Every original-thesis post this blog publishes has to commit to a dated prediction and say what would prove it wrong, or it does not get published. All of them are here, settled or not.
Past due, no verdict
said it would be true by 2026-06
By June 2026, at least one major AI incident in an under-reported category (e.g., environmental harm or overreliance) will be revealed through a non-traditional source (e.g., academic paper, whistleblower, or citizen report) that the trade press had missed entirely.
The argument it came from: The concentration of AI incident reporting in just five legal and security trade outlets means that the AI risk landscape is being shaped by the legal profession's and security vendors' interests, not by actual system failures, and this is systematically hiding the most consequential risks like overreliance and environmental harm.
What would prove it wrong: No such incident emerges, and the trade press continues to be the primary source for all consequential AI incidents.
Read the post that made this call →
Open
said it would be true by 2027-03
By 2027-03, at least one major EU-based AI developer will publicly announce a reduction in generative AI features for EU users, citing the NCII/CSAM ban's compliance burden, and will relocate development to a non-EU jurisdiction.
The argument it came from: The EU AI Act's NCII/CSAM ban (effective 2026-12-02) will create a 'false positive crisis' for legitimate AI developers, because the ban's strict liability for generating prohibited content will force developers to over-filter outputs, and the incident data shows that 'genai' stories have dropped by 8 in the last 45 days—evidence that developers are already self-censoring, which will suppress legitimate use cases and drive innovation offshore.
What would prove it wrong: No such announcement occurs, and EU-based generative AI usage and development continues to grow at the same rate as before the ban.
Read the post that made this call →
Open
said it would be true by 2027-02
By 2027-02, the average salary for an AI model-risk validator in North America will have risen by at least 25%, and at least 20% of OSFI-regulated institutions will publicly warn of compliance delays.
The argument it came from: The OSFI Guideline E-23, effective 2027-05, will force Canadian financial institutions to treat AI models as regulated 'models' under existing model-risk management, and this will create a talent bottleneck that drives up compliance costs by 40% for early adopters, a cost that is not being budgeted for.
What would prove it wrong: If salaries rise less than 10% or no institution warns of delays, the talent bottleneck is overstated.
Read the post that made this call →
Open
said it would be true by 2027-01
By 2027-01, at least one major AI governance framework will add 'memory manipulation' or 'agent tool invocation' as a named risk category, directly borrowing from security research.
The argument it came from: The security community is 18 months ahead of the governance community on AI risk, and the gap is not a lag but a structural misalignment: security writes about actively exploited vulnerabilities and supply chain attacks, while governance writes about privacy and fairness, meaning the risk teams are defending against yesterday's threats while the attackers have already moved to agentic and memory-based attacks.
What would prove it wrong: If governance frameworks continue to ignore these attack vectors, the structural gap claim is overstated.
Read the post that made this call →
Open
said it would be true by 2027-04
By 2027-04-01, legal commentary and CPPA guidance will reveal that companies with large language models are claiming they are exempt from ADMT opt-out requirements by asserting 'human-in-the-loop review,' while companies with simpler automated scoring systems are being forced to comply—and the ratio of ADMT exemption claims for neural models vs. rule-based systems will be at least 3:1 in published compliance guidance.
The argument it came from: The 2027 California ADMT opt-out and pre-use notice requirements will create a perverse incentive for companies to deploy less transparent, less explainable AI models—because a model that cannot articulate why it made a decision is easier to claim is 'not subject to ADMT' than a rule-based model whose logic is auditable and therefore demonstrably automated.
What would prove it wrong: If the CPPA's final ADMT regulations explicitly state that any model that generates a decision affecting a consumer is subject to opt-out regardless of human review, and companies with black-box models are found to be complying at the same rate as those with transparent systems, this claim is wrong.
Read the post that made this call →
Open
said it would be true by 2027-06
By 2027-06, at least one major AI governance framework will explicitly incorporate MITRE ATLAS techniques into its risk taxonomy, and public incident reporting will start citing these techniques.
The argument it came from: The attack techniques with documented real-world cases (e.g., LLM Prompt Crafting, 22 cases) are absent from the news window because the governance world is focused on privacy and fraud, not on the adversarial techniques that security teams are actively tracking—and this gap means governance frameworks are being built on the wrong threat model.
What would prove it wrong: If no major framework or regulator references ATLAS techniques by then, the misalignment is not being corrected.
Read the post that made this call →
Open
said it would be true by 2028-08
By 2028-08, when the EU AI Act Annex I embedded high-risk obligations apply, at least two major industrial AI deployments will face sudden regulatory halts due to unmeasured robustness failures that never appeared in prior incident feeds.
The argument it came from: The absence of reporting on environmental harm and system robustness is a structural failure of incident databases, not an indicator of zero risk.
What would prove it wrong: If all regulatory halts or enforcement actions under EU AI Act Annex I prior to August 2028 stem exclusively from risks already tracked in current top-five incident categories.
Read the post that made this call →
Open
said it would be true by 2027-03
By 2027-03, public governance incident reports will continue to decline even as total internal AI incidents (as measured by corporate disclosures in securities filings) rise.
The argument it came from: The steep decline in governance-related AI incident reporting is not a sign of improvement but a leading indicator that organizations are shifting incident disclosure from public channels to private legal and compliance workflows ahead of enforceable deadlines.
What would prove it wrong: If public governance incident reports increase while compliance reports also rise, the shift hypothesis is wrong.
Read the post that made this call →
Open
said it would be true by 2027-03
By early 2027, at least two major AI incidents will be revealed to have been reported as 'compliance issues' in 2026, with the underlying vulnerability still unpatched.
The argument it came from: The collapse in reported AI incident volume (from 450 to 344 stories) is not a decline in risk but a migration of incidents into the 'compliance' category, indicating that organizations are re-labeling failures to fit regulatory checklists rather than fixing underlying system flaws.
What would prove it wrong: If a retrospective audit of 2026 incident reports shows no systematic re-labeling from governance to compliance categories.
Read the post that made this call →
Open
said it would be true by 2028-01
Publicly disclosed internal AI algorithm failures by Fortune 500 companies operating in California will decline by at least 25% in the twelve months following the January 2027 CPPA effective date.
The argument it came from: The impending enforcement of the California CPPA ADMT rules in early 2027 will cause enterprises to aggressively suppress internal AI incident logging to avoid creating discoverable compliance evidence.
What would prove it wrong: If public disclosures of internal AI algorithm failures by Fortune 500 companies increase or remain flat through January 2028.
Read the post that made this call →