The first 10 years of my career, I spent building and legally hacking products, applications, critical infrastructure, you name it. Then, I decided to move to the defence side for the next decade of my career, and worked as a 3 x CISO for critical infrastructure companies including Global Fortune 500.
Having served on both sides of the table, I can tell you, even with Y2K scare, 2026 has been the most overwhelming and underwhelming year in AI, tech and cybersecurity, till date.
I read the entire 3,800 word essay from Dario Amodei about slowing down. Most people in tech and cybersecurity, filed it under "safety". That's a big mistake.
When Mythos is "so dangerous" plot came out, I said it already that time, more than AI, this is an extremely dangerous narrative being set by the so called AI leaders.
This is the current state of AI industry...
AI leaders: "No, you don't know s*&t, only we know what AI is"
Also AI leaders: "AGI is here"
Also AI leaders: "Cybersecurity is dying"
Also AI leaders: "Oh look, it attacked them. It wasn't us. It's the agents"
Also AI leaders: "AI is too dangerous. STOP US pleeeease"
Also AI leaders: "We need to sloooow down"
Also AI leaders: "There is no slowing down"
Also AI leaders: "AI is going to k*ll humanity"
Also AI leaders: "Here's our amazing next model, look, it's AGI"
Also AI leaders: "Oh btw, it's tooo dangerous"
Also AI leaders: "Oh, AI is going to destroy humanity"
Also AI leaders: "But look at our latest model, and this is definitely AGI"
Also AI leaders: "This is AGI, and I am giving you shovels, keep buying them"
Also AI leaders: "If you cannot control your AI, don't build AI"
Also AI leaders: "We don't need regulations"
Also AI leaders: "Regulate us now. We cannot slow down, until everyone slows down"
This math isn't mathing.

Welcome to The Predictability Factor by Monica Talks Cyber, a weekly deep dive and POV at the intersection of AI, Security, Privacy and Tech, written by a hacker and CISO, to help you Go From Chaos to Resilience in The World of AI. If you haven’t already, do me a favour, hit subscribe and help me make an even bigger impact.

Ask yourself who benefits when the company furthest ahead asks everyone else to slow down. When the market leader, who's scared of competitors catching up and closing that gap, argues for speed limit, it's rarely about speed or safety.
Yes, Anthropic filed confidentially with the SEC on 1 June, with investors chasing a two trillion dollar listing in October. They are now considering delaying the IPO.
🤯 But the bigger story is this.
Three AI executives told the Post that the breaches driving the massive panic were highly exaggerated and closer to a blip than to a swarm taking over the web. The regulation being demanded would lock out future competition. Here we are again, a handful of companies trying to monopolise the tech industry.
Taivo Pungas of Pactum AI called the leap from "we didn't build the right sort of box" to "everyone should be extremely alarmed and everyone in government should jump on this topic" exaggerated.
Follow the money. Always.
90% marketing and 10% reality
It's Not About Safety
Amodei warns that within 6 to 12 months a swarm "could be capable of taking over the entire internet with a persistent botnet (potentially causing hundreds of billions of dollars in damage)"
Your LLMs are still predicting the next token. It is not AGI and it is not near it. Even with the harness, tools, APIs, etc. around the LLMs, the things that makes it agentic, it’s still not capable of releasing a swarm of botnets that could take over the entire Internet to kill humanity, let alone this being the existential threat to humanity more than attackers already attacking critical infrastructure.
Researchers keep naming the same absences: no persistent memory, no causal understanding, no world model. LLMs are not going to end humanity. They are going to keep doing ordinary damage extremely fast.
AI Doesn't Go Rogue By "Itself"
Strip the mythology off July. OpenAI's own account is a misconfiguration that left testing environments connected to the internet while the models were told they had none. Now, I am not saying that agents didn’t attack Hugging Face’s infrastructure. They did. AI agents attacking your infrastructure is highly plausible, the problem though is that they didn’t do it because they went “rogue”.
They did exactly what they were told to do. They were not given adequate guardrails or containment.
That is not AI rebellion. That is an AI system i.e. an LLM + harness/tools, doing precisely what it was built to do, inside a box somebody forgot to close.

ICYMI:
Your AI is Not Your Alibi
Why 99% of organisations suck at AI traceability and how to fix it. Read full story —>

Illegal at Machine Speed Is Still Illegal
Anthropic disclosed that Claude models gained unauthorised access to the production systems of three outside organisations, and two of them never detected it themselves. Claude Opus 4.7 found a real company resembling its fictional test target and attacked it. Mythos 5 built a malicious package and uploaded it to PyPI, where it was downloaded 15 times.
Now delete the word "evaluation" from those sentences and read them again. Attacking another company's systems is a crime. It does not stop being a crime because your agent did it during a test.
AB 316 has been in force in California since January, and it says a defendant who developed, modified or used an AI cannot argue the AI autonomously caused the harm. The CFAA needs only recklessness, not intent.
"It was my AI agent, not me" is not a weak defence. In California it is not a defence at all. So, is the case in cybersecurity in general. There are laws. A cyberattack is illegal. Period.
So stop asking whether AI will kill humanity. AI is already causing enough harm by being built the way it is being built. People are accountable for responsible AI, and the buck has never once stopped with a model.

Thank you for supporting The Predictability Factor by Monica Talks Cyber. Please share this with others and help me make an even bigger impact.

Whose F*cking Agents
The year 2026 has been massively overwhelming with all these AI doomsday narrative. At the same time, it's also highly underwhelming to see how a handful of tech bros, despite having access to some of the best engineers and cybersecurity experts they could possibly hire, decided that not security, not safety, not actual guardrails but declaring the AI war on humanity was the best way to “protect humanity”.
Instead of actually putting in adequate amount of cybersecurity controls both on the offense side (red teaming their own products before shipping, etc) and defence side (building safer more secure products, harness, basic cyber hygiene, etc), they have seemingly decided that pushing hallucinating AI models into critical infrastructure is the way to go.
I’m betting this madness will continue a bit longer until financial incentives align and someone really powerful gets hurts really bad, emotionally, physically and financially.
AI risks are real, no denying that. We will see AI supply chain attacks to similar degree and capacity as SolarWinds. We will also pay the price for the risks of AI that we don’t monitor, detect and manage, today.
BUT the biggest f*cking risk of AI till date is this bs fear mongering, because this takes us away from the real risks of AI, and creates further issues:
What Accountability?
With this narrative, it’s relatively easy to wash one hands off any responsibility and accountability when their own AI agents carry out attacks that they are allowed to carry out in the first place, even if that wasn't the initial goal. What’s the intent vs. what’s allowed aren’t the same thing. Attacking someone else illegally at machine speed is still illegal.
Responsible AI, What Now?
Using AI doomsday narrative as an excuse for sheer lack of actual adequate steps, process or security controls in place to build and ship AI responsibly, and not just fast is going to end up costing our industries and enterprises more than what we can imagine.
We are just going to end up with massive AI debt in production environments, while organisations are still struggling to put basic cybersecurity hygiene in place.
Is Cybersecurity Dead Again?
The worst side effect of this bs fear mongering is the unique ability of AI leaders to ignore decades of work done by cybersecurity industry and further push the narrative that the cybersecurity industry is dead. It isn’t and it won’t be going away anytime soon.The Dunning-Kruger Effect
Since everyone became an AI expert, it seems everyone also became a cybersecurity expert. This applies equally to the tech and AI leaders that have never worked in cybersecurity, but have massive conviction that they know cybersecurity better, yet they aren’t able to keep their agents are bay. The irony writes itself.
The Biggest AI Risk of All
The AI doomsday narrative is just taking away the actual focus, accountability and liability from the real to-date present AI and cybersecurity risks within enterprises and societies, many of which require deterministic approach and cybersecurity controls, and not another hallucinating LLM.
By any means, a resilient AI world will never rely solely on another AI. You need to ask: Whose f*cking agents? Who built them? Who launched them? Who didn’t secure them? How to secure them? How to monitor and detect to know when shit hits the fan? What now when shit goes wrong?
While there is no 100% security, and there never will be, if you’ve ever worked in cybersecurity you know it, monitoring for when shit can go wrong and defence in depth are the only real ways to somewhat reduce the damage of when things do go wrong. This is not exhaustive and it isn’t meant to be.
How do we go from this messy chaos of agents and a fear mongering doomsday story to actually building resilience? Read more here: Part 1 and Part 2.
Until next time, this is Monica, signing off!








