The Hacker Has an Address
~9 min read · By Jeroen Janssen · July 2026
A language model can write a criminal sentence that reads perfectly. Every clause in place, the tone exactly judicial. Paste it into a terminal and no one goes to prison. Let a judge speak the same words in open session and a person loses ten years of liberty. The strings are identical. The difference is everything, and it is the difference Yuval Noah Harari walks past.
In his 2026 Tanner Lecture at Oxford, Harari argues that AI is hacking the operating system of human civilisation. The chain is elegant. Human dominance rests on cooperation among strangers. Cooperation rests on trust. Trust is manufactured by bureaucracies. Bureaucracies are built from words. AI now masters words. So AI inherits everything upstream: the banks, the courts, the churches, the civilisation itself.
Take the argument seriously and it comes apart at one joint. The chain holds for four links, then changes category. Bureaucracies are expressed in words. They are not composed of them. AI has achieved total command of the syntax of civilisation and acquired no standing in its runtime. Harari’s takeover has a precise failure condition, and it is not magic. It is abdication: authority leaking out of named roles into workflows nobody has re-audited. Unlike a civilisational hack, abdication is observable, auditable and reversible, one organisation at a time. Everything below is that claim, shown.
The Token Is Not the Act
Start with the token. It is not the act. “You are hereby sentenced” compiles when a judge says it in session and throws an error when anyone else does. The force was never in the words. It sits in the mapping between the words, the authorised speaker and the recognised procedure. So the governance question is not whether a model can produce the sentence. It is the moment the sentence becomes an act.
Language tokens are the syntax of civilisation. Institutions are the runtime. AI can generate any string the runtime accepts, and it holds no native standing to make the runtime honour that string. It gets operational standing only by delegation: an account, an API key, a workflow permission, a mandate, or a human who rubber-stamps the output. The takeover scenario therefore begins only when institutions start honouring unassigned output, output no named role was mandated to adopt. That is not hacking. It is abdication, sometimes explicit, more often procedural.
When the Token Is the Execution
One domain earns Harari the concession. Sometimes the token is the execution. Social media content. Market-moving text. Persuasion. There, emitting language is the act, and no institutional grant is needed. This is why his social media example is his strongest and his AI-judge example his weakest. The line between them is the trust boundary: does the output become consequential by itself, or only after an institution types it. Every governance question an organisation faces sits on one side of that line, and the two sides demand entirely different controls.
The Monopoly Belonged to the Clerks
Now the monopoly he mourns. It was never humanity’s. It belonged to the clerks. Harari says that for thousands of years nobody else on the planet could read the code of civilisation. True as stated, and quietly misleading. Most humans never read the code either. The readers of law codes, ledgers and holy books were always a tiny clerical caste. Medieval peasants stood to canon law roughly as Harari’s pigs stand to the Bible: governed by text they could not read. The condition survives, and Harari supplies the proof himself. The collateralised debt obligations at the centre of the 2007 to 2008 crisis were unintelligible even to the politicians charged with regulating them. Too few supervisors could interrogate those instruments at the depth and speed the moment required.
So the monopoly was never “humanity reads the code.” It was “a small class of clerks reads the code, and everyone else trusts the clerks.” AI is a new entrant into that class, not the first breach of a human wall. The party it threatens first is not the species. It is the professional intermediary whose value rested on exclusive code-literacy: the lawyer, the accountant, the analyst, the consultant. Their moat was reading. The moat that survives is standing, the authority to make a reading count.
Arbitrage, Not Takeover
And when someone understands a system better than the people who own it, history does not produce takeover. It produces arbitrage. What happens when AI understands money, law and regulation better than we do? Harari answers: takeover. The record answers otherwise. Tax lawyers understand the tax code better than the state that wrote it, and they do not seize the treasury. They extract at the margins. Quant funds read market microstructure better than any regulator, and they do not own the money system. They skim it. Canon lawyers know canon law better than most bishops, and the bishops still ordain. In every mature bureaucracy the deepest understanding already sits outside the control positions, and has for centuries. Control tracks mandate, not comprehension.
The real fear is therefore not a coup. It is asymmetric arbitrage at machine speed, a million exploited seams that supervisory bodies cannot triage. A coup calls for walls and kill switches. Arbitrage calls for matching analytical capacity on the oversight side. The 2008 failure was not that complex instruments existed. It was that the understanding gap between inventors and supervisors was near total. Whether oversight can interrogate machine-generated complexity as fast as it is produced is an institutional capacity question. It has owners, budgets and deadlines, which a species-level hack never does.
The Hacker Has an Address
Which brings us to the actor. There is no “something” hacking the code. There is a counterparty, and it has an address. Harari says there is now “something” on the planet hacking the operating system, and the word carries more than it can hold. There is no single alien agent. There are millions of model instances, and behind each one an operator, a jurisdiction, an infrastructure bill, terms of service, a log. Where those records are absent, the absence is itself the finding. His own immigration metaphor concedes it: the AI immigrants, he says, will be loyal to a corporation or government across the ocean. Then the hacker has an address. An entity with an address is not a civilisational force. It is a counterparty. You can regulate it, contract with it, sue it, deny it standing. The rhetoric needs the “something” to belong to nobody, because a hack with a named operator stops being destiny and becomes liability.
The hybrid civilisation he announces needs the same correction. Civilisation has been hybrid since the first ledger. For four centuries we have shared it with non-human entities that hold purposes, memory, legal personality and indefinite lifespans: corporations. We never settled whether they were conscious. We settled, slowly and after real damage, what they could own, what they owed, and when the veil pierces so a named human becomes personally answerable. That is the working template for the AI case, lag included.
The Signature Is the Wall
There is one thing language mastery cannot reach, and it is the point everything has been driving toward. Harari ends by relocating humanity to the truth beyond words, a refuge that by definition cannot be operationalised. There is a defensible kernel in it, Polanyi’s: we know more than we can tell. But institutions run only on what gets represented, so tacit knowledge cannot carry the weight he places on it. He also misreads his own proof text. He cites the Gospel of John for a tension between word and flesh; the prologue asserts their union. The Logos becomes flesh. The tradition he reaches for does not say truth abandons language for the ineffable. It says truth enters language, and a body that can be wounded.
That points at the single institutional act language alone cannot perform: the signature. Not the ink, which is a symbol like any other, but what the ink attaches. A signature adds no information the document lacked. It adds enforceable exposure, a named person whose licence, liability, career and reputation are now bound to the content. A model can generate any sentence, including “I take responsibility.” It cannot take responsibility, because nothing can be taken from it. That is the wall. Everything before it falls to language. Nothing after it does.
The Corrected Thesis
So the corrected thesis reads as an instruction, not a prophecy. AI will take over everything that was only words, and in doing so will force every institution to discover which of its products were only words. Where the value was the string, the cheapest producer of strings wins, and that contest is already over. Where the string carried something else, staked judgment, delegated authority, exposure to consequence, nothing has been taken, because producing the string was never the scarce part.
This is where governance turns practical. The first question is not whether the model is impressive. It is where its output crosses into institutional effect. Does it inform, recommend, decide, trigger, approve, reject, price, classify, report, escalate, or sanction? At each crossing there should be a named role, a mandate, an evidence object, a control, and a signature that still means something.
That inventory does not compile itself. It is an audit, run deliverable by deliverable and workflow by workflow: which outputs in this organisation become decisions, who signs there, and where the signature has quietly decayed into a rubber stamp. Harari announces the flood. The work is the sorting.
Sources
- Y.N. Harari, “AI bureaucrats, AI religions, and AI boyfriends: What happens when a non-human intelligence hacks the operating system of civilisation,” Tanner Lecture on Human Values, Linacre College, University of Oxford, May 2026. linacre.ox.ac.uk
- Y.N. Harari, “Yuval Noah Harari argues that AI has hacked the operating system of human civilisation,” The Economist, 28 April 2023. economist.com
- M. Polanyi, The Tacit Dimension, 1966. Cited to grant Harari his one defensible point. Polanyi’s thesis, that we know more than we can tell, establishes that real knowledge exists below the level of explicit representation: skill, judgment, recognition that resists being put into words. The essay concedes this and then bounds it. Tacit knowledge is real, but institutions act only on what gets represented in words, records and signatures, so it cannot serve as the refuge from AI that Harari’s closing move requires.
- Regulation (EU) 2024/1689 (AI Act), Article 14, human oversight of high-risk AI systems. The Act’s oversight obligations can serve as one reference frame for structuring the audit described above; they do not perform it.
