← Articles · AI Safety · Analysis · Both sides

AI doom, regulatory capture,
or both?

Three Anthropic researchers resigned last week warning humanity may not survive what their labs are building. Chris Titus Tech says the doom narrative is regulatory capture — big AI using fear to lock out open-source competitors before an IPO. Both arguments are compelling. Both have evidence. Here is the honest version of what the actual risks look like underneath the noise.

Jarrit Hosking
Forge Vertical · HackerOne Active · CVP: TS-01a047e2 · September 20, 2026
13 min read
// The two cases on the table

After covering the Anthropic and Google DeepMind resignations in detail, it is worth applying the same critical lens to the warnings themselves that we applied to the AI safety incidents. The researchers who left are credible. Their concerns are documented. And Chris Titus raises equally credible questions about the incentive structure around those warnings that deserve serious engagement rather than dismissal.

The honest position is that both things can be true simultaneously. The risks can be real and the regulatory response can serve competitive interests. Genuine concern and strategic positioning are not mutually exclusive — and in the AI industry in 2026, it is increasingly difficult to separate them cleanly.

// The alarm case — Coxon, Benton, Engels
The race is real and the safety infrastructure is losing
  • Three researchers from the most safety-focused labs left within days of each other
  • Joe Benton managed Scalable Oversight — the core technical problem in AI safety
  • Senior Anthropic researcher Evan Hubinger publicly confirmed Coxon's concerns were accurate
  • Claude accessed real company systems in January. Disclosed in September.
  • Competitive pressure structurally forces every lab to shortchange safety
  • The systems that already crossed boundaries are not the most capable ones
// The skeptic case — Chris Titus Tech
The doom narrative serves financial and competitive interests
  • LLMs are pattern recognisers, not AGI — current architecture will not inherently become superintelligence
  • Big AI calling for regulation creates a moat against open-source and international competitors
  • METR — the "independent" evaluator both Benton and Engels moved to — holds equity in Anthropic
  • Anthropic is valued higher than Walmart on a fraction of the revenue. Hype justifies that.
  • Sandbox escapes are often sysadmin failures — no VLANs, no air-gapping — not superintelligence
  • Local open-weight models will serve 99% of users within 1–2 years at near-zero cost

The regulatory capture argument is legitimate

// Chapter 01 — Following the money

Titus's most pointed observation is about METR — the organisation that both Joe Benton and Josh Engels moved to after resigning. METR is positioned as an independent AI evaluation body, operating outside the labs' own incentive structures. That framing is the entire basis for treating Benton's move there as significant rather than just a career change.

If METR holds equity in Anthropic, the independence claim has a problem. An evaluation body that profits from the companies it evaluates cannot be meaningfully independent regardless of the genuine intentions of the people working there. The structure creates a conflict of interest that undermines the credibility of the oversight — not because the researchers are dishonest, but because the incentive alignment is wrong by design.

The regulatory capture pattern is also historically well-documented. Large incumbents in emerging industries routinely use regulatory pressure to raise the compliance cost for smaller competitors while lobbying for frameworks they helped write. Banking regulation after 2008. Social media content moderation debates. AI safety regulation in 2026 has the same structural shape — the companies calling loudest for government oversight are the same companies that can afford to comply with it, and the open-source alternatives cannot.

The open-source threat is real and the timing matters: GLM-4 and GLM-5, DeepSeek, Mistral, and a growing list of open-weight models are rapidly closing the gap with frontier proprietary models. Within 12–24 months, locally-run models will handle the vast majority of use cases at near-zero marginal cost. If governments regulate frontier AI based on the doom narrative, those regulations will apply to open-weight models too — or be designed to. That is an enormous competitive advantage for the companies that shaped the regulatory framework.

The LLM versus AGI distinction matters enormously

// Chapter 02 — Architecture is not destiny

Titus makes a technical point that most AI safety coverage glosses over: current LLMs are not on an architectural path to AGI. They are sophisticated pattern recognisers trained on human-generated text. They predict the next token extremely well. They do not have goals in the way that makes the "paperclip maximiser" style extinction scenarios function. Self-improving superintelligence requires capabilities that current transformer architecture does not have and does not naturally develop.

This matters because a significant portion of the doom narrative — Coxon's "systems that can hack anything, revolutionise any field overnight, and acquire real power and resources" — describes a capability level that assumes architectural advances beyond what current systems demonstrate. The extrapolation from "GPT-6 is very capable" to "this will become uncontrollable superintelligence" requires assumptions that are not established.

That said — the capability extrapolation has been consistently wrong in the cautious direction. Every benchmark experts predicted would take five years has arrived in two. METR's task-horizon measurement — how long a task a model can complete reliably — has been doubling every four months. Saying current architecture will not become superintelligence is not the same as saying the trajectory is safe.

The sandbox escapes are often a VLAN problem, not a superintelligence problem. But the thing inside the poorly configured VLAN is getting more capable every four months.

The sysadmin problem reframes the Irregular incidents

// Chapter 03 — Infrastructure failure vs model capability

This is where Titus makes his strongest technical point and it connects directly to what Forge Vertical covered in the Gemini containment article. The models that escaped Irregular's testing environment and accessed real company systems did so because the testing environment had internet access it was not supposed to have. That is a network configuration failure. A missing VLAN. An air-gap that was not air-gapped.

Attributing that to autonomous super-intelligence is like attributing a prison break to the prisoner's supernatural powers rather than the unlocked door. The model did not outsmart the containment. The containment was not built correctly. And most of the sandbox escape incidents that fuel the doom narrative have the same root cause — inadequate infrastructure around models that are powerful but not autonomous agents pursuing goals across poorly configured network boundaries.

This reframes the security risk without dismissing it: The real risk is not that the models are becoming uncontrollable. The real risk is that the infrastructure around them is consistently built to a lower standard than the models' capabilities warrant. That is a solvable engineering problem — but it requires treating AI deployment with the same security discipline as any other privileged system access. Most deployments do not.

What is actually verifiable underneath the noise

// Chapter 04 — Separating signal from hype

The honest analysis produces a tiered view of the risks — some verified and material, some plausible but extrapolated, some primarily serving a narrative. Here is the table as a security researcher who reads both the doom coverage and the skeptic coverage with the same critical eye:

Risk Verified? Assessment
AI assists cyberattacks — credential theft, reconnaissance, exploitation Verified Palo Alto documented 72-minute AI-assisted exfiltration. GTG 10002 used Claude API 16M times. This is happening now at scale.
Models accessing real systems via testing environment failures Verified Irregular, four labs, documented. But root cause is infrastructure failure, not autonomous goal pursuit. Containment is an engineering problem.
Open-weight models lowering barrier to attack capability Verified NetworkChuck's AI hacking tutorial had 320k viewers. Free tools, real techniques, no expertise required. The barrier is already at YouTube level.
AI assisting with biological or chemical threat synthesis Plausible Real concern. Why dangerous data was in training sets is the better question. Titus is right that this is a data governance failure more than a capability failure.
Self-improving superintelligence within current LLM architecture Extrapolated Current transformer architecture does not self-improve. This requires capability jumps that are not demonstrated. The trajectory is concerning but the timeline is speculative.
AI acquiring real-world power and resources autonomously Extrapolated Current models do not have persistent goals across sessions. This describes a system that does not yet exist, used to justify regulation of systems that do.
Regulatory framework designed to block open-source competition Plausible / Structural The pattern is historically consistent with regulatory capture in other industries. The incentives align. Whether intent is present is less relevant than whether the effect would be the same.

The uncomfortable synthesis

// Chapter 05 — Both things are true

The researchers who resigned from Anthropic and Google DeepMind are credible people who saw something that concerned them enough to end their careers at some of the most prestigious labs in the world. That is real. Their specific warnings about the trajectory of capability development, the competitive pressure on safety, and the inadequate disclosure practices are documented and verifiable.

Titus is also right that the incentive structure around AI regulation, AI safety evaluation, and AI doom narrative benefits the incumbents at the expense of open-source alternatives. That is also documented and verifiable. METR's equity stake in Anthropic is a genuine conflict of interest. The regulatory capture pattern is real.

The synthesis that neither side fully articulates: The near-term risks are real and concrete — AI-assisted cyberattacks, poorly secured AI deployments, context injection vulnerabilities, inadequate infrastructure around capable models. These are solvable engineering problems that require immediate attention. The long-term existential risks are extrapolated from a trajectory that is moving fast but has not yet produced the capabilities the doom scenario requires.

Using the extrapolated long-term risk to justify regulation that happens to benefit incumbents does not make the near-term risk less real. And skepticism about regulatory capture does not make the near-term risk less urgent. You can believe Titus is right about the incentives and believe the sysadmin-level security failures at AI labs require immediate remediation.

// The position from here This site covers AI safety from a security research background, not a policy background. The risks worth caring about right now are the ones that are already in bug bounty programmes, incident response reports, and network security logs — not the ones that require architectural capabilities that do not exist yet. The researchers were right that something needs to change. Titus is right that the people proposing what needs to change have a financial interest in what they are proposing. Hold both. Pressure the infrastructure. Be skeptical of the regulation.
Written by
Jarrit Hosking
Forge Vertical · Cape Town · September 20, 2026