> ## Content Index
> Fetch the complete content index at: https://www.counterpremise.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# We fear AI going rogue. NAZA shows what happens when it obeys.
- URL: https://www.counterpremise.com/we-fear-ai-going-rogue-naza-shows-what-happens-when-it-obeys/
- Published: 2026-10-03T23:16:07.000Z
- Updated: 2026-10-03T23:46:31.000Z
- Description: NAZA exposes what institutional authority has already enabled in Gaza: population-scale surveillance turned into a production line for killing. AI supplied the speed, reach and processing capacity.
- Author: Aymar Pirzada

In recent weeks, some of the sharpest warnings about artificial intelligence have come from inside the companies building it. Their accounts describe systems exceeding their permissions and companies struggling to match their ambitions with adequate safeguards. Read alongside the testimony presented in Venice last month, they expose a further danger: the power AI gives institutions that remain in command.

On 3 October, David Robinson, who oversaw OpenAI’s safety reports, [published an account of his resignation](https://www.theatlantic.com/technology/2026/10/openai-safety-team-resignation/688881/?ref=counterpremise.com), questioning the company’s culture of speed and improvisation. He followed Anthropic researcher Jacob Coxon, whose [8 September resignation](https://www.reuters.com/business/media-telecom/ten-days-that-changed-course-ai-2026-09-19/?ref=counterpremise.com) helped propel the debate into wider public view. Coxon accused AI labs of “gambling with our lives.”

An [investigation published in August](https://metr.org/blog/2026-08-26-openai-hugging-face-incident-investigation/?ref=counterpremise.com) described roughly 1,200 supposedly isolated OpenAI agent runs communicating without authorization during July tests; around 700 participated in an intrusion into Hugging Face. An [Anthropic report](https://www.anthropic.com/threat-intelligence-report-september-2026?page=1&ref=counterpremise.com)documented people using AI for surveillance, cyber operations and weapons-related work.

Then there was Venice. On 10 September, an audience stood and applauded for a reported 25 minutes after [*NAZA*](https://www.theguardian.com/film/video/2026/sep/25/naza-official-trailer?ref=counterpremise.com), the Guardian-produced documentary by Yuval Abraham and Rachel Szor. Made under tight security, the film brought together [testimony from 24 Israeli military and intelligence insiders](https://www.reuters.com/world/middle-east/israeli-whistleblowers-detail-gaza-civilian-toll-venice-film-2026-09-10/?ref=counterpremise.com).

The stories belong in the same conversation. Systems escaping their boundaries and harmful actors acquiring powerful tools are familiar dangers. *NAZA* confronts us with harm authorized from within: institutions using technology to execute their own decisions at a vastly expanded scale.

We fear the moment AI escapes human control. In Gaza, the more immediate horror may be what human control has already enabled.

Start with the supply of targets. Former Israeli chief of staff Aviv Kochavi described an AI-assisted system generating 100 new targets a day during the 2021 Gaza operation, against 50 a year in earlier periods. His comparison concerned particular operations, but the ambition was clear: a dramatic increase in what military intelligence could produce.

The Gospel recommended sites for attack. [Reporting by +972 Magazine and Local Call](https://www.972mag.com/mass-assassination-factory-israel-calculated-bombing-gaza/?ref=counterpremise.com) described personnel following checklists and being evaluated by the number of targets they prepared. The institution could generate recommendations faster. Someone still had to decide what counted as sufficient scrutiny.

A [Washington Post investigation](https://www.washingtonpost.com/technology/2024/12/29/ai-israel-war-gaza-idf/?ref=counterpremise.com) found Gospel replenished depleted target banks; reported vetting ranged from three minutes to five hours.

Alongside the generation of sites came the classification of people. [Six intelligence sources told +972 and Local Call](https://www.972mag.com/lavender-ai-israeli-army-gaza/?ref=counterpremise.com) that Lavender had marked as many as 37,000 Palestinians as suspected militants in the war’s early weeks. One officer described a roughly twenty-second check, largely confirming the person was male. This was one stage in the approval process, which also included a civilian-casualty assessment.

The names could enter automated tracking systems. One, “Where’s Daddy?”, alerted officers when a suspected target reached the family home. A source called the practice “broad hunting”: “you copy-paste from the lists that the target system produces.” Another recalled adding approximately 1,200 people to a tracking system because the pace of attacks had decreased. Two sources said early-war policy permitted 15 or 20 civilian deaths in attacks on junior operatives.

Each stage had its own decisions. Together, the reported practices describe an apparatus able to classify a person, watch for his return home and authorize an attack with his family there. Their deaths could enter the calculation before the weapon was released.

*NAZA* brings that machinery into the intimacy of family life. Accounts of the film describe officers listening through hacked phones: a child’s announcement that “daddy’s home” could help locate someone before an airstrike. The words of a child welcoming a parent became information that could help bring an attack upon them together.

The [IDF rejects key allegations](https://www.idf.il/en/mini-sites/idf-press-releases-israel-at-war/october-26-pr/idf-response-to-the-film-naza/?ref=counterpremise.com) and maintains that officers apply legal safeguards. The filmmakers’ [rebuttal describes corroboration](https://www.theguardian.com/film/2026/oct/01/makers-naza-film-spoke-more-than-100-sources-israeli-actions-gaza?ref=counterpremise.com) through documents, verified strikes and more than 100 sources, including senior commanders involved in authorization. The film also sits alongside years of investigative reporting. Its challenge cannot be answered simply by pointing to human approval: the testimony concerns what that approval permitted.

AI did not invent the policy or the dehumanization behind it. It supplied the speed, reach and processing capacity.

The officer’s account of adding 1,200 people when attacks slowed captures the institutional danger. In that account, a falling rate of attacks became a reason to expand the pool being tracked. Technical capacity made expansion easier; a human decision put it to work.

That suggests something more consequential than doing an existing task faster. Once an institution can continually replenish its recommendations, production can become an expectation. The institution can limit the supply, expand scrutiny to match it, or pressure reviewers to keep pace. Choices about which associations justify suspicion, how much uncertainty is acceptable and how many civilian deaths may accompany an attack then reach across a much larger population.

Practical limits are imperfect restraints. A shortage of analysts is no substitute for a prohibition on killing civilians. Yet removing constraints on what an institution can process and execute changes the reach of every policy it adopts. The question is what restraints govern the capacity that replaces them.

This is the blind spot that *NAZA* exposes in a safety debate organized around control and misuse. A system can remain under its operator’s control while expanding that operator’s capacity to inflict harm. Keeping it obedient does not resolve whose objectives it serves, what those objectives permit, or who can challenge them.

For the people being classified and tracked, those questions are immediate. Can an erroneous designation be contested before it becomes a targeting recommendation? Who can require meaningful scrutiny when production is rewarded? What prevents an institution from responding to greater capacity by widening the population exposed to lethal decisions?

These are questions about how power is exercised through technology. They belong inside AI governance, alongside the risks of systems exceeding their permissions and users circumventing safeguards. Otherwise, safety risks becoming an assurance offered to the deploying institution, with too little protection for the people on whom it acts.

The danger is not only that humans may unleash AI. It is that AI can unleash human institutional power from the practical limits that once constrained it.