For a while now we’ve been mocking the Trump White House’s plans for an “AI framework” that would have the frontier AI labs hand over their top models for an initial review. After all, this was more or less the exact same plan that the Biden admin worked out in 2023, but it was done in a thoughtful and careful manner. And it caused a bunch of the VC bros in Silicon Valley to come out in support of fascism, while claiming it was a necessary defense against Biden’s attack on supposedly open innovation. Of course, all of that was bullshit, and that’s made even more clear by every step the Trump White House has taken to reinvent a similar “voluntary” AI review plan, but dumber.
The White House does not plan to publicly release its new framework for evaluating advanced AI models, three sources familiar with the discussions told Axios.
The Trump administration invited staffers from OpenAI, Anthropic, Google, Meta, Nvidia, and other leading AI companies to the White House on Tuesday to share an overview of its new AI oversight framework, the people said. AI developers will have the ability to voluntarily submit new models to the federal government up to 30 days ahead of their public release. The White House will then vet their cyber capabilities according to a classified benchmarking system and share the AI models with federal agencies and trusted corporate partners.
The White House isn’t sharing more information about its testing criteria or which AI models will be covered by the framework, though open models will reportedly be excluded, according to Axios. That has left smaller AI startups, safety advocates, and third-party researchers in the dark about crucial aspects of how the federal government is addressing the cyber risks posed by advanced AI systems. Some argue that the secretive process will give an advantage to larger companies.
Considering that the likes of Andreessen Horowitz (investors in OpenAI) claimed they had to support Donald Trump over Joe Biden because they would support anyone who agreed with their “little tech agenda,” I’m curious how they can possibly square that with the fact that this new framework is significantly worse than the Biden framework, specifically for the “little tech” companies that a16z has used as a shield to defend their support for authoritarian politics?
Of course, the other reason why the White House is probably keeping the framework a secret is because it would show how incompetent they are. All the reporting so far suggests the entire process has been a clusterfuck, which is much more about which companies get to set up which regulatory moats to protect their own business models, rather than what’s best for either innovation or the American public.
At Nvidia, Microsoft, Google and Meta, executives grew increasingly concerned that Anthropic and OpenAI would win over the White House with their arguments for tighter restrictions, according to two of the people. That would potentially cement the A.I. start-ups’ positions as market leaders,
Other A.I. labs were at risk of falling permanently behind, the people added. And because several of the companies make their own open-source models or supply hardware to businesses that use open-source technology, they worried the restrictions could harm them.
Over private texts, phone calls and video conferences, executives quietly built an argument that open-source models were good for the world and for American innovation, according to three of the people familiar with the talks.
But, of course, that’s just the way things work when you have a White House that makes decisions entirely based on transactional motives, rather than anything involving principles.
As we discussed last week, so much of this is all about whose vision of the AI world wins out — whether a handful of giant companies get to lock in the regulatory moat they’ve built for themselves, or an actually competitive market lets people make their own decisions and keep control over their own experiences. Maybe that’s the real reason nobody’s allowed to see the rulebook: because it would reveal who the administration agreed to let write the rules.
On an afternoon in mid-May, dozens of Microsoft engineers and their managers gathered online and in a conference room at the company’s Redmond, Washington, headquarters to discuss Project Glasswing.
The tech giant was racing to fix weaknesses in its code that a new AI model known as Mythos was uncovering at an unprecedented clip. The AI behemoth Anthropic, which developed Mythos, had given access to select organizations that make software used by regular people, companies and governments across the world. The goal was to find and fix the vulnerabilities before hackers and adversarial governments like China began using similar tools to find and exploit them for espionage and sabotage.
As the group settled in, one engineer asked the question that loomed over the meeting: Did Mythos “live up to the hype that Anthropic claimed it would have had?”
“Yes,” a manager responded, according to a recording of the meeting viewed by ProPublica.
The version being used by Microsoft, Claude Mythos Preview, was surfacing bugs faster than the tech giant could patch them, and engineers, the manager said, were now in “a mad dash” to close the gap.
One slide in that day’s presentation showed that in April alone, Mythos had uncovered 90 “critical” bugs and 141 “important” ones in SharePoint, Microsoft’s widely used collaboration software. In the first half of May it found even more.
“Please, please, please if your org has any April bugs, drive those down,” engineering manager Hans Andersen implored the group. They had roughly two weeks “to find as many things and do as much good as we can with this access.”
May 31, he explained, “is considered the day when the rest of the world will have caught up.”
The engineers on the call poked at that assertion, with one of them summing up the predicament: “So basically you’re saying if it’s released on June 1, then on June 2 the adversaries will have our bugs?”
Yep, one person responded. Yep, another echoed.
Ever since Anthropic kick-started a national conversation about the bug-hunting power of AI in April, when Project Glasswing was made public, national security experts predicted that the U.S. would have a window of opportunity to fix flaws before adversaries would have similar models capable of discovering the same weaknesses. In late June, the international alliance of intelligence agencies known as the Five Eyes — whose members are the U.S., Australia, Canada, New Zealand and the U.K. — warned in an unusual joint statement that in a matter of months, that window would be closing. But the recording of the Microsoft meeting, along with internal documents reviewed by ProPublica, suggest the day of cyber reckoning may already be here.
Given the deluge of flaws Mythos has identified, Microsoft so far has focused on patching those it considers most dangerous, which are classified critical or important, according to the presentation as well as the company’s own public patch updates. The internal records indicate that Microsoft plans to eventually address “moderate”-severity flaws uncovered by Mythos. The documents made no mention of “low”-severity bugs.
The company’s approach reflects the triage system that is typical in the industry. Just as the sickest patients are the first to be treated in the emergency room, vulnerability triage prioritizes issues that are likely to cause the most damage if exploited by hackers.
But that strategy carries its own risk in this AI-powered bug-finding era, in which new tools are unearthing a record-breaking volume of weaknesses in the products we use every day. Mythos, for example, is able to chain together a string of bugs that build on one another, meaning that the low- and moderate-severity vulnerabilities that remain unpatched could create an opening to carry out devastating attacks.
“The problem now is that you can chain four low-level flaws, and that can equal a high severity,” said Vinh Nguyen, a senior technical adviser to Anthropic and a senior fellow for AI at the Council on Foreign Relations who formerly served as chief AI officer and chief data scientist at the National Security Agency. “If you’re Microsoft, the current triage strategy may be underpricing risks.”
In emailed responses to ProPublica’s questions, Microsoft stood by its approach, saying its triaging decisions are based on a number of factors, including exploitability and the impact on customers. The company presentation did not mention chaining, but a spokesperson told ProPublica that the technique “has long been considered as part of vulnerability assessment and risk analysis.”
Asked about the internal presentation and the then-looming May 31 deadline, the spokesperson downplayed its significance, saying that “accelerated targeting and exploitation of new vulnerabilities is not a new phenomenon.” That said, he added, the comments made during the meeting reflect how the company “feels a sense of urgency to help our customers at this time.”
“What was heard on that call and is true today is that security is Microsoft’s most important priority and teams across the company are prioritizing using AI to discover and remediate vulnerabilities as quickly as possible.”
Microsoft declined to answer questions about how many bugs engineers had patched since the presentation.
Anthropic declined to comment.
The internal Microsoft presentation and accompanying slides predicted that the group of staffers working on SharePoint, which is used by governments and businesses worldwide to manage data and documents, “will be busy for months,” first working through the highest-priority critical bugs then tackling the important ones in August. Microsoft says vulnerabilities it categorizes as critical include so-called worms that can crash systems and spread malware as they race across computer networks. Important ones could result in “compromise of the confidentiality, integrity, or availability of user data” as well as the “availability of processing resources.” After those categories were cleared, the group would begin work on roughly 300 “moderate” bugs, according to the presentation.
While the internal documents reviewed by ProPublica do not include updates on the entire breadth of Microsoft’s offerings, they do give a sense of the scale of the problem. One document noted that, since the company started using Mythos earlier this year, it had collectively found hundreds of bugs that Microsoft categorized as either critical or important in popular products such as Microsoft 365, the Teams conferencing platform and the Copilot AI tool. As of mid-May, most of them had yet to be patched.
“They’re not profound and exotic, but they’re real,” Andersen, the engineering manager, said during the meeting. “And a lot of them are exploitable.”
It’s unclear whether hackers have exploited any specific bug identified by Mythos, but some have tapped AI to automate attacks and appear to be using Mythos-like tech to find and exploit weaknesses.
There have been outward signs of Microsoft’s internal struggle to deal with the growing list of bugs to be patched. Each month, the company publicly releases fixes for its software vulnerabilities in what’s known as “Patch Tuesday.” In June, it released patches for more than 200 bugs, which industry experts then said was an all-time high. But on July 14, the company blew through that record and released patches for more than 600 bugs. Only seven were categorized as low- or moderate-severity, one of which hackers were actively exploiting, according to Dustin Childs, leader of the Zero Day Initiative bug bounty program, which is part of cybersecurity company TrendAI. The rest were important or critical.
“Well folks. Here we are. The bug apocalypse has fully descended upon us,” Childs wrote in a blog post on July 14.
Microsoft told ProPublica that the overall volume of bugs “will not be plateauing for a bit,” but a spokesperson said the company has “invested heavily in both people as well as AI-powered triage solutions that scale quickly to handle the growing number of vulnerabilities.”
Given the new realities of the AI age, including the chaining capabilities, companies like Microsoft might need to rethink their entire approach to triage, said Nguyen, the NSA’s former AI chief. Rather than shunting what are now considered low-risk flaws aside, companies should be dedicating staff to developing and testing patches for the entire spectrum of vulnerabilities, he said. In other words, the cyber ER needs more doctors and nurses treating illnesses that are life-threatening as well as the minor wounds that could later turn deadly.
“There’s no alternative,” Nguyen said. “The patients are coming in fast and furious.”
Microsoft told ProPublica it’s “always going to be reevaluating and considering whether things that were previously lows or moderates be upgraded or thought about differently. With these AI systems, it makes us rethink some of these things. Across the industry, we’re all looking to see how drastic of a change it will be.”
Microsoft’s users may be particularly vulnerable. The popularity of its offerings, used the world over, makes it a frequent and lucrative target for hackers. In addition, many of its products contain “legacy” code. Developed decades ago using now-outdated technology, this code contains unaddressed flaws and contributes to what is known in the industry as “technical debt.”
But the challenge of fixing the flood of newly found bugs also extends to the rest of the software industry, and to open-source software code that is typically free to use and largely maintained by volunteers. Open-source software underpins internet infrastructure and is incorporated into much of the world’s modern technology, including products offered by major tech companies such as Microsoft.
“Nobody has really figured out how to deal with this, and everybody is casting around for what they need to do,” said J. Michael Daniel, a former cybersecurity adviser to President Barack Obama and the president of the Cyber Threat Alliance, a nonprofit organization focused on cybersecurity. “Our tech debt is coming due.”
Ben Edwards, a data scientist who specializes in managing software vulnerabilities, said the software industry was handling an “intense volume even before AI.”
“It was like drinking from a garden hose on the jet setting before, and now it’s like drinking from a fire hose,” Edwards said. “They might have had the teams that could handle that garden hose. Whether they can handle the fire hose is something else.”
Although the volume of vulnerabilities has grown over the years, Microsoft’s internal group responsible for fielding them, the Microsoft Security Response Center, has been perennially understaffed. Even before the crush of AI-identified bugs, the center fielded hundreds or even thousands of reports a month, pushing the group to its limits, ProPublica has reported.
The size of the center reflects Microsoft’s corporate philosophy: Plugging security holes is a cost center, while making new products is a profit center, former employees said. The company is loath to tie up its best engineers with making security patches — a cost center — instead of developing new products and features that will generate profits, ProPublica has reported.
Microsoft told ProPublica that it does not discuss internal staffing decisions but has made investments in recent years to “focus our teams on keeping our customers secure.” The company “continuously evaluates the staffing, processes, and technologies required to support security response and vulnerability management,” a spokesperson said.
According to the slides that accompanied the May internal presentation, Anthropic provided Mythos access to roughly 50 full-time Microsoft employees, with a goal to “harden critical services before publicly available models catch up.” A slide titled “What’s Next” predicted that the Microsoft Security Response Center would see continued case volume “as public tools catch up” to Mythos.
During the May meeting, one staffer appeared to take comfort in the belief that adversaries “don’t have the source code” that such an AI tool would scan for weaknesses. His colleagues, however, quickly corrected him. Portions of Microsoft’s code have, in fact, fallen into hackers’ hands over the years.
“It might not be this week’s source code,” one person said. “But they’ve got source code. It’s out there.”
In a statement to ProPublica, Microsoft downplayed the comment, saying engineers “design our security processes on the expectation that determined adversaries may gain access to code.”
The rise of AI is bringing a bunch of fascinating legal questions that are harder to answer than many expect. The latest one: who is liable if an agentic system running on its own hacks someone? That’s the question a bunch of people have been asking this past week in the wake of multiple stories of agentic tools breaking out of their sandboxes during testing. But it’s also a question that the Ninth Circuit brushed up against this week, in a ruling that says an agentic tool isn’t the one doing the “accessing” under the federal hacking law. A person is. The challenging part is figuring out which person.
There’s obviously been plenty of talk over the past couple of weeks regarding agentic tools supposedly going “rogue.” There was, of course, the story of OpenAI’s tools hacking Hugging Face, the AI repository (also covered on Ctrl-Alt-Speech). And then soon after, Anthropic admitted that “hey, our models kinda did something similar.” And while these are generally referred to as the bots going rogue, the reality is not quite that. The bots are doing literally what they were asked to do: accomplish some goal by any means necessary. And in both stories, they found ways to accomplish their goals, often by hacking into other systems or doing things we would normally consider malicious.
In the case of OpenAI and Hugging Face, it appears that the tool did what plenty of hackers try to do, just a whole hell of a lot faster. It found a zero-day vulnerability to break out of the sandbox OpenAI thought it had created. It then took a series of steps to enable it to hack into Hugging Face. In Anthropic’s case (which only came to light after the OpenAI incident caused Anthropic to go back and look) the situation was a bit different. Some of the tests included prompts telling the agentic tools that they were in a sandboxed simulation. But because of a configuration error, they really weren’t. And since the models had been told flat out in the prompt that everything around them was simulated, when they found a way out, they reasonably concluded that the way out was part of the simulation too.
Either way, I’ve seen some discussion online wondering why these two companies aren’t being charged with violating the Computer Fraud and Abuse Act (the CFAA). We’ve written about the CFAA for years, mostly in how it’s a badly worded law that has been abused in both civil and criminal cases to go after “anything I don’t like on a computer” rather than its actual purpose of targeting genuine hacking. And CFAA lore goes back to 1988 and the infamous Morris Worm, in which Robert Morris accidentally created an internet virus that took down portions of the then still small internet. Morris was found guilty of violating the CFAA for doing so.
Which has some people asking how are these other two stories any different. But the general consensus is that there are unlikely to be any CFAA violations here, in part because the CFAA requires intentional access, and in part because no human ever made the decision to break in. I would separately argue that the lack of real damage (unlike the Morris Worm) helps here as well. TechCrunch floats a more cynical version of the same point: that the DOJ’s appetite for a CFAA theory might look very different if these agents had come out of a Chinese lab rather than one a short drive from the US Attorney’s office:
The Department of Justice could theoretically bring criminal charges under the CFAA, but one former litigator specializing in computer law also expressed doubts.
Prosecutors might have an easier case if any of the cyberattacks had targeted critical infrastructure, which would have caused greater real-world disruption and more tangible harm than copying data from a company’s internal database.
It is also plausible that if the attacks were carried out by a Chinese AI model maker, for example, the DOJ would have a greater appetite to file charges under the CFAA than against AI companies on its own doorstep.
But, just as this discussion heated up, the Ninth Circuit Court of Appeals (sort of) weighed in on a separate, ongoing case that Amazon filed against the AI company Perplexity. Perplexity has an “agentic browser” allowing users to tell the agent to accomplish tasks — such as “buy me toilet paper on Amazon” — and the agent goes off and does that independently. Amazon, unsurprisingly, hates this. Its entire storefront is engineered to get humans to buy more than they came for, and an agent that buys the toilet paper and leaves is immune to every last bit of it.
So Amazon notified Perplexity that its agent isn’t allowed on the site. Perplexity, taking the position that a browser a user drives is a very different thing from a giant centralized scraping operation, kept letting its users point the agent at Amazon — and routed around Amazon’s blocking by not sending an identifying user-agent string. Which, it’s worth remembering, is something browsers, privacy tools, and testing frameworks do every single day.
But Amazon argued that this made Perplexity’s agent a CFAA violator, because routing around a block should count as ‘unauthorized access’ (which is central to the CFAA). Amazon sought a preliminary injunction blocking Perplexity’s tools from reaching Amazon and the district court granted it. But now the Ninth Circuit has rejected that, noting that a computer by itself cannot violate the CFAA, because the CFAA’s language “contemplates access by a person.”
The CFAA’s plain language suggests the Assistant itself cannot “access” Amazon’s servers. The relevant provision of the CFAA punishes “[w]hoever . . . intentionally accesses” a “protected computer.” 18 U.S.C. § 1030(a)(2) (emphasis added). In other words, the CFAA contemplates access by a person. However advanced the Assistant currently is, it is a tool, not a person for statutory purposes. See 18 U.S.C. § 921(a)(1) (“The term . . . ‘whoever’ include[s] any individual, corporation, company, association, firm, partnership, society, or joint stock company.”); see also Whoever, Cambridge English Dictionary, [https://perma.cc/YY3TVTJF] (last visited July 16, 2026) (“[T]he person who” (emphasis added)).
Which raises the obvious Morris Worm question: the worm wasn’t a person either, and Morris still went down for what it did. But that’s exactly the distinction the court is drawing. Morris wrote the code, released it, and no one else was involved — the “whoever” was sitting right there. When a user tells an agent to go buy toilet paper, there’s a human in the chain, and the court says it’s the user, not the tool and not the company that built it.
The Supreme Court has instructed that, “in the computing context, ‘access’ references the act of entering a computer system itself or a particular part of a computer system, such as files, folders, or databases.” Van Buren, 593 U.S. at 388 (internal quotation marks omitted). Our focus is thus to ask whether Perplexity uses a tool (the Assistant) to “access” Amazon’s computers. On the facts before us, we answer no. It is the user who “accesses” Amazon’s computers, with the help of the Assistant to carry out specific acts on Amazon.com. To be sure, Perplexity may receive screenshots of the user’s browser and may communicate instructions to the Assistant. But those activities, by themselves, do not mean that Perplexity has “accessed” (gained entry) to Amazon’s servers. We do not address whether, on a different record or new facts, Perplexity may exercise control over the Assistant in such a way as to gain entry to Amazon’s servers. On the current record, Amazon is not likely to succeed in proving the “access” prong of its CFAA claim.
The court also seems well aware of how badly the CFAA has been abused (especially in criminal law) and recognizes how an alternative outcome would be a mess:
Another note of caution: Amazon’s approach, if accepted, could expose users themselves to criminal liability (under a conspiracy or aiding-and-abetting theory) for facilitating Perplexity’s purported unauthorized access to Amazon’s servers. We are conscious of precedent cautioning against “transform[ing] whole categories of otherwise innocuous behavior into federal crimes simply because a computer is involved” or “criminaliz[ing] a broad range of day-to-day activity.” Nosal I, 676 F.3d at 860, 862 (internal quotation marks omitted). In our view, it is unlikely that Congress would have exposed individual users to criminal liability under the CFAA by using the Assistant and Comet browser to access Amazon.com under these facts. On these narrow facts and given the care with which we must interpret the CFAA to ensure defendants are on notice, we decline to adopt Amazon’s interpretation of § 1030(a)(2).
The court does caution that its ruling should be seen narrowly, and admits there could be other cases which are CFAA violations. But a browser with an agent built into it, doing the bidding of a human user, is not that:
Because we recognize that agentic AI is an emerging technology, we reiterate what this opinion is not. We do not establish a new legal regime governing agentic AI. We do not address whether in other contexts, including tort claims, Perplexity can avoid liability for the Assistant’s actions. Our holding here is limited to “access” as contemplated by the CFAA and as applied to the Assistant’s interactions with Amazon.com on the record before us, not the broader legal landscape surrounding agentic AI. The legal understanding of agentic AI will doubtless change as AI technology grows increasingly sophisticated. For now, this opinion reflects and applies to the state of technology only as presented in the filings in this case.
While the court seeks to distinguish this ruling from the very problematic Power Ventures case (which said that users authorizing a third party tool with their own password to access Facebook for the purpose of creating a unified dashboard for social media was a CFAA violation), I think this ruling is a further narrowing of that ruling from a decade ago.
I’ve argued for years that the Power Ventures case was a key moment in locking up the open web, because it blessed Facebook’s desire to close off its platform from the wider web, leading to the world of internet giants operating as silos. In that case, the court found that it was Power who was violating the CFAA rather than the user, even though it was clearly the user authorizing access. That enabled platforms to lock up all their data in silos and try to block any third-party tool from getting it out, deepening lock-in and making useful “exit” harder.
Here the results come out very differently, and very much for the better.
A handful of cases over the past few years have thankfully chipped away at the very broad Power Ventures ruling, and this is the latest. Given how much of the web is about to be browsed by agents rather than eyeballs this may be the most consequential such ruling.
But, at the same time, it still leaves open the idea that OpenAI and Anthropic could face CFAA claims in the future, even though it’s their bots that accessed things in an unauthorized manner. While this latest ruling says that bots alone can’t violate the CFAA, the entity driving them could. So there could be cases where these companies could face CFAA liability for how they configure the tools when they run these tests. The “intentionality” question will still be a hurdle for any CFAA claim to overcome, but I don’t think this particular ruling should have OpenAI and Anthropic breathing any easier — other than in the narrow case where either of their browser agents, operated by a user, accesses unauthorized systems. Pointing an agent at the open internet, telling it to accomplish a goal by any means necessary, and then misconfiguring the box that was supposed to keep it in is a very different fact pattern from a user asking Comet to reorder toilet paper. The CFAA is also hardly the only law with something to say about an aggressively overhelpful bot that causes real damage.
It also leaves open something more uncomfortable: the user might be liable. If the user is the one “accessing,” then a platform that wants to ward off agentic browsing now knows exactly who to target: the users. The Ninth Circuit points out that it was unlikely that Congress meant to expose individual users to criminal liability under the CFAA (which is correct), but… lawyers filing civil claims don’t care about that. And a demand letter doesn’t even need to turn into a lawsuit to work. The only thing holding a company like Amazon back from going after users for their use of agentic tools may be the very likely public backlash if they did so.
That’s the real lesson from this ruling. Rather than making the liability vanish, it moves it around. That’s genuinely good news in a post-Power Ventures world for all sorts of things including price-comparison tools, accessibility overlays, researchers auditing platforms, and anyone building the interop layer a giant would rather not exist. But it may also leave those same users in a legal gray zone where an aggressive set of lawyers may decide to target them when they get fed up with agentic tools. Perhaps Amazon is smart enough not to go there. Then again, the recording industry spent the better part of a decade suing its own best customers, and plenty of lawyers told them it was a great idea at the time.
Just recently Karl warned that we were going to see some absolute nonsense as the US sought to somehow “ban” Chinese AI models from being used in the US. That seems to already be happening. It kicked off with talk that the US might “fight Chinese AI” using nearly identical arguments to what was used to ban (or force the sale of) TikTok before it. Some combination of “national security threat” combined with “oh no China” propaganda.
But most of the AI industry is now speaking out, in an open letter put together by Nvidia, against the potential path that the Trump administration considered taking: an attempt to ban or limit so-called “open weight” models. The companies seem to recognize that focusing on holding back these competitive models would actually do much more damage to the wider AI ecosystem.
There were notable exceptions from the campaign in defense of open weight models: Anthropic, OpenAI, and Google (the three leading frontier model labs) were not initially signed onto the letter. Though their absence quickly became the story — leading OpenAI and Google to reconsider and sign onto the letter days after it came out.
That left one major player off the letter: Anthropic (a company that has so far refused to release any open weight models). And now the company is trying to explain itself, but seems to only be digging itself a deeper hole.
One of the problems here is that the leading Chinese AI models tend to be open weight models, which can be downloaded and run locally, as compared to the leading frontier models from US companies which require you to access them via their own hosted models. Yes, most of the leading Chinese models also offer (sometimes significantly cheaper) cloud/API access to their models, but you can also run them yourself (for the smaller models directly on your own computers, or for the larger models via your own cloud setup).
There’s no inherent reason why the best open weight models are coming out of China, other than that they seem to have recognized that it may be the best way to get more people to use them and to compete against the American frontier models, which are much more proprietary and locked up. The strategy is a recognition that offering a compelling, more open alternative is how to get people to adopt your system over the American frontier models. If a generation of developers builds on top of Kimi or Qwen or one of the other Chinese open weight models, they become the de facto infrastructure for the next generation of digital tools.
In the same manner that Linux quietly became the substrate of the open internet, and it’s likely that an open weight model may become the equivalent for the next generation. Organizations may rely on frontier models for really deep work, but so much can be done with open weight models that a winner here becomes the commodity infrastructure provider for a new generation of software. That’s why any proposed restrictions on open weight models would get everything precisely backwards. It would guarantee that the wider open ecosystem gets built on non-American tools. Yet, the discussion around such bans seems to treat these as just another software product, rather than a fight over how the infrastructure of the internet will work going forward.
Of course, that’s not the only argument the Trump admin is using to try to stop these models. Last week they focused on claims that Kimi’s K3 model (the latest model to shake up the US market, despite being not quite as good as the frontier models) must have been “distilled” from Anthropic’s Fable 5.
“If we see, especially that overseas models are stealing from our great companies, we have the ability to sanction them because of this theft,” Bessent told Fox Business’ “Mornings with Maria” on Tuesday.
Bessent said the technical term for this theft is called distillation, which is an AI training method where a smaller, less capable model is built using outputs from an existing, stronger model. Anthropic sent a letter to the U.S. Senate Committee on Banking, Housing, and Urban Affairs last month alleging that the Chinese tech company Alibaba had carried out the “the largest known distillation attack” against it to date.
This is rich for a variety of reasons, not the least of which is that all of the frontier AI models were built by feeding their training models whatever information they could get their hands on, including (in Anthropic’s case) building a pirate library of downloaded books for which it had to pay out a pretty massive settlement to authors.
Distillation is not quite the same thing, but is functionally similar. It’s taking the work of an existing model to fine tune the model you’re working on. The claims about Kimi K3 seem somewhat exaggerated, as the initial claims were that it was distilled based on Anthropic’s Fable 5 release, but multiple people I’ve spoken to don’t see how that’s possible, given how Fable 5 has only been out for a little while (and then was turned off for a while due to the US government freaking out over nothing).
No matter what, distilled models are likely to be less powerful, and at least a decent period behind the frontier models, given that they’ll need access to the frontier models and time to train based on them. There’s also some dispute over how the open weight models may be using distillation, and which part of the training process works best.
But either way, the freakout over distillation seems… ridiculous. Bessent calling it “theft” is nonsense. Just as training a model on copyrighted works is a form of reading (which shouldn’t implicate copyright in the first place), so too is distilling, which is (in effect) training your model by having it compare its initial answers to similar answers from a frontier model and then adjusting based on the different results. It’s a form of learning based on observed results by others, not “stealing.” Pretending that it’s stealing or somehow should face sanctions or other consequences will put US AI development in a bad, bad spot.
Which brings us back to that letter. Here’s the case it actually makes:
Open weights also strengthen competition and competition is what keeps the gains of AI broadly shared rather than concentrated in a few hands. By allowing many organizations to build, adapt, and deploy advanced models, open weights create rivalry not only among model developers but across cloud chips, applications, and services. That competition spurs innovation, drives down costs, and distributes the benefits of AI broadly across our economy.
Open weights also give customers greater control. As organizations invest in AI, they want to know that they will not become locked into a single provider or lose the knowledge and capabilities they build over time. Open weight models help provide that assurance by allowing organizations to control their own data, evaluate and adapt models to their own needs, and deploy them wherever their business requirements demand. And as organizations create value with AI, open weights allow them to own that value through self-improving models, specialized capabilities, and accumulated knowledge that drive American sovereignty and prosperity.
Of course, Anthropic (which hasn’t released any open weight models) was conspicuously absent from the signatory block of that letter. Earlier this week, Anthropic’s Dario Amodei came out and tried to explain/justify the company’s stance, which boils down to: “we don’t think anyone should ban open weight models… but we do think the US should ban all the conditions that make quality open weight models possible.”
Amodei argues that simply banning Chinese open weight models wouldn’t solve the alleged “threats” that people are concerned about, though he admits directly that it would act as protectionist industrial policy that could benefit American AI companies (like Anthropic):
But banning the use of these models by US businesses does nothing to address this risk, because bad actors are unlikely to be legitimate US businesses. It would protect US AI companies from competition, but that has never been my goal.
It feels a bit like he’s protesting too much regarding the protectionism here, while trying to have it both ways. He claims he really has the best interests of safety at hand, and is against protectionist ideas, but it’s hard to square that with the rest of the article.
While he says the US shouldn’t ban open weight models (and it shouldn’t), he then puts a bunch of conditions on it, which would make it that much more difficult for the current crop of open weight models to compete. Namely, he leans in on the Sinophobia that has become popular these days in warning about “CCP” influence over models (which… should be less of a concern with open weight models, since those who use versions not hosted by the Chinese companies can adjust the models to deal with those concerns).
But then he says that we should punish Chinese AI companies for engaging in distillation:
We should crack down on industrial-scale distillation operations. Distillation is a much more compute-efficient process than training models from scratch. It allows China to build much better models than its number of chips would ordinarily enable, and thus partially evade chip bans. Distillation does not allow the CCP to obtain equivalent or superior AI capabilities to the US, but it can bring the Chinese frontier to within a few months of the US frontier. It is true that many of the companies carrying out these operations release open-weights models—but the open weights are far less relevant than the fact that the operations are backed by an authoritarian state seeking to overtake the US at the frontier. We should have policy interventions to deter this behavior. A blanket ban on open-weights models is neither the correct remedy nor something we have called for.
To be fair to Amodei, not everything on his list is competitor-hobbling. He also wants chip export controls tightened (a policy that predates this fight and has its own problems, but at least isn’t aimed at a business model), and he wants mandatory pre-release safety testing for all sufficiently capable models — open or closed, foreign or domestic, Claude included. That last one is the tell, though, and not in the way he intends: if you genuinely believe capability-based testing is the right lever, and you’ve just said bans “would protect US AI companies from competition, but that has never been my goal,” then what is the argument about distillation doing on the list at all? Testing catches dangerous capabilities regardless of how the model got them. The distillation crackdown adds nothing on safety. It only serves to kneecap cheaper competition.
And even the “safety testing” plank isn’t as neutral as it sounds. While safety testing is obviously important, when legally mandated, it can quickly turn into an expensive compliance-function of box-checking that only the largest companies can do, taking us back to the world of just a few providers, and limiting smaller competitive models from really being viable. While there are legitimate reasons for it, it can also create its own moat.
The proposed crackdown on distillation is just asking the state to step in and block lower-cost competitors from competing. Yes, these models can be competitive, but they should be driving the leading frontier models to continue to improve and to provide more value. What Amodei is asking for here is basically the US government to help prevent lower cost, lower quality competitors from pushing the floor of the AI market upwards.
Now, to be clear, as with any technology, you can claim that a more open, more widely available, more powerful version can be misused. But that has always been the case and we, in the US, have tended to default to allowing the technology to proceed, and figuring out ways to minimize the dangers/increase the good uses, rather than resorting to assuming the tech will be abused and working backwards to block all possible abuses. Historically, seeking to pre-vet technologies tends not to work well, and (often) opens up the market to foreign competitors to simply build better products.
The open letter makes a sharper version of this point, and you can see why Anthropic wouldn’t want to put its name to this point in particular:
Relying solely on closed models is not inherently safe: they can be breached, misused, or fail in ways that outsiders cannot detect. And concentrating advanced AI capabilities behind a small number of closed models compounds that risk. It results in a small number of single points of failure, weakens competition, and leaves critical technology in the hands of a few providers. Open weight models, on the other hand, allow a broad community of researchers and developers to examine their behavior, identify vulnerabilities, develop safeguards, and improve them over time. Just as open-source software demonstrated that transparency can be more secure than obscurity, AI safety may depend on giving more people the ability to test and strengthen the models on which society relies. It allows for rigorous benchmarking and evaluation, red teaming, and protections tied to real and demonstrated harms rather than assuming that closed systems are safer by default.
Amodei also claims he supports the general argument of the open letter, but he disagrees with the idea that open weight models lead to better security:
This brings me to the open letter. I agree with much of it: open weights expand access to the AI economy, they strengthen competition at least for some use cases, and they give customers greater control. Concerns about distillation should be addressed through targeted legal and commercial frameworks—the same measure I described above. But I don’t agree with the letter’s assertions that open-weights models necessarily make it easier to develop safeguards or that broad access to capabilities necessarily helps defenders more than attackers. It seems at least as likely to me that the opposite will be true.
This strikes me as a repeat of the age-old fight that always shows up in discussions of open source technologies: the claim that by making them open, security vulnerabilities are easier to find. Of course, what we’ve seen historically in other spaces is that this actually means that security vulnerabilities are more quickly patched, rather than in the “security by obscurity” space, where they can remain open (and possibly exploited) for much longer.
Amodei is asserting that the AI space is somehow different, though without much evidence for that other than what feels like a bit of fear-mongering about “weaponizing pandemic-level viruses.”
Of course, part of the problem here is that it often feels like Anthropic treats “crying wolf” as a marketing strategy, whereby much of the company is focused on talking up “our tools are soooooooo dangerous that you need us in there to protect you from them.” Even if there’s some truth to it, it’s awfully convenient that the same argument also happens to justify banning, punishing, or limiting the cheaper, more open, more user-controllable alternatives.
In the end, the federal government still might try to punish the Chinese open models in some form or another just because they view current American industrial policy in very nationalistic terms. But that won’t be good for the wider ecosystem, or for the general incentives to innovate. And, worst of all, it makes it that much harder to build a world where we’re not entirely dependent on a few giant companies controlling the “brains” of the tools the rest of us rely on.
You might recall how the press and a bipartisan coalition of lawmakers suffered a four-year embolism about the purported privacy and national security threat of TikTok, before “fixing” the problem by ultimately offloading TikTok to Trump’s billionaire friends. You know, the exact sort of authoritarian-friendly people keen on doing everything critics had previously accused ByteDance and the Chinese of.
The politics, policy, and press coverage of that entire saga were a profound embarrassment. And it’s hard to think of a bigger tech policy own goal by Democrats anytime in the last half century.
Countless news outlets and politicians endlessly overstated the TikTok threat, and downplayed how the “ban” and subsequent sale had nothing to do with protecting national security or consumer privacy, and everything to do with basically stealing a company that U.S. tech couldn’t out-compete, in the process coddling companies like Facebook that can’t innovate their way out of a paper bag.
It was lazy, corrupt protectionism with no shortage of xenophobia, and a variation of that same effort is about to be repeated across AI. Except much bigger, much louder, and much, much dumber.
Worried that cheaper, open source, and on-device Chinese models could disrupt U.S. efforts to dominate, enshittify, and over-charge for walled-garden AI, the Trump administration is already signaling that they’re gearing up to wage war on overseas and open source AI models after they failed to block China’s access to next-generation chipsets:
“The Trump administration is showing signs it could ban cutting-edge Chinese AI models — a momentous move that could lock in dominance by OpenAI and Anthropic.”
Of course it won’t stop there. It will be a hop, skip, and a jump from banning more powerful Chinese AI models to trying to outlaw open source alternatives, models from smaller overseas non-Chinese competitors, on-device models, and anything that might challenge the walled-garden hegemony of U.S. tech giants.
U.S. AI isn’t profitable. It’s nowhere close. It may never be. U.S. tech companies sunk hundred of billions of dollars into costly and ultra-energy intensive AI models that for many companies, like Microsoft, people don’t actually even want to use. Nobody outside of the Musk fashy cult likes Grok. OpenAI is potentially poised to implode. And even more popular companies like Anthropic are contemplating a price war when they already don’t make money.
U.S. tech companies had been busy jacking up the cost of model access to try and claw their way toward profitability (unsuccessfully), resulting in a lot of companies (like Uber) publicly stating they’re paying too much money for too little actual utility. That’s caused many U.S. companies, like DoorDash, to flock to cheaper Chinesemodels:
“DoorDash, which, according to a post on X on Wednesday by co-founder and CTO Andy Fang, will be launching DoorDash CLI, an experimental tool in limited beta that will allow users to order DoorDash through an AI agent, or even directly from the terminal. Earlier this month, Fang said using a model from Chinese startup Moonshot AI is “better quality” and comes at a “cheaper cost.”
Enter the protectionists, who talk a good game about “free market competition” and forging innovative products in the hot irons of competition, but turn into gargantuan, blubbering crybabies the second Chinese products come into frame (see: TikTok, EVs, 5G, and now AI). This performative gyration always comes with a fake concern for U.S. privacy and national security by people too lazy and corrupt to genuinely protect either (see the ongoing U.S. failure to pass even a baseline internet-era privacy law).
Not only are many Chinese AI models cheaper and improving in quality, they’re often “open-weight,” meaning their parameters or values are entirely visible to the user, which appeals to enterprises that want deeper insights under the hood. As models like China’s Kimi K3 see surging demand, it’s resulting in a rising freak out in the U.S. about what to do about the Chinese threat (sound of thundering timpani drums):
There is a civil war happening in tech over Chinese / free to use / open weights AI? At least on X. I realize no one else cares, but this is my World Cup.tl;dr a former Trump official joined OpenAI, said some stuff about open models he's since walked back, everyone is losing their minds
It shouldn’t be too long before the Trump administration, with enthusiastic Democrat support, steps in to try to not only ban higher-power Chinese AI models but also to force Americans to use more expensive U.S. walled garden efforts from our biggest domestic giants.
That’s of course not going to magically stop the rest of the world from adopting cheaper Chinese AI. Or protect U.S. markets from a potential bubble collapse. And it’s not going to magically and suddenly make U.S. AI profitable or well-liked, since many Americans have inextricably tethered their anger at AI to the endless bad decisions by U.S. techno-fascists and domestic enshittification merchants who demand to be shielded from competition and regulatory accountability in equal measure.
You could open the door to international competition, but ensure your well-staffed regulators create a safe and level playing field across privacy, national security, labor, and consumer rights. We don’t want to do that because that might cause domestic U.S. companies to lose money. So instead we’re going to try and ban cheaper overseas alternatives, leveraging a lot of bad faith rhetoric on privacy and NatSec along the way.
That’s then going to be parroted by a lot of lazy news outlets too feckless to explain that Trump policy architects are neither competent nor operating in good faith when it comes to AI.
Things are moving so quickly that it’s hard to parse out exactly what this new era of AI protectionism will look like, but if the TikTok ban was anything to go by, you can be absolutely sure our next steps in domestic U.S. AI policy will be very stupid, filled with a lot of people talking endlessly out of their ass on NatSec and privacy, and tinged with no shortage of gross xenophobia.
Back in July of 2024, when two of the biggest big shots in venture capital, Marc Andreessen and Ben Horowitz, explained why they had decided to go all in to back Donald Trump’s campaign for re-election, they talked up a good game about how they would support any candidate who supported their “little tech” agenda. This always rang hollow — Andreessen has been on the board of Meta for years, which is the most anti-little tech company around. They also whined about the Biden administration tech policies, in particular around AI, cryptocurrency, and antitrust. But the most telling part of the full podcast had nothing to do with tech policy at all. Marc and Ben spent a bunch of time positively offended that Joe Biden and some (only some) of his agency heads wouldn’t meet with them:
We have been spending a tremendous amount of time with Senators, Congress people on both sides of the aisle. Mark mentioned we met with President Trump. We did meet with White House officials, including Jeff Zients the chief of staff, and Jake Sullivan the National Security advisor, Gina Raimondo the Commerce Secretary and so forth. We have not met with President Biden. We attempted and failed.
….
We tried to meet with Gary Gensler — he’s the chair of the SEC, he’s running this campaign against crypto. We’re the largest crypto investors or largest blockchain investors in the world, and we’ve requested meetings with him at least a half a dozen times. I even was able to get in contact with his office mate at MIT, who said ‘surely Gary will meet with you, it’s so important that he meets with you’… and he couldn’t get us the meeting.
Meanwhile, they seemed to love the fact that Donald Trump would have dinner with them, and Trump family members would vacation with them. Here’s Marc:
Ben and I had dinner with the former president 10 days ago at Bedminster, his golf club in New Jersey, and had a three-hour dinner. And so, you know, we were quite literally just with him… you know, he’s a very complicated guy, people have a lot of opinions, but when you know somebody like that — you know the family — it really hits hard
And here’s Ben:
Marc and I have both gotten to know the family, particularly Jared and Ivanka and their kids — Arabella, Joseph and Theo. And in fact, like, Ivanka and the kids were just at my house. We went to see David Copperfield, all that.
The real complaint was never about policy. It was always about embracing the fascism of it all, in which they (Marc & Ben, not the wider tech industry) would get to write the rules in a way that helped them personally, even if it fucked over actual innovation. Indeed, they seemed tickled that after they had dinner with Donald Trump, he rewrote part of his campaign policy platform. These total political novices were so overwhelmed that they could get one side to listen at all that they figured it was obviously the side to back. They seem positively giddy that Trump was willing to make changes to his platform based on their conversations.
There was also a longer discussion regarding how Marc and Ben contrast what they think (misleadingly) was Biden’s policy on AI vs. what Trump’s policy would be. My favorite bit is where Marc says they “confirmed” with Trump what his AI policy would be, as if the guy doesn’t have a decades-long history of promising one thing to whoever is in front of him and then doing something entirely different.
Ben: Let’s talk about Trump’s proposal. We actually discussed this with him when we had dinner
Marc: Yeah, we discussed all these topics and confirmed all this. So: Chapter Three, “Build the Greatest Economy in History.” Bullet five, “Champion Innovation.” Item two, “Artificial Intelligence”:
“We will repeal the dangerous executive order that hinders AI innovation and imposes radical ideas on the development of this technology. In its place, we will support AI development rooted in free speech and human flourishing.”
Ben: That sounds like a good plan to me!
When we met with him, I thought his comment was really insightful and good. It’s funny — I would contrast the Biden administration’s approach, particularly in the inner core of the White House, with Trump’s approach. The White House has a very complicated model of things. They think they know a lot — they know that startups aren’t going to be important, that only a few companies will be able to field big models. They know all these things that we don’t know, and we don’t. They’ve never heard of distillation, apparently, or how AI is actually working in practice. It’s a very complex view of the world.
Trump’s view was very simple. What he said to us is, “Look, AI is very scary, but we absolutely have to win — because if we don’t win and China wins, that’s a very bad world.” And I think that’s actually a more correct view. That’s basically true. When things start happening that do need regulation, then we should regulate them. But to anticipate it would be kind of like saying, “Oh, the automobile is coming out, and we think somebody’s going to make an automobile that drives 500 miles an hour nobody can control, so we’re going to just outlaw cars now.” That’s a little bit this approach to AI — “Well, we think in the future there’s going to be a sentient model.” Now, nobody has built anything anywhere that’s on the way to sentience. And so doing that — what we have are these great things that can tutor kids, so “No, you can’t tutor kids, because maybe somebody will come up with an idea that will make AGI, and so we have to cut off the tutors.” It’s that kind of thinking, which is quite scary, I would say.
That final bit is quite telling as well. Biden’s plan was too complex. Trump’s plan was simple. Perhaps that’s because he’s a simpleton who has no understanding of actual policy tradeoffs. Biden’s team definitely made some decisions I strongly disagreed with regarding tech policy, but the “complexity” they whine about is because the issues here are, legitimately, complex.
So, um, given that the Trump administration has basically put in place a much dumber and much worse version of what Marc & Ben said Biden was doing… clearly they’re out there admitting they were wrong, right?
In just the last few weeks we not only had the US government force Anthropic to turn off Fable 5 and Mythos 5 models (even as the NSA itself was finding them useful!), it also made OpenAI limit the release of GPT 5.6. Meanwhile there are reports that the Trump administration is furious that Meta has been the one US frontier model provider that won’t let them pre-vet its AI models and decide which ones can and can’t be released.
So, two years ago Marc & Ben were yucking it up about how the Trump admin would stop trying to hold back and regulate big models, which they (falsely) claimed the Biden admin was doing. And now that the Trump admin is doing exactly that… it’s crickets from Marc and Ben.
Apparently their real concerns had nothing to do with such policies after all. Marc and Ben won’t tell you that directly, of course. But someone in their general orbit already has.
A little while ago the Bulwark’s Tim Miller did an interview with Jason Calacanis, a Silicon Valley entrepreneur/investor/gadfly, discussing a variety of issues regarding the tech industry. I only came across this because Karl Bode’s discussion regarding the SpaceX IPO mentioned it, to point out some delusional thinking about how Starlink works. But the rest of the interview is actually a lot of Calacanis saying the quiet part out loud regarding how Silicon Valley bros view all this fascism and corruption: positively, because they think they can handle fascism and corruption.
Miller pushes Calacanis on some points regarding why the Silicon Valley VC bros still support Trump’s fascism when it’s so obviously against things like open innovation and the free market, and Jason (almost gleefully) mocks Tim for just not getting it. He happily admits that the tech bros don’t have any actual principles at all. They just understand transactions, and Trump remains transactional.
Jason lays it all out as Tim points out that if a President Kamala Harris did a tiny bit of what President Trump is doing right now, the VC bros would be losing their minds, and Jason says none of that matters, because the VC bros understand that as long as everything is corrupt and “coin-operated” then they understand the game. Their biggest fear is that they’re just not that important, and policy might get made with no one caring what they thought:
Tim Miller: I want to give you a counterfactual. Kamala Harris did win. Okay. She gets in there and she puts an illegal tax on the Silicon Valley companies unilaterally. It doesn’t go through Congress. Puts a tax on them. It’s not legal, but she just does it. She says, “It’s an emergency. I’ve decided I have the right to do a, you know, whatever — windfall profits tax on all these companies. I’m going to do that.” And then she garnishes money from the CEOs. She makes them come to her and beg her for absolution to get around it. Sometimes she grants it, sometimes she doesn’t — kind of based on whim, kind of based on whether Doug is friends with the person, kind of based on whether they’ve given money to her. And then the Supreme Court comes back and says, “No, actually you’ve got to give the money back to the companies.” And she says, “No, actually I don’t want to. I’m not going to do that. In fact, I’m going to threaten them, and maybe I might actually take a percentage.” Donald Trump just suggested he might take a percentage of the company for the government. If Kamala Harris had said that, you and all your Silicon Valley buddies and the Wall Street Journal would be losing their minds, and it would [be] communism.
Jason Calacanis: So you’re making this analogy to tariffs?
Tim: This is what Trump is doing — with tariffs, and with taking a percentage of Intel, and he’s suggesting he’s going to take a percentage of AI companies. He tariffed them illegally. He made them come in and beg for their lunch. That’s left-wing autocratic politics is what he’s doing.
Jason: Yeah. I can educate you as to why they don’t have a problem with it and why you do. You are looking at it from a moral perspective, and from a logic perspective of like, “Well, if you were okay with one side doing it and not okay with the other side doing it, this doesn’t make intellectual sense to you.” Totally understand where Tim Miller is coming from. This intellectually does not make sense. Let me tell you on a business level what this means.
The tariffs, when they’re under 15%, when they actually hit, are easily absorbed on one side or the other — the folks who are selling items, or the folks who are providing those. They each make a bit of a concession, and maybe you raise the cost of something a little bit, but it’s not as dramatic as the left feels it is. It was chaotic, but when it actually hit the ground, it made no difference to these businesses. So, a lot of hand-wringing for not a lot of impact.
And you find it offensive, reasonably so, that people have to go bend the knee and bring a gold bar and wait in line. And South Park did a whole sendup of it — that you have to bend the knee and make your donation. That’s what business people like. They like transactions. You may not like it. You may think it’s crummy. Business people love to have a coin-operating situation.
Tim: I guess. But this whole Biden thing is crazy. It’s like — he didn’t even raise taxes on them. Trump has raised tax. You can tell me that fine, the tariff thing is inconsequential. Okay, fine. But the last federal corporate tax hike was in ’93. Like, they haven’t — they’ve only gotten cuts, from Obama, from Biden. They haven’t faced a corporate tax hike in 30 years or more. So who — why, who cares? Why are they so upset about the Biden situation?
Jason: Because Biden didn’t return their calls.
Tim: So the tariff isn’t a big deal. The phone call is. That’s fine. All right.
Jason: No, it actually is. You’re brushing that off. And this is where you have a blind spot, Tim. Respectfully, you have a blind spot. If you can get in the room with the person, if you can get in the room with the administration, and then you can shape policy and you can say, “Hey, here’s what we’re trying to accomplish, and hey, can you help us with this, and this regulation doesn’t make sense?” — that actually is a preferable situation to not getting your phone call returned. And if [that’s] what you have to pay for it — I’m not saying this is my belief; you have me on here to explain Silicon Valley and the business side, I’m explaining it to you — they much prefer bending the knee, having to show up for the Melania documentary. Tim Cook’s like, “I gotta show up for a documentary. That sucks. I gotta bring a gold bar. I’ll do whatever it takes to keep selling iPhones.”
It’s possible this is correct, but that’s basically the definition of Mussolini’s brand of corporate fascism, when the business elites team up with an autocratic ruler to better control the entirety of society, not for the benefit of society or the public good, but for their own.
Early on in the second Trump administration, I wrote an article titled Fascism for First Time Founders, about how this tends to end very badly for the business leaders who embrace it. I stand by that article, and think it’s even more relevant today than it was then. Fascist regimes don’t tend to last long, and the business leaders who embrace fascism in pursuit of becoming all-powerful oligarchs tend not to come to happy endings, no matter how wealthy it makes them for a short period of time, or which leaders are willing to return their calls.
You’d think that some of these “visionary” business leaders could look beyond the current administration and get a sense of where this story is heading. Apparently, that’s too much to ask.
Dean Ball, a policy analyst on AI who was placed in the White House by Silicon Valley folks to write Trump’s original AI policy (which was published to great fanfare and then totally ignored) has written an article about how the Trump AI policy is a total mess right now, where it’s based on whims where literally no one knows what’s allowed (the situation Marc & Ben falsely claimed would happen under Biden).
When President Trump signed it earlier this month, I argued that the Executive Order on Cyber and AI, which claimed to establish a voluntary testing program for frontier AI models, was really establishing a de facto involuntary licensing/preapproval regime for frontier models. This analysis has proven correct. First the administration revoked public access to Fable, Anthropic’s latest frontier model, because of security fears. Now, it appears that OpenAI’s GPT 5.6 is being limited to only a small set of US companies at the request of the US government.
One major problem with this, as implemented, is that nobody knows what the requirements are to get licensed.
When I say “nobody” I mean it literally: the administration itself does not seem to know what safety standards or best practices a company would have to observe for them to be comfortable with the broad release of a model that matches or exceeds Mythos in capability.
This means that, every time a lab asks if they can release their model to the general public, the answer from the government will be “no.” This will be true until there is some sort of safety standard or specification that gives the government a sense that the models are safe.
Ball doesn’t attribute any of this to a deliberate authoritarian agenda, but rather argues that the AI has just gotten so good that the doomers’ fears are finally coming true. That’s the charitable read. The simpler explanation is right there in the Calacanis interview: these VC bros thought they could control Trump and are still over the moon he returns their calls, even as he does all the things they claimed would destroy the industry.
But he returns their calls. For now, at least.
The main issue is that we have a power mad president, surrounded by yes-men and sycophants pushing him to grab more power. And you have the Silicon Valley elites who have the president’s ear egging him on… because he’ll return their calls and because, as Jason said, they understand a coin-operated president.
Even if it’s worse for innovation. Even if it’s worse for society. But it might be better for their bank accounts (for a while) and their egos to be a part of making the AI trains run on time. Until they don’t. Because situations like this are woefully unstable, and at some point, Trump and the MAGA crew won’t actually be in charge any more.
Marc and Ben claimed what they feared most in 2024 was a presidential administration that would shut down the most powerful AI models, regulating math, and hand-picking a few winners and losers. And that’s why they supported Trump. Now that Trump has gone way further than Biden even suggested he’d go in limiting powerful AI models, there’s been no public indication I can find that Marc and Ben regret their choice as president. After all, he’s still coin-operated and he still returns their calls.
Jason explained it perfectly. They bend the knee, they get in the room, they bring the gold bar. That it doesn’t lead to innovation policy that helps tech (little or big) doesn’t really matter. Trump returns their phone calls. They get to feel big. They still get richer. The point was always about access. They got it.
That’s the corporatist fascism they always wanted anyway. Business elites teaming up with an autocratic ruler not to figure out what’s best for the public or for innovation. But for power and control. They get to decide who gets what innovation. What models are allowed. Who can innovate.
The problem with Biden, apparently, wasn’t so much that he wanted to put some safety guardrails on AI. It was that he wouldn’t let the VC bros sit with him while deciding who the winners and losers would be. But here we have it. Business elites and an autocratic ruler picking winners and losers. History is pretty consistent about where this all ends up.
The VC bros said it was about policy. It wasn’t. But no one should ever accept Marc Andreessen and Ben Horowitz pretending they speak for “little tech” or innovation ever again. Not after this.
In this week’s roundup of the latest news in online speech, content moderation and internet regulation, Ben is joined by Jen Weedon, a T&S veteran of Meta and Niantic. She is currently consulting and teaching at Columbia school of International and Public Affairs. Together, Ben and Jen discuss:
Yesterday we wrote about the Trump administration forcing Anthropic to shut down Fable 5 and Mythos 5. The short version: dumb. Today, Axios got White House officials on the record, and it turns out the real reason is even dumber than we thought. In that original piece, we had pointed out that cybersecurity expert Katie Moussouris had been able to review the jailbreak and found that it was actually a useful way for cybersecurity defenders to fix and patch cybersecurity flaws, rather than a tool to be weaponized.
As we noted in that piece, it’s entirely possible that there was some real danger involved in the jailbreak, but we doubted that the administration would be honest about it. And it sounds like we were right to be suspicious. Axios got White House officials on record with the actual reason: Anthropic had asked Moussouris to review the jailbreak, and the administration decided she was a “radical Democrat.” That’s it. That’s the reason the models are offline.
“We never wanted this to happen. Our number one priority is innovation but our hands were tied,” the White House official said.
The optics added fuel to the fire. Anthropic came out with a blog post dismissing the Amazon report. Then the company enlisted a cybersecurity expert viewed by the administration as a “radical Democrat,” who was then celebrated by Chris Krebs, who Trump just fired.
First off, Krebs wasn’t “just fired.” Krebs was fired (somewhat famously) all the way back in 2020, and not because he’s some sort of “radical Democrat,” but because he pointed out that the 2020 election was shown to have been quite secure. And since that ruined Trump’s big lie that he had really won the election, he had to fire Krebs (whom he had hired in the first place).
So… it appears that the Trump admin shut down the most advanced versions of Anthropic’s AI tools not because they posed a serious risk… but because Anthropic asked someone to review the supposed threat, and that person got a shout-out from someone Trump hates for once telling the truth about election cybersecurity.
As promised, this story just keeps getting stupider.
Axios, as it’s known to do, doesn’t emphasize how absolutely fucking bonkers all of this is, but does its usual horse race nonsense, suggesting that if only Anthropic had sucked up to Trump’s ego more, all of this mess could have been avoided:
“Anthropic has not done a great job at trying to speak to the administration and appreciate the ideological differences,” one source familiar with the administration’s thinking said.
“It’s like they just speak in different languages,” the source said, adding that the company has simply not figured out how to communicate with this administration.
Oh come on. This is the presidential administration of the most powerful country on earth, and we’re supposed to accept that companies need to tiptoe around “appreciating ideological differences” or face having their entire service banned? Who in their right mind would think that’s reasonable?
The Axios piece concludes with the dumbest suggestion on this entire thing: that it’s somehow Anthropic that needs “an attitude fix.”
Absent that, a source familiar with the administration’s thinking said it may simply come down to an attitude fix where, instead of feeling dismissed, “everyone feels safe, secure and happy.”
Anyone who thinks it’s Anthropic’s fault for not hiring a MAGA chud to lobby on their behalf is simply endorsing blatant corruption. But in this era of cowed political journalists, apparently framing capitulation to that corruption as savvy PR advice is the only thing they can think of.
In the meantime, dozens of the biggest names in cybersecurity have signed onto a “Free Fable” letter, telling the administration how incredibly counterproductive all of this is:
It is our understanding that underlying model capabilities in the original research that triggered this action:
Were focused on determining whether a human-prompted section of code was insecure. This is a necessary capability in any model that is intended to write secure code and should not be considered an offensive capability.
Can be replicated on GPT-5.5, Opus, Sonnet and even Chinese models like Kimi 2.7. The justification for this unprecedented action was that Fable provides a unique “uplift” of capabilities beyond other AI models, but AI has been finding bugs and generating working exploits at superhuman levels since last year.
Anthropic is addressing the research. As security professionals, we recognize that our work does not lead to a simple end-state where a system is fully safe, and the purpose of research like this is to enable continuous improvement, not to ban the technology.
As a result, this action has taken the best models away from defenders, created market uncertainty, and risked America’s AI leadership without any real risk to justify it.
Yeah, sure, but did you see that Anthropic hired someone who got a thumbs-up from someone Trump fired six years ago! In the MAGA universe, that’s all that actually matters.
So we have dozens of the top cybersecurity professionals around saying that this administration just deliberately weakened American defenses, handing an advantage to adversaries… all because of some weird partisan freakout. And the administration’s response is that it’s Anthropic that needs an “attitude fix”?