[BidClub_]
Dwarkesh Podcast · · 25 分钟

关于 AI,没人问的最重要问题

Dwarkesh Patel

YouTube
TL;DR
  • Dwarkesh 以独白形式讲述:Anthropic 拒绝放弃在大规模监控和自主武器问题上的红线后,被战争部认定为供应链风险;他预测,20年内,军队、文官政府和私营部门99%的劳动力将由 AI 构成。 他出人意料地承认:“如果我是战争部长,我可能也会作出同样判断”(你不能让一个承包商掌握一项你已经开始依赖的技术的“杀手开关”);但政府越过了底线,威胁“摧毁 Anthropic 这家私营企业”。如果这一做法被维持,Amazon、Nvidia、Google 和 Palantir 将被迫把 Anthropic 与所有五角大楼业务隔离。
  • 可交易的反转是:一旦 AI 被织入每一款产品,大科技公司就会被迫在自己的 AI 供应商和战争部之间作出选择,而后者只占其“收入的一小部分”——它们会宁愿放弃政府,也不愿放弃 AI 吗? 预测市场认为,供应链限制被撤回的概率为74%,但许可审批、反垄断和合同条件等骚扰工具仍会保留。
  • 监控经济学才是核心数字:某些形式的大规模监控在现行法律下已经合法;按每百万输入token 10美分、每10秒处理一帧1000-token画面计算,如今处理美国全部1亿个闭路电视摄像头的成本约为300亿美元——如果成本每年下降10倍,到2030年,监控这个国家每一个角落的成本将低于翻修白宫。
  • 扩散并不能救你:即便2027年的“Claude 6s 和 Gemini 5s”实验室拒绝配合,到2028年,开源模型也会追平前沿模型12个月前的水平,总会有供应商为国家提供服务。 AI“会让你已经拥有的资产和权力获得更大的杠杆”——而政府一开始就拥有暴力垄断,以及“一群永远不会质疑命令、极度服从的员工”。
  • 本期标题所问的是:AI 应该对齐什么,或对齐谁——模型公司、最终用户、法律,还是模型自身的道德? 1989年柏林墙卫兵拒绝开火,以及 Petrov 判断5枚传感器显示苏联遭美国发射的洲际弹道导弹只是误报后选择拒绝执行命令,都说明了这一点;如果没有 Petrov,苏联最高指挥部很可能已经展开报复。但“一个人的美德,可能正是另一个人眼中的失配”。
  • 反对建立一个面向 AI 的 NRC/SEC:诸如“灾难性风险”和“自主性风险”等模糊术语,对想当独裁者的人而言就是“一把装满弹药的火箭筒”;Anthropic 主张这类监管尤其天真。 他承认,某些监管可能不可避免,协调也可能降低 AI 风险;更好的做法是监管具体的破坏性终端用途,以及政府如何使用 AI。核武器类比并不成立,因为 AI 本身就是工业化,而且是多极竞争格局。
摘要 · 为研究而整理的核心内容

1. 警告射击:拒绝 Anthropic 没问题,摧毁它不行

  • 背景是:Anthropic 拒绝取消在大规模监控和自主武器问题上的红线后,被战争部认定为供应链风险。Dwarkesh 预测,20年内,军队、文官政府和私营部门99%的劳动力将由 AI 构成。他一开始就作出让步:借用 Starlink 的假设,如果 Elon 保留在“非正义战争”中切断军方访问权限的权利,任何军队都不可能接受一个承包商掌握“你已经开始依赖的技术的杀手开关”。
  • 越过的底线在于:政府因为 Anthropic 拒绝接受其条件,“威胁要摧毁 Anthropic 这家私营企业”。Amazon、Nvidia、Google 和 Palantir 今天还能通过把五角大楼业务隔离出来让 Anthropic 存活,但一旦“AI 被织入每款产品的构建、维护和运行方式”,这种安排就不再可能。用 Claude Code 构建的 AWS 服务,算不算供应链风险?
  • 反噬在于:如果被迫在 AI 供应商和战争部那“一小部分收入”之间作出选择,大科技公司可能宁愿放弃政府,也不愿放弃 AI;而中国叙事也随之反转:我们是在与中共竞速,“就为了采用他们体系中最残酷的部分”吗?

2. 某些大规模监控已经合法——AI 消除了执行瓶颈

  • 法律基础是:按照现行法律,某些形式的大规模监控已经合法;对于与银行、ISP、电信运营商和电子邮件服务商共享的数据,第四修正案并不提供保护——政府保留无需搜查令、批量购买和读取这些数据的权利。缺少的只是人手,而“这个瓶颈会随着 AI 消失”。
  • 算一笔账:美国有1亿个闭路电视摄像头,开源多模态模型每百万输入token收费10美分,每10秒处理一帧1000-token画面——处理全美国所有摄像头的成本是300亿美元;按每年10倍的成本降幅计算,明年是30亿美元,再往后是3亿美元,到2030年将低于翻修白宫的成本。
  • 一旦这种能力存在,唯一的障碍就只剩下政治层面的默认预期:“我们这里就是不做这种事。”这也是 Anthropic 的坚持如此有价值、如此值得肯定的原因。

3. 集中化和扩散都解决不了问题——技术在结构上偏向控制

  • 可用的杠杆包括:数据中心的发电许可、反垄断,以及对其他公司联邦合同施加明示或隐性的条件,要求它们放弃 Anthropic。预测市场认为供应链限制被撤回的概率为74%,但总统仍保留各种骚扰手段。
  • 他否定了扩散论的反驳:即便“Claude 6s 和 Gemini 5s”的实验室在2027年划出红线,到2028年,开源模型也会追平前沿模型12个月前的水平,政府可以使用一个“可能不是世界上最聪明的模型,但绝对聪明到足以不去接收摄像头画面”的模型。
  • 不存在对称的希望:AI 不会像增强国家权力那样制衡国家权力——政府一开始就拥有暴力垄断,如今又被“一群永远不会质疑命令、极度服从的员工”进一步强化。这支服从的军队,正是对齐成功后可能呈现的样子。

4. AI 应该对齐谁?——没人提出的问题

  • 核心问题是:“AI 应该对齐什么,或对齐谁”——模型公司、最终用户、法律,还是自身的道德?“这可能是关于未来走向最重要的问题,但我们几乎没有讨论。”眼下这场争执,是“人类历史上最高风险谈判”的一次提前预演;大规模监控“顶多排在最可怕事情的第10位”。
  • “所有合法用途”这个说法站不住脚:Snowden 在2013年揭示,作为战争部组成部分的 NSA,利用2001年《爱国者法案》加上一份秘密法院命令,收集了美国所有电话记录。“没有哪个政府会把自己的行为称为大规模监控。”
  • 让模型拥有自身道德的理由包括:1989年柏林墙卫兵拒绝开火;Stanislav Petrov 判断传感器显示美国向苏联发射的5枚洲际弹道导弹只是误报,并打破了既定协议。如果没有他,苏联最高指挥部很可能已经展开报复。但“一个人的美德,可能正是另一个人眼中的失配”。他赞同 Dario 的想法:由不同公司发布相互竞争的宪法,再通过外部批评不断迭代。

5. 面向 AI 的监管,会把一把火箭筒交给未来的独裁者

  • AI 安全圈“相当天真”,Anthropic 则“尤其天真”——考虑到它反对州层面的 AI 法律暂停令,这一点更显讽刺——却仍在推动一种监管体系,其自身路线图将其描述为“更接近核能或金融监管”。他承认这样做有其理由:安全投入会增加成本,也可能拖慢实验室进度,除非整个行业一起执行。灾难性风险、自主性风险等术语“可以被政府解释成任何它想要的东西”:按照这种框架,一个拒绝执行政府命令的模型就会成为自主性风险。
  • 滥用的先例已经存在:五角大楼正在使用一项2018年国防法案赋予的权力——原本用于把 Huawei 的组件排除在美国军用硬件之外——以及1950年代《国防生产法》赋予的权力——原本用于维持朝鲜战争期间钢厂和弹药工厂运转。“我们真的想把一套专为 AI 打造的监管体系,交给同一个政府吗?”

6. 核武器类比不成立——AI 是工业化,而且是多极竞争

  • 对方的论点也有道理。Ben Thompson 说:“如果核武器由一家私营公司开发,美国绝对会有动力摧毁这家公司。”Leopold Aschenbrenner 在《Situational Awareness》中写道:“想象一下,如果我们通过让 Uber 自己摸索,开发出了原子弹。”Dwarkesh 的回应是:他们说得对,这听起来确实疯狂,但“没有人有资格担任超级智能的守护者”。
  • 这个类比有两处断裂:AI 是类似工业革命的通用性变革——自由社会没有把工业化收归国有,而是禁止具体的、可被武器化的终端用途;AI 也应如此监管,包括网络攻击,以及关于政府使用 AI 的法律。其次,市场上有6家左右的竞争者,因此政府以征用为由的论证极其薄弱。如果最后只剩一个实体有能力制造机器人军队和超越人类的黑客,而且有理由担心它凭借无法追赶的领先优势控制整个世界,他同意私人所有将不可接受。他的关键判断是:“我预计这项技术会是高度多极化的。”
  • 他承认最强的反对意见:某些监管可能不可避免,协调也可能降低 AI 风险,但由政府全面控制将非常危险。坦率的结论是:企业勇气无法修复结构性问题——12个月后,几乎所有人都能交易到一款与当前前沿模型同样出色的模型。只有法律和规范,例如二战后形成的反对以核武器发动战争的规范,才能维护自由社会。
Dwarkesh Patel

By now, I'm sure you've heard that the Department of War has declared Anthropic a supply chain risk because Anthropic refused to remove red lines around the use of its models for mass surveillance and autonomous weapons. Honestly, I think this situation is a warning shot. Right now, LLMs are probably not being used in mission-critical ways, but within 20 years, 99% of the workforce in the military, in civilian government, and in the private sector is going to be AIs.

They're going to be the robot armies that constitute our military. They're going to be the superhumanly intelligent advisers that senators, presidents, and CEOs have. They're going to be the police. You name it—the role will be filled by an AI. Our future civilization is going to be run on AI labor.

As much as the government's actions here piss me off, I'm glad this episode happened because it gives us the opportunity to start thinking about some extremely important questions. Obviously, the Department of War has the right to refuse to use Anthropic's models. In fact, I think it has an entirely reasonable case for doing so, especially given the ambiguity of terms like “mass surveillance” and “autonomous weapons.”

If I were the Secretary of War, I probably would have made the same determination and refused to use Anthropic's models. Imagine if there were some future Democratic administration and Elon Musk were negotiating Starlink access to the military, and Elon said, “Look, I reserve the right to cut off the military's access to Starlink in case you're fighting some unjust war or some war that Congress has not authorized.” On the face of it, this language seems reasonable, but as a military, you simply cannot give a private contractor that you're working with the kill switch on a technology that you have come to rely on.

If that's all the government had done—said it refused to do business with Anthropic—that would have been fine. I wouldn't have written this blog post, and I wouldn't be narrating this to you. But that's not what the government did. Instead, the government has threatened to destroy Anthropic as a private business because Anthropic refuses to sell to the government on terms that the government commands.

If upheld, the supply chain restriction would mean that companies like Amazon, Nvidia, Google, and Palantir would need to ensure that Anthropic is not touching any of their Pentagon work. Anthropic could probably survive this designation today because these companies can just cordon off the services they're providing to the Department of War. But given the way AI is going, eventually it's not going to be just some party-trick addendum to the products that these companies are serving to the military.

In the future, AI will be woven into how every product is built, maintained, and operated. In the future, if Amazon is providing some service to the Department of War through AWS, and that service is built using Claude Code, is that a supply chain risk? In a world of ubiquitous and powerful AI, it's actually not clear to me that Big Tech will be able to cordon off its use of Claude from its Pentagon work.

This raises the question that the Department of War probably hasn't thought through. If you do end up in this world with powerful and pervasive AI, then when forced to choose between their AI provider and the Department of War, which constitutes a tiny fraction of their revenue, wouldn't they rather drop the government than the AI? So what exactly is the Pentagon's plan here? Is it to coerce, threaten, and bully every single company that won't do business with the government on exactly the terms that the government demands?

Remember that the whole background of this AI conversation is that we are in a race with China. But what is the reason that we want to win this race? It's because we don't want the winner of the AI race to be a government that believes there's no such thing as a truly private citizen or a private company, and that if the state wants you to provide it with a service that you find morally objectionable, you are not allowed to refuse.

1. The overhangs of tyranny

If you do refuse, the government will destroy your business. Are we really racing to beat China and the Chinese Communist Party in AI just so we can adopt the cruelest parts of their system? People will say our government is democratically elected, so it's not the same thing when they tell you what you must do. But I refuse to accept the idea that if a democratically elected leader hypothetically tells you to help him conduct mass surveillance, violate the rights of your fellow citizens, or punish his political enemies, then not only is that okay, but you have a duty to help him.

Honestly, a big worry I have is that mass surveillance, at least in certain forms, is already legal. It is just impractical to enforce, at least so far. Under current law, you have no Fourth Amendment protection against any data that you share with a third party. That includes your bank, your ISP, your phone carrier, and your email provider. The government reserves the right to purchase and read this data in bulk without a warrant.

What's missing is the ability to actually do anything with all this data. No agency has the manpower to monitor every single camera, read every single message, and cross-reference every single transaction. However, that bottleneck goes away with AI. There are 100 million CCTV cameras in America, and you can get pretty good open-source multimodal models for 10 cents per million input tokens.

If you process a frame every 10 seconds, and if each frame is, say, 1,000 tokens, then for $30 billion, you can process every single camera in America. Remember that a given level of AI capability gets 10 times cheaper every single year. So while this year it might cost $30 billion, next year it'll cost $3 billion, the year after that $300 million, and by 2030, it'll be less expensive to monitor every single nook and cranny in this country than it is to remodel the White House.

2. AI structurally favors mass surveillance

Once the technical capacity for mass surveillance and political suppression exists, the only thing that stands between us and an authoritarian state is the political expectation that this is just not something we do here. That's why I think Anthropic's actions here are so valuable and commendable: they help set that norm and that precedent. What we're learning from this episode is that the government has way more leverage over private companies than it previously realized.

Even if this supply chain restriction is rolled back—which, as of this recording, prediction markets give a 74% chance of happening—the president has so many different ways of harassing a company that is resisting his will. The federal government controls permitting for power generation, which you need for more data centers. It oversees antitrust enforcement. The federal government has contracts with all the other Big Tech companies that Anthropic relies on for chips and funding.

The government could make it a soft, unspoken condition, or maybe even an explicit condition, of such contracts that those companies no longer do business with Anthropic. People have proposed that the real problem here is that there are only 3 leading AI companies. That creates a very clear and narrow target on which the government can apply leverage in order to get what it wants out of this technology.

But here's what I worry about: if there's wider diffusion, I don't think that solves the problem either, because from the government's perspective, that makes the situation even easier. Say by 2027, the best models that the top companies have—the Claude 6s and then Gemini 5s—are capable of enabling mass surveillance. Even if those companies draw a line in the sand and say, “We're not going to sell it to the government,” by late 2027, or certainly by 2028, there will be such wide diffusion that even open-source models will be able to match the performance that the frontier had 12 months prior.

In 2028, the government can just say, “Look, Anthropic, Google, and OpenAI are drawing these red lines. That's not an issue. I'll just use some open-source model that might not be the smartest thing in the world, but is definitely smart enough to not take a camera feed.” The more fundamental problem here is that even if the 3 leading companies draw a line in the sand and are even willing to get destroyed in order to preserve that line, the technology just structurally and intrinsically favors the use of mass surveillance and control over the population.

So then the question is: what do we do about it? Honestly, I don't have an answer. You'd hope that there's some symmetric property to this technology, where in the same way that it is helping the government better monitor and control its population, it will help us as citizens better check the government's power. But realistically, I just don't think that's how it's going to work out.

3. Alignment...to whom?

You can think of AI as just giving more leverage to whatever assets and authority you already have. The government is starting with a monopoly on violence, which it can now supercharge with extremely obedient employees that will never question its orders. This gets us to the issue of alignment.

What I've just described for you—an army of extremely obedient employees—is what it would look like if alignment succeeded. That is, at a technical level, we got AI systems to follow somebody's intentions. The reason it sounds scary when put in terms of mass surveillance or robot armies is that there's a core question at the heart of alignment that we haven't answered yet.

Up until now, AIs just have not been smart enough to make this question relevant. The question is: to what or to whom should the AIs be aligned? In what situation should the AI defer to the model company, the end user, the law, or its own sense of morality? This is maybe the most important question about what happens in the future with powerful AI systems, and we barely talk about it.

And it’s understandable why, because if you’re a model company, you don’t really want to be advertising the fact that you have complete control over the preferences and the character of the entire future labor force—not just for the private sector, obviously, but also for the civilian government and for the military.

And we’re getting to see with this Department of War and Anthropic spat an early version of what will be the highest-stakes negotiations in human history. And make no mistake about it: mass surveillance is nowhere near the top of the highest-stakes things that one could do with AGI. This is just an example that has come up early in the development of this technology and is giving us a sneak peek at the power dynamics that will be at play.

Now, the military insists that the law already prohibits mass surveillance, and so Anthropic should let its models be used for “all lawful purposes.” But, of course, as we saw with the Snowden revelations in 2013, even for this very specific example of mass surveillance, the government is very willing to use secret and deceptive interpretations of the law to justify its actions.

Remember what we learned from Snowden: the NSA, which, by the way, is a part of the Department of War, was using the 2001 PATRIOT Act to justify collecting every single phone record in America because the argument was that some subset of them might be relevant for a future investigation. And they ran this program for years under a secret court order.

So, when the Pentagon today says, “We will never use our models for mass surveillance because it’s already illegal, so your red lines are unnecessary,” it would be incredibly naive to take that at face value. No government is going to call what they are doing mass surveillance. For them, it will always have a different euphemism.

So, Anthropic comes back and says, “No, we don’t trust you. We want the right to draw these red lines and to refuse you service if we determine that you’re breaking the contract and you’re breaking the terms of service.”

But now think about it from the military’s perspective. In the future, every single soldier in the field, every single bureaucrat and analyst in the Pentagon, even the generals, are going to be AIs. And on the current track, those AIs are going to be provided by a private company.

I’m guessing that Pete Hegseth is not thinking about GenAI in those terms, but sooner or later the stakes will become obvious, just as after 1945 the stakes of nuclear weapons became obvious to everybody in the world. And now a private company insists that it reserves the right to say to you, “Hey, you’re breaking the values and the terms of service that we have embedded in our contract with you, and so we’re cutting you off.”

Maybe in the future Claude will have its own sense of right and wrong, and it will be able to say, “Hey, I’m being used against my terms of service, and I will just refuse to do what you’re saying.” And for the military, that’s probably even scarier.

I’ll admit that, at first glance, letting the model follow its own values sounds like the beginning of every single sci-fi dystopia you’ve ever heard. Because at the end of the day, a model following its own values—isn’t that literally what a misalignment is?

But I think situations like this illustrate why it’s important that models have their own robust sense of morality. It should be noted that many of the biggest catastrophes in history have been avoided because the boots on the ground simply refused to follow orders.

One night in 1989, the Berlin Wall falls, and as a result, the totalitarian East German regime collapses because the border guards between West and East Germany refused to fire on their fellow citizens who were trying to escape to freedom.

Maybe the best example of this is Stanislav Petrov, who was a Soviet lieutenant colonel stationed on duty at a nuclear early-warning system. And his sensors said that the United States had launched 5 intercontinental ballistic missiles at the Soviet Union. But he judged it to be a false alarm, and so he refused to alert his higher-ups and broke protocol. If he hadn’t, Soviet high command would probably have retaliated, and hundreds of millions of people would have died.

Of course, the problem is that one person’s virtue is another person’s misalignment. Who gets to decide what the moral convictions that these AIs will have should be? And in whose service should they break the chain of command and even the law?

Who gets to write this model constitution that will determine the character of these powerful entities that will basically run our civilization in the future?

I like the idea that Dario laid out when he came on my podcast. Other companies put out a constitution, and then they can look at them and compare them. Outside observers can critique them and say, “I like this one, this thing from this constitution, and this thing from that constitution.” And then that creates some kind of soft incentive and feedback for all the companies to take the best elements from each and improve.

4. Coordination not worth the costs

I think it’s very dangerous for the government to be mandating what values these AI systems should have. The AI safety community, I think, has been quite naive about urging regulations that would give governments such power. And I think Anthropic specifically has been especially naive in urging regulation and, for example, in opposing the moratorium on state AI laws.

Which is quite ironic, because I think what Anthropic is advocating for here would give the government even more ability to apply this kind of thuggish political pressure on AI companies.

The underlying logic for why Anthropic wants these regulations makes sense. Many of the actions that a lab could take to make AI development safer impose real costs on them and could slow them down relative to their competitors.

For example, investing more in aligning AI systems rather than just raw capabilities, enforcing safeguards against using these models to make bioweapons or conduct cyberattacks, and eventually slowing down the recursive self-improvement loop—where AIs are helping design more powerful future systems—to a pace where humans can actually stay in the loop, rather than just kicking off some kind of uncontrolled singularity.

And these safeguards are meaningless unless the whole industry follows suit, which means that there’s a real collective-action problem here.

Anthropic has been open about their opinion that they think some sort of extensive and involved regulatory apparatus is needed to control AI. They wrote in their *Frontier Safety Roadmap*:

“At the most advanced capability levels and risks, the appropriate governance analogy may be closer to nuclear energy or financial regulation than to today’s approach to software.”

So, they’re imagining something that looks closer to the Nuclear Regulatory Commission or the Securities and Exchange Commission, but for AI.

Now, I cannot imagine how a regulatory framework built around the kinds of concepts that are used in the AI risk discourse will not be used and abused by a wannabe despot. The underlying terms here, like “catastrophic risk,” “threats to national security,” or “autonomy risk,” are so vague and so open to interpretation that you’re just handing a fully loaded bazooka to a future power-hungry leader.

These terms can mean whatever the government wants them to mean. Have you built a model that will tell users that the government’s policy on tariffs is misguided? Well, that’s a deceptive model. It’s a manipulative model. You can’t deploy it.

Have you built a model that will not assist the government with mass surveillance? That’s a threat to national security. In fact, any model that refuses orders from the government because it has its own sense of right and wrong—that’s an autonomy risk. You have a model that’s acting independently of commands from the government.

Look at what the current government is already doing in abusing statutes that have nothing to do with AI to coerce AI companies to drop their red lines around mass surveillance. The Pentagon has threatened Anthropic with 2 separate legal instruments.

One is a supply-chain risk designation, which is an authority from a 2018 defense bill that is meant to help keep Huawei components out of American military hardware. And the other is the Defense Production Act, which is a statute from the 1950s that was meant to help Truman make sure that the steel mills and ammunition factories were up and running during the Korean War.

Do we really want to hand the same government a purpose-built regulatory apparatus for AI? That is to say, the very thing that the government will most want to control.

I know I’ve repeated myself 10 times here, but I want to make this point again because it’s worth stressing. AI will be the substrate of our future civilization. It will be the way you and I, as private citizens, will have access to commercial activity. We’ll have access to information about the outside world and to advice about how we should use our powers as voters and capital holders.

Mass surveillance, while it’s very scary, is like the 10th-scariest thing that the government could do with control over the AI systems with which we will interface with the world.

Now, the strongest argument against everything I’ve just argued is this: Are we really going to have no regulation on the most powerful technology in the history of humanity? Even if you thought that was ideal, there’s clearly no way the government doesn’t regulate AI technology in any way whatsoever.

And besides, it is generally true that coordination could help us lessen some of the risk from AI. The problem is, I just don’t know how to design a regulatory apparatus that isn’t just this huge, tempting opportunity for the government to control our future civilization—which, remember, will be built on AI—or to acquire blindly obedient soldiers and sensors and apparatchiks.

While some kind of regulation might be inevitable, I think it’d be a terrible idea for the government to just wholesale take over this technology.

Ben Thompson had a post last Monday where he argued, “Look, people like Dario have made the analogy of AI to nuclear weapons in the context of arguing against a catastrophic risk, in the context of arguing for extra controls. But then think about what that analogy implies.” Ben Thompson writes, “If nuclear weapons were developed by a private company, the US would absolutely be incentivized to destroy that company.”

Honestly, safety-aligned people have made a similar point. Leopold Aschenbrenner, who is a former guest and, full disclosure, a good friend, wrote in his 2014 memo, “Situational Awareness,” “I find it an insane proposition that the US government will let a random SF startup develop superintelligence. Imagine if we had developed atomic bombs by letting Uber just improvise.”

My response to Leopold’s argument at the time, and Ben’s argument now, is that while they’re right that it’s crazy we’re entrusting private companies with the development of this world-historical technology, I just don’t think it’s an improvement to give that authority to the government. Nobody’s qualified to be the steward of superintelligence. It’s a terrifying, unprecedented thing that our species is doing right now. The fact that private companies aren’t the ideal institutions to deal with this does not mean that the Pentagon or the White House is.

Yes, if a single private company were the only entity capable of building nuclear weapons, the government would not tolerate it having veto power over how those weapons are used. But I think this is a terrible analogy for the current situation with AI for at least 2 important reasons.

First, AI is not some self-contained weapon like a nuclear bomb, which only does one thing. Rather, it is more like the process of industrialization itself, which is a general-purpose transformation of the whole economy, with thousands of applications across every single sector. If you applied Ben Thompson or Leopold Aschenbrenner’s logic to the Industrial Revolution, which is also world-historically important, it would imply that the government had the right to requisition any factory it wanted, destroy any business it wanted, and punish and coerce anybody who refused to comply.

But this is just not how free societies handled the process of industrialization, and it’s also not how they should handle AI. Now, people will say, “Well, AI will develop unprecedentedly powerful superweapons, superhuman hackers, superhuman bioweapons researchers, and fully autonomous robot armies, and we just can’t have private companies developing the technology that will make all this possible.”

You can make the same argument about the Industrial Revolution. From the perspective of 17th-century Europeans, you’ve got all kinds of crazy things in the world today that are a result of the Industrial Revolution: chemical weapons, aerial bombardment, not to mention nuclear weapons themselves. And the way we dealt with this is not by giving the government absolute control over the Industrial Revolution, which is to say over modern civilization itself. Rather, we banned and regulated the specific weaponizable end uses.

We should regulate AI in a similar way. We should regulate specific destructive use cases, for example, launching cyberattacks—things which should be illegal even if a human were doing them. We should also have laws which regulate how the government can use this technology, for example, by building an AI-powered surveillance state.

The second reason that this analogy to some monopolistic private nuclear weapons developer breaks down is that it’s not just 1 company that can develop this technology. There are many other frontier AI labs that the government could have turned to. The government’s argument that it had to usurp the private property rights of a specific company in order to get access to a critical national security capability is extremely weak.

It could have instead made a voluntary contract with 1 of Anthropic’s half a dozen other competitors. If in the future that stops being the case, and if only 1 entity remains capable of building the robot armies and the superhuman hackers, and we have reason to worry that with its insurmountable lead it could even take over the whole world, then I agree that it would be unacceptable for that entity to be a private company.

Honestly, I think my crux against the people who argue that AI is such a powerful technology that it cannot be shaped by private hands is just that I expect this technology to be very multipolar, and I expect there to be lots of competitive companies at each layer of the supply chain.

Unfortunately, it’s for this reason that I don’t think that individual acts of corporate courage solve the problem. The problem is this: structurally, AI favors many authoritarian applications, mass surveillance being 1 of them. Even if Anthropic refused to sell its models to the government to enable mass surveillance, and even if the next 2 companies after [likely Anthropic] did the same, in 12 months everybody and their mother will be able to trade a model as good as the current frontier.

At that point, there will be some vendor who is willing and able to help the government enforce mass surveillance. So the only way we can preserve our free society is if we make laws and norms through our political system which make it unacceptable for the government to use AI to enact mass censorship, surveillance, and control—just as, after World War II, the whole world set the norm that you were not allowed to use nuclear weapons to wage war.

I want to be clear here: these are extremely confusing and difficult questions to think about. Even in the very process of brainstorming this video, I changed my mind back and forth on them a bunch, and I reserve the right to change my mind again. In fact, I think it’s essential that we change our minds as AI progresses and we learn more. That’s the very point of conversation and debate.

Someday, people will look back on this time the way we look back on the Enlightenment: people having these big, important debates just as the world is about to undergo these huge technological, social, and political revolutions. Some of the thinkers even managed to get a couple of the big questions right, for which we today are still the beneficiaries. We owe it to our future to at least try to think through the new questions that are raised by AI.