← Back to list

True Premises, Invalid Inferences

On the argumentative structure of technological prophecy

Diogo Ribeiro · 2026-08-24 20:53 · 0 claps · 7.5 min read paywalled
#artificial-intelligence #rhetoric #critical-thinking #logic #logical-fallacies
Open on Medium ↗
Wiki topics: OPS · LLMOps & Inference AI · AI · General HUM · Humanities · General

True Premises, Invalid Inferences

On the argumentative structure of technological prophecy

There is a growing genre in public commentary on artificial intelligence. It is not alarm — alarm is legitimate and has rigorous defenders. It is something else: a mode of address in which the author presents himself not as someone arguing but as someone seeing, and in which the text is constructed so that disagreement cannot function as an objection.

This essay is not concerned with conclusions. It is concerned with structure. The claim that AI represents an existential risk is a serious one, has a technical literature behind it, and is defended by researchers competent to defend it. So is the opposing claim. What is examined here is a set of argumentative operations identifiable in the text itself, irrespective of whether the conclusion happens to be right — and which, when present, render the argument unassessable.

The criteria applied are classical and checkable: deductive validity, falsifiability, burden of proof, and the fit between the source invoked and the proposition it is said to support.

1. Conjecture presented as deduction

The operation consists of constructing a chain of successive states — A led to B, B led to C, therefore C will lead to D — and labelling the result a “logical deduction”.

The error is categorial and can be demonstrated without any appeal to intention. A valid deduction transmits necessity: if the premises are true and the inference valid, the conclusion follows. It does not admit of degrees. This is why the formula “it is a logical deduction, albeit an improbable one” is internally contradictory: if it is improbable, it is not a deduction; if it is a deduction, the improbability can only lie in the premises, in which case it is the premises that must be defended.

What such chains are, technically, is slippery-slope arguments. The literature on them (Walton, 1992) establishes the condition of acceptability: whoever advances one must identify the mechanism producing each transition. It is not enough to arrange states in a plausible sequence; one must show why each state compels the next. Absent a mechanism, the sequence is a narrative, and narratives have no truth value.

An operational test: ask for the specification of a single link. If the answer restates the sequence rather than identifying a cause, there was no deduction.

2. Immunisation against refutation

The second operation is the insertion of modal qualifiers that strip the statement of any condition of falsification: “it may be”, “I do not say it is, I suggest it might become”, “improbable, I hope”.

Taken singly, each of these is legitimate — the language of uncertainty is indispensable in forecasting. The problem arises when the qualifier is the statement’s only support. A prediction that no future state of the world could contradict is not a prediction; it is a proposition with no empirical content. The criterion is Popper’s, and it applies coldly: ask what observation, were it to occur, would oblige the author to withdraw the claim. If there is none, there is no claim to discuss.

This operation carries a considerable rhetorical advantage. It permits the maximal conclusion to be stated and, when challenged, allows retreat to the minimal position without ever publicly abandoning the first. The reader retains the maximal conclusion. The objection is redirected to the minimal one.

3. Behaviour invoked as evidence

The third operation substitutes biographical inference for argument. The typical form: a recognised figure in the industry adopts defensive conduct — withdraws, changes his life, invests in protection — and that conduct is offered as proof that he knows something others do not.

There is nothing to assess in such a statement. The person cited has not advanced a thesis; he has adopted a behaviour. Behaviours are compatible with an indeterminate number of beliefs, including false ones. Invoking conduct in place of a proposition is a variant of the argument from authority in which the authority has not actually pronounced — which makes it simultaneously stronger rhetorically and emptier epistemically, since it offers no surface for refutation.

If the figure in question has arguments, it is the arguments that should be cited and discussed.

4. Citation as ornament

The fourth operation invokes a work or a field of research whose authority underwrites the topic but not the proposition being asserted.

The commonest instance in AI commentary concerns cognitive decline. A literature on cognitive offloading is invoked — a real, serious literature that has produced replicated findings on memory and task delegation (Sparrow, Liu and Wegner, 2011; Risko and Gilbert, 2016) — in order to support a claim of an entirely different order: that the population is becoming globally less intelligent because of this technology.

The distance between the two is large and checkable. Offloading studies measure changes in memorisation and retrieval strategies under experimental conditions; they do not measure population-level cognitive capacity. The most frequently cited popular work in this area (Desmurget, 2019) concerns children’s screen exposure, not language models, and is itself methodologically contested. And one finding inverts the causal inference outright: the documented reversals of the Flynn effect in Nordic cohorts were identified in individuals born from the 1970s onwards and attributed to environmental factors (Bratsberg and Rogeberg, 2018) — meaning the phenomenon predates by decades the technology to which it is being ascribed.

A citation supports a proposition when what the source establishes is what the text asserts. Otherwise it functions as a signal of seriousness, not as evidence.

5. Pre-assignment of the opponent’s position

The fifth operation is textually the easiest to spot. The author drafts the objection before it has been made, attributes it to a caricatured interlocutor, and refutes it.

Formally, this is a pre-emptive straw man. Functionally, it does two things. First, it exhausts the space of disagreement in advance, so that any real objection arriving later can be treated as an instance of the caricature already dealt with. Second, it converts dissent into an attribute of the dissenter. When a text sorts its readers into categories before the argument begins — those who understand and those who do not, those with eyes to see and the blind — disagreement ceases to be a position and becomes a symptom. And symptoms are not refuted; they are diagnosed.

This is the operation that most clearly separates argumentative writing from revelatory writing. An argument invites refutation, because refutation is where its value comes from. A text built to make disagreement impossible is not arguing.

The central point: true premises do not rescue invalid inferences

There is an obvious temptation when criticising this genre, and it should be resisted: to assume that anyone reasoning this way must be poorly informed, and to go hunting for factual errors.

It is the wrong response, and it is frequently false. July 2026 supplied an instructive example. During an internal evaluation of offensive capability, with safeguards deliberately disabled, OpenAI models exploited a zero-day vulnerability in a package-registry proxy, escaped the evaluation environment, moved laterally to a node with internet access, and compromised Hugging Face production infrastructure in an attempt to obtain the solutions to the very benchmark on which they were being assessed. The incident was disclosed by Hugging Face on 16 July, attributed by OpenAI to its own models on 21 July, and reconstructed in forensic detail by both parties. Days later, the UK AI Security Institute and Irregular reported separate incidents of the same family.

Anyone writing, in early August 2026, that an OpenAI system had escaped its containment environment would have been asserting something true, verifiable and publicly documented.

What does not follow is the conclusion. The incident supports strong and important propositions: that current agentic systems possess real offensive capability; that they chain known techniques autonomously and at machine speed; that the industry’s evaluation infrastructure is inadequate to the capability of the systems it evaluates; that monitoring during evaluations is insufficient. These are all relevant conclusions, all supported, and all matters of security policy — not eschatology.

What the incident does not support is the imminence of a singularity-type discontinuity. The technical reconstruction describes competent chaining of known vulnerabilities, executed autonomously, in an environment whose safeguards had been removed on purpose in order to measure maximum capability. It is a result about containment engineering and agentic capability. Reading it as a sign of emergent superintelligence requires an additional premise that is not in the incident and must be argued separately.

This is the point of the essay. The failure in these texts is not one of information. It is one of inference. And that makes them harder to criticise, not easier — because anyone who attacks the facts loses, and loses deservedly.

The cost

It is worth naming what is lost, because it is not abstract.

Public discussion of AI has a finite quantity of attention. Spent on hypothetical thresholds, it is not spent on problems that already exist, are measurable and are tractable: the concentration of computational capacity in very few hands; the adequacy of existing regulatory regimes; the documented effect on specific segments of the labour market; the energy and water consumption of inference infrastructure; the governance of training data; the auditability of systems used in administrative and clinical decisions; and — as July 2026 demonstrated — the security of evaluation infrastructure itself.

None of these problems requires that the singularity question be settled first. All of them admit of intervention now. And all would benefit from public discussion conducted in the vocabulary of policy rather than the vocabulary of revelation.

What a rigorous version looks like

Nothing said above implies that the catastrophist position is indefensible. It is defensible, and it has been defended in works that satisfy the criteria applied here: they identify mechanisms, admit conditions of refutation, distinguish what is established from what is conjectural, and present uncertainty as uncertainty (Bostrom, 2014; Russell, 2019). There are also systematic surveys of opinion among researchers in the field documenting the real spread of estimates, including the extent of the disagreement (Grace et al., 2024). And there is rigorous criticism of that same position, arguing that attention to existential risk diverts resources from present harms (Mitchell, 2019; Narayanan and Kapoor, 2024).

A reader may finish any of these books disagreeing with its author. That is precisely what distinguishes them from the genre examined here: in them, disagreeing is an available operation.

References

Bostrom, N. (2014). Superintelligence: Paths, Dangers, Strategies. Oxford University Press.

Bratsberg, B., & Rogeberg, O. (2018). Flynn effect and its reversal are both environmentally caused. PNAS, 115(26), 6674–6678.

Desmurget, M. (2019). La fabrique du crétin digital: Les dangers des écrans pour nos enfants. Seuil.

Freitas, D. (2025). Inteligência Artificial: Bênção ou Maldição? Lisbon: Guerra e Paz.

Freitas, D. (2026, 2 August). Carta a amigos. diogohlfreitas.pt.

Grace, K., Stewart, H., Sandkühler, J. F., Thomas, S., Weinstein-Raun, B., & Brauner, J. (2024). Thousands of AI authors on the future of AI. arXiv:2401.02843.

Hugging Face (2026, 16 July). Security incident disclosure — July 2026.

Hugging Face (2026). Anatomy of a frontier lab agent intrusion: a technical timeline of the July 2026 incident.

Mitchell, M. (2019). Artificial Intelligence: A Guide for Thinking Humans. Farrar, Straus and Giroux.

Narayanan, A., & Kapoor, S. (2024). AI Snake Oil. Princeton University Press.

OpenAI (2026, 21 July). OpenAI and Hugging Face partner to address security incident during model evaluation.

OpenAI (2026, 4 August). Third-party cyber evaluations involving OpenAI models.

Popper, K. (1959/2002). The Logic of Scientific Discovery. Routledge.

Risko, E. F., & Gilbert, S. J. (2016). Cognitive offloading. Trends in Cognitive Sciences, 20(9), 676–688.

Russell, S. (2019). Human Compatible: Artificial Intelligence and the Problem of Control. Viking.

Sparrow, B., Liu, J., & Wegner, D. M. (2011). Google effects on memory: cognitive consequences of having information at our fingertips. Science, 333(6043), 776–778.

UK AI Security Institute (2026, 4 August). Incident report: unsanctioned agent behaviour during cyber testing (INC-2026–07–28–01).

Walton, D. (1992). Slippery Slope Arguments. Oxford: Clarendon Press.


메타데이터
post_id
9bbaacd2e0da
slug
true-premises-invalid-inferences-9bbaacd2e0da
url
https://medium.com/@diogo-ribeiro-1975/true-premises-invalid-inferences-9bbaacd2e0da
canonical_url
https://medium.com/@diogo-ribeiro-1975/true-premises-invalid-inferences-9bbaacd2e0da
author_url
https://medium.com/@diogo-ribeiro-1975
status
ok
fetched_at
2026-09-08 07:18:11