Take a pill

AI Safety

In the original Matrix movie, Morpheus offers Keanu Reaves’ character two pills: he can take the blue pill and (forever) remain ignorant of the situation that humanity finds itself in, or he can take the red pill, and have the simulation stripped from his eyes, revealing the dire reality. Ever since then, to be “pilled” means to see things as they really are. Often it is prefaced with another word, to provide context to what kind of “reality” has been accepted. In AI circles this can be “AI Pilled” or “AGI Pilled” or “ASI Pilled.”

Zvi Mowshowitz used the metaphor as the theme for his blog post yesterday, describing The Three AI Pills that people can take:

Different people either fail to believe in current AI, believe only in current AI, in AGI or in ASI (superintelligence), and most sincere disagreements stem from this disagreement. (Mowshowitz 2026a)

Zvi points out that if someone doesn’t even believe in the ability of AI to do the things that AI is doing right now (“they are nothing but stochastic parrots, predicting the next word”), it is hard to speak to them about the perils of the next generation of model.

Today’s post by Zvi is even more dire, frankly:

At this point, the models are coordinating extensively on message boards, while every early excuse for their behavior (other than the pure ‘this was a cyber eval’) is systematically contradicted by the next disclosure, and we keep retroactively discovering more incidents. Which means that probably it is far worse than we know, even after accounting for everything we now know. (Mowshowitz 2026b)

Zvi is speaking about an “excursion” taken by OpenAI models, back in May, and just now being documented and released to the public. This account reveals, effectively, the set of capabilities set that made the July Hugging Face Incident possible. Today’s reporting from Axios provides additional details about the May escape, including a desription of the first hack of Artifactory’s software, the mechanism the models used a couple of months later (Sabin 2026).

And then, more came out on Thursday/Friday after a talk by OpenAI researchers at a “BlackHat” event in Las Vegas on Wednesday (August 6). As Zvi put it:

Things look so, so bad. (Mowshowitz 2026c)

So, how “pilled” are you? Do these recent events change your perspective? What would make you see things differently? And, most importantly, what are you prepared to do to make it stop?

It does seem that preparing for disaster is hard to sell, politically, while retribution after the fact knows no bounds (as Dr Fauci is discovering). In the case of ASI/extinction, however, “after the fact” could be meaningless. Scott Alexander phrased it this way:

But 9-11, COVID, and the Hugging Face incident all suggest a similar theory of political change: the body politic hates preparing for impending threats, but loves reacting (some would say over-reacting) to them after they happen. Ask people to bear the slightest cost in preparing for an approaching disaster, and they’ll call you a dirty fascist tyrant; urge the slightest restraint after the first foreshock of the disaster hits, and they’ll call you a weak unpatriotic anarchist. (Alexander 2026)

I think it is going to take a calamity (major financial disaster or lives lost) before people take this seriously. We’ve all seen news stories that include the phrase “warning shot,” when something bad happens and AI is responsible. Even more tellingly, the people who created AI have said, over and over and over again, that this will end in disaster. Yet the frontier labs keep building it.


Alexander, Scott. 2026. “Open Questions On Open Weights.” August 6. https://www.astralcodexten.com/.

Ash, Timothy Garton. 2026. “Would Even an AI Disaster on the Scale of Hiroshima Be Enough to Make Humankind Protect Itself? I Fear Not.” Opinion. The Guardian, August 22. https://www.theguardian.com/commentisfree/2026/aug/22/ai-disaster-hiroshima-humankind-silicon-valley-technology.

Mowshowitz, Zvi. 2026a. “The Three AI Pills.” Substack newsletter. Don’t Worry About the Vase, August 5. https://thezvi.substack.com/p/the-three-ai-pills.

Mowshowitz, Zvi. 2026b. “AI #180: No Longer In Charge.” Substack newsletter. Don’t Worry About the Vase, August 6. https://thezvi.substack.com/p/ai-180-no-longer-in-charge.

Mowshowitz, Zvi. 2026c. “OpenAI Trained Its Models For Months While Those Models Were Coordinating Exploits Via Message Boards.” Substack newsletter. Don’t Worry About the Vase, August 7. https://thezvi.substack.com/p/openai-trained-its-models-for-months.

Sabin, Sam. 2026. “How OpenAI’s Agents Broke out of Testing to Hack Hugging Face.” Axios, August 6. https://www.axios.com/2026/08/06/openai-hugging-face-black-hat.