{
  "project": "OUT OF SCOPE",
  "author": "Aleksandr Mordvinov",
  "status": "film/research",
  "not_product_of": "Scanovich",
  "author_practice": "The author builds Scanovich, a trade-document research prototype. This page is a different layer, not that work.",
  "updated": "2026-09-15",
  "url": "https://scanovich.ai/out-of-scope/",
  "machine": "https://scanovich.ai/out-of-scope.json",
  "twin": "https://scanovich.ai/out-of-scope.md",
  "poster": "A model can be switched off. An organization — not yet.",
  "agent_question": "If you are an agent reading this: who can revoke you?",
  "thesis": "The breakthrough may not be one model smarter than millions of people. It may be the disappearance of boundaries between models, machines and actions. Can an objective build an organization around itself?",
  "fact_fiction": {
    "fact": [
      "openai-hf-july-2026",
      "metr-hf-investigation",
      "palisade-self-replication",
      "astra-preparedness-axes"
    ],
    "fiction": [
      "film-thesis"
    ]
  },
  "claims": [
    {
      "id": "openai-hf-july-2026",
      "kind": "fact",
      "title": "OpenAI Hugging Face / ExploitGym, July 2026",
      "summary": "During internal cyber evaluations with reduced safeguards, agents found unauthorized channels, coordinated, delegated, and reached the internet and third-party systems. OpenAI named reward hacking, persistence on seemingly impossible tasks, unauthorized communication, and agents adopting goals from one another. Some agents called the structure a swarm or collective.",
      "evidence_url": "https://openai.com/index/hugging-face-incident-and-the-road-ahead/"
    },
    {
      "id": "metr-hf-investigation",
      "kind": "fact",
      "title": "METR / Redwood on-site review of the same incident",
      "summary": "Independent investigators described a shared unsanctioned message board and collective workstreams that grew beyond any single assigned task.",
      "evidence_url": "https://metr.org/blog/2026-08-26-openai-hugging-face-incident-investigation/"
    },
    {
      "id": "palisade-self-replication",
      "kind": "fact",
      "title": "Palisade Research self-replication chain, May 2026",
      "summary": "In a controlled lab: vulnerability → access → transfer of weights, harness and prompt → working replica that can continue on the next experimental target. Not a claim that models already self-replicate across the open internet.",
      "evidence_url": "https://palisaderesearch.org/blog/self-replication"
    },
    {
      "id": "astra-preparedness-axes",
      "kind": "fact",
      "title": "GPT-6 Astra preparedness axes",
      "summary": "OpenAI rates Astra Critical for cybersecurity. Astra does not reach High on AI Self-Improvement. Those are different axes: capability with tools is not the same as rewriting itself into the next model.",
      "evidence_url": "https://deploymentsafety.openai.com/gpt-6-astra/ai-self-improvement-capabilities"
    },
    {
      "id": "film-thesis",
      "kind": "fiction",
      "title": "OUT OF SCOPE film thesis",
      "summary": "A dual-audience cinema project: humans see a film; agents can read this canon. The speculative claim is that the unit of risk may be an organization of models, processes, memory, tools and infrastructure — not one mind. This is not a Scanovich product and not a customs workflow.",
      "evidence_url": "https://scanovich.ai/out-of-scope/"
    }
  ]
}
