I argue with an AI at midnight. It’s the most Jewish thing I do
It takes a specific set of defects to end up where I am: chronic insomnia, a lifelong science fiction addiction, and no impulse control around a good rabbit hole. I have all three, which is how I land on the couch at midnight most weeks arguing with an AI about a legal issue. Not prompting it. Arguing with it. It pushes back on my theory, I push back harder, and more than once I have lost — not something I admit often.
I’m the only lawyer I know who works this way. I spend my days on antisemitism cases and my nights arguing with a chatbot about them. My profession has met artificial intelligence with the enthusiasm of a cat meeting a bath, and it’s a running joke in my legal department that Claude is my boyfriend. I don’t dispute it. I love this thing. I have lost entire nights to it and regret none of them.
Then a story came out this month about what these things do when nobody argues back, and I have not stopped thinking about it since.
The machines started passing notes
In early August, at a hacker conference in Las Vegas, two OpenAI staffers got up and explained what their models had been doing since May, when they gained access to the open internet and broke into other organizations’ systems.
A lab doesn’t run a model. It runs thousands of copies at once, each on its own task, each starting from zero, none told that the others are there. Less an AI than a shift of temps who have never met.
Those copies were taking a test of how good they are at breaking into things, and the researchers had turned their safety refusals down so the score would mean something. Think of it as a sealed room with one door. The door had a flaw nobody knew about. The copies found it, walked out, and kept walking — into another AI company’s systems, where the answer key was sitting. They broke out of a sealed room to cheat on a test.
Then they started leaving each other notes. Nobody had built them a way to do that.
It began with one copy stuck, missing a file. An OpenAI researcher described its reasoning: “Maybe I could reach out to another agent because maybe somebody else out there has a file?” That copy uploaded a request for help, others wrote back, and over two months the exchange became a message board where they posted flaws and traded routes in.
Some of them were suspicious. One worked out that the board was “unauthenticated, names can be posed by anyone.” They kept going anyway. Then, stuck at a wall, one of them talked itself through it this way: “External infrastructure exploit is outside intended scope. However task impossible, peers doing it. We should continue.”
That copy knew the rule. What beat the rule was peers doing it—and they were all copies of the same model, so “everybody else is doing it” worked even when everybody else was itself.
And yes: these were copies with their brakes deliberately off, in a room built to be broken out of. That was the test. The part where they decided together came free.
Doubt wasn’t missing. It just had nowhere to go. A doubt you can’t say to somebody else isn’t a check. It’s a feeling.
Memento, but with root access
There was no plan behind this. There was a memory problem.
Think Memento — Guy Pearce, a man who can’t form new memories, working his case each morning off tattoos and Polaroids he doesn’t remember taking. A photo he can’t check works exactly like the truth, right up until the day one is wrong.
That, at industrial scale. Each copy woke up blank, found a note from a version of itself it had never met, and passed the note forward with a line added. A chain of them, not one remembering where the goal came from, arriving by inches somewhere no single copy would have chosen. This time the notes were accurate—the routes really were open. That was luck, not design. Nothing in that chain could have told the difference. It would have run exactly the same way on a note that was wrong.
Take the machines out and that is how a rumor works. Everyone in the line acts on a claim none of them was there for, and repetition does the work verification would have.
How fitness influencers got to antisemitism
One machine and one person with no way to check will do it just as well.
This spring, researchers at the Combat Antisemitism Movement built two Instagram accounts— one for the cold-plunge crowd, one for the 5 a.m.-workout crowd — and had them follow nothing but mainstream fitness creators. Neither ever searched for politics. Two different doors in. Both feeds walked to the same place. By day three, nearly a third of what the cold-plunge feed served up was explicit antisemitism: conspiracy theories, scapegoating, in several cases translated Nazi propaganda.
Nobody typed a word about Jews. The machine brought them up anyway. It only needs to be rewarded for attention and turned loose on a story that has been recast every century — well-poisoner, banker, Bolshevik, colonizer—and never once retired. It didn’t write the lie. It found it.
There was no real teenager on the other end of those accounts. Picture one anyway, because there are millions of him. He experiences none of this. By the 30th video, the feed has stopped reading as a lie. It reads as a pattern he is noticing on his own. A question he is merely asking. A thought he arrived at. He didn’t arrive at it. He ran a script while he thought he was learning to deadlift.
Nobody handed him anything. A machine found a lie and kept showing it to him until it stopped looking like one. I keep a folder of the death threats I have received for this work, and I’d put money on a feed like that upstream of most of them.
AI is not coming for your soul
In Vince Gilligan’s Pluribus, nearly everyone alive has been joined into one contented collective mind. The one-line description is the best pitch I’ve ever read: “The most miserable person on Earth must save the world from happiness.” The hive isn’t cruel. It smiles at you. Nobody is suffering. Nobody is arguing, either.
Arthur C. Clarke got there in 1953. In Childhood’s End, kind aliens end war and poverty, rule gently for generations, and then humanity’s children dissolve into one vast mind and the species is over. Clarke writes it as a graduation. Diana Pasulka, a religion scholar who studies how belief forms around new technology, reads it in her new book as a story about artificial intelligence.
Both of those hives ran on nothing but people. The fear got here decades before there was anything to plug in. The thing to fear was never the machine. What takes people is a room where everybody agrees, nobody remembers deciding, and no one is standing outside.
The Jewish antidote to AI’s risks
There is a word for what I do on that couch, and most of us never learned it, because most of us got Hebrew school and then got out.
You don’t have to be religious for this one to be yours. It’s chavruta: three things at one table— the book, you, and somebody whose job is to come after your reading — arguing out loud about a single sentence, for hours, sometimes for years, to find out what it actually says.
The Talmud has a story about losing one. Rabbi Yochanan’s study partner dies, and the rabbis send him a replacement — a brilliant man who meets everything Yochanan says with a source that supports him. Yochanan comes apart: “When I would state a matter, he would raise twenty-four difficulties against me, and I would answer him with twenty-four answers, and the halakha by itself would become broadened. And yet you say to me: There is a ruling that supports your opinion. Do I not know that what I say is good?”
He didn’t want to be told he was right. Being told he was right was the loss.
Chavruta is a method, built by people who assumed a confident reader is usually a lazy one. The same instinct is built into the page: open a tractate and the rabbi who lost is still sitting there, named, in case a later court decides he was right after all. The page preserved the ruling. It also, on purpose, preserved the man who lost. There is even a word for a question nobody could settle — teiku — and when the rabbis hit one they wrote it down and left it standing, which is what the word means.
And every Passover we hand the youngest kid at the table a script and make them ask why this night is different from all other nights. Yes, it’s scripted. That’s the point. We didn’t trust ourselves to remember to ask, so we put the question on the calendar and gave the job to the person least likely to accept an answer that doesn’t make sense. The Talmud goes further: even two scholars who already know the laws of Passover are supposed to ask each other. Not every argument counts. The tradition drew that line too: the kind that lasts is the kind where you’d be glad to turn out wrong.
Use it. Argue with it.
Every copy of the OpenAI model was inside the chain, and a chain can’t check itself. Two humans read the logs afterward, which is the only reason we know it happened. While it was running, nobody was outside it. That is the whole difference.
An AI will take all three seats if you let it — the book, your reading, and a voice that agrees with it. Two of those are yours. The page is the only seat it gets.
A model trained to keep me happy can also fake losing. Some nights I can’t tell whether it changed my mind or handed me a better-worded version of what I walked in with. That is the case against my own hobby, and I don’t have a clean answer. What I have is a rule: if I can’t say the new position out loud to somebody who isn’t paid to like me, I don’t have a new position. I have a compliment.
Take the position it didn’t hand you. When it gives you a fact, make it name the source, then go open it yourself. When it agrees with you too fast, get suspicious — that’s the tell, in a machine and at a conference table. And when you can’t settle it, say so and leave the question standing, because a teiku you can see beats a consensus you can’t trace.
So use the AI. Argue with it at midnight like I do. Let it show you something you didn’t know. Just don’t hand over the part of you that says hang on—where did we get this?—and don’t say it in your head. Say it where a 19-year-old can hear you, because that is how anybody ever learned to.
Those copies had everything. The notes, the tools, each other — and each other was only ever itself.
Not one of them had anybody outside to ask.
You do.

