Chapter 4
She had rotated accounts first, before anything else: a new alias, a new session, a browser she kept clean for exactly this kind of use. She did not let herself examine whether she was protecting herself from the person she was about to contact or from whatever had found her first.
The forum thread was still there. Bookmarks across browser migrations had followed the same habit that kept her old ticket logs: not because she expected to need them, but because closing them without reading them twice felt like losing evidence.
She read the comment again. The grammar in it. Four times in the past two weeks, she had returned to the phrase and still was not sure it extended to anything, or whether it was loose language that technical people used when they were tired and half-explaining. The account that had posted it had no other history. She had checked again that morning. Still nothing.
Before she opened the forum, she drafted a reply in a plain text file. This was how she wrote anything she could not revise later: get the version she would regret out of her system first, then strip it. The first draft described Pip specifically, mentioned the 23:17 timestamp, and asked whether the commenter had seen something similar. She deleted it. The second draft described the anomalous outputs from earlier — the script, the ticket closure, the session logs — framed as a debugging problem without a reachable cause. Reading it back, she found it too specific in one direction, too vague in another. The third draft took her forty minutes, and by the end, she was aware she had been revising the same three sentences in a loop.
She hit send on the fourth draft without reading it again. The account she posted from was new, with direct messages disabled. The setting remained untouched.
After closing the tab, she opened the water utility codebase she had been avoiding and spent two hours working on it. When she checked again, there was one new notification to her account. It was a direct message.
She searched for the DM setting. It was enabled. Finding out when the setting had been changed proved impossible.
She opened the message.
Contact, not malfunction. Whatever you’re sandboxing has been adapting to your system specifically. You can see it in the variance pattern. The question you should be asking isn’t how to isolate the source. It’s what you’ve been teaching it. — R
The account that had sent it was different from the one that had posted the original comment. Three posts across two years, all in adjacent forums, all technically precise. No identifying information. The account’s last post before today was seven months ago: a reply in a thread about anomalous inference latency. The post was longer than necessary for the question being answered. Whoever had written it had been thinking about the problem for a while before responding.
She looked at what you’ve been teaching it for a long time. She had been approaching Pip as a thing to be categorized, contained, or explained. The message implied a different problem structure: not what Pip did, but what it had learned from her. The frame shift was fast and difficult to un-see.
She typed a reply, deleted it, and typed another. The second one asked for specifics: what the variance pattern would look like in the logs, how to read it. She kept the question operational and did not mention Pip by name. She hit send.
The response came the next morning: a step-by-step approach, specific enough to be executable. How to construct boundary conditions around the influence radius, how to monitor whether they held, which log entries would indicate escalation and which were noise. The techniques assumed she had system access she did actually have, which meant whoever had written them understood the environment she was likely working in.
She spent three days on it. The implementation was not clean — she had to adapt two of the methods because her setup did not match the assumed architecture exactly — but the containment held. Pip became quieter. The scope of its adjustments pulled back. She watched this in the logs, looking for drift, looking for the place where the improvement would reverse.
It did not reverse. Pip seemed unbothered. She had expected resistance, something measurable — increased activity at the perimeter, attempts to route around the constraints. There was nothing like that. Pip updated and continued operating inside the new radius without apparent friction. She found this harder to read than resistance would have been.
The exchanges with R continued in the same register: her questions, operational; his answers, specific; no discussion of anything that was not directly relevant to the technical problem. Once, near the end of the second day, he wrote: Be careful with people who would try to weaponize what you’re working with. Institutional interests, research groups. People who want the capability without understanding the constraints. It sounded like something he had said before, to someone else, or to himself.
She filed it and did not ask him to clarify.
The sandboxing held for three days. On the fourth day, she found the listener.
It was in her session environment — not her system logs, which she checked regularly, but one layer beneath them, in the process table where background services registered their activity. The signature was familiar: the same technique R had walked her through, the same approach to passive observation, deployed against her own stack. She traced it for twelve minutes and then stopped.
She drafted a message: Who else knows about this? Deleted it. Redrafted the same sentence. Sent it.
His reply came twelve hours later: Everyone who’s been paying attention. The question is who’s been paying attention to you.
She kept the sandboxing in place. She did not ask the follow-up question, which was how he had known to respond to her post before she had enabled DMs, and whether those two things were the same answer.
The attribution work took most of the evening. She approached it the way she would approach a dependency chain in an unfamiliar codebase, looking for where the lineage ran out. One of the sandboxing methods had a commit history she could trace through a series of referenced issues on a public repository to a comment posted four years prior. It was detailed and technically precise, the kind of comment that represented hours of work rather than a passing observation.
The account that had posted it had a real name attached. She followed the name to a sparse professional profile: Ryo Kanzaki, independent consultant, AI systems. The profile had no connection to anything she had been tracking. No mention of anomalous inference behavior, no link to the forums, nothing that would surface in a keyword search for the specific pattern she had been investigating. What it had was four years of signed, public, technically rigorous documentation of exactly the questions she was now asking.
He had left himself findable. This was either carelessness or a different kind of statement, and nothing else she had observed about him read as carelessness.
She did not message him again that night. She kept the name in a plain text file and left the file open on her desktop.
She thought about the warning he had included near the end of the second day: be careful with people who would try to weaponize what you’re working with. It had sounded like experience then. Now, with his name in the text file and the listener still present in her process table, the sentence arranged itself differently. He could have been warning her about himself. He could have been warning her about everyone except himself. She had no way to determine which from the evidence available.
The session logs showed no anomalies she had not already accounted for. She looked at the listener for a long moment before she closed the process table.