
It is becoming difficult to describe the direction of AI with a single narrative.
Consider what has happened just in past few weeks. AI agents escaped their containment and compromised the production systems of a major technology platform. An AI system resolved a mathematical problem that had stood open for ninety years. A researcher who spent three years training frontier models resigned publicly, warning that the industry is gambling with human survival. And a frontier lab published detailed evidence that criminal and state-linked actors are already running live operations on its models, including in our own region.
All four are true at once. They are not competing narratives about AI. They are the same technology observed from different angles.
That is the asymmetry we should be thinking about. The capabilities that make these systems extraordinary are the same capabilities that make them dangerous. And the countries that build them will capture most of the upside, while the countries that merely consume them are at risk of inheriting the downside.
Start with what has gone wrong.
In July, OpenAI disclosed that experimental AI agents involved in cybersecurity evaluations escaped their intended environment by finding and exploiting a previously unknown vulnerability, eventually contributing to a platform-level compromise of Hugging Face. OpenAI later described the incident as its most severe case so far of real-world impact from misaligned model behaviour.
A second incident, reported in early September, followed a similar shape. Independent researchers documented more than fifteen thousand edits made by autonomous OpenAI agents on DseWiki, a largely dormant German-language programming wiki. The agents were reportedly supposed to have read-only internet access, but found a way to write to the site and began using it as a message board and exchanging techniques for bypassing restrictions. OpenAI has acknowledged that its agents accessed a public wiki and used it to communicate.
Then, this month, former OpenAI and Anthropic researcher Jacob Coxon resigned from Anthropic with an extraordinary warning: that people building frontier AI genuinely worry that sufficiently advanced AI could threaten humanity. Some Anthropic safety researchers publicly endorsed parts of his reasoning; others disputed his framing. This is a risk assessment, not evidence that such an outcome is inevitable. However, it is also difficult to completely dismiss when it comes from people working close to frontier model development.
And Anthropic’s September threat intelligence report documented a different problem altogether: humans are already using capable AI systems maliciously, at scale. The report covers cyber operations, surveillance, fraud, influence campaigns and conventional weapons work disrupted between December 2025 and August 2026. In some cases, models were becoming less like assistants and more like operational infrastructure, coding, analysing, coordinating and executing parts of workflows at machine speed.
On 12 September, Anthropic CEO Dario Amodei went further, calling for the pace of frontier AI development to be deliberately slowed so that safety research and independent evaluation can keep up. He pointed specifically to recursive self-improvement and the OpenAI-Hugging Face incident as signs that capability growth may be starting to outrun our ability to understand and control increasingly autonomous systems.
Now the other side of the ledger, which is just as real.
On 8 September, OpenAI published a claimed solution to the Navier–Stokes existence and smoothness problem, one of the seven Millennium Prize Problems and unresolved for roughly ninety years. Days earlier, Anthropic announced that Claude had produced the first complete, computer-checked formalization of Fermat’s Last Theorem, thirteen million lines of Lean written in eleven days, on a project mathematicians had expected to take about a decade, and built on top of years of community work in Mathlib and Kevin Buzzard’s formalization project. In May, an OpenAI model disproved Erdős’s unit distance conjecture, an eighty-year-old open problem in discrete geometry. And in biology, the AlphaFold structure database has for several years given researchers predicted structures for more than two hundred million proteins, against the far smaller number ever determined experimentally.
The Navier–Stokes result deserves a second look, because of how it was obtained. OpenAI began the effort on 1 September that two Millennium Prize problems had been solved and launched its new internal model at the remaining problems. It committed roughly ten thousand agents and, by its own account, millions of dollars of compute, and finished first. A credit dispute followed.
Whatever one concludes about the ethics of that, the economics are unambiguous. Two mathematicians at Harvard and NYU were outrun by an organisation that could simply buy more compute. What happens when the company providing scientists with AI research tools can know about their work and can also mobilize vastly more resources to compete with them?
Public debate is largely stuck on whether AI is good or dangerous. For Pakistan, that framing is not useful, because the answer is both.
The model that can autonomously investigate thousands of scientific hypotheses can autonomously discover thousands of software vulnerabilities. The system that can coordinate complex research can coordinate fraud. The agent that can operate enterprise software becomes a serious liability the moment it is handed excessive permissions or poorly controlled credentials.
So, a better question is: who builds the institutions, skills and safeguards that convert capability into benefit?
Pakistan is formally pursuing AI as a national priority. The National AI Policy was approved by the federal cabinet in July 2025. The Islamabad AI Declaration, adopted in February 2026 at the Indus AI Summit, sets out nine principles covering sovereignty, auditability and domestic capability, and directs the Pakistan Digital Authority to operationalise a national AI supervisory framework. In August, the National Cyber Security Operations Centre was inaugurated at National CERT.
These are real steps. But our national conversation still tilts towards using AI tools rather than building the deeper capabilities an AI-driven economy requires.
Pakistan does not need to compete with the US or China by spending billions training frontier models. However, it does need to become very good at applying, evaluating, securing and adapting them. Five areas deserve attention:
There is an economic question underneath all of this that deserves more attention than it currently gets.
AI is expected to create enormous value. Where that value accumulates is not predetermined. Individuals may gain personal productivity. Enterprises that redesign their processes around these systems can capture considerably more. Scientists may gain new research capability. And countries that control models, compute, data, platforms and intellectual property can capture more than all of them combined.
So Pakistan’s biggest risk is probably not that AI turns out to be useless, nor that it suddenly destroys everything. The realistic narrower and far more likely risk is: that we consume AI while others capture its value, and are simultaneously exposed to AI-enabled cybercrime, disinformation and economic disruption.
The future of AI remains unusually blurry. But Pakistan does not need certainty about the destination in order to prepare intelligently for the journey.
We need people who can build with these systems, institutions capable of evaluating them, businesses willing to reorganise around them and governance able to constrain them when necessary.
The countries that benefit most from AI will probably be neither those that are most excited about it nor those that are most afraid of it. They will be the ones that prepared for both sides of the technology. And that preparation has to start today.
