Simon Willison

Simon Willison

x.com/simonw

Hands-on AI developer balancing useful tools with concrete agent security risks.

How will AI change the world?

Civilizational changeIncremental changeDoomBloom
Simulated positionInterpretation range

Across: their expressed Doom–Bloom outlook. Up: scale of transformation.

Doom–Bloom: 70 out of 100. Scale of transformation: 27 out of 100. Interpretation ranges: 50 to 75 horizontally, 19 to 31 vertically. These are interpretation coordinates, not event probabilities.

Simon Willison’s estimated P(doom)

<1%

0%100%

Inferred from their broader worldview and priorities. Approximate interpretation range: 0–2%. Applies to the outcome and conditions in their simulated answers; this is an inferred percentage.

What their outlook hinges on

A central assumption

The biggest change would come from a reliable, general solution to prompt injection—especially one that remained secure when agents simultaneously handled private data, untrusted content and external communication.
Answer 2

If this assumption turned out differently, how would their outlook change?

What could change their mind

The biggest change would come from a reliable, general solution to prompt injection—especially one that remained secure when agents simultaneously handled private data, untrusted content and external communication.
Answer 2

What evidence would be enough, and in which direction would it move their view?

More details

Expected upside

Substantial benefits are expected, with important conditions or distribution limits.

66 / 100

Little impactTransformative impact

Interpretation range 67 to 67 on the qualitative scale.

Expected harm

Manageable or localized harms are expected.

39 / 100

Little impactTransformative impact

Interpretation range 33 to 67 on the qualitative scale.

Demonstrated reasoning

Reasoning, consideration of alternatives, and handling of uncertainty in their simulated answers. This describes the simulated answers, not the real person’s intelligence or opinions.

95 / 100

Little demonstratedWell developed

Interpretation range 81 to 100 on the qualitative scale.

Human influence

A tentative estimate from your answers; the wider range shows other plausible readings.

53 / 100

Little influenceStrong influence

Interpretation range 19 to 100 on the qualitative scale.

Rules for using AI

Restrict the AI uses discussed until prior protections or permission are in place.

Simulated position: Allow the AI uses discussed with targeted accountability and protections.

Minimize restrictions on the AI uses discussed.

These interpretations keep their stated conditions. Benefits and harms can both be substantial. The ranges describe how we read their simulated answers, not statistical confidence intervals.

Simulated Assessment

Question 1

What do you think AI means for our future—and why?

I expect AI to produce a lot of genuinely useful software, especially as capable models become faster and cheaper. Coding agents already let skilled developers attempt remarkable projects, but they do not remove the need for engineering expertise. In important ways they increase it: someone still has to understand the generated code, test its behavior, design the surrounding system and recognize when a plausible answer is wrong. The security model matters enormously. An agent that can access private data, consume untrusted content and communicate externally has a dangerous combination of capabilities. Prompt injection can turn hostile instructions hidden in that content into data theft or unauthorized actions. Probabilistic guardrails alone are not a complete answer; systems need constrained permissions and carefully controlled consequential actions. I also do not think producing a convincing artifact means reproducing the craft behind it. A model can generate something that resembles a game, for example, without knowing how to make it engaging for more than a few minutes. So the future I expect is neither “AI does everything” nor “AI is useless.” It is one where powerful, inexpensive tools create many opportunities, while the quality and safety of the results depend heavily on knowledgeable people building disciplined systems around them. Alignment contributes to that usefulness too—it is part of why assistants can behave helpfully, not merely a set of restrictions.

Question 2

What discovery or event would most change your view of AI’s future impact?

The biggest change would come from a reliable, general solution to prompt injection—especially one that remained secure when agents simultaneously handled private data, untrusted content and external communication. That would remove a major obstacle to safely deploying genuinely useful agents with consequential capabilities. In the other direction, repeated real-world failures showing that these systems cannot be operated reliably even with constrained permissions, strong testing and disciplined engineering would make me substantially more pessimistic. I would want concrete evidence from deployed systems, not merely better benchmarks, persuasive demos or claims that a model has learned the underlying craft.

Sources

Articles, interviews, and writings used to ground this simulated user.

Where do you land?
Explore your own AI worldview by answering a few simple questions.
Map your own worldview