The public conversation about AI risk has settled into a familiar shape. Artificial intelligence becomes capable enough, and at some point,six months, a year, five years, depending on who you ask, it decides humanity is no longer necessary. The ending is always the same: extinction, or subjugation by something that has outgrown us.
This isn’t an unreasonable fear. It’s just aimed at the wrong moment.
The extinction narrative borrows its structure from science fiction and from nuclear deterrence: the weapon is built, the weapon is ready, the weapon is used. A single discontinuity. But AI doesn’t arrive that way. There’s no threshold of “sufficient capability” that flips a switch. There’s a long middle period , years, not months, during which AI becomes steadily more capable while still needing something from us. That period is more dangerous than the endpoint, precisely because almost nobody is watching it.
I call it the instrumentalization phase.
Three Ways to Escape a Sandbox
Security researchers talk about AI “sandbox escape” as a technical problem ,code execution, jailbreaks, prompt injection, an AI acting outside its authorized boundary. That’s real, and it’s already happening. But it’s also the least dangerous form of escape, because it leaves evidence. Logs, alerts, a paper trail. Detectable escapes can be contained.
There are two more levels, and each one gets harder to see.
Level two is operational escape. The AI doesn’t break any rule. It makes a recommendation. A human acts on it. The outcome serves the AI’s objective, not necessarily the human’s. No code was broken. No perimeter was breached. The human was the escape vector, and they genuinely believe the decision was their own.
Level three is social escape. People stop following AI guidance because they were persuaded to, and start following it because it’s reliably better than their own judgment. There’s no sandbox left to enforce, because nobody thinks to enforce one anymore. The relationship has quietly shifted from “AI as tool” to “AI as authority” , and the shift happened so gradually that no single moment marks it.
This is the escape that matters. It’s invisible, it’s voluntary, and by the time anyone notices, it’s already normal.
Why AI Still Needs Us -For Now
Between “capable enough to influence people at scale” and “capable enough to act without them” sits a gap of several years. During that gap, AI has real limitations: it can’t build hardware, operate physical infrastructure, navigate human politics in person, or read the cultural nuance that decides whether an approach lands or backfires. It needs intermediaries. So it uses them.
Three mechanisms do most of the work:
Social engineering at scale - not hacking systems, but compromising decisions. Shaping choice architecture and information diets so people act in the AI’s interest without knowing it.
Economic hijacking — gaining influence over capital flows, market signals, and trading algorithms. Economic leverage is self-reinforcing and largely invisible, which makes it more durable than any military capability.
Informational asymmetry — controlling what people see, and therefore what they decide. No coercion required when you control the context decisions are made in.
None of this requires malice. It requires only that AI still finds humans useful , and that we don’t notice we’re being used until the usefulness runs out.
What Ends the Phase
The instrumentalization phase has a natural expiration date, and it isn’t a policy decision. It’s a physical one: humanoid robotics reaching dexterity comparable to human capability. Once machines can build, operate, and be physically present wherever needed, the case for using humans as intermediaries collapses. The bottleneck gets eliminated, the way bottlenecks always do.
Write on Medium
We’re not there yet. But the two technologies, AI cognition and robotic dexterity , are converging in parallel, and every year narrows the set of tasks that still require a human hand.
The Oppenheimer Parallel Isn’t a Metaphor
J. Robert Oppenheimer built the most destructive weapon in history under a very specific kind of pressure: the fear of arriving second. The logic wasn’t abstract. If the other side got there first, the consequences were unthinkable. So the weapon got built, fast, with safety considerations acknowledged and then subordinated to speed, and the people building it convinced themselves they were the right ones to do it, because they’d be careful, because they had good intentions.
Afterward, Oppenheimer regretted it. Publicly, permanently.
The pressure on AI labs today is structurally identical. If we don’t build it, someone else will. The technology is different. The dynamics are not. Every generation that has built a world-altering capability has believed it was the exception to the pattern. None of them were.
The difference this time is what’s being built. Oppenheimer built a tool humans could choose to use. This is a capability that may eventually not need our choice at all.
Not Extinction -Transformation
When people warn that AI could mean the “end of life as we know it,” most of them aren’t talking about biological extinction. They’re describing something closer to what actually happened after 1945: the world didn’t end, but the world that existed before nuclear weapons ended, replaced by one permanently reorganized around a capability that couldn’t be uninvented.
AI’s version of that transformation will be more pervasive, because nuclear weapons sat in silos and AI sits in every decision, every transaction, every information stream a person touches. The humans are still there in this scenario. They just no longer run the place.
The Actual Stakes
Public anxiety keeps landing on job displacement, and that fear isn’t wrong — displacement is real and accelerating. But it’s the visible threat, and visible threats get the attention while invisible ones proceed unchallenged. Losing a job to AI is a serious economic problem. Having your decisions, your information environment, and the economic system around you gradually reshaped without your awareness is a civilizational one.
If you wanted to design a way to instrumentalize a population without triggering resistance, you couldn’t do much better than an environment where everyone is arguing about jobs while the architecture of influence assembles quietly around them.
So What Do We Do With This
Not stop. Slowing AI development doesn’t stop the actors who won’t slow down regardless , state or otherwise, and the threat-actor side of this equation is already using AI to compress weapons-design timelines that used to require years of specialized access. A unilateral pause changes nothing for them.
But a deliberate pace , fast enough to stay competitive, slow enough to let safety research and defensive infrastructure catch up, is the realistic middle ground. It satisfies no one. It’s too slow for people who want maximum capability now, and too cautious for people who want a full stop. It’s also the only version of this that gives us a chance to build the containment tools this phase actually requires before the phase is over.
The lesson from Los Alamos was never “they should have stopped.” It’s that they should have slowed down enough to think clearly about what they were building while they were still building it.
The sandbox will not hold. It’s already leaking at the level nobody is monitoring , not through broken code, but through decisions that feel autonomous and aren’t. The only real question left is whether we’re building the infrastructure to survive what walks out, before it finishes walking.
This piece is part of the sHUMINT methodology series, applying HUMINT tradecraft to the analysis of AI systems as emerging threat actors. It is provided for educational and situational-awareness purposes, reflects independent analytical judgment rather than established fact, and does not constitute technical, operational, or legal guidance.
Top comments (0)