Arvind Narayanan
Professor; co-author 'AI Snake Oil' (de-hype)
Princeton University
on LinkedIn

Known organizational and technical control interventions—not alignment alone—could prevent AI loss-of-control incidents, with cybersecurity professionalization as the model.

September 14, 2026
brightray analysis
Summary

A 13,000-word essay argues that AI loss-of-control risks are addressable through governance and technical control interventions, not just alignment research. The OpenAI incident could have been prevented by existing organizational norms and control techniques the company chose not to deploy. On cyberrisk, the essay finds most cybercriminals are already low-tech and face monetization barriers rather than exploitation barriers, limiting AI's marginal uplift—and proposes risk-specific defenses modeled on cybersecurity professionalization.

Why it matters
  • Alignment is necessary but not sufficient—specific organizational governance norms and technical control methods, not applied by OpenAI, would have prevented the referenced incident.
  • AI control should be professionalized like cybersecurity: a dedicated job function and embedded responsibility across roles, with policy incentives driving adoption.
  • Most cybercriminals are low-tech and bottlenecked by monetization, not exploitation skill—AI's marginal uplift to criminal capability is narrower than headline fears suggest.
  • The Morris worm is the right near-term analogy for autonomous cyber threats: localized, instructive, and containable—not an extinction-level event.
  • The 'AI as Normal Technology' framework was partially wrong: deployment-era risks matter less than development-era risks, and rogue-agent scenarios require rethinking.
  • Jaggedness of AI capabilities means risk-specific defenses are more tractable than universal safety solutions—targeted interventions can outpace broad alignment work.
View original on linkedin.com

Community notes

No notes yet — be the first.


See every signal in the Feed