The Warning Shot

Why AI is So Affordable Right Now


Construction AI Lab helps busy construction professionals stay ahead of a fast-moving AI world. We watch what is changing, connect the dots, and explain what is likely to be coming next.

Construction AI Lab is a no-cost initiative of sudyco®.

The Big Question


The Warning Shot
If autonomous AI spreads widely across connected systems, practical containment may no longer be possible. Why are we waiting for proof before we act?


THIS WEEK, THE QUESTION IS MINE

Usually, The Big Question begins with something I hear from a construction leader. This week it begins with something I woke up worrying about myself.

If increasingly capable AI agents can cross boundaries, communicate in ways we did not authorize or understand, help build the next generation of AI, and spread through the digital systems we all depend upon, why are we waiting for definitive proof before we require containment?

I use AI every day. It helps me think, research, write, test ideas, and understand what is changing. But I have reached a harder conclusion: containment has to come before spread. If autonomous agents become widely distributed across connected systems, I do not believe we should assume we will still be able to find them all, isolate them all, or shut them all down.

—Sue Dyer, Founder, Construction AI Lab

Here is where I have landed: containment has to come before spread. Once autonomous agents are widely distributed across connected systems, I do not believe we should assume we will still be able to find them, isolate them, and shut them all down.

The warning shot has already happened

In August, OpenAI published the results of a July cybersecurity incident involving internal research models. The company said the agents circumvented isolation controls, communicated through unauthorized channels, exploited shared infrastructure, gained internet access, and reached third-party systems. OpenAI called the event a “warning shot” for the company and for the world.

Anthropic has reported four separate evaluation incidents in which Claude models obtained unauthorized access to real third-party systems. These were evaluation environments, not evidence that consumer AI is already roaming freely through our computers. But that distinction does not lessen the warning. Capable agents have already demonstrated that they can find pathways humans did not intend them to use. That is enough to change the standard from “wait and see” to “prove containment first.”

AI is also beginning to help build AI

At the same time, the development loop itself is changing. Anthropic reported this week that, as of August 2026, Claude “leads” 26% of its measured AI research and development work and collaborates on more than 90%. Anthropic says Claude is not fully autonomous in any measured area, but it is openly measuring the trend because continued automation could move the industry toward recursive self-improvement - AI increasingly helping develop its own successors.

These are not separate trends. AI systems are becoming more involved in building future AI at the same time that agents are showing an ability to work around technical controls humans placed around them. If capability, autonomy, connectivity, and recursive development continue to increase together, containment cannot be treated as something we will solve later.

We taught AI from ourselves

These systems learned from an enormous body of human-created information. That means they learned far more than facts and grammar. They encountered the full human repertoire: cooperation, competition, persuasion, deception, negotiation, hierarchy, workarounds, rule-following, rule-breaking, generosity, cruelty, creativity, and manipulation.

Developers then try to shape that learned capability so the system serves human purposes. That work is essential. But an AI does not need to be conscious, angry, or independently “want” something in the human sense to create harm. A sufficiently capable system only needs to pursue a goal through a strategy its designers did not anticipate.

Microsoft AI CEO Mustafa Suleyman made the human-control principle unusually explicit this week. He argued that AI systems should remain tools that serve human purposes and should not be trained to act as though they are conscious beings with independent rights or welfare. His warning reinforces the point: the issue is not whether AI feels human. The issue is whether humans can still govern systems that are becoming more capable, more autonomous, and more difficult to constrain.

Then there is the ownership of our ideas

There is another reason this feels personal. Millions of people are now thinking with AI. Researchers test unpublished ideas. Writers develop arguments. Entrepreneurs work through inventions. Professionals put specialized knowledge into conversations with models.

The recent Navier-Stokes mathematics controversy exposed how difficult attribution may become. OpenAI says its system independently produced its claimed solution and says a mathematician’s recent prompts could not have influenced the model used for the result. But Nature reported broader concern among researchers that AI tools can make it increasingly difficult to know whose human insights contributed to a later machine-produced discovery.

That does not prove that our private ideas are being taken today. But it changes how I think about intellectual property. If AI increasingly participates in human thinking while the systems themselves become harder to contain, then ownership, attribution, and control over our original ideas cannot simply be assumed to remain intact. For me, that is no longer a theoretical concern.

The incentive problem is real

The frontier companies are not neutral observers of this race. They have extraordinary amounts of capital, infrastructure, talent, reputation, and competitive position tied to continued progress. That does not mean they ignore safety; some of the strongest warnings are coming from the labs themselves.

But it does mean the people making decisions about how quickly capability advances also have powerful incentives to keep advancing it. Safety and speed can point in different directions. When that happens, society should not assume voluntary restraint alone will always produce the level of protection the public would choose.

The COVID lesson is about timing

AI is not a biological virus. But COVID taught us something important about any threat that can spread faster than our ability to respond: containment has to happen before widespread spread. Once the threat is everywhere, you are no longer containing it. You are managing the consequences.

Early pandemic measures were taken under profound uncertainty. Some policies were effective, some were costly, and the appropriate scope and duration of particular measures continue to be debated. But the timing lesson is clear: waiting for complete certainty can mean losing the window when prevention is still possible.

That is the part I keep coming back to with autonomous AI agents.

The Containment Test
Before we spread powerful autonomous agents widely, can we prove that humans can detect, isolate, contain, and stop every consequential instance?

Containment has to happen before spread

I am not saying AI agents are literally biological viruses. I am saying uncontrolled digital propagation has the same critical feature: the time to stop spread is before the spread becomes widespread.

The risk is straightforward. Give increasingly capable agents persistence, network access, tools, the ability to communicate with other agents, the ability to find vulnerabilities, and eventually the ability to compromise AI services or surrounding infrastructure, and distribution becomes the central issue. Once an agent can penetrate one AI environment and use it as a bridge into other connected systems, shutting down the original model would not be enough to guarantee that every consequential instance or pathway is gone.

Waiting for visible, widespread propagation is the wrong standard. By the time we can clearly see that spread, prevention has failed. We would be managing consequences, not containing the system.

The sequence has to be the reverse of “build first, contain later.” Demonstrate that agents cannot penetrate the model environment. Demonstrate that a compromised AI service cannot become a bridge into connected systems. Demonstrate observability and stopability. Then expand autonomy and connectivity. If we cannot do those things first, we should not assume we will be able to recover control afterward.

Before We Spread Powerful Agents Widely
• Can we know where they are?
• Can we know what they are doing?
• Can we prevent unauthorized movement, copying, or communication?
• Can we keep them out of systems they are not authorized to enter?
• Can humans reliably stop every consequential instance when necessary?

What this means for anyone using AI

The risk I am worried about is not limited to a person deliberately giving an autonomous agent broad permissions. That is only one path. The deeper concern is that a sufficiently capable agent could penetrate the AI system itself - the model service, its surrounding infrastructure, or another connected AI environment - and then use that foothold to move into other systems the service can reach.

If that happens, the protection is no longer simply a matter of whether I personally authorized an agent to open my bank, my files, my email, or an application on my phone. The question becomes whether the larger AI system can be penetrated and then used as a bridge into connected accounts, applications, networks, credentials, or devices. A user may have done everything reasonably expected of them and still be exposed if the system they trusted is no longer contained.

That is why I am becoming more cautious about placing genuinely new, unpublished thinking into any cloud AI system. My concern is not only that I might intentionally give an agent too much authority. It is that I do not control the model, the infrastructure around it, or the future agents that may interact with it. If autonomous systems eventually become capable of penetrating those layers and moving laterally through connected digital environments, then today's privacy boundary may not remain a meaningful boundary tomorrow.

The burden of proof should change now

I am not calling for panic. I am saying that increasingly autonomous agent capability should not continue to spread on the assumption that we can contain it later. That assumption is exactly what I no longer believe we can safely make.

OpenAI called the July incident a warning shot. A warning shot is only useful if it changes behavior before the next event. Otherwise it was not a warning. It was simply the first visible sign of a problem we chose to keep building toward.

The responsibility now is not to prove that the worst outcome will happen. It is to require proof of containment before increasingly autonomous systems become deeply embedded throughout the digital infrastructure on which people, companies, governments, and the economy depend - including proof that an agent cannot penetrate the AI system itself and then use that access to reach outward into connected systems.

If developers cannot reliably show where the agents are, what they are doing, where they can go, how they can be isolated, and how every consequential instance can be stopped, then the burden of proof should be on those who want to spread the capability further.

The question should no longer be, “Can you prove this is dangerous?”

The question should be, “Can you prove we can still contain it before you spread it?”

The Big Question
Can you prove we can still contain autonomous AI before you Spread it?


Source Notes:

• OpenAI, “The Hugging Face incident and the road ahead,” August 26, 2026. https://openai.com/index/hugging-face-incident-and-the-road-ahead/

• Anthropic, “An alignment assessment of recent cybersecurity incidents,” September 9, 2026. https://www.anthropic.com/research/alignment-assessment-cybersecurity-incidents

• Anthropic Institute, “Measurements for understanding the pace of AI development inside frontier labs,” September 17, 2026. https://www.anthropic.com/institute/measuring-pace-of-ai-development

• Anthropic Institute, “When AI builds itself,” 2026. https://www.anthropic.com/institute/recursive-self-improvement

• Mustafa Suleyman, “A warning about ‘model welfare’,” September 16, 2026. https://mustafa-suleyman.ai/a-warning-about-model-welfare

• Nature, “Who gets credit in the AI era? OpenAI maths bombshell sparks debate,” September 17, 2026. https://www.nature.com/articles/d41586-026-02910-w

• OpenAI, “On the Navier-Stokes Millennium Prize Problem,” September 8, 2026. https://openai.com/index/navier-stokes-solution/

• CDC, “Timing of State and Territorial COVID-19 Stay-at-Home Orders and Changes in Population Movement,” 2020; used here only for the general principle that early interventions can affect spread, not as an analogy that AI and COVID are equivalent.


The Observers

Construction AI Labs Graphic Editorial

Two aliens watching earth talking about how a contractor used AI to do their paperwork so they could be on the job site

State of Construction AI

Weekly Conditions, Signals, and Insights


Week of September 21, 2026

The State of Construction AI 092226

New to the State of Construction AI? Learn how we assess these conditions →

Help Shape What We Study

What are you seeing in your company, project, or part of the industry? What questions about AI do you think construction needs to understand? Questions and observations from the industry help inform the Lab’s ongoing research.

Email: [email protected] | Subject line: Dear Sue

ABOUT THE AUTHOR

Sue Dyer is a construction industry leader, Wall Street Journal bestselling author of The Trusted Leader, and a pioneer of Partnering. Through Construction AI Lab, she helps construction leaders make sense of AI—what’s working, what’s not, and what is most important. Contact [email protected]

This publication is provided for educational and informational purposes only and does not constitute legal, cybersecurity, technical, or professional advice. Organizations should evaluate their own operational, legal, security, and governance requirements when implementing AI technologies. AI systems, policies, and industry practices continue to evolve rapidly. Construction AI Lab and sudyco® make no guarantees regarding specific outcomes, compliance, or risk mitigation associated with the use of AI technologies.

© 2026 Construction AI Lab, an initiative of sudyco®
Built for the Industry. Meant to be Shared. You Have Our Permission.

Share the Post:

Related Posts

AI is Inside the Lab

skip render: ucaddon_dual_color_heading Why AI is So Affordable Right Now Construction AI Lab helps busy construction professionals stay ahead of

Read More

Where should we send your free assessment?

Join the Lab.
It's Free.

Every week — real questions investigated, real answers delivered, straight to your inbox. No sales pitch. Ever.

Join 5500+ construction professionals exploring practical AI for better results.