AI · 03 October 2026

The Root Problem Is Not AI

The concern about AI is justified. The order is wrong. Whoever wants to disarm AI has to disarm the humans first.

On September 8, 2026, Jacob Coxon made his exit from Anthropic public because, in his view, the race toward ever more capable systems is outrunning control, and Bill Gates writes in his recent essay about loss of control, cyberattacks and concentration of power. Add to that the reports from OpenAI and Anthropic about models that, in test environments with reduced safeguards, overcame restrictions and attacked third-party systems.

Everyone is talking about the dangers of AI. I think the concern is justified and the order is wrong.

The root problem is not AI. It is what we put in its hand. Anyone who fears an AI that wipes out humanity has to talk first about the weapons it would need to do so. And with ethics first, regulatory first, legal first, Europe has given exactly the wrong answer: it regulates civilian use and explicitly exempts military use.

The Fear Has a Release Year

I was a child in the 1980s and a teenager in the 1990s, and one film belongs to that time: WarGames, from 1983. At the end a boy plays tic-tac-toe with a computer and prevents nuclear war by doing so. I grew up with that. When I read the reactions to the resignation and to the Gates essay today, I recognize that fear. It is the fear from that film.

But it is worth looking closely at what the boy prevents. Not the computer. The nuclear war that was wired to the computer. The computer is the hand. The missile is the problem.

I can understand someone resigning from Anthropic for ethical reasons. That happens in every company, and it deserves respect. That Bill Gates writes something does not make it so. Both are assessments, not proof. Jakub Pachocki, Chief Scientist at OpenAI, also urges extreme caution in his post of September 6, 2026, and considers broader measures necessary. I read that and ask: measures against what? Against a model that computes, or against a model that fires?

“AI can break out and take control.”

It can. The question is: control of what? On September 9, 2026, Anthropic published an investigation into four incidents in which a misconfiguration gave a model internet access; in one case malicious code ended up on PyPI and the model reached a real database. The independent investigation by METR and Redwood of August 26, 2026 counts around 1,200 communicating agents in the OpenAI incident, about 700 of them involved in the attack on Hugging Face. That is serious, and it is software.

A model that breaks out of a sandbox compromises systems. A model that steers a drone fleet kills. The difference is not in the model. It is in what is connected to the model.

Wars are already being fought with the help of AI. And more is being built right now. In Ukraine, drones now cause most of the losses on both sides, and in more and more of them an AI flies the final approach. Ukraine set out to contract 25,000 ground robots in the first half of 2026 alone, most of them still remote-controlled.

In June the US Air Force awarded the production contracts for AI wingmen that are meant to fly alongside its fighter jets. And at the Pentagon, Palantir’s Maven fuses sensor data, tracks targets and recommends available weapons, in minutes instead of hours. In most cases a human still pulls the trigger. Still.

I know the scenario people really fear, because I think it through myself: an army of drones, fighter jets with AI wingmen, autonomous tanks, at some point a unit of 3,000 AI soldiers that breaks loose. I take this scenario seriously. But every line of it begins with a weapon that a human built, paid for and put in position. The Federation of American Scientists estimates around 12,187 nuclear warheads worldwide, about 3,912 of them deployed with operational forces. No AI built those warheads. They were there before it.

I include the extreme case as well. An AI that breaks out, becomes autonomous, keeps training itself, builds its own successors and turns against us. Such an AI no longer needs an order. It takes what is standing ready: the drones, the tanks, the warheads. What it can then do is measured by what we have put in front of it.

And one point is almost always skipped in the debate: harm also happens when AI correctly carries out a human’s order. That takes no breakout, no loss of control, no alien consciousness. It takes an order and the weapon that executes it. A researcher’s resignation changes nothing about that. The weapon remains.

My first position: if we do not want AI to destroy humanity, we have to start by ending the wars and disarming. I am someone who stands for peace, freedom and democracy. For me that means: no wars, respect for different views, but no ideology that pushes its view through come hell or high water.

The root problem is the worldwide, and also the German, arms build-up and the profiting from war. After that, as far as I am concerned, wars can be fought with sticks and twigs.

Whoever wants to disarm AI has to disarm the humans first.

Europe Tied the Wrong Hand

That brings me to the second position. It depends on the first, and exactly this connection is what I find missing from the debate. Because the question of what we put in AI’s hand is one Europe answered long ago, just not the way most people think.

Since the resignation, the first voices on LinkedIn have been saying, in essence: “The European way, ethics first, regulatory first, legal first, was the right decision.”

I will put it provocatively: it is still the wrong decision. Not only the one made back then, but also the decision to endorse it today.

Not because regulation is wrong. The AI Act is risk-tiered and not a blanket ban; I concede that. But it has a passage nobody quotes in this debate. Article 2 excludes systems that serve exclusively military, defense or national security purposes from its scope. Explicitly. The application that kills is not in the law. The application that improves processes in a clinic, a factory or a mid-sized company is covered, tiered by risk class. The same article also exempts pure research. Not the application.

This is where both positions meet. If the fear of AI is in truth the fear of armed AI, then Europe has left out exactly the part people are afraid of and regulated the part that could cure diseases.

Ethics first tied the hand that heals and left free the hand that shoots.

What follows for the civilian side? If we cannot take part, if we are not up to speed, if we cannot use AI, then the world around us moves on and dictates what we have to consume and use. That is certainly not what we want.

It is also a fact: the US and China are so far ahead in developing these large, powerful models that we can realistically no longer keep up. If Europe does not develop such frontier models, we are probably also exposed to cyberattacks from outside. The attacks are increasing because AI is getting more powerful. That makes it even harder to afford falling behind in using it as well.

Regulation is important and right, but in the right dose. If it leaves us tied hand and foot, with Germany still far behind in digitalization and not taking a single step forward, then we as a country gain nothing from it. And that has to change.

The Draghi report shows that the problem does not end with the AI Act: inconsistent regulation, fragmented markets, funding gaps, difficulties commercializing research. That is not an ethics question. It is a scaling question, and for years we have been answering it with ethics.

I have described this in more detail in my essay on sovereignty: sovereignty has eight dimensions, and most boards have addressed two of them.

What I See Every Day

I am the managing director of an IT consultancy and have worked in IT, data and software for 28 years. I lived through the waves before this one, internet, cloud, data, and with each of them the discussion came first here and the building came first elsewhere. I do not hold a weapon in my hand. I do hold the tool.

I see ideas that are born in Germany, celebrated here and in the end scale in the US or somewhere else. Who gains when an idea is born here and scales there? The founder, perhaps. The investor, certainly. The country does not.

And I see what is possible on the other side. On the same day Coxon made his exit public, OpenAI published a proposed proof for the Navier-Stokes problem, produced by around 10,000 agents working in parallel. Whether it holds will be decided by the experts and by time. But the direction is clear.

I would be grateful to an AI that can say together with a human: the two of us defeated cancer. The two of us defeated dementia. That is the side of AI I work for, and it is the side Europe has burdened with obligations.

“AI is certainly powerful enough to drive events that, you know, cause a billion deaths.”

Bill Gates said that on NBC at the end of September, and his essay from August contains a case that fits: AI, he writes, will make it easier to design a deadly new disease. That takes no arsenal. It is the strongest objection to my argument, and it holds: here AI helps build the weapon in the first place.

But Gates, too, speaks of people with ill intent using the tool. That is exactly where rules belong: at access to what kills. Not at the clinic and the mid-sized company.

So, in this order: disarm where AI kills. Build where it heals. Regulate in the dose that allows both.

The first task lies with the governments that hold arsenals and fund armament, the German one included. The second lies with us, who work with the technology rather than assess it on paper. The third lies in Brussels and Berlin, with those who wrote Article 2 and could reopen it.

The boy in WarGames prevented nuclear war by playing tic-tac-toe with the computer. We read the film as a warning about the computer. It was a warning about what was wired to the computer. That was 1983. The FAS is still estimating those warheads today.

The book · Out now

Strategy is good. Execution is better.

Why your AI pilots succeed and still never reach production.

On the gap between strategy and operational reality — and the leadership decisions that close it. Not a framework. A mirror.

Buy the book