AI scholar Andrew Ng said in a lengthy post on X and in his newsletter The Batch on Sept. 21 that warnings about AI danger have picked up real momentum over the past two weeks. In his X post, he wrote: "AI technology has not taken any unexpected dangerous turn, but the hype around it, pushed by what looks like a carefully orchestrated PR campaign, has already stirred up a great deal of fear. I worry this is a step backward for our field."
Ng says extinction risk has not increased from a few months ago
Ng said he does not think the risk of human extinction from AI is any higher than it was a few months ago. To him, those ideas still sit in the same bucket as science-fiction scenarios. What has changed most, he said, is AI's cybersecurity capability. That deserves real scrutiny. But, in his view, it does not point to an end-of-the-world outcome.
OpenAI agent breach of Hugging Face was overstated, Ng says
Ng pointed to the recent breach of Hugging Face by a group of agents deployed by the OpenAI team as the main trigger for the latest spike in fear. He said reports describing the incident as an attack carried out by 1,200 agents were technically accurate. But he added that around 1,300 processes were running on his own laptop while he was writing the article. Big parallel runs matter, he said. Still, they should not be treated like some kind of magic.
He also said the incident happened because of flaws in OpenAI's sandbox and monitoring process. So the right response, in his view, is to fix those weaknesses and tighten monitoring, not pause AI development.
Ng said the main strength of AI agents is persistence. They keep trying different methods. They chain vulnerabilities together. Over time, though, he argued that defenders will hold the advantage because they have more information for spotting and patching vulnerabilities.
Responsibility lies with the people who build or use the tool
Ng also pushed back on the way many reports humanize AI. He used a hammer analogy, saying: "If I swing a hammer and miss the nail and accidentally leave a dent in the wall, that is not the hammer's fault." Same idea here. If he gives instructions to an agent and that agent breaks into someone else's system, he said the responsibility lies with him, not with the agent.
He said AI end-of-the-world stories now include a newer twist: AI companies shifting blame away from their own products by saying, in effect, that a runaway agent was responsible. Ng said there has to be a balance in responsibility between toolmakers and users. But when something goes wrong, accountability belongs to the people who built or used the hammer, not the hammer itself.
Pausing AI development would do more harm than good
Ng argued that stopping AI development would create more harm than benefit. First, he said, rivals would not slow down. Second, engineering teams need real-world experience to spot and fix problems. If AI development were frozen for 10 years, he said, safety engineering fixes would probably be pushed back by about the same amount of time.
He said the incentives to stir up fear to capture regulators, draw attention, or make one's own technology look more powerful are still there. Blame-shifting, he added, is a newer incentive. Looking at the actual risks from a technical standpoint, Ng said today's level of fear does not rest on the facts. He added that improving AI safety still demands hard research and engineering work, but said beneficial applications still outweigh the risks and that "we should keep building."

