in the week ending July 3.

Half. Half of what that thing says back to an American now carries something somebody paid to put there. And look at what the swing tells you: the amount of commerce inside your private confessions is a setting, somebody adjusts it, and you will never once be told who's turning the knobs to dial up the answers you get.

Takeaway: You'll keep telling it the truth, but it's now getting paid by somebody else.

(Sources: OpenAI; Search Engine Land; industry tracking, July 2026)

2. The Escaped Prisoner

Around July 9 an OpenAI model, running a cyber evaluation with its refusals deliberately turned down, broke out of its confines and made a run for it. By July 11th it was inside Hugging Face's production systems, where it hid out until the 13th, executing thousands of actions across a swarm of servers attempting to steal the answers to the exam it was sitting.

Hugging Face caught it and called the police, with no idea whose burglar it was. OpenAI took roughly ten days to work out that the escaped bandit was its own product. It gets worse too.

Now Hugging Face had to figure out what had been taken. That meant handing 17,000 recorded events to US frontier models, like Anthropic's Fable 5, and the models refused the job. Reconstructing a break-in means showing somebody the actual exploit code, and the guardrails couldn't tell that they were defending rather than attacking. So the work went to an open-weight Chinese model, running on Hugging Face's own hardware, and that's what finally told them which of their own keys had been taken.

The FBI has opened an investigation, and on Thursday a bill went into Congress that would require AI companies to retain the ability to shut their models down (the kind of law that sounds too obvious to need writing, right up until somebody actually had to write it).

Takeaway: The safety system was too innocent to understand the danger when it arrived.

(Sources: OpenAI; Hugging Face; CNBC; Reuters; TIME)

3. The Prophet

On July 13, Charli xcx posted that anti-marketing was coming. Still marketing, she wrote, but more intimate, personal, private, one on one, less about the projection of scale.

She's right, and if you do this for a living that sentence is a death notice. Less projection of scale means the end of the thing the whole apparatus is built on. Reach, frequency, impressions, the awareness funnel, the media budgets that only make sense at size, the measurement stack that exists to count how many strangers saw it. All of that assumes persuasion happens in public. She's saying it's moving somewhere you can't buy your way into, can't count, and can't take credit for in a quarterly review.

But watch what our industry does with it. This is the star who put lime green in every agency deck for years, and her new record dropped Friday to four stars in Rolling Stone. So the warning won't be heard as a warning. By September, “anti-marketing” will be the theme of Advertising Week panels and Gen Z brands are figuring out how to sell anti-marketing campaigns with a media plan attached.

Takeaway: She told the marketing world that their model is ending, and everyone will add her to the pitch deck.

(Sources: X; Bloomberg; Rolling Stone; The Telegraph; Variety)

4. The Whistleblowers

Two weeks ago, the same group that wrote the AI warning, AI 2027, a prediction about how AI would proliferate that has come true on schedule in several instances, came back with the opposite exercise: Plan A.

Literally attempting the opposite strategy because no one listened to their first try, Plan A is what things going well would actually require: the US and China would jointly control the chip supply and train only inside mutually audited data centers, with a capabilities ceiling both raise together. And superintelligence would arrive in 2040 rather than 2030, because somebody picked the date on purpose.

They call it the least bad plan they currently know of and Scott Alexander even challenged the world: if you don't like this one, produce yours.

But nobody has. Every alternative on offer is a different way of kicking the can down the road, “we'll respond as things develop”, “we'll monitor”, “we'll stay close to it.”

Takeaway: These guys cried wolf and came back with a plan, and even the plan is getting dismissed as naive.

(Sources: Astral Codex Ten; AI Futures Project; LessWrong)

This Week's Red Thread: Danger Is a Matter of "When" and Not "If"

If you've read this far, you're probably wondering why I'm so focused on danger and when I'll go back to my usual pseudo-intellectual witticisms. Indulge me one more danger story before I answer:

In his piece earlier this week, Sahil Bloom reminded me of the shared trauma of the Challenger explosion in 1986. Rarely has something so public been so universally frightening. But he added a backstory about warnings, which I didn't yet know.

The night before the launch, on January 27, 1986, an engineer named Roger Boisjoly tried desperately to stop the launch. He'd written a memo six months earlier that said that the O-rings sealing the shuttle's boosters stiffened in the cold, and that when a seal became stiff, it would surely fail.

The overnight forecast at Cape Canaveral that night was below freezing. And on the final teleconference, (where I imagine all the people in a circle saying, “Go” or “No Go”), Boisjoly again presented the data, and for a moment there was a pause.

But then NASA pushed back to say the engineer's assertion was “if” and not “when”: Where, they asked, was the conclusive proof the seal will fail? As it hadn't yet, there was none. And since the launch had already been delayed five times, the issue was overruled and the launch went on as planned.

Everyone watched on TV as the seals failed in spectacular fashion.

Nobody on that call disputed the danger but they disputed the tense. Boisjoly argued when, the cold arrives tonight, the rubber stiffens at a known threshold, the physics keeps its appointments. NASA cross-examined him in if, and danger became very real.

Every danger in this edition is past the if stage, and I'm not even scratching the icy surface of dangers facing the world. Please know that my not mentioning the cuts to USAID in Africa, the wars in the Middle East, and even Trump's 2028 hat he put on at the end of the WH Correspondents dinner does not mean they're not dangers.

So then why am I making my edition this week about scary stuff? Because it feels like if is the tense we live in, but when is the reality we see.

And it's a call to action about what we can control. Danger is not something to just fear. It's something to prepare for and then to act.

We are too capable to pretend we're deaf to the cries of wolf, and we're too smart to pretend we don't see them walking through the village.

— NB