Yves here. Rob Urie gives us a debunking double-header, on two big current freakouts, one on agentic AI, the other on the bond market non panic. As Rob said via e-mail, “This is like debating adults over the existence of Santa Claus. With all of them taking the side that Santa lives.”
By Robert Urie, author of Zen Economics, artist, and musician who publishes The Journal of Belligerent Pontification on Substack
This essay was just being finished when new revelations were brought to light that OpenAI had at least six more incidents where its AI ‘agents’ (hack bots) escaped containment in order to complete the tasks that they had been given. As the press uses language about ‘bad behavior’ by the bots, there exist mechanical explanations for why the bots are doing what they are doing. That OpenAI and Anthropic may not have expected these outcomes is the only news story here.
The hurdle to overcome is what the AI executives are saying versus less romanticized explanations of what actually happened. The executives are claiming that the hacks happened because the AI agents (bots) are ‘superintelligent’ and ‘too powerful’ to keep contained. Nonsense. The actual problem as I understand it is a chicken or egg temporal dilemma. AI coders can’t effectively prevent AI agents from escaping their containment without knowing all of the exit points. And all of the exit points can’t be known until the AI agents have found them by escaping their containment.
Those claiming no danger from ‘Agentic’ AI are mistaking self-serving articulations of the problem with there being no problem. Agentic AI faces the fact that AI engineers don’t know what they don’t know. No one does. But finding previously unknown points of entry and exit is what AI ‘agents’ are created to do. This was how the OpenAI hack bots (agents) escaped their digital containment. The problem is that the information needed to code effective restrictions into agent behavior isn’t available until after the problems warranting the restrictions have already been caused.
So, what happened? Developers at OpenAI were running a test of multiple AI hacking ‘agents’ when the agents hacked their way out of their digital containment and hacked their way into the Hugging Face system to complete the task to which they had been put. The implication has been put forward by multiple parties that the AI agents were acting against their nature and / or instructions. They weren’t. In fact, they did precisely what they were created to do. Nothing more and nothing less. So, why is this news?
It’s news because the AI agents did what they were created to do. In the OpenAI case, they found an exit and went on to hack the Hugging Face system. As I understand them, the four hacks that Anthropic did were similar in their basic facts. AI agents built to hack other computer systems hacked the systems which hosted them after they were unable to complete assigned tasks without doing so. Coded restrictions to prevent them from escaping their containment required specific knowledge of the exits that logically (temporally) couldn’t have been known until they had been found.
As I understand it, the AI agents weren’t specifically directed by OpenAI or Anthropic management to do the hacking. The agents were 1) created as hack-bots, 2) to use brute force computing to hack computer systems, 3) based on coded restrictions on their activities, 4) that had been reduced or removed in the test environment, 5) that the agents hacked their way out of. In theory at least, well written coded restrictions could have prevented the hacks. But again, the temporal problem is unsolvable as I understand it. Effective coded restrictions require knowledge that no one possesses until a hack has occurred.
The common factor in the hacks was the removal of ‘safety’ restrictions to see how the models would behave in test environments without them. But the practical problem with containing AI hack-bots is that they are AI hack bots. Their raison d’etre (reason to be) is to find and exploit computer system vulnerabilities. That they would hack their way out of their test environments if they could should have been expected. This is so obvious that the question must be asked if the release of these hack-bots was accidental or intentional?
What is newsworthy is how reckless both OpenAI and Anthropic were with these ‘dual-use’ hacking agents. The claim of defensive purpose is misleading. Both incidents were in fact cases of AI hacking agents hacking other computer systems. This hacking can be done offensively, as was carried out by the OpenAI and Anthropic hacking agents, or defensively to find system vulnerabilities. The irony is that without the AI hacking agents, the vulnerabilities discovered wouldn’t necessarily be vulnerabilities.
What is missing from these explanations is understanding of brute force computing. Brute force computing iterates within defined parameters through every available pathway until a solution is found— if one exists. This is the process that people— including AI executives, are confusing with intelligence. An analogy would be my washing machine going through a series of sub-cycles. The washing machine isn’t thinking about what to do next in doing so. It is following a set of mechanical instructions.
This follows broadly the shift in the Western sciences from deterministic to probabilistic modeling in the late nineteenth century. While probability adds nuance to otherwise binary outcomes (something works / doesn’t work), that hardly makes it ‘intelligent.’ Mechanical instructions (embedded in hardware) work fine for a washing machine. Adding digital systems to it might improve functionality minimally while increasing the probability of the machine breaking. From my own experience, I would pay extra not to have digital systems installed when mechanical systems will suffice.
What makes brute force computing a different animal from what preceded it is volume and capacity. Think of computer chess where a computer can run through every possible future move and its probability of success while a human player has a library of strategies to recall. These strategies represent a subset of all of the possible future moves, giving the computer the advantage. This isn’t because the computer is smarter than a human player. It is because the computer is using a different method of playing the game.
Question: isn’t finding a better way to complete a task a sign of intelligence? The choice of what is ‘better’ is a value judgment. Better at what? In what way? Chess is a game played between humans. It is a shared experience. The idea that the purpose of chess is to find the most efficient solution to the game is a redefinition of this purpose. In that case, chess is no longer a game. It is a test of who has the best algorithms and the most computing power behind them.
What Dario Amodei (Anthropic) likely means by stating that some AIs might be ‘too powerful’ is the explanation that I provided above. The knowledge needed to code effective restrictions on AI hack bots requires knowledge that the coders do not possess until a hack has been achieved. Fixing this would seem to require a time machine. But there is no time machine. What caused the bizarre behavior (in human terms) once the AI hacking agents broke out of their test environments? Simple answer: the math.
Many of the restrictions placed on AI agents are procedural, to prevent unpredictable interactions with other aspects of AI that create loops and hallucinations. These are the restrictions that were removed in both the OpenAI and Anthropic generated hacks. In the absence of coded restrictions, these interactions are 1) unpredictable but 2) mathematically bounded. They are unpredictable in the sense that they emerge from complex interactions that are largely hidden. And they are bounded in the sense the AI is beholden to its basis in math. What makes mathematical sense to an AI agent might not make intuitive sense to humans.
Consider, the OpenAI hack bots didn’t know what escape hatch they would find out of their test environment until they found it. They used brute force computing and found a previously unknown way out. But doing so is the job of hack bots. It is what they were created to do. Further, any advantage from Agentic AI will last only until a hack bot equilibrium is established. The idea of a permanent advantage goes against history.
Much is being made of the idea that the hacking agents ‘cheated.’ Those making the claim have never solved an optimization problem. Unless the acceptable pathways are explicitly defined, the model just follows the math. The AI hacking bots deployed in both cases had limited restrictive coding, meaning that they followed the most mathematically efficient method of completing a task within the given parameters. The claim of cheating represents a category error in this case. The anthropomorphizing language is not constructive.
From mythology, the myth of the Genie is a good analogy. In the myth, a Genie is a magical being that grants wishes. But through literal interpretations of the wishes made, the wishes granted take away more than they give. In an (un-original) example, if someone wishes that they were rich, someone dear to them might die with a life insurance policy that names them as beneficiary to make them rich. The wish will be granted. But at an unanticipated cost. No matter how tightly AI coders code agent restrictions, the results will be other than imagined.
The broader public explanations of these incidents that I have heard — that AGI (artificial general intelligence) has been achieved and that the singularity has been reached, are so implausible that I am at a loss. Could someone please describe the process by which algorithms become something more than algorithms in terms of known physics? And if AI has transcended its physical limitations to become something else entirely, what happens if I just pull the plug? Surely if AI can achieve consciousness, it can function without electricity. Please people, find better mind-altering drugs if that is what is inspiring this nonsense.
The problem from the OpenAI and Anthropic hacks is that the AI engineers don’t know what they don’t know. Through brute force computing, the AI hack bots can find a solution if there is one. But the engineers cannot predict what it will be else they would send the AI hack bots right to it or write restrictions against exploiting it. This is what makes Agentic AI so dangerous. That Donald Trump doesn’t understand the problem but knows that restrictions on AI are bad makes him a fool.
Last, it is important to keep in mind that the AI Agents did what they were conceived and built to do. They weren’t sitting around having cocktails and discussing the state of the world. Why not? Because they are AI hack bots, not people. And this particular problem likely isn’t solvable. I went through the available solutions and they are band-aids, not solutions. So, when Dario Amodei speaks of ‘slowing down’ Agentic AI development, the AI industry needs a solution. As of today, it doesn’t have one.
The Great Bond Market Panic of 2026 / Fed Move +25bps
I have every confidence that between Donald Trump, Scott Bessent and Kevin Warsh, a bond market crisis can be created. And this may be the start of such a crisis. But get a grip, people.
The 10-Year US Treasury yield has been within a few basis points (hundredths of a percentage point) of the current yield three other times within the last three years. Volatility measures (graph below this one) place recent 10-Year Treasury yield movements towards their lowest level of volatility in modern history.

Source: CNBC.

Graph: yield volatility (see far right of graph) is close to the lowest in modern history. Source: St. Louis Federal Reserve.
The Federal Reserve’s decision to raise the Fed Funds rate 25bps is a bold move politically two months before midterm elections. This isn’t to support the policy. It is to suggest that with the everything bubble in full bubble form, the last dozen years of reckless policy decisions created a mess of financial asset prices that makes raising rates in the present not unlike lighting a bonfire in a fireworks factory. Luckily for (Kevin) Warsh and Donald Trump, Fed policy typically has a lead time from rate changes to market impact of 12 – 18 months.
What I heard of Warsh’s comments regarding the move centered on the productive economy, suggesting that Warsh learned little from the GFC and Great Recession. Stated differently, context matters. The everything bubble is built on leverage that won’t become visible until a crisis is underway. Interest rates represent the price of financial leverage. Raising interest rates raises the price of financial leverage. Once a few highly leveraged players go under, a market contagion begins.
This wouldn’t be as large a risk were the valuation levels of stock markets and housing not so stretched. But as it stands, both markets are above or at their highest levels ever recorded. And Warsh’s nod toward the productive economy would be welcomed were it not for this financially leveraged backdrop. I would disagree with the decision to raise rates were that the case. With energy prices in particular, rising prices are inflationary by definition until they are deflationary in fact via demand destruction.
Warsh is facing the most complicated macroeconomic environment in recent history. The next decade will more likely than not be about choosing the least bad options for the US. And if Trump loses the midterms, he will still have two more years to make his displeasure with Warsh’s rate decision known. On the one hand, I give Warsh credit for fighting the political headwinds. On the other, I don’t see how deflation isn’t the problem that will be harder to solve once the current inflation has waned. I wouldn’t be raising interest rates in this environment.
Oil and gas supply constraints won’t be solved by rising rates, and this will be the driver of inflation. And deflation.


















