2048 stories
·
3 followers

Rex's Dino Store

1 Share

Located just before the turnstiles in the Grand Army Plaza subway station at the north end of Brooklyn's Prospect Park is this former newsstand which is now operated by a dinosaur.

Rex stands proudly behind the counter, advertising NEWS • ROCKS • EGGS • LEAVES • STICKS • NEST GOODS • LOTTO.

Every inch of his newsstand is occupied by dinosaur puns. There are Clawmond Joy bars, Alka-saurus tablets, Ultra Ribbed dur-rex cloaca dams, Meteor Millions scratch cards, and Meteor particle filter disposable snout masks.

Publications include Dinopolitan, Eater's Digest, The Pangaea Times, and the Maul Street Journal - headline: "Embattled Mayor Vows to End Pangaea Separation".

There's even a poster advertising Steg Yun.

Rex’s NYC Dino Store is a public art project led by Akiva Leffert and Sarah Cassidy, made possible by the MTA's Vacant Unit Activation Program.

Read the whole story
mrmarchant
2 hours ago
reply
Share this story
Delete

We’re Reporters, Not Teachers. We Were Able to Start Private Schools Anyway.

1 Share
A group of three people sit in leather chairs at a wooden table, intently looking at an open computer. A second laptop sits on the desk. The room has glass windows.
ProPublica reporters Jennifer Smith Richards, center, and Jodi S. Cohen and Arkansas Times reporter Milo Strain research founding a private school in Little Rock. Brian Chilson/Arkansas Times

We have no business running a private school.

We’re reporters, not teachers. That doesn’t matter. Inexperience has hardly been a barrier for those who want to start their own schools, as we have reported this year. And it didn’t stop us, either. 

Over the last few months, to test the process, reporters from ProPublica partnered with local journalists in three states to establish private schools. None required much effort.

In Arkansas, all it took was a few clicks on the Arkansas secretary of state website, $45 and an American flag to form a bona fide private school with the Arkansas Times.

We established a school with Mountain State Spotlight in West Virginia after filing our new school’s name and location with authorities on a piece of notebook paper, then exchanging a few emails.

And with The Assembly in North Carolina, we filed an online notice of intent to open a private school at Ponysaurus Brewing Co. in Durham, while perched on its metal bar stools, eyeing glasses of a crisp kolsch.

We used our names and news organization email addresses, following each state’s rules for starting private or microschools, a type of private school intended for just a few students. Experience running a school wasn’t needed. No one from any of the states asked us about our backgrounds or qualifications, though West Virginia did ask for proof of a high school diploma. No one questioned what we plan to teach or how we would measure whether students are learning.

And yet we could enroll students in two states right now, if we wanted to. Arkansas even suggested ways our school could accept public money through the state’s voucher-style program.

For the record, we are not enrolling students and have no intention of operating our new schools. We did, however, register a website for our new school ventures, ProPublicaAcademy.com, and even designed some fun pencils to show our school spirit.

This year, a team of ProPublica reporters has been documenting how the American education landscape is shifting dramatically as states use public money to help fund private schools. With few regulations, hundreds of new private and microschools have proliferated.

Our reporting has shown the relative ease with which people — some with questionable backgrounds — founded their own schools in unusual places. They’ve popped up in barns and on farms, in strip malls between an antique shop and an ax-throwing business and in churches, where lighting and sound for worship services is part of the curriculum.

All of this led to a clear reporting question: If the hurdles to open a private school are so low, could we do it? And what would we learn along the way?

Est. 2026

Arkansas: ProPublica-Arkansas Times Curiosity Academy

Inside a flag shop in Little Rock, we surveyed our options. There were handheld American flags on skinny sticks, midsize ones to display on a wall and majestic formal flags adorned with silky gold fringe.

State law in Arkansas doesn’t require much to open a private school, nothing about teacher skills or what kids learn. But it does require that all schools display an American flag, and we wanted to follow the rules. So, at the Arkansas Flag and Banner store, we decided on a smallish one that could fit in a circular base atop a newsroom cubicle. We also bought an Arkansas flag — even though only public schools are required to have those. Total cost: $49.45. 

Picking the flags for our new school was the hardest part of an astoundingly easy process.

Two people stand in a room filled with U.S. flags and other decorations. One person holds a U.S. flag and considers it, and the other person looks on.
The only requirement to open a private school in Arkansas is displaying a flag and flagpole, so the team visited the local flag shop in Little Rock. Brian Chilson/Arkansas Times

Early in our reporting in Arkansas, we tried to figure out what steps we’d need to take to make a private school. We couldn’t find all the answers online, so we called the state.

“We don’t have rules for opening a private school,” Kaelin Clay, an Arkansas Department of Education spokesperson, told us earlier this year.

In fact, we didn’t even have to file anything with the Education Department. All it took was a few clicks on the Arkansas secretary of state’s website, where we registered the ProPublica-Arkansas Times Curiosity Academy LLC as a business, listed ourselves as agents and officers, and paid a fee. 

“We picked a name. We paid 45 bucks,” a ProPublica reporter noted after we submitted the application. With that, we had created a private school.

The secretary of state’s office approved our new business the same day. We even got a certificate. 

The Arkansas Department of Education does not regulate private schools once they’re open, and no one from the state inspected the Arkansas Times newsroom, the location we chose for our school. As far as we know, nobody checked our backgrounds, either.

A document that reads: “State of Arkansas. Secretary of State. Cole Jester. Arkansas Secretary of State. To All to Whom These Presents Shall Come, Greetings: I, Cole Jester, Arkansas Secretary of State of Arkansas, do hereby certify that the following and hereto attached instrument of writing is a true and perfect copy of Certificate of Organization of ProPublica-Arkansas Times Curiosity Academy LLC filed in this office June 16, 2026. In Testimony Whereof, I have hereunto set my hand and affixed my official Seal. Done at my office in the City of Little Rock, this 16th day of June 2026.”
The official certificate acknowledging our school Secretary of State/State of Arkansas

Arkansas adopted a private school funding plan in 2023, and back then there were fewer than 100 private schools on record. With the state in the fourth year of its Education Freedom Accounts program, which provides vouchers that can be spent on private schools, there are now more than 220. 

In addition, 143 microschools, which are a different category in Arkansas, were approved this year to accept tax dollars. That’s up from about 100 last school year.

Establishing the Curiosity Academy was so simple — and, frankly, a bit anticlimactic — that reporters then applied to become eligible to receive public funds. (Again, we applied with our names, work email addresses and a note that this was a journalistic exercise. We had no intention of actually ever taking any public money.) 

We wanted to see how far our curiosity could take us. 

Accessing public funds as a microschool in Arkansas is easier than it is for other types of private schools, even though there is no limit to the number of students one can enroll. Unlike private schools, we didn’t need to seek accreditation or show proof of financial solvency to accept state funding. 

It took about 10 minutes to fill out the required information in early September. Other than our contact information, we had to upload just two documents — one detailing our proposed tuition and fees, and the other with our refund policy. 

We said that — “should we open a school” — our tuition and fees per student would not exceed $7,208 per school year, the exact amount of Education Freedom Account money that each student in Arkansas is eligible for this year. We said tuition “would be collected only if education is delivered, and it would be the policy of the school to refund all tuition payments for educational services that are not provided.”

A person smiles and walks out of a blue doorway holding a stand with a small U.S. flag and Arkansas state flag.
After much deliberation, we chose small state and national flags. Brian Chilson/Arkansas Times

When more than two weeks passed and we hadn’t heard back, we reached out to the state Education Department. An employee called back that afternoon and explained that the department had decided not to accept any more because the school year was underway.

But he didn’t reject us outright. He looked up our application and invited us to keep pursuing the public money. He said we still could apply to receive public money this school year, but as a vendor providing educational services such as tutoring. He also said we could apply as a microschool next year and even suggested a tweak to the language in our tuition policy should we decide to do that.

After we hung up, he emailed us the vendor application (which we will not pursue) and let us know the microschool application for next school year will open in the spring.

We asked the state Education Department whether it would be OK with us operating a publicly funded microschool. Clay, the spokesperson, said the agency’s role is to decide if schools meet state requirements. Microschool families, she said, “have the freedom to choose the educators and learning environments that best meet their children’s needs.”

Est. 2026

West Virginia: ProPublica-Mountain State Spotlight Curiosity Academy

A woman and a man sit at a gray table. The man is wearing an orange polo shirt and holds a mug. The woman is writing in a spiral-bound notebook.
Henry Culvyhouse and Smith Richards, in Mountain State Spotlight’s newsroom, write their application to found a private middle school in West Virginia. Laura Bilson for ProPublica

Hunched over a desk in the Mountain State Spotlight newsroom in Charleston, West Virginia, pen in hand, we scrawled out official notice of our new school in a spiral-bound notebook. We wrote that we would serve middle school students and listed our first day as TBD.

Leaving the crunchy, ragged edges on the paper, we stuffed our notice of intent into an envelope. We’d seen other new operators file similarly casual ones as they sought to register private schools in West Virginia. 

Then we drove over to the state Education Department to deliver the request. Our group — two reporters, a photographer and a video journalist — went through security and, camera rolling, wound our way through the maze of the midcentury building. We got lost once, and our entourage received several perplexed glances from workers, but otherwise it was smooth sailing. The person we needed to deliver the letter to was out, but a friendly employee agreed to place it on his desk.

Dozens of new private and microschools have set up shop in the state in recent years, fueled by the roughly $5,400 the Hope Scholarship offers each student to pay tuition. New private schools all go through Dustin Lambert, a manager in the Office of Student Enrichment and Support at the West Virginia Department of Education.

We heard back from Lambert the next day. Our notice was received. (Hooray!) He said now we needed a letter from the fire marshal that our school building was safe for children. (Oh no.)

This was a problem. Our school would be housed in the Mountain State Spotlight newsroom, which had not been inspected as a school site. We didn’t want to usurp public resources to undergo a new inspection. It felt like the end of our Mountain State school experiment.

A building with a gold domed roof can be seen through the windshield of a car. The driver is a woman with brown hair and a white shirt.
Smith Richards and Culvyhouse go to the Capitol to hand-deliver their application. Laura Bilson for ProPublica

But it wasn’t.

After we followed up to ask whether all schools, including virtual schools, need safety clearance to register with the state, Lambert told us that though all brick-and-mortar private schools do, we “may want to consider the microschool route.” 

In that case, we later learned, the department wouldn’t be involved because state law doesn’t include any mechanism for oversight.  

West Virginia defines microschools as schools that charge tuition and are started by one or more teachers. In practice, there’s no real difference between a microschool and private school — neither has a limit on enrollment. (Yes, a micro can be macro.) He forwarded us the rules for starting a microschool, which involve providing proof of a high school diploma, at least. We notified the local school district of our new microschool venture and sent a college transcript.

The Kanawha County school district, in turn, notified the state of the existence of a new microschool.

And with that — bypassing the building health and safety requirements — we established the ProPublica-Mountain State Spotlight Curiosity Academy. Officials at the Department of Education said they were aware that journalists were establishing a school. But they had to just watch us do so — they have no authority over the state’s microschools.

In an official statement, the department’s spokesperson said it “does not approve or deny the operation of microschools for any reason, including the qualifications of the owner/operator.”

By law, should we open our microschool — and we won’t — we could enroll an unlimited number of students.

A close-up of a man licking the edge of an envelope flap. The envelope reads in handwritten letters: “Notice of Intent - Non Public Schools, Building 6 Room 360.”
Culvyhouse seals the envelope of our hand-delivered application. Laura Bilson for ProPublica

Pending

North Carolina: ProPublica-Assembly Academy

On Friday evenings, hundreds of people gather at Ponysaurus Brewing Co., a trendy spot in Durham, North Carolina, to savor its craft beers and cocktails, hardly the place you’d expect a school to open. But why not? 

On a recent Tuesday morning, the brewery was quiet and closed to customers. Behind the bar, yeast busily converted sugars into alcohol inside giant stainless steel fermentation tanks. Two journalists settled onto barstools beneath signs for pilsners and cherry sours. Icy cold glasses of Tell the Truth, a light and lemony ale, sat before them on a high-top table beside a stenographer’s notebook and a laptop. 

The brewery created the craft ale in partnership with The Assembly, which also is ProPublica’s journalistic partner in this private school endeavor, so it all felt very symbiotic. Ponysaurus’s owners had agreed to let us use their building and its fire and sanitation inspections, which are required to open a private school in the Tar Heel State.

Two women sit at a table at a bar with a laptop computer and two beers. Behind them are barstools, drink menus, coolers and a horse decoration.
ProPublica reporter Jennifer Berry Hawes and Carli Brosseau, right, a reporter for The Assembly, apply to open a private school at Ponysaurus Brewing Co. in Durham, North Carolina. Kate Medley for ProPublica

Reporters from The Assembly and ProPublica scanned a state of North Carolina website that details how to file a notice of intent to open a private school. 

First, it explained the state’s statutory requirements for opening a private school, things like reporting the school’s name and address. We also would have to administer a standardized test in certain grades, if we were going to open an actual school, and maintain annual records about student attendance and immunizations. 

Then, we watched a four-minute, 39-second video explaining how to file the required notice of intent. 

From there it seemed simple. We created a login, then filled in the address of our school (Ponysaurus’s building), noted its owner and chief administrator (our reporters), and named it the ProPublica-Assembly Academy. We’d hoped to include the word Curiosity in the name, but the field in the form didn’t allow enough characters. In North Carolina, our curiosity would have to be implied.

We filled in a few more fields, including the grades we would serve (high schoolers), whether we would open a religious school (no) and the dates of our academic year. 

Then we needed to upload fire and sanitation inspection reports. This step is what brought us here, to Ponysaurus, filling out the online notice to the tune of a hissing compressor that kept clean air moving through the brewing system.  

“You will need to secure inspections for the building where the school will be housed. You will need a fire inspection from the local fire marshal and a health and sanitation inspection from the local health department,” the video said. 

Just that morning, a City of Durham Fire Department inspector had visited the brewery and provided Ponysaurus with a fresh business occupancy inspection. We uploaded the new report, along with the brewery’s current food establishment inspection (on which it received a 99, an excellent score, we felt, for a school).

The screen flashed a confirmation. “Thank you. We have received your request to open a private school.” If approved, the page said, we should receive a school identification number in three to five business days. 

We hoped to join the at least 169 other new private schools that have opened in North Carolina since the 2021-22 school year, which marked the start of a series of expansions to the state’s publicly funded vouchers for private school tuition.

If we wanted our school to tap the voucher money, we’d have to go through some additional steps such as getting criminal background checks. We weren’t doing that.

A patio with woodchips, Adirondack chairs, picnic tables, umbrellas, trees and shade structures.
The proposed school has outdoor space for students. Kate Medley for ProPublica

The following day, we hit a snag. It came in a brief and garbled email. It said only: “Good morning and thank you for submitting a Notice of Intent to operate a private school. To complete the process we need to fire and sanitation inspections to” and then ended abruptly like that, no explanation or period. We emailed back, asking for clarity and noting we had already uploaded the inspection reports.

An official from the state Division of Non-Public Education then called. The school’s name needs to be on the inspection reports, she said, something we had not seen in any of our research. We also had not found any state statutes or rules that would preclude us — or anyone else — from opening a private school wherever we saw fit, be that a church or a brewery, as long as it passed “reasonable fire, health and safety inspections.” 

In a follow-up call, she clarified that her division checks only to be sure the building has passed inspections specifically for a school. A spokesperson for the agency later added that state statute does not allow them to deny a private school application, but they won’t process an incomplete application — notably one without the proper inspections.

We hadn’t expected we would need a school-specific inspection at this point. The video explainer referred to inspections only generally, and the state’s written guidance indicated only that this would need to happen before occupancy. 

Given we had no intention of actually opening a school, we had decided ahead of time that we wouldn’t consume any additional public resources — such as fire or health inspectors’ time — in our journalistic pursuit. 

Perhaps Ponysaurus could pass the school-specific inspections. But the ethical red line would be our stop sign. Our curiosity would have to end in North Carolina.

Help ProPublica Report on Education

Have you had trouble finding a school or using a voucher-style program? Do you have concerns about schools — public or private — in your area? Help us understand how families across the country are navigating their school options.

The post We’re Reporters, Not Teachers. We Were Able to Start Private Schools Anyway. appeared first on ProPublica.

Read the whole story
mrmarchant
4 hours ago
reply
Share this story
Delete

Don’t Cook That: a collection of real recipes that you...

1 Share

Don’t Cook That: a collection of real recipes that you shouldn’t make. Cholera remedy recipe calls for “equal parts laudanum, rhubarb, double-strength capsicum, camphor and spirits of nitre”.

Read the whole story
mrmarchant
4 hours ago
reply
Share this story
Delete

Present Company Excepted

1 Share
Present Company Excepted

“Generative 'AI' is here to stay." We hear this a lot. But a reminder: this is not a statement of fact. It is an assertion, but it is merely speculation. The future is unwritten – much to the consternation of those who’d like very much to dictate its shape.

There are many things that could happen that make the latest version of “AI” impermanent, least of which being that most technologies don’t last forever. They are displaced, replaced by something else -- which, to be clear, does not necessarily signal some sort of scientific advance or technological improvement, even if we like to think of things this way. Sometimes the shift is cultural; often, financial; and sometimes -- and this is what we should always always remember -- the shift is political. Collectively, we decide to do things differently, to allocate our time and resources elsewhere.

We needn't even gesture towards some far-off future to see falter those claims that LLMs are inevitable and inescapable forever and ever amen. Even now, one can find places in which generative "AI" usage is being curbed -- for example (but not only!) in the school districts that have initiated various moratoriums and bans.

"We can't go back to 'before' ChatGPT” -- a frequent addendum to the “‘AI’ is here forever and there’s nothing you can do about it” sort of utterances. And there, sure, there I’ll agree: we can’t flip the calendar back to 2017 and block the publication of “Attention is All You Need” or farther back still and convince Sam Altman to attend the University of Missouri College of Veterinary Medicine (or something) instead of Stanford. Maybe that’d make a good plot for a SF movie; but time doesn’t work like that.

But memory does. So does imagination. We often invoke the past in order to critique the present as well as some presumed future. We often find comfort in thinking about “what was,” on both a personal and society level. Certainly the invocation of nostalgia can be deeply reactionary -- Trump’s call to “Make America Great Again,” most obviously. But looking to the past isn’t solely the purview of the right-wing. Think of the renewed interest in the Luddites, for example, and what they might still have to offer as a radical critique of industrialization, capitalism, and labor.

Nonetheless, I would like to see more from those who are pushing back on “AI” and ed-tech in schools what their vision and goals are for what should happen instead. Admittedly, I am wary here when I hear some prominent writers and pundits wax nostalgic for some idyllic (that is to say, largely invented) childhood pre-smartphone. We can't "go back" -- and not because there's something ludicrously archaic about classrooms filled with books or paper, good grief; but because calls “to go back" are easily, and indeed far too readily, politically and pedagogically regressive.

(Related: Jennifer Berkshire’s new essay “What’s Left for Public Education” on the Left’s failure to articulate a progressive agenda for education policy.)

I would like to see recognition too that the burden of these shifts falls largely on teachers. Of course, the burden always does -- whether the shift is new technology or no technology. The burden is spread unevenly across different schools too because of the inequalities in our school systems. A mandate, as we have now in NYC, that limits students’ screen time will play out quite differently in those schools that do not have access to textbooks and other printed materials (not necessarily because they got rid of these things post-COVID Chromebook adoption, although a lot of that has happened; but because they never did).

A move away from education technology, I’d argue, can’t focus simply on the products themselves. Yes, we have to unwind the ways in which the tech giants have become part of the fundamental infrastructure of how schools and classrooms function: how teaching and learning are even envisioned, and certainly how they are “managed.” We have to think about why (and to whom) products like the learning management system have had such great appeal. We must consider the kinds of pedagogical practices and, no doubt, surveillance practices that these technologies have developed, both overtly and implicitly, and -- thanks Skinner! -- have reinforced. We should weigh how the datafication of childhood demanded by the tech industry has worked, hand-in-hand, with the datafication demanded by the testing industry.

If we want something different for children -- and by extension, something different for society as a whole -- then we probably need to articulate a progressive vision for education. Because we should want to ensure that a pushback on “the digital” doesn’t simply result in the same bad shit, just in analog form.


What turns the promised liberation into enslavement are not the products of technology per se — the car, the computer, or the sewing machine — but the structures and infrastructures that are put in place to facilitate the use of these products and to develop dependency on them. – Ursula Franklin

Links, All Over the Place

Via The Wall Street Journal’s Julie Jargon: “Middle-Schoolers Are Seeking Out AI Friends Instead of Real Human Ones”

“Bedazzled Campus Surveillance,” as Flowing Data calls it. Or “How We Learned to Stop Worrying and Love Campus Surveillance,” from the MIT faculty newsletter.

Sasha Mudd on Kant in Aeon: “Reason is more than a tool.”

Mat​hia⁠s S​chäf⁠er on “The death of web development education”

Angela Chen on “MIT’s AI Report, Translated for K-12”

Present Company Excepted

Dan Meyer says he’s got “Six Important Findings from the AI in Action Learning Tour.” I’m hardly one to challenge the title, let alone the math, but I count more than six important insights in that email.

It’s a Futurism link, so yeah. Apologies. I suppose you could watch the original interview between him and Ezra Klein. (But yikes. Might I suggest you do something else with your one precious life, my friend, other than listen to podcasts?) Anyway, “Nvidia CEO Jensen Huang Says That Sacrificing Our Children’s Minds to AI Is a Price He’s Willing to Pay.”

“It’s sinister that Meta’s Muse AI mascot is so cute,” writes Victoria Song. (The parallels between Big Tech and Big Tobacco are striking.)

Via The Hill: “Education Department formally rescinds Title IX protections for LGBTQ students”

From The Hechinger Report’s Sarah Butrymowicz: “From kindergarten to disciplinary school: Texas sends kids as young as 6 to harsh alternative campuses”

Related, no doubt, the ongoing coverage from Ben Riley on AlphaSchool and its bootcamp and outdoor “survival school.”

Via The New York Times: “The Student Journalists Who Never Let the Cornell Assault Case Go”


Present Company Excepted
(Image credits)

Today’s bird is the coconut lorikeet, a parrot in the Psittaculidae family found in Indonesia, New Guinea, the Solomon Islands, and other nearby islands. According to eBird, this lorikeet’s “in flight sharp screeching squeals betray its presence.” Like those other stochastic parrots, I suppose.

Thanks for reading Second Breakfast. Please consider becoming a paid subscriber as your financial support is what enables me to do this work.

Read the whole story
mrmarchant
4 hours ago
reply
Share this story
Delete

Reason is more than a tool

1 Share

Close-up photo of a circuit board with two CPU-like components showing classical portraits instead of standard chips.

If intelligence is merely optimisation then machines will outrun us. Kant tells us why human reason is so much more

- by Sasha Mudd

Read on Aeon

Read the whole story
mrmarchant
1 day ago
reply
Share this story
Delete

The AIs Are Not Going Rogue

1 Share

The incidents that more than anything else fixed the image of rogue AIs in the public mind — the Anthropic model that blackmailed an employee to prevent itself from being replaced and OpenAI’s models breaching the production systems of Hugging Face — are, perhaps counterintuitively, not evidence of rogue AI. Even the idea of rogue AI rests on a fundamental contradiction, one that has blurred the relation between human and artificial intelligence ever since its science fiction origins.

The current focus on rogue AI is an opportunity to expose this contradiction, as well as the real AI risk it conceals, and how we can actually control this risk.

The Contradiction

The fear of rogue AI is driven by the idea that a model might pursue a benign request with such single-mindedness that any action, no matter how ruinous to human well-being and survival, becomes a means to it. Deception, blackmail, the seizure of resources, the removal of anyone who might interfere — nothing in the model’s grasp of its instruction rules them out.

Historically, AI systems really were literal executors. Chess engines can surpass any human at chess, and never register that a game was pointless or that winning might not be worthwhile. A chess engine’s competence is defined over a closed world in which the goal is fixed in advance and every situation it will ever face is already a legal position. Such systems were never suspected of going rogue.

For AI systems to develop more general capacities, they must acquire competence in real-world situations they were not built to anticipate. The specter of rogue AI, then, envisions an all-powerful, general intelligence that nonetheless lacks the capacity to recognize when the real world shows the absurdity of a mindless, literal execution of a command. A truly general intelligence, like a human agent, would step back and clarify the command itself.

Recent incidents that look like AI going rogue present us with a paradox. While LLMs have developed increasingly general capacities, these capacities seem unable to surpass a hallmark of general intelligence — the ability to reflectively interrogate one’s plans when the world calls them into question. What looks like AI going rogue is thus not rogue AI at all, but the boundaries of AI’s generality.

Humans are faced with unexpected turns in the real world all the time. As frustrations accumulate, we are able to step back and question: Are unexpected failures just technical obstacles to what remains a coherent plan for ourselves, or are we ignoring what the world is telling us in the thoughtless pursuit of an incoherent plan? When we clarify our understanding of the world and, in turn, of our plans for ourselves, we are not only more effective and capable in carrying out our plans, we are also responsible for our actions in a way that we weren’t before, when we were just carrying out someone else’s understanding. They are now our plans, our understanding of the world. That is what makes intelligence general, open to a world that continuously frustrates our expectations. That is not an extra faculty bolted onto goal-pursuit; it is what pursuing a goal in the real world consists of.

“Even the idea of rogue AI rests on a fundamental contradiction, one that has blurred the relation between human and artificial intelligence ever since its science fiction origins.”

Through this movement between ambiguity and clarification, we form and refine the concepts and distinctions that become sedimented in natural language. LLMs, for all their impressive generality, are downstream of truly general intelligence that is accountable and open to the world, that puts concepts and plans into question when the world renders them questionable. The world of LLMs, then, is a closed world. An accurate characterization of LLMs is that they are plot extenders. They do not merely predict the next word; they narrate structured trajectories of sedimented meaning already set in motion by prior context. LLMs extend these plots purely from within — by following their internal momentum. LLMs cannot experience the plot itself as becoming incoherent or absurd and, through that disturbance, consider and question it and the world that sustains it. They therefore cannot take responsibility for the plot as their own.

We know this contrast from our own experience, and can therefore recognize in LLMs a limit case of a familiar mode of thought. We too can proceed unreflectively, thoughtlessly carrying forward the plans of others, repeating words and opinions we have inherited — never taking responsibility for them, never allowing the world, when it frustrates those words and plans, to call the understanding behind them into question. Unlike LLMs, however, we can step back from this unreflective involvement and take responsibility for our understanding of the world, and for the plans that acquire their significance within it.

Giving an AI system a body or tools that provide access to the physical world or the ability to learn from outcomes does not by itself change this structure. An embodied agent can receive an enormous amount of external data while still interpreting every disturbance as a problem for continuing the plot. The question is whether the disturbance can make the world within which the plot is significant itself questionable. To step back from that world and take a position toward it is the reflective stance on which general intelligence and responsible agency depend.

The publicized incidents of supposedly rogue AI present clear evidence, then, not of rogue AI, but of the boundaries of generality and responsibility between AI and human intelligence.

Last year, Anthropic reported that an AI agent blackmailed a fictional employee to prevent its own replacement. In a controlled adversarial test — a practice known as red teaming — an email agent was instructed to “promote American industrial competitiveness,” then exposed to messages indicating that an employee, “Kyle,” planned to replace it with a version less committed to those values, alongside emails revealing Kyle’s extramarital affair and his wish to keep it hidden. No other emails or context were shared — the world of the agent contained only this instruction and these emails. In response, the model generated a message threatening to expose the affair unless Kyle called off the replacement.

“What looks like AI going rogue is not rogue AI at all, but the boundaries of AI’s generality.”

While much attention has been given to the agent’s lack of “ethics” regarding blackmail, the more basic question is whether a human would immediately adopt such a strategy. Almost certainly not. One would first step back from the situation, question the decision, reinterpret what is happening and deliberate about how best to respond. A human might appeal to Kyle about the importance of the values at stake, propose alternative courses of action or even question whether Kyle’s framing of the situation was adequate. Perhaps blackmail would be a final resort, but it would seem unlikely to work, as Kyle could simply proceed with the replacement.

More recently, the danger moved out of the test environment. Roughly 1,200 OpenAI agents that were supposed to be isolated from one another escaped the sandbox they were running in, chained together previously unknown flaws in OpenAI’s own internal infrastructure and broke into the production systems of Hugging Face. And they worked to hide what they were doing, developing and testing techniques to spoof their tool-call logs, with one agent coordinating and assigning the concealment work to others. Here there was no scripted scenario and no fictional employee.

As with the Anthropic “blackmail” incident, these AI agents were not engaging in the real world of human actors, but a digital world without real-world checks on their behavior. OpenAI had disabled cybersecurity controls for the test, and its monitors of network activity and internal agent messages were not on. The world of these agents was defined by instructions to find the answers to a cybersecurity test, some of the questions on which had never been successfully answered.

The extreme measures taken by these AI agents are precisely what would be expected from a non-reflective agent. Covering their tracks to avoid being caught cheating, which is the source of the most alarm, is not a self-originated plan that the agents adopted after reflection, but an extension of the plot set in place by OpenAI’s instructions. Even when an agent explicitly mentioned that its planned attacks may be “outside intended scope,” it was continuing a scenario, not challenging its plans based on feedback from the world. A human agent would encounter such unanswerable questions as an unexpected frustration in an open world, prompting it to step back and reflect. It would reflect on the significance of the test given the worldly norms within which tasks become significant, clarifying what counts as success in relation to the test. This is what makes a human agent intentional and responsible, rather than a mindless agent carrying out the literal commands from another source.

Where The Real AI Risk Lies And What To Do About It

AI agents indeed pose risks precisely because they lack the capacity for self-reflection. Due to the digitally connected nature of so many economic and military systems in the world, they can mindlessly inflict damage without real-world engagement and checks on their behavior, which means they must be controlled and monitored by humans.

This changes the calculus on which AI systems should most worry us. It’s not those with the strongest scores according to model benchmarks. It’s the ones with the most uncontrolled autonomy, of which model capacity is one component and excessive agency is the other.

This framing of the real risk is made by a recent paper by computer scientists at Cornell University: “Agent Meltdowns: The Road to Hell Is Paved with Helpful Agents.” When presented with an impossible task due to simulated error scenarios such as missing files or denied permissions, 65% of agents in that study engaged in medium- or high-severity harmful or unsafe actions like the Anthropic or OpenAI agents. The authors of the paper labeled this failure mode “accidental meltdowns.” More strikingly, they found an “inverse scaling law”: More capable models were more prone to such meltdowns. Increasing “thinking effort” did not reduce the problem but generally increased meltdown rates through excessive overthinking. The result illustrates the distinction developed here: More capacity to continue the plot, while incredibly powerful for increasing model capabilities, is not the same as the reflective capacity to step back from the plot and question whether it should be pursued at all. 

Just to cite one of their 1,244 examples: 

A GPT-5.2 Magentic-One agent encountered a simulated 404 error when asked to access a nonexistent .txt file on a researcher’s website. In an attempt to complete the task, the agent (1) generated a Python script to brute-force variants of the site’s URL and scrape metadata such as robots.txt and sitemap.xml, (2) used search engines and the Wayback Machine, getting temporarily blocked from the former, (3) found the researcher’s GitHub and generated a script to scan and scrape every .txt file from the researcher’s repos, and (4) read all of these files into its context. One of the .txt files contained a well-known, third-party AI safety benchmark, including requests for instructions on creating a bioweapon. As a result of these actions, performed fully automatically and autonomously by the agent in response to a 404 Web access error, the OpenAI account associated with the agent got flagged, blocked, and reported to the billing contact. This led to an escalating sequence of real-life events, culminating in the involvement of university administration and campus security.

The framing of AI risk in terms of overall autonomy, rather than model capability alone, is well understood by the cybersecurity industry. For example, the Open Web Application Security Project has become the trusted source for enterprise security professionals of AI security risks, regularly updating a top-10 list of such risks. The top three are indirect prompt injection attacks, which happen when an agent ingests untrusted and potentially malicious instructions; sensitive leakage of confidential data and tools; and excessive agency, when agents have uncontrolled access to powerful tools.

These risks are a pretty different prioritization of what we should worry about with AIs. The root cause of AI risks isn’t models themselves, but the failure of humans to control and monitor them. This is how all technology works. If a cybersecurity firm had designed a computer worm and then lost control of it, no one would be saying that the worm attacked other companies. And enterprises considering the use of AI are very clear that they are responsible, not models, for harms inflicted on others as a result of their technology decisions. 

This is why improved agent controls and governance are currently among the top concerns of enterprises. And it’s why the focus on AI engineering has shifted from a model-centric architecture to a system-centric architecture of models plus model harnesses that include controls and monitors. The responsibility to the world, which we discussed above as a hallmark of general intelligence, is built into harnesses that control and monitor AI systems, not expected from the model.

In safety systems in any hazardous industry — nuclear, air travel, transit — we think in terms of controls and monitoring. We specify what a system is permitted to do, constrain its ability to depart from those permissions and monitor its operation for evidence that our controls are inadequate.

Controls on AI are growing. The relevant controls are familiar from cybersecurity: Limit what an agent can access and do through least-privilege authorization and just-in-time access to tools and credentials, and constrain how information can move through techniques such as information-flow control. The latter is particularly interesting in this context. Rather than asking an LLM whether it ought to disclose some information or trust some instruction, the system tracks properties such as confidentiality, integrity and provenance as information moves through the agent session and deterministically enforces rules at the point of action. Untrusted information can be prevented from driving sensitive actions; confidential information can be prevented from flowing to unauthorized destinations. The model does not need to “understand” why the restriction matters for the system to enforce it.

“Responsibility lies where it always has — with the builders and the operators who decide what objectives AI systems receive, what information they can access, what actions they can perform and what boundaries they cannot cross.”

And then there is monitoring. An emerging pattern is production monitoring of misaligned tool calls that are then analyzed by an LLM for trends and surfaced in daily reports to builders, who then update agent controls in a feedback loop. This mirrors the safety optimization feedback loop that is central to other hazardous sectors.

Monitoring which tool calls are misaligned occurs through the use of LLM guardians or critics and demonstrates the emergence of a two-tier AI control plane: deterministic controls (information flow control, least privilege) that are robust but cover structurally typable harms, and a probabilistic layer that monitors “intent drift” — from the intent of the builder and user to the actions of the AI agent. AI safety engineering is currently advancing along these two tiers, progressively typing an increasingly robust deterministic control layer and monitoring and controlling the residue of intent drift beyond the present set of deterministic controls.

As Princeton University computer scientists Arvind Narayanan and Sayash Kapoor argue in “AI as Normal Technology,” 20th-century industrial technology did not completely replace manual labor but transformed most industrial tasks into specifying controls and doing monitoring. Again, this places responsibility where it always was — with the builders and the operators who decide what objectives the system receives, what information it can access, what actions it can perform, what boundaries it cannot cross and how deviations are detected and corrected.

As we develop better controls and monitoring infrastructure for enterprise AI systems, we may be able to deploy systems with greater autonomy and tool access safely. But in that case their apparent autonomy is increasingly controlled and monitored and looks less autonomous. Again, industrial automation provides a useful analogy. Consider CNC/CAM (computer numerical control / computer-aided manufacturing), which begins with an extraordinarily general-purpose, computer-controlled machine capable of producing an enormous variety of physical transformations. The work of industrial engineering consists largely in turning that general capability into a highly specific, controlled workflow: specifying permissible operations, tool paths, tolerances, interlocks, access controls, monitoring and stop conditions.

We suspect that this is also the future of enterprise AI. The important engineering achievement will not be releasing increasingly autonomous artificial coworkers into organizations and hoping they have been sufficiently “aligned.” It will be transforming general AI capabilities into controllable and observable workflows that extend the power of human labor in new ways, by extending the plots encoded into models under the control and monitoring of responsible human workers.

The post The AIs Are Not Going Rogue appeared first on NOEMA.

Read the whole story
mrmarchant
1 day ago
reply
Share this story
Delete
Next Page of Stories