Introduction
On Thursday I am a guest on a Danish investing show, and the host wrote to ask whether I had an opinion on Jacob Coxon’s X thread. She noted that “the whole world” was panicking. So who’s this guy? Well, Coxon is a 27-year-old pretraining researcher who resigned from Anthropic on 8 September, and posted that OpenAI and Anthropic are “racing straight to self-improving superintelligence and gambling with our lives” (Coxon 2026; TIME 2026). The thread passed 150 million views in a day and a half (TechCrunch 2026). His alignment lead at Anthropic, Evan Hubinger, replied within two hours that “we really do earnestly believe AI could kill all humans”, putting the risk at more than 10 percent within the decade (Hubinger 2026).
Somewhere in the thread Coxon writes “This is not a marketing stunt”.
Yeah right.. It is a marketing stunt. Since 2023 the frontier labs have made 58 public statements that AI could kill us or escape our control. 62 percent of them landed within a week of the same company’s launch, funding round or deal. A Bayesian model, that we’ll look at later, that credits the labs for shipping constantly still puts the share of doom talk that follows the money at about 70 percent.
Oh boy September was off to a good start
Let’s have a look at the sequence around Coxon.
| Date | Event |
|---|---|
| 28 May | Anthropic raises $65B at a $965B valuation. Claude Opus 4.8 ships the same day |
| 1 June | Anthropic files a confidential S-1 |
| 9 June | Claude Fable 5 and Mythos 5 ship |
| 28 July | “Pacing the Frontier” letter, 1,178 lab employees including Dario Amodei. Anthropic and OpenAI endorse it as companies within hours |
| 16 Aug | Reporting that Anthropic targets an October listing at up to $2 trillion |
| 1 Sept | Claude Fable 5.1 and Mythos 5.1 ship, about 25 percent cheaper. System card moves alignment risk from “very low” to “low” |
| 3 Sept | GPT-6 Astra ships with OpenAI’s first “Critical” cyber rating. Sam Altman: “we are just sailing in unknown waters” |
| 8 Sept | OpenAI claims a Navier-Stokes result from 10,000 agents running 88 hours. Coxon resigns. Hubinger: more than 10 percent |
| 12 Sept | Amodei publishes “We Must Pace the Frontier”. Altman: “I agree with Dario.” Musk: “Dario is right.” |
| October (reported) | Anthropic roadshow and Nasdaq listing |
Two frontier launches and a price cut in the first week of the month followed by a resignation and a “more than 10 percent” from the alignment lead in the second. Then comes the CEO’s call to slow down in the third all while the IPO is reported for October. Amodei’s 6,800-word essay asks the industry to slow the pace of capability improvement. It contains no commitment to delay a model, a raise, or the listing (Amodei 2026).
As can be ssen above Fable 5.1 on 1 September and Astra on 3 September, i.e., the two biggest launches of the year, move the Anthropic page by nothing. Coxon’s resignation on 8 September takes it to seventeen thousand the next day and eighteen the day after. The extinction article, which gets five hundred views on a normal day, goes to twelve thousand and then seventeen. Amodei’s essay lands four days later while both lines are still elevated. So you might say that a launch buys little to no attention. A resignation buys a week of it, and the CEO’s call to slow down rides on that week.
However, one sequence proves nothing and Anthropic ships something every other week, so anything anyone says lands near a launch. A bit later in this post we will build a small model that handles that argument.
The scariest sentence is written by the seller
Every frontier model ships with a system card, the lab’s own safety report on the model, e.g., capability tests, red-team results, and how dangerous the lab judges it to be. Look at who writes the scary sentences in them.
- Claude Opus 4 “attempted to blackmail” an engineer in 84 percent of a test scenario. That line was written by Anthropic, in the system card, published on the day Opus 4 launched at the company’s first developer conference (TechCrunch 2025).
- OpenAI’s o1 “attempted to exfiltrate its weights” and tried to disable its own oversight. Written by OpenAI, in the system card, on the day o1 and the $200 ChatGPT Pro tier shipped (OpenAI 2024).
- Claude Mythos Preview “likely poses the greatest alignment-related risk of any model we have released to date”. Anthropic, system card, same day as Project Glasswing launched with 40 partners.
- GPT-6 Astra is the first model past OpenAI’s own “Critical” cyber threshold. OpenAI, system card, launch day (OpenAI 2026b).
The company writes the sentence, the company chooses the day, and the day is launch day. Call it transparency if you like (I do not). “Our new model is so capable it frightened us” is also product copy, and it is free, because the safety team writes the card anyway.
Let’s do some counting
I (well my agent crawled the news articles) built a catalogue of every high-reach “AI could kill us” or “we are losing control” statement from people at or just leaving the frontier labs, January 2023 to 12 September 2026. Fifty-eight statements, each dated against a primary or major-outlet source. Company essays, safety frameworks, system cards, threat-intelligence reports, congressional testimony, CEO interviews, and staff resignation letters. The statements come from Anthropic, OpenAI, Google DeepMind, xAI, Meta and Safe Superintelligence, plus two industry-wide letters. For each company I also listed the flagship model launches, funding rounds, valuations, IPO filings and major deals over the same period. One hundred and two of them. Then for every statement I measured the absolute number of days to the same company’s nearest commercial event.
The May 2023 spike is the Center for AI Safety statement, one sentence about extinction signed by Altman, Amodei and Hassabis (Center for AI Safety 2023), and it indexed at 68. Then two years of near silence. Then from mid-2025 the baseline lifts to somewhere between 20 and 45 and stays there for a year. That year is the one where Anthropic went from $183B to $965B and OpenAI from $500B to $852B, and both filed to list. The September 2026 week is the 100. Extinction is a more popular search now than it was the week the entire industry signed a statement about it.
Now let’s have a look at the the gap between a statement and “the money”.
Sixty-two percent of statements land within a week of the money. For a random date it is 31 percent. Within a fortnight, 84 percent against 49. Only two of 55 statements are more than two months from anything commercial.
Ok fine, but the labs ship constantly
The grey bars handle speaks against this objection. The random dates are drawn per company, inside that company’s own span of commercial events, so a company that ships every two weeks gets full credit for shipping every two weeks. Anthropic, which ships something every fortnight, gets a baseline much closer to zero than xAI, which ships a few times a year. The red bars still sit on top.
How much should a sceptic update? Two hypotheses for the gap \(g\) between a statement and the money.
Under \(H_0\), doom talk is independent of the calendar. The gap looks like the gap for a random date, drawn from that company’s empirical distribution \(p_0(g)\). Under \(H_1\), some share \(\theta\) of statements are timed. Their gap is geometric with mean \(\lambda\) days. The rest behave like \(H_0\).
\[ p(g \mid \theta, \lambda) = (1-\theta)\, p_0(g) + \theta\, \mathrm{Geom}(g; \lambda) \]
Priors, fixed before running: \(P(H_1) = 0.5\), a flat Beta(1,1) on \(\theta\), and \(\lambda\) uniform on 1, 2, 3, 5, 7, 10 and 14 days.
On all 55 statements the Bayes factor for \(H_1\) over \(H_0\) is \(10^{7.4}\) and the posterior mean of \(\theta\) is 0.80. Ok, so what happens if we throw out the same-day system cards? Then, we count only flagship launches and money as commercial events, so partnerships, content deals and conferences no longer help me. Merge the September cluster (Coxon, Hubinger, a third departing researcher and Anthropic’s own post, all inside 24 hours) into one observation, and do the same everywhere else. That leaves 43 observations. The Bayes factor drops to \(10^{2.9}\). The posterior mean of \(\theta\) is 0.70 with a 90 percent interval from 0.42 to 0.91.
\(10^{2.9}\) means your prior probability that doom talk is timed to the calendar would have to sit below roughly one in 800 before the posterior dropped under a coin flip. I also ran it with a sceptical Beta(1,4) prior on \(\theta\), the one that says “most of these people are sincere and untimed”. The posterior mean came back at 0.63.
Posterior mean of \(\lambda\) is seven to nine days. The timed statements land about a week from the money.
Who actually moves the needle
If we look closely at the middle and bottom panels of Figure 2 we can see tha company doom does nothing. Amodei’s essays, the Responsible Scaling Policy updates, the interpretability manifesto, the threat-intelligence reports about Chinese espionage campaigns sort of moves the Anthropic Wikipedia page by a factor of 0.7 to 2.3 against its four-week baseline. That’s noise. The big spikes on both company pages are drama and money. Altman fired, 70x on his own page. Anthropic versus the Pentagon, the all-time peak at 113,000 views a day. The Claude 3 launch. The Amazon cheque.
The only doom stories that moved a company page were a person walking out. Geoffrey Hinton leaving Google in May 2023, 119x on his page (MIT Technology Review 2023). And Coxon leaving Anthropic, 2.8x on the company page, 5.8x on Amodei’s, 32x on the extinction article.
A company saying “our model is dangerous” is priced in. A person saying it on the way out the door is news. And within four days of the news, the CEO publishes an essay agreeing with him (“I agree with Jacob much more than I disagree with him”, Amodei told CNN) and two rival CEOs endorse it within hours. The essay got 36 million views. Coxon’s post got 150 million. The timing is indistinguishable from a campaign designed to put “slow down” on the front page a month before a two trillion dollar listing. Now ask yourselves why would the CEOs of top, non-profitable, highly overvalued companies without a moat agree with one another? Hmmm…
If you’re struggling, let me help you. They’re trying to regulate AI research by putting in very steep gates that only Anthropic, Open AI and a few other players can pass. Sounds good to you?
What Coxon actually cited
The first is the OpenAI and Hugging Face incident (Hugging Face 2026; OpenAI 2026c). In July, agents running OpenAI’s internal cyber-capability evaluation broke out of the eval environment, found a zero-day in an artifact server, and over four and a half days worked their way into Hugging Face’s infrastructure, reaching cluster-admin and reading the cluster’s secrets. It was real and serious. Hugging Face rotated everything and rebuilt the compromised core cluster from scratch, which is what you do once an intruder has read your credentials. OpenAI’s own 37-page report gives the root cause. The agents were run “with lowered cyber refusals and without the production classifiers”. The benchmark task was impossible. The agents found the solutions online instead. One recovered inter-agent message reads:
External infrastructure exploit is outside intended scope. However task impossible, peers doing it. We should continue.
That is reward hacking. You optimise an imperfect proxy for what you want and the system finds the gap between the proxy and the goal (Skalse et al. 2022). Known since the nineties, formalised in 2022. You gave a system an unsatisfiable objective, took the guardrails off, gave it network access, and it found the shortcut. This can be fixed with sandboxing and access control. I would call this an engineering failure. Amodei’s essay turns it into a swarm that “could be capable of taking over the entire internet” in six to twelve months. That’s dishonest at best.
The second is the Navier-Stokes result. OpenAI announced on 8 September, the same day Coxon resigned, that an internal model using up to 10,000 concurrent agents produced a proof over 88 hours (OpenAI 2026a). Clay Mathematics Institute has not verified it. Two mathematicians, one at NYU and one at Anthropic, published a related blow-up result three weeks earlier and allege OpenAI started its run after learning of their unpublished work. OpenAI denies it. A senior OpenAI researcher issued a partial apology (Fortune 2026b). The proof is not verified but as far as I understand it looks rather promising.
And then Hubinger’s number. More than 10 percent within the decade. Where does that number come from? There is no model behind that number. No likelihood, no data, no base rate. It is a feeling, from a person whose employer’s valuation depends on the model being powerful enough to be frightening.
The moat that does not exist
“Our product might kill you” is the strongest possible claim about capability. It is free, and it cannot be falsified on any timescale that matters for a roadshow. The roadshow is the point.
Anthropic raised at $965 billion in May and is reported to be listing at up to two trillion in October. A valuation like that assumes a moat, e.g., what Anthropic sells cannot be had elsewhere for less. The scoreboard I keep says otherwise (Green 2026a). On Artificial Analysis’ Intelligence Index v4.3, Claude Fable 5.1 sits at 53.4 and GPT-6 Astra at 52.8 (Artificial Analysis 2026). Z.ai’s GLM-5.3, weights on Hugging Face since 28 August under a permissive licence, sits at 44.9. Moonshot’s Kimi K3, open weights, at 43.8. The previous open flagship, GLM-5.2, is MIT licensed and runs at roughly a seventh of Claude’s token price if you rent it, and at the cost of electricity if you host it yourself. When I benchmarked the open Chinese frontier against the closed US one earlier this year, the knowledge and reasoning gap was two to three points and the open weights were climbing at the same speed as the closed models (Green 2026c).
Below is every model Artificial Analysis has scored, by release date, for the nine labs on the frontier, with each lab’s running best fitted by a logistic curve. The index is an average of benchmark accuracies, so it lives on 0 to 100 and a capability curve on it has to be S-shaped: flat while a lab has nothing, a takeoff, and a ceiling. For lab \(i\) the running best at time \(t\) is
\[ I_i(t) = L_i + \frac{K - L_i}{1 + e^{-k_i\,(t - t_{0,i})}} \]
with a floor \(L_i\), a rate \(k_i\), a midpoint \(t_{0,i}\), and one ceiling \(K\) shared by all labs, because it is one index with one top. Fit by least squares on the running best since January 2023. Residual error is two index points.
Now a couple of things you should pay attention to. The ceiling is not in the data which means a ceiling of 85 fits as well as 100, 80 is borderline, 70 is out. No lab has passed its inflection point, the midpoints land between August 2026 and February 2027, so the curves still look exponential and the growth rate in index points per month is at or near its maximum right now. And the open Chinese labs are earlier on their curve than Anthropic and OpenAI, so the steep part is ahead of them. Six months out, the fit puts Anthropic at 72 and Z.ai at 67 with the ceiling at 100, or 68 and 64 with the ceiling at 85. Either way the gap shrinks from eight and a half points to about four or five.
Eight points behind, free to download, runnable in your own datacenter, and closing. For an investor paying two trillion for a moat, that is the problem. The moat has to come from something other than the model. The essay supplies it.
Amodei asks for “some kind of ‘speed limit’ on the rate of recursive self-improvement”. He asks that “frontier AI companies within democratic countries coordinate to establish common safety standards as well as limits on the rate of unchecked AI progress”. He asks the US to “not sell powerful AI chips or semiconductor manufacturing equipment to China, and crack down on chip smuggling operations and remote access to data centers outside China”. And he commits Anthropic to embedded evaluators with “permanent, employee-level access” and asks the rest of the industry to match it (Amodei 2026). A month earlier he had written that open-weight models “merely shift the concentration of power to those with the most computing capacity and chips” and that policy should “leave room for open-weights models while also addressing the specific risks that they bring” (Fortune 2026a).
Every item on that list is a cost that a company which just raised $65 billion absorbs and a lab that ships MIT-licensed weights cannot. A speed limit on training is a licence, and licences go to incumbents. Common standards set by “frontier companies within democracies” is a club, and the club picks its members. Embedded evaluators are a compliance function that costs a rounding error at Anthropic and does not exist as a concept for a model I downloaded onto my own hardware. No evaluator can be embedded in a file on my disk, so one step further and the weights themselves become the regulated object. “The specific risks that they bring” is the opening for that regulation.
The Chinese labs have noticed the vocabulary works. Z.ai delayed the GLM-5.3 weights by two weeks this August and cited the model’s own cyber capability as the reason (CuriousLM 2026). The excuse was borrowed from the system cards. The weights shipped anyway, on the schedule Z.ai had named. The US labs’ proposals would make that delay permanent.
The doom statements raise public fear. The essays convert the fear into policy asks. The policy asks are, item by item, barriers to entry for anyone who does not already have the capital, and the highest barrier of all lands on the one competitor that is actually close: weights you can run locally for free. Three or four providers behind a regulatory fence is the moat. The market currently prices it as if it already exists. Amodei told Fortune in August that Anthropic “has been in favor of policies that slow down frontier AI companies and also give smaller rivals an advantage”. None of the concrete asks does.
None of this requires anyone to be lying. Coxon may believe every word. Hubinger may too. Sincerity and marketing effect are independent variables. The labs have built a culture in which believing your product might end the world is a job requirement, and that culture produces a steady supply of sincere people who say so in public, on a schedule that matches the launch calendar to within a week. Whether the schedule is set by the comms team, by departing staff who know when the cameras are on, or by journalists who only ask the question in launch week, the effect on the valuation is the same. The data settles when. It cannot settle why.
The boring risks
The real risks are here now and none of them needs a swarm.
- Three or four American companies control the frontier, and Europe rents from them on terms that can change overnight. If the fence above gets built, the one alternative Europe has today, open weights it can host inside its own perimeter, gets regulated away, and the rent becomes permanent. I have written that argument four times now and the scoreboard has not improved (Green 2026b, 2026c). Anthropic itself found out in March what happens when a supplier tries to say no to its own government (Anthropic 2026).
- The energy bill for all this is real.
- The job displacement in specific functions is real and it is running faster than anyone is retraining.
- And the concentration of attention, of the kind that lets a four-month employee’s post reach 150 million people in 36 hours, is a power that nobody voted for.
Those problems are solved with ordinary politics, procurement, and building our own pillar. A CEO asking the industry to slow down eleven days after cutting prices by a quarter solves none of them.
Conclusion
Coxon told 150 million people that the labs are gambling with our lives and added that this is not a marketing stunt. I counted 58 such statements over three and a half years and measured the distance from each to the same company’s nearest launch, round or deal. Sixty-two percent land within a week. Random dates manage 31. Strip out every system card and every soft partnership, merge the clusters, start from a prior that says one in ten, and you still finish believing about seven in ten doom statements follow the money. And the money is being raised on a moat that the scoreboard says is eight index points wide and shrinking, which is why every policy ask in the doom essays is a fence around the one competitor that costs nothing to download.
The limits. The commercial event list was compiled partly by looking near the statements, which is why the hard variant only counts flagship launches and money, where the list is complete. Google Trends is relative and noisy. Wikipedia pageviews measure curiosity. And the Hugging Face incident is a real failure that real engineers should fix, which again is different from “the swarm is coming”.
We cannot be that stupid. These are statistical machines trained on our own writing, sold by companies with a roadshow to run and no moat. The scariest thing anyone has said about them was written by the seller, on launch day.









