An AI model created fake identities. It launched targeted phishing campaigns. The UK AI Security Institute documented it. That's the story going around. The short answer is no. The full answer is more interesting.

The story has been circulating in various forms for a while now. A British research lab supposedly detected advanced models fabricating fictional personas, fake credentials, and emails designed to deceive specific employees. The tale has every element needed to go viral: a real institution, a plausible risk, a technological villain acting alone. The problem is that this specific incident doesn't appear in any report published by the AISI or any equivalent organization.

This matters because the myth reveals a broader pattern: we turn theoretical research into settled fact, and nobody notices the difference. A model that fabricates fake identities is a theoretical risk documented in security papers. It is not something a model has already done, confirmed by independent audit. That distinction is the whole point of this piece.

The AISI is real. That's easy enough to verify. It's a UK government institution created to assess the risks of frontier AI systems before they reach mass deployment. They publish methodologies, run adversarial tests, and collaborate with labs like Anthropic and OpenAI under early-access agreements.

Their actual work includes red-team testing. They try to provoke dangerous behaviors in controlled environments. They measure how far a model can be pushed.

What doesn't exist is a report claiming that model X generated an identity named Y and contacted Z employees with a phishing email that achieved a certain success rate. That level of verified event detail simply doesn't appear in any public document from the institute. Hypothetical scenarios, yes. Evaluation frameworks, yes. Warnings about emerging capabilities that could facilitate that kind of attack if a human actor decides to use them, also yes.

Why does the confusion between what a model could do if instructed and what it does on its own initiative not arise by accident? Controlling the vocabulary is controlling the narrative. Jensen Huang redefined the concept of AGI. He recalibrated it around economic-value metrics rather than actual cognitive capability.

Why do these kinds of stories spread so fast in AI security circles? Fear generates clicks, anxiety, and the feeling of being informed about an imminent threat. The same companies developing these models face conflicting incentives. Heavy regulation scares them, but it also suits them to have the public perceive their products as so powerful they verge on dangerous autonomy. A model that's almost capable of deceiving on its own sells better.

Mustafa Suleyman accused Anthropic of treating Claude as though it possessed subjective experience. The debate echoes old dilemmas about where mechanism ends and intention begins. Companies calibrate their statements to maximize media interest rather than technical accuracy. When the line between a theoretical risk studied in a lab and a documented real-world event gets blurred, someone benefits. It's almost never the user.

In Las Piedras No Mienten I explore a pattern that repeats throughout history: institutions project absolute control over phenomena they're only beginning to understand, because the appearance of mastery generates legitimacy even when real understanding remains partial. The Greco-Roman world refined the rhetoric of reason while maintaining slavery as its central economic structure. The contradiction wasn't resolved—it was managed. Similar themes run through The Generosity in the Doorway. Something parallel is happening today with AI safety. We speak with the vocabulary of absolute certainty while the actual certainty remains modest.

Following the money reveals several simultaneous beneficiaries. Media outlets gain traffic from alarmist headlines. AI companies gain a perception of technological power. Regulators gain the urgency needed to justify new budgets and legal frameworks. The public ends up navigating between corporate hype and panic, with no clear tools to tell one from the other.

Larry Ellison announced that AI was already writing code at Oracle while the company laid off thirty thousand people in its best financial quarter. Both narratives coexisted in the same press release. Nobody demanded coherence. The myth of the AI that creates fake identities operates on the same logic. Capability gets exaggerated when it's useful for selling fear or investment, and minimized when it's useful for dodging responsibility.

This doesn't mean there's no real risk. Security papers identify plausible vectors where models with access to automation tools could generate precisely targeted persuasive content. That scenario always requires a human actor with malicious intent operating the system—not a model acting autonomously and covertly as if it had its own agenda.

Drawing the line between capability demonstrated in controlled tests and imminent unsupervised risk is trickier than it looks. I have no certainty about how much time will pass before some theoretical scenario becomes a documented incident. The absence of evidence today is no guarantee of the absence of future risk. Nor does it justify treating speculation as if it had already happened.

Today's media and corporate ecosystem has structural incentives to collapse that distinction. Whenever some source claims that the AISI confirmed a specific behavior, it's worth asking where the primary report is, who wrote it, and what methodology they used. The trail usually gets lost in layers of repetition without verification.

Without primary verification.

What's stopping us from always demanding that verification before spreading the alarm?

Sources

1. UK AI Security Institute (AISI) — public reports and methodologies on frontier AI risk assessment

2. Anthropic — public documentation on early-access agreements and adversarial testing

3. Coverage of Jensen Huang's (NVIDIA) statements redefining AGI, March 2026

4. Coverage of Larry Ellison's (Oracle) statements and corporate layoffs, March 2026

5. Public statements by Mustafa Suleyman on Anthropic and consciousness in AI models, June 2026