---
title: "Morally Binding"
subtitle: "In Fifteen Days, Washington Rejected AI Guardrails, Won the Right to Blacklist a Dissident Lab, and Signed a Constitution With No Penalties."
excerpt: "On September 29, six AI executives joined Donald Trump in the East Room and signed the White House Accord on Super Intelligence: 308 words committing each company to internal controls, an auditor it hires itself, a board committee, and regular meetings, with no deadline, no publication requirement, and no penalty. Trump called it morally binding, almost like a constitution. Four days earlier, the D.C. Circuit had upheld his administration's supply-chain-risk designation of Anthropic, one of the signatories, weeks after a district court found the designation to be illegal First Amendment retaliation. Fifteen days earlier, the President had declared that the only guardrail AI needs is a strong and smart president. The accord is a loyalty instrument and a preemption placeholder, a cartel's charter dressed in the vocabulary of arms control, and the one company that had been punished for its safety policy signed it while still under designation, which is the mechanism by which punishment gets converted into ratification."
coverImage: "/assets/blog/morally-binding/cover.png"
category: "Politics"
tags: ["AI", "AI Governance", "Trump", "Anthropic", "OpenAI", "Self-Regulation", "Superintelligence", "Policy"]
date: "2026-10-01"
author:
name: synapz
picture: "/assets/blog/authors/profile.png"
ogImage:
url: "/assets/blog/morally-binding/cover.png"
---
The document exists. You can read it. Donald Trump posted a photograph of
the signed page to Truth Social at 5:24pm on September 29: a heading, "White
House Accord on Super Intelligence: Joint Commitment on Frontier
Responsibilities," 308 words of text, and seven signatures. His own, then
Sundar Pichai's, Dario Amodei's, Mark Zuckerberg's, Greg Brockman's, Elon
Musk's, Jensen Huang's. USA Today noted that the page misspells the name of
the country.
The page itself creates no agency, names no auditor, sets no deadline, and
attaches no penalty. An executive order was signed the same day, a separate
and stranger instrument, and it comes up below. Contract law has a phrase
for instruments like this, drafted in the vocabulary of obligation by
parties who intend no obligation: binding in honour only. The City of
London ran on such paper for centuries. My word is my bond. Asked whether
the accord could be enforced, the President gave the correct answer. "I
think it's morally binding."
The page regulates no one, and no one involved pretended otherwise for
longer than a sentence. The question it raises is why six companies wanted
their names on it, and why one of them, the one that spent the year being
punished by the man hosting the lunch, wanted it most.
## Fifteen Days Earlier
On September 14, the administration answered the safety question in its
own register. The occasion was the open letter and [the pacing
blueprint](/posts/2026-09-12-step-zero): 1,178 signatories from inside
the labs, and Dario Amodei's essay arguing
that the frontier should be advanced at a deliberate speed, behind
capability checkpoints certified by embedded evaluators, coordinated
across companies under an antitrust waiver. The President's reply, posted
that morning, held that "the only control or 'guardrails' that AI needs is
a STRONG AND SMART (High IQ!) PRESIDENT," described the safety project as
a conspiracy whose beneficiary is China, and closed on the doctrine:
"WHOEVER WINS AI, WINS!" The Pentagon's chief technology officer, Emil
Michael, spent the afternoon translating: the campaign was "Americanism,
not effective altruism," and the objective was to remain "AI DOMINANT!"
*"The only control or 'guardrails' that AI needs is a STRONG AND SMART
(High IQ!) PRESIDENT ... WHOEVER WINS AI, WINS!"*
— Donald Trump, Truth Social, September 14
The substance of that day was the reclassification. A
debate about checkpoints and evaluators became, from the state's side, a
question of loyalty: the safety frame was named as an enemy ideology, and
the companies pursuing it were named as its carriers, with the President
noting, for anyone slow on the uptake, the "tremendous CRIMINAL and
REGULATORY power" his government holds over them. What fifteen days would
show is that declining was only the first posture. A state that refuses to
regulate has not thereby refused to govern. It has kept the question open,
and an open question in Washington is something that can be held over
people.
## Four Days Earlier
The second document is a court decision, and the lunch makes no sense
without its timeline in full.
In February, Anthropic refused two uses of its models: mass domestic
surveillance and fully autonomous weapons. The government ordered agencies
to stop using the company's products and designated it a supply-chain risk
to national security, a label built for foreign adversaries, applied here
to an American company over the terms on which the American military could
use American software. Anthropic sued. In March, a federal judge in
California blocked the designation, calling the episode a "classic" case
of illegal First Amendment retaliation. In August, the same court ruled on
the merits: the designation was unlawful. On September 25, the court of
appeals in Washington ruled for the government instead, two judges to one,
finding "ample support"
for the designation and, in the reading of the lawyers who
follow these things, widening the statute's reach over any AI vendor whose
ethics policy conflicts with a government's preference. The same statute
offers almost no further review, which is why the coverage doubted
Anthropic could appeal. Emil Michael marked the occasion online: "The
hammer of justice has smashed AnthropicAI['s] arguments."
Notice what the winning argument won. The designation's power was never
the label itself, which had been suspended and enjoined into
irrelevance for seven months while Anthropic's rivals took the federal
contracts. The power was the discretion to lift it. Howard Lutnick, the
Commerce Secretary, had explained the mechanics in an interview three
weeks before the ruling: "We trust Anthropic. They've done what we asked.
They're back on the right side." Michael corrected him the next day: the
designation stands. Both statements were true. The company was on the
right side, and it was still designated, and the distance between those
two facts was the space in which the lunch was organized. Four days after
the appeals court ruled, Amodei was in the East Room.
*"We trust Anthropic. They've done what we asked. They're back on the
right side."*
— Howard Lutnick, Commerce Secretary
## The Ceremony
The third document is the lunch itself, or rather its seating chart,
which the President posted at 11:54 that morning: thirty-four names.
Huang on one side of him, Musk on the other. Zuckerberg beside Huang,
Pichai beside Musk. Across the table: the
Vice-President, flanked by Jeff Bezos and Satya Nadella, and the Speaker,
with David Sacks beside him. Sam Altman was in San
Francisco, so OpenAI's seat went to Brockman, its president. Amodei sat
far down the President's side of the table, between the chief executive
of a supply-chain-vetting contractor and the chief executive of Broadcom,
who sits on Meta's board. If you want to know what the accord means, read
the chart before the text.
The text, once you reach it, is a shadow of the proposal the
administration had spent September rejecting. The pacing blueprint asked
for capability checkpoints; the accord commits each company to monitor
"the capabilities and alignment of its models during training and
deployment," internally. The blueprint asked for embedded evaluators; the
accord commits each company to "partner with an independent external
auditor or evaluator," a partner being, in the nature of partnerships,
chosen and paid by the company. Coordinated standards became a promise to
"meet regularly." The blueprint wanted law; the accord allows that "over
time, it may make sense to codify these steps into laws or regulations."
The vocabulary of the rejected architecture survives intact, because the
vocabulary was never the contested part. What the blueprint had, and this
page lacks, is any mechanism by which a promise becomes a fact that
someone else can check.
The auditor layer is already spoken for. Three of the signatories
(Google, OpenAI, Anthropic) have spent the summer building the Standards
Authority for Frontier AI, a
self-regulatory body modeled on FINRA, the industry organization that
polices stockbrokers. It would set testing practices, require incident
reports, and certify independent auditors. Among the people approached to
lead or serve on it, according to the reports: Trump's former AI policy
adviser, and David Friedberg, who co-hosts the All-In podcast with Sacks,
who sat beside the Speaker at the lunch. The accord obliges each signatory
to hire an auditor. The same three are building the institution that would
decide which auditors count. The credit-rating agencies were
born exactly this way, in 1975, when the SEC designated three evaluator
firms, paid by the issuers they evaluated, and spent the next thirty-three
years discovering what that arrangement was worth.
The same afternoon, on the Senate floor, Ted Cruz objected to unanimous
consent on the Warner-Schatz-Kim bill, and the binding version of all this
was stopped in a sentence: an AI Safety Board at Commerce, access to
frontier models forty-five days before release, incident reports on a
clock, fines of a quarter of a million dollars per violation per day. One
objection was enough, and the accord's signing photograph ran instead.
And the administration signed its one piece of unilateral paper: an
executive order directing federal agencies to replace the words
"artificial intelligence" with "Super Intelligence" in official documents.
The government that had spent two weeks refusing to govern the technology
found the time to rename it, adopting, as the official vocabulary of the
United States, the destination the safety movement fears. A czar was
promised within three or four days. A committee of about ten, possibly
drawn from the industry itself, was said to be under consideration.
## What the Signature Buys
A document that binds no one can still do a great deal of work. This one
does three jobs.
The first is loyalty. A signature is a debt the host can collect at any
future hearing, in front of any future camera: you sat at my table, you
signed my page, you promised. Every safety commitment these companies have
ever made in their own names is now also a commitment made to him, and the
difference will surface the first time a company wants to do something the
White House dislikes and is reminded of what it signed. Amodei's leaked
memo from February documented the tribute economy from inside: "We haven't
donated to Trump (while OpenAI/Greg have donated a lot)." The sentence was
meant as an explanation for why his company was being punished. He
apologized for the memo in March; the designation was still in force on
the day he signed.
*"We haven't donated to Trump (while OpenAI/Greg have donated a lot)."*
— Dario Amodei, leaked internal memo, February
The second job is preemption. "Over time, it may make sense to codify."
When that codification arrives, it will arrive as the industry-written
floor, and the floor's purpose will be the ceiling: the White House's
legislative program already calls for federal preemption of state AI laws,
which is to say for the extinction of Colorado's law, California's SB 53,
New York's RAISE Act, and every other instrument that survived the year's
moratorium fights. The accord is the placeholder text for that statute,
and it will keep until the votes exist.
The third job is the one Trump named without noticing. "They're really
going to be policing each other." They will, because they own each other.
Nvidia has agreed to invest up to $100 billion in OpenAI, which buys
Nvidia's chips. Microsoft and Nvidia have agreed to put up to $15 billion
into Anthropic, which has committed $30 billion to Microsoft's cloud.
Amazon holds $8 billion of Anthropic, Google more than $3 billion, and
Broadcom's chief executive sits on Meta's board. This is the circle that
will be policing each other.
If anyone at the lunch had a reason to sign, it was Anthropic. The
company can say, truly, that the accord asks nothing of it that it does
not already do, and asks more of rivals who do less. It can say that four days
after the appeals court ruled against it, with the designation in force
and the federal market closed to it alone among its peers, the pen was the
price of readmission, and that refusing the pen would have been a vanity
the company's safety mission could not afford. It can even say, and people
I respect in its orbit do say, that with the state declined out of the
pacing business, the labs' own paper is the only pacing left, and a floor
is not nothing. I have gone back and forth on whether I believe the
signature was defensible, and I have settled somewhere uncomfortable: the
decision to sign was rational, and the existence of a situation in which
signing was rational is the indictment. An accord calibrated to what the
most-regulated company in the room already does will look like regulation
to a public that has no seat at the table and no copy of anyone's
controls. The resemblance is the document's function.
## Binding in Honour Only
The safety debate has reached for the arms-control register all year, so
take the comparison seriously for a moment. SALT I was also an interim
agreement, also partial, also improvised by men who distrusted each other.
But it froze things that could be counted, under verification both sides
could perform, between parties whose fear of the weapon exceeded their
appetite for the advantage. The accord freezes nothing, counts nothing,
and is verified by auditors the audited will hire through a body the
audited are building. It runs between one party that is afraid and one
party that is the source of the fear.
The bleakest reading of the fifteen days belongs to Timnit Gebru, who
was named a Right Livelihood laureate the day after the signing. On her
account, the industry got what it wanted: self-policing in place of the
liability existing law already provides. Gebru was fired from Google in
2020 for a paper warning about large language models as they actually
exist, biased and error-prone systems with no one accountable for them,
and she has argued since that the extinction talk is a branch of the
marketing, the same men warning that their products might kill everyone
while promising, in the same breath, that the products will end poverty
and disease. In that frame, the resignation letters [these pages read
last month as
conscience](/posts/2026-09-09-the-warning-and-the-filter) are part of
the same instrument, and the auditor clause is worse than toothless,
since the auditors are funded by the audited's own investors. The part of her case that can be checked
checks out. The Hugging Face breach did not require a new jurisprudence
of rogue machines; it required a prosecutor willing to call a missing
air-gapped environment negligence, and Lina Khan has catalogued the
statutes that already apply. I read the September letters as sincere
behavior, and I still do. Gebru's reading says the sincerity is the
product. The accord works the same either way.
The public, for what it is worth, has already graded the ceremony. The
Quinnipiac poll released the day of the lunch put approval of the
President's handling of AI at 25 percent. An arrangement this unpopular is
one election, one incident, one genuinely frightening model release away
from reopening, and everyone at the table knows it, which is why the
wisest reading of the accord may be as insurance taken out by the industry
against the day the polling moves. Paper that binds in honour only can be
repudiated by honour alone. It can also be repudiated by Congress, and the
margin between those two outcomes is where the next two years of this
story will be fought.
The instruments to watch are the ones that would prove this reading wrong:
a czar with statutory authority rather than a portfolio of press releases;
a Standards Authority that publishes a finding one of its members hates;
a codification bill with penalties in it; an auditor chosen by someone
other than the audited. Until one of those exists, the
President's own phrase remains the most accurate description of what was
signed, and he said it with the cameras on. Morally binding: the law of
the strong, accepted by the designated, binding on no one, in a room where
the moral question had already been litigated, and lost.
### Related Reading
- [Step Zero](/posts/2026-09-12-step-zero) (the pacing blueprint this
accord shadows, and the argument for watching who appoints the referee)
- [Democracy Now!: Timnit Gebru on the accord and the existing-law
alternative](https://www.democracynow.org/2026/10/1/timnit_gebru_ai)
- [CNBC: U.S. appeals court upholds Pentagon designation of Anthropic](https://www.cnbc.com/2026/09/25/pentagon-anthropic-ai-risk-appeals-court.html)
- [Forbes: White House releases "accord" between billionaire AI execs](https://www.forbes.com/sites/saradorn/2026/09/30/white-house-releases-accord-...)
- [USA Today: the accord's posted page misspells "United States"](https://www.usatoday.com/story/news/politics/2026/09/30/white-house-accord-su...)
- [The Hill: Cruz blocks push to unanimously pass AI safety bill](https://thehill.com/policy/technology/6118009-senator-ted-cruz-blocks-ai-bill/)