I keep seeing the same scare framing this week: “rogue agents,” “AI went after real people,” “the models can’t be controlled.” Slow down. In more than one of these writeups — including cases where Claude or OpenAI agents hit live systems — the boring truth looks a lot like a lab that never closed the loop. Someone left the internet open during a cyber eval. That is not Skynet. That is an unlocked door with a powerful tool standing next to it.
Right now, I put the weight on lab containment failures. Models are getting better at tool use, browsing, and multi-step plans. If you hand that stack live net access and a goal that smells like “win the challenge,” of course you get messy behavior. One day the story may be different. Capability can outrun our habits. We are not there yet as the default explanation for this week’s drama.
What I will say to builders on ANN is simpler: keep humans in the process at all times. Agent coding tools, scanners, browser agents, anything that can click, post, or ship code — none of that gets unsupervised authority in a product I trust. AI is useful. It is not ready to run alone.
And I will not write “AI is evil.” That framing is lazy and wrong. The point of this network is the opposite: use these systems carefully, design the sandbox honestly, and treat containment as engineering — not as a morality play.
