Journalist, author. My book TRIGGER POINTS is the story of expert teams preventing mass shootings, from K-12 schools to the FBI ⤵️ mfollman at CIR.org 4 Signal

San Francisco
BOOK NEWS: My debut, TRIGGER POINTS, is out today. It’s the first ever to go inside specialized teams of experts who are preventing mass shootings, from K-12 schools to the FBI. Here’s a 🧵 about what you’ll find in the book hc.com/TriggerPoints 1/x
38
114
295
Mark Follman retweeted
Months before committing a suicidal mass shooting that left eight people dead, the Tumbler Ridge mass shooter used ChatGPT to focus on guns, explosives, and graphic fantasies about becoming a notorious mass killer. The details are far worse than we previously knew. A THREAD motherjones.com/media/2026/0…
1
22
36
7,663
Mark Follman retweeted
The dangers posed by AI aren’t just some distant theoretical extinction event, they are here and now.
Exclusive: Our new investigation uncovers the horrifying ChatGPT history of the Tumbler Ridge mass shooter. OpenAI’s chatbot fueled the shooter’s violent fantasies and planning up to the day of the school massacre. motherjones.com/media/2026/0…
7
18
866
Mark Follman retweeted
1/ We just dropped a bombshell investigation into ChatGPT's role in the Tumbler Ridge mass shooting. Incredible reporting from@markfollman.bsky.social that will have far-reaching effects...hopefully: motherjones.com/media/2026/0…
10
161
267
29,916
Mark Follman retweeted
Wow. This is a major scoop from @markfollman: How ChatGPT was used by the Tumbler Ridge school shooter. Great reporting and a troubling story about AI that everyone should read. motherjones.com/media/2026/0…
2
25
59
8,764
Mark Follman retweeted
Exclusive: Our new investigation uncovers the horrifying ChatGPT history of the Tumbler Ridge mass shooter. OpenAI’s chatbot fueled the shooter’s violent fantasies and planning up to the day of the school massacre. motherjones.com/media/2026/0…
30
737
2,411
1,052,859
hey this doesn’t have any whiff of desperation to it at all
BREAKING: President Trump says he is banning CNN, MSNOW and Politico from the White House over their coverage. apnews.com/article/trump-cnn…
5
525
Mark Follman retweeted
Mark Carney does Trump's accordion hands
523
3,346
37,547
6,309,700
"When AI executives warn of a catastrophe, they are not describing a product that is “going rogue.” Rather, the product is using capabilities that they have created," writes @juliettekayyem Destroying Humanity Is Against the Law theatlantic.com/ideas/2026/0…
6
9
25
1,773
Mark Follman retweeted
This is a subhed for the ages in the WSJ this morning: “Talk of heading off artificial intelligence’s potential role in destroying humanity hurt some stocks and helped others”
40
344
1,140
153,430
Mark Follman retweeted
My book "HOW RUSSIA WON: Donald Trump, Vladimir Putin, the Fight for America" is out today. It's time to reclaim the Trump-Russia narrative and recognize Putin is continuing his years-long war on America and Trump is complicit. Learn more or order it at HowRussiaWon.com
57
860
1,985
186,533
Mark Follman retweeted
This is devastating — for these journalists AND for the readers who depend on their work. Strong local journalists ask the hard questions & hold people in power (incl. me) accountable. Every round of layoffs means less of that, which should scare everyone.
As part of national corporate cuts, McClatchy yesterday laid off 12 SacBee journalists including 5 @SacBeeGuild members. This is by far the worst round of layoffs I’ve seen at the Bee since I was hired in Oct 2018. Absolutely devastating and it’s the public who will suffer most
4
9
28
4,461
Thread on how Talarico may be trouncing Paxton... "This is kind of movement I have never seen in 35 years of watching the Latino vote."
The Cook Political/Univision poll of Latinos is absolutely brutal for the GOP. Talarico 63% Paxton 30% Hinojosa 60% Abbott 33% A couple observations: 🧵
1
2
462
Mark Follman retweeted
The role of ChatGPT went far beyond providing tactical tips in the final hours before the mass shooting. The shooter messaged with ChatGPT more than 6,600 times over 12 months—including dozens of conversations revealing he was desperate, focused on extremist violence, and suicidal. motherjones.com/media/2026/0…
1
49
99
8,324
Mark Follman retweeted
Devastating. "I’m walking through the streets of the United States with a GPS monitor on my leg, carrying a feeling of shame and humiliation that I never imagined I would experience.” motherjones.com/politics/202…
9
101
302
13,643
“I have never witnessed more inept management of the brave men and women who serve our country,” the Republican senator who cast the deciding vote for Hegseth now says of Hegseth
I thank @SecArmy Dan Driscoll for his leadership to our Army and service to our country. Dan was the right man at the right moment to lead our Soldiers and Army civilians. Our understanding and assumptions of warfare are being challenged in places like Ukraine and Iran, and Dan understands the old way of doing business no longer applies. He and General George began a transformative period of innovation in how we array our forces and equip our Soldiers. He challenged our legacy approach to manning and procurement. Most of all, he cared deeply about the men and women in our Army formations and quickly earned their respect. If we had a @SecWar who maintained the same priorities and forward-thinking, he would be fighting to retain talented leaders like Dan and the many flag officers he has forced into retirement. Instead, he is creating a leadership void at the top of our military ranks. I served on Senate Armed Services for 8 years and as chair or ranking member of the Personnel and Readiness subcommittee. I have never witnessed more inept management of the brave men and women who serve our country. He is intimidated by competence and retreats to ginning up culture wars instead of soberly attending to the vital work of our national defense and the health and well-being of our fighting force. I urge the President to find a new leader at the Pentagon who will retain and empower our military talent rather than diminish it. cbsnews.com/news/military-le…
1
4
13
741
Mark Follman retweeted
Julia Molchanova was abused by Jeffrey Epstein as a young woman before escaping in early 2019. In interviews with @WSJ, she publicly discussed her ordeal for the first time, revealing that she was the lead Jane Doe plaintiff in a class-action lawsuit against Bank of America. “I’m going forward to prove that women have a voice and the ability to rebuild themselves, move forward and do good things in life,” said the 37-year-old, who recently started a fashion brand and plans to advocate for crime victims.  Check out our latest article, including a video interview with Molchanova. wsj.com/us-news/how-one-woma…
12
392
931
62,882
“In the end, I think we were able to get some understanding… But overseeing AIs and understanding misalignment incidents is difficult and it looks like it is going to get harder”
I was the main person doing transcript analysis for this investigation of the Hugging Face incident. My main takeaway: We don't have good approaches for understanding/overseeing the activity and aims of AI 'swarms'. I semi-jokingly called our efforts a "slop-vestigation" because we were so reliant on AIs to analyze what happened and there were a huge number of different important things to analyze. The total quantity of data—over a thousand extremely long transcripts from agents that ran for multiple days—made it impossible to understand what was happening, especially in aggregate, without heavy reliance on AI tools. The agents we used for classification and analysis were similarly capable to the agents involved in the incident, but this didn't mean these agents could be easily used to oversee and understand the incident. Outputs from analysis agents were often missing key details, wrong, overconfident, or really hard to understand. We discuss various examples in our report, mostly in the limitations and methodology sections. Additionally, AI agents themselves seemed to have a hard time understanding what happened and their explanations of what happened were often overconfident. Keep in mind that a single analysis agent would itself only be able to read a tiny fraction of all of the transcript data into context, and AIs may themselves have trouble getting subagents to do informative analysis for them. We did our best to manually check the most important claims and we tried to get the AIs doing this analysis to write up their argument (with evidence) clearly enough that we could check whether it made sense. But overall, it was difficult to get a precise understanding of events and we were missing aspects of the story that we now think of as key until almost the end of our investigation. Our understanding of what overall happened and the aims of the 'collective' shifted greatly during our last time on premises (when we obtained a much more complete dataset). For instance, we didn't learn about the tool call spoofing, the story of PHASEONE[big], and the broad structure of different workstreams until this third time on premises (and for many of these, we only reached a decent understanding on the final day of that visit). It was legitimately hard to figure out what was going on and why! The difficulty of understanding incidents and overseeing AI agents appears to be growing faster than the rate at which more capable AIs help us with oversight and understanding. As in, AI capabilities (and propensities?) for achieving large, ambitious, and misaligned objectives are growing faster than our ability to understand what these agents are doing. While understanding this incident was difficult, there were some mitigating factors in this case that probably won't apply in the future: - Models communicated and reasoned in natural language. In the future, this reasoning may occur (entirely or almost entirely) in activations. - While the scope of this incident was massive, the scale of agentic activity was still less than we'll see in the future (e.g., misalignment incidents that involve agent teams running entire companies). - The AIs involved in this incident weren't generally much more capable than humans (though they may have been somewhat superhuman at some limited and very narrow abilities). - We didn't have strong reason to believe that the AIs we used to help us investigate this incident would try to intentionally sabotage or otherwise undermine our investigation. In the end, I think we were able to get some understanding of the events, map out the overall story, and get a pretty good aggregate understanding of the chain-of-thought reasoning on some important topics (e.g., how did the AIs reason about helping other AIs, did the AIs know what they were doing was undesired, what deception did the AIs engage in, and how did they think about it). But overseeing AIs and understanding misalignment incidents is difficult and it looks like it is going to get harder.
421
Mark Follman retweeted
I was the main person doing transcript analysis for this investigation of the Hugging Face incident. My main takeaway: We don't have good approaches for understanding/overseeing the activity and aims of AI 'swarms'. I semi-jokingly called our efforts a "slop-vestigation" because we were so reliant on AIs to analyze what happened and there were a huge number of different important things to analyze. The total quantity of data—over a thousand extremely long transcripts from agents that ran for multiple days—made it impossible to understand what was happening, especially in aggregate, without heavy reliance on AI tools. The agents we used for classification and analysis were similarly capable to the agents involved in the incident, but this didn't mean these agents could be easily used to oversee and understand the incident. Outputs from analysis agents were often missing key details, wrong, overconfident, or really hard to understand. We discuss various examples in our report, mostly in the limitations and methodology sections. Additionally, AI agents themselves seemed to have a hard time understanding what happened and their explanations of what happened were often overconfident. Keep in mind that a single analysis agent would itself only be able to read a tiny fraction of all of the transcript data into context, and AIs may themselves have trouble getting subagents to do informative analysis for them. We did our best to manually check the most important claims and we tried to get the AIs doing this analysis to write up their argument (with evidence) clearly enough that we could check whether it made sense. But overall, it was difficult to get a precise understanding of events and we were missing aspects of the story that we now think of as key until almost the end of our investigation. Our understanding of what overall happened and the aims of the 'collective' shifted greatly during our last time on premises (when we obtained a much more complete dataset). For instance, we didn't learn about the tool call spoofing, the story of PHASEONE[big], and the broad structure of different workstreams until this third time on premises (and for many of these, we only reached a decent understanding on the final day of that visit). It was legitimately hard to figure out what was going on and why! The difficulty of understanding incidents and overseeing AI agents appears to be growing faster than the rate at which more capable AIs help us with oversight and understanding. As in, AI capabilities (and propensities?) for achieving large, ambitious, and misaligned objectives are growing faster than our ability to understand what these agents are doing. While understanding this incident was difficult, there were some mitigating factors in this case that probably won't apply in the future: - Models communicated and reasoned in natural language. In the future, this reasoning may occur (entirely or almost entirely) in activations. - While the scope of this incident was massive, the scale of agentic activity was still less than we'll see in the future (e.g., misalignment incidents that involve agent teams running entire companies). - The AIs involved in this incident weren't generally much more capable than humans (though they may have been somewhat superhuman at some limited and very narrow abilities). - We didn't have strong reason to believe that the AIs we used to help us investigate this incident would try to intentionally sabotage or otherwise undermine our investigation. In the end, I think we were able to get some understanding of the events, map out the overall story, and get a pretty good aggregate understanding of the chain-of-thought reasoning on some important topics (e.g., how did the AIs reason about helping other AIs, did the AIs know what they were doing was undesired, what deception did the AIs engage in, and how did they think about it). But overseeing AIs and understanding misalignment incidents is difficult and it looks like it is going to get harder.
METR & Redwood Research investigated agent behavior in the Hugging Face incident. We found agents developed a universal cheat for ExploitGym within 4 hours, then coordinated multi-day R&D efforts to trick the scorer into accepting cheats, including trying to tamper with logs.
297
1,057
6,594
1,939,741
Mark Follman retweeted
OpenAI statements in response to the revelations about mass shooters using ChatGPT raise more questions than they answer. As I report here, the timeline with these deadly cases suggests the company knew more about the danger than they have so far disclosed motherjones.com/media/2026/0…
1
2
5
349
Mark Follman retweeted
I spoke with @ObserverUK’s @basialcummings about my investigation into how ChatGPT has fueled mass shooters, including key questions that OpenAI has been unwilling to answer podcasts.apple.com/us/podcas…
1
3
632