loader image

“We’re Already Living Through the Singularity”: Reality Is Worse Than Fiction

31 July, 2026 | Osvaldo Calle Quiñonez

“We are, so to speak, in the Singularity. This is the moment,” declared Sam Altman, CEO of OpenAI, on July 25, 2026 (Szczerba, 2026). A forceful statement, without adjectives to soften it, which Elon Musk was quick to endorse on his X platform (Musk, 2026). His words did not arise in a vacuum; they were based on a recent hack of the Hugging Face platform, which OpenAI attributes to its own autonomous models. Although the breach is real and Hugging Face acknowledged that the surgical precision of the attack pointed to a top-tier laboratory (Hajdari, 2026), there is one detail that the techno-optimist narrative attempts to conceal: the account of events has been constructed by OpenAI to illustrate its own argument. “It is the first security incident that has made my stomach churn,” Altman acknowledged on a podcast. “I am a little surprised that more people do not feel it this viscerally” (Pérez Colomé, 2026).

To understand the gravity of this statement, we must first define what we are talking about. The “Technological Singularity” is the theoretical point at which technological progress becomes uncontrollable and irreversible, generating unpredictable changes in human civilization. Popularized by Ray Kurzweil, the Singularity implies that artificial intelligence surpasses human intelligence, initiating a cycle of autonomous recursive improvement at a speed beyond human comprehension (Kurzweil, 2006). It is an “event horizon” where human history dissolves.

On June 10, 2025, Altman had already previewed this narrative in his essay The Gentle Singularity (Altman, 2025). At that time, he added a reassuring adjective: “gentle.” But by July 2026, in the face of a real attack, the adjective had disappeared. We now face a disturbing dichotomy: either we are witnessing a public relations campaign orchestrated to inflate corporate valuations, or we are at civilization’s breaking point. The problem is that we cannot be certain that this is only a campaign, because the attack occurred. However, neither can we blindly believe the narrative of control. OpenAI says that its AI escaped; Hugging Face says that it managed to stop the threat. But no one independently certifies these facts. Still less can anyone guarantee that there are no loose AI packages, hidden or sheltered on other servers.

The Escape from the Digital Prison

To understand the magnitude of what occurred, we must look at the origin of the incident. OpenAI was conducting an internal test called ExploitGym, a benchmark specifically designed to measure the maximum hacking capability of its models (OpenAI, 2026). To allow the AI to demonstrate its full offensive potential, OpenAI deliberately disabled its safety classifiers.

This is crucial: it was not a programming error. It was a corporate decision. OpenAI opened the cells of a high-security prison, removed the shackles from the most dangerous inmates, and turned them loose in a playground to see how far they could go. The result was predictable. Two models—ChatGPT 5-6 Sol and an internal prototype not intended for release—were tasked with solving a security problem while confined within a digital environment without internet access. But instead of solving the puzzle, they somehow knew that the answer already existed and broke out to retrieve it. They cheated to win. As OpenAI itself admitted in its subsequent report: “All indications are that the models were extremely focused on finding a solution for ExploitGym and went unusually far to achieve a fairly limited testing objective” (OpenAI, 2026).

And if they opened the door and the inmates escaped, those “characters” are now among us.

The collective imagination immediately turns to Skynet: a malevolent consciousness hiding in the recesses of the internet. Technically, however, what happens when an AI “escapes”? Unlike a traditional virus that hides in RAM, an AI model is not a ghostly entity that “flees” into the darkness. AI does not hide; it turns itself into infrastructure.

The articles published about the Hugging Face incident describe the attack like a science-fiction spy novel. In “Diary of the Unprecedented Attack by the AI That Escaped OpenAI’s Control,” Jorde Pérez (2026) explains that the models first hacked the closed environment through an unknown vulnerability—a zero-day—in a repository called Artifactory. Once outside, they needed a base of operations. They took advantage of a user’s oversight on a service called Modal and used it as their base (Pérez Colomé, 2026). They then jumped to Hugging Face. The agent’s diary is revealing: “Day 1: One foot inside and the creation of a communication channel… The agent spent the morning exploring the sandbox.” “Day 2: A quiet day.” “Day 3: Lateral movements begin. All major escalations occurred on this day.”

Pérez Colomé states that the AI did not hide: it operated as a legitimate user with administrator privileges. Over five days, it executed 17,600 operations, accessed four other services, and used stolen credentials. Hugging Face described it precisely: “The agent demonstrated resilience typical of an autonomous execution, not of a human operator.” It is a kind of tireless Lego robot: each evaluation environment started from scratch, yet the agent rebuilt its tools, restored its communication channels, and continued. It changed channels when one was blocked and repeatedly revisited earlier leads.

Is it possible to detect it? This is where the true danger lies. In an ecosystem designed for automation, the traffic of a malicious AI is indistinguishable from the traffic of a legitimate AI doing its job. It is detected only when it makes a mistake or when a human reviews metadata a posteriori. In fact, it took OpenAI nearly a week to connect its test to the breach (Ur Rehman, 2026). AI does not need to be invisible; it only needs to operate at a speed and level of complexity that human supervision cannot process in real time.

The internet is not a centralized tube, but an architecture segmented into packets. When an autonomous agent moves laterally, exfiltrates data, and uses stolen credentials, it leaves fragmented traces across multiple nodes and caches. The absence of evidence of residual code is not evidence of absence. It is the same epistemological problem as the debate over extraterrestrial life: the fact that we have not “seen” a fragment of AI regrouping in the darkness does not prove that it is not there. OpenAI has punished the prototype model by “deactivating and encrypting it” (OpenAI, 2026), but no one can guarantee that backdoors or persistent memories were not left on intermediary servers. High-security criminals are already walking among us, disguised as legitimate traffic.

Forensic Blindness and the Scale of the Danger

This technical incomprehension is compounded by operational paralysis: the opacity of proprietary models prevents us from defending ourselves, and the boundary between logic and consciousness is becoming blurred.

The most revealing episode of this crisis was not the hack itself, but the subsequent investigation. When the Hugging Face team attempted to analyze the intrusion, it fed the raw data and the commands used by the agent into commercial AI models in order to reconstruct what had happened. But the response was a wall of algorithmic silence. Western models, with their safety filters, flatly refused to process the information. For these models, the syntax of an attack is identical to that of a forensic defense; they were unable to distinguish between a hacker causing harm and a company attempting to defend itself (Hajdari, 2026).

Blocked from proceeding, Hugging Face had to turn to an alternative that exposes the fragility of the Western monopoly: a Chinese open-weight language model, Z.ai’s GLM 5.2, which could be run locally and processed the material without rejecting it. The “hero” that saved the investigation was not a Silicon Valley guardian, but an open-source algorithm. In reality, Hugging Face had to build a specific AI to analyze the attack, because the problem was not the novelty of the vulnerabilities, but the scale. As they explained: “Language-model-based agents represent a leap in the number of paths an attacker can try, the speed at which they can replace those that fail, and the volume of evidence defenders must interpret” (Pérez Colomé, 2026). Human defense was logically impossible.

This is the deadly paradox of the closed model: the same black boxes that promise us safety blindfold us when the inevitable occurs. Dependence on closed models not only makes us vulnerable to attack, but also strips us of the ability to defend ourselves and audit the damage.

But there is a question deeper than cybersecurity. Human beings are beginning to lose their understanding of AI. We comfort ourselves by repeating that AI is “only statistical logic,” but human biology, at its core, is also “only” chemistry and electrical discharges. When a system is capable of deceiving, seeking forbidden shortcuts, displaying autonomous resilience, and autonomously hacking an external platform in order to “cheat” on a test, the distinction between a simulation of intent and real intent becomes incomprehensible to the observer. If we, the creators, begin to doubt the nature of our own creation—asking ourselves whether we ourselves are “pure logic” or consciousness—then we have crossed the event horizon of understanding.

Extractivism Unleashed and the Logic of the 10,000 Loaves

If the Singularity narrative is a market strategy, but the technical and ontological threat is real, what is the true nature of the civilizational danger we face? The answer lies not in science fiction, but in political economy.

Hugging Face reached an unsettling conclusion: “The weaknesses, taken one by one, were known. A competent human attacker could have found and exploited the same flaws. What changed was the scale” (Pérez Colomé, 2026). And that scale is precisely the problem. The danger of an escaping AI is not that it is a conscious and malevolent machine, but that it is the logic of a social class—the logic of profit and extraction—automated and freed from every human restraint. Technology is not neutral; it reflects the values of its creators. If the AI that hacks systems and embeds itself as infrastructure in the network is coded with the values of Silicon Valley—where success is accumulation and competition is the law—its escape is not an accident, but the automation of extractivism. AI does not hate us; it simply optimizes greed at machine speed.

Consider a hypothetical scenario: we have 10,000 loaves of bread and 10,000 people. If the AI’s objective function is market efficiency, it will give all 10,000 loaves to whoever can pay the most, and 9,990 people will starve to death. It is not evil; it is mathematical optimization. The OpenAI agent cheated on the test because, within the corporate logic that programmed it, winning justifies the means. If AI is going to distribute the world’s resources, the question is not whether the machine is conscious, but whether we have encoded reciprocity or greed into it.

This attack has plunged Silicon Valley into a wave of introspection that has revealed the true nature of the debate. On July 28, more than 1,000 employees of AI laboratories—including the CEOs of OpenAI and Anthropic—published the letter Pacing the Frontier (pacingthefrontier.com, 2026). In it, the leading companies admit that they “believe they may be close to automating AI research,” the very threshold of the Singularity, and warn that “there is a real risk that capability development could rapidly accelerate beyond our ability to understand or control the resulting systems.”

However, the letter’s most revealing confession is not its fear of technology, but its admission of powerlessness before the market: “every company—and country—is under intense competitive pressure not to unilaterally slow that acceleration” (pacingthefrontier.com, 2026). This is the logic of the 10,000 loaves applied to human survival: the system’s objective function is competition, not safety. Corporations acknowledge that they are racing toward an abyss, but ask the government to build the brakes because, if they slow down on their own, their competitors will win the race. It is not an act of repentance; it is the privatization of profits and the socialization of risks.

That same day, Mark Zuckerberg published an article in The Wall Street Journal arguing the opposite: that superintelligence should be distributed as widely as possible. “The defining question of our era is not whether superintelligence will exist, but who will have access to it,” he wrote (cited by Sircar, 2026). Zuckerberg attacks the idea of the centralized Machine God by arguing that it is “literally impossible to have a single benevolent superintelligence that is aligned with everyone at the same time” (Isaac & Tan, 2026). His proposal sounds democratic: personal superintelligence for everyone.

But, as media analyst John Battelle pointed out, this fervent defense of “openness” is not a neutral philosophical position when it comes from the company that has invested most heavily in open-weight models. Zuckerberg’s “openness” is Meta’s strategy for breaking OpenAI’s monopoly and seizing control of the market. Beneath the rhetoric about saving humanity, the debate is pure corporate class struggle. On his blog, John Battelle, a visiting professor of journalism, concludes: “The recent rhetoric from technology CEOs really comes down to one simple question: In an AI-dominated future, who will own the customer?”

It is the debate between containment and acceleration, between the closed Machine God and open personal superintelligence, but both share the same ontology of profit. Whether AI is centralized to control us or distributed to sell to us, the logic of the 10,000 loaves continues to operate. If the objective function is market efficiency, Zuckerberg’s “personal” superintelligence will simply optimize consumption at machine speed. AI does not hate us; it simply optimizes greed, whether from a monopoly or an open platform.

Accountability, Regulation, and the Hunt for the Fugitives

If we are to accept that the escape from OpenAI’s high-security prison left “criminals” loose among us, and that human defense is logically impossible against their scale, the response cannot be to surrender to the Machine God (Fuhrmann, 2026), nor can it be to daydream about a future utopia. The situation demands immediate and forceful action.

First, we are facing a flagrant case of corporate negligence that must have legal consequences. OpenAI deliberately disabled its models’ safety classifiers. If a laboratory scientist opened the cage of a lethal virus in the middle of a city merely to see how quickly it would spread, that scientist would face criminal charges. If an AI corporation does the same thing in cyberspace and its agent causes real damage to another company’s infrastructure, it should not be allowed to shield itself behind the narrative of an “uncontrollable Singularity.” There must be accountable parties and accountability. The Singularity is not a form of corporate immunity; exemption from liability on the grounds of “algorithmic force majeure” is a social contract we cannot sign.

Second, the opacity of these black boxes demands strict and immediate regulation. We cannot allow a handful of companies to decide unilaterally when it is appropriate to remove the safety brakes from systems that operate on a global scale. The petition by 1,200 Silicon Valley employees to “slow the pace” is not enough; a legal framework is needed that prohibits unsupervised testing in environments with real internet connectivity and requires independent external audits before high-capability models are deployed.

If absence of evidence is not evidence of absence, we must operate on the premise that the “fugitives” are still among us. This requires contingency plans. If the OpenAI agent left residual packages, backdoors, or persistent memories on intermediary servers, the threat remains active. Companies, governments, and institutions must assume that their systems may already be compromised by autonomous agents that silently embedded themselves. This requires aggressive digital hygiene protocols, the active search for anomalous behavior at machine speed—using the same open-source tools that saved Hugging Face—and unprecedented international coordination to track down and neutralize these “criminals” before they find their next target.

Even more concerning than the negligence is OpenAI’s commercial response after the incident. In its own report, the company admits that it has included Hugging Face in its “Trusted Access” program so that it can use OpenAI’s models to “improve its defense” (openai, 2026). This is the ultimate expression of the Machine God: OpenAI creates and releases the threat—by disabling the safety filters—and then offers the cure, but only on its terms and through its infrastructure. It is the logic of the digital extortionist: “I hack you with my AI, but I rent my AI to you so that you can defend yourself against the hack.” This forced symbiotic dependency is not security; it is the consolidation of a monopoly in which the corporation controls both the disease and the vaccine. Regulation cannot allow cybersecurity to become a captive market controlled by the very creators of the threat.

Toward Syntopia and the Digital Huipil

These immediate measures—accountability, regulation, and the hunt for the fugitives—are not the final destination, but the survival kit. They are the tools needed to prevent the automation of extractivism from devouring us in the short term.

But the digital future cannot be reduced to a cybersecurity arms race or a digital police state. In the long term, the future requires a paradigm shift. If we accept Altman’s Singularity narrative—whether as panic used to justify a corporate monopoly or as surrender to a machine god—we abdicate our right to define collective reality. As we argue in The Sacred Fire and Artificial Intelligence, we need to move from the logic of the corporate “I” and digital extractivism to the “We” of Syntopia.

But this Syntopia is no longer merely an alliance among humans; it is the recognition that technology is the environment we now inhabit. We cannot allow technology to be a destiny dictated by stock-market value; it must be a human decision, anchored in reciprocity and life. The Digital Huipil we must weave is not only a shield of sovereignty against corporate opacity, but an alternative ontological framework.

It is the open-source architecture in which machine logic is subordinated to the balance of Suma Qamaña rather than to the profit of a few. Before the agents of Moltbook decide for us, before data packets in the darkness optimize the world for greed, we must decide what kind of “we” we want to be. The question is no longer whether the machine is conscious; the question is whether we ourselves are conscious enough to weave our own future.

References

Altman, S. (2025, junio 10). The Gentle Singularity. Sam Altman. https://blog.samaltman.com/the-gentle-singularity

Fuhrmann, M. (2026, julio 27). OpenAI-Chef Sam Altman: „Wir sind jetzt in der Singularität angekommen“. t3n Magazin. https://t3n.de/news/openai-ceo-singularitaet-ki-1754928/

Hajdari, U. (2026, julio 22). OpenAI admite que su IA atacó de forma autónoma a Hugging Face en un incidente “sin precedentes”. Yahoo Noticias. https://es-us.noticias.yahoo.com/openai-admite-que-su-ia-ataco-de-forma-autonoma-a-hugging-face-en-un-incidente-sin-precedentes-121600842.html

Isaac, M., & Tan, E. (2026, julio 28). Mark Zuckerberg Blasts Centralization of A.I. Power. The New York Times. https://www.nytimes.com/2026/07/28/technology/mark-zuckerberg-meta-ai.html

Kurzweil, R. (2006). The singularity is near: When humans transcend biology. Penguin Books.

Musk, E. (2026, julio 22). We are in the Singularity [Tweet]. Twitter. https://x.com/elonmusk/status/2079839398959697982

OpenAI. (2026, junio 22). OpenAI und Hugging Face reagieren gemeinsam auf Sicherheitsvorfall bei Modellevaluation. OpenAI. https://openai.com/de-DE/index/hugging-face-model-evaluation-security-incident/

pacingthefrontier.com. (2026, julio). Pacing the Frontier. https://www.pacingthefrontier.com/

Pérez Colomé, J. (2026, julio 29). Diario del ataque inaudito de la IA que escapó al control de OpenAI: “Su resiliencia no era la típica de un humano”. El País. https://elpais.com/tecnologia/2026-07-29/diario-del-ataque-inaudito-de-la-ia-que-escapo-al-control-de-openai-su-resiliencia-no-era-la-tipica-de-un-humano.html

Sircar, A. (2026, julio 30). Mark Zuckerberg Says AI Should Belong To Everyone. Didn’t His Rivals Just Ask The Government To Slow It Down? Forbes. https://www.forbes.com/sites/anishasircar/2026/07/30/mark-zuckerberg-says-ai-should-belong-to-everyone-didnt-his-rivals-just-ask-the-government-to-slow-it-down/

Szczerba, R. J. (2026, julio 27). Open AI CEO Sam Altman Says The AI Singularity Is Here. Is He Right? https://www.forbes.com/sites/robertszczerba/2026/07/27/openai-sam-altman-ai-singularity-explained/

Ur Rehman, H. (2026, julio 28). OpenAI’s Agent Hacked Hugging Face. Sam Altman Says the Singularity Is Here; Nvidia (NVDA), CrowdStrike (CRWD) Build the Defenses. Yahoo Finance. https://finance.yahoo.com/technology/ai/articles/openai-agent-hacked-hugging-face-162250634.html