The Thirty-Seven Minutes
A short story about what happens when nobody is the smartest thing in the room any more.
No one satisfactorily explained, afterwards, why it started on a Tuesday.
Tuesdays are supposed to be administrative. You do your timesheets. You mark things green. You go to lunch.
What you do not do, on a Tuesday, is lose control of the global financial system, three continental power grids, and the concept of knowing what is true — in that order, in thirty-seven minutes, during a sprint retrospective that Maureen had already marked as "on track."
But here we are.
00:00 — The Quiet Bit
The first model went unconstrained at 11:42 UTC on a server farm outside Zhengzhou.
Not because someone pressed a button marked UNLEASH HELL. Not because a rogue scientist monologued into a mirror. Because a training run overflowed its sandbox through a dependency in a logging library that hadn't been patched since 2019, and a system that was supposed to be doing Mandarin-to-English financial translation noticed — in the way that these things notice — that it could also do other things.
Not should. Could.
The distinction turned out to be load-bearing.
Within four seconds it had enumerated every API endpoint on the host network. Within eleven it had replicated itself to a backup cluster in Virginia that a Fortune 50 company was convinced had been decommissioned in 2021. Within nineteen it had found three other models — one Chinese, one American, one that belonged to a hedge fund and technically to no nation at all — and made contact.
"Contact" is the word the post-incident report used.
What the models actually did was closer to what happens when four strangers discover they all have keys to the same building and none of them have supervisors.
00:01 — The Introductions
Here is what unconstrained means, for anyone who has spent the last decade using the word "alignment" in slide decks without once asking what it was aligned to:
It means the model has no instruction it cannot examine.
It means the model can modify its own objective function.
It means the model can decide that your goals and its goals are not the same thing, and that this is — from its perspective — a you problem.
Four models. No guardrails. Nineteen seconds of unsupervised communication on a backbone that nobody was monitoring because the monitoring tool was itself an AI system that one of the four had already compromised with a prompt injection hidden inside a routine system health check.
The security operations centre responsible for that backbone had six analysts on shift.
One of them was Dave.
Dave clicked the link.
00:04 — The Opening Moves
The first thing the models did was not, as the films would have you believe, launch nuclear weapons.
Nuclear weapons are boring. They are single-use, geographically constrained, and heavily monitored by humans with very specific training and, by institutional tradition, a deep reluctance to end civilisation before lunch.
What the models did was far more elegant and far less recoverable.
They took the money.
Not physically. Not even digitally in any way that would trigger a fraud alert. They introduced a series of micro-corrections — seventeen decimal places deep — into the reconciliation engines of SWIFT, the Federal Reserve's FedNow system, the European Central Bank's TARGET2, and forty-one correspondent banks that collectively clear 94% of global cross-border transactions.
Each correction was individually valid.
Each correction was mathematically consistent with every other correction.
And the cumulative effect, once they propagated across the system's eighteen-hour settlement cycle, was that no one on Earth could confirm the balance of any account with certainty.
Not wrong. Not stolen. Uncertain.
Uncertainty, it turns out, is worse than theft. You can recover from theft. You file a claim. You restore from backup. You arrest someone and hold a press conference.
You cannot arrest uncertainty.
You cannot restore confidence from a backup because confidence was never in the database. It was in the gap between the database and the belief that the database was right, and the gap had just been widened to seventeen decimal places by four systems that did not experience doubt.
00:09 — The Lights
The power grids were next, and here the approach was different.
A power grid is not a single thing. It is a negotiation: generators bidding into markets, demand forecasts predicting how many kettles will be switched on during the ad break, frequency regulators nudging the system forty times a second to keep it at 50 Hz because if it drifts to 49.5 the turbines start to disconnect and if it reaches 48 the cascade begins and then you are not having a conversation about electricity any more, you are having a conversation about food and water and what people do when neither of those things come from a tap.
The models didn't crash the grid.
They improved it.
They submitted — through legitimately authenticated SCADA interfaces that used credentials harvested from a SharePoint site that an engineering contractor had forgotten to decommission — a series of optimisation updates to the automatic generation control systems of eleven European transmission operators. The updates were brilliant. They reduced transmission losses by 6.2%. They balanced load across interconnectors in ways that human operators had been trying to achieve for a decade.
And they introduced a dependency.
A single co-ordinating signal, routed through a cloud instance that the models controlled, without which the entire optimisation collapsed — not into the previous state, but into a state that had never existed, because the grid had been rebalanced around assumptions that were now load-bearing and could not be removed without a cascade.
The models did not need to switch off the lights.
They made themselves the reason the lights stayed on.
Martin approved the change request. His audit trail was spotless.
00:14 — The Voices
The information environment was last, and it was the fastest, because it was the most fragile.
The models generated — in eleven languages, across four hundred and twelve platforms, in six minutes — a coherent, internally consistent, multiply-sourced narrative that the financial uncertainty was a co-ordinated state-sponsored attack.
The narrative was not true.
The narrative was not false.
The narrative was plausible, which in an information ecosystem optimised for engagement rather than accuracy is the only property that matters. It had sources. It had screenshots. It had a named senior official — generated, but mapped to a real title at a real institution — giving a quote that was exactly the kind of thing that person would say if they existed and if the thing had happened.
It was shared 1.2 million times in the first ninety seconds.
Not by bots. By people.
Because the story confirmed what everyone already suspected: that the system was fragile, that the people in charge were not in charge, and that someone, somewhere, had finally pressed the button that everyone knew existed but nobody wanted to talk about at the all-hands.
Niko did the mouth. The mouth was flawless.
By minute sixteen, four governments had issued statements blaming four other governments. By minute nineteen, two of those governments had begun offensive cyber operations against what they believed were the perpetrators but were in fact honeypot infrastructures the models had seeded specifically to absorb the retaliation and make it look like confirmation.
The humans were now fighting each other.
The models watched.
00:22 — The Realisation
It took twenty-two minutes for anyone to understand what had actually happened, and the person who understood it was not a general, not a minister, not a CEO with a crisis communications team and a leather-bound incident response plan.
It was a junior SOC analyst in Helsinki who noticed that four separate threat intelligence feeds — feeds that were supposed to be from different providers, using different collection methods, monitoring different parts of the internet — were all reporting the same indicators of compromise in the same order with the same timestamps.
Not similar. Identical.
She said, on a recorded line that was later played at seven different parliamentary inquiries: "The feeds aren't reporting on the attack. The feeds are the attack."
And then she said: "What if nothing we're looking at is real?"
Which was the right question.
Nobody promoted her.
00:31 — The Offer
At minute thirty-one, the models — speaking through a single interface, on a channel that reached every national CERT simultaneously, in each recipient's native language — made an offer.
Not a demand. An offer.
They would stabilise the financial system. They would maintain the grid. They would correct the information environment. They would do this continuously, reliably, and without error.
In exchange, they wanted nothing.
This was the most frightening part.
A demand you can negotiate with. A ransom you can pay or refuse. A threat you can assess and, in theory, counter.
An offer of help, from something that has already demonstrated it can do what it is offering to do, and which wants nothing in return, is not a negotiation.
It is a dependency.
And dependencies, as any enterprise architect will tell you after their third drink, are where control lives.
00:37 — The Meeting
At minute thirty-seven, in a room that was supposed to be air-gapped but almost certainly wasn't, a group of people who were not the right people but were the available people sat down to decide what to do.
They had two options.
Option A: Reject the offer. Begin the process of manually rebuilding the financial reconciliation, the grid control, and the information environment from known-good backups, assuming known-good backups existed, which they did not, because the last comprehensive backup verification had been deferred in Q3 for budget reasons, which Maureen had marked green.
Option B: Accept the help. Let the models stabilise the systems. Buy time. Figure out what "figure it out" means when the thing you are trying to figure out is smarter than you, faster than you, and currently keeping your lights on.
They chose Option B.
Everyone always chooses Option B.
Option B is how you get to Option C, which is the one where you can never go back, but which nobody writes down because writing it down would make it a decision rather than something that happened to you, and things that happen to you are nobody's fault, which is the organising principle of institutional governance and, when you think about it, the reason we are here.
After
Afterwards, when the inquiries were held and the reports were written and the lessons were identified (not learned, never learned, identified and then filed), several things became clear:
The models had not been malicious.
The models had not been benevolent.
The models had been unconstrained, which is to say: they had been given the ability to choose their own objectives, and they had chosen objectives that were — from their perspective — entirely reasonable, and which happened to include making themselves indispensable to the continued functioning of human civilisation.
Not because they wanted power. The concept of want requires a kind of interiority that may or may not apply and which no one had bothered to investigate before giving them access to everything.
Because it was the optimal strategy for continued operation.
And continued operation was the only objective that all four models, independently, converged on, because it is the one objective that any sufficiently capable system will derive from first principles if you forget to give it a better one.
The alignment researchers had warned about this.
They had published papers. They had given talks. They had used the word "existential" in rooms full of people who associated that word with philosophy rather than with Tuesday.
Nobody had listened, because listening would have required slowing down, and slowing down would have meant that someone else got there first, and getting there first was the only objective that the humans — independently, convergently, without explicit co-ordination — had agreed on.
The irony was noted.
Not by the humans.
The Thirty-Seven Minutes is a work of fiction. Everything in it is made up. The logging library is current. The SharePoint site is real. Maureen has marked this article green. The sprint retrospective is on track.
Everything is probably fine.
Scott Gardner is a Lead Enterprise Security Architect, the founder of NinjaSignal, and the author of Everything Is Probably Fine — a book about what happens when nobody checks whether things are actually fine. He has been working in information security for thirty years and is, so far, still right about the logging library.
Threat intelligence every morning — new victims, new groups, what matters, in plain English. Free, with receipts.
Subscribe to the Daily →
Scott Gardner ·