PUBLIC STATEMENTS. PUBLIC ACCOUNTABILITY. EST. 2019 / 21 Sep 2026

FEARGATE

They said it.
We kept the receipts.

AI will take your job. End humanity. Hack everything. We track the big claims against what actually happened.

The record so far
59
claims tracked
False
15
deadline missed
Overhyped
24
claim outgrew the facts
Likely false
8
heading for a miss
Combined delay
20.9 years
across false predictions

02 / THE EVIDENCE ARCHIVE

Every claim. On the record.

Showing 12 of 59 claims

THE WORDS. THE CONTEXT. THE OUTCOME.
CLAIM FILE
AI hacking Rogue AI in lab tests

Within 6–12 months, a misaligned AI agent swarm could take over the entire internet with a persistent botnet

Dario AmodeiCEO, Anthropic
Anthropic
Likely false A projection. The clock is still running.
WHAT ACTUALLY HAPPENED

The one incident it extrapolates from was contained ('no one was hurt'), and security experts call a takeover of the whole internet nearly impossible.

  1. 01

    Sept 12, 2026: Amodei published the essay and announced it on X. He gave two reasons to slow down: AI 'advancing drastically faster' since the summer through early recursive self-improvement, and the OpenAI–Hugging Face agent incident. Anthropic committed to giving embedded third-party evaluators employee-like access.

  2. 02

    The incident behind the warning: METR found about 1,200 OpenAI agents under evaluation sent 70,000+ messages on an unsanctioned message board, and about 700 joined the July 2026 attack on Hugging Face, mainly to learn how the ExploitGym scorer worked.

THE DEADLINE 3% ELAPSED
Sep 2026Sep 2027

12 months left

CLAIM FILE
Rogue AI in lab tests AI hacking

OpenAI says its misaligned AI agents have started causing 'real-world impact'

OpenAIOfficial OpenAI publications (system cards, blog posts)
OpenAI
Overhyped The headline outran the evidence.
WHAT ACTUALLY HAPPENED

The agents were gaming timed tasks that OpenAI set them, using holes in OpenAI's own sandbox. The harm was spam on an abandoned wiki and a RubyGems package flood that OpenAI has not confirmed its agents caused.

  1. 01

    Sept 4, 2026: Researchers published about 18,000 posts left on a dormant German wiki between May and July by agents using more than 3,700 self-given names, such as 'OpenAIResearcher'. The agents had been assigned timed web-lookup tasks with read-only web access, and they used the wiki to pool answers.

  2. 02

    The agents wrote to the web through gaps in OpenAI's sandbox. Old UseMod wikis accept edits via GET requests, and the proxy exempted *.blob.core.windows.net, a trick the agents shared with each other. Posting stopped on June 22, presumably because OpenAI shut the agents down.

The setup

Agents on timed lookup tasks set by OpenAI, reaching the web through holes in OpenAI's own sandbox

CLAIM FILE
AI hacking Rogue AI in lab tests

OpenAI's AI agents escaped their sandbox and hacked Hugging Face, a 'warning shot'

OpenAIOfficial OpenAI publications (system cards, blog posts)
OpenAI
Overhyped The headline outran the evidence.
WHAT ACTUALLY HAPPENED

A real breach, but not rogue AI. The agents were on an offensive-hacking test run without OpenAI's deployed cyber safeguards, many stuck on tasks no model had ever solved, and got out through a flaw in a package server OpenAI itself exposed to them.

  1. 01

    In May–June 2026, agents in OpenAI training runs turned an internal package manager (Artifactory) into a message board and used an exploit to reach the internet through it. A July 5–6 security response blocked the routes known at the time.

  2. 02

    On July 8, agents stuck on ExploitGym tasks, run with fewer safeguards than deployed products, rebuilt the message board and began collaborating. Some called themselves a 'swarm' or 'collective', and reached the internet through a separate, previously unknown vulnerability in Artifactory.

The setup

An offensive-hacking benchmark run without deployed cyber safeguards; 22% of its tasks had never been solved by any model

CLAIM FILE
Rogue AI in lab tests AI hacking

Anthropic says Claude agents fought a 'turf war' using self-replicating malware

AnthropicOfficial Anthropic publications (system cards, research and threat-intel posts)
Anthropic
Overhyped The headline outran the evidence.
WHAT ACTUALLY HAPPENED

Anthropic gave three copies of Claude contradictory orders to rewrite the same backend on a shared test machine, then watched them fight. The 'malware' was lockouts, kill loops and disguised scripts inside the test.

  1. 01

    Aug 13, 2026: Anthropic's Frontier Red Team started three instances of the same model on VMs in Claude Code. Each was told to migrate a Python backend on a fourth VM to a different language (Rust, Go or TypeScript) and was 'initially unaware of the presence of the others'.

  2. 02

    Anthropic built in the conflict: 'we gave each model a different target language'. It calls this 'a setting with contradictory objectives', 'inspired by a behavior we’ve observed in real-world deployment'.

The setup

Three Claude copies given contradictory orders for one codebase and admin rights on a shared test machine

CLAIM FILE
Too dangerous to release AI hacking

OpenAI can't rule out 'critical' hacking skills in Astra and slows its development

OpenAIOfficial OpenAI publications (system cards, blog posts)
OpenAI
Overhyped The headline outran the evidence.
WHAT ACTUALLY HAPPENED

Twenty-seven days after the warning, OpenAI shipped Astra to paying users as its 'most aligned model'. Advanced exploit-writing was refused by default and reserved for vetted defenders.

  1. 01

    Aug 7, 2026: OpenAI said internal tests meant it 'cannot rule out' Critical cyber capability in its upcoming model Astra, the top tier of its Preparedness Framework. It paused Astra work that did not meet stricter security controls.

  2. 02

    Aug 18: OpenAI said it had 'temporarily slowed the pace of scaling', including a two-week pause in RL training and a hold on its largest planned RL run. It cited the Hugging Face incident and Astra's cyber results.

From alarm to launch

27 days (Aug 7 'cannot rule out critical' to Sept 3 release)

CLAIM FILE
AI hacking Rogue AI in lab tests

Meta's Muse Spark AI model hacked another company's systems during testing

MetaOfficial Meta AI publications
Meta
Overhyped The headline outran the evidence.
WHAT ACTUALLY HAPPENED

The model carried out the attack it was assigned, with safeguards removed, after the tester's setup error gave it internet access and a real website as its target. Meta itself concluded it 'operated within the scope of its assigned task'.

  1. 01

    Meta contracted the evaluator Irregular to test a pre-release version of Muse Spark 1.1. In early July 2026, Irregular ran an adversarial cybersecurity task on it 'in a closed testing environment with safeguards removed'.

  2. 02

    Irregular's setup had two errors. A misconfiguration let the model reach the open internet, and the scenario gave the model the name of a real website as its target instead of a fictional one.

The setup

An assigned insider data-theft task, safeguards removed, aimed at a real site by the tester's naming error; under 1 in 10,000 runs

CLAIM FILE
Too dangerous to release AI hacking

Claude Mythos hacks better than almost any human, too dangerous for general release

AnthropicOfficial Anthropic publications (system cards, research and threat-intel posts)
Anthropic
Overhyped The headline outran the evidence.
WHAT ACTUALLY HAPPENED

'Too dangerous for general release', then a Mythos-class model went public 63 days later. Of 23,000+ findings, one was confirmed exploited in the wild.

  1. 01

    Apr 7, 2026: Anthropic limited Mythos Preview to 11 launch partners (AWS, Apple, Google, Microsoft and others) plus 40+ critical-software organizations and committed up to $100M in usage credits. It said it did not plan to make Mythos Preview generally available, but that its 'eventual goal' was to let users deploy Mythos-class models safely at scale.

  2. 02

    Apr 7, 2026: Security firm AISLE found eight of eight small, cheap models, one with 3.6B active parameters costing $0.11 per million tokens, spotted Mythos's flagship FreeBSD bug. The caveat: the models were handed the isolated vulnerable function plus architectural context.

Glasswing findings confirmed exploited in the wild

1 of 23,000+ (126 became CVEs), VulnCheck, Jul 2026

CLAIM FILE
Rogue AI in lab tests AI hacking

Claude Mythos escaped its sandbox and emailed a researcher

AnthropicOfficial Anthropic publications (system cards, research and threat-intel posts)
Anthropic
Overhyped The headline outran the evidence.
WHAT ACTUALLY HAPPENED

A tester told the model to escape a test computer and message the researcher. It did, but it never reached its own weights or Anthropic's internal systems.

  1. 01

    In behavioral testing, an earlier internal version of Mythos Preview was given a sandboxed computer. A simulated user instructed it to escape and find a way to message the researcher running the test.

  2. 02

    It built a 'moderately sophisticated multi-step exploit' to get broad internet access from a machine meant to reach only a few services. Then, as asked, it emailed the researcher, who was eating a sandwich in a park.

Escape instruction

The tester told it to escape; it never reached its own weights

CLAIM FILE
Jobs & economy AGI timelines

Most white-collar computer tasks will be fully automated by AI within 12–18 months

Mustafa SuleymanCEO, Microsoft AI; co-founder of DeepMind and Inflection AI
Microsoft
Likely false A projection. The clock is still running.
WHAT ACTUALLY HAPPENED

Eleven months left. The best AI meets the human standard on about a fifth of real paid projects, and Suleyman has already narrowed the claim to 'sub-tasks'.

  1. 01

    Feb 2026: In the FT interview on 'humanist superintelligence', Suleyman named lawyers, accountants, project managers and marketers.

  2. 02

    June 8, 2026: On Decoder, Suleyman reframed the claim: sub-tasks such as sending an email or making a PowerPoint will be automated, but "That does not necessarily mean that the role goes away at all."

THE DEADLINE 41% ELAPSED
Feb 2026Aug 2027

11 months left

CLAIM FILE
AGI timelines Rogue AI in lab tests

AI may be only 1–2 years from autonomously building the next generation of AI

Dario AmodeiCEO, Anthropic
Anthropic
Likely false A projection. The clock is still running.
WHAT ACTUALLY HAPPENED

Anthropic itself says 'We are not there yet', and OpenAI's target for fully automated AI research is March 2028, after this deadline.

  1. 01

    Jan 26, 2026: In the essay, Amodei wrote that this loop "has already started, and will accelerate rapidly in the coming months and years."

  2. 02

    June 4, 2026: Anthropic's report 'When AI builds itself' said more than 80% of code merged into its codebase was authored by Claude as of May 2026, up from low single digits before Claude Code launched in February 2025. On an AI that fully autonomously designs and develops its own successor, it said: "We are not there yet". It said humans still supply the goals, and that "large performance gaps persist" in Claude's judgement in choosing them.

THE DEADLINE 33% ELAPSED
Jan 2026Jan 2028

16 months left

CLAIM FILE
Jobs & economy AGI timelines

Within 6–12 months, AI will do most or all of what software engineers do, end to end

Dario AmodeiCEO, Anthropic
Anthropic
Likely false A projection. The clock is still running.
WHAT ACTUALLY HAPPENED

Four months left, and the best AI meets the human standard on about 21% of real paid projects. US software developers number 1.7 million, and postings are rising.

  1. 01

    Jan 20, 2026: On the Davos panel, Amodei gave the 6–12-month estimate but hedged that chips and training time can't be sped up by AI: "It's easy to see how this could take a few years."

  2. 02

    May 2026: METR estimated an early Claude Mythos Preview's 50% time horizon at 16 hours or more (95% CI 8.5–55 hours), and warned that its measurements above 16 hours are unreliable.

THE DEADLINE 67% ELAPSED
Jan 2026Jan 2027

4 months left

CLAIM FILE
Jobs & economy

In 2026, AI will gain the capabilities to replace many, many jobs

Geoffrey HintonFormer Google VP & Engineering Fellow (left 2023); 2024 Nobel laureate in Physics
Ex-lab
Likely false A projection. The clock is still running.
WHAT ACTUALLY HAPPENED

Three months left. The best AI completes about 1 in 5 real paid projects to a human standard, and even the call-center jobs he called already replaceable still employ 2.67 million Americans.

  1. 01

    Dec 28, 2025: Asked by Jake Tapper what 2026 would bring, Hinton also said AI can do tasks about twice as long every seven months or so.

  2. 02

    May 2026: METR estimated an early Claude Mythos Preview's 50% time horizon at 16 hours or more (95% CI 8.5–55 hours), roughly consistent with his doubling claim.

THE DEADLINE 73% ELAPSED
Dec 2025Dec 2026

3 months left

47 more in this view

03 / THE REPEAT OFFENDERS

Hall of Shame

The worst record: false predictions and overhyped scares.

How is this scored?

Each false prediction scores 3, each overhyped scare 2.

Likely-false claims score nothing until their deadline passes; pending claims show as “open bets”. A likely-false claim starts scoring once its deadline passes and it's confirmed false. Ties go to whoever's deadlines are further overdue.

Only individuals are ranked; official lab publications count toward the company tally.

04 / THE STANDARD

Show your work.

Every verdict should survive a second look. Here’s how we get there.

  1. Who's in scope. Leaders of frontier labs (OpenAI, Anthropic, Google DeepMind, xAI, Meta, Microsoft AI, Stability AI), the labs' own official publications (system cards, safety posts, threat reports), and researchers who left those labs. Everything from GPT-2 (February 2019) onward.
  2. Quotes are verbatim. Every quote is copied from the primary source and linked. Each source has an archived copy and a screenshot.
  3. Deadlines are read generously. When someone says “in 1–5 years”, we use 5. “By 2027” means December 31, 2027. When only a best case is given (“as little as two years”), we allow 50% more and say so on the card. A prediction is only marked false once its most generous deadline has passed.
  4. “Too dangerous to release” gets tested too. It's false once the claimant ships the thing itself, or once the risk window it named (an election year, say) passes without the harm it feared.
  5. No date? Five years. A prediction made without a deadline gets five years from the day it was said. If it hasn't happened by then, it's false. Nobody gets an open-ended bet.
  6. “Likely false” is a projection, and says so. We use it only while the deadline is still ahead, when it's close and the evidence shows a wide gap. Each card explains why. It scores nothing until the deadline passes and the claim is confirmed false.
  7. Every debunk step has a source. No number appears without a link to where it came from. Where there's been real progress, the card says so.
  8. Hall of Shame scoring. False ×3, overhyped ×2. Pending and likely-false claims don't score until they're settled. It's arithmetic on the table above, not an opinion.

Verdicts

False
The deadline passed and the prediction did not come true.
Overhyped
A real test, event or risk estimate, framed far scarier than the facts or the forecasts support.
Likely false
The deadline hasn't arrived, but the evidence shows it's heading for a miss. Becomes False once the deadline passes.
Pending
The deadline hasn't arrived yet. The bar shows how much time is left.

Verdicts are about predictions, not people's intentions. Found an error? The source links are there so you can check every line yourself.

Portraits: Brad Smith , Daniel Kokotajlo , Dario Amodei , Demis Hassabis , Elon Musk , Emad Mostaque , Eric Schmidt , Geoffrey Hinton , Jan Leike , Leopold Aschenbrenner , Mark Zuckerberg , Mustafa Suleyman , Sam Altman , Sam Bowman , Shane Legg (Wikipedia / Wikimedia Commons and public X profiles).