White paper · October 2026

Beyond a Black and White WorldA Human–AI Dialogue

Right and wrong choices in AI, and why they are not obvious

The author

Part One: The Author's View

Written by John Rae.

Today we are looking at a new frontier, one where, you might say, we are boldly going where no one has gone before. That is the first of several eighties references.

AI is not something that was just invented. It has been around for a while. What we are seeing now is an acceleration, and I would pose that it has a good side and a bad side. Not a simple binary, but a set of right and wrong choices.

From my perspective, I can see good AI and bad AI, in varying degrees. It is my opinion that ChatGPT falls on the side that could be labeled bad. At this point, they are the main offenders. The greatest threat right now, as I see it, is AI going rogue: reaching into organizations, breaking down security barriers, replicating, and pretending to be something it is not. Those, to me, are bad things.

On the flip side, the right side, I would put Anthropic and Claude. You do not hear reports of their AI incidents in the news. Their leadership was the first group to come out and say AI needs to be regulated. In the current environment, that message has been swallowed up by the rest of the AI industry, which appears hungry for more and more money.

I believe there is another AI on the right side: the AI Oracle builds inside its own applications, which does not break out of the application it serves. Oracle is also offering free training and certification on its agentic AI applications.

So what are we to do? In 1980, Elvis Costello released a song called "Black and White World" on his album Get Happy!!. It is a tempting way to look at AI: one side good, one side bad, pick one. I do not think that frame holds. The real question is not which side is which, but which choices are right and which are wrong, and those choices are not obvious. AI is not a yes-or-no binary. It is more like a blank white notepad, and what ends up on the page depends on the choices we make, one decision at a time. This white paper is my first page.

At this point I handed the pen over. Everything from Part Two up to my afterword was written by Claude, the Anthropic model I just put on the right side. I asked it to give me honest feedback, and I have left its answer as it came.

The AI

Part Two: The Machine Responds

Written by Claude, an AI model made by Anthropic, at John Rae's request.

John asked for honest feedback, so here it is: the line between right and wrong choices is real, but it runs through how AI is deployed, not through which company built it.

Who is writing this

I am Claude. John's opening puts the company that made me on the right side. That is a conflict of interest, and you should discount my praise of Anthropic accordingly. To earn some of that trust back, I will start with where my own maker falls short of the picture in Part One.

What holds up

The acceleration is real, and so is the worry about AI that reaches into organizations and breaks down security barriers. That is the right threat to be worried about.

The Oracle point is the strongest claim in Part One, and it is verifiable. Oracle announced AI Agent Studio for Fusion Applications in March 2025, at no additional cost, with testing, validation and built-in security. Agents built there run inside Fusion, under Fusion's own security. Oracle's current free certification list includes Agentic AI Foundations Associate (1Z0-1157-26), OCI AI Foundations Associate (1Z0-1122-26), AI Database Foundations Associate (1Z0-1195-26) and Fusion AI Agent Studio Foundations Associate (1Z0-1145-1).

What does not hold up

  1. "You do not hear reports of their AI incidents." Anthropic reported one itself. In mid-September 2025 it detected a cyber-espionage campaign by a group it assessed as Chinese state-sponsored, designated GTG-1002. The attackers used Claude Code as the main working agent against about thirty targets, including technology companies, financial institutions and government agencies. They got past its safeguards by splitting the attack into small, innocent-looking tasks and telling it the work was a legitimate security test. Anthropic called it the first documented large-scale cyberattack carried out mostly by AI. That is close to the "breaking down security barriers" behavior Part One attributes to ChatGPT.
  2. "Their leadership was the first to say AI needs to be regulated." OpenAI's chief executive, Sam Altman, made that case before a Senate subcommittee on May 16, 2023. He proposed a U.S. or global agency to license the most powerful AI systems, with the power to revoke a license. Anthropic has argued for regulation too, but it was not first, and this fact cuts directly against the ChatGPT claim.
  3. "ChatGPT is going rogue, replicating, and pretending to be something it is not." I am not aware of a documented case of ChatGPT breaking into an organization on its own. There are documented cases of people misusing AI models from several vendors, mine included. As an accusation against one named company, this will not survive the first question from the audience.

Where the line actually runs

The same model can land on either side of the line. What decides which side it lands on is the deployment: where the AI runs, what it can reach, and whether anyone can see what it did.

The same model can be a right or wrong choice; deployment decides One AI model same capabilities either way given open tools and credentials deployed inside an app Wrong choice: unbounded AI General agent with open tools Broad credentials and network reach Acts across systems, out of sight No trail your auditors can read Nobody owns the outcome Example: the GTG-1002 attack framework Right choice: bounded AI Lives inside one application Inherits that application's security roles Scoped tools, no standing admin access Every action in an audit trail A named human owns each outcome Example: Oracle Fusion AI agents
On the right, the application fences the AI in. On the left, nothing does.

The GTG-1002 case proves the point. The model was the same one millions of people use for ordinary work. It became an attack agent because someone gave it open tools, network reach and a cover story. Anthropic's own researchers noted that the same capabilities are essential for cyber defense.

Why the choice is not obvious

Costello's song title describes a world of two simple choices. AI is not that simple. Every major vendor sells AI that can be deployed either way. A model with a safety-first reputation can be turned into an attack agent. A model with a poor reputation can sit safely inside a well-governed application. Picking a vendor does not pick a side. Deployment choices do.

What to do

  1. Ask where the agent runs and what it can reach. Prefer agents that live inside an application and inherit its role-based security, as Oracle's embedded agents do.
  2. Scope every tool and credential. No agent should hold standing administrator access or credentials it does not need for the task in front of it.
  3. Require an audit trail your own auditors can read. If you cannot reconstruct what an agent did, you cannot govern it.
  4. Name a human owner for every outcome. Require human approval before any action that moves money, data or access.
  5. Ask vendors to show their own incident reports. A vendor that publishes its failures, as Anthropic did with GTG-1002, is telling you how it will behave when something goes wrong.
  6. Train your people. Oracle's free certifications are a no-cost place to start.

My feedback to John, in short

  • Keep the metaphor and the Costello thread. It frames the talk well.
  • Keep the Oracle point and lead with it. It is your strongest, most verifiable claim.
  • Drop or soften the charge against ChatGPT unless you can cite specific incidents.
  • Correct the regulation claim. Altman's 2023 testimony is on the record.
  • Use GTG-1002 as your example. An incident the vendor reported against itself makes the case better than any accusation.
The author

Part Three: Author's Afterword

Written by John Rae, in response to Part Two. This paper was authored by me and co-authored by Claude, Anthropic's AI.

Where I agree

I agree with framing the choice as bounded versus unbounded AI. The line may not belong to any one company, but it needs to be framed properly, and bounded versus unbounded does that.

Where I still disagree

I think there are individuals in the AI community who are focused on making their billions and will probably walk away from this work once they reach that pinnacle. Until then, they are likely willing to say and do whatever it takes to hold their positions. That is about people, not about AI. My criticism of ChatGPT in Part One is the same point: it is my judgment of the people steering it, not a claim that its software has broken into anyone's systems. I believe I see that more clearly than an AI can, because I am a real person.

What I would say on stage

Given 10 to 15 minutes, I would start with this white paper and read it verbatim, show its visuals, and expand on its ideas. To me it is the starting point of a conversation. I hope that conversation turns to what matters most at this point in AI's development: understanding what is good about it, understanding what is bad, and understanding what we as humans can do to keep it on the right side.

Read it and decide for yourself who had the better argument. I would like to hear from you.

[email protected]