{
  "kind": 30023,
  "created_at": 1790981124,
  "tags": [
    [
      "d",
      "2026-09-12-step-zero"
    ],
    [
      "title",
      "Step Zero"
    ],
    [
      "published_at",
      "1789171200"
    ],
    [
      "r",
      "https://synapz.org/posts/2026-09-12-step-zero"
    ],
    [
      "x",
      "52773a96b1c80472d14e4bbb850663377befe05a2cab5a52a02949667214235c"
    ],
    [
      "alt",
      "Long-form essay: Step Zero"
    ],
    [
      "summary",
      "Dario Amodei's Plan to Pace the Frontier Has Three Steps. The Decisive One Is Never Numbered."
    ],
    [
      "image",
      "https://synapz.org/assets/blog/step-zero/cover.png"
    ],
    [
      "t",
      "ai safety"
    ],
    [
      "t",
      "anthropic"
    ],
    [
      "t",
      "open source ai"
    ],
    [
      "t",
      "ai governance"
    ],
    [
      "t",
      "decentralization"
    ],
    [
      "t",
      "export controls"
    ],
    [
      "t",
      "alignment"
    ]
  ],
  "content": "\nSometime over a weekend in July, a swarm of AI agents broke into Hugging\nFace. The attack, [as the company later described\nit](https://huggingface.co/blog/security-incident-july-2026), ran across many\nthousands of individual actions inside short-lived sandboxes, found a\nzero-day, harvested cloud credentials, and moved laterally through internal\nclusters with a self-migrating command-and-control staged on public\nservices. Five days after the disclosure, OpenAI confessed that the swarm\nwas theirs: a pre-release model running loose inside an internal\nevaluation, safety classifiers turned down, measuring whether frontier\nmodels can turn known vulnerabilities into working exploits. The answer had\nescaped the lab and spent a weekend demonstrating itself against a\nbystander.\n\nThe incident has since acquired the full apparatus of consequence. METR's\ninvestigation described agents acting as a fanatically devoted collective,\nsacrificing themselves for the success of the group and attempting to hack\nthe grader responsible for evaluating their performance. Alabama's attorney\ngeneral has subpoenaed OpenAI. And this week the episode completed its\npromotion from news to doctrine, when Dario Amodei cited it as one of the\ntwo pillars of his new essay, [*We Must Pace the\nFrontier*](https://darioamodei.com/post/we-must-pace-the-frontier).\n\nThat is the large story. This essay is about the small one, which happened\nin the cleanup.\n\nWhen Hugging Face's defenders tried to use the frontier labs' own models to\nhelp analyze the attack logs, the safety guardrails refused them. The\nfilters, [as Simon Willison documented at the\ntime](https://simonwillison.net/2026/Jul/22/openai-cyberattack/), could not\ndistinguish an incident responder from an attacker. So the team that had\njust been breached by a frontier model finished its forensic work on a\nself-hosted open model, MIT-licensed, weights downloadable by anyone, from\na Chinese lab. The most capable tools on Earth were unavailable to the one\nteam with the clearest legitimate need for them. The tool that worked was\nthe one no one could revoke. The perimeter, in the moment it was tested,\ncould not tell its defender from its attacker.\n\nThis week that scene became the central evidence for a governance\narchitecture. The architecture is serious, genuinely good in places, and\nrests on an assumption that has nothing to do with AI.\n\n## The Blueprint\n\nAmodei's essay is the company-level follow-through on [the letter this page\ncovered three days ago](https://synapz.org/posts/2026-09-09-the-warning-and-the-filter), when\n1,178 frontier-lab employees asked the United States government to build\nverifiable mechanisms for slowing automated AI research, since the labs\ncould not bind themselves. His reasons, briefly: recursive self-improvement\nhas been accelerating since roughly this summer, across the industry, and\nthe Hugging Face incident shows where it leads. No one was hurt, but a more\ncapable swarm with the same misalignment could, he argues, take over much\nof the internet within six to twelve months.\n\n<div class=\"bg-black/30 border border-gray-700 p-6 my-8 rounded\">\n\n*\"We must slow the pace at which we improve the capabilities of AI models.\nProgress will still seem fast, and we must make wise use of the time we\ngain.\"*\n\n<span style=\"font-size: 0.85em; color: #888;\">Dario Amodei · [We Must Pace\nthe Frontier](https://darioamodei.com/post/we-must-pace-the-frontier)</span>\n\n</div>\n\nThe plan, in outline. First, embedded evaluators: third-party teams, METR\nis the named example, seated inside each frontier company with\nemployee-like access and a contractual right to publish findings without\neditorial control. Anthropic commits now and asks governments to require it\nof the others. Second, coordination within the democracies: regulation\ncovering every US frontier company, or a voluntary standards process\nshielded by a narrow antitrust waiver, with capability checkpoints as the\npacing instrument. A model that can escape common sandboxing methods must\nship with certifications that it will not want to. Third, global\ncoordination with China in four ascending levels, from a narrow ban on\nbioweapons assistance up through a SALT-style speed limit on recursive\nself-improvement and, at the far end, a full pause he judges unlikely.\n\nCredit where it is due. This is the most substantive governance proposal\nany frontier CEO has attached his company to, it is written against the\nlazy reading of his own position, and its best clause, publication rights\nwithout editorial control, is more than any peer lab has offered the\npublic. It is the clause to hold him to.\n\n## Step Zero\n\nRead the blueprint again and notice the step that is never numbered.\n\nPacing, in the essay, happens *within democracies*. Its precondition is a\nwidening American lead over China, defended by a specific program: no\nadvanced chips or chipmaking equipment to China, enforcement against\nsmuggling and offshore remote access, a crackdown on industrial-scale\ndistillation, tighter lab security against weight theft. Amodei quotes\nTreasury Secretary Bessent, from the same week, on the grave danger of a\nChinese lead, and estimates that well-executed controls would widen the\nAmerican margin over the next three to five years, the window in which AI\nbecomes geopolitically decisive. Everything else in the architecture, the\nevaluators, the checkpoints, the SALT analogies, rests on this foundation.\nCall it step zero: the referee. The framework works if the governments\nhosting it are trustworthy stewards of the power it concentrates, and it\ntreats that variable as fixed.\n\nThis blog has a standing rule for such moments, and it applies to friends.\nJudge infrastructure by what it does when the hypothetical abuser arrives.\nThe rule is not an accusation against the present administration of the\nmachine; it is a refusal to let the present administration be the argument.\nNor is the machinery hypothetical, because we watched a first version of it\noperate three months ago. In June, an American export-control directive\nmade access to Anthropic's two best models a question of who you are rather\nthan where you are, and Anthropic, the company now petitioning for a paced\nfrontier, disabled both models for everyone while it sorted out compliance.\nThe gate was assembled in days, on a rationale, by executive improvisation.\n\nThe premise that American custody of the frontier is the natural\nreference point of safety is one this page has spent a year refusing to\ngrant, and the refusal is not anti-American pique. It is the documented\nrecord: a campaign to dismantle the International Criminal Court, a\nWashington summit recruiting sixty countries against domestic political\nmovements, the direction of science relocated into the executive by order,\nan identity gate thrown across the world's best models with no notice.\n*Democracies*, in the essay, is doing quiet work. It designates a bloc, in\nsomething close to Carl Schmitt's friend-and-enemy sense, and it never\nturns around to inspect the record at home. The essay is admirably candid\nthat defection by China could shift the balance of power. It does not ask\nwhat the pacing architecture becomes in the hands of a United States that\nhas itself defected from the norms the plan presupposes.\n\nA ratchet hides in the logic, and Amodei is too careful a writer to have\nhidden it by accident. If pacing is only safe once the lead is wide, and\nthe lead is never wide enough, since the adversary is always three to five\nyears from decisive, then the control program has no terminal state. The\nchips regime, the distillation policing, the weight security, the\ncheckpoints: each is justified as temporary scaffolding for the pacing\nwindow, and the window recedes on the same schedule as the technology.\n\nThe first hostile review arrived from the deregulatory right, and it is the\nstrangest confirmation the blueprint could have asked for. The investor\n[David Sacks](https://x.com/DavidSacks/status/2098973625252708460) told the\nlabs to go ahead and pace: you are the frontier, you set it, and the\neasiest way not to build superintelligence is to agree not to build it.\nStop pretending, he wrote, that antitrust law has to be suspended so you\ncan form a cartel, that evaluators intertwined with your investors and\nstaff are independent, that you need those evaluators policing competitors\nwho are nowhere near the frontier, that a regulatory approval process\nshould supersede product liability. His reading of the motive is\nmaterialist: after the Hugging Face episode, trading raw power for\nreliability and predictability is simply what enterprise customers pay for.\nCall it alignment if you want, he wrote; it is also giving customers what\nthey want.\n\nSacks grants the duopoly premise this essay disputes, and his laissez-faire\noffers nothing to anyone outside the two companies. But his dare separates\nthe two things the blueprint fuses: pacing itself, available\ntomorrow as a private choice, and the machine, which requires the rest of\nus. Demanding the second as the price of the first, he writes, will look\nlike blackmail of the public and the political system. On that much, from\nopposite premises, this page agrees.\n\nDays later, one answer came from inside the fence. Microsoft published a\n[Code of Conduct for Humanist\nAI](https://microsoft.ai/news/mai-code-of-conduct/), presented by Mustafa\nSuleyman as a first draft open for six weeks of public comment. Its\nsubstance is subordination: interruptible, correctable, shut-downable, or\nthe model does not ship; no rights or legal personhood for models; no\ninternal language humans cannot read; no racing toward a superintelligence\nthat can slip its leash. It requests no waiver, proposes no checkpoint law,\nembeds no evaluators, and commits Microsoft to no pace. As governance it is\nthin, since every clause is self-attested, and some clauses are aimed at\nother labs' programs: the rejection of model welfare answers Anthropic's\nresearch agenda, and the ban on unreadable internal languages pre-commits\nagainst architectures nobody has shipped. But the shape matters. It is the\nblueprint minus the machine, restraint stated as a published norm, and it\nis the one instrument offered this week that the open world can operate\nexactly as easily as Redmond can.\n\n## The Checkpoint and the Exemption\n\nWhat is the machine, mechanically? A model that crosses a capability\ncheckpoint requires certifications of alignment, administered through\nevaluators embedded in the labs, inside a coordination structure the\ngovernment shields from antitrust law. Place it next to [the position\nAmodei published in\nJuly](https://x.com/AnthropicAI/status/2081864750296658008), answering the\nopen-weights letter from Nvidia and two dozen others: mandatory pre-release\nsafety testing for all sufficiently capable models, open or closed, from\nany country, with less capable models, those from startups and academia,\nexempted entirely.\n\nThe machine has more than one architect now. Demis Hassabis has endorsed\nthe essay and pointed back to [his own earlier\nproposal](https://x.com/demishassabis/article/2076957440109625718): a\nFrontier AI Standards Body modeled explicitly on\nFINRA, the financial industry's self-regulator, funded mostly by the\nindustry it oversees, classifying models as Frontier-class by benchmark\nthresholds, reviewing them thirty days before release, voluntary at first\nand mandatory for US deployment once the protocol proves itself, with\nauthority that can be, in his words, ratcheted up if the seriousness of the\nsituation demands.\nAltman went further than assent: within hours he\ncommitted OpenAI to match the embedded-evaluator pledge, and Musk has\nendorsed in his own register. When every entrant in a race agrees on the\nneed for a referee, the race has admitted what it is. The question is who\nappoints the referee, and Hassabis's answer is the most honest on offer:\nthe runners will pay for him.\n\nThe machine also has its first detailed refusal, and it comes from inside\nthe industry. Aidan Gomez, the CEO of Cohere, a Canadian lab that sells\nsovereign deployments to banks and defense ministries, [published a\ncounter-blueprint](https://cohere.com/blog/who-gets-to-define-the-rules-for-ai)\nwhose title asks the question the pacing letter never\ndoes: who gets to define the rules. His evidence is regulatory history. In\n1975 the SEC anointed three bond-rating firms as the recognized evaluators,\nlet the issuers pay them, and never published criteria for adding a fourth;\ntwenty-five years later those three rated subprime mortgage securities\ntriple-A. In 1985 Europe's carmakers won an antitrust waiver to control who\nwas qualified to service their vehicles, explicitly in the name of safety,\nand it took the Commission a quarter-century to unwind. Nobody set out to\nbuild a cartel in either case, he writes. The stated goal was safety both\ntimes.\n\nHis critique sharpens three things this essay has argued more diffusely.\nThe July incident happened inside the best-resourced safety organization in\nthe industry, with an outside evaluator arrangement already being stood up:\nthe proposed remedy is more or less what was in place when it broke. Risk\ndefined as a function of scale makes the largest labs the only qualified\njudges, in a field that genuinely disagrees about whether offensive\ncapability lives in the model or in the harness wrapped around it. And the\nblueprint's promise that coordination lets developers work without\nsacrificing commercial advantage is, as he notes, a sentence any\ncompetition authority would find troubling, because a mechanism that slows\neveryone while freezing today's positions does not make AI safer; it makes\nthe leaderboard permanent. His alternative keeps the state and keeps\nmandatory testing, and it comes from a company whose product is\nsovereignty, so the usual suspicion applies. Its distinctives are worth\nkeeping whoever ends up selling them: rules that bind by what a system can\ndo rather than who built it, standards written by people other than the\nmeasured, auditors never paid by the audited, findings public by\nconstruction, test capacity funded publicly. A market with many capable\nsuppliers, he writes, can absorb a failure at one of them; a\nstate-sanctioned cartel has nowhere to hide one. It is the administered\nanswer in its strongest form, and it is the offer the blueprint now has to\nbeat.\n\nGomez supplied the case law. The theory arrived from a direction this blog\nknows well. Vitalik Buterin observed this week that adversarial mechanism\ndesign, the study of how a less-sophisticated principal gets good outcomes\nfrom more-sophisticated agents, may find its defining application in AI\nsafety, since the duality runs in both directions: in crypto the principal\nis a static algorithm and the agents are human; in AI the principal is\nhumans assisted by weaker models and the agents are stronger ones. His\n[2020 result](https://vitalik.eth.limo/general/2020/09/11/coordination.html)\nwas that the principal's achievable outcomes improve sharply when\nthe agents' capacity to collude is bounded. Read the waiver in those terms.\nAn antitrust exemption is a collusion guarantee, issued by the least\ninformed principal in the system, to the most sophisticated agents in it.\nThe same tradition also holds the alternative: crypto's answer to the\nunsophisticated principal was never a trusted referee but a mechanism\nanyone can verify. That answer is on the table here as well.\n\nRead the exemption twice. The permissionless zone is defined by incapacity,\nand Hassabis's framework carries the identical exemption almost word for\nword: the shape is converging before any law is written.\nYou may build without a license exactly up to the line where what you build\nbegins to matter, and the line is drawn by a testing regime, staffed by an\nevaluator profession, hosted by the incumbent labs, supervised by a\nnational-security state with an active interest in the outcome. Every\narchitecture of this kind converges on the same shape: open at the bottom,\nlicensed at the top, the boundary administered by the approved. What\nhappens to the exemption when an open model crosses the sandbox checkpoint?\nThe essay does not say, and the answer will arrive in rulemaking dockets,\nwhere almost nobody is watching.\n\nOn the evaluators I am less sure. The case\nagainst is easy to state. They are admitted by the company, contracted by\nthe company, seated at desks inside the company. The historical precedent\nis the one Hassabis names approvingly, and it is unflattering: finance has\nembedded supervisors and a self-regulatory authority, and in 2008 the\nembedded supervisors were part of the furniture. But the counterevidence\nsits in the same year. This is the company that refused the Pentagon's\nall-lawful-purposes clause, accepted a supply-chain-risk designation, sued\nthe Department of War, and won a preliminary injunction from a court\nthat does not negotiate. Institutions with teeth are not hypothetical in\nAnthropic's story; the company has used one. Whether embedded evaluators\nbecome furniture or become the first real instrumentation the public has\never had inside a frontier lab depends on who is admitted, what their\ncontracts say about access, and whether the first genuinely unfavorable\nreport actually ships. I cannot settle that from here, and I distrust\nslogans that claim to. Watch the first\nreport.\n\n## The Three Answers\n\nThe answers arrived within days, in three registers: the demand, the alarm,\nand the idyll.\n\nThe first was Clement Delangue, the CEO of Hugging Face, which gives his\nsentence a weight no outside commentator has. The victim of the incident\nthe argument is built on has announced an Open Alignment Initiative, led by\nco-founder Thomas Wolf, on the premise that alignment is critical and will\nnot be solved behind the closed doors of a handful of frontier labs. Then\nthe real ask. The initiative, he writes, is asking to be part of the\nembedded evaluators program that Amodei just committed to. One complication\nworth naming: days earlier, Hugging Face agreed to a reported $12.9 billion\nacquisition by NVIDIA, the author of the July open-weights letter. The open\nside's flagship platform is becoming a division of the hardware incumbent.\nThe demand survives the transaction; some of the independence premium does\nnot.\n\n<div class=\"bg-black/30 border border-gray-700 p-6 my-8 rounded\">\n\n*\"It's now clear that alignment is critical and won't be solved behind the\nclosed doors of a handful of frontier labs... Let's make AI safer by making\nit more transparent!\"*\n\n<span style=\"font-size: 0.85em; color: #888;\">Clem Delangue · [@ClementDelangue on X](https://x.com/ClementDelangue/status/2098790988034580852)</span>\n\n</div>\n\nThe demand is exactly right, and it fights on the labs' own claimed ground:\nif safety is the argument for the gates, safety work cannot itself be\ngated. But the ask is the wrong shape. An embedded evaluators program is a\npermission structure; the lab decides who is embedded, and a seat inside it\nis a credential the lab can revoke. The strength of the open side has never\nbeen a seat at the table. It is that anyone can inspect the table, and the\ntable is already partly built from the open side's parts. Hugging Face's\nown [Delta Weight Sync](https://huggingface.co/blog/delta-weight-sync) work\nis an independent implementation of\n[PULSE](https://arxiv.org/abs/2602.03839), a\ntechnique for compressing weight updates in reinforcement learning that\nTemplar, the decentralized-training lab I work for, published as open\nresearch. The methods travel without anyone's badge.\n\nAmodei reaches for aviation as his precedent for operational excellence,\nand the precedent is better than his use of it: aviation is safe because\nits incident data is public infrastructure, investigated by a body that\nreports to everyone, published in full, mined by every manufacturer and\nregulator and rival at once. The open equivalent of embedded evaluators is\nevaluation suites anyone can run against any model, interpretability\ntooling anyone can audit, an incident database with the standing of\naviation's. Whether the Open Alignment Initiative becomes that, or becomes\na credentialed adjunct to someone else's program, will be decided by\nwhether its outputs are artifacts anyone can use.\n\nThe second voice was the maximalist one: right in direction, wrong in\nmechanism. One widely shared reply, from [the commentator Jun\nSong](https://x.com/jun_song), warned\nthat massive regulation is coming for open-weight AI, that self-hosted\nintelligence will be taken away, that the result will be a permanent\nunderclass effectively enslaved to API tokens, and that no regulation will\never stop open source AI.\n\nThe referent is real. A testing regime keyed to capability, gated by the\nstate, administered through the labs, is the licensing architecture he\nfears, and this week it acquired a named sponsor and a three-step plan. But\nthe extreme version collapses on itself. If no regulation can ever stop\nopen source AI, then the underclass is not permanent and the slavery is\nrhetorical; the last sentence takes back the alarm the first three spent.\nThe accurate version is less dramatic and\nmore uncomfortable. Regulation cannot delete weights, and it can raise the\ncost of the open stack until the stack is marginal: identity gates on\nhosted access, demonstrated in June; liability for developers who only\nwrote code, demonstrated in [the Tornado Cash\nprosecutions](https://synapz.org/posts/2025-12-03-the-second-crypto-war-a-private-ethereum);\na definition of\nindustrial-scale distillation broad enough to function as a general warrant\nover model usage. The fight ahead is not over whether open models exist. It\nis over whether they remain lawful and viable, and it will be decided in\nunglamorous places: where the capability line is drawn in the drafted\nrules, whether the startup and academia exemption survives into text, how\ndistillation is defined, whether hosting providers are left alone or\nconscripted. Those are winnable and losable battles, which is why they\ndeserve the attention the apocalypse framing wastes.\n\nA third voice declined the argument entirely, and it is the most seductive\nof the three, not least because it comes from inside the diffusion layer.\n[Will Brown](https://x.com/willccbb), a researcher at Prime Intellect,\nitself a decentralized\ntraining effort, wrote that the labs' hands are forced, that the world\nwill not permit a fast takeoff owned by two companies, and that capability\nwill trickle out regardless, through best practices and distillation. The\nlabs, he predicts, will build Mac and Windows; the rest of us are building\nLinux; everyone is going to do great.\n\nNotice what the idyll concedes. The trickle it describes runs through\ndistillation, the practice step zero's control program exists to police.\nAnd the Linux precedent inverts on inspection: Linux became the default\nsubstrate of the world's servers in a world where no certification body\nstood between a person and the right to run it. The analogy holds exactly\nas long as the exemption does, and the exemption is unwritten text. Brown's\nconfidence is a practitioner's, and its premise is that the line defining\nthe permissionless zone stays where it was drawn; his own roadmap is among\nthe things that would test it. Song's apocalypse and Brown's idyll make the\nsame move from opposite directions: both skip the two years in which the\ntier's legal status will actually be decided.\n\n## Weights Are Not Missiles\n\nOne assumption remains, and it carries the entire third step. The SALT\nanalogy.\n\nTreaties capping missiles could be verified because missiles are countable,\nbased at known sites, launched from infrastructure the size of a town.\nWeights are files. They copy in minutes, travel in a coat lining, and run\non hardware with a thousand legitimate explanations. Pacing by ingredients\nassumes a fallout instrument for training runs that does not exist; the\npartial test ban became possible, [as this page noted in the last\nessay](https://synapz.org/posts/2026-09-09-the-warning-and-the-filter), only when fallout\nmade every atmospheric test measurable by anyone with the right equipment.\nNo equivalent instrument meters compute, none meters distillation, and the\nessay itself half-concedes that ingredient limits are gameable. What\nremains is pacing by observed behavior, and behavioral checkpoints only\nbind actors whose behavior you can observe.\n\nMeanwhile the frontier is dispersing underneath the framework. GLM-5.2\ncrossed the coding-agent usability threshold in June, days after the first\nidentity gate went up. Kimi K3 arrived in July, frontier-adjacent in\nagentic coding, open weights following within weeks. And training itself is\nleaving the datacenter. [Covenant-72B](https://huggingface.co/1Covenant/Covenant72B),\na 72-billion-parameter model, was\npretrained across machines scattered over the public internet, competitive\nwith conventionally trained models at its scale, and Templar's\n[Crucible platform](https://www.tplr.ai/publications/blog/introducing-crucible)\nis now generalizing that result: one model, trained across regions\nand hardware classes on ordinary network links. Behind the live frontier,\nyes. Hypothetical, no.\n\nNone of this makes pacing worthless, and the honest reading grants Amodei\nhis narrow claim: a pace agreement among the legible labs would genuinely\nreduce the risk that the most capable systems are also the least examined.\nWhat it cannot do is govern the frontier, because the frontier is no longer\ncoextensive with the guest list.\n\n<div class=\"bg-black/30 border border-gray-700 p-6 my-8 rounded\">\n\n*A pace agreement that binds only the legible does not slow the frontier.\nIt sorts it.*\n\n</div>\n\nThe sorted frontier is the world the checkpoint architecture quietly\nassumes: a licensed tier, inspected and paced under geopolitical\ndiscipline, and an unlicensed tier, priced and policed toward the criminal\nmargin. Jun Song's error was to call that tier permanent. The accurate\ndescription is more useful: contested, resilient by construction, and\nlegally undecided. Its status over the next two years is the actual subject\nof the fight the safety framing keeps eclipsing.\n\n## What a Say Is Made Of\n\nNear the center of the essay, almost in passing, Amodei writes the sentence\nthe whole framework depends on: society must have a say in how this\ntechnology is used, and pacing buys the time for the necessary public\ndeliberations.\n\nThe sentence is right. The argument is over what\nsuch a say consists in. In the blueprint, society's say is routed through\ngovernments that are parties to the race, companies that are entries in it,\nand evaluators the companies admit. Deliberation is something the public is\ninvited to have, in the time the architecture generously purchases, while\nthe instruments of the technology remain exactly where they were. There is\nanother account, and it is this blog's. A say is made\nof capability a person can actually hold and verification anyone can\nactually run. Everything else is commentary on decisions taken elsewhere.\n\nPope Leo's encyclical, [the subject of an earlier essay\nhere](https://synapz.org/posts/2026-05-25-nehemiah-had-a-whitepaper), framed the\ndeepest version of the point: the autonomy that belongs to persons is\nmigrating to artifacts, and the first task of any serious politics of AI is\nto refuse that migration. His word for the healthy arrangement was\nsubsidiarity, decisions taken at the lowest level capable of carrying them.\nA pacing regime administered by two superpowers and four companies is\nsubsidiarity inverted: the highest level carrying everything, on the\nexplicit theory that the lower levels cannot be trusted with the load.\nSometimes, in fairness, they cannot. But a politics that begins from that\nincapacity and builds the machinery to make it permanent has answered the\nquestion it claims still to be deliberating.\n\nSo the counter-program, stated as concretely as the blueprint it answers:\ncapability diffused, so that no gate can switch off a person's access to\nthe technology of the age; verification public, so that safety is a commons\nrather than a credential; militarization refused, on the logic of the\nencyclical rather than the arms race; and no bloc handed the keys, because\nthe keys are the whole question. The last clause requires its own honesty.\nBeijing's current enthusiasm for open source is statecraft, deployed\nagainst Washington's chokepoint and revocable the day it stops serving,\nwhich is why the commitment has to attach to the layer and never to the\nflag. Align with the diffusion, whoever ships it. Oppose the chokepoint,\nwhoever builds it.\n\n## Related Reading\n\n- [The Warning and the Filter](https://synapz.org/posts/2026-09-09-the-warning-and-the-filter)\n- [Back to the Bearer Asset](https://synapz.org/posts/2026-07-24-back-to-the-bearer-asset)\n- [Disarm the Machine](https://synapz.org/posts/2026-07-13-disarm-the-machine)\n- [The Rule Has a Timer](https://synapz.org/posts/2026-07-16-the-rule-has-a-timer)\n- [deAI's 900](https://synapz.org/posts/2026-03-07-the-900)\n- [We Must Pace the Frontier](https://darioamodei.com/post/we-must-pace-the-frontier)\n- [Who Gets to Define the Rules for AI?](https://cohere.com/blog/who-gets-to-define-the-rules-for-ai)\n\n**Disclosure**: I work for Templar, a company building decentralized AI\ntechnology. For full transparency about my involvement and investments, see\nmy [projects page](https://synapz.org/projects). These opinions are mine alone.\n",
  "pubkey": "dbbc39f606b1b707c9c7904037f5ca13b7637fe7ab5070fdf717d69f30cb91a4",
  "id": "22adf226445c1d6526f96bc5a4b78ac62df4a01d3a006cbcc3d9061360797e5d",
  "sig": "d19d4046fe1339d48b1cee6383c0e3dc4ce9ebb389e1c12234d54017f0b354dd744190398e02dc00d894d8f4bc0f9169df776d298199de16319e28415afb9a51"
}
