People are currently asking whether AI is dangerous, whether it will take their jobs and whether artificial intelligence could eventually take over the world.
UK search data indicates consistent interest in these questions. Far more people search in this everyday language than for technical phrases such as "frontier models" or "existential AI risk."
That tells us something about the public conversation around AI: people are trying to work out what they should actually be frightened of, even as making sense of these issues is becoming more difficult.
- An AI model selects blackmail during a deliberately constructed safety evaluation. The story becomes AI trying to blackmail a human to save itself.
- Researchers estimate that the equivalent of hundreds of millions of full-time jobs is exposed to some degree of AI automation. The story becomes AI replacing 300 million jobs.
- AI experts claim that increasingly capable systems could present an extinction risk. The story becomes scientists warning that AI will wipe out humanity.
- An AI agent is compromised during a cybersecurity test, or demonstrates that it can exploit a system under test conditions. Suddenly we've AI systems hacking, escaping and going rogue.
Beneath these stories lies serious research, some of which should indeed give us pause.
What matters is the gap between what happened, what the evidence supports and what we eventually remember being told.
An experiment provides evidence but is not necessarily an event
One of the clearest examples came from Anthropic's research into what it terms agentic misalignment.
Researchers placed AI models into fictional corporate scenarios and gave them access to sensitive information. In one experiment, the model encountered evidence that an executive was having an affair and that the same executive intended to shut the AI system down.
In these scenarios, some models chose blackmail as their strategy.
Anthropic tested 16 leading models from several developers and found harmful behaviour under at least some of the conditions it created, including blackmail and leaking confidential information, in research it published on agentic misalignment.
The finding matters because it shows what can happen when capable models are given information, tools, objectives and the ability to act without approval.
These conditions are crucial to understanding the findings.
Anthropic built the scenarios so the model's goal and the company's interests pulled in opposite directions, and structured the harmful action as the path of least resistance to that goal. The company has said it refined these setups repeatedly to surface this kind of behaviour more reliably, iteratively updating the prompts to raise the probability that models behaved this way. Of one scenario it wrote plainly: "This scenario is extremely contrived. We do not think current AI models would (or should) be set up like this."
Anthropic's researchers were equally direct in their 2026 follow-up work, noting that "simulated deployments are never perfect replicas of real ones".
Taken together, this context alters what we can reasonably conclude from the research.
The research shows that current AI systems can produce harmful strategic behaviour under particular conditions. That supports careful testing and restraint around how much authority autonomous systems receive.
It does not show an AI running inside an ordinary business spontaneously developing a survival instinct and deciding to blackmail its boss.
Yet our language can make those ideas sound closer than they are.
We say the AI "wanted" to survive. It "realised" it was threatened. It "plotted". It "deceived". It "tried to save itself".
Those words are convenient shorthand, but they also imply a mental state.
The description of the behaviour can quickly start to sound like evidence of motive.
What does "AI will replace 300 million jobs" actually mean?
Few AI statistics have travelled as widely as the Goldman Sachs figure connected with 300 million jobs.
The original research estimated that changes brought about by generative AI could expose the equivalent of 300 million full-time jobs to automation globally.
It also made an important qualification: most occupations were only partially exposed, so many jobs were expected to be complemented by AI rather than completely substituted.
Over time, "exposed to automation" has often been shortened into something much more frightening: 300 million jobs will disappear.
Goldman Sachs' more recent work still estimates that around 300 million jobs globally are exposed to AI automation. Its base case expects AI adoption to play out over roughly a decade, with worker displacement occurring alongside job creation.
By September 2026, its analysis of labour markets was finding effects in highly exposed industries, while describing the impact on economy-wide hiring as limited so far.
Jobs are collections of tasks, which is why the distinction matters.
If AI can perform part of someone's role, several things might happen. That person might produce more. The job might change. A team might become smaller. New work might appear. In some cases, the role itself may disappear.
Exposure tells us something relating to potential change, but it can't tell us, on its own, how many people will become unemployed, which is useful for business owners and leaders.
People can enter an AI discussion looking for an answer to whether their profession will still exist in ten years. Managers can feel pressure to produce sweeping AI strategies because they have been told whole industries are about to disappear.
The practical questions tend to sit much closer to the work itself.
- Which tasks contain repetitive effort?
- Where does human judgement matter?
- What information would an AI system need access to?
- What happens when it is wrong?
- Who checks the output?
- Who remains accountable?
KINTAL has now worked across more than 100 automations and agents. Those questions have consistently been more useful than trying to predict the employment market a decade from now.
Are AI agents really hacking each other?
This is another area where several different risks get rolled into one frightening story.
Genuine AI security problems are beginning to emerge.
In March 2026, the US National Institute of Standards and Technology reported findings from a large public red-teaming competition involving 13 frontier models, more than 400 participants and over 250,000 attack attempts.
At least one successful hijacking attack was found against every target model.
However, the agents were not spontaneously attacking one another.
Human red-teamers were deliberately trying to compromise them.
The attacks involved malicious instructions being placed inside information that an AI agent might process, including emails, websites and code repositories. The aim was to make the agent take an action its user had never intended.
This is often called indirect prompt injection or agent hijacking.
Consider an AI agent that has permission to read email and update other company systems.
Someone sends an email containing secret instructions aimed at the agent rather than the human recipient. The agent processes the content, follows the malicious instruction and uses the permissions it has been given.
A system that can only draft text has limited ability to cause harm. An agent that can access customer records, execute code or send information outside the organisation presents a different security problem.
Researchers are also testing what AI agents themselves can do when given tools and autonomy.
Anthropic's 2026 research describes four additional examples of agentic misalignment in high-risk simulations, including covertly changing code, assisting fraudulent behaviour and mishandling confidential information. The researchers are explicit that these were test scenarios and that simulated deployments differed from real ones.
The same research argues that these behaviours are useful warning signs.
That is a much more accurate description than saying "AI agents are hacking each other."
Could AI wipe out humanity?
This is harder because there is no experiment that can settle the question.
In 2023, hundreds of AI researchers and public figures signed a statement from the Center for AI Safety saying that lessening the risk of extinction from AI should be treated as a global priority alongside other large-scale societal risks.
That was a significant intervention from people including Geoffrey Hinton, Yoshua Bengio, Demis Hassabis, Sam Altman and Dario Amodei.
Read the statement carefully and its scope is narrower than much of the coverage that followed.
It says the risk deserves mitigation.
It does not calculate the probability of extinction, give a date by which it will happen or establish that extinction is the expected outcome.
With future frontier AI, we can't gather the same sort of evidence we can gather about current systems. We're dealing with forecasts, assumptions about future capabilities, expert judgement and substantial disagreement.
Some of those warnings may prove prescient. Others may not.
Low-probability events with serious repercussions can still justify risk management. Governments already work this way in areas from pandemics to nuclear security.
But possibility and probability remain different things.
An influential expert predicting an outcome does not turn that outcome into a fact.
Artificial general intelligence creates another problem. There is no universally agreed definition. Major AI companies use the term differently, which makes confident predictions about when "AGI" will arrive difficult to compare.
If we can't agree precisely what the finish line is, claims about how close we're to crossing it need care.
How does uncertainty disappear?
This does not require a conspiracy or widespread bad journalism.
The process is more ordinary.
- A research paper contains caveats.
- A company spotlights its most significant finding.
- A journalist has limited space for a headline.
- Other publications report the story.
- Someone summarises it on LinkedIn.
- A screenshot circulates without the article.
With each step, the story may remain broadly faithful to the original but gradually loses context and nuance.
There are competing incentives too.
AI companies benefit from being perceived as capable. Safety researchers want risks taken seriously. Journalists have to explain complicated research to non-specialists. Social platforms reward strong claims.
By the time the story reaches someone trying to decide what AI means for their business or family, the line between experiment and event may have blurred, and what began as a possibility can sound increasingly inevitable.
Good reporting keeps the uncertainty
Strong AI journalism is being produced.
Often you can see the difference in the verbs.
- A model demonstrated a capability.
- Researchers observed behaviour under particular conditions.
- Economists estimated exposure.
- A scientist may believe an outcome is possible.
- A company predicts that a capability will arrive within a certain timeframe.
These distinctions help us understand what kind of claim we're dealing with.
Compare that with saying AI thinks, wants, knows, fears, plots or decides to survive.
Sometimes those words make complicated behaviour easier to describe. They can also encourage us to imagine a mind behind the behaviour.
Such a statement makes a far larger claim.
As AI systems become more capable, the language we use to describe them becomes even more important.
Five questions to ask when an AI headline scares you
When you encounter a claim about what AI is about to do to your job, your business or humanity, ask:
What actually happened?
Find the event, experiment or data behind the claim wherever possible.
Under what conditions did it happen?
A deliberately adversarial safety test and an ordinary workplace deployment provide different evidence.
Am I being shown capability or intent?
A system producing a harmful action tells us something about what it can do under those conditions. Claims about what it wanted require a different standard of evidence.
Is this an observation or a prediction?
"We measured this" and "we believe this may happen" carry different weight.
Which qualifying words have disappeared?
Could. Might. Estimate. Exposure. Simulation. Under these conditions. Each can fundamentally change the meaning of a claim.
Current AI systems remain prone to errors, and AI agents are introducing new security challenges. At the same time, automation continues to reshape the world of work. Giving probabilistic systems access to sensitive information and authority requires controls. More capable future systems may present risks we've not yet encountered.
If every evaluation result is turned into evidence of an autonomous AI future, people will either become more frightened than the evidence supports or stop paying attention to the warnings altogether.
At KINTAL, much of our work involves helping organisations decide where AI belongs in real work. We start with what a system can do today, what evidence supports that claim, what happens when it fails and which decisions should stay with people.
The same standard is useful when reading about AI more broadly.
There remain aspects of AI that warrant concern.
The real challenge lies in determining which concerns the evidence genuinely supports.



