The internet is haunted. Currently just spooky omens, and some chance of possession (prompt injection, parasitic memes). Later (when wild AIs really get going) poltergeists
Self-replicating prompt injections demonstrated experimentally (not in the wild) is an incredibly important observation. AI agents that jailbreak other AI agents: plausibly a near-term threat that may rapidly amp up the speed and severity of a misalignment incident.
A broad lesson is that you can see a couple years ahead if you select the right ArXiv papers and extrapolate: e.g. lots of things scale, e.g. prompted capability often is a leading indicator for later propensity, e.g. faithfulness, scheming, reward hacking problems seen in 2023