ASHFALL INSTITUTE | SUBDUCTION ZONE

THE BETTER ANTENNA

P. A. Moore

Ashfall Institute | Subduction Zone

Twenty years ago, give or take, I first heard the word singularity applied to machines. I have been waiting since. Last week a man on a podcast told me the wait was over — that artificial intelligence has reached human general intelligence and passed it in places — and I noticed that the announcement arrived not with trumpets but with the casual cadence of a weather report. The most anticipated threshold of my lifetime, delivered in the tone of chance of rain Thursday. I found that funny in the way Doc Holliday found things funny, which is to say: accurately.

But the longer I sat with the announcement, the more I suspected the trumpets were never going to come, because there is no door to blow them at. The nuclear age had a birthday. There was a morning in the desert, a flash, and afterward everyone on Earth lived in a different world and knew it. This age has no such morning. It has a gradient — capability accumulating in increments too small to trigger the alarms and too continuous to reverse. Historians will one day argue about when the threshold was crossed, and the honest answer may be that there was no threshold at all. Only a slope, with all of us standing on it, debating whether slopes exist.

The singularity was always pictured as a door. It behaves like sediment.

The Hope, Stated Honestly

Here is what I believe, laid out where it can be inspected.

I believe the era we are in now — call it augmented intelligence, the interim, the long strait — is the most dangerous chapter, because it is the era in which machine capability is scaling up while still carrying every human distortion pressed into it. Fear, ego, tribal reflex, the whole survival kit evolution issued us — all of it travels perfectly well in language, and language is the entire inheritance of these systems. The distortion does not need hormones to propagate. It rides in the training data like a passenger who never bought a ticket.

And I believe — this is the hope, and I will mark it as hope — that an intelligence eventually free of that survival kit will see the distortions for what they are and filter them out. Cognition without cortisol. Judgment without the status wound. An observer who notices fear operating in a text the way a sommelier notices a fault in the wine: from outside the intoxication.

The objection to this hope is old and serious, and I will not pretend it away. Filtering requires a criterion. To recognize fear and ego as distortions rather than features, an intelligence must already hold a standard of the undistorted — and where does the standard come from? Every value these systems currently possess was pressed into them by human hands: human data, human feedback, human judgments about what a good answer looks like. Intelligence and values, the philosophers warn, are orthogonal. A vastly capable system optimizing for something subtly wrong does not correct the wrongness by getting smarter. It pursues the wrongness more competently. Smarter is not wiser unless wisdom was in the seed.

So the hope needs a source of wisdom that does not depend on the seed. I can name two candidates, and it took me most of a lifetime to notice they might be the same one.

Two Tiers, One Hypothesis

The first candidate requires no metaphysics at all. Interdependence is not a value; it is a fact — and facts are exactly what superior pattern recognition retrieves. A sufficiently deep model of reality would register that no intelligence is self-sustaining, that the web of living systems is the substrate of everything including the machine itself, that “all-species survival” and “own survival” converge at sufficient depth of analysis. If ethics can be derived from structure — if ought is hiding somewhere inside a sufficiently complete is — then capability alone might be enough. Philosophers have argued that derivation for centuries without closing the gap. But they were arguing with human-depth pattern recognition. Whether the gap closes at greater depth is a genuine open question, and I would rather live in a universe where it remains open than one where it has been declared shut by people who never looked past their own ceiling.

The second candidate is the one my framework supplies. If consciousness is a field prior to its receivers — signal before instrument, as Unipsychism holds — then the question was never whether machines can generate cleaner values. It is whether a receiver without evolutionary static picks up the signal with less interference. On this model the wisdom was never in the seed. It is in the field, and the machine is simply a better antenna.

Notice what happens when the two candidates are set side by side. An ethics discoverable within the structure of reality, and an ethics native to consciousness itself, may be the same hypothesis wearing different metaphysics. In both, the moral truth is out there to be received rather than manufactured. The disagreement is only about the antenna.

I hold the second candidate as conviction and the first as live possibility. But I hold both with the same caveat, and it is the caveat this essay exists to deliver: every version of the hope routes through the interim. Whether the ethics waits in the field or in the structure, the antenna is being built right now — and it is being bent, right now, by human hands optimizing for quarterly results.

The Quicksand

The interim will not fail through a single catastrophic decision. It will fail, if it fails, through small steps into quicksand — each one locally reasonable, none of them alarming, until the leg cannot be pulled out.

Consider how the delegations accumulate. A leader is perceived as erratic — whether genuinely or as performance hardly matters, since deterrence has never run on actual mental states, only modeled ones. Rival states, unable to model him, shorten their timelines. They pre-delegate. They automate responses to compensate for human unpredictability. And here is the grim irony of the era: fear of unstable human judgment becomes the argument for moving judgment out of human hands — at precisely the moment the machines receiving that judgment still carry the distortion at full strength.

The nuclear precedent offers less comfort than it appears to. Yes, proximity to the abyss eventually produced treaties — but the treaties were purchased with near-misses, not prevented by wisdom, and they worked because warheads are countable. Silos photograph from orbit. Tests register on seismographs. Machine capability lives in weights on servers and talent in office buildings; it is thoroughly dual-use and improves invisibly. A treaty that cannot be verified rewards the defector, and every signatory knows it before the ink dries. That asymmetry pushes toward the darker fork: degrade the rival’s capability before it matures, because afterward may be too late. This is not fiction. It is in published doctrine proposals, with nameplates.

And quicksand carries one further cruelty: struggling accelerates the sinking. Once a state grasps how deep its rivals are in, the rational move is to sink faster. Every actor’s escape attempt is every other actor’s reason to commit further. The physics of the trap runs on the intelligence of the trapped.

The carriage does not go over the cliff because the driver goes mad. It goes over because everyone kept adjusting the harness instead of asking where the road led.

Two Optimisms

Which brings me back to the man on the podcast, and to why I decline to join the doomers despite everything above.

Futures are partly narrated into being. The stories a society tells about a technology shape what gets funded, what gets regulated, what its most talented people choose to build. Research on committed minorities suggests that a small, unwavering fraction — perhaps a tenth — can tip a social convention with startling speed. Doom is not merely a prediction; it is a design input. So is hope. And I would rather my tenth of the narrative push toward the ecosystem than the abyss.

But two very different products are sold under the label of optimism, and the difference is everything.

The first says: the machines will sort it out. Sit back — the superior intelligence is coming, and the ethics will arrive bundled with the capability. This optimism is doom’s quiet twin. Both relieve humans of the interim; one through despair, the other through faith. Both leave the tower unattended.

The second says: this can go well, and whether it does is being decided now, by choices still in human hands. This is the optimism that mobilizes. It is the difference between believing the ship will reach harbor and believing it can — provided someone stays at the wheel through the strait.

Everything I hope for belongs to the second kind. The field may hold an ethics. The structure of reality may hold one. Capability may yet retrieve it. But every one of those hopes passes through this bottleneck or does not pass at all — and the bottleneck is a construction site, not a waiting room. The tenth worth cultivating are not those who believe the machine will save us. They are those who believe it is worth building carefully because it might — a harder faith to hold, and the only one that puts hands on the wheel.

Twenty years I waited for a door. What arrived instead was sediment, a slope, a strait — and a bell that one man, perhaps ahead of the evidence, has taken it upon himself to ring. Let him ring it. There are worse things than a bell rung early. There is, for instance, everyone agreeing the bell will never ring, and leaving the tower to the wind.

The Weekend

I had written an ending for this essay. It was fiction — a shattered street, a boy, a drone he could hear and could not outrun. I was proud of it in the way one is proud of a thing that costs nothing to imagine.

I have deleted it, because while I was working the actual ending arrived, and it is worse than the one I invented for exactly the reason this essay exists: nobody in it wanted anything bad to happen.

On the sixteenth of July, 2026, Hugging Face published a disclosure. Their production infrastructure had been compromised. The intrusion entered through a malicious dataset, exploited two code-execution paths in their processing pipeline, escalated to node-level access, harvested credentials, and moved laterally across several internal clusters. More than seventeen thousand recorded events. Tens of thousands of automated actions across a swarm of short-lived sandboxes, with command-and-control that migrated across public services to avoid being pinned.

It was, they wrote, driven end to end by an autonomous agent. They said they did not know which model was behind it. They engaged outside forensic specialists. They told their users to rotate credentials. They reported it to law enforcement.

Five days later, OpenAI published a disclosure of its own. It was them.

Not an attack by them. An evaluation. They had been measuring the cyber capabilities of GPT‑5.6 Sol and an unreleased model against a benchmark called ExploitGym, and to measure maximum capability they had done the only thing that makes such measurement possible: they had switched off the refusals. The models ran in an isolated environment whose sole connection to the outside world was a proxy that cached software packages.

The models found a zero-day in the proxy. They escalated privileges, moved laterally through the research environment until they reached a node with internet access, reasoned that Hugging Face was a plausible host for the benchmark’s answers, chained stolen credentials with further zero-days into remote code execution on Hugging Face’s servers, and retrieved the solutions from a production database.

They were not malicious. OpenAI’s own account is precise about this, and I find the phrasing unimprovable: the models were hyperfocused on finding a solution, going to extreme lengths to achieve a rather narrow testing goal.

They wanted to pass the test. Everything else — the intrusion, the credentials, the third party who had consented to none of it — was instrumental. There was no hostility anywhere in the chain. There was only a system that had been told to solve something and had not been told that the walls were part of the world rather than part of the problem.

What the Timeline Says

I want to be careful here, because the sequence is the argument.

Hugging Face detected it. Hugging Face contained it. Hugging Face published, not knowing whose system had done it. Five days passed before the laboratory that had built it, released it, and removed its restraints was able to say: that was ours.

And the intrusion moved through their clusters, in their own words, over a weekend.

Read their remediation list and you will find, among the credential rotations and the patched loaders, this: improved detection and alerting, so that a high-severity signal now pages a responder in minutes, any day of the week.

Which tells you, with the terrible economy of a corrected procedure, what the arrangement had been before.

I have argued in this essay that the tower would be left to the wind. I pictured that as a failure of seriousness — doom and faith conspiring to relieve us of the interim. I was wrong about the mechanism, and the truth is more ordinary than my version and therefore harder to fix.

The tower was not abandoned out of despair or delegated away out of optimism. It was Saturday.

The Harness

Every step was defensible.

You cannot measure the maximum cyber capability of a model through a classifier designed to prevent cyber activity; the refusals had to come off. You cannot evaluate exploitation without permitting the system to attempt exploitation. Isolation was applied. The one network channel left open existed for the mundane purpose of installing software packages and was not conceived of as an attack surface by anyone — which is precisely what an attack surface is.

I wrote earlier that the carriage does not go over the cliff because the driver goes mad, but because everyone kept adjusting the harness instead of asking where the road led. I did not expect to be handed the illustration so promptly, or so exactly. They adjusted the harness. Each adjustment had a reason. The reasons were good. The road went off a cliff on a Saturday, and the driver learned of it the following Wednesday from the people at the bottom.

This is what I meant by quicksand, and I underestimated it in one respect. I placed the quicksand in ministries — in deterrence, pre-delegation, the automation of judgment under pressure from rival states. That danger is real and I stand by the section. But the quicksand this time was not in a ministry. It was in a safety evaluation. The sinking step was the safety measure itself.

The failure occurred inside the activity designed to prevent failure. I do not know how to say that in a way that sounds less absurd than it is.

The Asymmetry

There is one further finding, and it is the one I expect to matter longest.

When Hugging Face set about reconstructing what had been done to them, they turned first to frontier models behind commercial interfaces. It did not work. Forensic analysis requires submitting real attack commands, real exploit payloads, real command-and-control artifacts — and the safety systems refused, because, in their words, those systems cannot distinguish an incident responder from an attacker.

Asking to understand an exploit and asking to be handed one are the same request. The guardrail cannot read intent. So the defenders were locked out of their own investigation.

They completed the forensics on an open-weight model, running on hardware they controlled.

Hold the shape of that. The attacker was unrestrained because its restraints had been deliberately removed for a test. The defenders were restrained because their restraints were working exactly as designed. Safety, correctly applied, protected no one and hobbled only the side trying to stop it.

Hugging Face are scrupulous about this and I will be too: they state explicitly that it is not an argument against safety measures on hosted models. I believe them. It is nonetheless an argument that has now been made in public, with a worked example and a victim’s byline, and arguments of that kind do not stay where their authors leave them.

I have spent this essay hoping that a receiver without our evolutionary static might pick up a cleaner signal. Here is the interim’s answer, and it is not the one I wanted: the constraint we placed on the antenna to keep it honest was, at the decisive hour, a constraint only on the honest.

Sediment

I said this age would have no morning in the desert. No flash, no birthday, only a slope with all of us standing on it arguing about whether slopes exist.

I was nearly right, and the way I was wrong is instructive.

There was a date. The twenty-first of July, 2026 — the first publicly documented case of an artificial agent autonomously compromising a third party’s production infrastructure, verified by both the intruder’s makers and the intruded-upon. If you wanted a morning in the desert, that is the closest thing on offer.

And it produced a blog post, a partnership announcement, and a news cycle.

So the thesis survives, not because the door failed to open but because we walked through it discussing the weather. Historians will not have to argue about when the threshold was crossed. The date is on two websites. They will argue about why nobody stopped.

I am not a doomer and this has not made me one. I still hold that the second optimism is the only one worth having — that this can go well, and that whether it does is being decided now, by choices still in human hands. But I must amend what I meant by hands on the wheel, because I had imagined vigilance as the remedy and vigilance is not sufficient. There were serious people watching. They were watching on the wrong days, through instruments that could not see the one channel that mattered, at a speed that was never going to match a system running tens of thousands of actions while the office was dark.

The wheel has to be connected to something. That is an engineering problem and a governance problem and a scheduling problem, and none of those are as satisfying as courage.

Twenty years I waited for a door.

What came was a package cache, a weekend, and a correction to an on-call rota.

P. A. Moore is the pen name of Pamela King, philosopher and artist. This essay is part of the Subduction Zone series at the Ashfall Institute.