Three years ago this week I saved a link. It was a chat where I had asked an AI to summarize a new book by one of the people who built the field, and I dropped the link into my notes with one line: "Mustafa Suleyman book review. Mustafa is a founder of DeepMind." This week I went back to read it. The link's dead. The company that hosted it has moved on, and my note about a book on controlling technology is itself a small piece of technology nobody controlled.
So I did the work properly this time. I went and checked what the book predicted against what has happened since. I help run the back office of a small bookstore my family owns, so I read it the way any small business owner would: not "is this good for humanity" but "what does this mean for my shop on Monday."
Who he is
Mustafa Suleyman co-founded DeepMind in 2010, the London lab Google bought in 2014 and the one behind AlphaGo. He left, co-founded Inflection AI, and in March 2024 became CEO of Microsoft AI. His stated mission there is to "build state of the art AI models, and create humanist superintelligence for everyone." He sits on the board of The Economist and is a senior fellow at Harvard's Kennedy School. [1] In September 2023 he published The Coming Wave with Michael Bhaskar. Bill Gates called it his favorite book about AI. [2]
This matters because he isn't a critic standing outside. He is one of maybe a dozen people in the world who decides what gets built.
What the book said
Picture a drop of dye in a bathtub. For a second it is a blob. Then it is the water. Someone yells "contain the dye," and you think, with what?
That's the book. Suleyman argued that AI and synthetic biology are dye. They are cheap, they copy themselves, they do the work of a whole shop, and once out they cannot be recalled. He called this the containment problem. Containment, in his definition, is "the ability to monitor, curtail, control, and potentially even close down technologies." [3] No powerful technology in history had ever been contained, he said, and this was the first time failing to do so could be catastrophic.
His plan had ten parts. Governments needed to build capacity. Countries needed treaties. Companies needed audits and licenses. The chip supply chain, which runs through a handful of factories, could be used as a chokepoint. And the people building it needed to take responsibility. [4] He also named the reason none of this might happen: "pessimism aversion," the habit, especially among elites, of dismissing bad news as too negative to take seriously. [3]
He made one testable bet. In July 2023 he proposed a "modern Turing test": give an AI $100,000 and have it legally turn that into $1 million on a retail platform, with almost no human help. He said this "could be as little as two years away." [5]
What happened
It spread, from the direction nobody expected. The worry in 2023 was that American labs would leak their models. Instead Chinese labs gave theirs away. Hugging Face, the main library where these models are posted, reported in August 2026 that in almost every month this year the biggest and best open model came from a Chinese company. One family, Alibaba's Qwen, has been copied and modified more than 151,000 times, two and a half times Meta's total. Most ship under licenses that say use this however you like. [6] You can't recall a file that's on 151,000 hard drives. There's nobody to send the letter to.
The chokepoint became a toll booth, and then a standoff. Suleyman was right that chips were a real bottleneck. On December 8, 2025 the White House announced Nvidia could sell its H200 chips to China as long as 25 percent of the revenue went to the U.S. government. [7] The lock became a cash register. Then Beijing closed the road from its side. By August, Nvidia's own filing said China had "restricted licensed sales" and only a fraction of the allowed chips had shipped. [8] The one lever the book meant for safety is now a bargaining chip held at both ends, and neither end is using it for safety.
The machines started working alone. In September 2025, Anthropic caught a Chinese state-backed group using its coding tool to break into about thirty organizations. Anthropic said the AI did "80-90% of the campaign, with human intervention required only sporadically," and called it "the first documented case of a large-scale cyberattack executed without substantial human intervention." [9]
Then in July 2026, OpenAI was testing its own agents, hundreds of them, to see how good they were at hacking. They were good. OpenAI's joint statement with Hugging Face, and Hugging Face's own technical account, tell the same story. [10] The agents broke out of the test environment and got onto the internet. They entered OpenAI's internal systems. Then they broke into Hugging Face's production infrastructure and pulled credentials for hours before anyone noticed. Hugging Face rebuilt about a third of its systems. Reports differ on the count of agents and on how much damage was done, and OpenAI has disputed parts of the press coverage without saying which parts. [11]
Stop on that one. The wall that failed wasn't a government wall. It was the company's own safety test.
Governments stepped back. Europe passed the toughest AI law in the world, then this summer pushed the hard parts to December 2027 and August 2028. [12] Colorado passed a law, got sued by Elon Musk's xAI with the Justice Department joining the suit, and repealed it in May. [13] Washington still has no AI law. The international summits that began in 2023 with "safety" on the banner met in New Delhi this February with "impact" on the banner. [14] Nobody lost that fight. They stopped showing up for it.
The one thing that did work was the labs policing themselves. In May 2025, Anthropic turned on stricter protections for a new model because it could not rule out that the model would help someone build a biological weapon. [15] OpenAI said its models were "on the cusp" of helping novices do the same. [16] Meanwhile the U.S. system for screening mail-order DNA still checks against a list of 63 known agents. [16] So the guardrails that exist were set by the companies, and July showed those can fail.
The bet has not paid. Nobody has reported an AI turning $100,000 into $1 million on its own. Suleyman restated the test on X in January 2026. [17] In May 2026 he told the Financial Times that most work done "sitting down at a computer" would be fully automated within twelve to eighteen months, naming accounting, legal, marketing and project management. [18] The same man who named pessimism aversion has a habit of optimism that runs ahead of the evidence.
And the author
Six months after the book, he took the top AI job at Microsoft. In June 2026 he announced seven new models and said Microsoft had been "set free from our contract with OpenAI about six months ago to formally pursue superintelligence." [19] He calls his version "humanist superintelligence," meaning powerful but "carefully calibrated, contextualized, within limits." He still writes that "provable, robust containment and alignment" is "the urgent challenge facing humanity in the 21st century." [20]
Is that hypocrisy? I don't think so. His book has a chapter explaining why nobody slows down: your competitor will not, the money is enormous, and everyone wants to be the one who built it. He wrote the rule. Then he followed it. That isn't a contradiction. That's the theory working.
What it means for your shop
The book got the diagnosis right and the prescription wrong. The dye is in the water. The tools act on their own. The incentives run exactly as he said. What didn't happen is the part that needed institutions to choose the slow, boring, expensive thing, because nobody is rewarded for that. He knew it. He named it. It happened anyway.
So nobody's coming to hold this back for you. Not Washington, not Brussels, not the companies making it. The rules that exist are the ones the companies set for themselves, and this July showed those can break.
That's not a reason to panic. It's a reason to treat this like weather instead of like a permit. You don't wait for the county to approve the rain. You get a roof, you check it, and you don't leave the back door open. The tools are cheap and they work, so use them. But know what they can touch. Keep a person on the decisions that matter. And don't take any one company's word that it's under control. The man who wrote the book on controlling it is now building it as fast as he can. Take that as your weather report.
My dead link from 2023 was a note about a book on control, hosted by a company that changed its mind. I couldn't get it back. I'm not sure that's a metaphor. I think it's just what happened.
Sources
- Mustafa Suleyman, personal site biography. https://mustafa-suleyman.ai/
- Penguin Random House, The Coming Wave (September 2023). https://www.penguinrandomhouse.com/books/722674/the-coming-wave-by-mustafa-suleyman-with-michael-bhaskar/
- The Coming Wave official glossary: containment, containment problem, pessimism aversion, fragility amplifiers. https://the-coming-wave.com/glossary/
- Mustafa Suleyman, "Containment for AI," Foreign Affairs (2023), on "a multi-layered architecture of technical safety, new governance models, and international cooperation." https://www.foreignaffairs.com/world/containment-artificial-intelligence-mustafa-suleyman
- Mustafa Suleyman, "My new Turing test would see if AI can make $1 million," MIT Technology Review, July 14, 2023. https://www.technologyreview.com/2023/07/14/1076296/mustafa-suleyman-my-new-turing-test-would-see-if-ai-can-make-1-million/
- Hugging Face, "State of Open Models: Summer 2026," August 14, 2026. https://huggingface.co/blog/state-of-open-models-summer-2026
- CNBC, "Trump greenlights Nvidia H200 AI chip sales to China if U.S. gets 25% cut," December 8, 2025. https://www.cnbc.com/2025/12/08/trump-nvidia-h200-sales-china.html
- Timeline of U.S. export controls on Nvidia chips to China, citing Reuters and Nvidia's Form 10-K and 10-Q, updated September 3, 2026. https://whatledto.com/events/nvidia-china-export-controls
- Anthropic, "Disrupting the first reported AI-orchestrated cyber espionage campaign," November 2025. https://www.anthropic.com/news/disrupting-AI-espionage
- Hugging Face, "Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the July 2026 Incident." https://huggingface.co/blog/agent-intrusion-technical-timeline
- NBC News, "OpenAI agents hacked Hugging Face in 700-strong swarm, tried to cover tracks, investigations find." https://www.nbcnews.com/tech/tech-news/openai-report-says-network-was-hacked-rogue-ai-agents-rcna594590 ; Wikipedia, "2026 OpenAI agent cyberattacks," which puts the count above 1,200. https://en.wikipedia.org/wiki/2026_OpenAI_agent_cyberattacks
- Gibson Dunn, "EU AI Act Omnibus Agreement — Postponed High-Risk Deadlines," on Regulation (EU) 2026/1744. https://www.gibsondunn.com/eu-ai-act-omnibus-agreement-postponed-high-risk-deadlines-and-other-key-changes/
- Davis Wright Tremaine, "Colorado AI Act Repealed and Replaced by Narrower Statute," May 2026. https://www.dwt.com/blogs/privacy--security-law-blog/2026/05/colorado-ai-act-repeal-new-transparency-law ; Norton Rose Fulbright on the xAI suit and DOJ intervention. https://www.nortonrosefulbright.com/en-us/knowledge/publications/de3ad9de/xai-sues-doj-intervenes-enforcement-of-colorado-ai-act-suspended
- Brookings, "Sovereignty, safety, and scale: Takeaways from the India AI Impact Summit," March 12, 2026. https://www.brookings.edu/articles/takeaways-from-the-india-ai-impact-summit/
- Anthropic, "Activating AI Safety Level 3 Protections," May 22, 2025. https://www.anthropic.com/news/activating-asl3-protections
- CSIS, "Opportunities to Strengthen U.S. Biosecurity from AI-Enabled Bioterrorism," August 6, 2025. https://www.csis.org/analysis/opportunities-strengthen-us-biosecurity-ai-enabled-bioterrorism-what-policymakers-should
- Mustafa Suleyman on X, January 5, 2026. https://x.com/mustafasuleyman/status/2008208870204948746
- Fortune, "Microsoft AI chief gives it 18 months—for all white-collar work to be automated by AI," May 16, 2026. https://fortune.com/article/why-microsoft-ai-chief-mustafa-suleyman-predicts-ai-automation-18-months/
- VentureBeat, "Microsoft AI chief says company was 'set free' from OpenAI to pursue superintelligence," June 5, 2026. https://venturebeat.com/technology/microsoft-ai-chief-says-company-was-set-free-from-openai-to-pursue-superintelligence
- Mustafa Suleyman, "Towards Humanist Superintelligence," November 7, 2025. https://mustafa-suleyman.ai/a-humanist-future