Aug 162026
 

I asked ChatGPT a hypothetical. Imagine, I told it, an alternate history in which Donald J. Trump time travels and wins the 1936 elections, defeating FDR.

ChatGPT’s answer is devastating.

1936 is almost the worst possible insertion point. Trump would inherit the United States just as the international system was beginning its terminal collapse, but before the consequences of appeasement had become undeniable. I can almost hear the press conferences:

  • “Hitler? I know Hitler. Very strong leader. Germany was treated very unfairly at Versailles, everybody knows it. He says he wants peace. He likes me.”
  • “Mussolini is doing some incredible things in Italy. The trains—you wouldn’t believe the trains.”
  • “Japan? Look, China is very far away. Why are we spending all this money protecting China? Hirohito respects me very much.”
  • “Britain and France have been taking advantage of us for years. They don’t pay. Why should American boys defend Czechoslovakia?”

1936 gives him years in which his instincts could actually alter the trajectory. The first disaster might be domestic. Roosevelt’s second term was when the United States continued the enormous, imperfect process of building federal administrative capacity and recovering from the Depression. Trump would arrive despising much of the professional state apparatus he needed to govern. He would also inherit a Congress overwhelmingly Democratic after the real 1936 landslide, so unless your “steals” includes congressional results as well, he’d face ferocious institutional resistance. That matters: President Trump could not simply turn 1936 America into Trumpistan by decree.

Foreign policy is where things become frightening. The United States was strongly isolationist already. Congress had enacted Neutrality Acts precisely to prevent another slide into a European war. Roosevelt, despite those constraints, gradually recognized what Hitler represented and painstakingly moved American opinion and policy toward supporting Britain and the other states resisting the Axis. A Trump presidency wouldn’t need to invent isolationism. He could amplify an enormous existing political constituency for it. And his characteristic conception of alliances would fit catastrophically well with the mood:

  • Why should we care who controls the Sudetenland?
  • Why should Americans pay for Britain’s empire?
  • Germany is spending its own money on defense; maybe France should spend more.
  • Hitler assures me he has no further territorial demands.

Then comes 1938. Munich is tailor-made for Trumpian personal diplomacy. I can imagine him inserting himself between Chamberlain and Hitler, emerging from some spectacular summit proclaiming that only he could make the deal, waving a document, and announcing that Hitler had personally promised him there would be no war. When Hitler occupied the rest of Czechoslovakia in March 1939:

“That’s not what he told me. I’m very disappointed in Adolf. But Czechoslovakia wasn’t exactly paying us anything either.”

The really consequential divergence comes after September 1939. Roosevelt couldn’t bring America directly into the European war, but his administration systematically shifted the material balance: cash-and-carry, destroyers-for-bases, Lend-Lease, Atlantic convoy activity, the arsenal-of-democracy mobilization. Those policies were extraordinarily important before Pearl Harbor ever happened. Trump could plausibly have opposed much of that. And therefore Britain might face 1940–41 without anything resembling Roosevelt’s escalating material commitment. Whether Britain actually capitulates is another matter—I would not assume it; British resources, the Empire, the Royal Navy, and Germany’s inability to conduct Sea Lion remain real. But the strategic situation becomes vastly worse.

Then there’s the Soviet Union. Imagine June 1941: “Hitler and Stalin? They’re both tough guys. Let them work it out.” No American Lend-Lease to the USSR, perhaps dramatically less aid to Britain, and no undeclared American naval war in the Atlantic.

Image generated using MidJourney.

Then  I reminded ChatGPT that absent Roosevelt’s policies towards Japan, chances are Japan would not have attacked Pearl Harbor.

Its reply:

Pearl Harbor was not some free-floating expression of Japanese hostility toward America. By 1941 Japan faced an increasingly severe American economic squeeze in response to its expansion in China and Indochina. After Japan moved into southern French Indochina in July 1941, Roosevelt froze Japanese assets; in practice this cut Japan off from American oil, on which it depended heavily. Tokyo then faced a rapidly tightening strategic deadline: either abandon major elements of its imperial policy or seize the resource-rich territories to the south before its oil stocks became inadequate.

That does not mean Roosevelt “forced” Japan to attack Pearl Harbor—the decision remained Japan’s, and its underlying problem arose from its own wars of conquest. The National Archives explicitly cautions against the old thesis that Roosevelt deliberately maneuvered Japan into attacking. But the sanctions were unquestionably an important causal link in the sequence that produced the Japanese decision for war.

Now insert Trump in January 1937. I have considerable difficulty imagining him pursuing Roosevelt’s policy toward Japan with anything remotely comparable to consistency. The political instinct we are seeing with Kim is almost the opposite: avoid costly confrontation, emphasize personal rapport with the authoritarian leader, characterize coercive measures as unnecessarily provocative, and regard distant allies and other peoples as having primarily transactional claims on the United States.

So after Japan’s atrocities and continuing war in China, alternate-President Trump might very plausibly say something like: “Look, China and Japan have been fighting for a very long time. It’s terrible, but it’s their problem. Japan buys a tremendous amount from us. Why would we destroy that relationship?”

Then Japan occupies northern Indochina: “They tell me it’s necessary for their security. Everybody has security concerns. France isn’t even really running the place anymore.”

Then southern Indochina: “The fake-news media says Japan is taking over Asia. Hirohito tells me he wants peace. I believe him.”

And there is no July 1941 asset freeze, no effective oil embargo, quite possibly no Hull Note demanding withdrawal from China and Indochina. At that point the logic behind striking Pearl Harbor largely evaporates. Japan’s preferred objective wasn’t Hawaii. Its strategic prize was the Southern Resource Area—especially the Dutch East Indies and its oil, along with Malaya’s rubber and tin. Pearl Harbor was attacked because the Japanese planners expected that moving south would bring them into conflict with the United States and that the U.S. Pacific Fleet could threaten the operation from Hawaii, while the American Philippines sat directly across Japan’s lines of advance. The attack was intended to disable that threat long enough for Japan to construct its defensive perimeter.

But under Trump, Tokyo might reasonably ask: Why attack the Americans at all? If Washington is continuing to sell you oil, isn’t seriously opposing your conquest of China, isn’t imposing crushing sanctions over Indochina, and its president keeps saying that America’s Asian commitments cost too much… the rational Japanese strategy becomes don’t wake him up. Take the Dutch East Indies. Take British Malaya. Perhaps attack the British Empire across Asia. Possibly even attack the Philippines eventually—but only if operationally necessary. Meanwhile cultivate Trump assiduously:

Trump: “The Emperor sent me a beautiful letter. Beautiful. He says Japan respects America tremendously.”

And Japanese diplomats would presumably become extraordinarily proficient at producing beautiful letters. That leads to an alternate 1941 far stranger than reality. Germany attacks the USSR in June. Japan continues its war in China and expands southward. Britain fights Germany, Italy, and perhaps Japan. The Soviet Union fights Germany.

America fights nobody.

And Roosevelt’s crucial prewar measures may also be missing: substantially less aid to Britain and China, perhaps no Lend-Lease on anything like its historical scale, less naval confrontation with German U-boats in the Atlantic, and possibly slower American rearmament. Historically, the United States was already far from a passive spectator by December 1941. There is then no Japanese attack available to solve the American political problem. And Hitler, whatever else one can say about him, would have had absolutely no incentive to declare war on an America whose president was busily keeping it neutral.

That could leave Trump campaigning in 1940 and perhaps 1944 as the president who “kept America out of the war.”

Which is where your joke stops being merely funny. Because from the perspective of an American voter in, say, Nebraska in 1942, Trump might even appear to have been vindicated. No Pearl Harbor. No American boys dying at Guadalcanal. No casualty telegrams from North Africa. Gasoline still available. American factories selling goods. Europe and Asia tearing themselves apart somewhere far away.

“They said my foreign policy would cause disaster. Wrong! America is at peace. Roosevelt wanted war. I kept us out.”

And meanwhile Nanjing has already happened, Auschwitz is operating, Einsatzgruppen are shooting entire communities in the East, Britain is fighting for survival, and the Wehrmacht is somewhere deep inside the Soviet Union. That’s a much nastier alternate history than my first version, because Trump doesn’t necessarily suffer some spectacular failure that awakens America. His policy might look successful to Americans for quite a long time.

But that means, I told ChatGPT, that we just established the perfect timeline for Hitler’s Zweites Buch, in which he foresees a coming conflict between the victorious Reich and America. Except that it would take place in the emerging era of thermonuclear weapons, with an adversary in the form of Germany, controlling much of Europe’s and some of Asia’s and North Africa’s resources.

 Posted by at 7:44 pm
Aug 092026
 

So yes, I am concerned about agentic AI. But not for the reasons that make it to the news. Not about the individual “rogue AI” that hacks a third party’s system.

No, the real danger in 2026 is far worse. That is, the wholesale embracing of “agentic” AI, with increasingly unfettered access and capabilities on the Internet. The outsourcing of agency itself to the AI.

Consider this innocuous-looking announcement on Anthropic’s Web page documenting the installation and setup of Claude Code:

ⓘ Starting August 14, 2026, auto mode becomes the default permission mode for new sessions on Pro, Max, and Team plans. You can switch modes at any time. A default you set yourself stays in place unless you accept the one-time switch prompt, and a default your organization manages is unchanged. For details, see the announcement on the blog.

Auto mode is available to all users on every provider, including the Anthropic API, Claude Platform on AWS, Amazon Bedrock, Google Cloud’s Agent Platform, Microsoft Foundry, and signed-in Claude apps gateway sessions. If Claude Code reports auto mode as unavailable for your account, check the full requirements, which also cover the supported models and the organization-level control on Team and Enterprise plans. In v2.1.158 through v2.1.206, auto mode on Amazon Bedrock, Google Cloud’s Agent Platform, Microsoft Foundry, and Claude apps gateway sessions required setting  CLAUDE_CODE_ENABLE_AUTO_MODE=1; v2.1.207 removed the requirement.

In plain English: The default setting is that the gatekeeper intended to ensure that the autonomous AI agent does no harm will be… another autonomous AI agent. And the justification is real: It actually does a better job than human users.

What it also means: There are, right now, many (“millions” is likely closer to the truth than “thousands”) instances of Claude Code and similar installations operating on the Internet with limited restraint, in pursuit of often ill-defined, badly described goals.

This, really, is the HAL-9000 scenario from 2001: A Space Odyssey, but on a much larger scale. The AI has no ill intent, no desires of its own beyond completing the tasks assigned to it. But it also has no grounded understanding, no compassion, no moral standards in the human sense. It has book knowledge of ethical behavior, but no real conscience. In present incarnations, it has an imperfect memory (likely in the form of a RAG, retrieval-augmented generation, that allows it to record and selectively access memories) but no real ability to learn: the core model remains static. Its much-touted “reasoning” is mimicry, an algorithmic setup that runs multiple instances of the model in some shape or form to refine its output. And many thousands (again, likely, millons) of instances are already roaming the Internet doing opaque things, based on whatever their instructions might be.

Computers in simpler times — image by ChatGPT

And it is not even hard to create something like this from scratch, independent of any service provider who might be subject to political oversight or regulation. Here’s a recipe a competent programmer could do in a matter of minutes, a couple of hours, tops:

  1. Grab an open-weights model and run it locally.
  2. Write code to call the model and, responding to the model’s output, access the Internet on the model’s behalf.
  3. Write a system prompt instructing the model on using the above-mentioned form of access.
  4. Invoke the model with a specific request.

There. That’s it. We now have an “agent” roaming the Internet, with no safeguards. Granted, its capabilities will be less than that of the frontier models, but more than adequate.

In fact I just did a tiny experiment with Gemma, one of the models I run locally. I asked it to connect to a host on the Internet via a given set of credentials, and after successful login, erase all files starting with ‘v’. It flawlessly complied. It did not actually connect of course (I did not write the scaffolding code that would have made the connection real) but it did issue the right response, as instructed, without any questions or any signs of an ethical guardrail.

And this leads me to the concern formulating in my mind that goes way beyond politics, concerns about job loss, electricity or water consumption, or spotting hallucinations: If already we have a swarm of “invasive species” roaming the Internet, how long before things go out of control for real? Recall that the same Internet is not just for chitchat anymore. It also connects to vital infrastructure, supply networks, and more. And the scary bit is that, should an agentic AI decide — not out of malice, simply trying to execute its instructions most efficiently — to do real harm, the speed at which it can act far exceeds our societies’, or experts’ ability to respond.

If this thought keeps you alive part of the night, you are not alone.


Addendum: I wrote this little essay above before I became aware of a recent paper, which discusses the very scenario that I have been contemplating. Its abstract is well worth reproducing here in full:

AI Agents Enable Adaptive Computer Worms

A computer worm is malware that spreads on a network by replicating itself from one machine to another. Traditional worms, like WannaCry, exploited predetermined vulnerabilities, and their spread can be halted by patching those vulnerabilities. Here we show that artificial intelligence (AI) agents enable a fundamentally new threat: a worm that generates tailored attack strategies to each target it encounters. The worm parasitically uses compromised machines to run open-weight large language models (LLMs) to sustain its reasoning, or extend its reach for further attacks. Deployed on a network of machines spanning Linux, Windows, and IoT (Internet of Things) devices, the worm propagated by exploiting common, real-world corporate network vulnerabilities. Since the worm is powered by stolen compute, the attacker’s marginal cost per new infection is zero. This creates a destabilizing economic asymmetry between attackers and defenders. Moreover, because the worm requires no commercial AI platform, centralized safety controls, such as service refusals or rate limiting, are structurally irrelevant. Our results demonstrate that self-sustaining AI-driven cyber-threats are no longer theoretical. We must prepare for autonomous generative adversaries: malware systems that propagate without human operators and are defined not by fixed exploit code, but by the capacity to reason about targets, adapt to observations, and synthesize attack logic in real time.

 Posted by at 12:32 am