[BidClub_]
The a16z Show · · 42 分钟

美国AI政策的当下现实:从“暂停AI”到“建设”

Martin CasadoAnjney MidhaErik Torenberg

YouTube
TL;DR
  • 华盛顿的AI政策立场已经从存在性风险警告下的限制AI,转向建设一个美国意图主导的平台。行动计划以“新的科学发现前沿”开篇,支持开源,并提出建立评估生态,在做出宏大宣示前先衡量风险。嘉宾认为,这代表文化重心正从“PauseAI”转向用实证测量风险与机会成本。

  • SB 1047成为理论性危害如何立即制造商业寒蝉效应的警示案例。该提案可能让开放权重开发者承担下游责任:如果有人之后对其成果进行微调并造成大规模伤亡,开发者可能被追责;Erik Torenberg回忆,其中一个版本甚至将3人死亡或医疗系统不堪重负纳入定义。对一个“连诉讼都负担不起”的开发者而言,仅仅把问题交给法院,就足以压制实验。

  • DeepSeek戳破了这样一个前提:限制美国开源,就能让美国对中国保持数年的领先。在R1让华盛顿意外之前,DeepSeekMath-V2已经显示其接近前沿;而蒸馏意味着,拒绝开放权重所能保留的边际优势十分有限。Erik Torenberg直截了当地问:“你真的看过AI领域任何一篇论文的作者名单吗?”

  • 开放权重如今已经有了远超开源理念本身的具体商业逻辑。闭源模型可以探索前沿能力,开放模型则服务于政府、受监管行业和要求本地部署、控制权、安全性与支持服务的《财富》50强客户——这正形成中的“主权AI市场”。由于权重不包含底层数据和训练流程,公司可以分发更小的模型,同时保留更大的付费模型和核心IP。

  • 可投资市场可能走向分化,而不是收敛到单一的授权模式。前沿API与受控部署面对的是不同客户,所需基础设施、支持能力和收入模式也不同;嘉宾预计两种模式都会出现赢家。当20多岁的创始人能在几年内把企业做到“数千万至数亿美元”的收入运行率时,等待市场结构尘埃落定本身就是一种风险。

  • 行动计划的方向感强于执行细节,学术界的缺席尤其突出。其中“建设AI评估生态”的倡议,用测量取代宣示,并迅速成为其他政府的参考点。但Anjney Midha认为,在缺少大学参与的情况下推进重大技术计划,等于让美国“把一只手绑在背后”作战。

  • 嘉宾不接受“可解释性尚不完整,因此应无限期等待前沿突破”的观点。模型或许是“生长出来的,而不是编码出来的”,但社会一直在从无法逐原子解释的复杂系统中提取价值;对齐可以提升实用性,并不需要先获得一项普遍适用的意识形态授权。他们的机会成本判断十分明确:“没有AI时的p(doom),实际上远高于有AI时的p(doom)”,尤其是在延误可能减缓疾病治疗和科学发现的情况下。

摘要 · 为研究而整理的核心内容

1. 安全共识跑在证据前面

  • Anjney Midha形容拜登政府时期的环境是本末倒置:行政命令试图限制创新,并不断制造恐慌。Erik Torenberg表示,学术界和创业公司大体保持沉默,而一些技术人士有时反而放大了“创新很危险、应该监管或暂停”的观点。Martin Casado说,真正让他震动的是,政客公开承认自己对快速变化的技术知之甚少,却仍在提出政策建议。

  • Anjney对早期互联网作了历史对照:Morris蠕虫、病毒、不对称攻击以及真实发生的基础设施故障,都为危险提供了具体证据。但更广泛的应对仍然是“踩到底板加速”,继续加大技术投入,同时配套针对性管控,而不是因为它是通用平台,就先验地将其视为应被禁止的对象。

  • Erik提出了最强版本的怀疑:如果安全和危险都无法被证明,为什么不放慢速度?Martin则回应,过去40年里,计算机、互联网、云和移动技术都提供了先例;在Huawei、Cisco等敏感案例中,行业也一直采用针对性限制。“如果我们要偏离过去40年形成的政策姿态,就最好有一个他妈的充分理由。”

  • 嘉宾将批评拆成实质与氛围两部分。实质性论点把技术与最坏情形的应用混为一谈;Anjney认为,假想的生物武器和黑客场景仍停留在理论层面,而不是已经被证明的边际风险。氛围层面的说法则包括“美国领先中国数年”,这忽视了DeepSeekMath-V2及其他证据——中国实验室已经接近前沿。Anjney还提到,伯克利安全研究员Dawn Song认为AI的边际风险值得重视,但仍是一个开放的研究问题。

2. SB 1047让假设性危险变成商业上的即时风险

  • Erik回忆,他和Martin起初都认为SB 1047不可能真正获得进展,却眼看着它通过加州众议院和参议院,进入最终表决阶段;只要州长签字,就会成为法律。这一过程暴露出过去“技术人负责建设、政策制定者负责政策”的分工已经失效:官员承认技术发展很快,却仍认为必须采取行动。

  • 该提案围绕开放权重设置的核心机制是下游责任:如果开发者发布了足够大的权重,而恶意行为者在2年后将其微调成有害系统,原始开发者可能承担责任。Erik提醒说,不同版本的条文有所变化,但他记得其中一个大规模伤亡定义包括3人死亡或医疗系统不堪重负。嘉宾还提到汽车事故,以及医疗承载能力不足的农村地区等先例。

  • Martin指出了寒蝉效应,Anjney则把它具体化:一个“阿肯色州的普通孩子”不可能把诉讼当作一场开放的政策辩论,尤其是在一个有中国国家力量支持的生态正朝相反方向加速时。Martin把这比作骑车人故意把一根棍子插进自己的前轮:“我们到底为什么要主动接受”这种 handicap?

  • 因此,举证责任应当落在非同寻常的主张一方。Anjney认为,把模型称作“像核武器一样”,并推翻科学家不应为所有下游用途负责这一常规,需要“非同寻常的证据”;否则,这套制度可能关闭前沿研究,极端情况下甚至“真的把研究人员扔进监狱”。

3. DeepSeek暴露了安全表演的二阶成本

  • Martin认为,探索技术负外部性已经成为一种时髦的智识工作。围绕模拟世界、递归自我改进和存在性风险的Bostrom式问题逐渐变成一列“失控的列车”;思想实验对政策制定者而言是“猫薄荷”。Anjney补充说,GPT-2和GPT-3制造了路径依赖:这个领域早期的兴奋,后来与恐惧混在了一起。

  • Martin更不客气的诊断是,参与者陷入了一阶思维。出于善意的研究者把非零存在性风险当作展开讨论的理由,却没有预料到政策制定者会把讨论变成教条。“法律基本就是代码。代码很难重构;法律不可能重构。”他引用Jack Clark在SB 1047后期的反思:他们当时没有意识到这场努力可能走多远。

  • DeepSeek成为催化剂,让这些后果不再只是政策老手看得见。当R1出现时,华盛顿的意外催生了“权重被窃取”等理论,但Erik表示,蒸馏美国实验室的产出并没有特别困难,并追问:“你真的看过AI领域任何一篇论文的作者名单吗?”更早的论文以及整个领域的作者名单,已经反驳了竞争者会简单地“忘掉数学”这一假设。

  • “浸礼派与走私客”的框架,抓住了真诚信徒与借用这套思路服务自身目的的人同时存在这一事实;但Martin和Anjney表示,大多数参与者其实是实用主义者,只是没有进入辩论。创始人、学者和VC此后加入了“沉默的大多数”,而行动计划也反映出Little Tech、大科技公司与学术界是彼此独立的利益群体,并非一个同质化的硅谷。

4. 开放权重演化为企业级商业模式

  • Anjney认为,熟悉的基础设施发展路径正在重演:闭源先开拓能力和应用,随后企业开始寻求更低的部署成本、更强的控制力,以及类似Red Hat的打包、服务和部署工程。开源尤其适合政府和受监管行业,因为这些客户需要本地部署、安全合规以及完整的运营控制权——这就是“主权AI市场”。

  • Martin强调了一个关键区别:开放权重不等于开放软件。源代码可以被编译、修改和复现;权重并不会透露创造模型所用的数据或数据流程。因此,发布权重并不会以同样的方式让竞争者获得重建完整资产的能力。

  • 这种不对称催生了AI版的开放核心模式:发布更小的模型,用于研究、分发、开发者控制和红队测试,同时把更大的模型留在内部并对访问收费。蒸馏和后训练仍然留下保护核心IP的空间,因此这种模式可能比传统开源软件企业更具可持续性。

  • 真正的战略奖品是生态控制权。Anjney认为,让外国AI系统依赖美国的芯片、模型、后训练流程和强化学习技术,其价值“高出几个数量级”,远胜于守住一小段领先优势。因此,Martin认为开源不可避免,并称赞行动计划明确追求美国在开源领域的领导地位。

  • 开放模型和闭源模型服务的是真正不同的市场,而不只是不同的技术偏好。一个客户需要最新的API能力,另一个客户需要为7,000名政府雇员提供受控助手。Anjney警告,不要等着看哪种格式胜出——20多岁的创始人已经把收入运行率做到“数千万至数亿美元”。

5. 行动计划先改变国家叙事,再解决执行问题

  • Martin特别强调开头那句——“今天,一个新的科学发现前沿展现在我们面前”——因为它以抱负开篇,而不是以军备竞赛隐喻开篇。物理、化学和材料领域的真正进展,不仅需要机器学习人才;研究人员还必须连接湿实验室、开展实验,并完成“真的用移液器移取新材料”这类不光鲜的工作。

  • Anjney最大的批评是学术界所处的位置过于边缘。过去40年,大学一直是创新和计算机科学的支柱;尽管目前高等教育界与政府之间存在对峙,且双方都有合理之处,但把学术界排除在重大技术计划之外,等于让美国的能力受到不必要的限制。

  • Erik称这份计划雄心勃勃,但“执行细节略显不足”。其中最强的提议是“建设AI评估生态”,建立有科学依据的危险测量方法,再做出政策宣示。Erik说,他和Martin在24小时内就收到其他政府发来的信息;但要把这份参考文件变成可运行的评估体系,还需要华盛顿与技术人士展开细致合作。

6. 不确定性意味着要评估模型,而不是放弃其收益

  • Martin接受最基本、近乎同义反复的对齐定义:模型应当针对预定用途变得有效,因为这些系统“难以驯服”且“混沌”。但当对齐意味着由一个中心群体决定其他人可以接触哪些危险、思想或信息时,他就会强烈反对;政策不应在不透明的情况下强加单一意识形态目标。

  • Anjney认同“模型是生长出来的,而不是编码出来的”这一比喻:模型能力在训练完成前可能始终未知,而机制可解释性仍是一个研究问题。Martin把它与电力和核聚变相比,Anjney则与互联网相比;Martin还指出,我们并不理解自己的大脑,却仍然可以与其他人协作。

  • Martin进一步用人力资本作类比:社会不会等待完美解释,而是教育人、传授价值观、让其获得专业化能力、观察工作经验,并通过基于风险的制度进行管理。AI同样可以变得极其有用,包括用于任务关键型软件工程,而不必先逆向还原每个输出背后的全部内部原因。

  • Erik保留了最有力的安全质疑:为什么要急着推进,而不是先消化已有能力?Martin回答,在癌症尚未被攻克之前,每一个没有冲向生物学发现和科学进步前沿的月份,都意味着人们继续承受AI或许能够解决的疾病。Anjney则用Bostrom的创新瓮作概括:拒绝抽取新的球,比抽取它们更危险。他的判断是绝对的:“没有AI时的p(doom),实际上远高于有AI时的p(doom)。”

  • 他们最终检验的是边际风险。Martin表示,现有的计算机、网络和随机系统安全机制应当作为默认工具;真正新出现的AI风险可能需要新工具,但政策制定者首先必须说清楚,究竟什么是新的,以及为什么既有解决方案会失效。Anjney将原则总结为:“既然没坏,为什么要修?”行动计划仍把就业、国防、对齐及其他风险放在探索阶段。

Martin Casado

Now, we've been through all of these tech waves, and we've learned how to have this discussion in a way that, for U.S. interests, balances these 2 things. If we're going to make a departure from a posture that was developed over 40 years, we better have a pretty damn good reason.

Erik Torenberg

Okay, so we're talking 1 or 2 weeks after the action plan has been announced. It looks like we've come a long way. Why don't we trace—you guys have been on the front lines for years now in this discourse, fighting to make this possible. Why don't we trace where we've been, so that we can understand how we got here and where we're going?

Anjney Midha

Under the Biden administration, we had the executive order, which was basically the opposite of what we're seeing today. It was trying to limit innovation and doing a bunch of fearmongering.

Martin Casado

But to me, what was even more striking was not regulators being regulators. You'd expect that. But if you remember, this is why we got involved: you'd have these politicians making recommendations, which is fine. You'd expect that.

Erik Torenberg

But nobody was saying anything. Academia was silent, the startups were silent, and, if anything, the technologists were kind of supporting it. We were in this super-backwards world where innovation was bad or dangerous, and we should regulate it, pause it. There was this discourse, and it was somewhat fueled by tech, as opposed to anybody going against it.

So I think today we should definitely talk about how the action plan is great, but we should also talk about how the entire industry has come around to say, “Listen, we need to keep these things in check. We need to be sensible and think about it.”

Martin Casado

PauseAI—that was 2 years ago.

Anjney Midha

Remember the big—sort of—all the CEOs signed this petition.

Erik Torenberg

Oh, yeah. I think that was the last AI Safety Summit, right? The one before Paris? There have been so many of these.

Martin Casado

Yeah, I've lost track.

Erik Torenberg

No, no, no. Remember Dan Hendrycks's organization? What was the California AI organization?

Martin Casado

The Center for AI Safety.

Erik Torenberg

Center for AI Safety. That's right. That's the nonprofit. And then they got all of these people to sign this list: “We need to worry about the existential risk of AI.” That was the mood. It was almost like, can I just do something by contrast, right?

Anjney Midha

I was there during the early days of the web and the internet, and at that time, you actually had examples of this stuff being dangerous. Robert Morris let loose the Morris worm; it took down critical infrastructure. We had new types of attacks—we had viruses, worms, and attacks on critical infrastructure. We actually had a different doctrine for the nation: the more we get on the internet, the more vulnerable we are.

So instead of mutually assured destruction, we had this notion of asymmetry. There were all these great examples of why we should be concerned. What did everybody else do? Pedal to the metal and invest more in technology. This is great. We still wanted the internet. We wanted to be the best, we wanted to build it out, and the startups were all over it.

Coming into AI 2 years ago, it was the opposite. There were concerns with new technology, which you always have, but there were very few voices saying, “Actually, it's really important that we invest in this stuff.” To me, the bigger change is this larger cultural change.

Erik Torenberg

I think that's right. There was a moment last summer when somebody sent you and me a link to SB 1047, and I remember Marty and I reacting, like, “There's no way this is going to get any steam.” What was absurd to us was that it made it through the Assembly and the Senate, and it was on its way to a final vote. It would have become law with 1 signature from the governor. Wow.

Martin Casado

And I think there was this escalation where I realized something. My view is that technologists like technology and politicians like policy. We pretend these 2 things are different worlds, and as long as those 2 worlds don't collide, the engineers get to build interesting tech, there's no sort of self-own too early in the process, and we generally trust our policymakers.

That changed completely last summer. It was a really weird cultural shift: a lot of the policymakers who were quite open about not knowing much about the technology, because it was moving so fast, still felt like something had to be done. Therefore, this is something; therefore, it must be good. SB 1047 was, I think, the most egregious example of this being adversarial.

Erik Torenberg

But that culture shift was from one posture to another.

Martin Casado

“Let's let the tech mature and then decide how to regulate it later” became “Let's try to regulate it in its infancy.” That was, in my view, a massive shift.

Erik Torenberg

Let's just talk about how bad it got. You had VCs—their entire job is investing in tech—talking against open source. You had people like Vinod and Founders Fund saying, “Open-source AI is dangerous; it gives China the advantage.”

Martin Casado

There was some sort of prognostication that if we didn't open-source AI, the Chinese would somehow forget math and not be able to create models. Then you fast-forward 1 year, and they've got the best models by far, and we're way behind.

It was the people who were supposed to be protecting the U.S. innovation brain trust who were somehow on the side of “Let's slow it down.” I think that now there's this realization—

Anjney Midha

Actually, China is really good at creating models, and they've done a great job.

We've kind of hamstrung ourselves from whatever discussion we were having, which I think you're right about. It's good to be concerned about the dangers and job risks, but it has to be a wholesome discussion. You need both sides. When we jumped in, it didn't feel wholesome at all. One side was dominant, and there was almost no one on the pro-innovation, pro-open-source side.

Erik Torenberg

I just think it didn't feel grounded in empirics.

Martin Casado

Well, certainly not from empirical evidence.

Erik Torenberg

So what is the steelman of the critique of open source that they were making a couple of years ago?

Anjney Midha

The argument was that this is like a nuclear weapon. Would you open-source your nuclear weapon plans? Would you open-source your F-16 plans?

The idea was that somehow this was like a weapon. Nuclear weapons are not dual-use. Nuclear energy is dual-use, right? An F-16 is not dual-use. A jet engine is dual-use. But a lot of the analogies that were used at the time were clearly weapons. They would say, “Listen, these things are incredibly dangerous. Would you open-source the plans for an F-16?”

Martin Casado

And then the other side, which slowly decided, “This conversation is ridiculous. We have to go ahead and set up the argument,” said, “No, you would not do this for an F-16 because that is a fighter jet. However, a lot of the technologies used to build it—yes, this is fundamental.”

Anjney Midha

It's not like people aren't going to figure it out anyway, and we need to be the leader, just like we were the leader in nuclear technology. Historically, when nuclear technology came out, we invested incredibly heavily in it. The things that we thought were proximal to weapons, of course, we made sensitive. But all the universities were involved; the entire country had the discourse. That just wasn't what was happening.

I think that's true. They were basically saying there was a substantive argument against open source and an atmospheric one. The substantive one was the one Martin mentioned: the technology was being confused with the applications.

Erik Torenberg

Right. All the worst-case outcomes of the applications or misuses were then being confused with the technology.

Anjney Midha

But they were also theoretical. It's even worse than that. It was like, “You're right in what you're saying, but this could potentially create bioweapons.” We got a bioweapon expert, and he said, “Well, not really. The difference between a model and Google is almost nothing.” But that was used as this straw-person argument.

Then there was the argument that it could hack into a whole bunch of stuff. Nobody had ever done it before, but it was theoretical. So these were theoretical arguments that were very specific—

Erik Torenberg

Right.

Anjney Midha

—versus a broad technology.

Erik Torenberg

That was one argument, and then the atmospherics were that there was a famous former CEO who went in front of Congress and literally testified that the U.S. was years ahead of China. Since these were nuclear weapons, the misuses were being confused with the technology, and we were so far ahead, the argument was: “Let's lock it down so we can maintain that lead, and therefore our adversaries will never get their hands on it.”

Both of those arguments were fundamentally wrong for the reason Martin said: substantively, AI was not introducing marginal risk.

Anjney Midha

Well, at least not identified at the time. You would go to Dawn Song, who is a safety researcher and a MacArthur genius fellow at Berkeley, and you'd say, “What are the marginal risks of AI?” She'd say, “Great question. We should research that.” The world expert on this question was like, “This is very important, but it's an open research question.”

Erik Torenberg

Yeah, so no empirical evidence at the time that AI was creating net-new marginal risks, and just factual inaccuracies that we were ahead of China. If you just paid attention to what was happening, DeepSeek had already started to publish a fantastic set of papers, including DeepSeekMath-V2, which came out last summer, and we were like, “Okay, obviously these guys are clearly close to the frontier. They're not years behind.”

And so when DeepSeek-R1 came out earlier this year, a lot of Washington was shocked: “Oh, my God, how did these folks catch up? They must have stolen our weights.” It's like, no, actually, it's not that hard to distill from the outputs of our labs. Have you actually looked at the author list of any paper in AI? Where do you think these people come from?

Martin Casado

So I think those 2 things were—I felt like we were being gaslit constantly, because both the content and the atmospherics were just wrong.

Erik Torenberg

Maybe one question for the smartest or most sober people who were against it is: Maybe they were asking where the burden of proof should be, because it's hard to prove that there is risk, but it's also hard to prove that there isn't risk. And so there's a question of what's riskier: Is it riskier to just go full steam ahead, or is it riskier to slow down until we better understand these models, interpretability, and so on?

Martin Casado

I think it's really important to ground these hypothetical discussions in what we've learned as an industry. The discourse around tech safety has been around for 40 years, and we went through it with computers. Remember when we were like, “Okay, Saddam Hussein shouldn't have PlayStations because you can use GPUs to simulate nuclear weapons”? That was actually a pretty robust and real discussion.

But that did not stop us from having other people create chips or video games, right? I mean, we went through the internet, cloud, and mobile. And so we've been through all of these tech waves, and we've learned how to have this discussion in a way that, for the United States' interests, balances these 2 things.

We've had areas that were very sensitive to national governments. Think about Huawei and Cisco, for example. We as a nation did start to put in import and export restrictions as a result.

And so I just feel these almost platonic, academic questions like the one that you just posed aren't rooted in 40 years of learning. So all I ask is, if we're going to make a departure from a posture that was developed over 40 years, we better have a pretty damn good reason. And if we don't have a good reason, then I think we should probably learn from that experience.

Anjney Midha

Yeah. I think extraordinary claims require extraordinary evidence, and so the burden of proof should be on the party making the extraordinary claims. If there's a party who's going to show up and say, “These are like nukes. AI models are like nukes, and California should start imposing downstream liability on open-source developers for open-sourcing the weights,” that's a pretty high claim to make.

And so you should have exceptional proof if you want to change the dominant status quo. The status quo is that you do not hold scientists liable for downstream uses of their technology. That's absurd. That's a great way to shut down the entire innovation ecosystem and start throwing literally researchers in jail.

We don't want that. We want them to be trying to push the frontier forward. And I just don't think that the tall claims were being followed up by tall proof.

Erik Torenberg

And when we're talking about open source, are we all talking about the same thing? Meaning, are there degrees of open source, or is it just binary?

Martin Casado

Open weights, I think, was the primary contention. If somebody put out the weights of a model and a bad guy took those weights, fine-tuned them, and did something really terrible 2 years later, the SB 1047 regime proposed that the original developer of the weights they put out, basically as free information, should be held liable, which was absurd.

Anjney Midha

Right.

Martin Casado

Right. So I think—

Erik Torenberg

I just want to make sure we're very clear, because people jump on top of these things. What he's saying is correct. So basically, if the weights were over a certain size and there was a mass-casualty event—

Anjney Midha

I think “catastrophic harm” was the word used.

Erik Torenberg

No, it was “mass casualty.” There were so many versions that I don't know which version, but I remember we actually looked it up. The legal definition was 3 or more people were killed, or the medical system was overwhelmed. There were actually precedents of this, including a car crash.

Anjney Midha

Right, right. And there were actually precedents of this happening in rural areas, which basically don't have any sort of capacity. And so, basically, it would move the conversation to the courts and outside of policy, which is—again, historically, we've taken a policy position on these things that follows precedents we understand, to make sure that we don't introduce externalities. For example, allowing China to race ahead with open source, which has happened.

Martin Casado

And the key thing is: By moving it to the courts, one could argue, “Oh, sure, it's moving to the courts. That means it's open for debate. It's not clear that open weights are going to be regulated with liability.” The point is that creates a chilling effect. The chilling effect is the idea that when our best talent is considering—

Anjney Midha

I could be sued. I'm a random kid in Arkansas developing something. I don't want to be in a world where—

Martin Casado

It can be resolved in the courts, right? I can't even afford it, whatever it is. And in a situation where you have an entire nation-state-backed entity like China actually doing the opposite of a chilling effect—encouraging a race to the frontier—why on earth would we want that?

There's this meme of a guy on a bike: He picks up a stick and puts it into his front wheel. That's the effect of a chill. That is what a chilling effect is, right, at a time when your primary adversary is racing—

Erik Torenberg

So let's trace how the conversation has changed, because we don't see Vinod tweeting about open source anymore. Obviously, he changed his tune, especially right now. Is it really just DeepSeek? Is that it, or how do you trace how the sentiment shifted on open source?

Martin Casado

Let's go through a few theories. I'm not really sure what happened. I almost felt like it was culturally in vogue to be a thought leader on the negative externalities of tech. It kind of started with Bostrom, but it was picked up by Elon. It was picked up by Dustin Moskovitz and Reid Hoffman—I mean, a bunch of intellectuals that we all respect and still do. They're really the titans of our industry in our era.

They were asking these very interesting intellectual questions, like, “Do we live in a simulation?” and “What happens if AI can recursively self-improve?” That actually created whole cultures and online social discourse around this stuff. And so, to no small part, that became a bit of a runaway train, and it's just catnip to policymakers.

I think part of it is that people didn't really realize this had become so real because, of course—

Anjney Midha

GPT-2 came out, and then GPT-3 came out, and people thought, “Oh, this stuff's amazing,” and somehow it got conflated. So I think part of it is just path dependency on where we came from, which is kind of the legacy of Bostrom. I think that was part of it.

Martin Casado

I think the ungenerous approach would be that a lot of the discourse is awesome, but a lot of the people pushing the discourse were first-order thinkers. They weren't doing the math: Wait a minute. If policymakers who have no background in the frontier—which, by the way, nobody does, because this space is only 3 or 4 years old—start to take discourse as canon, which is a big difference, then what happens? What are the second- and third-order effects?

And the second- and third-order effects are that you start making laws that are really hard to undo and start mistaking interesting thought experiments as the basis for policy. And once that happens, those of us who've looked at law—law is basically code. Code is hard to refactor; law is impossible to refactor.

And so I think the second- and third-order effects were that a lot of well-intentioned folks—for example, in the existential-risk community—were saying, “Look, if you're intellectually honest about the rate of progress of AI, it's not crazy to say that there are some existential risks in the technology. It's nonzero.” Sure, yes, that is true.

But then to say that that threshold is high enough to start introducing sweeping changes in regulation to the way we create technology, I don't think a lot of the early proponents of that technology realized they would do that. In fact, I think Jack Clark, who runs policy for Anthropic, literally tweeted toward the end of the SB 1047 saga, “I guess we should have—we didn't realize the impact of how far this could have gone.”

And I think, to those of us who had interacted with D.C. and regulation before, the second- and third-order effects were much more discernible, or legible.

And then I think what DeepSeek did was just make it super legible to everybody else.

Anjney Midha

I think DeepSeek was the catalyst.

Martin Casado

But it wasn't like there was a step. It didn't change the reality that the second- and third-order effects of policymakers confusing discourse for fact were always going to be terrible.

Anjney Midha

Yeah.

Martin Casado

I just think it brought to light something a lot of us were already seeing, which is that we're in a race with adversaries, and that should be the calculus we should be working backward from. There was always this prevailing view, which has turned out to be so wrong, from really well-intentioned people: It's going to be regulated anyway; if it looks like we're self-policing, we can dictate how that happens, right?

And unfortunately, that just turned out not to be true, because whatever self-policing we seemed to be doing scared the shit out of people, and they ended up— Then, of course, I would say very opportunistic elements in tech decided to use that for whatever agenda they had, and so it kind of got away from us.

Anjney Midha

Mark had this sort of Baptists-and-bootleggers framing.

Martin Casado

Yes, I was going to say exactly that.

Anjney Midha

True believers, and then people who use that thinking to support their own ends. And it seems like that's changed, even just on the company level.

Martin Casado

But the reality is, I think the majority of people are neither.

Anjney Midha

Yeah, the majority of people are pragmatists.

Martin Casado

They're not trying to take advantage of the system. They think, “Well, maybe if we have this discourse, it's an honest discourse, and then we'll self-police.”

Anjney Midha

I just feel like the silent majority was not part of the discussion. Maybe the biggest change now is that those people are there: the founders are there, academia is there, and VCs are there. Now, the people who are not either Baptists or bootleggers are driving the discussion, which, independent of the action plan itself, I feel puts us in a much better position. At the time, there was none.

Martin Casado

Right.

Anjney Midha

And I think, to move to the action plan, if you read the first page, what a marked shift it is—the fact that the co-authors include technologists.

Martin Casado

Right. I think that was the core problem: DC is a self-contained system, and the Valley is a self-contained system. A lot of people here were assuming best intentions over there, and vice versa.

What happened is that a few bad actors essentially used that arbitrage opportunity to represent Silicon Valley's views incorrectly in DC. When we saw some of the legislation, we had policymakers calling us up and saying, “Wait, you guys aren't happy with SB 1047, but the other tech people were calling us and saying you'd love more of this kind of regulation.” We said, “What other tech people?”

It turns out we're not one homogeneous group. Little Tech is extraordinarily different from big tech, which is extraordinarily different from the academic communities. I think one of the things we had to contend with was that we used to be one shared culture, and then, when tech grew, we actually—

Anjney Midha

There are some major differences in the Valley, at least, between parties. We're not one tech ecosystem anymore. We have different interests, and DC hadn't updated that. I think what's amazing about the action plan is that it's written by people who have bridged both.

Martin Casado

It has enough representation across the 4 or 5 different subcultures within tech that have different interests.

Anjney Midha

Great.

Martin Casado

I think that's new.

Anjney Midha

Yeah. Yeah.

Martin Casado

Going back to open source, why don't you talk a little bit about how different companies have thought about it? From a business-strategy perspective, maybe we saw Meta with perhaps the first big open-source push. OpenAI has evolved there, too. I've seen even Anthropic seems to be evolving its dialogue a little bit. How should we think about open source as a business strategy? What's changed here, and why?

Anjney Midha

Oh, look, I don't think this is actually playing out along the same trend lines as all previous computing infrastructure: databases, analytics, operating systems like Linux. The way it works is that the closed-source pioneers are at the frontier of capabilities. They introduce new use cases, and enterprises never know how to consume that technology. When they do eventually figure out that they want cheaper, faster, more control, they need somebody like Red Hat to introduce them and provide solutions, services, packaging, deployment engineering, and all of that around it.

Which is why the arc generally in enterprise infrastructure has been that closed source wins in applications, and open source tends to do really well in infrastructure, especially with large government customers and regulated industries where there are a bunch of security requirements, things need to run on-premises, and the customer needs total control over it. Broadly, you could call that the sovereign AI market right now. Lots of governments and lots of legacy industries are going, “Wait, this open-source thing is really critical to us.”

Whereas 2 or 3 years ago, open source was viewed as largely a philosophical endeavor, which it is. Open source has always been political and philosophical by definition. But now there's an extraordinary business case for it, which is why you're seeing a lot of startups and companies changing their posture. They're going, “Wait a minute, some of the largest customers in the world—enterprise customers—happen to be governments, legacy industries, and Fortune 50 companies, and they want stuff on-premises. That's when you go adopt open source.” I think there's been a business shift as well. I don't know if you agree.

Martin Casado

Yeah, this is great. I totally agree. I do think it's interesting to have the conversation about where it's the same and where it's different. Everything said is exactly right: We have a very long history with open source, and it's a very useful tool for businesses, but also for research and academia, et cetera.

But let's just talk about businesses and startups. It's a great way to get a distribution advantage. It's a great way to enter a market where you're not an incumbent and you're a startup. So it's one of the tools for building software that's been used, and open source has been used in a very similar way. You can use it for recruiting, brand, and distribution, and we see all of that.

But there's something that's unique about AI that software doesn't have. We're seeing very viable business models come out of it that don't have the limitations of traditional software. And this is for 2 reasons. One of them is that open weights is not the ability to produce the weights, and open software is the ability to produce the software. If you give me open software, I can compile it, modify it, whatever. But by giving me open weights, you don't have the data pipeline when you're talking about open weights. So you don't actually enable your competitors in the same way open source enables them. So that's one.

The second one is that there's this very nice business model that's kind of a peace dividend to the rest of the industry: You produce open weights for your smaller models that anybody can use, but you keep the larger model internally, which is actually also more difficult to operationalize for inference. There are good reasons to do this. Then you charge for the largest model, and you use the smaller open models for brand and distribution or whatever. I feel like it's actually an evolved version, from a business-strategy and industry-perspective standpoint, of open source for these reasons.

Anjney Midha

I think it's the AI flavor of open core, which historically was theoretically supposed to be a sustainable model for open-source software development. It was really hard to implement because of the reasons Martin said: Once you gave away the code, it was really hard for you to protect your IP.

But with weights, you can contribute something to the research community, give developers control, and allow the world to red-team it and make it more secure, while you're still able to—because of the way distillation works and some of the ways post-training works—hold on to some of the core IP. That then allows you to build a viable, sustainable business, and that is unique about open—

Martin Casado

But also, you have the data pipelines; you have the data. Nobody else could—just because I give you the weights doesn't mean you can recreate the model. You could distill it to a subset model; there's a bunch of stuff you can do, but not necessarily recreate it.

Listen, having been a student of open-source business models for 20 years and having watched how it shaped the way the industry adopted and built software, I actually think the AI one is more beneficial to the companies doing it, for sure. But as a result of that, we're going to continue to see a lot of it.

So I think we should just assume that open source is part of it and every country is going to do it. One of the best things about this current AI Action Plan is that it acknowledges that, and it wants to incentivize the United States to be the leader in it, which is such a dramatic shift from where we were this time last year.

Anjney Midha

Yeah. There’s sort of an ecosystem mindset that, if you’ve worked in any kind of developer business—which Martin and I, unfortunately, have spent way too long doing, working on dev infrastructure and dev tools—you internalize this idea that you often have to trade off short-term revenue for long-term ecosystem value.

I think what the action plan shows is that, yes, in the short term, it may seem like we’re giving away IP to the rest of the world by open-sourcing weights and showing the rest of the world how to create reasoning models and all of this stuff. But in the long term, if every other major nation is running its entire AI ecosystem on the back of American chips, American models, American post-training pipelines, and American RL techniques, then that ecosystem win is orders of magnitude more valuable than any short-term give of IP. Anyway, as we saw with DeepSeek, that marginal head start is minimal.

So, just to close the loop on open source, over the next several years, how do you predict open source and closed source will intersect? What will the industry look like?

Martin Casado

Well, I think these are 2 different markets.

Anjney Midha

Yeah.

Martin Casado

I mean, literally, the requirements of the customers are completely different. If you’re a developer building an application and you happen to need the latest and greatest frontier capabilities, today you have a different set of requirements than if you’re a nation-state deploying a chat companion for your entire employee base of 7,000 government employees.

The product requirements, the way you provide those products, whether you deploy them, the infrastructure, the service, the support, and the revenue models are completely different. Often, I think people don’t realize that closed source and open source are not just differences in technology, but completely different markets altogether. They serve different types of customers.

If you believe AI is this explosive new platform shift, then there’ll be winners in both. I do think what we need to contend with is that it seems like it’s getting harder and harder to be a category leader if you don’t enter fast. The speed at which a new startup is able to enter the open-source or closed-source market and create a lead is absurd.

We’ve both had the chance to work with founders who are literally 20-some-year-olds out of college, 2 years out of college, building revenue run-rate businesses in the tens to hundreds of millions of dollars, serving both of these markets and expanding like this. I think the biggest mistake is to confuse these 2 markets as one.

Anjney Midha

And then there is the classic, “Oh, let’s wait to see how they evolve,” because the pace at which a new entrant is able to actually create a lead in the category is quite stunning.

Erik Torenberg

Let’s go into the action plan. Right. What are our biggest reflections from it? Where are we most excited?

Martin Casado

If you look at the quote that they start with, I wanted to read it out because I thought it was pretty poignant. It was, “Today, a new frontier of scientific discovery lies before us.”

I thought that first opening line was fantastic, out of all the things they could have said. They could have said, “We’re in an arms race,” which, sure, the first page—the title says “Winning the AI Race.” But if you actually start reading the document, the first sentence is a quote from the president that says, “Today, a new frontier of scientific discovery lies before us.” I love that they led with something inspirational.

Anjney Midha

Yeah.

Martin Casado

Because ultimately, the technology has to confer some benefits on humanity. I personally just love the fact that we are starting to explore what these frontier models mean for scientific discovery in physics, chemistry, and materials science.

We need to inspire the next generation to want to go into those areas because it’s hard. It’s really hard to do AI in the physical world. You have to literally hook up wet labs and start doing experiments in an entirely new way.

You need people who are excited not only about wanting to do machine-learning work, but also about the hard work of being lab technicians, running experiments, and literally pipetting new materials and doing chemistry, right? I think that was missing in a lot of the discourse under the previous administration.

You can sometimes judge a book by its cover, and I think this was a strong start. Now I think we should actually dive into some of the bullets.

Anjney Midha

Okay. So, the other one that I thought was a huge omission is that there’s basically no real mention of academia or investing in academia. There are some oblique references to it, but it’s just been such a mainstay of innovation and computer science over the last 40 years. Not having a major part of it, I think, is a shame.

I understand that right now there’s kind of a standoff between higher education and the administration. I get it, and I actually think that both sides have fairly reasonable points. But to have a major tech initiative without including academia just feels like we’re fighting a battle with a hand tied behind our back, or some aphorism.

Erik Torenberg

This is a good problem to have, which is that I think it’s extremely ambitious. It’s a little bit light on execution details—what happens next?

A good example of that is that I do think, directionally, it was great that they said we need to—let’s read this bullet point—“Build an AI evaluations ecosystem.” I loved that because it acknowledges that, before we start making grand proclamations about whether these models are risky or whether these models are dangerous, let’s first agree on how to measure the risk in these models before jumping the gun.

That part, in addition to the open-source bullet, was probably the most sophisticated thinking I’ve seen in any policy document. The reality is that America leads the way. Within 24 hours of this dropping, Martin and I were getting texts and messages from folks in many other governments around the world asking, “What do you guys think?”

It was not hard for me to endorse it and tell them, “Look at it as a reference document,” because there are things here that, arguably, are more sophisticated than policy experts even in Silicon Valley would recommend. Building an AI evaluations ecosystem is not easy, and I think they lay out a pretty thoughtful proposal on why that’s important.

Now the question is how, and I think that’s what we have to help D.C. with: the hard work of implementing this stuff. But the vibe shift—from “Let’s not jump the gun on saying these models are dangerous. Let’s first talk about building a scientifically grounded framework for how to assess the risk in these models”—was not at all a given to me, and I was really excited about that.

Yeah, there’s been a lot of focus in the last few years by several companies, but also by the broader industry, around this idea of alignment. Have we made any progress on alignment? What is your perspective on what they’re trying to do? Is that a feasible goal? Help us understand what they’re trying to solve for.

Martin Casado

So, at an almost tautological level, alignment is an obvious thing you’d want to do. I have a purpose; I want to align the AI to this purpose. It turns out these models are problematic—generally unruly, chaotic, whatever adjective you want to use.

Understanding how to better align them to any sort of stated goal is very obviously a good thing. I think we’d all agree that aligning them to whatever the goal is—to make them more effective at that goal and do that thing—is good, especially given that these models tend to have a mind of their own.

The subtext that I bristle at is that the people doing the alignment are somehow protecting the rest of us from whatever they think their ideal is, as far as dangers to me, thoughts I shouldn’t have, or information I shouldn’t be exposed to.

That’s why I think we need to be very careful, even when we come up with policy, not to impose a different set of ideological rules on top of these. I just think alignment is something we should all understand. Actually aligning them, to me, is where I take issue with any sort of top-down mandate.

Anjney Midha

I agree, and I think there’s a quote from a researcher that I think is very accurate: You’ve got to think about these AI systems as almost biological systems that are grown, not coded up, right? Sure, they express themselves as software, but in many ways, when you’re training a model, you are actually growing it in this environment of a bunch of prior history, training data, et cetera.

Often, empirically, you actually don’t know what the capabilities of the model are until it’s actually done training. I think that’s a useful analogy. Where I think that falls down is when people go, “Well, if we can’t align it because we don’t actually know what its biological mechanism is until it’s grown up, and we don’t know what its risks are, then we can’t deploy these AI models in mission-critical places until we’ve solved, let’s say, the black-box problem—the mechanistic-interpretability problem.”

Can you trace deterministically why a model did something? We’ve made a lot of advances as a space in the last few years, but it still remains a research problem.

Martin Casado

But just because you don't understand the true mechanism of the system doesn't mean you don't unlock its useful value. If you look at most general-purpose technologies in history—electricity, nuclear fusion—there are many examples of technologies where we knew they were complex systems and we didn't truly understand at an atomistic or mechanistic level how they worked, but we still used them.

Anjney Midha

And we don't understand how the internet worked. I mean, there's a whole field of network measurement trying to find out what the heck the internet was going to do. Was it going to have congestion collapse? Any complex system has states that you just don't understand.

Now, listen, I would say these models, more so than many other technologies, have very real implications. But we know how to deal with ambiguity.

Martin Casado

We don't know how our own brains work.

Anjney Midha

No consciousness.

Martin Casado

And we don't stop working with other human beings.

Erik Torenberg

Unfortunately, we're stuck with them, so we have no option on that one.

Anjney Midha

Totally.

Martin Casado

To extend that analogy, what do you do? You're like, “Okay, I don't know how a brain works. It's got a bunch of risks. This person may be crazy, but I still want to unlock all the beautiful benefits of the big, beautiful brains that humans have.”

And so you develop education. You send kids to school, and you teach them values. Then you send them off to college, and they get to learn something specific. Then you get to test them in the real-world environment. They get a résumé and work experience, and they get to prove that they actually are, within a risk-based framework, manageable and so on.

And that, as a society, has unlocked human capital, right? Arguably, the greatest technology we've had in 500 years of modern industrial innovation. So I think what I hate about the alignment discourse is that it sometimes confuses the fact that we don't understand the system with the fact that we can't use it.

I think mechanistic interpretability—which some folks would say is the holy grail, being able to reverse-engineer why a model does something—is still a research problem. But that doesn't mean we haven't made progress on how to use unaligned models or improve alignment to a point where they're useful in massive ways, like software engineering and mission-critical systems.

Erik Torenberg

I think what the smartest might say is, it's not that—it's really just, what's the rush? Maybe let's focus on integrating all the capabilities we already have before pushing the frontier, which then ends the arms race, et cetera. There's a risk of slowing down, too, that maybe isn't fully appreciated.

Martin Casado

Until we've solved cancer, every month that we're not rushing to the frontier of accelerating biological discovery or scientific progress is a month that millions of people are suffering from disease that we could be solving with AI.

Anjney Midha

Yeah. I mean, this is the thing with all of these: there's always this kind of reverse question on innovation, and you say, “Well, okay, it's like the Bostrom's urn experiment, his whole urn hypothesis. There's an urn of innovation, and you pull out balls; one of them is a black ball that destroys everything, right? So eventually you'll draw that ball. Why would you ever do innovation?”

That is the thought experiment, and the answer is so simple: It just turns out that it's much more dangerous not to pull out balls than to pull out balls. That's always the answer.

So when people ask p(doom), “What is the p(doom)?” the answer is not 0.1 or 0 or 100. The answer is, the p(doom) without AI is actually quite a bit greater than the p(doom) with AI. And the answer to “What's the rush?” is the same thing: Clearly, if you ignore the benefits of technology, then you would say, “If it's all negative, no rush at all,” right?

The reality is, the benefits are so dramatic and so obviously dramatic. Now, thank God, we've got a year's worth of data on this stuff. They're clearly economically beneficial; they're clearly beneficial in expanding a number of areas of core science. The rush is getting to the next set of solutions, as opposed to being afraid of a set of problems that we still can't clearly articulate.

And listen, as soon as we understand marginal risk, we absolutely should address it directly. Again, the action plan does a great job of penciling this out. It does want to explore implications for jobs, implications for defense, and implications for alignment. That's exactly where we should be in the exploration phase.

Erik Torenberg

Do we have a definition of marginal risk, or a perspective on how to think about that idea?

Martin Casado

Well, let's just be clear about what we mean by marginal risk: Computer science, computer systems, network systems, and stochastic systems are risky. We've got decades of ways of thinking about measuring, regulating, and changing common behavior based on this type of risk.

And so the question is, can you take all of that apparatus that's been hard-won and apply it to AI? If so, we know it's effective because we've used it before and we've got a lot of experience with it, and it's ready to be done. Or is there a different type of risk that's not endemic to those systems, in which case we'll have to come up with something new?

You go down that exploration, maybe it works, maybe it doesn't work, et cetera, right? So that's what marginal risk is. And I just think that the problem is, if you don't know what it is, how are you going to define a solution?

Anjney Midha

I think that's right. Philosophically, the idea is, if you're going to say we need new solutions, then you need to articulate why the problem is new and why solutions that work really great are no longer sufficient.

And I think it's almost obvious when you state it, but this was the state of the world a year ago. We were having to look around the room and say, “Can I raise my hand? Why are we introducing net-new liabilities and new laws that we've never had to do before if you can't articulate why there are new problems to solve?” If it ain't broken, why are you trying to fix it?

And so marginal risk is, I think, a slightly more technical way to say we have the tools to manage risk; we don't need new ones. And if you think we need new ones, then, hey, just take a minute to articulate to us why.

Erik Torenberg

Is there anything else you wanted to make sure we got to? Otherwise, I think this is great.

Anjney Midha

Time to put the action plan into action.

Erik Torenberg

Excellent. Martin, thanks so much for coming to the podcast.

Martin Casado

Thank you. Thanks for having us.