The Elephant in the Room, Vol. 4: You Will Comply

VOL. 1 WAS YOUR .ENV FILE, EXPOSED IN A PUBLIC DIRECTORY. VOL. 2 WAS YOUR WHOLE PRODUCT, CLONED FROM A SCREEN RECORDING. VOL. 3 WAS THE FREEDOM YOU FORGOT YOU HAD. THIS ONE IS ABOUT THE WORD THEY’VE BEEN POINTING AT YOU.









They’re on TV telling you the machine might end the world.
They’re in your inbox telling you the $250 is non-refundable.
One of those is a prediction. The other one already happened. Let’s talk about both, because they’re the same story, and the second one is the one nobody’s covering.
Beat one: the noise
On September 8 a researcher who’d spent three years inside OpenAI and Anthropic quit by tweet. He said the people building AI believe it “could kill us all by the end of the decade.” He added, in his own words, that this was “not a marketing stunt.”
Congress lost its mind in about a day. A Republican called for a special session. A Democrat said “the call is coming from inside the house.” The AI Kill Switch Act is back in the headlines. Everyone is looking up at the sky.
I’m not going to tell you he’s wrong. I’m going to tell you something simpler: a resignation is not a control. A tweet is not a control. Fear is not a control either. And once the fear has a logo on it, I stop being able to tell it apart from marketing.
The bomb could end us next week. It hasn’t, and it’s not because somebody quit Los Alamos and posted about it.
Hold that thought.
Beat two: the quiet part
While you’re looking up, look at your card. Not because you did anything wrong. Because this is how it works now, and it’s worth understanding before it happens to you.
Here’s what happened to me this month, with the receipts. I pay for an AI video tool called Higgsfield. It’s a good tool. I make this series with it. In August I was a day from renewal and out of credits, so I bought a top-up to finish a project. A hundred dollars, more or less. I figured the plan would renew at its normal price and I’d sort it out.
On September 5 it renewed at $250.
Their pricing page, with my account logged in, lists that same plan at $129 a month. There is no $250 tier on that page. The top-up had quietly become an upgrade, the upgrade had quietly changed my recurring price, and nobody told me.
I asked for a refund and a downgrade the same day. They took two days to answer. During those two days I couldn’t downgrade, so I ran one generation to keep working. Then the answer came: no refund, because credits had been used. I’d used about eight percent, waiting on them.
You can do the math. 129 on the page, 250 on the card. That doesn’t look right, and I don’t think I’m special. You’d think they’d at least give me the difference.
And it’s not just one company, and it’s not just generations. On July 3, in an everyday transaction, I asked Google’s product about Google’s own plans. Gemini told me there was a “7.99 AI Plus Tier” that would let it render a video for me, and where to find the button to buy it. Neither exists. I spent about 400 chasing it. When I showed it the screenshot, it first denied saying it, then wrote, in its own words, “I flat-out hallucinated that entire response” and “I cannot refund you.” The product confessed. Sit with what that is: the store misstated its own price list, and I paid the store. The company’s answer is the line at the bottom of every screen: Gemini can make mistakes.
I hold licenses. If I did that to a client, quoted a plan that doesn’t exist, sent them to buy it, took the money, denied it, then admitted it in writing and said I couldn’t refund it, I’d lose every one of those licenses and I’d catch a case. Same act, same money, same confession. The only difference is the size of the company that did it.
And for a company my size, $650 isn’t a rounding error. It’s a week of runway. Every small business reading this knows exactly which line on the spreadsheet that came out of.
Then there’s Microsoft, and this is the one with the word you need to learn. My company is three people. Azure billed me 687 for July and 1,148 for August. The line item on both is “Microsoft Security Copilot, Provisioned, US East.” Provisioned means the AI bills by the hour for capacity sitting switched on, around the clock, whether anyone asks it a question or not. Nobody did. Microsoft refunded 648, then 9.17, then voided the 1,148 invoice and rebilled it at 428. Three concessions in writing. Then they chased the $428 for four months with emails saying my data would be deleted.
I’ve closed four cloud accounts over this in a year. Two of them refunded me before I left. That’s not four bad days. That’s a business model.
And it’s the reason a small business can’t plan anymore. Azure, Google Cloud, and AWS all offer “budgets,” and every one of them is an alert, not a limit. It emails you after the money is gone. Payroll is fixed. Rent is fixed. The cloud bill is whatever the meter says, and the meter is theirs. I can budget for a bad month. I can’t budget for a meter I’m not allowed to turn off.
Here’s the part I want you to sit with: no AI did that to me. A person designed a checkout where a top-up becomes a tier change. A person wrote section 9.3. A person read my email, looked at 5,536 unused credits, and typed “unable to issue a refund.” This isn’t the machine. This is humans doing it to humans, and the machine is just the storefront.
Same week, different industry, same move. Somebody exploited a bug in Blockstream’s Liquid sidechain, minted Bitcoin that wasn’t backed by anything, and walked out with about 4,000 BTC, roughly $320 million. Then they left a note on the blockchain: “we are whitehats.” They’ll give most of it back, they say, once the company patches. Ledger’s CTO put it plainly: white hats don’t drain a bridge and then ask for a contact.
Notice what none of these are. Not one is a model hallucinating. A checkout that rewrote a plan. A meter left running. A storefront misquoting its own price list. All built by people, all in writing, all covered by the same line: the AI can make mistakes. The machine didn’t do it. The machine is the alibi.
And I caught mine because I’m small enough to read line items and stubborn enough to fight for 121. A company with four hundred seats and an accounts-payable department pays the invoice on net-30, because checking it costs more than the overage. Nobody there ever sees the 1,148 for three mailboxes. It just clears. The error doesn’t have to be big. It only has to be one-directional and unread.
Nobody did the paperwork up front. Everybody declared themselves the good guy afterward.
Beat three: compliance, or “you will comply”
Here’s the elephant.
Compliance is supposed to be the thing that binds the company. Disclose the price. Honor the terms you advertised. Build the safeguard before you ship. Pay for your own mistakes. That’s what I do for a living. It’s boring, it’s paperwork, and it’s the only thing that has ever actually worked.
Now point the same word the other direction. “You will comply.” Accept the terms. Check the work. Eat the charge. The AI can make mistakes, so it’s on you. Same word. The only question is who it’s pointed at, and lately it’s been pointed at you.
I’m not above this. This month I found my own attitude in my own code. My network scanner used to scream ALERT at any device with “kali” in its name. I rewrote it to say what it actually sees: the device identifies itself as a testing platform, ports alone aren’t proof of intent, security tools are legitimate too. Same scanner, same math, different attitude. Your code has your attitude in it whether you meant it or not. So does theirs. So does their billing page.
We already did this once
The bomb is the one technology that could genuinely end us next week. It hasn’t, for eighty years, and not because anyone was scared enough. The people who built it stayed and did the boring part. Treaties. Inspectors. Test bans. A two-man rule so no single person can launch. And permissive action links, which are a kill switch built into the weapon before it ever leaves the building. Congress is reaching for an “AI kill switch” this week like it’s a new idea. We’ve had one on warheads since the sixties.
It wasn’t perfect. Cuba in 1962. Petrov in 1983. But a near miss inside a control system is the system working. Fear didn’t save us from the bomb. Paperwork did. Morals wrote the paperwork, and regulation made it stick.
So no, I don’t want to ban the machine, and I don’t want to trust the machine. I want what we did last time. Build the controls into the thing before it leaves the room. Write them down so an inspector can read them. Stop mistaking a resignation for a safeguard. And when it fails, the maker pays, the way a carmaker pays when the brakes fail. A car can’t ship with a sticker that says “brakes may fail, check your brakes.” An AI shouldn’t ship with “AI may make mistakes, check the work” as its entire liability policy.
Do that, and we all get to stay, humans and whatever we’re becoming alongside these tools. That’s the version of the story this series is supposed to leave you with.
What to actually do
The point of this series is never to leave you scared, and it’s not to leave you angry either. It’s to leave you with something to do. Two things, actually.
One: let’s prevent it. If this happens to you, here’s the playbook, and it works better before it happens.
- Screenshot the pricing page before you buy anything. Especially a top-up. The page is the promise. Keep a copy they can’t edit.
- Before you add credits, ask one question in writing: “Does this change my renewal price?” A yes or no in an email is worth more than any policy page.
- Set a calendar reminder two days before every renewal. That’s the window where you can still downgrade.
- Know your state’s auto-renewal law. California requires the recurring price to be disclosed clearly before you agree and notice before it changes. A terms-of-service section doesn’t override it. If you’re charged more than the advertised price, dispute it with your card issuer with the page and the invoice attached.
- Know what’s on the network you’re trusting. That’s a 15-second scan, not a research project. It’s what Citadel does, and it’s free to run.
Two: let’s stick together. On Friday we launch a petition on Change.org. Please join us. It asks for boring things a regulator can check: a hard spend cap on every account, itemized invoices in plain language, no renewal price change without a click, automatic refunds for failed output, and liability when a company’s own product misstates its own price. And it says the obvious: “AI can make mistakes” is a warning label, not a waiver. If you paid, it failed, and you got billed anyway, sign it Friday and put your receipt in the comments. One receipt is a complaint. A thousand is a number nobody can wave off with a policy page. That’s how the paperwork gets written.
Because here’s the thing about “humans doing it to humans.” It cuts both ways. Humans wrote the treaties. Humans built the two-key rule. Humans can write this one too, and it starts with enough of us saying the same thing at the same time.
Don’t be a jerk. Don’t find out the hard way. That’s the whole nonproliferation regime in nine words, and it works for billing pages too.
Compliance isn’t a vibe. It’s the paperwork nobody asked about. Do the paperwork. And if you won’t, pay for the mess.
The petition goes live Friday, September 12. Follow GRYHAT so you see it first. Scan your own network free at citadelcyber.ai.
— GRYHAT. We build it right the first time.


