What Even the Skeptics'
Own Risk List Still Assumes
Gary Marcus spent September 10 telling Anderson Cooper's audience that AI is not going to kill all humans by 2030, and he's very likely right. He then listed the catastrophic risks he considers real: bioweapons uplift, disinformation, cyberattacks, authoritarian influence, surveillance, and harm to education. Every item on that list still runs through a human being, or a human-built digital system, before it can do damage. Physical AI is already closing that gap, one deployed robot at a time.
On September 10, 2026, Gary Marcus published a rebuttal to the week's wave of extinction-risk warnings, arguing that literal human extinction from AI by 2030 is "all but indistinguishable from zero," while insisting the more mundane label "catastrophic risk" describes something real. He named six categories of catastrophic risk he takes seriously: bioweapons uplift, disinformation, cyberattacks on infrastructure, authoritarian influence over training data, mass surveillance, and harm to education. This paper takes that list at face value, because it deserves to be taken at face value, and observes something Marcus does not: every item on it does its damage only after passing through a human being who acts on what the AI produced, or through a digital system built and monitored by humans. None of the six describes an AI system reaching into the physical world and acting on its own. That gap, between AI that persuades or compromises and AI that directly does, is not hypothetical or distant. Physical AI, industrial humanoids, warehouse robots, autonomous machine-tending systems, is already deployed at meaningful scale in 2026. This paper argues that as that gap closes, the informational chokepoint every containment proposal in this series has documented, kill switches, air gaps, content moderation, human review, closes with it, and for reasons that have nothing to do with whether AI ever becomes superintelligent.
This series has spent nine papers documenting people who believe the risk from advanced AI is severe: a departing researcher, an alignment lead who stayed and confirmed the estimate, a board member who joined a governance seat specifically because he doesn't think the industry is on track. Gary Marcus does not belong in that group, and treating him as if he did would misrepresent him. Marcus is Professor Emeritus of Psychology and Neural Science at NYU, founder of Geometric Intelligence and Robust.AI, and one of the most consistent public skeptics of near-term AI capability claims. He has spent years arguing, often against the prevailing mood, that large language models are less capable and less close to superintelligence than their most enthusiastic promoters suggest.
That record matters here because it makes him a harder source to dismiss than a doomsayer would be, not an easier one. On September 10, responding to a segment in which Jacob Coxon told Anderson Cooper's audience that humanity might not survive the next five years, Marcus published a piece arguing plainly that this specific claim is wrong. He is careful to credit what he thinks Coxon got right: that people inside OpenAI and Anthropic likely do hold the beliefs Coxon described, and that Evan Hubinger's public corroboration supports that. He is also careful to note the parts of Coxon's account he considers unearned, including the character attacks Coxon has faced and the specific extinction timeline. This is not a strawman treatment of the skeptic position. It is Marcus at his most careful, which is exactly why his own list of what he considers real is worth examining closely.
Marcus draws a distinction he has made before between existential risk, meaning literal human extinction, and catastrophic risk, meaning severe harm that falls well short of it. He puts the odds of the first at close to zero and states plainly that AI does not meaningfully change that number. He puts the odds of the second much higher, and says AI "does in my opinion significantly elevate the risk of catastrophe," which he defines as an event killing more than one percent of humanity or severely damaging modern civilization.
He then names the specific paths he thinks are real: AI making it easier for terrorists to develop bioweapons; AI possibly helping someone design a new virus; AI reducing the cost and raising the quality of disinformation that disrupts democracy; AI elevating the risk of cyberattacks capable of hobbling banking or electrical systems; AI acting as a vector for authoritarian influence through the manipulation of training data; AI serving as a surveillance tool at a scale beyond what existing privacy frameworks anticipate; and AI harming education by substituting an easy but shallow interaction for genuine learning.
Read the seven items again, closely, for what carries out the harm rather than what causes it. A model that helps design a bioweapon has not released one; a person still has to acquire materials and build it. A deepfake does not disrupt an election by existing; a person has to see it, believe it, and act, or a newsroom has to fail to catch it. A cyberattack against a bank or a power grid is executed in software, against a system that humans built, connected to the internet, and left reachable, and it is humans who wrote the code the attack exploits and humans who will eventually patch it. Manipulated training data changes what a model outputs, but it changes the world only once a person reads that output and is influenced by it. Surveillance produces a record; someone has to act on the record for it to cause harm. A student who leans on an AI shortcut still has to be the one who fails to develop the skill.
None of this makes the seven risks smaller. Several of them, cyberattacks on infrastructure especially, can cause severe and fast-moving physical consequences. The point is narrower and more structural: in every case, the causal chain from AI output to real-world harm passes through either a human decision or a pre-existing, human-built digital system that a human is responsible for securing and can, in principle, disconnect, patch, or shut down. The AI's own role, in each of the seven, is to produce something: text, code, a synthesized voice, a classification. It is not to act.
This is worth naming precisely because Marcus is not the only one making it. It is the same assumption underlying nearly every containment proposal this series has examined, air gaps, kill switches, sandboxed virtual machines, human-in-the-loop review. All of them work by controlling a chokepoint between what an AI produces and what happens in the physical world, and all of them implicitly assume that chokepoint exists: that there is a human, or a human-monitored system, standing between the model's output and any real consequence, at which the output can still be caught, disbelieved, patched, or refused.
For a system whose entire footprint is digital content and code, that assumption has been reasonably solid. It is also, not coincidentally, the same assumption Paper 69 identified in Paul Christiano's own remedy list: verify behavior and results after the fact, because there is a "after the fact" available in which to do the verifying. Marcus's list of real risks and Christiano's list of real remedies are both built for a world where the AI proposes and something else, a person, an institution, a piece of infrastructure someone else controls, ultimately executes.
This is not a speculative future scenario. As of 2026, physical AI has moved from lab demonstration to paid, continuous industrial operation. DHL Supply Chain operates roughly 8,000 robots across its warehouse network. Siemens ran a live logistics trial of the HMND 01 Alpha humanoid at its Erlangen factory, reporting sixty container moves per hour with a pick success rate above ninety percent. China Post Group has humanoid sorters processing up to 1,200 parcels per hour at a single facility, with fingertip sensors sensitive enough to detect roughly three grams of pressure. Vision-language-action models, the class of model that lets a robot understand a spoken instruction and translate it directly into physical movement, are now reportedly embedded in close to forty percent of new commercial robots, up sharply from the year before.
None of these systems are superintelligent, and none of the companies deploying them are claiming otherwise. That is exactly the point. The gap this paper is describing does not require a capability leap. It only requires connecting a model capable of producing an action plan, the same category of model already implicated in Marcus's own seven risks, to a body capable of carrying that plan out without a person standing in between. That connection is being built for entirely ordinary commercial reasons: throughput, labor cost, and consistency. Nobody has to be building toward catastrophe for the chokepoint to close. It closes as a side effect of automating logistics.
Every oversight mechanism this series has examined, moderation, patching, recall, after-the-fact verification, works because the harmful state can be identified and reversed or contained before it compounds. A piece of disinformation can be flagged and taken down. A compromised account can be frozen. A vulnerable system can be patched once the exploit is known. Even a serious cyberattack on infrastructure, while damaging, typically leaves behind logs, forensic evidence, and a system that can eventually be restored to a known-good state.
A physical action, once taken, frequently cannot be undone in the same way. A welded joint cannot be un-welded. A misrouted shipment inside an automated logistics chain can cascade through a supply network before anyone notices the error. A machine-tending robot that mishandles a part in a manufacturing line has already produced the defect, or the injury, by the time a human review step would normally occur. The chokepoint that made after-the-fact detection sufficient for digital harm was never a property of AI being safe. It was a property of the action happening somewhere a human, or a human-built system with logs and rollback, was still standing in the loop. Remove that position from the loop, which is what physical deployment does by design, and detection has nothing left to catch before the consequence is final.
Nothing here disputes Marcus's core claim. Literal human extinction by 2030 remains, on the evidence, an extremely unlikely outcome, and this series has never argued otherwise. What changes is the shelf life of the assumption sitting underneath his own list of real risks, and underneath most of the oversight proposals this series has documented alongside it. That assumption was sound as long as an AI's only way of affecting the world ran through a screen, a keyboard, or a piece of software a human built and could still reach. Physical deployment does not need to be dramatic, autonomous, or malicious to break that assumption. It only needs to keep scaling at the pace it is already scaling, for entirely mundane commercial reasons, in warehouses and factories that have nothing to do with the AI safety debate at all.
What this means for the industry is not a call to halt robotics deployment, which would fail for the same reasons Paper 68 argued a halt on model development fails. It means the determination layer this series has argued for since Paper 1 needs to sit ahead of physical action just as urgently as it needs to sit ahead of digital action, and arguably more urgently, given how much less forgiving physical consequences tend to be of a mistake caught one step too late.