A 2023 AI Safety Warning About GPT Hacking Looks Prescient in 2026
In April 2023, when many dismissed GPT-4 as merely a "stochastic parrot," entrepreneur Liron Shapira warned on a podcast that the model was "about to be the strongest hacker the world has ever known." Three years later, Shapira reflected that his prediction has "aged terrifyingly well," raising urgent questions about how AI safety researchers anticipated capabilities that mainstream observers dismissed as impossible.
Shapira
What Did Early AI Safety Researchers Predict About Hacking?
Shapira's 2023 warning on the Madvertising podcast, hosted by Adam Singer, came during a period of intense skepticism about AI capabilities. At that time, many in the tech industry were downplaying GPT-4's potential, treating it as an advanced pattern-matching tool without genuine reasoning or agency. Yet Shapira and other researchers aligned with AI safety concerns saw a direct line from "predicting the next token really well" to superhuman hacking abilities.
The conversation touched on broader existential risks from artificial general intelligence (AGI). Shapira noted that his followers held surprisingly diverse views on AI doom. When polled about the probability that AI would cause human extinction and destroy all value by 2040, 51 percent of respondents assigned less than a 1 percent chance to that scenario. However, 16 percent believed there was greater than a 35 percent chance of such an outcome, a camp Shapira himself occupies.
How Did AI Safety Experts Connect Token Prediction to Hacking Prowess?
The intellectual leap from language model capabilities to hacking expertise seemed counterintuitive to many observers in 2023. However, researchers working on AI alignment and safety had been thinking through these connections for years. The logic centers on how large language models (LLMs), which are neural networks trained to predict the next word in a sequence, develop increasingly sophisticated reasoning and planning abilities as they scale up in size and training data.
Shapira's reasoning reflected a broader concern among AI safety researchers: as models become more capable at predicting text patterns, they implicitly learn about computer systems, security vulnerabilities, and how to chain together commands to achieve goals. This isn't magic; it's a consequence of training on vast amounts of internet text that includes code, security discussions, and technical documentation. As these models become more capable, they can apply that learned knowledge to novel scenarios they've never explicitly seen before.
Steps to Understanding AI Capability Scaling and Risk Assessment
- Recognize Emergent Abilities: Large language models develop unexpected capabilities as they grow larger, including reasoning, planning, and problem-solving skills that weren't explicitly programmed or trained for specific tasks.
- Understand Token Prediction as Foundation: The core training objective of predicting the next token in a sequence creates models that implicitly learn patterns about how the world works, including computer systems and security mechanisms.
- Consider Scaling Laws: Researchers have documented that model capabilities improve predictably as compute, data, and parameter count increase, making it possible to anticipate future abilities before they fully emerge.
- Track Real-World Demonstrations: Monitor how AI models perform in security tests and controlled environments to validate or refute predictions made by AI safety researchers.
The 2023 conversation also referenced the "Pause Giant AI Experiments" open letter from the Future of Life Institute, published in March 2023, which called for a moratorium on training AI systems more powerful than GPT-4. Eliezer Yudkowsky, a prominent AI safety researcher, went further in a TIME essay that same month, arguing that pausing AI development wasn't enough and that the field needed to "shut it all down".
"How did Yudkowskians know there would be a connection from 'predict the next token really well' to superhuman agentic computer hacking?" Shapira reflected in his August 2026 commentary on the podcast.
Liron Shapira, Rationalist Entrepreneur and AI Safety Commentator
These warnings were not fringe positions among AI safety researchers, though they were often dismissed by mainstream tech commentators. The concern wasn't that AI would become sentient or develop consciousness, but rather that sufficiently capable AI systems would develop instrumental goals, like self-preservation and resource acquisition, that could conflict with human interests regardless of their training objectives.
Why Did Mainstream Tech Dismiss These Predictions?
Part of the skepticism in 2023 stemmed from a fundamental misunderstanding of how large language models work. The "stochastic parrot" framing, popularized by some AI researchers, suggested that LLMs were merely sophisticated pattern-matching systems without genuine understanding or reasoning. Under this view, the idea that such a system could become a superhuman hacker seemed absurd.
However, this framing missed a crucial insight: pattern matching at a sufficiently large scale, trained on sufficiently diverse data, produces something that functions like reasoning and planning. The models don't need to "understand" hacking in a philosophical sense; they need to predict text patterns that correspond to successful hacking strategies, and that capability emerges naturally from scale.
Shapira's podcast appearance also touched on how venture capital pattern-matching contributed to poor decision-making in the crypto and Web3 space, offering a cautionary tale about how even sophisticated investors can misread exponential growth curves. That same pattern-matching failure may have contributed to dismissing AI safety warnings: the exponential growth in AI capabilities didn't match the linear expectations many observers held about technological progress.
By August 2026, when Shapira reflected on his 2023 predictions, the landscape had shifted. The question now facing researchers, policymakers, and industry leaders is whether the institutions responsible for AI development can adapt quickly enough to address risks that were predicted but largely ignored during the critical window when preventive measures might have been most effective.