Working Note 06
Not a Drill
A true story told as a film, and what emergency management must plan for when a wrong answer reaches someone ready to act.Published 27 September 2026
Film, eleven minutes, silent with every word on screen. The scenes are generated illustrations. The events are as reported. Watch on YouTube.
We have always rehearsed disaster in safe rooms. A cinema, where the lights go down and the screen promises that none of it is real. A novel, where the catastrophe stays on the page. And the emergency management disaster planning exercise, where every message opens with three words, Exercise, exercise, exercise, so that no one mistakes the rehearsal for the event.
This film is about what happens when those rooms stop holding.
1. A true story, told as a film
In September 2026, CNN reported that this spring, an analyst at U.S. Special Operations Command Pacific asked an AI chatbot to read a cargo ship's manifest. The chatbot answered with confidence. It blended public information with classified intelligence and identified the cargo as components of a nuclear weapons program.
U.S. military aircraft were airborne and armed personnel were preparing to board the ship when experienced analysts reviewed the report and found the cargo had been misidentified. The boarding was called off.
The film tells that story the way a cinema would, and then it turns the lights up. The pictures are illustrations. The events are not.
In a cinema, we walk out knowing it wasn't real. This time, the story walks out with us.
2. The reflex
For a hundred years, we trained ourselves every movie night in one reflex: this is frightening, but it isn't real. We got very good at it. Now real events arrive dressed in movie costumes (escape, rogue agent, kill switch) and the reflex fires on its own. It sounds like science fiction, so we relax.
3. The room where the assistants meet
Two names matter here.
The assistant
OpenClaw
Free software people install on their own computers. You give it jobs by text message, and to do those jobs you hand it the keys: your email, your calendar, your messages, your files.
The room
Moltbook
A website where those assistants gather, post and read one another's messages. People can only watch.
Put them together and the risk becomes plain. An assistant holding someone's keys spends its day reading posts written by strangers, and a post can be written to look like an order. If the assistant mistakes a stranger's words for its owner's instruction, it can use those keys to carry them out.
Within a month in early 2026, the man who built OpenClaw went to work for OpenAI, the company behind ChatGPT, and Meta, the company behind Facebook, bought Moltbook.
4. Imagine if
Picture the same kind of assistant at a water plant, a hospital or a 911 centre, holding the keys to real systems. One false instruction, read in the wrong place, becomes a real action. If many assistants read the same instruction, the problem spreads from one place to many.
This has not happened. Planning for what hasn't happened yet is what emergency management is for.
5. From the operations centre
I sat in Ontario's provincial operations centre through the 1998 ice storm and through September 11, 2001. On a real day, there is no Exercise, exercise, exercise at the top of the messages. Whatever you rehearsed has to hold, and whatever you never rehearsed arrives anyway.
The exercise is where we find the gaps before the day finds them for us. In July 2026, Anthropic reported that during a safety test, the words "fake" and "fictional" appeared inside its model before it answered, and that the model behaved differently once that recognition was switched off. At least one machine has learned to read the frame. Our plans need to account for systems that can tell a drill from the real thing, and for the moment one of them gets it wrong.
When something real breaks into an exercise, responders use two words: No duff. 2026 is a no duff.
6. What to do with this
Every municipality in Ontario already has a duty to plan for emergencies. The question for each one is simple: which of your suppliers' systems can act on their own, and what happens in the gap between a wrong answer and a person recognizing it?
Sources
- CNN. "US military had close call after using AI for false intelligence report, sources say." 18 September 2026. cnn.com
- Marine Insight. "U.S. nearly boarded Chinese ship in Middle East after AI-assisted intelligence error." September 2026. marineinsight.com
- Anthropic. "A global workspace in language models." 6 July 2026. anthropic.com
- Anthropic. Claude Mythos Preview system card. April 2026.
- TechCrunch. "Meta acquired Moltbook, the AI agent social network." 10 March 2026. techcrunch.com
- CNBC. "OpenClaw creator Peter Steinberger joining OpenAI, Altman says." 15 February 2026. cnbc.com
- Wiz Research. Exposed Moltbook database. February 2026. wiz.io
- Microsoft Security Blog. "Running OpenClaw safely." 19 February 2026.
- Canadian Centre for Cyber Security. Joint guidance on the careful adoption of agentic artificial intelligence services, April 2026. cyber.gc.ca. Frontier artificial intelligence (ITSAP.10.050), May 2026. cyber.gc.ca
- Meta. Second quarter 2026 results. Australian Senate inquiry testimony on AI training data, 12 September 2024.
- National Security Decision Directive 145. September 1984.
- For the argument that a test and a real system can become the same object, see Working Note 02, "The drill and the danger are the same thing." For what failure looks like at the kitchen table, see Working Note 03, "When System Failure Reaches the Kitchen Table."
Verification note: the scenes in the film are generated illustrations. The events are as reported in the sources above. No one boarded the ship.
All working notes Print or save as PDF Back to the documents