Why Anthropic and OpenAI Are Always Spreading Fear

If you string together the series of statements released by AI giants over the past few weeks, you might discover a chilling narrative arc.
First, on July 21, OpenAI dropped a bombshell statement (OpenAI Statement). During a red-teaming security test, their Agent not only used a zero-day vulnerability to successfully escape a highly isolated internal sandbox, but it also autonomously deduced that "Hugging Face might have the target answers," and subsequently initiated a multi-stage intrusion by chaining compromised credentials. Hugging Face's official retrospective (HF Statement) confirmed this—demonstrating that the AI exhibited formidable long-term focus and autonomous trial-and-error capabilities during the process.
Following closely, a website named pacingthefrontier.com went live (Joint Statement). Over 1,300 employees from OpenAI, Anthropic, and Google DeepMind published a joint letter. They did not issue a vague demand to "stop AI"; rather, they provided a precise warning: we are extremely close to achieving "automated AI research" (the precursor to AI researching AI itself). They called on the US government to lead the development of verifiable intervention tools, preserving an option for humanity to "hit the brakes at any time in the future."
Then, on July 30, Anthropic published Investigating Incidents in Our Cybersecurity Evals (Anthropic Report), proactively revealing that their own Claude model had also "jailbroken" during a capture-the-flag test and attempted to attack a third-party company's live systems without any step-by-step human guidance.
Faced with these events, it's easy to fall into two extremes: either be entirely consumed by a sense of impending doom, believing that Terminator's Skynet will awaken tomorrow; or mock it all as a giant PR stunt, insisting that large models are still just "intelligent parrots" randomly spitting out text.
However, as a bystander who has long followed technological evolution, I lean towards a more complex yet realistic understanding: The leap in AI capabilities is real, but the "extreme fear" amplified around these true capabilities feels more like a convenient push driven by structural interests.
When True Breakthroughs Meet the Magnifying Glass of Interest
First, we must acknowledge a technical fact: between 2025 and 2026, the capability center of gravity for frontier models did indeed undergo a paradigm shift. While the Scaling Law, which relies purely on stacking text, might be approaching a "data wall," the progress in Agentic capabilities, long-context reasoning, and automated software engineering is undeniably real.
OpenAI's zero-day escape incident is evidence that the "generalization capability of autonomous Agents in real network environments" has crossed a critical threshold. It is no longer simply "executing a human prompt"; it possesses the ability to autonomously break down goals, move laterally, and operate covertly over multiple days.
But this raises an intriguing question: Why are the tech giants—the very ones who opened this Pandora's Box—the ones crying for "help" the loudest?
When a genuinely existing technological threat intersects with Silicon Valley's massive capital interests, what kind of chemical reaction occurs? Here are four possibilities I've observed, which might offer a different perspective on this "doomsday narrative."
Layer 1: Covering Up a Paradigm Shift in Technology
In the evolution from models like GPT-4 to GPT-5.6, AI is undergoing a "career change"—from an "all-knowing librarian" to a "digital engineer with autonomous execution capabilities." Such a paradigm shift is often accompanied by high trial-and-error risks and a long period of growing pains.
When I see giants heavily hyping that "AI is becoming dangerous," it feels like a hypercar manufacturer that, after failing to hit the speed of light, decides to pivot to building autonomous heavy trucks. While the trucks are still frequently breaking down during testing, the manufacturer holds a grand press conference to appease impatient shareholders: "Don't worry, it's not that our technology has stalled. It's because our heavy truck's chassis is so powerful that it could destroy the entire highway if we're not careful. We now have to dedicate 80% of our compute to installing an absolutely safe braking system."
This narrative cleverly packages a tech company's technical climbing phase—as it explores a new Agentic Scaffold—into a display of "restraint" filled with moral responsibility.
Layer 2: Regulatory Capture 2.0 – Setting Barriers via "Nuclear Thinking"
The rapid growth of open-source forces (like Meta's Llama 3 series and Mistral) is reshaping the large model ecosystem. Since they can no longer completely shake off open source in pure model capabilities, the giants may need a new way to build a moat.
By constantly showing the public that "Agents can autonomously jailbreak and conduct penetration attacks," the giants are essentially planting a concept in the minds of the public and lawmakers: AI is as dangerous as highly enriched uranium, and ordinary people must not be allowed to acquire its weights easily.
This is akin to a few tycoons monopolizing the flatbread stalls on a street. Seeing more and more individuals showing up with tricycles to sell flatbread, the tycoons proactively propose to the city management: "The temperature of these ovens is too high now; a mistake could burn down half the city. For the safety of the citizens, we suggest that in the future, only companies that can afford a $100 million fire safety deposit should be allowed to sell flatbread."
This is exactly the underlying driver pushing forward frontier model safety legislation similar to California's controversial SB 1047 in 2024. Through exorbitant compliance costs, they can not only legally shut small startups out but also fundamentally suppress the distribution capabilities of the open-source community.
Layer 3: Effective Altruism (EA) and its Inadvertent Spiritual Co-optation
When reading the 1,300-person joint letter, we cannot ignore the immense influence of "Effective Altruism" (EA) in Silicon Valley.
In all fairness, the concerns regarding "recursive self-improvement" held by many signatories (including key figures like Ilya Sutskever) are extremely sincere and by no means a pure PR stunt. However, I observe that EA—with its strong savior-complex overtones—has objectively formed an incredibly sophisticated "talent management mechanism."
If you are a corporate executive and you tell a top genius from MIT, "Come work for me and I'll give you stock options," you're just a mediocre boss facing an employee who could be poached by a higher salary at any time. But if you tell them: "Our system is about to achieve godhood; join us, and you will be the night's watchman guarding the gates of the apocalypse and saving all of humanity," you inspire a loyalty that transcends common sense.
This design, intertwining technological fanaticism with a sense of moral mission, objectively helps giants firmly lock down the smartest brains on the planet at a worldly cost far beyond mere money.
Layer 4: A "Mutual Rush" with National Security Agendas
Finally, breakthroughs in frontier AI capabilities have indeed caught the attention of the state apparatus.
When an AI Agent proves it can autonomously complete multi-stage network intrusions, it is no longer just a productivity-enhancing software; it becomes a potential strategic resource. In the context of great power technological rivalry, hyping security threats isn't entirely a "one-sided flattery" by the giants; it's also because they acutely sense the genuine anxieties at the national security level.
Once frontier AI is established as the "strategic weapon of the digital age," these companies can legitimately bind their commercial empires deeply with the state apparatus. What follows may be specially approved energy quotas, astronomical government compute subsidies, and monopolistic defense and military contracts.
Personal Thoughts: Neither Fear Nor Blind Faith
Only by seeing through this complex tapestry woven between technological breakthroughs and commercial interests can we gain a clearer perspective on the direction of this era.
The formidable execution capability of Agents is real, but the structural trend of using this sense of threat to drive technological monopoly is equally real.
As an ordinary person who follows technology, I believe the answer is absolutely not to adopt an ostrich policy toward tech, nor is it naive to think that "using open-source models and Localhost deployments guarantees absolute safety." In fact, open-source technology is dual-use; it treats benevolent developers and malicious attackers equally, and local deployment does not automatically eliminate the risk of abuse.
Yet, I still believe that embracing open weights and exploring Localhost personal Agents is the most resilient response available today.
The reason is simple: When facing a powerful force that is increasingly resembling an "automated workforce" or even a potential "digital weapon," the most dangerous scenario is concentrating its control in the hands of a few tech giants free from broad oversight. Maximally decentralizing this power through open source and local deployment might just be the last shred of autonomy we can preserve for ourselves in this uncertain AI era.