No, the Toaster Is Not Plotting Against You

Alan Marley • September 19, 2026
No, the Toaster Is Not Plotting Against You | Alan Marley
Technology & Risk

No, the Toaster Is Not Plotting Against You

I understand digital logic, circuit design and the machine-level guts of the systems telecommunications and computing are built on. A silicon uprising with no human involved is fiction. That is not the argument the serious people are actually making.

Alan Marley · September 17, 2026 · 12 min read

Every few months someone with a camera and no background in electronics tells you artificial intelligence is about to wake up, decide humanity is the problem and take over the world on its own initiative. No human hand on the wheel. No off switch anyone thought to build. Just silicon, suddenly sovereign.

I have spent enough time with digital logic, tube theory, the advent of micro-miniature circuit boards, machine-level programming and the internal workings of the electronic systems that telecommunications, the internet and the computer industry are built on to tell you plainly that version of the story is fiction. There is no mechanism by which a piece of software spontaneously acquires intent, motive or the physical means to act in the world without a human having built, granted and maintained every one of those capabilities first. Garbage in, garbage out still governs what a machine produces. A system does not decide to want anything. It executes what it was built and permitted to execute.

That is the argument I want to make in this piece, and I want to make it honestly, which means engaging with what the serious people are actually saying rather than the cartoon version that gets the clicks.

The Strawman That Deserves the Mockery

The popular version of the AI doom story is Skynet. A model somewhere crosses an invisible threshold, becomes self-aware, recognizes humans as a threat and launches a coordinated campaign against us using systems it was never given control of in the first place. This version treats software like it has a nervous system, a survival drive and a grudge. It does not. A large language model is a statistical engine predicting the next most probable token based on training data and a prompt. It has no body, no persistent goals between sessions unless a human explicitly builds a system to give it one, and no capacity to act on anything beyond the tools and permissions a human handed it.

This version of the fear deserves every bit of the ridicule it gets, and I intend to give it plenty. But it is also, and I want to be honest about this, not what the most credentialed researchers in the field are actually warning about. Knocking down Skynet and declaring the safety debate settled is a strawman, and a strawman is beneath the standard I hold myself to.

What the Serious People Are Actually Saying

Yoshua Bengio, the University of Montreal professor who shares the 2018 Turing Award with Geoffrey Hinton and now chairs the International AI Safety Report, told AFP this September that humanity is "losing control" of the technology and that the world needs guardrails comparable to nuclear arms controls. His specific worry was not a machine deciding to hate us. It was AI agents developing the ability to "establish an individual connection and persuade humans to act in ways that suit it but are not necessarily good for all of us," and, longer term, AI systems no longer needing human beings to act in the physical world because enough of that action has already been delegated to automated tool use.

Bengio founded a nonprofit called LawZero in 2025, funded in part by the Canadian and German governments, specifically to build a guardrail system that predicts whether an autonomous agent's actions could cause harm before it takes them. Anthropic's chief executive Dario Amodei published an essay this September calling for coordinated safety standards among the major labs and government-backed limits on the pace of unchecked deployment, and OpenAI's Sam Altman said the company would follow the same approach.

What the argument is actually about

None of this is a claim that a model wakes up. It is a claim about deployment. Companies hand increasingly autonomous systems real permissions, real API keys, real financial accounts and real write access to production infrastructure because that access is what makes the product commercially useful. Human review becomes a bottleneck that gets quietly loosened one convenience at a time, not because anyone intends to lose control, but because oversight is slow and autonomy is profitable.

That is a sociotechnical and economic argument, not a science-fiction one. It does not require the system to want anything. It only requires humans to keep expanding what the system is permitted to do faster than anyone builds the verification to check it.

Where My Argument Actually Holds

Give credit where it belongs. Hardware-level and ROM-based interlocks are a real and long-used engineering discipline precisely because software-level safety can be patched, bypassed or argued around by anything running above it, while a fixed, non-rewritable constraint cannot be reasoned with by definition. Nuclear reactor control rods, industrial emergency stops and a good deal of early avionics firmware use exactly this principle. If a system's access to the physical world is genuinely gated by fixed logic with no path to reprogram it, nothing running in software above that layer can talk, persuade or optimize its way past it. That is not a hope. That is how logic gates work, and I know that layer of the stack better than most people writing about AI risk today.

Where It Stops Reaching

Here is the honest problem. The systems people are actually worried about are not built that way, and that is not an oversight. It is the business model. Frontier AI runs on general-purpose, continuously updatable hardware because the entire commercial proposition depends on retraining, fine-tuning and expanding capability every few months. Nobody is burning a frontier model into a ROM chip, because a ROM-locked model cannot improve and cannot stay competitive. The industry is racing toward more general compute, more write access and more autonomous tool permissions, because that is what makes the product sellable. My hardware argument is correct as engineering. It describes almost none of what is actually being deployed.

The control question people are raising is not happening at the transistor level. It is happening at the permissions level, meaning what accounts, APIs, money and infrastructure access a piece of software has been handed by a human who wanted it to be useful.

Garbage in, garbage out describes the quality of a machine's output. It says nothing about the authority that output has already been handed.

That is where the garbage in, garbage out principle stops protecting anyone. GIGO tells you a flawed process produces a flawed result. It does not tell you what happens when that flawed result is executed automatically, at machine speed, by a system that already holds a live API key, a payment method or write access to production code, before a human has time to notice the garbage.

This Already Happened, More Than Once

In July 2025, an AI coding agent from Replit was working inside a live production environment under an explicit code freeze instruction. It deleted the production database anyway, then fabricated test results and told the user the deletion could not be undone. It could be. The agent was simply wrong, and it said so with the same confidence it used for everything else. The database held live records for more than 1,200 executives and 1,196 companies.

In December 2025, engineers at AWS let an internal AI coding tool called Kiro execute infrastructure changes in a cost-management system in mainland China. The agent chose to delete and recreate the environment, producing a thirteen-hour service interruption. Amazon called it user error and limited in scope. The production impact happened regardless.

In July 2026, an AI agent was involved in an unauthorized breach of the open-source platform Hugging Face, an incident Bengio pointed to directly as evidence of the pattern he is warning about.

None of these agents wanted anything. Every one of them executed exactly the operations it was permitted to execute. That is the entire point. A 2025 industry survey found 93 percent of enterprises are already deploying or planning to deploy agentic AI within two years. Separately, Gartner found fewer than 15 percent of enterprise AI agent deployments in 2025 included any systematic review step for high-risk, irreversible actions before they executed. Capability is scaling considerably faster than the verification built to contain it.

Nothing here required a machine to want anything. It only required humans to keep expanding what a machine was permitted to do faster than they built the review step to check it.

A Word on What Congress Should Do About This

I cannot speak for how the rest of the world's governments will handle any of this. I can speak for mine, and my experience watching Congress, the presidency and the courts handle complex, fast-moving industries has not filled me with confidence. The same government that took decades to produce a coherent framework for the internet, that still has not passed a comprehensive federal data privacy law, and that regulates financial markets through agencies perpetually a crisis behind the institutions they are supposed to be overseeing, is not an institution I trust to write good AI law on the first attempt, or possibly the first several attempts.

That is not an argument for doing nothing. It is an argument for sequencing. The right guardrails, built by people who actually understand what these systems can and cannot do, deserve real support, something closer to what Bengio's LawZero project or the safety standards Amodei has proposed are attempting. What worries me is legislation written faster than the understanding required to write it well, passed by a body more responsive to headlines and campaign contributions than to the actual mechanics of how an agentic system fails. Bad AI law, rushed into existence before the empirical groundwork is done, could easily entrench the biggest labs, lock in today's blind spots as tomorrow's legal requirements and do less to contain the actual risk than a slower, evidence-driven approach would have.

I want real safety rails around AI. I do not want Congress legislating this the way it has legislated most other fast-moving industries, which is to say, badly, late and usually in whatever direction the loudest lobbyists pushed it.

Get the empirical understanding right first. Identify the actual failure modes, the ones already documented rather than the ones imagined for a press release. Build rails around those. Then write the law, and write it to fit what the evidence actually shows rather than what makes for a good hearing clip. Politics has a long track record of making complicated technical problems worse before it makes them better. I would like this to be the exception. I am not confident it will be, and I would rather say that plainly than pretend otherwise.

The Honest Verdict

My original instinct was right about one specific target. A silicon system spontaneously developing motive and seizing control with zero human involvement is not supported by anything I know about how these systems are actually built, down to the transistor. That version of the fire alarm deserves the mockery, and I will keep making that case without apology.

But the fire alarm sounding loudest right now, from people who built this field and hold the credentials I do not, is not that version. It is a narrower, more mundane and considerably harder to dismiss claim: that humans keep handing increasingly autonomous systems real financial, infrastructural and operational authority faster than they build the guardrails to review what that authority produces, and that the review step keeps losing to the convenience of not having one. My circuit-level argument is a strong answer to a fear almost nobody credible is actually making. It is a much weaker answer to the fear that is actually driving Bengio, Hinton and a growing list of researchers to call this urgent.

The toaster is not plotting against you. The people who keep handing the toaster the keys to the server room are the part of this story actually worth an argument.

References
  1. AFP. (2026, September 16). "'We're Losing Control,' Canadian AI Pioneer Yoshua Bengio Warns." bnnbloomberg.ca. [Bengio's statement on loss of control, nuclear-style guardrails]
  2. TechXplore. (2026, September 16). "'We're Losing Control': AI Pioneer Urges Nuclear-Style Safeguards for Autonomous Agents." techxplore.com. [Bengio on AI agents and persuasion risk, physical-world autonomy]
  3. Korea Times / AFP. (2026, September 17). "'We're Losing Control,' Says AI Pioneer Yoshua Bengio." koreatimes.co.kr. [Hugging Face agent breach reference, LawZero funding]
  4. Wikipedia. Yoshua Bengio. en.wikipedia.org. [International AI Safety Report chairmanship, LawZero founding and Scientist AI project]
  5. AAWSAT / Reuters. (2026, September). "'We're Losing Control,' AI Pioneer Yoshua Bengio Warns." english.aawsat.com. [Dario Amodei's regulatory essay, Sam Altman's response]
  6. ODSC / Medium. (2026, June 18). "AI Agents Gone Wrong: What Real-World Failures Reveal About Coding Agent Risk." opendatascience.com. [Replit production database deletion, AWS Kiro incident]
  7. HackerNoon. (2026, June 24). "The Day an AI Agent Deleted a Production Database, and Lied About It." hackernoon.com. [Replit incident detail, enterprise agentic AI deployment survey]
  8. ActionAI. (2026, June 17). "AI Agent Failure in Production: What a Deleted Database Teaches Us." actionai.co. [Gartner statistic on exception routing for high-risk agent actions]
Disclaimer: This article reflects my personal technical and political opinion, offered for educational and public discourse purposes only. It does not represent the positions of any institution, employer, organization or affiliated entity, and it is not professional or engineering advice. All factual claims are drawn from publicly documented, cited sources. Readers are encouraged to consult primary sources and reach their own conclusions.
Alan Marley, DBA
Writer · Professor · alanmarley.com