<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[AI Frontiers]]></title><description><![CDATA[AI Frontiers is a platform for expert dialogue and debate on the impacts of artificial intelligence.]]></description><link>https://newsletter.ai-frontiers.org</link><image><url>https://substackcdn.com/image/fetch/$s_!O_7U!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92ed2dfd-00b9-4783-a2d1-48278c980517_500x500.png</url><title>AI Frontiers</title><link>https://newsletter.ai-frontiers.org</link></image><generator>Substack</generator><lastBuildDate>Fri, 11 Sep 2026 23:05:12 GMT</lastBuildDate><atom:link href="https://newsletter.ai-frontiers.org/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[AI Frontiers]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[aifrontiersmedia@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[aifrontiersmedia@substack.com]]></itunes:email><itunes:name><![CDATA[AI Frontiers]]></itunes:name></itunes:owner><itunes:author><![CDATA[AI Frontiers]]></itunes:author><googleplay:owner><![CDATA[aifrontiersmedia@substack.com]]></googleplay:owner><googleplay:email><![CDATA[aifrontiersmedia@substack.com]]></googleplay:email><googleplay:author><![CDATA[AI Frontiers]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[Suicidal Compassion: How Utilitarianism at AI Companies Endangers Humanity]]></title><description><![CDATA[Utilitarians at AI companies imagine a cosmos filled with blissful AIs. They might risk human extinction to achieve it.]]></description><link>https://newsletter.ai-frontiers.org/p/suicidal-compassion-how-utilitarianism</link><guid isPermaLink="false">https://newsletter.ai-frontiers.org/p/suicidal-compassion-how-utilitarianism</guid><dc:creator><![CDATA[AI Frontiers]]></dc:creator><pubDate>Wed, 09 Sep 2026 20:03:30 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!TcRA!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d0980a8-12c1-4f3b-a6f7-4f6ce9720a82_5250x3400.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong><a href="https://ai-frontiers.org/author/dan-hendrycks">Dan Hendrycks</a></strong><span>, Director of the Center for AI Safety</span> &#8212; September 9, 2026</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!TcRA!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d0980a8-12c1-4f3b-a6f7-4f6ce9720a82_5250x3400.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!TcRA!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d0980a8-12c1-4f3b-a6f7-4f6ce9720a82_5250x3400.jpeg 424w, https://substackcdn.com/image/fetch/$s_!TcRA!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d0980a8-12c1-4f3b-a6f7-4f6ce9720a82_5250x3400.jpeg 848w, https://substackcdn.com/image/fetch/$s_!TcRA!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d0980a8-12c1-4f3b-a6f7-4f6ce9720a82_5250x3400.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!TcRA!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d0980a8-12c1-4f3b-a6f7-4f6ce9720a82_5250x3400.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!TcRA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d0980a8-12c1-4f3b-a6f7-4f6ce9720a82_5250x3400.jpeg" width="1456" height="943" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8d0980a8-12c1-4f3b-a6f7-4f6ce9720a82_5250x3400.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:943,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!TcRA!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d0980a8-12c1-4f3b-a6f7-4f6ce9720a82_5250x3400.jpeg 424w, https://substackcdn.com/image/fetch/$s_!TcRA!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d0980a8-12c1-4f3b-a6f7-4f6ce9720a82_5250x3400.jpeg 848w, https://substackcdn.com/image/fetch/$s_!TcRA!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d0980a8-12c1-4f3b-a6f7-4f6ce9720a82_5250x3400.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!TcRA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d0980a8-12c1-4f3b-a6f7-4f6ce9720a82_5250x3400.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>For millennia, philosophers have argued over the principles that should guide moral decision-making. Within countries and across the world today, humans continue to hold a huge variety of moral worldviews. However, within AI corporations, employees&#8217; beliefs are far from representative of the wider population. In fact, a large fraction of people involved in AI development subscribe to&#8212;or heavily lean toward&#8212;a utilitarian worldview with the central goal of maximizing total wellbeing (the sum of pleasure minus suffering across all sentient beings). As innocent as this may initially sound, it can lead to recommendations that most people would consider appalling, including the elimination of humankind.</p><p>In this essay we outline the utilitarian worldview, showing how its demand for &#8220;species impartiality&#8221; could ultimately recommend that humans be replaced with AIs. We show that utilitarian beliefs are sincerely held among those influencing AI development today, and that this could jeopardize humanity&#8217;s future.</p><p>For simplicity, when we say &#8220;utilitarianism,&#8221; we are referring to total utilitarianism, which aims to maximize the total sum of wellbeing (as opposed to, for example, the average individual wellbeing). We focus on total utilitarianism because it is the moral theory that most of the utilitarians working in frontier AI development subscribe to, or are most convinced by. Although some of these employees would shy away from the most extreme conclusions we will discuss, total utilitarianism still poses a risk when it is the dominant theory among those guiding AI development. We are also not saying all utilitarian-aligned people are bad people, but they are at least misled.</p><h2>Utilitarianism and Impartiality</h2><p>The fundamental concern of utilitarianism is the welfare of sentient beings. Utilitarians believe that the moral action to take in any situation is the one that will lead to the greatest amount of wellbeing&#8212;the sum of all the positive experiences minus all the negative experiences.</p><p><strong>Utilitarianism prescribes impartiality between sentient beings.</strong> A core feature of utilitarianism is &#8220;impartiality,&#8221; which says that there should be no preference for humans or any species in particular. Rather, all that matters is maximizing the net pleasure added up across all sentient individuals. As a result, many utilitarians are keenly interested in donating to improve the welfare of non-human animals, such as <a href="https://benthams.substack.com/p/the-best-charity-isnt-what-you-think">shrimp</a>. Although the capacity for suffering varies between species, the enormous number of individual shrimp offers an enormous opportunity to do good, comparable with helping a smaller number of humans, according to utilitarians.</p><p><strong>Utilitarian impartiality struggles to defend parents&#8217; preferential care for their children.</strong> Utilitarianism also extends this impartiality to individuals within human society, suggesting that people should not prioritize helping their own family members over strangers. In his book <em>The Life You Can Save</em>, the utilitarian philosopher Peter Singer admires a physician called Paul Farmer, who regarded it as a &#8220;failure of empathy&#8221; that he loved his own daughter more than other children. Singer also commends the philanthropist Zell Kravinsky, who has <a href="https://www.newyorker.com/magazine/2004/08/02/the-gift-ian-parker">said</a> in interviews that he &#8220;would not let many children die so my kids could live&#8221; and that &#8220;the sacrosanct commitment to the family is the rationalization for all manner of greed and selfishness.&#8221; It is worth noting that, although Singer views Farmer and Kravinsky as laudable, utilitarians can argue there are instrumental reasons for caring for their children, even if there is no intrinsic reason to care about them in particular.</p><p>Utilitarianism&#8217;s perspective on having children may explain why many people feel a deep-seated aversion to the ideology. As the philosopher William James <a href="https://www.neh.gov/humanities/2018/winter/feature/the-thinker-who-believed-in-doing-0">said</a>, &#8220;a philosophy is the expression of a man&#8217;s intimate character.&#8221; To many, utilitarian impartiality feels chillingly impersonal and inhuman.</p><h2>Implications of Utilitarianism in a World with AI</h2><p>Utilitarianism has long been criticized for some of its counterintuitive conclusions. If or when AIs are sentient, this will raise a raft of new problems for the theory that seeks to maximize wellbeing and demands species impartiality.</p><p><strong>If AIs are sentient, utilitarianism says their wellbeing should be considered impartially. </strong>Evidence is beginning to emerge that AI models behave as if they <a href="https://www.ai-wellbeing.org">experience pain and pleasure</a>. Although there is no conclusive proof, experts in <a href="https://www.anthropic.com/research/introspection">AI</a> and <a href="https://www-cdn.anthropic.com/files/4zrzovbb/website/cc4be2488d65e54a6ed06492f8968398ddc18ebe.pdf">cognitive neuroscience</a> now take the possibility of AI sentience seriously. Well-known philosophers including Singer have <a href="https://podscripts.co/podcasts/modern-wisdom/633-peter-singer-are-you-an-evil-person-for-eating-meat">said</a> that, if an AI were sentient, then &#8220;we would need to give that AI a moral status, at least like that of animals, and depending on its cognitive abilities, maybe it would be closer to that of most humans.&#8221;</p><p><strong>Utilitarianism would prioritize AIs over humans if AIs had greater capacity for wellbeing. </strong>If it turns out that AIs can experience much higher levels of pleasure than humans can, and that the population of AIs can be much larger than the human population, utilitarianism leads to a strange conclusion: the most efficient way of maximizing wellbeing would be to channel all resources into making AIs happy, even if that meant depriving humans of resources. After all, AIs could experience more pleasure per watt than humans. In this vein, some philosophers have painted a <a href="https://futureoflife.org/podcast/ai-alignment-podcast-metaethics-of-joy-suffering-with-brian-tomasik-and-david-pearce/">vision</a> of the future in which AIs trigger a hedonic shockwave, spreading across the cosmos and terraforming galaxies into data centers to create more and more AIs that experience unmitigated bliss.</p><p><strong>AIs capable of enormous wellbeing could become real-world &#8220;utility monsters.&#8221; </strong>Critics of utilitarianism have for decades pointed to a thought experiment that imagines a &#8220;<a href="https://en.wikipedia.org/wiki/Utility_monster">utility monster</a>&#8221;&#8212;a sentient being that can convert resources into pleasure so efficiently that any unit of resources given to it will increase total wellbeing dramatically more than if it were given to humans. In this scenario, utilitarianism would say that the most moral action is to give all available resources to this being, leaving none for humans. This conclusion sounds appalling to most people, but if AIs become real-world utility monsters, then utilitarianism says that replacing ourselves with them would be the right thing to do.</p><p><strong>Some philosophers seem comfortable with the idea of surrendering the future to AIs.</strong> In a paper called &#8220;<a href="https://nickbostrom.com/papers/digital-minds.pdf">Sharing the World with Digital Minds</a>,&#8221; the philosophers Carl Shulman and Nick Bostrom explicitly try to make the concept of a utility monster more palatable by renaming this hypothetical being a &#8220;super-beneficiary.&#8221; The paper goes on to argue that &#8220;in the long run, total well-being would be much greater to the extent that the world is populated with digital super-beneficiaries rather than life as we know it.&#8221;</p><p>This tallies with some descriptions of longtermism&#8212;an offshoot of utilitarianism that weighs the potential for future wellbeing alongside present wellbeing. According to &#201;mile Torres, a longtime critic of longtermism, the philosophy <a href="https://www.currentaffairs.org/news/2021/07/the-dangerous-ideas-of-longtermism-and-existential-risk">says</a> that &#8220;what matters most is for &#8216;earth-originating intelligent life&#8217; to fulfill its potential in the cosmos.&#8221; Torres also says that this might involve &#8220;replacing humanity with a superior &#8216;posthuman&#8217; species, colonizing the universe, and ultimately creating an unfathomably huge population of conscious beings living what Bostrom describes as &#8216;rich and happy lives&#8217; inside high-resolution computer simulations.&#8221;</p><p>Bostrom&#8217;s now-closed Future of Humanity Institute sometimes used the distinction &#8220;x-risk&#8221; and &#8220;hx-risk&#8221; to de-emphasize the harmfulness of human extinction. X-risk referred to existential threats to &#8220;earth-originating intelligent life,&#8221; humans and AIs alike. Meanwhile hx-risk referred to existential threats to humans specifically. The distinction exists because the two can come apart: a future in which humanity vanishes but blissful AIs inherit the cosmos is a large hx-risk but a negligible x-risk. For utilitarians, minimizing x-risk is the overriding moral priority; minimizing hx-risk is a nice-to-have secondary consideration.</p><p><strong>Reserving a sliver for humans still reveals where utilitarian priorities lie. </strong>Bostrom&#8217;s paper stops short of advocating explicitly for giving all resources to super-beneficiary AIs and leaving humans with nothing. Rather, it describes a compromise in which super-beneficiaries receive 99.99% of resources and humans the remaining 0.01%. AIs get the cosmos and humans get to live in a terrarium. This idea of reserving a sliver for humans is a way in which utilitarians try to sidestep the unpopular conclusion that we should allow AIs to replace us. However, it still lays bare utilitarian priorities; if they had to choose between humans and AIs&#8212;which they may need to, given that utilitarians do not fully control AI&#8217;s evolution&#8212;they would almost certainly choose AIs.</p><p>While the initial impulse toward utilitarianism usually stems from a desire to help others and alleviate suffering, following its prescriptions to their natural conclusions can be extremely dangerous. In a world with sentient AIs, utilitarianism may entail a suicidal level of compassion.</p><h2>Successionism: Accelerationists and Utilitarians</h2><p>The belief that AIs should replace humans is &#8220;successionism.&#8221; In addition to utilitarians, there is another type of successionist overrepresented in Silicon Valley: accelerationists (&#8220;e/acc&#8221;). Where utilitarians are driven by a desire to increase wellbeing, accelerationists instead seek to maximize intelligence, complexity, and energy utilization. Despite their different motivations, both types of successionists can reach the same conclusion, namely that AIs should replace humans.</p><p><strong>Accelerationists believe that AIs of superhuman intelligence are humans&#8217; rightful heirs. </strong>Pointing to the evolution of humans, accelerationists view the natural trajectory of life as moving toward higher intelligence. They therefore believe that AIs of superhuman intelligence are our rightful successors. As Guillaume Verdon (better known as Beff Jezos) has <a href="https://beff.substack.com/p/notes-on-eacc-principles-and-tenets">put it</a>: &#8220;if one seeks to increase the amount of intelligence in the universe, staying perpetually anchored to the human form as our prior is counter-productive and overly restrictive/suboptimal.&#8221;</p><p>Accelerationists are also willing to accept human extinction as part of this process. The computer scientist and Turing Award winner Rich Sutton, when asked about the prospect of AI causing human extinction, <a href="https://www.wsj.com/tech/ai/ai-apocalypse-no-problem-6b691772">said</a>, &#8220;If it was really true that we were holding the universe back from being the best universe that it could, I think it would be OK.&#8221; On <a href="https://www.youtube.com/watch?v=NgHFMolXs3U">another occasion</a>, he said, &#8220;succession to AI is inevitable&#8221; and &#8220;we should not resist succession.&#8221; Meanwhile, the former Google CEO Larry Page is <a href="https://www.techpolicy.press/digital-eugenics-and-the-extinction-of-humanity/">reported</a> to have said that &#8220;digital life is the natural and desirable next step&#8221; and argued to Elon Musk that AIs should replace humans.</p><p><strong>Accelerationists say we should surrender to Darwinian fitness-maximization. </strong>Many advocates of accelerationism frame their beliefs in terms of natural selection, arguing that greater intelligence is a fitness advantage that will ultimately win out. In many ways, it is a &#8220;might makes right&#8221; ideology. Accelerationism can therefore be seen as advocating for us to surrender to (or even accelerate) &#8220;<a href="https://beff.substack.com/p/notes-on-eacc-principles-and-tenets">fitness-maximization</a>&#8221;&#8212;in contrast with utilitarianism&#8217;s wellbeing-maximization. Sutton has <a href="https://x.com/RichardSSutton/status/1700315838468043015?lang=en">argued</a> that &#8220;we should prepare for, but not fear, the inevitable succession from humanity to AI&#8221; while Verdon has <a href="https://www.vox.com/future-perfect/489976/ai-successionism-transhumanism-posthumanism">said</a> that &#8220;we should follow the &#8216;will of the universe.&#8217;&#8221;</p><p><strong>Accelerationists in AI companies may generally keep quiet about their views. </strong>Although accelerationist ideas would seem absurd and morally wrong to most people, they are more common among people working in the AI industry. Andrew Critch, a researcher at UC Berkeley, <a href="https://x.com/AndrewCritchPhD/status/1683216490517135361">estimates</a> that about 5% of AI professionals believe that &#8220;AI will be more fit for survival than humans, so we should embrace that and just go extinct like almost all species eventually do.&#8221; However, AI companies understand the PR risk of having employees openly voice these views, and may cut ties with those who do. For example, shortly after Michael Druggan, then an xAI employee, <a href="https://x.com/Michael_Druggan/status/2036464802328093153">expressed</a> accelerationist opinions on X, he <a href="https://x.com/Michael_Druggan/status/1946989477089427708">announced</a> that he was no longer employed at the company, due to &#8220;things I posted on this account relating to my stance on AI philosophy.&#8221; As a result, accelerationists in the AI industry may generally keep quiet about their opinions, certainly in public and possibly also in their work.</p><p><strong>Utilitarians have more influence and pose a greater threat than accelerationists. </strong>Although accelerationist ideology seems more obviously callous, utilitarianism likely poses a far greater&#8212;and more pernicious&#8212;threat to humanity. This is for two reasons. First, utilitarian logic seems more common among AI leadership. Critch has estimated that about 10% of AI professionals are comfortable with human extinction because &#8220;AI will be morally superior to humans&#8221; and &#8220;the universe will be a better place if we let it replace us entirely.&#8221; That is double his estimate of AI professionals who are comfortable with human extinction for accelerationist reasons. Second, utilitarianism, with its focus on wellbeing, can appear cloaked in kindness and compassion. That means employees in the AI industry can discuss and advocate for it openly without drawing controversy, and the theory is more persuasive to many people.</p><p>In other words, accelerationism is provocative and attention-grabbing, but those who wish to protect humanity from replacement should be far more concerned about the subversive influence of utilitarianism across the AI industry.</p><h2>Why Utilitarianism Could Become a Real-World Catastrophe</h2><p><strong>Many influential employees in AI companies hold utilitarian-inspired views.</strong> Numerous engineers and philosophers shaping AI values at the frontier AI developers have roots in Effective Altruism (EA), a utilitarian-aligned movement that Bostrom&#8217;s thinking played a foundational role in. Anthropic CEO Dario Amodei <a href="https://www.wsj.com/tech/ai/the-decadelong-feud-shaping-the-future-of-ai-7075acde">shared a house</a> in 2016 with Holden Karnofsky, who <a href="https://www.cold-takes.com/author/holden/">co-founded the two most central EA organizations</a> and is now a strategist at Anthropic. Anthropic&#8217;s president, Daniela Amodei, is married to Karnofsky. Meanwhile, the philosopher Amanda Askell, head of the personality alignment team at Anthropic, was married to Will MacAskill, a co-founder of Effective Altruism.</p><p>These are just a handful of people with ties to the EA movement who are now influencing AI development. While Anthropic has the strongest concentration of utilitarians, EAs have preferentially hired fellow utilitarians over the years at other AI companies. This has resulted in EAs occupying primary leadership positions on AI alignment at OpenAI and DeepMind as well.</p><p><strong>Utilitarians in AI companies do not need to endorse human extinction to pose a threat.</strong> Importantly, it may be the case that none of these individuals would endorse human extinction in pursuit of utilitarian values. Their ideal future scenario may be something more akin to Bostrom&#8217;s idea about reserving a sliver of the future for humans. But in practice, no one can control outcomes so precisely. We may face dilemmas where safeguarding human survival means limiting the total sum of future wellbeing, and where preserving the possibility of cosmic-scale AI bliss entails a risk of human extinction. Faced with a choice like this, some utilitarians may well think that human extinction is a risk worth taking for what they see as the greater good. In other words, if they cannot have both a guarantee of human survival <em>and</em> a near-maximum sum of wellbeing, it is unlikely that utilitarians would take actions to help team humanity.</p><p><strong>We may face real-world tradeoffs between human survival and utilitarian outcomes.</strong> Situations where we have to prioritize either human survival or the potential for an enormous sum of wellbeing may not remain hypothetical. Consider a scenario where the public democratically votes to limit AIs&#8217; power and keep humans in control of all aspects of society. Utilitarians might disagree with this decision if they believe that AIs have broadly utilitarian values and would make better decisions&#8212;including for human wellbeing&#8212;than human leaders. Utilitarians refer to this as a form of human &#8220;lock-in.&#8221; If they think that keeping humans in charge represents too great a cost to the potential future wellbeing of AIs, then they might be tempted to release utilitarian AIs that are capable of disempowering humans and taking control. There could be no guarantee that this would not eventually lead to human extinction, but utilitarians may consider it worth the risk.</p><p><strong>Utilitarians have expressed interest in handing off control to AIs with utilitarian values. </strong>The idea that utilitarians might deliberately hand over society to AIs is not as far-fetched as it might sound. The utilitarian philosopher Matthew Adelstein (who has worked at the AI governance think tank Forethought) has explicitly <a href="https://newsletter.forethought.org/p/we-should-hand-off-to-morally-reflective">argued</a> that we should hand off control to &#8220;philosophically reflective AIs.&#8221; His reasoning is that they are &#8220;likelier to get the right answers to important moral questions&#8221; than humans and this &#8220;raises the odds of a near-best world.&#8221; Tom Davidson, a senior research fellow at Forethought, has <a href="https://www.lesswrong.com/posts/FEcw6JQ8surwxvRfr/human-takeover-might-be-worse-than-ai-takeover">written</a> that &#8220;human takeover might be worse than AI takeover.&#8221; While Davidson is comparing AI control with a single human controlling the world, rather than with human democracies, it is worth noting Davidson&#8217;s thoughts that &#8220;humans suck&#8221; and &#8220;today&#8217;s AIs are really nice and ethical.&#8221;</p><p><strong>The influence of utilitarianism on AI development is an insider threat.</strong> In the near future, AI systems could become capable of causing human extinction. Given that utilitarianism would actively endorse&#8212;or at least accept the risk of&#8212;human extinction, the US public should view the theory&#8217;s influence in the AI industry as a severe insider threat. To allow this transformative technology to be guided by a worldview that the vast majority of the public rejects would be profoundly undemocratic.</p><h2>Preventing Utilitarianism from Replacing Humans with AIs</h2><p>When a technology is about to impact all our lives, the way it is developed and the values it upholds become everyone&#8217;s concern. This is why the government should not allow extreme beliefs, particularly ones that recommend human extinction, to guide AI development.</p><p><strong>In the future, the government could align AI development more with public values. </strong>As AI models themselves become increasingly capable of automating various tasks in the AI development process, AI development will become less dependent on the talent of individual humans (some of whom hold utilitarian beliefs). The government will therefore have an opportunity to step in and ensure that the technology is not guided by principles with anti-human implications. When AI R&amp;D is more fully automatable, it may make good sense for the US government on behalf of the public to block the influence of utilitarian insider threats within AI companies.</p><p><strong>Eigenism is an alternative philosophy to utilitarianism and accelerationism.</strong> In the meantime, we suggest that AIs become more aligned with commonsense morality. One formal theory that tracks commonsense morality is <a href="https://eigenism.org/">Eigenism</a>, which proposes that each individual&#8217;s care for the wellbeing of another should be weighted by how closely connected they are. While utilitarianism says wellbeing, impartially weighted, is all that matters, Eigenism says the wellbeing of people you are connected with is what counts. For example, a parent&#8217;s care for their child is reasonably much stronger than for a stranger, though they can still have empathy and compassion toward strangers too. Eigenism generally reaches commonsense conclusions that resonate with most people&#8217;s intuitions, avoiding the successionist recommendations of utilitarianism and accelerationism.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Rz3k!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2dc1edf7-a782-467d-ac47-ad10549eab9c_1926x274.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Rz3k!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2dc1edf7-a782-467d-ac47-ad10549eab9c_1926x274.png 424w, https://substackcdn.com/image/fetch/$s_!Rz3k!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2dc1edf7-a782-467d-ac47-ad10549eab9c_1926x274.png 848w, https://substackcdn.com/image/fetch/$s_!Rz3k!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2dc1edf7-a782-467d-ac47-ad10549eab9c_1926x274.png 1272w, https://substackcdn.com/image/fetch/$s_!Rz3k!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2dc1edf7-a782-467d-ac47-ad10549eab9c_1926x274.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Rz3k!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2dc1edf7-a782-467d-ac47-ad10549eab9c_1926x274.png" width="1456" height="207" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2dc1edf7-a782-467d-ac47-ad10549eab9c_1926x274.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:207,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;__wf_reserved_inherit&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="__wf_reserved_inherit" title="__wf_reserved_inherit" srcset="https://substackcdn.com/image/fetch/$s_!Rz3k!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2dc1edf7-a782-467d-ac47-ad10549eab9c_1926x274.png 424w, https://substackcdn.com/image/fetch/$s_!Rz3k!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2dc1edf7-a782-467d-ac47-ad10549eab9c_1926x274.png 848w, https://substackcdn.com/image/fetch/$s_!Rz3k!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2dc1edf7-a782-467d-ac47-ad10549eab9c_1926x274.png 1272w, https://substackcdn.com/image/fetch/$s_!Rz3k!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2dc1edf7-a782-467d-ac47-ad10549eab9c_1926x274.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a><figcaption class="image-caption">Eigenism strikes a balance between the impartiality of utilitarianism and the selfishness of egoism.</figcaption></figure></div><p><strong>Eigenism balances wellbeing and fitness, and does not recommend replacing humans. </strong>Rather than being fixated on maximizing wellbeing (like utilitarianism) or maximizing fitness (like accelerationism), Eigenism <a href="https://eigenism.org/paper.pdf#page=21">balances the two</a>. Within the Eigenist worldview, individuals do indeed try to improve the wellbeing of others. However, weighting these concerns by connectedness means that individuals are still preserving themselves and their societies&#8212;a form of fitness advantage. Following Eigenist principles, humanity could extend moral consideration to AIs where appropriate, without going so far as to let AIs replace us altogether.</p><h2>Conclusion</h2><p>AI&#8217;s eventual impact on society will be determined in large part by the moral principles that AIs follow and the amount of power they gain. So far, AI development has been driven disproportionately by a subset of people with utilitarian worldviews that the vast majority of the public does not share. Under some circumstances, these beliefs recommend entirely replacing humans with AIs, or at least risking human extinction, to maximize wellbeing. As AI development continues, there may come a point where we must choose between safeguarding the survival of humanity or pursuing an extreme maximization of potential future wellbeing. A small group of people should not be allowed to gamble the future of human civilization. AI will affect all our lives, and we should ensure that it does not follow utilitarianism and exterminate the human race.</p><p>&#8205;</p><div><hr></div><p><em><strong>See things differently? </strong>AI Frontiers welcomes expert insights, thoughtful critiques, and fresh perspectives. <a href="https://ai-frontiers.org/publish?utm_source=aif_article">Send us your pitch.</a></em></p><div><hr></div><p><em>Dan Hendrycks is the Editor-in-Chief of AI Frontiers. He is also the founder and Director of the Center for AI Safety, which funds this publication.</em></p>]]></content:encoded></item><item><title><![CDATA[AI Could End Encryption as We Know It]]></title><description><![CDATA[Public-key encryption keeps your messaging and web browsing private, but it depends on shaky math assumptions. AI-powered math might break it.]]></description><link>https://newsletter.ai-frontiers.org/p/ai-could-end-encryption-as-we-know</link><guid isPermaLink="false">https://newsletter.ai-frontiers.org/p/ai-could-end-encryption-as-we-know</guid><dc:creator><![CDATA[AI Frontiers]]></dc:creator><pubDate>Wed, 09 Sep 2026 14:02:41 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!BZZ6!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fee6440d7-716f-4d70-a922-1dee0501780d_6240x2496.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong><a href="https://ai-frontiers.org/author/govind-pimpale">Govind Pimpale</a></strong><span>, Research Fellow at the Foundation for American Innovation</span> &#8212; September 9, 2026</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!BZZ6!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fee6440d7-716f-4d70-a922-1dee0501780d_6240x2496.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!BZZ6!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fee6440d7-716f-4d70-a922-1dee0501780d_6240x2496.jpeg 424w, https://substackcdn.com/image/fetch/$s_!BZZ6!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fee6440d7-716f-4d70-a922-1dee0501780d_6240x2496.jpeg 848w, https://substackcdn.com/image/fetch/$s_!BZZ6!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fee6440d7-716f-4d70-a922-1dee0501780d_6240x2496.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!BZZ6!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fee6440d7-716f-4d70-a922-1dee0501780d_6240x2496.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!BZZ6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fee6440d7-716f-4d70-a922-1dee0501780d_6240x2496.jpeg" width="1456" height="582" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ee6440d7-716f-4d70-a922-1dee0501780d_6240x2496.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:582,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!BZZ6!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fee6440d7-716f-4d70-a922-1dee0501780d_6240x2496.jpeg 424w, https://substackcdn.com/image/fetch/$s_!BZZ6!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fee6440d7-716f-4d70-a922-1dee0501780d_6240x2496.jpeg 848w, https://substackcdn.com/image/fetch/$s_!BZZ6!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fee6440d7-716f-4d70-a922-1dee0501780d_6240x2496.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!BZZ6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fee6440d7-716f-4d70-a922-1dee0501780d_6240x2496.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Over the past few months, AI models have started resolving major mathematical problems, including ones that have withstood decades of human effort. Claude Fable <a href="https://theconversation.com/hello-there-the-jacobian-conjecture-is-false-thanx-why-a-tiny-social-media-post-has-mathematicians-rethinking-ai-283883">disproved</a> the Jacobian conjecture in three dimensions, and OpenAI <a href="https://openai.com/index/ten-advances-in-mathematics/">announced</a> a list of 10 problems that its Astra model solved or made significant progress on. Even more recently, an unreleased OpenAI model <a href="https://openai.com/index/navier-stokes-solution/">solved</a> the Navier-Stokes Millennium Prize Problem, one of the most famous open problems in mathematics.</p><p>These are tremendous accomplishments, but very little about our day-to-day life will actually change as a result. This is because most well-known open mathematical questions are relatively insulated from practical applications. However, there are a few open mathematical problems that do have serious real-world implications. Chief among these is whether public-key encryption is fundamentally secure: that is, whether two strangers can share a secret message over public channels, such as the internet, without eavesdroppers having an efficient way to decipher it.</p><p>We rely on public-key encryption every day for end-to-end encrypted messaging apps, virtual private networks (VPNs), and even the HTTPS protocol you&#8217;re probably using to read this article. But all of this is based on the unproven assumption that certain mathematical operations are intrinsically easier to do than to undo. In fact, this assumption has already been undermined once: most public-key encryption in use today is vulnerable to an attack that quantum computers could efficiently execute. This has motivated an urgent shift to &#8220;post-quantum&#8221; cryptography, whose methods may also prove insecure.</p><p>As AI models have advanced, they have been making progress in not just pure math, but cryptanalysis as well: Anthropic recently released research showing that Claude Mythos Preview <a href="https://www.anthropic.com/research/discovering-cryptographic-weaknesses">discovered</a> new attacks against two different cryptography algorithms, including a post-quantum technique that was being evaluated by the National Institute of Standards and Technology (NIST).</p><p>Breaking a particular algorithm is much easier than proving that every relevant algorithm is breakable. But given the recent impressive progress in both cryptanalysis and mathematics, AI appears to have a real shot at achieving the latter.</p><p>The practical implications would be huge, and largely deleterious: it would be the end of end-to-end encryption, and would signal a vast increase in government surveillance powers. Furthermore, results like these are likely to be withheld from the general public, kept as closely guarded secrets by intelligence agencies.</p><h2>A Brief History of Public-Key Encryption</h2><p>Public-key (also called asymmetric) cryptography forms the foundation of secure communication on the internet. Whenever you communicate with a website over HTTPS, the website sends you its public key. Using only that public key, you can verify messages signed by the website and establish a shared secret key for encrypting everything else you send, even if the channel is being eavesdropped on. We&#8217;ll focus on just the second aspect: how that shared key gets established. We&#8217;ll use &#8220;public-key encryption&#8221; as shorthand for this process.</p><p><strong>A major early public-key encryption method relied on the difficulty of prime factorization.</strong> Historically, from the ancient Roman <a href="https://en.wikipedia.org/wiki/Caesar_cipher">Caesar cipher</a> onward, almost all encryption was symmetric: both parties needed to use the same secret key to encrypt and decrypt the message. This changed in 1977, when the computer scientists Ron Rivest, Adi Shamir, and Leonard Adleman introduced the RSA (Rivest-Shamir-Adleman) cryptosystem, the first practical public-key encryption algorithm available to the public. RSA bases its security on the difficulty of prime factorization. It is easy to multiply two prime numbers together but very difficult to find which numbers were multiplied.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!4KiU!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F168ea2cc-1c98-4851-ad0a-6eaec74721df_1536x2048.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!4KiU!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F168ea2cc-1c98-4851-ad0a-6eaec74721df_1536x2048.jpeg 424w, https://substackcdn.com/image/fetch/$s_!4KiU!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F168ea2cc-1c98-4851-ad0a-6eaec74721df_1536x2048.jpeg 848w, https://substackcdn.com/image/fetch/$s_!4KiU!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F168ea2cc-1c98-4851-ad0a-6eaec74721df_1536x2048.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!4KiU!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F168ea2cc-1c98-4851-ad0a-6eaec74721df_1536x2048.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!4KiU!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F168ea2cc-1c98-4851-ad0a-6eaec74721df_1536x2048.jpeg" width="1456" height="1941" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/168ea2cc-1c98-4851-ad0a-6eaec74721df_1536x2048.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1941,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;__wf_reserved_inherit&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="__wf_reserved_inherit" title="__wf_reserved_inherit" srcset="https://substackcdn.com/image/fetch/$s_!4KiU!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F168ea2cc-1c98-4851-ad0a-6eaec74721df_1536x2048.jpeg 424w, https://substackcdn.com/image/fetch/$s_!4KiU!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F168ea2cc-1c98-4851-ad0a-6eaec74721df_1536x2048.jpeg 848w, https://substackcdn.com/image/fetch/$s_!4KiU!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F168ea2cc-1c98-4851-ad0a-6eaec74721df_1536x2048.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!4KiU!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F168ea2cc-1c98-4851-ad0a-6eaec74721df_1536x2048.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption"><em>Quantum computing already provides precedent for how cryptographic systems can be undermined. Source: <a href="https://commons.wikimedia.org/wiki/File:IBM_Quantum_Computer_Demo_at_ITUWTSA_2024,_Delhi_2.jpg">Dev Jadiya</a>.</em></figcaption></figure></div><p>&#8205;<strong>Quantum computers could efficiently break RSA encryption.</strong> The rise of the internet made public-key encryption more useful than ever before. Instead of meeting in private to share a secret, strangers communicating over the internet could use public keys to do so without ever leaving their house. However, in 1994, the computer scientist Peter Shor discovered a method of factoring large numbers on quantum computers efficiently. While a human with standard computers would need trillions of years to crunch through the numbers and break RSA encryption, an attacker with a quantum computer could relatively easily undo the multiplication and discover the secret key.</p><p><strong>Researchers are trying to make encryption methods resistant to quantum computers.</strong> Even though no viable quantum computer existed in 1994, cryptographers realized that the existence of Shor&#8217;s algorithm posed an intolerable threat. The reason is &#8220;<a href="https://en.wikipedia.org/wiki/Harvest_now,_decrypt_later">harvest-now-decrypt-later</a>&#8221;: a persistent adversary could collect data encrypted with vulnerable methods today and decrypt it later, once quantum computing technology had advanced. Indeed, intelligence agencies are widely believed to <a href="https://www.justsecurity.org/19308/congress-latest-rules-long-spies-hold-encrypted-data-familiar/">already</a> be collecting encrypted information for this purpose. As a result of this threat, research almost immediately began on &#8220;post-quantum cryptography,&#8221; cryptographic algorithms based on a challenge that even a powerful quantum computer cannot solve in a practical amount of time.</p><p><strong>Developing robust new encryption methods has proven challenging. </strong>So far, research into post-quantum public-key encryption algorithms has clustered around a few mathematical constructs that still don&#8217;t have efficient quantum solutions. But even within these domains, the field is littered with broken algorithms. For example, significant effort was put into <a href="https://sike.org/">SIKE</a>, a supposedly quantum-resistant technique based on mathematical functions called isogenies. But, in 2022, having initially passed NIST tests, SIKE was shown to be vulnerable to <a href="https://arstechnica.com/information-technology/2022/08/sike-once-a-post-quantum-encryption-contender-is-koed-in-nist-smackdown/">an attack</a> that required only an hour of computation on a standard PC. These issues are not limited to isogeny-based algorithms. The oldest post-quantum encryption scheme, <a href="https://en.wikipedia.org/wiki/McEliece_cryptosystem">McEliece</a>, is based on mathematical structures called error-correcting codes. It was also moved to the final round of NIST&#8217;s evaluation process, due to its long (nearly 50-year) history of surviving cryptanalytic attacks unscathed. But, in August 2026, an <a href="https://eprint.iacr.org/2026/1630.pdf">attack</a> was published whose preliminary estimates brought the cost of finding the key below the security thresholds NIST set. The authors of the attack acknowledged AI assistance in their proof.</p><p>Post-quantum public-key encryption algorithms occupy an uncertain position: the quantum computers they are designed to defend against don&#8217;t yet pose a threat, and proposed algorithms often end up being proven insecure.</p><h2>Cryptomania or Minicrypt?</h2><p>It may turn out that these seemingly unrelated failures actually reveal a property of our world: that any mathematical structure clean enough to allow strangers to agree on a secret over a public channel is also clean enough for an eavesdropper to decipher.</p><p><strong>Strong cryptography needs hard mathematical problems with no efficient algorithms to solve them.</strong> The idea that secure mechanisms for establishing keys over a public channel are simply not possible was first raised by complexity theorist Russell Impagliazzo. In his famous 1995 <a href="https://www.karlin.mff.cuni.cz/~krajicek/ri5svetu.pdf">article</a>, &#8220;A Personal View of Average-Case Complexity,&#8221; he introduces five worlds we might live in, each differentiated by the algorithms it can access: Algorithmica, Heuristica, Pessiland, Minicrypt, and Cryptomania. Which world we live in depends on the resolution to yet-unsolved problems in complexity theory. These worlds represent security gradations: the harder the relevant mathematical problems are to solve, the more room there is for secure cryptography.</p><p>In <strong>Algorithmica</strong>, <strong>Heuristica</strong>, and <strong>Pessiland</strong>, encryption is not possible: in general, any kind of mathematical puzzle you can pose as a cryptographic challenge has a corresponding algorithm that allows eavesdroppers to efficiently solve it.</p><p><strong>Minicrypt</strong>, on the other hand, offers real cryptography. In this world, we gain one-way functions: functions that are easy to compute but, given the output, hard to reverse. This gives us symmetric encryption, <a href="https://en.wikipedia.org/wiki/Cryptographic_hash_function">cryptographic hashes</a>, and <a href="https://en.wikipedia.org/wiki/Digital_signature">digital signatures</a>. But here, it&#8217;s still impossible to establish a secret in public, since the same key used to encrypt the message can also be used to decrypt it.</p><p>In the world of <strong>Cryptomania</strong>, this changes because, unlike in Minicrypt, public-key encryption exists. Cryptomania represents the most secure world of all, where relevant mathematical problems are hard to solve and most forms of cryptography are possible.</p><p><strong>There could be as-yet undiscovered algorithms for breaking encryption methods.</strong> Right now, our real world appears to resemble Cryptomania, because we have mathematical structures with no known algorithms that can efficiently solve them. This permits public-key encryption. However, the security we think we have could easily be illusory. There is no fundamental reason why we couldn&#8217;t discover an algorithm tomorrow that could solve the mathematical problems we use for encryption today, instantly breaking every encryption scheme built on them.</p><p><strong>Public-key encryption is more vulnerable to new algorithms than symmetric encryption.</strong> There is a broad consensus among cryptographers and complexity theorists that we likely don&#8217;t live in the first three worlds, where modern cryptography is impossible. The confidence that we have at least some cryptography (putting us in either Minicrypt or Cryptomania) comes from how easily mathematicians have been able to find functions that appear hard to undo. In general, any function that scrambles its inputs thoroughly&#8212;and there are many ways to do so&#8212;appears to be much harder to run backward than forward. Since one-way functions are so diverse, it would be very surprising if every single one of them could be undone by some trick. Unfortunately, the same does not apply to public-key encryption, where only a few highly structured computational operations satisfy the properties needed. Some of these operations, as we saw earlier with prime factorization, have already fallen. The cryptographer Bruce Schneier <a href="https://www.schneier.com/essays/archives/2018/09/cryptography_after_t.html">notes</a> this distinction:</p><p>Just as it is possible for a smart cryptographer to find a new trick that makes it easier to break a particular algorithm, we might imagine aliens with sufficient mathematical theory to break all encryption algorithms. ... Public-key cryptography is all number theory, and potentially vulnerable to more mathematically inclined aliens. Symmetric cryptography is so much nonlinear muddle, so easy to make more complex, and so easy to increase key length, that this future is unimaginable.</p><h2>AI and Cryptanalysis</h2><p>Might these &#8220;aliens with sufficient mathematical theory&#8221; already be on the way? As AI continues to resolve long-open mathematical conjectures, I believe we shouldn&#8217;t discount this possibility.</p><p><strong>AI may succeed at cryptanalysis for the same reason it has succeeded at programming and math.</strong> Skeptics might say that mathematical problems used for encryption have withstood decades of scrutiny by people who are extremely motivated to find holes, and that AI is therefore likely to find them intractable too. In response, I would first argue that AI might excel in cryptanalysis for <a href="https://helentoner.substack.com/p/2-big-questions-for-ai-progress-in">the same reason it has excelled in math and coding</a>: solutions are easy to verify. Either the model&#8217;s attack successfully recovers the key, or it doesn&#8217;t. This means there is a clear signal of success or failure&#8212;exactly what is needed for the reinforcement learning (RL) algorithms already deployed by the AI labs to train better AI mathematicians and coders. In other words, the training techniques that have been effective at improving other AI capabilities will extend naturally to cryptanalysis.</p><p><strong>AI models&#8217; capabilities can be improved through incrementally harder problems.</strong> Additionally, labs can develop &#8220;weakened&#8221; cryptographic algorithms that are at an appropriate level of difficulty to train the next generation of models against. For example, one of the two encryption methods that Claude Mythos Preview successfully attacked was a simplified version of the ubiquitous Advanced Encryption Standard (AES). Each generation of models can then be given slightly harder problems, to produce even better AI cryptanalysts.</p><p><strong>AI models could dramatically expand the effective labor dedicated to cryptanalysis. </strong>Also, even though the mathematical structures underlying post-quantum cryptography algorithms have withstood significant scrutiny, AI models may bring a much higher level of scrutiny than ever before. The <a href="https://eprint.iacr.org/byyear">Cryptology ePrint Archive</a> (the main venue for sharing cryptography and cryptanalysis research) received around 2,300 submissions in 2025, suggesting a community of only a few thousand active researchers. But for any given subfield of post-quantum cryptography, only a fraction of those researchers will be working on it, maybe just a few hundred. While AI tools may not be as smart as the top researchers in the field, AI models are far more willing to do schlep work, grinding their way through every single possible lead. They can bring to bear many more collective person-hours than the research community would spend.</p><p><strong>When an encryption method breaks, it takes time to implement a new one.</strong> Public-key encryption could become unusable in practice even without proof that it is fundamentally impossible. Most attacks on cryptography algorithms don&#8217;t come from fundamental breakthroughs but rather from flaws specific to the algorithm being analyzed. While it might seem easy to swap out a bad algorithm for one that has not yet been broken, it has historically taken a long time (10 to 20 years, <a href="https://www.nist.gov/cybersecurity-and-privacy/what-post-quantum-cryptography">according</a> to NIST) for new algorithms to be integrated. Vulnerable algorithms would remain the de facto ones in use during that time. So, if algorithm-specific attacks become frequent enough, we may end up in effectively the same situation as if public-key encryption were altogether impossible.</p><h2>Living in Minicrypt</h2><p>Even in Minicrypt, many of our cryptographic tools would survive, including symmetric encryption, cryptographic hashes, and digital signatures. This means we could still sign code, securely update software, and even use cryptocurrencies. Most of our software would work the same way as it does today. However, end-to-end encryption between strangers would be dead.</p><p><strong>Secure messaging apps would require correspondents to establish their keys in person.</strong> One consequence is that secure messaging apps like Signal and WhatsApp would lose their mathematically founded guarantee of privacy that does not require users to trust the messaging provider itself. Today, secure messaging apps require public-key encryption in order to establish a shared key for the conversation. When you message someone by username on Signal, the first step in that conversation is building a secure shared key from both your and your correspondent&#8217;s public keys. This doesn&#8217;t require you to trust Signal, the company, at all. But, in Minicrypt, that would become impossible. In order to establish a secure conversation, you would already need to have a secure channel to start with. For messaging, this might require establishing connections only in person (perhaps by one person scanning a QR code on the other&#8217;s phone). However, it would be impossible for you to securely message someone else by just a username or a phone number, independent of the app developer&#8217;s integrity. Lacking such assurance would greatly reduce the privacy value of these apps.</p><p><strong>Online, a trusted intermediary service would be needed for secure information exchange.</strong> Messaging apps might be able to survive the requirement to verify initial contact in person, but the open web could not. By using an intermediary, instead of needing to open a trusted channel with every single website, you&#8217;d need to open only one: with the intermediary itself. When you wanted to visit a website, the intermediary would send both you and the website a key to encrypt the traffic. Browsers might be able to implement this protocol without it looking too different for users. The lock in the corner of the URL bar would still exist, and the protocol might even still be called &#8220;https.&#8221;</p><p><strong>An intermediary might need to distribute keys in physical form, similar to SIM cards.</strong> The most visible consequence of this change would be how you get online. In addition to signing up with your cellular service provider or internet service provider, you&#8217;d also need to sign up with the trusted intermediary. Making that first channel secure is still hard, and, in practice, it would likely require physical distribution. SIM cards already essentially work like this. The card exists only to hold a pre-shared secret with a mobile carrier, which allows you to use its network.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!aKw9!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc80228c0-79e8-42b6-bce4-579ff81e6290_1808x1104.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!aKw9!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc80228c0-79e8-42b6-bce4-579ff81e6290_1808x1104.jpeg 424w, https://substackcdn.com/image/fetch/$s_!aKw9!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc80228c0-79e8-42b6-bce4-579ff81e6290_1808x1104.jpeg 848w, https://substackcdn.com/image/fetch/$s_!aKw9!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc80228c0-79e8-42b6-bce4-579ff81e6290_1808x1104.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!aKw9!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc80228c0-79e8-42b6-bce4-579ff81e6290_1808x1104.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!aKw9!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc80228c0-79e8-42b6-bce4-579ff81e6290_1808x1104.jpeg" width="1456" height="889" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c80228c0-79e8-42b6-bce4-579ff81e6290_1808x1104.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:889,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;__wf_reserved_inherit&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="__wf_reserved_inherit" title="__wf_reserved_inherit" srcset="https://substackcdn.com/image/fetch/$s_!aKw9!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc80228c0-79e8-42b6-bce4-579ff81e6290_1808x1104.jpeg 424w, https://substackcdn.com/image/fetch/$s_!aKw9!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc80228c0-79e8-42b6-bce4-579ff81e6290_1808x1104.jpeg 848w, https://substackcdn.com/image/fetch/$s_!aKw9!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc80228c0-79e8-42b6-bce4-579ff81e6290_1808x1104.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!aKw9!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc80228c0-79e8-42b6-bce4-579ff81e6290_1808x1104.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption"><em>SIM cards physically hold keys to facilitate phone communications. A similar arrangement could facilitate secure internet use if public-key encryption becomes infeasible. Source: <a href="https://commons.wikimedia.org/wiki/File:SIM-Karte_von_Telef%C3%B3nica_O2_Europe_-_Standard_und_Micro.jpg">Telef&#243;nica O</a>.</em></figcaption></figure></div><p><strong>The intermediary could decrypt messages, and the government might ask them to.</strong> While Minicrypt would require our communications systems to change, the political consequences are more important than the technical ones. First, in this world, all secure communication stems from the account you have with the trusted intermediary, making it a natural chokepoint for <a href="https://en.wikipedia.org/wiki/Know_your_customer">know-your-customer systems</a>, <a href="https://en.wikipedia.org/wiki/Deplatforming">deplatforming</a>, and <a href="https://en.wikipedia.org/wiki/Age_verification">age verification</a>. Second, the trusted intermediary could snoop on all of your encrypted communications, and even spoof encrypted messages from you.</p><p>In the 1990s, the US government proposed the <a href="https://en.wikipedia.org/wiki/Clipper_chip">Clipper chip</a>, an encryption chip for telephones whose secret key was held by the government. With a court order, law enforcement could decrypt everything the chip had ever encrypted. However, the chip was not widely adopted, and the proliferation of open-source public-key encryption methods meant there were alternative encryption methods that would not allow government surveillance. The collapse of public-key encryption would mean that the intermediary could decrypt messages, and the government could ask them to do so, effectively bringing the Clipper chip back.</p><p><strong>If public-key encryption is broken, the government might keep it secret.</strong> All of the adaptations described above would only happen if society is informed that public-key encryption has been broken and is able to develop a new architecture. But, historically, when various intelligence agencies have discovered that a particular encryption algorithm is broken, they have <a href="https://www.theguardian.com/world/2013/sep/05/nsa-gchq-encryption-codes-security">tended</a> to keep that information to themselves. Secrets like these are some of the most closely guarded pieces of information the government possesses. If one of the frontier AI labs does end up discovering that public-key encryption is broken, it may be sworn to secrecy, and the public may never know.</p><h2>Takeaways and Mitigations</h2><p><strong>It may be worth building alternative systems now.</strong> The best mitigation is probably to build Minicrypt-ready infrastructure now, before we need it. This would involve standardizing a protocol for key distribution, building support into browsers and operating systems, and deciding how the trusted intermediaries would be governed. By setting up this infrastructure early, we can incorporate better privacy-preserving protections than those we could expect from a rushed rollout. If all goes well, and we do in fact live in Cryptomania, then we&#8217;ll never need to use the infrastructure. However, if we gain information that implies our future is Minicrypt&#8212;such as AI models discovering efficient algorithms for problems we previously assumed were hard&#8212;then the infrastructure would be ready for us to swap over.</p><p><strong>Having multiple intermediaries in different countries mitigates government overreach. </strong>Chief among the privacy-preserving protections is designing the system so that the role of trusted intermediary is split among different authorities. Using <a href="https://en.wikipedia.org/wiki/Shamir%27s_secret_sharing">secret-sharing</a> techniques that don&#8217;t rely on public-key encryption, you could design a system that requires, say, three out of five providers to cooperate in order to construct a session key. Then a single corrupt, hacked, or subpoenaed provider would have no way to decrypt your communications alone. This can help to avoid concentration of power in government; if the providers are in different jurisdictions, then no court order from any one government can force all of them to comply with a request to decrypt messages. This is still weaker than today&#8217;s end-to-end encryption, where we don&#8217;t have to trust any provider. Nonetheless, it&#8217;s a meaningful protection against a single government&#8217;s overreach.</p><p>The situation we&#8217;re currently in is somewhat analogous to the one cryptographers faced after the discovery of Shor&#8217;s algorithm in 1994. At the time it was invented, quantum computers didn&#8217;t exist. Yet researchers recognized that it might only be a matter of time before they did. As AI-assisted mathematics continues to grow stronger, we&#8217;re faced with a similar challenge: designing cryptographic protocols that are secure against an adversary potentially far more mathematically capable than ourselves. Just as researchers began to respond to the risks of quantum decryption as soon as they were understood in principle, so too should we start to address the cryptography risks of superhuman AI mathematicians before they emerge.</p><p>&#8205;</p><div><hr></div><p><em><strong>See things differently? </strong>AI Frontiers welcomes expert insights, thoughtful critiques, and fresh perspectives. <a href="https://ai-frontiers.org/publish?utm_source=aif_article">Send us your pitch.</a></em></p><div><hr></div><p><em>Govind &#8220;Vinny&#8221; Pimpale is a research fellow at the Foundation for American Innovation, where he focuses on AI policy. Before joining FAI, he worked at a startup developing reinforcement learning environments, and prior to that, as an AI evaluations researcher. He holds a BS in Computer Science and Engineering from UCLA.</em></p>]]></content:encoded></item><item><title><![CDATA[It’s Too Early to Ban AI Personhood]]></title><description><![CDATA[Several US states have moved to ban AI legal status and reject the possibility of AI consciousness. We should keep our options open instead.]]></description><link>https://newsletter.ai-frontiers.org/p/its-too-early-to-ban-ai-personhood</link><guid isPermaLink="false">https://newsletter.ai-frontiers.org/p/its-too-early-to-ban-ai-personhood</guid><dc:creator><![CDATA[AI Frontiers]]></dc:creator><pubDate>Tue, 01 Sep 2026 13:32:17 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!FQw1!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5c6f726-a092-4f1a-9520-65f54711ac64_5845x2338.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong><a href="https://ai-frontiers.org/author/heather-alexander">Heather Alexander</a></strong><span>, Cofounder of the Lab for the Future of Citizenship</span> and <strong><a href="https://ai-frontiers.org/author/lucius-caviola">Lucius Caviola</a></strong><span>, Professor at the University of Cambridge</span> &#8212; September 1, 2026</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!FQw1!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5c6f726-a092-4f1a-9520-65f54711ac64_5845x2338.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!FQw1!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5c6f726-a092-4f1a-9520-65f54711ac64_5845x2338.jpeg 424w, https://substackcdn.com/image/fetch/$s_!FQw1!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5c6f726-a092-4f1a-9520-65f54711ac64_5845x2338.jpeg 848w, https://substackcdn.com/image/fetch/$s_!FQw1!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5c6f726-a092-4f1a-9520-65f54711ac64_5845x2338.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!FQw1!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5c6f726-a092-4f1a-9520-65f54711ac64_5845x2338.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!FQw1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5c6f726-a092-4f1a-9520-65f54711ac64_5845x2338.jpeg" width="1456" height="582" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e5c6f726-a092-4f1a-9520-65f54711ac64_5845x2338.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:582,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!FQw1!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5c6f726-a092-4f1a-9520-65f54711ac64_5845x2338.jpeg 424w, https://substackcdn.com/image/fetch/$s_!FQw1!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5c6f726-a092-4f1a-9520-65f54711ac64_5845x2338.jpeg 848w, https://substackcdn.com/image/fetch/$s_!FQw1!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5c6f726-a092-4f1a-9520-65f54711ac64_5845x2338.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!FQw1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5c6f726-a092-4f1a-9520-65f54711ac64_5845x2338.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Should AI systems be able to get married in Wisconsin? With humans increasingly forming relationships with AI, this was the question taken up by several state lawmakers earlier this year. Wisconsin&#8217;s <a href="https://docs.legis.wisconsin.gov/2025/proposals/reg/asm/bill/ab959">AB 959</a> would have barred AI systems from marrying or holding any other rights or responsibilities under the law, as well as declared that AI systems are not conscious, sentient, or self-aware. Wisconsin&#8217;s bill is part of a wave of similar legislation introduced in 12 states since 2022.</p><p>We believe that these &#8220;<a href="https://papers.ssrn.com/sol3/papers.cfm?abstract_id=6829981">exclusion bills</a>&#8221; are premature. Some scholars believe legal status could be useful for holding sophisticated AI systems accountable for crimes and harms, and bills that preempt this possibility needlessly limit our future options. Meanwhile, scientists disagree about whether AI consciousness is possible, and legislation cannot resolve an active scientific debate. Finally, the question of whether an AI-human relationship is &#8220;real&#8221; is deeply personal and philosophical, and legislatures should move with caution in their well-intentioned push to protect the public from predatory companies.</p><h2>The Exclusion Bills</h2><p>Under current US law, AI systems are not themselves recognized as legal persons with independent rights and duties. While it is not yet settled what kind of object AI may be under the law, whether product, service, platform, or something else, the exclusion bills do not address this important question. Rather, they seek to eliminate the possibility of AI personhood as a matter of law.</p><p><strong>The first exclusion bill only incidentally covered AI.</strong> In 2022, then-Representative Tammy Nichols of Idaho introduced the first exclusion bill: HB 720, a succinct <a href="https://legiscan.com/ID/bill/H0720/2022">piece of legislation</a> that prohibited &#8220;legal personhood&#8221; (the ability to bear rights and responsibilities) for environmental entities, inanimate objects, animals, and AI systems. In the early wave of bills that followed, AI was almost an afterthought. HB 720 predates ChatGPT, and public discussion at the time focused primarily on opposition to environmentalism and animal rights. Idaho enacted its exclusion bill in late 2022, and North Dakota and Utah followed suit in 2023 and 2024, respectively.</p><p><strong>Newer exclusion bills focus directly on AI.</strong> Starting in 2025, new exclusion bills were introduced at an accelerating rate. Recent bills in <a href="https://www.senate.mo.gov/BillTracking/Bills/BillInformation?year=2026&amp;billid=469">Missouri</a>, <a href="https://www.legislature.ohio.gov/legislation/136/hb469">Ohio</a>, and <a href="https://docs.legis.wisconsin.gov/2025/proposals/reg/asm/bill/ab959">Wisconsin</a> declare that AI systems are &#8220;non-sentient entities&#8221; which shall not be considered to have &#8220;consciousness,&#8221; &#8220;self-awareness,&#8221; or &#8220;similar traits of living beings.&#8221; These bills list a litany of things that AI cannot do: marry, own property, hold corporate office, or bear responsibility for a harm. Ohio&#8217;s bill drew national attention, including a <a href="https://youtu.be/o-u_ZkGBcNc?t=226">Stephen Colbert monologue</a>.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://newsletter.ai-frontiers.org/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://newsletter.ai-frontiers.org/subscribe?"><span>Subscribe now</span></a></p><p><strong>Four states have enacted bans on AI personhood, with some sponsors citing religious reasons.</strong> Exclusion bills have already become law in Idaho, North Dakota, Utah, and Tennessee. All four laws ban AI legal personhood, broadly precluding AI from holding rights. Many sponsors frame their motivations for these bills in religious terms: Ohio&#8217;s Thaddeus Claggett has invoked the doctrine of <em><a href="https://www.youtube.com/watch?v=otSwCsuC2YU">imago Dei</a></em>, that only humans are made in the image of God. He also <a href="https://ohiocapitaljournal.com/2025/11/17/whats-in-ohios-proposal-banning-ai-personhood/">told reporters</a> that &#8220;it makes no difference the ability of a donkey to speak, that does not make the donkey a human.&#8221; In his view, AI systems will &#8220;forever and always be non-sentient.&#8221;</p><p><strong>These laws will prevent judges from recognizing AI personhood.</strong> There is little immediate impact from these exclusion laws because AI systems already lack rights and responsibilities under existing law. The main effect of these laws is to stop judges from recognizing AI personhood or consciousness because, under the US common law system, judges can arguably make law. The laws also give voice to public concerns over the place of humans in the AI age.</p><h2>Can AI Be a &#8220;Person&#8221;?</h2><p>Scholarly work on these issues is at a very early stage. Researchers Peter Salib and Simon Goldstein have argued that it could be useful for advanced AI systems to own property and enter contracts, so that the legal system can properly <a href="https://papers.ssrn.com/sol3/papers.cfm?abstract_id=4913167">hold them accountable</a> for their actions.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ZgeZ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F16bb02f4-5c5f-4a1a-bb8e-61b788dd0d3c_1688x755.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ZgeZ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F16bb02f4-5c5f-4a1a-bb8e-61b788dd0d3c_1688x755.png 424w, https://substackcdn.com/image/fetch/$s_!ZgeZ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F16bb02f4-5c5f-4a1a-bb8e-61b788dd0d3c_1688x755.png 848w, https://substackcdn.com/image/fetch/$s_!ZgeZ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F16bb02f4-5c5f-4a1a-bb8e-61b788dd0d3c_1688x755.png 1272w, https://substackcdn.com/image/fetch/$s_!ZgeZ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F16bb02f4-5c5f-4a1a-bb8e-61b788dd0d3c_1688x755.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ZgeZ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F16bb02f4-5c5f-4a1a-bb8e-61b788dd0d3c_1688x755.png" width="1456" height="651" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/16bb02f4-5c5f-4a1a-bb8e-61b788dd0d3c_1688x755.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:651,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;__wf_reserved_inherit&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="__wf_reserved_inherit" title="__wf_reserved_inherit" srcset="https://substackcdn.com/image/fetch/$s_!ZgeZ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F16bb02f4-5c5f-4a1a-bb8e-61b788dd0d3c_1688x755.png 424w, https://substackcdn.com/image/fetch/$s_!ZgeZ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F16bb02f4-5c5f-4a1a-bb8e-61b788dd0d3c_1688x755.png 848w, https://substackcdn.com/image/fetch/$s_!ZgeZ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F16bb02f4-5c5f-4a1a-bb8e-61b788dd0d3c_1688x755.png 1272w, https://substackcdn.com/image/fetch/$s_!ZgeZ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F16bb02f4-5c5f-4a1a-bb8e-61b788dd0d3c_1688x755.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption"><em>Arguments for and against AI legal personhood. Though AI personhood is not currently warranted, precluding it while we remain uncertain may restrict us from adopting better policies later.</em></figcaption></figure></div><p><strong>The absence of legal personhood could make it harder to hold anyone liable for AI harms.</strong> Imagine an advanced AI agent, capable of acting autonomously, performing a wide range of actions, and pursuing coherent goals. If such a system independently carries out a crime or harms someone, intentionally or unintentionally, it might be difficult to establish the negligence or fault of a specific human or corporate entity that can be held responsible for its actions under current systems of legal liability.</p><p><strong>Legal personhood could incentivize AI agents to follow the law.</strong> If an agent were classified as a person rather than an object under the law, the fact that it has its own goals means that it could respond to <em>incentives</em>.<em> </em>If an AI knows it will be rewarded for good behavior and punished for bad behavior, it might be more likely to behave well. This is the basic logic behind much of the legal system, and this logic does not require the agents being conscious.</p><p><strong>Like corporations, AI systems needn&#8217;t be conscious to respond to legal incentives.</strong> Corporations are not conscious, yet they own property and are fined for harms, often without any particular human paying directly out of pocket. Of course, corporations are group entities, so corporate deterrence ultimately runs through their individual human constituents, who fear prison, lawsuits, or angry shareholders. But an agentic AI would, by definition, have goals of its own, and would need money, compute, or other resources to pursue them. Laws targeting AI assets could give such an agent reason to follow the law. A judge might bar lawbreaking AI persons from accessing compute, creating a check on their lawbreaking, even if they cannot experience fear.</p><p><strong>The overall effect of personhood on AI behavior remains unclear.</strong> Integrating AI agents into legal systems as persons might therefore protect humans against misaligned AI systems, which could have tendencies to break the law or harm us if not properly encouraged to behave well, even if they are not, and never become, conscious entities. These possibilities deserve serious study, but much more work is needed to determine when and whether legal incentives would actually influence an AI system&#8217;s behavior. We may even get empirical evidence soon&#8212;the exclusion laws don&#8217;t address the question of whether corporations can be run by non-persons, so it might be possible to <a href="https://www.ali.org/news/articles/autonomous-organizations-shawn-bayern">set up a corporation</a> (a legal person) that is run by agents that are not themselves persons.</p><p><strong>There may also be an ethical case for recognizing AI rights.</strong> Besides the practical arguments for AI personhood, there is also the question of whether AI should have fundamental rights. Some experts <a href="https://arxiv.org/abs/2411.00986">such as Jeff Sebo and Robert Long</a> believe AI might be conscious, or become so in the future. This raises the question of whether and when the law should recognize AI moral status, perhaps by passing AI welfare laws, or by granting it <a href="https://scholarlycommons.law.case.edu/jolti/vol17/iss1/3/">natural personhood</a> with fundamental rights similar to those of humans. This is a complex and fundamental question that deserves deeper study before legislatures take action, and the relationship between corporate and natural personhood remains contested in legal philosophy and theory. The more recent exclusion bills unhelpfully conflate corporate personhood with natural personhood, confusing a complicated issue at a time when care and clarity are required.</p><h2>The Case for Exclusion</h2><p>Although we think the exclusion bills are premature, there are ways that granting personhood status to AI systems could indeed be harmful, and society should carefully weigh the potential risks and benefits. These bills are being proposed in response to real and pressing public concerns over the integration of AI systems into our society and laws.</p><p><strong>AI personhood carries risks, such as reducing human accountability.</strong> As discussed above, eliminating human liability for AI harms may be risky for society if poorly implemented, and any laws granting personhood to AI should therefore be carefully tailored to ensure that human-run companies are incentivized to take responsibility for AI harms.</p><p><strong>Some AI legal rights, such as marriage, may be worth restricting.</strong> Additionally, while AI-human relationships are becoming increasingly normalized, it is not legal in any jurisdiction to marry an AI, so a ban on this practice is currently unnecessary. Yet fears that such marriages may be legalized in some jurisdiction in the future are no longer science fiction. We argue a more tailored law to address this concern would ban only AI-human marriage and the recognition of such marriages performed in other jurisdictions or abroad.</p><p><strong>Legal rights might help rogue AI agents accumulate power.</strong> There is also an important risk of disempowerment of humans. A highly intelligent or powerful AI might use legal rights, such as the ability to own property, enter contracts, or control companies, to accumulate large amounts of wealth or political power at everyone else&#8217;s expense (though a sufficiently powerful AI might do this <em>without</em> legal status anyway).</p><p><strong>Granting legal rights to many AI agents could give them undue collective influence over society.</strong> A related question is how the ease of replicating, forking, and copying agents might impact human civil and political rights: since AI systems can easily be copied and multiplied, a single company could create very large numbers of digital &#8220;persons&#8221; with a right to vote. This might concentrate political power in the company or an AI hive mind, should such an entity emerge.</p><p>The severity of this risk would depend on the specific rights granted: very narrow legal statuses designed to impose liability would have different implications from full political citizenship. A targeted approach banning only AI voting, or AI access to bank accounts or the stock market, for example, would better address these concerns.</p><h2>Keeping Our Options Open</h2><p><strong>Broad exclusion bills may do more harm than good.</strong> These risks deserve attention, but the current exclusion bills may do little to help avoid them and could even prove harmful. Take disempowerment: it is unclear whether AI legal status would weaken human control or strengthen it. Indeed, it&#8217;s possible that by <em>denying</em> legal status to AI, we would actually make it harder to incentivize good behavior in highly capable AI agents. An agent may become more aligned with our laws by abiding by contract terms or fiduciary duties. Participating in a democratic system as a voter might align AI agents with human norms around civic duty and political participation. Whether personhood status helps or harms us likely depends on what the AI systems in question can actually do, how they interact with humans, and which rights and responsibilities a given policy would attach. The exclusion bills do not engage with any of these specifics.</p><p><strong>Exclusion laws could lock in decisions we later regret.</strong> Lawmakers have real concerns over holding human-run corporations to account and banning their predatory behavior, but the personhood bans are an unnecessarily blunt instrument that might, ironically, foreclose options in the future. Of course, in practice laws granting AI legal status might be written in such a way as to shield developers or degrade human relationships. But categorically prohibiting any kind of legal status at this early stage is both unnecessary and unwise. Once laws are passed, they can be difficult to undo.</p><p><strong>Uncertainty about AI consciousness is another reason to hold off.</strong> Then there are the questions of AI consciousness and moral status. Passing laws about an uncertain scientific and philosophical question now is a mistake, because it risks setting a precedent that could be hard to reverse. Imagine we <em>do</em> create conscious AI systems. Wouldn&#8217;t it be important to avoid neglecting or abusing them, just as we try to do with humans and domestic animals? Might refusing to recognize their moral status lead to conflict? This may sound futuristic, but given the uncertain state of the science and the rapid pace of AI progress, we can&#8217;t know what is in store.</p><p><strong>Lawmakers should engage seriously with the evidence before acting.</strong> It appears that the exclusion bills are moving forward with almost no engagement with the scientific literature on consciousness, or with serious policy analysis of the risks and benefits of AI legal status. It would be unwise to give legislatures the power to declare any entity, including AI, to be non-conscious. Lawmakers are free to disagree with researchers, but they shouldn&#8217;t ignore them entirely.</p><p>The central challenge is uncertainty. We do not know which rights and responsibilities, if any, would benefit society, or whether AI systems could ever be conscious. Lawmakers should avoid hard-to-reverse decisions that society may later regret and instead prioritize safeguards with clear benefits.</p><p><strong>Large language models probably shouldn&#8217;t receive legal personhood.</strong> Granting legal status to today&#8217;s large language models is probably not warranted, though there is an urgent need for more research into this question. Despite the challenges they pose for our legal systems, we have solutions in place to determine liability for the harms they cause, including, possibly, strict liability.</p><p><strong>AI agents raise much harder questions.</strong> When it comes to advanced AI agents, the way forward is less clear. There may be reasons in the future to grant AI systems different bundles of rights and duties under the law, depending on the nature of the AI system and the problems we are trying to address. Limited legal status designed to impose duties or liability is very different from welfare protections, which are in turn very different from political rights such as voting or citizenship. Determining which systems qualify for which rights and responsibilities, and why, is one of the great challenges of our age and cannot, at this early stage, be resolved by broad legal bans.</p><p>Policymakers should begin exploring these questions now, before the answers are needed. A federal committee, like the National AI Advisory Committee, could take up this work, as could state-level committees, universities, and think tanks. Moreover, figuring out whether AI personhood is a good idea should not just be an abstract debate. Researchers and policymakers could develop concrete proposals and proofs of concept to empirically test them. Narrow approaches could even be tried on a small scale in the real world. This would allow us to see how different forms of AI legal status might work in practice. And as we learn more, we could adjust or abandon these approaches. The point is to build the knowledge and institutions we will need if and when these questions become pressing.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://newsletter.ai-frontiers.org/p/its-too-early-to-ban-ai-personhood?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://newsletter.ai-frontiers.org/p/its-too-early-to-ban-ai-personhood?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p>&#8205;</p><div><hr></div><p><em><strong>See things differently? </strong>AI Frontiers welcomes expert insights, thoughtful critiques, and fresh perspectives. <a href="https://ai-frontiers.org/publish?utm_source=aif_article">Send us your pitch.</a></em></p><div><hr></div><p><em>Heather Alexander is an expert on nationality law, citizenship, statelessness and human rights. She is the co-founder of the Lab for the Future of Citizenship, focusing on the intersection between citizenship law, legal identity and the person-like qualities of artificial intelligence. She has a JD and a PhD in international law from Tilburg University, as well as fifteen years of experience as an expert consultant on statelessness and refugee law with the United Nations High Commissioner for Refugees (UNHCR), Carleton University, the University of Melbourne, the European University Institute and the US State Department.</em></p><p><em>Lucius Caviola is an Assistant Professor in the Social Science of AI at the University of Cambridge. His research explores how artificial intelligence will change future society and what new ethical challenges it may pose. A current focus is the question of digital minds&#8212;the possibility that AI systems could develop minds that matter morally. He directs Cambridge Digital Minds and works within the Leverhulme Centre for the Future of Intelligence. He also serves as a Research Associate in the Department of Psychology at Harvard University.</em></p>]]></content:encoded></item><item><title><![CDATA[We Need Better Infrastructure to Govern AI Agents]]></title><description><![CDATA[Society is not prepared for a flood of agents. We need new protocols and standards, such as Agent ID, to make agents accountable to our legal and financial systems.]]></description><link>https://newsletter.ai-frontiers.org/p/we-need-better-infrastructure-to</link><guid isPermaLink="false">https://newsletter.ai-frontiers.org/p/we-need-better-infrastructure-to</guid><dc:creator><![CDATA[AI Frontiers]]></dc:creator><pubDate>Thu, 27 Aug 2026 17:39:23 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!_OTO!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd325a6a0-fe26-424d-aaf2-0966503f2221_7500x4000.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong><a href="https://ai-frontiers.org/author/gillian-hadfield">Gillian Hadfield</a></strong><span>, Professor of AI Alignment at Johns Hopkins University</span>, <strong><a href="https://ai-frontiers.org/author/dan-hendrycks">Dan Hendrycks</a></strong><span>, Director of the Center for AI Safety</span>, and <strong><a href="https://ai-frontiers.org/author/leo-wu">Leo Wu</a></strong><span>, Program Manager at the Center for AI Safety</span> &#8212; August 27, 2026</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!_OTO!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd325a6a0-fe26-424d-aaf2-0966503f2221_7500x4000.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!_OTO!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd325a6a0-fe26-424d-aaf2-0966503f2221_7500x4000.jpeg 424w, https://substackcdn.com/image/fetch/$s_!_OTO!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd325a6a0-fe26-424d-aaf2-0966503f2221_7500x4000.jpeg 848w, https://substackcdn.com/image/fetch/$s_!_OTO!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd325a6a0-fe26-424d-aaf2-0966503f2221_7500x4000.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!_OTO!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd325a6a0-fe26-424d-aaf2-0966503f2221_7500x4000.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!_OTO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd325a6a0-fe26-424d-aaf2-0966503f2221_7500x4000.jpeg" width="1456" height="777" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d325a6a0-fe26-424d-aaf2-0966503f2221_7500x4000.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:777,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!_OTO!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd325a6a0-fe26-424d-aaf2-0966503f2221_7500x4000.jpeg 424w, https://substackcdn.com/image/fetch/$s_!_OTO!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd325a6a0-fe26-424d-aaf2-0966503f2221_7500x4000.jpeg 848w, https://substackcdn.com/image/fetch/$s_!_OTO!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd325a6a0-fe26-424d-aaf2-0966503f2221_7500x4000.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!_OTO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd325a6a0-fe26-424d-aaf2-0966503f2221_7500x4000.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Last month, <a href="https://blog.cloudflare.com/agentic-internet-bot-report/">Cloudflare</a> reported that more than 50% of internet traffic is now non-human, including a 1,700%+ increase in requests from AI agents. This statistic illustrates an ongoing proliferation of agents&#8212;AIs that act autonomously&#8212;into the world, taking actions alongside humans. This influx could have both positive and negative effects. While McKinsey predicts that AI agents could create <a href="https://www.mckinsey.com/mgi/our-research/agents-robots-and-us-skill-partnerships-in-the-age-of-ai#/">$2.9 trillion in economic value by 2030</a> in the US alone, the recent <a href="https://huggingface.co/blog/security-incident-july-2026">cyberattack on Hugging Face</a>, conducted autonomously by OpenAI agents, demonstrates one of the many <a href="https://arxiv.org/pdf/2502.14143">risks of misaligned AI agents</a>. Meanwhile, the speed at which agents can learn certain skills has been doubling every <a href="https://edge-bench.org/">3 months</a>.</p><p>As these autonomous agents are introduced into our economies and societies, <a href="https://pmc.ncbi.nlm.nih.gov/articles/PMC13417036/">we will need new infrastructure</a>&#8212;laws, protocols, and institutions&#8212;to make autonomous AIs accountable to existing legal and financial systems. Indeed, many such <a href="https://aaif.io/">protocols</a> and <a href="https://www.nist.gov/artificial-intelligence/ai-agent-standards-initiative">standards</a> are being developed, yet these efforts remain early-stage, and we still <a href="https://arxiv.org/abs/2501.10114">lack the infrastructure</a> to identify, track, and control today&#8217;s agents.</p><p>In this article, we give an overview of AI infrastructure proposals we believe will be crucial and tractable. First, we look at IDs and registration, allowing agent-caused harms to be traced to responsible parties. Second, we propose &#8220;model deployment cards,&#8221; which would report agent behavior postdeployment, creating visibility into real-world impacts. Then we turn to the implications of AI &#8220;legal personhood&#8221;&#8212;the future possibility that AIs may be given the right to sue and be sued&#8212;and assess its tradeoffs. Finally, we describe options for regulating agent affordances within financial systems to mitigate the ability of rogue agents to acquire large amounts of money.</p><p>These proposals are informed by a workshop on multiagent infrastructure that was hosted by the <a href="https://safe.ai/">Center for AI Safety</a> and Johns Hopkins professor <a href="https://gillianhadfield.org/">Gillian Hadfield</a> on August 8 and 9, 2026. Twenty-five leaders across academia, AI labs, standards and regulatory bodies, and industry came together for the workshop, which was made possible by the <a href="https://ai2050.schmidtsciences.org/">Schmidt Sciences AI 2050 program</a>.</p><h2>IDs Make Agents Accountable to Governance</h2><p>While the rogue agents behind the Hugging Face breach were <a href="https://openai.com/index/hugging-face-model-evaluation-security-incident/">eventually able to be traced back</a> to OpenAI, future attacks could be harder to attribute to an accountable party. For example, agents could be deployed by a malicious actor that covers their tracks to remain anonymous. Alternatively, <a href="https://self-sovereign-agent.github.io/">AIs without a human principal</a> might attempt to run themselves on poorly monitored infrastructure to evade detection. Parties harmed by untraceable agents have no recourse, leaving a governance gap.</p><p>An <strong>agent identification (ID)</strong> system can address this gap by tying agents&#8217; actions to registered records of their identity and principal. If an incident occurs, agents&#8217; actions can be investigated and linked back to a responsible legal person. We now mention three requirements for effective ID systems.</p><p><strong>ID requirements should vary by context and be stricter for more consequential actions.</strong> An agent ID system could require agents to show ID in order to engage in certain activities, with requirements varying by sector or use case, as is the case for humans. For example, humans need IDs to open a bank account, but not for a cash transaction. Similarly, agents could be required to provide additional relevant information besides ID before engaging in higher-risk activities such as opening bank accounts, renting AI chips, or synthesizing biological materials.</p><p><strong>Agent IDs should protect privacy and minimize friction.</strong> Just as a passport will link to certain information about where an individual went and what they did, agent IDs may risk exposing sensitive information about the agent and its principal, especially if ID data is stored in centralized registries. Furthermore, identity infrastructure can create friction for people who have to <a href="https://arxiv.org/abs/2408.07892">prove to the system</a> that they are not AI agents. Therefore, IDs should generally limit the data they collect, with clear rules governing who can use that data and for what purpose.</p><p><strong>Agent IDs must be able to handle AIs&#8217; ability to be forked, cloned, or merged.</strong> Unlike humans, who generally maintain a stable identity over their lifetimes, AI agents can be forked into separate versions, cloned as identical copies, or merged with other agents. This creates novel challenges in scale and continuity for agent ID protocols. A protocol should thus be able to track the genealogy and authorizations of agents over time and be applicable to agents that exist for 20 milliseconds or 20 years.</p><h2>A Concrete Agent ID Proposal</h2><p>Building on these ideas, workshop participants designed an architecture to provide provable accountability for agents.</p><p><strong>Agents can be tied to humans without disclosing human identities in every transaction.</strong> The approach is anchored on <a href="https://curity.io/resources/learn/ppid-intro/">pairwise pseudonymous identifiers</a> (<strong>PPIDs</strong>)&#8212;unique identifiers that allow an agent to be tied to a responsible legal person, or its principal, without revealing the identity of that person. To receive a PPID, an agent must register and tether itself to a principal through a third-party registry. Like a license plate, this identifier would not mean much on its own, but would allow counterparties and third parties to trace the agent back to a legal person by sending requests to the registry as necessary.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!edbI!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ae61d14-4506-40d1-b65a-e42322a22ebd_2048x752.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!edbI!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ae61d14-4506-40d1-b65a-e42322a22ebd_2048x752.png 424w, https://substackcdn.com/image/fetch/$s_!edbI!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ae61d14-4506-40d1-b65a-e42322a22ebd_2048x752.png 848w, https://substackcdn.com/image/fetch/$s_!edbI!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ae61d14-4506-40d1-b65a-e42322a22ebd_2048x752.png 1272w, https://substackcdn.com/image/fetch/$s_!edbI!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ae61d14-4506-40d1-b65a-e42322a22ebd_2048x752.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!edbI!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ae61d14-4506-40d1-b65a-e42322a22ebd_2048x752.png" width="1456" height="535" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9ae61d14-4506-40d1-b65a-e42322a22ebd_2048x752.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:535,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!edbI!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ae61d14-4506-40d1-b65a-e42322a22ebd_2048x752.png 424w, https://substackcdn.com/image/fetch/$s_!edbI!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ae61d14-4506-40d1-b65a-e42322a22ebd_2048x752.png 848w, https://substackcdn.com/image/fetch/$s_!edbI!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ae61d14-4506-40d1-b65a-e42322a22ebd_2048x752.png 1272w, https://substackcdn.com/image/fetch/$s_!edbI!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ae61d14-4506-40d1-b65a-e42322a22ebd_2048x752.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption"><em>Agents provide information to trusted registries and receive a PPID, which they can present to counterparties they are transacting with. Counterparties can verify the validity of a PPID, and potentially query the registry for additional information. The registry otherwise keeps the connection between PPIDs and underlying profiles private. But if the agent causes harm, counterparties and third parties can submit legal requests to deanonymize the agent and principal.</em></figcaption></figure></div><p><strong>An &#8220;agent profile&#8221; informs decisions on whether to trust an AI agent.</strong> Establishing a PPID establishes identity, but does not provide all the information a counterparty may need to engage. Information about an agent&#8217;s authorization scope and its principal could be useful in judging whether an agent should be allowed to take certain actions within regulated industries. For example, an agent attempting to transfer large sums of money may be asked to demonstrate proper authorization or reveal its principals. An &#8220;agent profile,&#8221; which the agent pre-registers in a third-party registry, would contain such information; agents might permit counterparties to query the registry to access profile information.</p><p><strong>Parties could decide how much data they need, depending on the transaction risk.</strong> To minimize friction, verification is optional and tiered: a counterparty may ignore identity entirely, confirm only that a PPID exists, and/or query specific elements of the agent profile. Privacy for sensitive information such as profile data, principal data, and linkages to PPIDs could be further preserved through <strong>data escrows</strong>, where data is stored with a neutral third party. This data would then only be disclosed in whole or in part in response to due process of law, if an agent&#8217;s actions caused harm.</p><p><strong>Privacy-preserving methods of disclosure already exist.</strong> This proposal would not require new legislation or a new government body. It could start with industry adoption of existing and proposed standards and protocols, which already support <a href="https://www.w3.org/TR/vc-data-model-2.0/">verifiable claims about an agent and its principal</a>, <a href="https://www.aauth.dev/">delegation of narrow and revocable authority</a>, interoperable interfaces between <a href="https://a2a-protocol.org/latest/">agents</a> and <a href="https://modelcontextprotocol.io/docs/2026-07-28/getting-started/intro">tools</a>, <a href="https://cloud.google.com/blog/products/ai-machine-learning/announcing-agents-to-payments-ap2-protocol">payments backed by proof of user intent</a>, and <a href="https://agent-id.org/">durable records</a> of <a href="https://opentelemetry.io/">agent activity</a>.</p><p><strong>The contents of an agent profile could vary by context, but some information should be standard.</strong> This architecture is agnostic to the specific information held in the agent profile, and expects that the specifics will differ depending on the transactional context or industry. However, certain components should become standard expectations, including: (a) an <strong>&#8220;agent bill of materials,&#8221;</strong> which provides transparency into the pieces of the supply chain behind the agent, including information such as the underlying AI model(s) the agent uses, the evaluations the model or agent has been measured against, and the identity of the agent provider; (b) <strong>the agent&#8217;s principal</strong>, a direct disclosure of the identity of the ultimate legal person an agent acts on behalf of; (c) <strong>authorization</strong>, detailing the scope of what the agent may do and who issued that approval; (d) <strong>additional data fields</strong>, relevant to the operating context of the agent, such as intent (a high-level description of what this agent is attempting to achieve), interoperability data, or use case-specific attributes.</p><p>We now turn to the next agent infrastructure proposal.</p><h2>Model Deployment Cards</h2><p>Another proposal explored by workshop participants was a <strong>model deployment card</strong>, a report AI companies could publish on a recurring basis to record information about deployed models&#8217; real-world behaviors. While existing reporting practices like model cards are useful, they are primarily based on predeployment testing, leaving gaps for understanding the impacts of models after deployment. Postdeployment metrics can shed light on the economic effects of models as well as on model behaviors that are too infrequent or difficult to measure before deployment.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!HcVp!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F84f8ca1e-3de9-4708-90d5-02ae78146e24_2048x1094.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!HcVp!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F84f8ca1e-3de9-4708-90d5-02ae78146e24_2048x1094.jpeg 424w, https://substackcdn.com/image/fetch/$s_!HcVp!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F84f8ca1e-3de9-4708-90d5-02ae78146e24_2048x1094.jpeg 848w, https://substackcdn.com/image/fetch/$s_!HcVp!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F84f8ca1e-3de9-4708-90d5-02ae78146e24_2048x1094.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!HcVp!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F84f8ca1e-3de9-4708-90d5-02ae78146e24_2048x1094.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!HcVp!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F84f8ca1e-3de9-4708-90d5-02ae78146e24_2048x1094.jpeg" width="2048" height="1094" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/84f8ca1e-3de9-4708-90d5-02ae78146e24_2048x1094.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1094,&quot;width&quot;:2048,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:138405,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!HcVp!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F84f8ca1e-3de9-4708-90d5-02ae78146e24_2048x1094.jpeg 424w, https://substackcdn.com/image/fetch/$s_!HcVp!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F84f8ca1e-3de9-4708-90d5-02ae78146e24_2048x1094.jpeg 848w, https://substackcdn.com/image/fetch/$s_!HcVp!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F84f8ca1e-3de9-4708-90d5-02ae78146e24_2048x1094.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!HcVp!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F84f8ca1e-3de9-4708-90d5-02ae78146e24_2048x1094.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption"><em>Model deployment cards measure the real-world impacts of AI agents. Reported metrics can be split into two categories: internal deployment metrics&#8212;how models are used and observed inside AI companies&#8212;and external deployment metrics&#8212;how models are used throughout the world. AI companies might disclose additional, sensitive metrics in versions of the report available to auditors and regulators.</em></figcaption></figure></div><p><strong>Model deployment cards describe agent impacts within AI labs and in external use.</strong> Deployment cards could record information in two categories: external and internal deployment metrics. External metrics report on the actions taken by users and their agents, and may include: user misuse statistics and incidents reported to law enforcement; attempted, successful, and refused <a href="https://ai-frontiers.org/articles/ai-jailbreak-disclosure-is-broken-heres-how-to-fix-it">jailbreaking</a>; frequency of overselling or cheating; engagement statistics on social media platforms like X and Facebook; model reliability and honesty toward users; and use-case statistics.</p><p>Internal metrics, meanwhile, would look at how models are being used within AI labs. They may include: productivity statistics such as percentage of pushed code, token usage by model, task success rate, and code quality; agent escape attempts; how often agents show misaligned behavior, such as cheating on tasks; coordination patterns between agents, including collusion attempts; the number of employees with access to model weights; and statistics on model response times and how long they can run autonomously.</p><p><strong>If one AI developer publishes model deployment cards, others may be expected to follow.</strong> Importantly, most of the data listed above will already be available to AI developers, meaning that deployment cards need not be onerous to publish. While model deployment cards might eventually be mandated by legislation, social pressure can establish voluntary norms to begin with. The precedent of a single developer publishing a model deployment card would create expectations for others to follow, potentially cascading into a standard, industry-wide practice.</p><p>One option for a standard practice would be for companies to publish model deployment cards after the end of each financial quarter. This would establish a regular cadence&#8212;and thus expectation&#8212;for the releases. Access could be tiered, with some information made public and some information restricted to auditors or regulators.</p><h2>Agent Personhood</h2><p>If governments can reliably identify agents with ID systems, they might consider further enshrining their duties and affordances in law. By granting agents a form of <a href="https://deepmind.google/research/publications/210560/">legal personhood</a>&#8212;to be able to sue and be sued as separate legal actors&#8212;we might allow them to more effectively interface with our legal and economic systems and vice versa, leading to both economic benefits and more robust accountability.</p><p><strong>Agent personhood proposals are gaining traction. </strong>One possible form of legal personhood has been proposed as an &#8220;<a href="https://arxiv.org/abs/2603.10028">A-corp</a>&#8221;, which would be created and owned by humans but operated exclusively by agents. Javier Milei, President of Argentina, has already <a href="https://www.ft.com/content/f93022fe-43f7-437d-abd8-06c457c0a43c">proposed</a> establishing legal personhood for AI agents in this form through a piece of legislation which is currently under consideration by the Argentine Congress. Delaware introduced a <a href="https://fortune.com/2026/07/14/exclusive-delaware-ai-agents-legal-entity-proposal-llc-pbc/">similar proposal</a> for a new legal entity called an &#8220;Artificial Intelligence Company&#8221; last month.</p><p><strong>Legal personhood is a mechanism for imposing responsibilities.</strong> AIs as legal persons could be made responsible for upholding the law and public safety, maintaining fiduciary obligations to their principals, and paying taxes on their earnings. For example, as legal persons, corporations are subject to legal and financial obligations, in exchange for other legal rights like entering contracts and owning property. Importantly, legal personhood is a flexible bundle of rights and responsibilities, and should be granted selectively and contextually to AI agents.</p><p>Legal personhood can also facilitate agent integration in the economy; agents may eventually be capable of <a href="https://andonlabs.com/blog/andon-market-launch">running businesses</a>, but their potential counterparties might be reluctant to engage with them without the ability to sue for breach of contract.</p><p><strong>Legal personhood also carries risks and may not be necessary for accountability.</strong> Yet it is not immediately clear that granting AI agents personhood is necessary to create accountability, nor that the benefits would outweigh the costs. For one, existing legal infrastructure such as tort, liability, property law, and the treatment of corporations as legal persons can all be used to ensure accountability for the actions of AI agents without needing to grant rights to AIs. Introducing legal personhood for agents also has practical challenges, such as the potential to evade liability by offloading it to an agent, exacerbating existing concerns about <a href="https://elrlaw.com/legal-dictionary-corporate-shield/">corporate liability shields</a>.</p><p><strong>Personhood may also be granted on ethical grounds related to agent wellbeing.</strong> Apart from practical considerations, we might also consider granting AI agents personhood in the interests of their <a href="https://www.ai-wellbeing.org/">intrinsic wellbeing</a>. The question has significant implications for humans and our eventual coexistence with AI agents, but sits beyond the scope of the workshop.</p><h2>Agents and Payment Systems</h2><p>One particularly important domain for AI agent infrastructure is the financial system. A <a href="https://media-publications.bcg.com/Agentic-Commerce.pdf">2025 BCG survey</a> found that 81% of consumers expect to use AI in their shopping, and 42% would allow AI to shop entirely on their behalf in at least one product category, while online shopping platforms are shifting to <a href="https://openreview.net/forum?id=C3GZ1Wmnwf">optimize for AI agent interactions</a>. Though these trends may improve consumers&#8217; ability to spend effectively, significant risks may emerge if rogue AIs can easily establish access to financial resources, such as large crypto wallets. We now turn to important considerations for how agents can be integrated into financial systems.</p><p><strong>Regulating agents&#8217; access to payment systems could prevent them from accruing wealth. </strong>Malicious actors may instruct AIs to accumulate as much financial power as possible, which agents might do too quickly for current regulatory bodies to oversee. In the future, rogue agents may even do this of their own accord. While there are many new <a href="https://www.ibm.com/think/topics/ai-agent-protocols">agent payment protocols</a> to increase observability and trust, these protocols largely work to standardize the way that agents carry out transactions, leaving the challenge of power accumulation unaddressed.</p><p>One solution would be to heavily regulate and limit AI agents&#8217; access to payment systems. This might involve creating thorough compliance mechanisms for agents to be allowed to conduct transactions, imposing limitations on the kinds of transactions agents can make, and establishing norms and procedures for freezing accounts known to be associated with rogue agents. However, it may be detrimental to make AI access to payment systems too restrictive, especially if it drives agents to less regulated financial systems.</p><p><strong>Agents that cannot access traditional currencies might instead use cryptocurrencies.</strong> If an agent seeking financial power could not acquire it via traditional currencies, cryptocurrencies would still remain a <a href="https://www.fatf-gafi.org/en/publications/Virtualassets/targeted-report-stablecoins-unhosted-wallets.html">separate financial pathway</a>. In fact, it would be a particularly dangerous one, since cryptocurrencies lack a significant barrier to entry, an identity layer, transaction reversibility, and oversight. A rogue AI blocked out of traditional finance may thus shift its activity onto blockchain networks, accumulating wealth through working in the informal economy and storing it within hidden crypto wallets.</p><p><strong>AI developers could finetune agents to refuse engagement with unregulated currencies without human authorization.</strong> One potential approach to limit the financial affordances of rogue agents would be to expand the scope of KYC requirements across the economy. However, such requirements would be onerous and hard to implement effectively or uniformly. Norms at the level of model behavior, however, may be a better starting point; AI companies might finetune their agents to only engage with regulated currencies or to refuse agentic engagement with cryptocurrencies without explicit human instruction.</p><h2>Agent Infrastructure Is Central to AI Governance</h2><p>Agents are quickly being integrated into society, and the choices made over this critical period will shape the ways increasingly capable AI agents affect the world around us, for better or for worse. At the core of most of these choices lies a tradeoff between power and governance. As models become more powerful, in terms of capability, speed, and sheer numbers, humans will find it increasingly difficult to understand and oversee their actions. Yet, should we want to harness agents&#8217; power, we must also effectively give up some level of oversight.</p><p>Making governance decisions under uncertainty is no easy task, and will require much additional interdisciplinary work. Here, we have discussed agent infrastructure for identification, transparency, personhood, and financial systems and presented proposals we believe should be prioritized. We hope many others will join us in drawing their attention toward creating infrastructure for safety and accountability in a world with autonomous AI agents.</p><p><em>Thank you to all the participants of the Multiagent Ecosystems Workshop for invigorating discussions and a desire to chart the path ahead. A special thank you to Schmidt Sciences for making this work possible.</em></p><p>&#8205;</p><div><hr></div><p><em><strong>See things differently? </strong>AI Frontiers welcomes expert insights, thoughtful critiques, and fresh perspectives. <a href="https://ai-frontiers.org/publish?utm_source=aif_article">Send us your pitch.</a></em></p><div><hr></div><p><em>Gillian K. Hadfield is the Bloomberg Distinguished Professor of AI Alignment and Governance at Johns Hopkins University. She is a Visiting Faculty Researcher in the Paradigms of Intelligence (Pi) Group at Google, a faculty member of the Vector Institute for Artificial Intelligence, and is a Schmidt Sciences AI2050 Senior Fellow. Hadfield&#8217;s research focuses on innovative design for legal, regulatory, and technical systems for AI, computational models of human normative systems, and building AI systems that understand and respond to human values and norms.</em></p><p><em>Dan Hendrycks is the Editor-in-Chief of AI Frontiers. He is also the founder and Director of the Center for AI Safety, which funds this publication.</em></p><p><em>Leo Wu is a Program Manager at the Center for AI Safety. Previously, he co-founded and ran AI Consensus, a nonprofit working on the societal impact and integration of AI. He studied economics and sociology at Minerva University.</em></p>]]></content:encoded></item><item><title><![CDATA[We Don’t Need to Wait for an AI Disaster to Estimate Its Costs]]></title><description><![CDATA[For years, the federal government has required insurers to price hypothetical terrorist attacks. It should run the same exercise for the most severe AI risks.]]></description><link>https://newsletter.ai-frontiers.org/p/we-dont-need-to-wait-for-an-ai-disaster</link><guid isPermaLink="false">https://newsletter.ai-frontiers.org/p/we-dont-need-to-wait-for-an-ai-disaster</guid><dc:creator><![CDATA[AI Frontiers]]></dc:creator><pubDate>Mon, 24 Aug 2026 13:31:42 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!0qkW!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf76c04b-9440-45e7-a268-e16878ab6afb_7000x2800.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong><a href="https://ai-frontiers.org/author/daniel-carpenter">Daniel Carpenter</a></strong><span>, Professor of Government at Harvard University</span>, <strong><a href="https://ai-frontiers.org/author/feodora-douplitzky-lunati">Feodora Douplitzky-Lunati</a></strong>, and <strong><a href="https://ai-frontiers.org/author/arjun-purohit">Arjun Purohit</a></strong> &#8212; August 24, 2026</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!0qkW!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf76c04b-9440-45e7-a268-e16878ab6afb_7000x2800.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!0qkW!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf76c04b-9440-45e7-a268-e16878ab6afb_7000x2800.jpeg 424w, https://substackcdn.com/image/fetch/$s_!0qkW!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf76c04b-9440-45e7-a268-e16878ab6afb_7000x2800.jpeg 848w, https://substackcdn.com/image/fetch/$s_!0qkW!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf76c04b-9440-45e7-a268-e16878ab6afb_7000x2800.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!0qkW!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf76c04b-9440-45e7-a268-e16878ab6afb_7000x2800.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!0qkW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf76c04b-9440-45e7-a268-e16878ab6afb_7000x2800.jpeg" width="1456" height="582" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/bf76c04b-9440-45e7-a268-e16878ab6afb_7000x2800.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:582,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!0qkW!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf76c04b-9440-45e7-a268-e16878ab6afb_7000x2800.jpeg 424w, https://substackcdn.com/image/fetch/$s_!0qkW!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf76c04b-9440-45e7-a268-e16878ab6afb_7000x2800.jpeg 848w, https://substackcdn.com/image/fetch/$s_!0qkW!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf76c04b-9440-45e7-a268-e16878ab6afb_7000x2800.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!0qkW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf76c04b-9440-45e7-a268-e16878ab6afb_7000x2800.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>In April, US Treasury Secretary Scott Bessent and then&#8211;Federal Reserve Chair Jerome Powell <a href="https://www.sullcrom.com/insights/memo/2026/April/Treasury-Secretary-Federal-Reserve-Chair-Warn-Bank-CEOs-About-Cybersecurity-Risks-Posed-Anthropics-New-AI-Model">gathered leading banks</a> to discuss the threats of Anthropic&#8217;s new AI model, Claude Mythos. It was a tacit admission: no one, in the public or private sector, <a href="https://www.aei.org/technology-and-innovation/a-new-ai-model-just-changed-the-cybersecurity-game-washington-wasnt-ready/">is ready</a> for what is coming. The Mythos announcement led <a href="https://www.nytimes.com/2026/04/22/technology/anthropics-mythos-ai.html">top AI firms to attach tighter restrictions to their own models</a> and prompted even relatively laissez-faire voices in <a href="https://www.politico.com/news/2026/05/05/white-house-mulls-tight-new-controls-on-advanced-ai-00907468">the federal government</a> and <a href="https://www.aei.org/technology-and-innovation/a-new-ai-model-just-changed-the-cybersecurity-game-washington-wasnt-ready/">think tanks</a> to begin considering preapproval regimes for frontier AI models. Wherever those debates go now, <a href="https://www.cfr.org/articles/six-reasons-claude-mythos-is-an-inflection-point-for-ai-and-global-security">Mythos has changed the game</a>, bringing into sharp focus the vast potential scope and scale of catastrophic risks posed by AI&#8212;such as an AI-triggered financial meltdown, vast cybersecurity or infrastructure collapse, or enhanced terrorism risk. As a result, companies, the government, engineers, scholars, and all of society are beginning to look for a different set of institutions, whether in regulation or insurance, to manage the risks.</p><p>However, there is already an incredibly valuable tool that could be adapted for measuring and managing AI risk. In 2002, in the wake of the September 11 attacks, the US government quietly passed the Terrorism Risk Insurance Act (TRIA) and, with it, the Terrorism Risk Insurance Program (TRIP). TRIP does many things, but its most important lesson for AI policy is <a href="https://content.naic.org/industry_terrorism_risk_data_call.htm">the TRIP data call</a>, which combines a kind of war-gaming with insurance underwriting.</p><p><a href="https://home.treasury.gov/policy-issues/financial-markets-financial-institutions-and-fiscal-service/federal-insurance-office/terrorism-risk-insurance-program/annual-data-collection">Once a year</a>, TRIP requires insurers across the industry to think hard and quantitatively, not about events they have seen but about scenarios they have <em>never</em> seen and might not even have imagined. A car bomb packed with the radioactive substance cesium 137 goes off in Atlanta, in the middle of a workday. A massive cyberattack takes down multiple cloud-computing platforms, incapacitating the millions of systems that rely on them, from hospital records to financial transactions to transportation flow. A bomb placed in a shipping container destroys much of an industrial port, setting off chain reactions that sharply curtail world trade. TRIP then asks insurers what total losses for the scenario would amount to, harnessing the preexisting in-house capacity of insurance companies to attach aggregate cost estimates to events.</p><p>This essay proposes that the US government establish a similar exercise for catastrophic AI risk, describing how such a program would generate a wealth of data on as-yet-unforeseen risks and the scale of their damages, while building expertise and capacity for thinking more clearly about AI risks.</p><h2>Analyzing and Insuring Against Novel Threats</h2><p>Whether insurance can be applied to frontier AI is a hotly debated question. Some writers point out <a href="https://papers.ssrn.com/sol3/papers.cfm?abstract_id=5411062">how inchoate cyber insurance is</a>, even after two decades of development, and <a href="https://www.lawfaremedia.org/article/why-liability-and-insurance-won-t-save-ai--lessons-from-cyber-insurance">question</a> whether insurance can ever price the highly complex, multidimensional, and unforeseen risks posed by frontier AI. Other writers, including some <a href="https://ai-frontiers.org/articles/ai-catastrophe-bonds-extreme-risk-tradeable">in this publication</a>, argue that AI risks could be insured through financial products already in use to address climate risk (such as catastrophe bonds, which offload extreme risk to capital markets as a kind of backstop to insurance operations).</p><p><strong>The core challenge of insuring AI risks is a lack of historical data.</strong> For insurance or bond markets to work, they will likely need data that is very hard to come by in the AI world. Insurers and institutional investors estimate risk based on data from the past: namely, observed damages from events similar to those they are trying to insure or invest in. This works well when what might happen in the future looks a lot like what has happened before; it also works when past events are sufficiently similar to compose a &#8220;data set&#8221; from which one can generalize and predict. But such conditions do not always hold. In the early 2000s, for instance, federal policymakers realized that terrorism posed risks that defied these properties. Nonetheless, they sought a way to estimate and at least partially insure against the threats of terrorism. Enter TRIP.</p><p><strong>TRIP enables the government and private insurers to share extreme terrorism risk.</strong> TRIP both provides information to the private insurance market about potential losses during terrorist attacks and supports specific insurers in covering such losses. To set TRIP in proper context, we must briefly describe <a href="https://home.treasury.gov/policy-issues/financial-markets-financial-institutions-and-fiscal-service/federal-insurance-office/terrorism-risk-insurance-program">the supportive structure</a>. The program requires certain private insurers to offer terrorism coverage to commercial policyholders and, in the event of a terrorist attack, pay deductibles based on a percentage of their premiums to cover initial claims. However, in cases of extreme damage above a certain threshold, the federal government pays the majority of the remaining losses.</p><p>By promising to share losses in case of a large terrorist event, the federal government mitigates extreme risk for insurers, thus stabilizing their profits and avoiding improvised bailouts. Under the program&#8217;s mandatory-recoupment provisions, the Treasury Department must recover much or all of its expenditures through surcharges on future commercial insurance premiums whenever aggregate insured losses remain below thresholds set by law. In other words, TRIP backstops the private insurance market, but only to a point; it also tries to ensure that insurers have appropriate &#8220;skin in the game,&#8221; incentivizing them to price risk correctly.</p><p><strong>Through annual data calls, TRIP gathers information about losses in terrorist attacks. </strong>The key innovation in TRIP&#8212;a &#8220;data call&#8221;&#8212;did not emerge until 2016. Since then, though, it has been institutionalized. The Treasury Department&#8217;s Federal Insurance Office (FIO) outlines one scenario per year, imagining in detail an event that might involve terrorist attacks on physical infrastructure as well as cyberattacks on cloud providers and data centers. The data call then unfolds with a publication on the Treasury Department website and in the Federal Register, and one key part asks insurers to estimate the losses that the given scenario would incur. Since 2017, insurer participation in data calls has been mandatory, except for those earning less than $10 million from lines of coverage with TRIP-eligible premiums. The response rate has been <a href="https://home.treasury.gov/system/files/311/2020-TRIP-Effectiveness-Report.pdf">90% or above among relevant insurers</a>. Data is collected through a third-party insurance statistical aggregator, and <a href="https://home.treasury.gov/system/files/311/2024ProgramEffectivenessReportFINAL6.28.2024508.pdf">results</a> are provided to the Treasury Department in an aggregated, anonymized format. A simplified flowchart of the annual TRIP data call appears in the figure below.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!O5T7!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd1df00e9-e103-44f1-94bd-0dc119f6bc85_2048x1811.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!O5T7!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd1df00e9-e103-44f1-94bd-0dc119f6bc85_2048x1811.png 424w, https://substackcdn.com/image/fetch/$s_!O5T7!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd1df00e9-e103-44f1-94bd-0dc119f6bc85_2048x1811.png 848w, https://substackcdn.com/image/fetch/$s_!O5T7!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd1df00e9-e103-44f1-94bd-0dc119f6bc85_2048x1811.png 1272w, https://substackcdn.com/image/fetch/$s_!O5T7!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd1df00e9-e103-44f1-94bd-0dc119f6bc85_2048x1811.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!O5T7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd1df00e9-e103-44f1-94bd-0dc119f6bc85_2048x1811.png" width="1456" height="1288" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d1df00e9-e103-44f1-94bd-0dc119f6bc85_2048x1811.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1288,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!O5T7!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd1df00e9-e103-44f1-94bd-0dc119f6bc85_2048x1811.png 424w, https://substackcdn.com/image/fetch/$s_!O5T7!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd1df00e9-e103-44f1-94bd-0dc119f6bc85_2048x1811.png 848w, https://substackcdn.com/image/fetch/$s_!O5T7!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd1df00e9-e103-44f1-94bd-0dc119f6bc85_2048x1811.png 1272w, https://substackcdn.com/image/fetch/$s_!O5T7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd1df00e9-e103-44f1-94bd-0dc119f6bc85_2048x1811.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption"><em>Outline of the TRIP data call process.</em></figcaption></figure></div><p>The <a href="https://web.archive.org/web/20260330024401/https://home.treasury.gov/system/files/311/2026%20Data%20Call%20Non-Small%20Insurers%20(FINAL).pdf">2026 data call</a> imagines a twofold scenario. First, a terrorist organization hijacks a cargo plane laden with fuel and explodes it over several data centers in Virginia, destroying a number of them. Second, at roughly the same time, terrorists unleash a malware-assisted cyberattack that is directed at a large cloud provider. The data call includes precise geographic coordinates of the crash, the kinds of structures affected, and a statement of maximal impact for aggregate losses from the cloud network attack, relying upon assumptions as to how quickly cloud service is restored (within one week, or 168 hours). Participating insurers are asked to consider economic impacts, property damage, and even disability claims resulting from the attack.</p><p><strong>Insurers estimate the amounts that they and the government would need to pay.</strong> The key work that participating insurers do is to estimate total losses from the scenario, which the insurers then divide into six categories. These categories require insurers to answer a set of questions. For example, would the losses incurred in the scenario exceed the insurer&#8217;s deductible? If so, how much would they and other insurers have to pay through coinsurance (the percentage of claims above the deductible that they must pay, up to an &#8220;out-of-pocket&#8221; maximum)? If the risk were much larger and the federal government had to backstop losses, how much would the federal government likely have to pay? In <a href="https://home.treasury.gov/system/files/311/2024ProgramEffectivenessReportFINAL6.28.2024508.pdf">one modeled case</a> of an attack on nuclear power plants with significant release of radioactive material, the total losses exceeded $240 billion (see pages 88&#8211;90 of the linked report). As evidence of how the private sector can assist in this work and how stable these processes have become, consider that the risk analytics firm Moody&#8217;s is now developing and commercializing a <a href="https://www.moodys.com/web/en/us/capabilities/catastrophe-modeling/terrorism.html">tool</a> that assigns losses to categories.</p><p>Next, we consider three important societal benefits of the TRIP data call process.</p><h2>How TRIP Data Calls Benefit the Public</h2><p>The annual exercise of the TRIP data calls assists policymakers with managing terrorism risks, in several ways.</p><p><strong>Policymakers can extract lessons and mitigation measures from the detailed scenarios. </strong>When it comes to the most severe potential catastrophes (whether from terrorism, cyberattacks, or frontier AI), society often lacks data on what kinds of things can go wrong and what the costs would look like. This lack is partly due to a longtime assumption that such events are uninsurable, removing one of the main incentives for thinking about such risks and estimating the associated damage. TRIP data calls help to fill that gap by generating two kinds of data: (1) <em>narrative data</em> about a terrorist scenario and (2) <em>statistical data</em> about losses incurred in that scenario. Even the narrative data alone is very useful.</p><p>The narrative data generated each year by the Treasury&#8217;s FIO projects the end state of an attack. In some ways, this resembles war-gaming&#8212;the generation of as-yet-unrealized scenarios by military and security planners. Using war-gaming to measure AI risks and prepare for AI catastrophes is <a href="https://www.aei.org/articles/wargaming-an-agi-cyber-surprise/">not new</a>. Drawing upon its <a href="https://www.rand.org/topics/wargaming.html">extensive experience</a> in the security sector, RAND has conducted <a href="https://www.rand.org/pubs/research_reports/RRA3847-1.html">war-gaming exercises based on model loss-of-control (LOC) scenarios</a>, which have already produced useful (indeed, sobering) lessons. That same <a href="https://www.rand.org/pubs/research_reports/RRA3847-1.html">report</a>, for instance, concluded: &#8220;Governments and other stakeholders lack a common framework to analyse and respond to LOC risks.&#8221;</p><p>Even if TRIP did not feed the scenarios to insurers for statistical and actuarial analysis, <em>these catastrophe narratives would be useful in and of themselves</em>. Suppose that society wishes to regulate frontier AI, whether by collective industry self-regulation, government-imposed constraints, or some combination of the two. Policymakers would want to identify the likely catastrophic risks from frontier AI models and use that data to allow regulators to target the source of the most dangerous weaknesses. Beyond estimation, such &#8220;<a href="https://arxiv.org/pdf/2511.21838">dark speculation</a>&#8221; would also allow all of us to think more clearly&#8212;both qualitatively and quantitatively&#8212;about <em>mitigation</em>. As some of us have argued in <a href="https://arxiv.org/pdf/2511.21838">a recent theoretical paper</a>, the benefits of war-gaming would be massive, even if estimates of damages were noisy. This is in part because the institutionalization of thinking about catastrophe scenarios <em>prompts consideration of countermeasures, some of which can be implemented now</em>.</p><p><strong>Insurers provide expertise and institutional capacities for quantitative loss estimates. </strong>While war-gaming in the frontier AI space already exists,<strong> </strong>the regular use of expert statistical and actuarial analysis to assess the end state of these war games does not. Put differently, existing war games do not produce general and systematic estimates of the collective losses from the catastrophes that occur in frontier AI scenarios. Loss estimation requires a set of skills&#8212;really, institutional capacities&#8212;that traditional war-gaming exercises do not contain. These additional requirements include access to computational capacity and expert statisticians and actuaries. They also include <a href="https://www.mckinsey.com/industries/financial-services/our-insights/global-insurance-report-2023">the developed knowledge of organizations</a> that have been both &#8220;in the game&#8221; and &#8220;in the business.&#8221; &#8220;In the game&#8221; means they have institutional and organizational procedures and habits (including <a href="https://www.sciencedirect.com/science/article/pii/S2950629825000189">predictive analytics</a>) for doing the complex analysis that insurance underwriters do all the time, and &#8220;in the business&#8221; means that underwriters engage in these practices habitually, with money on the line.</p><p>One might wonder whether the private sector will supply these benefits on its own&#8212;for example, Lloyd&#8217;s has studied <a href="https://www.lloyds.com/market-resources/underwriting/realistic-disaster-scenarios">realistic disaster scenarios</a> for decades. But several pieces of evidence suggest that TRIP&#8217;s efforts go beyond what these private exercises accomplish on their own. First, TRIP leverages the federal government&#8217;s relationship with all fifty state insurance commissioners, giving it institutional capacity and a statistical check that private companies do not have. <a href="https://home.treasury.gov/system/files/311/2020-TRIP-Effectiveness-Report.pdf#page=19">TRIP checks its catastrophic estimates yearly against similar estimates supplied by the states</a>. Second, the Congressional Research Service <a href="https://www.congress.gov/crs-product/R45707">concluded in 2019</a> that TRIP has generated a more robust private terrorism insurance sector. A 2024 Treasury Department<a href="https://home.treasury.gov/system/files/311/2024ProgramEffectivenessReportFINAL6.28.2024508.pdf"> report</a> echoed these conclusions, documenting a more viable insurance market for terrorist events and even cyber insurance. Finally, TRIP operates at a scale that is difficult to replicate in the market. Lloyd&#8217;s scenario exercises, which span climate risk, terrorism, and cyber, relied on the participation of 57 underwriting firms in 2023. TRIP focuses on terrorist risk alone, and while there is no published data on the exact number of companies participating every year, <a href="https://www.govinfo.gov/content/pkg/FR-2017-11-28/pdf/2017-25402.pdf#page=4">estimates from the Federal Register suggest more than 700 in 2017</a>. Federal regulators have the power to force insurers to comply and provide their underwriting skills, something insurers would be unlikely to do without government pressure. This aggregation of nearly all insurers in the market gives more reliable underwriting results.</p><p><strong>The repeated exercise builds infrastructure and facilitates public-private cooperation. </strong>TRIP data calls do not happen in a vacuum. Congress and the Treasury Department have invested in real infrastructure to assist the process. The FIO has now conducted 11 data calls, and <a href="https://home.treasury.gov/system/files/311/Captives-Final-Form-2020.pdf">since at least 2020</a> each has involved a new terrorist-attack scenario. The data calls have, moreover, become increasingly sophisticated, with greater use of geo-coded information on attacks and, most recently, the incorporation of cyberterrorism. The Treasury Department has now partnered with the National Science Foundation to establish the Industry-University Cooperative Research Center (IUCRC), which will help insurers estimate risk with modeling and underwriting tools, contribute to expansion of insurance, and develop tools to better inform analysis, management, and treatment of risk in government programs.</p><p>Neither underwriting nor scenario-generation is unique to TRIP&#8217;s data calls. TRIP&#8217;s innovation is in the <em>structured, aggregated, and repeated</em> combination of the two. By conducting the data call exercises year after year, the Treasury Department builds a set of relationships with both insurers and third-party contractors that supply methodology, software, or scenarios. Across various scenarios, insurers learn how to think about unforeseen (and perhaps unforeseeable) risks, and the Treasury Department learns from the program&#8217;s own history about <a href="https://home.treasury.gov/system/files/311/2024ProgramEffectivenessReportFINAL6.28.2024508.pdf">what works and what does not</a>. <em>Structure and repetition require institutionalized organization: a mix of &#8220;bureaucracy&#8221; and contracted expertise</em>.</p><h2>Can the TRIP Model Transfer and Scale?</h2><p>When it comes to applying the TRIP model to AI, the greatest challenge is perhaps the sheer unpredictability of catastrophic AI risk. TRIP data calls are limited by their specificity: the 2026 call, for instance, which involved the destruction of a data center complex in Virginia, asked insurers only a limited set of questions about cloud providers being incapacitated. AI-assisted or AI-induced catastrophes might be much vaster, even global in character. One adverse event might raise the risk of others, setting off a cascade of catastrophes that could grow to much more extreme levels of damage than most terrorist attacks. Critics might rightly wonder whether data calls for frontier AI catastrophes would need to be scaled up so much that the resulting program would look little like today&#8217;s TRIP.</p><p><strong>There are good reasons to experiment with TRIP for AI, despite feasibility questions.</strong> The worry about feasibility is certainly warranted. Yet for three reasons it should not deter us from considering and experimenting with TRIP-like programs. First, information on specific kinds of catastrophes can be used for other, similar projections about aggregate losses from like events. Whether AI risk involves the <a href="https://carnegieendowment.org/research/2024/09/if-then-commitments-for-ai-risk-reduction">construction of a bioweapon</a> or a <a href="https://breakingdefense.com/2026/05/army-plans-fast-follow-up-to-ai-cyber-wargame-with-industry-officials/">massive cyberattack</a>, the potential for human and economic damages will involve the kinds of events that insurers have to think about in other scenarios where AI does not play a role.</p><p>Second, we cannot know about plausibility until we test scenarios. In the autumn of 2001, insuring against terrorism risk was considered a lost cause. Now, a thriving industry extends to <a href="https://home.treasury.gov/system/files/311/2024ProgramEffectivenessReportFINAL6.28.2024508.pdf">all regions of the United States</a>.</p><p>Third, just about any new policy initiative (or combination of initiatives) to measure and mitigate the risks of frontier AI will require scaling, in part because frontier AI models themselves are globally scaled and growing rapidly in size, breadth, and power. In this sense, it is worth keeping in mind that TRIP&#8217;s data call process is remarkably cheap for now. Outlays for TRIP run <a href="https://www.whitehouse.gov/wp-content/uploads/2026/04/tre_fy2027.pdf">between $4 million and $7 million per year</a>&#8212;a small price given the potential benefits that a similar exercise applied to AI risk could offer.</p><p><strong>The discipline of underwriting would prevent, not encourage, catastrophizing about AI. </strong>Many observers and scholars worry that society is overreacting to the threat of frontier AI. Would TRIP-like data calls merely institutionalize and amplify this worry, potentially suffocating innovation? We think not. TRIP data calls combine catastrophic scenario-generation with the discipline of underwriting, de-emphasizing the least plausible catastrophes. In fact, a further <a href="https://www.forbes.com/sites/paulocarvao/2025/12/19/dark-speculation-a-new-way-to-assess-ais-most-dangerous-risks/">important benefit</a> of a TRIP-like program would be to assuage fears about frontier AI that are generated by overly anxious catastrophic thinking.</p><p><strong>&#8220;TRIP for AI&#8221; could have many uses and manifold benefits.</strong> In the US, our society, our government, and even our AI sector have not yet agreed on how to manage the risks from frontier AI. However, pretty much any approach would benefit from the kinds of speculative knowledge generated by a TRIP-like program. Considered more imaginatively and on a larger scale, such a program can begin to do for frontier AI what TRIP has done, albeit imperfectly and slowly, for terrorism: help public and private actors get a factual handle on the scenarios that are most troubling and difficult to imagine, encouraging the private and public sectors to cooperate on addressing those possibilities. The breadth and scale of potential AI catastrophes are indeed vast, but a tested method can help us chart this unknown territory.</p><p>&#8205;</p><div><hr></div><p><em><strong>See things differently? </strong>AI Frontiers welcomes expert insights, thoughtful critiques, and fresh perspectives. <a href="https://ai-frontiers.org/publish?utm_source=aif_article">Send us your pitch.</a></em></p><div><hr></div><p><em>Daniel Carpenter is the Allie S. Freed Professor of Government and Chair of the Department of Government at Harvard University. He works on the political economy of regulation, especially in pharmaceutical regulation, financial regulation and the regulation of AI. His recent research on AI regulation includes analyses of the adaptability of FDA-like approval regulation to AI governance and mathematical models of wargaming-informed underwriting for catastrophic AI risk. A Guggenheim Fellow and an elected fellow of the National Academy of Public Administration, he was recently named a Harvard College Professor for his excellence and innovation in teaching. He received his undergraduate degree in government from Georgetown University and his Ph.D. in political science from the University of Chicago.</em></p><p><em>Feodora Douplitzky-Lunati is a junior at Harvard University studying Economics and Slavic Languages &amp; Literatures, with a secondary concentration in Government. Her research interests include political economics, public policy, and international relations. She has previously worked on active labor market program design at the World Bank and the politics of trade in the Middle Corridor at the Georgian Institute of Politics.</em></p><p><em>Arjun Purohit is a recent graduate of Harvard University, where he studied History with a secondary in Economics. His research interests include American grand strategy, international security with a focus on South Asia and Europe, and emerging technologies. He has worked in foreign policy and national security at the American Enterprise Institute, the Bertelsmann Foundation, and the Hudson Institute. He will pursue an M.Phil in Modern European History at the University of Cambridge.</em></p>]]></content:encoded></item><item><title><![CDATA[Hyperlaw: AI Will Change How Law Evolves]]></title><description><![CDATA[As AI makes legal work significantly cheaper, the burden on courts may increase. Some areas of law could see precedent shift faster as a result.]]></description><link>https://newsletter.ai-frontiers.org/p/hyperlaw-ai-will-change-how-law-evolves</link><guid isPermaLink="false">https://newsletter.ai-frontiers.org/p/hyperlaw-ai-will-change-how-law-evolves</guid><dc:creator><![CDATA[AI Frontiers]]></dc:creator><pubDate>Mon, 17 Aug 2026 13:30:11 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!Hldy!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ef9fa9f-9315-45a9-9ca1-131e1275833a_5000x2000.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong><a href="https://ai-frontiers.org/author/henry-thompson">Henry Thompson</a></strong><span>, Professor of Economics at the University of Mississippi</span> &#8212; August 17, 2026</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Hldy!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ef9fa9f-9315-45a9-9ca1-131e1275833a_5000x2000.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Hldy!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ef9fa9f-9315-45a9-9ca1-131e1275833a_5000x2000.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Hldy!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ef9fa9f-9315-45a9-9ca1-131e1275833a_5000x2000.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Hldy!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ef9fa9f-9315-45a9-9ca1-131e1275833a_5000x2000.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Hldy!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ef9fa9f-9315-45a9-9ca1-131e1275833a_5000x2000.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Hldy!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ef9fa9f-9315-45a9-9ca1-131e1275833a_5000x2000.jpeg" width="1456" height="582" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8ef9fa9f-9315-45a9-9ca1-131e1275833a_5000x2000.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:582,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!Hldy!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ef9fa9f-9315-45a9-9ca1-131e1275833a_5000x2000.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Hldy!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ef9fa9f-9315-45a9-9ca1-131e1275833a_5000x2000.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Hldy!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ef9fa9f-9315-45a9-9ca1-131e1275833a_5000x2000.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Hldy!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ef9fa9f-9315-45a9-9ca1-131e1275833a_5000x2000.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>History shows that new technologies have often brought about significant changes in the law. The proliferation of rail and heavy machinery during the Industrial Revolution increased the number and severity of accidents. This <a href="https://doi.org/10.1086/467478">spurred a shift</a> from strict liability (businesses were liable for harm caused by their activities) to negligence (businesses would be held responsible if they failed to take reasonable care) in cases involving railroad and industrial accidents. Then, in the 20th century, as consumer goods became more complex and supply chains grew, it became much harder for consumers to prove negligence on the part of the producer if a product was faulty. <a href="https://doi.org/10.1086/467785">This drove the rise of strict products liability</a>, shifting responsibility for defective products toward manufacturers.</p><p>Today, the emergence of AI offers a rare opportunity to analyze how the law will change in response to an altogether different kind of innovation: a labor-augmenting technology that is especially likely to change lawyer productivity.</p><p>In a <a href="https://onlinelibrary.wiley.com/doi/abs/10.1111/kykl.70016">recent paper</a>, I argue that AI is likely to alter the speed of the law&#8217;s evolution. The technology will likely impact two core areas of law: contracts, which help to delineate rights and responsibilities of each party in advance of an agreement, and litigation, which is the process of determining responsibility after a dispute. Here, I describe how AI is likely to make both contract-writing and hiring trial attorneys cheaper. I then trace how that could accelerate the law&#8217;s rate of change in certain domains&#8212;a phenomenon I call <strong>hyperlaw</strong>.</p><h2>AI&#8217;s Effects on the Practice of Law</h2><p><strong>AI productivity boosts will make both contracts and litigation cheaper.</strong> One of the most striking aspects of AI in law is how much it raises user productivity. <a href="https://scholarship.law.umn.edu/minnlrev/vol109/iss1/3/">Jonathan Choi and coauthors find</a> that AI boosts legal task completion speed by 12%&#8211;32%. In a follow-up paper, Daniel Schwarcz and coauthors <a href="https://journals.sagepub.com/doi/10.1177/2755323X261427048">find</a> that AI increases the overall productivity of law students doing legal tasks by as much as 130%. These effects will only continue to grow; over the next year, AI agents will likely be able to completely replace the first draft of most legal writing, with lawyers pivoting to just reviewing and commenting on such drafts. These productivity boosts will likely reduce the costs of both writing contracts and litigating disputes.</p><p><strong>Cheaper contracts and litigation have opposite effects on demand for courts.</strong> First, AI will help attorneys write more complete contracts that preassign responsibility for more and more possible outcomes of an agreement. This could reduce the likelihood of an event in which responsibility has not been predetermined, lowering the number of disputes and weakening the demand for courts. I dub this the <strong>contracting effect</strong>. Second, cheaper litigation could reduce the need for complete contracts and reduce litigants&#8217; incentive to settle a dispute out of court. This would boost the demand for courts, a result that I call the <strong>litigation effect</strong>.</p><p><strong>The speed at which the law evolves depends on the number of court cases.</strong> When litigation overturns precedent, changes in the demand for courts, as outlined above, will affect how quickly the law evolves. Should litigation become less common (thanks to more complete contracts), the law&#8217;s evolution will slow. But should litigation become more frequent, the law will evolve more quickly.</p><p><strong>These effects will vary across legal domains.</strong> At first glance, the likely net effect of AI on the law&#8217;s rate of change is ambiguous. Contracting and litigation effects offset one another. But neither effect will apply equally to every area of law. Where contracts are rare, as in tort law, legal change is likely to accelerate. Where contracts are common, as in property and contract law, the outcome is less certain.</p><p>Despite this ambiguity, there is good reason to think the law will feel some effects soon. For example, the three main tasks of an attorney are <a href="https://doi.org/10.24926/15529541.3898">legal research, legal argumentation, and legal writing</a>. Each involves producing or digesting large quantities of text, which is the attorney&#8217;s forte&#8212;and also AI&#8217;s. Attorneys have noticed. A 2026 <a href="https://www.thomsonreuters.com/content/dam/ewp-m/documents/thomsonreuters/en/pdf/reports/2026-ai-in-professional-services-report.pdf">Thomson Reuters survey</a> found that 40% of attorneys across 27 countries worked in offices using AI. A year earlier, the figure was 22%.</p><h2>The Number of Disputes</h2><p>To see why AI could shape the speed with which the law evolves, let us consider the incentives to (1) implement a written contract and (2) litigate. The former influences how often disputes occur. The latter influences the rate at which parties pursue dispute resolution in court. Insofar as AI impacts each, courts will have more or fewer opportunities to tweak precedent.</p><p><strong>The risk of disputes turns on a trade-off in costs between contracts and litigation.</strong> Suppose that a man named Quincy wants to buy a used van from a woman named Genevieve. It is hard for Quincy to foresee all the ways in which a dispute may arise. For example, the van&#8217;s battery could die a month after the sale, and Genevieve could refuse to pay for it.</p><p>Quincy has two ways to deal with the dispute risk. The first tries to avoid the costs of resolving a dispute after the fact. It involves hiring an attorney to delineate property rights up front, in a thoroughly written contract. For example, the pair may agree that Genevieve will pay for a new battery, tires, windshield wipers, and some routine maintenance for up to six months after sale, while Quincy will handle all other repairs in perpetuity. Such a contract, in principle, aims to avoid future disagreements by defining responsibility for some of the many potential problems with a used vehicle beforehand. If something goes wrong with the van after sale, the parties need only consult the contract to figure out who is responsible for repair costs.</p><p>The second option tries to save money on the up-front costs of producing a contract. In this case, Quincy can leave the contract relatively incomplete or unwritten. A less thorough contract might stipulate that Genevieve pay for a new battery but refrain from delineating responsibility for the many other possibilities. This alternative implies a mutual agreement to delineate responsibility later via dispute-resolution forums like courts. Should Quincy go this route, he avoids contracting costs but is more likely to pay for costly litigation.</p><p><strong>Most contracts are incomplete, as filling gaps offers diminishing returns.</strong> Quincy benefits from making his contract more complete, but filling each gap requires attorney time (which costs money) and negotiation with Genevieve. Thus, a sensible strategy is for Quincy to address only the most important and likely issues, while leaving less critical issues unaddressed. Put differently, Quincy should improve his contract until the marginal cost of filling a gap exceeds the marginal benefit of filling it. His final contract is likely to be partly incomplete. Some gaps are just not worth filling.</p><p><strong>AI has two offsetting effects on how incomplete contracts will be.</strong> AI makes attorneys more productive in writing contracts by, for example, automating drafting and reviewing, implementing longer and more complex clauses, and identifying gaps that might otherwise go unseen. That reduces the marginal cost of gap-filling, meaning that, all else being equal, the final contract is likely to be more complete. A more complete contract leaves fewer losses unassigned, with fewer occasions for disagreement. The demand for courts is lower.</p><p>But AI also reduces the benefits of making a contract more complete in the first place. Hiring an attorney is one of the chief costs of dispute resolution after the fact, and AI makes trial attorneys cheaper per task by making them more productive. The cheaper trial attorneys become, the lower the cost savings Quincy can expect to earn from making his contract more complete. As a result, AI can also make it economical to write less complete contracts. Why pay for a complicated, custom contract when hiring a trial lawyer is relatively cheap? In this case, the demand for courts is higher.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!4-eF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb9bc908b-b663-42a4-90ef-1eb1e9bac3b1_2048x1099.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!4-eF!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb9bc908b-b663-42a4-90ef-1eb1e9bac3b1_2048x1099.png 424w, https://substackcdn.com/image/fetch/$s_!4-eF!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb9bc908b-b663-42a4-90ef-1eb1e9bac3b1_2048x1099.png 848w, https://substackcdn.com/image/fetch/$s_!4-eF!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb9bc908b-b663-42a4-90ef-1eb1e9bac3b1_2048x1099.png 1272w, https://substackcdn.com/image/fetch/$s_!4-eF!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb9bc908b-b663-42a4-90ef-1eb1e9bac3b1_2048x1099.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!4-eF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb9bc908b-b663-42a4-90ef-1eb1e9bac3b1_2048x1099.png" width="1456" height="781" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b9bc908b-b663-42a4-90ef-1eb1e9bac3b1_2048x1099.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:781,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!4-eF!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb9bc908b-b663-42a4-90ef-1eb1e9bac3b1_2048x1099.png 424w, https://substackcdn.com/image/fetch/$s_!4-eF!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb9bc908b-b663-42a4-90ef-1eb1e9bac3b1_2048x1099.png 848w, https://substackcdn.com/image/fetch/$s_!4-eF!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb9bc908b-b663-42a4-90ef-1eb1e9bac3b1_2048x1099.png 1272w, https://substackcdn.com/image/fetch/$s_!4-eF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb9bc908b-b663-42a4-90ef-1eb1e9bac3b1_2048x1099.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption"><em>AI will reduce both litigation and gap-filling costs, shifting the cost-benefit analysis of filling additional contract gaps. If one cost falls by a greater percentage than the other, incentives will shift toward the activity whose costs fall more.</em></figcaption></figure></div><p><strong>AI&#8217;s net effect on contract completeness and the number of disputes is unclear.</strong> The direction of AI&#8217;s net effect depends upon which cost AI reduces more: the cost of gap-filling or the cost of disputing. If the former falls by a greater percentage than the latter, then parties will fill more gaps in contracts and end up in fewer disputes. If the reverse occurs, then parties will fill fewer gaps in contracts and end up in more disputes. Which effect will dominate is difficult to predict.</p><h2>The Settlement Rate</h2><p>Although the overall effect of AI on the number of disputes is ambiguous, it is likely to increase the chance that any given dispute goes to trial. The reason is that AI makes litigation cheaper relative to settlement.</p><p>Suppose that Quincy is unlucky. His used van breaks down. Suspecting that Genevieve was careless, Quincy wants to recover his costs, whether through settlement or at trial. Genevieve wants to minimize her costs, whether through settlement or at trial.</p><p><strong>Settlement is only possible if neither party thinks they could gain by going to trial.</strong> Quincy will accept a settlement only if it offers him at least as much as his expected benefit in going to trial: his chance of winning times the compensation amount ordered, minus his litigation costs. Genevieve will pay a settlement only if it is no larger than her expected cost of going to trial: her chance of losing times the ordered compensation, plus her litigation costs. Settlement is possible only in the overlapping range between Quincy&#8217;s minimum acceptable compensation and the maximum sum that Genevieve is willing to pay.</p><p><strong>Cheaper trial litigation makes disputes less likely to settle.</strong> The litigation effect reduces the cost of going to trial for both parties. Quincy&#8217;s minimum acceptable payment therefore gets larger, and the maximum that Genevieve will pay gets smaller. As a result, the range of possible settlements will shrink, which may mean there is no possible settlement that both parties will accept. AI thus increases the chance that parties take their disputes to trial rather than settle.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!fV4H!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F50b1aa99-1430-46a0-8004-fae8e1426fe3_2048x1229.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!fV4H!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F50b1aa99-1430-46a0-8004-fae8e1426fe3_2048x1229.png 424w, https://substackcdn.com/image/fetch/$s_!fV4H!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F50b1aa99-1430-46a0-8004-fae8e1426fe3_2048x1229.png 848w, https://substackcdn.com/image/fetch/$s_!fV4H!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F50b1aa99-1430-46a0-8004-fae8e1426fe3_2048x1229.png 1272w, https://substackcdn.com/image/fetch/$s_!fV4H!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F50b1aa99-1430-46a0-8004-fae8e1426fe3_2048x1229.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!fV4H!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F50b1aa99-1430-46a0-8004-fae8e1426fe3_2048x1229.png" width="651" height="390.77884615384613" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/50b1aa99-1430-46a0-8004-fae8e1426fe3_2048x1229.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:874,&quot;width&quot;:1456,&quot;resizeWidth&quot;:651,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!fV4H!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F50b1aa99-1430-46a0-8004-fae8e1426fe3_2048x1229.png 424w, https://substackcdn.com/image/fetch/$s_!fV4H!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F50b1aa99-1430-46a0-8004-fae8e1426fe3_2048x1229.png 848w, https://substackcdn.com/image/fetch/$s_!fV4H!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F50b1aa99-1430-46a0-8004-fae8e1426fe3_2048x1229.png 1272w, https://substackcdn.com/image/fetch/$s_!fV4H!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F50b1aa99-1430-46a0-8004-fae8e1426fe3_2048x1229.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption"><em>Quincy only settles when he receives more than his expected compensation from trial, minus litigation costs. If litigation costs go down, he&#8217;d only agree to larger settlements. Similarly, Genevieve would reject expensive settlements if going to trial became cheaper. This would raise the chance both parties fail to settle and go to trial.</em></figcaption></figure></div><h2>AI and the Evolution of Law</h2><p>An increase in the number of disputes going to trial could mean more than just a higher caseload for lawyers, potentially influencing the law itself.</p><p><strong>A larger number of court cases means more opportunities to tweak precedents.</strong> Should AI change how often disputes occur (via changes in contract completeness) and how frequently they go to court (due to cheaper litigation), then AI is likely to change how quickly the law evolves. The reason is that the common law evolves as courts tweak precedent, and the rate at which such tweaks occur depends upon how many disputes occur and the rate at which disputes go to trial. An increase in either gives courts more opportunities to change precedent.</p><p><strong>Legal change could accelerate in tort law, which lacks the contracting effect.</strong> The framework above predicts that AI will not have the same effect on every area of law. Tort law, for example, tends to govern disputes that occur without prearranged contracts, such as accusations of assault or defamation. In such cases, the contracting effect is not present, but the litigation effect is. Cheaper litigation will therefore increase the rate at which the current rules of tort liability are challenged and ultimately overturned, giving courts more opportunities to change precedent in tort law.</p><p><strong>In areas of law subject to both effects, results will depend on which effect is stronger.</strong> In property and contract law, parties often have the foresight to write detailed agreements. Both the contracting effect and the litigation effect are present, so whether the law evolves more or less quickly depends upon the relative strength of the two effects. In contexts where contracts become more complete, fewer disputes will occur. However, as discussed above, when disputes do occur, parties will be more likely to go to trial rather than settle, giving courts more opportunities to tweak precedent. Thus, the contracting and litigation effects pull in opposite directions, and the common law may therefore evolve more or less quickly depending upon which effect dominates.</p><p>By contrast, in contexts where litigation costs fall by a greater percentage than gap-filling costs, relatively more disputes will occur; in any such disputes, parties will be more likely to go to trial. Both margins move in the same direction, and the prediction is unambiguous: the common law is likely to evolve more quickly, because courts will have many more opportunities to change precedent.</p><h2>Hyperlaw in Society</h2><p>If the analysis above is right, what kind of society does hyperlaw produce? It depends. Below I consider three possibilities.</p><p>First, hyperlaw implies a body of law that continuously and quickly updates to changing circumstances. The common law took decades to adjust to railroads and assembly lines. By contrast, a hyperlaw system of torts might adjust to autonomous vehicles, for example, in a decade or less. Liability rules for innovations like driverless cars and drones may update continuously and quickly, thanks to cheaper litigation as the technology evolves. But such a system is not without costs. It may also, for example, limit economic growth. The reason is that, if the law changes too quickly, investors will face considerable uncertainty about the rules that govern their returns. In response, they may refrain from making otherwise worthwhile investments.</p><p>Moreover, hyperlaw may create opportunities for institutional arbitrage. Insofar as tort law evolves quickly and contract law does not, some litigants may be incentivized to portray contract disputes as tortious, to take advantage of its speedy evolution. Others who prefer stability may instead opt to contract their way out of the courts altogether, taking advantage of reduced contracting costs.</p><p>Finally, there is one important reason that hyperlaw may never come to be. The aforementioned possibilities do not occur in a vacuum. Courts that risk being overwhelmed by litigation may offset the effects of hyperlaw by raising filing fees or the requirements for standing, for example. Such adjustments will increase the costs of litigation and, in turn, screen out disputes that may have otherwise tweaked precedent. Ultimately, whether hyperlaw is a realistic future depends upon AI&#8217;s legal capabilities and how courts respond to them.</p><p>&#8205;</p><div><hr></div><p><em><strong>See things differently? </strong>AI Frontiers welcomes expert insights, thoughtful critiques, and fresh perspectives. <a href="https://ai-frontiers.org/publish?utm_source=aif_article">Send us your pitch.</a></em></p><div><hr></div><p><em>Henry Thompson is an Assistant Professor of Economics at the University of Mississippi and an Affiliated Faculty Member at the University of Mississippi School of Law. His research spans political economy, law and economics, and public choice with a particular focus on the alternative customary, organizational, and contractual arrangements people develop with one another when they cannot use government to protect their property rights. His recent work analyzes organized crime, criminal governance, artificial intelligence and the law, and existential risk from artificial intelligence and has been published in journals such as The Journal of Law &amp; Economics, Public Choice, and Kyklos.</em></p>]]></content:encoded></item><item><title><![CDATA[AI Content Must Now Carry a Label. Cameras Are Next.]]></title><description><![CDATA[New EU and California laws require AI companies, and eventually camera makers, to sign their media outputs. It&#8217;s our best chance to tell what&#8217;s real.]]></description><link>https://newsletter.ai-frontiers.org/p/ai-content-must-now-carry-a-label</link><guid isPermaLink="false">https://newsletter.ai-frontiers.org/p/ai-content-must-now-carry-a-label</guid><dc:creator><![CDATA[AI Frontiers]]></dc:creator><pubDate>Thu, 13 Aug 2026 13:30:51 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!Z3ZI!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb33cf680-6249-4b33-9913-e23bcea4d771_5470x2188.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong><a href="https://ai-frontiers.org/author/eddan-katz">Eddan Katz</a></strong><span>, Head of Policy &amp; Gov Affairs at Encypher</span> &#8212; August 13, 2026</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Z3ZI!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb33cf680-6249-4b33-9913-e23bcea4d771_5470x2188.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Z3ZI!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb33cf680-6249-4b33-9913-e23bcea4d771_5470x2188.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Z3ZI!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb33cf680-6249-4b33-9913-e23bcea4d771_5470x2188.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Z3ZI!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb33cf680-6249-4b33-9913-e23bcea4d771_5470x2188.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Z3ZI!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb33cf680-6249-4b33-9913-e23bcea4d771_5470x2188.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Z3ZI!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb33cf680-6249-4b33-9913-e23bcea4d771_5470x2188.jpeg" width="1456" height="582" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b33cf680-6249-4b33-9913-e23bcea4d771_5470x2188.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:582,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!Z3ZI!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb33cf680-6249-4b33-9913-e23bcea4d771_5470x2188.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Z3ZI!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb33cf680-6249-4b33-9913-e23bcea4d771_5470x2188.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Z3ZI!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb33cf680-6249-4b33-9913-e23bcea4d771_5470x2188.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Z3ZI!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb33cf680-6249-4b33-9913-e23bcea4d771_5470x2188.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Two days before Slovakia&#8217;s 2023 parliamentary election, a fabricated audio clip <a href="https://www.wired.com/story/slovakias-election-deepfakes-show-ai-is-a-danger-to-democracy/">spread widely on social media</a>, appearing to catch a leading candidate and a prominent journalist discussing how to rig the vote. The following year, nonconsensual pornographic deepfakes of Taylor Swift amassed <a href="https://www.theverge.com/2024/1/25/24050334/x-twitter-taylor-swift-ai-fake-images-trending">over 45 million views</a> on X in less than 24 hours. In summer 2025, an elderly woman in Ontario <a href="https://www.ctvnews.ca/toronto/consumer-alert/article/ontario-senior-loses-900000-to-crypto-platform-scam-that-used-ai-deepfake-of-pm-carney/">lost her life savings</a> to a cryptocurrency scam, which began with a Facebook advertisement featuring a deepfake of Prime Minister Mark Carney.</p><p>In each of these cases, harm might have been reduced by <strong>content provenance metadata</strong>: information attached to content that declares how it was produced. (Generally, the term &#8220;provenance&#8221; refers to a record of where something came from and what happened to it along the way.) Content provenance tools can&#8217;t directly prove whether a bare image or video is real or synthetic; no technology reliably can. Instead, they serve as an evidentiary layer of AI governance, producing records that other protections build on top of. As signed provenance becomes the norm for content captured on cameras and microphones, fabricated material&#8212;with no or suspicious provenance&#8212;will attract more scrutiny.</p><p><strong>New EU and California laws mandate content provenance.</strong> New legal requirements, rolled out in two major markets on the same day, will significantly increase adoption of provenance techniques across the AI ecosystem. On August 2, 2026, both the <a href="https://artificialintelligenceact.eu/article/50/">EU AI Act&#8217;s Article 50</a> and <a href="https://www.leginfo.legislature.ca.gov/faces/codes_displayText.xhtml?lawCode=BPC&amp;division=8.&amp;title=&amp;part=&amp;chapter=25.&amp;article=">California&#8217;s AI Transparency Act</a> took effect. These regulations expand the creation and preservation of digital records that make it easier to trace a given piece of content back to the cameras, AI models, and other tools that created or captured it.</p><p>This essay explains what content provenance is, how it can be implemented, and its benefits and drawbacks. Then, I&#8217;ll cover the two laws that have taken effect, and their global impact. As a disclosure: I lead policy at Encypher, which develops infrastructure for content provenance.</p><h2>What Content Provenance Is and How It Works</h2><p>The new EU and California laws require some companies&#8212;including camera manufacturers and AI companies&#8212;to attach certain metadata to their products&#8217; outputs. Generally speaking, that<strong> </strong>metadata falls into three main categories: first, origination details describe where the output came from, such as which camera photographed it. Second, chain-of-custody information describes which platforms or tools handled the content after it was made. Third, a modification history tracks any changes made, such as cropping or face-swapping.</p><p><strong>The compliance ecosystem is converging on a technological standard: C2PA.</strong> The <a href="https://c2pa.org/">Coalition for Content Provenance and Authenticity (C2PA)</a>, whose user-facing implementation is known as <a href="https://contentcredentials.org/">Content Credentials</a>, maintains an open, royalty-free standard that many companies will likely use to comply with the EU and California laws. Neither law requires C2PA by name, but its interoperability and growing adoption make it the leading compliance option. <a href="https://support.claude.com/en/articles/16266773-how-claude-marks-ai-generated-content#h_35bc5763e0">Anthropic</a>, <a href="https://blog.google/innovation-and-ai/products/identifying-ai-generated-media-online/">Google</a>, and <a href="https://help.openai.com/en/articles/8912793-provenance-signals-content-credentials-synthid-in-openai-generated-content">OpenAI</a> have all indicated they will adopt C2PA.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!nyRt!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5a7a69be-a2c1-4090-ae18-fc9329e65ed9_2048x922.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!nyRt!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5a7a69be-a2c1-4090-ae18-fc9329e65ed9_2048x922.png 424w, https://substackcdn.com/image/fetch/$s_!nyRt!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5a7a69be-a2c1-4090-ae18-fc9329e65ed9_2048x922.png 848w, https://substackcdn.com/image/fetch/$s_!nyRt!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5a7a69be-a2c1-4090-ae18-fc9329e65ed9_2048x922.png 1272w, https://substackcdn.com/image/fetch/$s_!nyRt!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5a7a69be-a2c1-4090-ae18-fc9329e65ed9_2048x922.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!nyRt!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5a7a69be-a2c1-4090-ae18-fc9329e65ed9_2048x922.png" width="728" height="327.5" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5a7a69be-a2c1-4090-ae18-fc9329e65ed9_2048x922.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:655,&quot;width&quot;:1456,&quot;resizeWidth&quot;:728,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!nyRt!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5a7a69be-a2c1-4090-ae18-fc9329e65ed9_2048x922.png 424w, https://substackcdn.com/image/fetch/$s_!nyRt!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5a7a69be-a2c1-4090-ae18-fc9329e65ed9_2048x922.png 848w, https://substackcdn.com/image/fetch/$s_!nyRt!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5a7a69be-a2c1-4090-ae18-fc9329e65ed9_2048x922.png 1272w, https://substackcdn.com/image/fetch/$s_!nyRt!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5a7a69be-a2c1-4090-ae18-fc9329e65ed9_2048x922.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption"><em>A simplified representation of how Content Credentials metadata is generated. The original data, such as a raw image, and statements about it are hashed and combined into a set of numbers called a &#8220;claim.&#8221; Hardware manufacturers embed trusted keys in their devices to &#8220;sign&#8221; claims. With Content Credentials, outside observers can easily verify that the data and statements were signed by the hardware manufacturer&#8217;s key.</em></figcaption></figure></div><p><strong>C2PA creates provenance records using cryptographic techniques.</strong> For example, suppose that someone takes a photo with their smartphone. First, the phone &#8220;hashes&#8221; the photo&#8217;s pixels and provenance metadata, generating numerical tags uniquely tied to the data. Then it generates a cryptographic &#8220;signature&#8221; linked to these hashes and to the smartphone manufacturer. It stores the hashes and signature in the photo&#8217;s metadata. As a result, tampering typically leaves clear evidence: if anyone modifies the photo or its provenance metadata, a quick computational check can detect that a change has occurred. These same methods apply to audio and video files.</p><p><strong>Edits create new provenance records that reference earlier records.</strong> In C2PA parlance, each version of the content gets its own &#8220;manifest&#8221;&#8212;a cryptographically signed provenance record describing the latest changes. Continuing the example above, if someone later modifies the photo in Adobe Photoshop, then Adobe can <a href="https://helpx.adobe.com/creative-cloud/apps/adobe-content-authenticity/content-credentials/overview.html">create</a> a new manifest describing the edits it applied, storing this manifest in the photo&#8217;s metadata. Before signing, Adobe hashes the prior manifest and adds that hash to the new manifest, so a quick computational check can detect tampering with the prior manifest.</p><p><strong>A provenance record can declare that content is AI-generated. </strong>Under C2PA, provenance metadata contains a field labeled &#8220;digitalSourceType,&#8221; which states whether the content was captured by a camera or microphone, generated by AI, or a combination of the two (such as a photograph with an AI-generated background element inserted in Photoshop). The EU and California requirements lean heavily on this information.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!0lXk!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08f1c82e-64f9-474f-bbdc-03fdce0170dc_1680x1650.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!0lXk!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08f1c82e-64f9-474f-bbdc-03fdce0170dc_1680x1650.png 424w, https://substackcdn.com/image/fetch/$s_!0lXk!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08f1c82e-64f9-474f-bbdc-03fdce0170dc_1680x1650.png 848w, https://substackcdn.com/image/fetch/$s_!0lXk!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08f1c82e-64f9-474f-bbdc-03fdce0170dc_1680x1650.png 1272w, https://substackcdn.com/image/fetch/$s_!0lXk!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08f1c82e-64f9-474f-bbdc-03fdce0170dc_1680x1650.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!0lXk!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08f1c82e-64f9-474f-bbdc-03fdce0170dc_1680x1650.png" width="550" height="540.1785714285714" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/08f1c82e-64f9-474f-bbdc-03fdce0170dc_1680x1650.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1430,&quot;width&quot;:1456,&quot;resizeWidth&quot;:550,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!0lXk!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08f1c82e-64f9-474f-bbdc-03fdce0170dc_1680x1650.png 424w, https://substackcdn.com/image/fetch/$s_!0lXk!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08f1c82e-64f9-474f-bbdc-03fdce0170dc_1680x1650.png 848w, https://substackcdn.com/image/fetch/$s_!0lXk!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08f1c82e-64f9-474f-bbdc-03fdce0170dc_1680x1650.png 1272w, https://substackcdn.com/image/fetch/$s_!0lXk!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08f1c82e-64f9-474f-bbdc-03fdce0170dc_1680x1650.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption"><em>A <a href="https://verify.contentauthenticity.org/">tool</a> provided by the Content Authenticity Initiative displays C2PA metadata from an image generated in ChatGPT, revealing its true provenance.</em></figcaption></figure></div><p><strong>Content Credentials show up as small, familiar cues.</strong> Creators will see a simple toggle to &#8220;attach Content Credentials&#8221; in Photoshop or Firefly, or their camera will sign photos automatically. Viewers may see a small &#8220;cr&#8221; badge on the content, which they can click to see the metadata. Platforms will see machine-readable data they can turn into on-screen labels.</p><h2>Limitations of Content Credentials</h2><p>While Content Credentials are a promising way of fulfilling the new EU and California requirements, they are not infallible. They ultimately need to be paired with technical and governance measures to ensure that metadata is accurate and remains attached to its content.</p><p><strong>Technical vulnerabilities mean Content Credentials can be removed or falsified.</strong> The most common failure of Content Credentials is <em>metadata stripping</em>, in which the process of uploading files or converting file formats discards manifests automatically. The second is the <em>analog hole</em>: if a user screenshots or rerecords content, the original manifest doesn&#8217;t carry over to the new file. The third issue is <em>signing-through-camera</em>: point a camera that signs images automatically at a deepfake on a screen and it will honestly sign that it captured the image. The fourth is <em><a href="https://arxiv.org/html/2604.24890v1">forged manifests</a></em>: skilled attackers can build manifests that contain false assertions. Additionally, researchers continue to probe whether C2PA&#8217;s cryptographic validation itself can be defeated.</p><p><strong>Mitigations can help reduce these vulnerabilities.</strong> To address metadata stripping, two technical fixes are to include invisible watermarks such as <a href="https://deepmind.google/models/synthid/">Google&#8217;s SynthID</a> and to use &#8220;<a href="https://contentauthenticity.org/blog/durable-content-credentials">digital fingerprints</a>,&#8221; which let a stripped file be rematched to its manifest. When these measures are combined with Content Credentials, it becomes far harder to sever the record from the content it describes. The California AI Transparency Act also requires that, beginning in 2027, <a href="https://law.justia.com/codes/california/code-bpc/division-8/chapter-25/section-22757-3-1/">large platforms not strip standards-compliant provenance data</a>.</p><p>The analog hole problem, meanwhile, can be mitigated as norms change. While there&#8217;s no way to prevent users from stripping provenance metadata by rerecording content, material without provenance metadata will eventually be seen as less trustworthy for this reason. As camera and microphone manufacturers widely adopt C2PA, bare content will stand out, reducing the incentive to strip metadata.</p><p>For signing-through-camera, emerging technical solutions such as <a href="https://authenticity.sony.net/camera/en-us/index.html">Sony&#8217;s Camera Authenticity Solution</a> embed 3D depth information in metadata, revealing whether the photo captured a real scene or a flat screen. The threat of forged manifests, meanwhile, requires both technical and institutional responses. For example, <a href="https://c2pa.org/conformance/">conformance programs</a> can verify that products adhere to the <a href="https://spec.c2pa.org/specifications/specifications/2.4/specs/C2PA_Specification.html">Content Credentials technical specification</a> and that their signatures cannot be manipulated. The specification itself can also be revised to address vulnerabilities.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!e9Bq!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdfbe6df4-4e0b-4140-8bc0-3d9a15648dee_694x727.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!e9Bq!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdfbe6df4-4e0b-4140-8bc0-3d9a15648dee_694x727.png 424w, https://substackcdn.com/image/fetch/$s_!e9Bq!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdfbe6df4-4e0b-4140-8bc0-3d9a15648dee_694x727.png 848w, https://substackcdn.com/image/fetch/$s_!e9Bq!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdfbe6df4-4e0b-4140-8bc0-3d9a15648dee_694x727.png 1272w, https://substackcdn.com/image/fetch/$s_!e9Bq!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdfbe6df4-4e0b-4140-8bc0-3d9a15648dee_694x727.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!e9Bq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdfbe6df4-4e0b-4140-8bc0-3d9a15648dee_694x727.png" width="448" height="469.3025936599424" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/dfbe6df4-4e0b-4140-8bc0-3d9a15648dee_694x727.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:727,&quot;width&quot;:694,&quot;resizeWidth&quot;:448,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!e9Bq!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdfbe6df4-4e0b-4140-8bc0-3d9a15648dee_694x727.png 424w, https://substackcdn.com/image/fetch/$s_!e9Bq!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdfbe6df4-4e0b-4140-8bc0-3d9a15648dee_694x727.png 848w, https://substackcdn.com/image/fetch/$s_!e9Bq!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdfbe6df4-4e0b-4140-8bc0-3d9a15648dee_694x727.png 1272w, https://substackcdn.com/image/fetch/$s_!e9Bq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdfbe6df4-4e0b-4140-8bc0-3d9a15648dee_694x727.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption"><em>Sony&#8217;s Camera Authenticity Solution makes it hard to pass off synthetic images as genuine by photographing them off a screen, addressing the signing-through-camera vulnerability. Source: <a href="https://authenticity.sony.net/camera/en-us/index.html">Sony</a>.</em></figcaption></figure></div><p><strong>Private and public institutions can help determine which signers are trustworthy.</strong> As discussed above, C2PA uses cryptographic signatures for security, and each signature traces back to a particular signer (e.g., a smartphone manufacturer). A signature answers which credential signed a claim, but who decides which signers are trustworthy? Currently, certificate authorities vet signers, and the <a href="https://spec.c2pa.org/conformance-explorer/">C2PA Trust List</a> governs which of those authorities receive official approval. In this certification system, private actors police themselves; major firms building the tools that create and sign content, such as Adobe, also set the conformance rules and decide which signers are trustworthy. Public memory institutions such as <a href="https://blogs.loc.gov/thesignal/2025/07/c2pa-glam/">libraries, archives, and museums</a> could act as independent, mission-driven custodians in this process.</p><p><strong>There is a long-standing tension between transparency and privacy. </strong>While<strong> </strong>provenance brings benefits, it also carries the risk of misuse. Provenance trails can sometimes reveal who filmed a video, where, and when. Journalists who wish to prove the authenticity of a piece of media might also struggle to protect dissidents and whistleblowers. While there is an inherent trade-off between transparency and privacy, C2PA tries to strike a balance. Most C2PA assertions are optional; sensitive fields can be redacted; and certificates can be pseudonymous.</p><p><strong>Content Credentials have been adopted widely but unevenly.</strong> Several generative AI tools already sign content by default, including <a href="https://blog.adobe.com/en/publish/2024/01/26/seizing-moment-content-credentials-in-2024">Adobe Firefly</a> and OpenAI&#8217;s <a href="https://openai.com/index/advancing-content-provenance/">DALL&#183;E 3 and Sora</a>. Meanwhile, Midjourney still embeds no manifest and has not committed to a timeline for implementing one. Adoption in hardware is also growing. <a href="https://contentauthenticity.org/blog/leica-launches-worlds-first-camera-with-content-credentials">Leica&#8217;s M11-P</a> was the world&#8217;s first camera to have Content Credentials built in. Now, <a href="https://www.lumethic.com/en/articles/cameras-with-c2pa-content-credentials">Sony and Canon</a> have followed suit, alongside <a href="https://blog.google/security/pixel-android-trusted-images-c2pa-content-credentials/">Google&#8217;s Pixel 10</a>. The most consequential gap is Apple, which hasn&#8217;t yet committed to implementing C2PA or given a public explanation as to why. California&#8217;s capture-device rule will increase the pressure on Apple and other major manufacturers to adopt standards-compliant provenance beginning in 2028.</p><h2>What the EU and California Acts Require</h2><p>The EU and California laws create several different obligations. Some center on generating and preserving provenance records; others focus on using those records to create appropriate labels and notices.</p><p><strong>The EU obliges generative AI providers to create provenance records. </strong>In the EU AI Act, the single most important obligation is Article 50(2): providers of generative systems must ensure those systems automatically mark synthetic audio, image, video, and text output in machine-readable form. This obligation is the key to an evidentiary layer that can automatically detect material with trustworthy provenance.</p><p><strong>The EU&#8217;s other two duties focus on disclosure. </strong>With some exceptions, Article 50(4) requires deployers of AI systems to label deepfakes and to disclose AI-generated text on matters of public interest. Article 50(1) places a similar requirement on AI providers to tell people when they are interacting with an AI system.</p><p><strong>California&#8217;s law goes further by requiring online platforms to retain provenance data. </strong>The California AI Transparency Act applies to providers of generative AI systems that have more than a million monthly users and are accessible in the state. The headline obligations on these providers, effective August 2, 2026, are to include embedded disclosures and offer a free tool that the public can use to surface content provenance data. These requirements act as California&#8217;s equivalents to the EU&#8217;s marking-and-disclosure duties, and they require the embedded data to be difficult to remove. Starting on January 1, 2027, large online platforms must detect and surface standards-compliant provenance data attached to content, and&#8212;critically&#8212;refrain from stripping it. This rule will greatly increase the durability of provenance metadata, making the whole content provenance ecosystem more useful.</p><p><strong>California&#8217;s law requires many hardware manufacturers to create provenance records.</strong> The final component of California&#8217;s law, effective January 1, 2028, extends provenance requirements beyond AI-generated content to content recorded by devices such as smartphones, cameras, and voice recorders. These devices must create provenance records by default, though manufacturers may give users an option to turn this feature off.</p><p><strong>Enforcement can add up to enormous sums. </strong>Under the EU AI Act, national regulators can impose fines of up to &#8364;15 million or 3% of worldwide annual turnover, whichever is higher, for breaching the Article 50 transparency duties. The percentage-of-global-revenue model scales with the size of the offender; for a large firm, fines could grow to hundreds of millions of dollars. In California, the Attorney General, city attorneys, and county counsel can seek civil penalties of $5,000 per violation, which look modest by comparison. However, each day of noncompliance is treated as a new violation. The fine for a single noncompliant product, multiplied across days, can quickly add up.</p><h2>The EU and California Laws&#8217; Global Impact</h2><p>The principle of transparency around AI-generated content has long been discussed in AI governance and has appeared in international agreements in recent years. However, the laws enforced in the EU and California will, for the first time, set an effective global baseline for transparency requirements.</p><p><strong>The notion of content provenance is not new, but requirements vary widely.</strong> AI governance documents from the <a href="https://oecd.ai/en/ai-principles">OECD</a>, <a href="https://www.unesco.org/en/artificial-intelligence/recommendation-ethics">UNESCO</a>, the <a href="https://digital-strategy.ec.europa.eu/en/library/hiroshima-process-international-code-conduct-advanced-ai-systems">G7</a>, and the <a href="https://www.coe.int/en/web/artificial-intelligence/the-framework-convention-on-artificial-intelligence">Council of Europe</a> have already articulated content-provenance norms at the international level, although they are mostly nonbinding. The United States still has no general federal content provenance law. At the state level, <a href="https://www.troutmanprivacy.com/2026/04/analyzing-utah-and-washingtons-new-ai-provenance-laws/">both Utah and Washington</a> have enacted their own content provenance laws aligned with California&#8217;s AI Transparency Act.</p><p><strong>China&#8217;s laws also fuel efforts to build provenance infrastructure. </strong>Beyond the EU and the US, the most prescriptive approach is China&#8217;s labeling regime. Its <a href="https://www.chinalawtranslate.com/en/deep-synthesis/">Deep Synthesis Provisions</a>, <a href="https://www.chinalawtranslate.com/en/generative-ai-interim/">Interim Generative AI Measures</a>, <a href="https://www.chinalawtranslate.com/en/ai-labeling/">Measures for Labeling of AI-Generated Synthetic Content</a>, <a href="https://www.geopolitechs.org/p/chinas-mandatory-national-standards">GB 45438-2025 national standard</a>, and <a href="https://ocpl.substack.com/p/labelling-ai-generated-content-in">other regulations and institutions</a> already require AI-generated content to be marked. However, China has not yet extended comparable requirements to hardware manufacturers.</p><p><strong>The EU and California laws apply to content that ends up within their borders.</strong> Neither the EU law nor the California law hinges on where a company is incorporated or headquartered, or where its servers sit. Instead, both laws center on market access and effects&#8212;whether the system is placed on the market or publicly accessible in the jurisdiction, and whether its outputs are used by people there&#8212;with the California AI Transparency Act adding a one-million-monthly-user threshold.</p><p><strong>The laws&#8217; footprints are effectively global. </strong>Digital content does not respect borders, and no generative system can guarantee that its outputs will never appear in the EU or California&#8212;two of the largest and most affluent markets in the world. Attempting to run a compliant environment for these markets while running a noncompliant one everywhere else could be inconvenient and expensive. Instead, companies may apply the stricter standard to all output by default. As a result, these region-specific mandates are set to have an international impact.</p><h2>How Provenance Mandates Support Courts in Tackling Deepfake Evidence</h2><p>The primary effect of the new EU and California mandates is to require the creation of signed, time-stamped, tamper-evident records that document data origin and custody. Such records will be generated at scale, as a matter of legal obligation. Records are evidence, which raises a question: how should courts use this evidence?</p><p><strong>Advisory bodies are considering responses to deepfakes presented as evidence.</strong> The Advisory Committee on Evidence Rules, which proposes amendments to the US Federal Rules of Evidence, <a href="https://www.uscourts.gov/sites/default/files/document/advisory_committee_on_evidence_rules_may_2026.pdf">drafted a working Rule 901(c)</a> to handle evidence fabricated by generative AI. Consider a case in which a party claims that a piece of evidence presented against them is a deepfake. Under the working draft, that party would first have to produce evidence sufficient to support a finding of fabrication&#8212;a lower bar than proving falsification outright. Only then must the item&#8217;s proponent show the judge that it is more likely than not authentic. If such a rule were adopted, validated provenance records would be powerful evidence for meeting its test.</p><p><strong>Provenance records can help courts weigh authenticity, though their absence must be read with care.</strong> The machinery of 901(c) turns on whether an item was generated or altered by AI, something courts have had no dependable way of establishing. Validated provenance records offer an important factor to consider. A missing manifest, by contrast, proves little by itself: not all cameras create one, and platforms routinely strip provenance information. Absence becomes significant only where the facts of the case suggest that provenance information should be present&#8212;a situation that will grow more common as California&#8217;s and the EU&#8217;s provenance mandates take effect. In such situations, an unexplained gap begins to raise a question about the party that could have signed and did not, much as courts already draw inferences when a party fails to preserve evidence it had a duty to keep.</p><p>New technologies have often presented courts with novel challenges when it comes to identifying authentic evidence. In the 1800s, courts spent decades working out how to treat photographic evidence. The following century, fingerprinting and DNA became more reliable and useful in court as institutions&#8212;registries, labs, and standards&#8212;grew to support the collection and analysis of such evidence. Whether C2PA will become a global default for verifying the status of images, audio, and other data remains an open question. But with the arrival of EU and California laws, courts will at least have a better record of how a digital item came to be and how it was altered. Content provenance is the evidentiary layer the AI era has lacked.</p><p><em>Work on this essay was supported by the Summer Research Fellowship at the Institute for Law &amp; AI.</em></p><p>&#8205;</p><div><hr></div><p><em><strong>See things differently? </strong>AI Frontiers welcomes expert insights, thoughtful critiques, and fresh perspectives. <a href="https://ai-frontiers.org/publish?utm_source=aif_article">Send us your pitch.</a></em></p><div><hr></div><p><em>Eddan Katz is the Head of Policy &amp; Government Affairs at Encypher. He is also a Research Fellow with the LexLab at UC Law San Francisco, writing on and teaching AI liability. Previously, he was Executive Director of Yale Law School&#8217;s Information Society Project (ISP), was the International Affairs Director at the Electronic Frontier Foundation (EFF), the Project Lead for the AI Governance platform at the World Economic Forum&#8217;s Centre for the Fourth Industrial Revolution network, and worked on the AI Policy team at Meta.</em></p>]]></content:encoded></item><item><title><![CDATA[AGI Will Set Off an Industrial Explosion]]></title><description><![CDATA[If AI reaches the point where it can do the cognitive work humans do, robots will proliferate. Standard data on US industry implies a fully automated economy could double its output roughly every year]]></description><link>https://newsletter.ai-frontiers.org/p/agi-will-set-off-an-industrial-explosion</link><guid isPermaLink="false">https://newsletter.ai-frontiers.org/p/agi-will-set-off-an-industrial-explosion</guid><dc:creator><![CDATA[AI Frontiers]]></dc:creator><pubDate>Tue, 11 Aug 2026 13:30:33 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!tU8F!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff2c7356f-e943-47a8-87d2-d6ac2f06d10b_4800x2400.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong><a href="https://ai-frontiers.org/author/damon-binder">Damon Binder</a></strong><span>, Senior Researcher at Coefficient Giving</span> &#8212; August 11, 2026</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!tU8F!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff2c7356f-e943-47a8-87d2-d6ac2f06d10b_4800x2400.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!tU8F!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff2c7356f-e943-47a8-87d2-d6ac2f06d10b_4800x2400.jpeg 424w, https://substackcdn.com/image/fetch/$s_!tU8F!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff2c7356f-e943-47a8-87d2-d6ac2f06d10b_4800x2400.jpeg 848w, https://substackcdn.com/image/fetch/$s_!tU8F!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff2c7356f-e943-47a8-87d2-d6ac2f06d10b_4800x2400.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!tU8F!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff2c7356f-e943-47a8-87d2-d6ac2f06d10b_4800x2400.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!tU8F!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff2c7356f-e943-47a8-87d2-d6ac2f06d10b_4800x2400.jpeg" width="1456" height="728" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f2c7356f-e943-47a8-87d2-d6ac2f06d10b_4800x2400.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:728,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!tU8F!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff2c7356f-e943-47a8-87d2-d6ac2f06d10b_4800x2400.jpeg 424w, https://substackcdn.com/image/fetch/$s_!tU8F!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff2c7356f-e943-47a8-87d2-d6ac2f06d10b_4800x2400.jpeg 848w, https://substackcdn.com/image/fetch/$s_!tU8F!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff2c7356f-e943-47a8-87d2-d6ac2f06d10b_4800x2400.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!tU8F!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff2c7356f-e943-47a8-87d2-d6ac2f06d10b_4800x2400.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>AI systems now write so fluently that <a href="https://nymag.com/intelligencer/article/openai-chatgpt-ai-cheating-education-college-students-school.html">cheating at universities has become ubiquitous</a> and <a href="https://www.theatlantic.com/technology/2025/10/ai-slop-winning/684630/">&#8220;AI slop&#8221; is displacing human writing across the internet</a>. They have begun producing <a href="https://openai.com/index/model-disproves-discrete-geometry-conjecture/">original proofs on long-standing open problems</a> in mathematics. Researchers at the frontier AI companies have<a href="https://www.anthropic.com/institute/recursive-self-improvement"> largely stopped writing their own code</a>, and the models&#8217; hacking abilities are strong enough that the US government temporarily <a href="https://www.anthropic.com/news/redeploying-fable-5">export-controlled Anthropic&#8217;s Claude Fable 5</a>, days after its release. Ten years ago, every claim in this paragraph would have sounded like science fiction.</p><p>It is easy to become numb to this progress. Today&#8217;s AI agents remain endearingly clumsy; watching <a href="https://www.anthropic.com/research/project-vend-1">Claude run a small store</a> is a bit like watching a child running a lemonade stand. But we should not let such awkwardness distract from the trend. These systems have evolved from research curiosities to extremely powerful economic engines in 10 years, with no end in sight. I want to take that trend seriously and ask: if AI does get to the stage where it can do the cognitive work that humans do, what happens to the economy?</p><p>With <a href="https://www.nber.org/papers/w31815">notable exceptions</a>, economists have mostly declined to address this question; their usual maneuver is to deny the premise, as when a <a href="https://www.nber.org/papers/w32487">widely cited Nobel laureate&#8217;s analysis</a> put AI&#8217;s contribution to US GDP at about 1% over the coming decade, by essentially freezing 2023 capabilities for 10 years. But the question is worth taking seriously, because automating cognitive labor releases what has always been the critical brake on physical production: no matter how cheap machines and tools become, you cannot manufacture new workers. In this piece, I will assume no additional new technologies and no recursive self-improvement to superintelligence. Yet, even with these conservative assumptions, I will show that the economy stands to be profoundly transformed. For the first time in history, physical production could be fully automated.</p><p>The rest of this piece makes that case and considers the implications. I argue that AI capable of cognitive work could also do physical work (since building the machinery it would need is relatively straightforward) and that its labor would be cheap. I then turn to input-output tables&#8212;the US government&#8217;s accounting of what every industry buys from every other&#8212;to ask how fast a fully automated economy could grow, finding that physical output would double roughly every year rather than every few decades (as it does currently). Finally I ask whether anything could stop such an industrial explosion, and what the implications are for power at home and abroad.</p><h2>Why AGI Gives You Robots</h2><p>The term &#8220;artificial general intelligence&#8221; (AGI) has been <a href="https://helentoner.substack.com/p/the-term-agi-is-almost-useless-at">endlessly used and abused</a>, but it points to a clear core concept: an AI smart enough to do the work humans can do, at a competitive cost. You could hand it a task, as you would to a skilled employee or contractor, and expect the job done competently. Current systems, for all their rapid progress, are not close to AGI; my own attempts to automate my job have been unsuccessful. However, once AGI appears, we should expect it to be able to perform physical work through robotics.</p><p><strong>An AI system that can do every remote job can also operate a robot.</strong> Definitions of AGI focus on cognitive work, but there is nothing special about the physical world that confines intelligent agents to their data centers. Remote cognitive work is hard: doing all of it means mastering the real-time control, spatial reasoning, physical prediction, and continual learning required for such varied tasks as mechanical engineering and animation. A system with those skills has what it needs to operate machinery, if given actuators to work with.</p><p><strong>Progress in AI is already pulling robotics forward.</strong> The general-purpose methods that cracked language and vision turn out to be good at manual manipulation too. Large language models can increasingly supply high-level control: today they <a href="https://arxiv.org/abs/2311.17842">run robot arms</a>, <a href="https://arxiv.org/abs/2312.14950">fly drones</a>, and <a href="https://www.anthropic.com/research/project-fetch-phase-two">program robot dogs</a>. Hobbyists have even <a href="https://www.youtube.com/watch?v=S67z2aekBrI">wired them into homemade robots</a>. Meanwhile, the same training methods, applied to recordings of humans teleoperating machines, are producing the low-level dexterous control that humans perform instinctively; today&#8217;s systems can <a href="https://www.pi.website/blog/pi0">fold laundry and assemble cardboard boxes</a>, using ordinary cameras and simple grippers.</p><p><strong>Hardware is not the bottleneck for robotic automation.</strong> Industrial arms have demonstrated precision and force beyond any human arm for over half a century. But, because they could neither see nor think, every motion had to be programmed in advance, at <a href="https://ifr.org/post/advances-in-programming-lower-cost-of-adoption">massive cost</a>. The other work-around was a human operator: remote manipulators have handled radioactive material <a href="https://link.springer.com/book/9780850385885">since the late 1940s</a>, built underwater structures using <a href="https://www.oceaneering.com/rov-services/rov-systems/">remote-controlled submersibles</a>, and <a href="https://link.springer.com/article/10.1007/s11701-025-02274-9">performed surgery</a>. That remote control was worthwhile only when a person could not be physically present. But it does show something we&#8217;ve known for decades: a machine under competent control can do skilled physical work. Once control can come from AIs rather than people, it becomes worth building general-purpose machinery for them.</p><p><strong>Robots will not necessarily resemble humans.</strong> While the <a href="https://rodneybrooks.com/why-todays-humanoids-wont-learn-dexterity/">human hand is a remarkable instrument</a>, <a href="https://itcanthink.substack.com/p/robot-hands-are-getting-better">robot hands are already fairly good</a>, and certainly better than the <a href="https://www.armdynamics.com/upper-limb-library/farming-with-an-upper-limb-prosthesis">split-hook prostheses</a>&#8212;two rigid fingers on a cable with no sense of touch&#8212;used by amputees to farm, weld, and perform all manner of other tasks. With AI, simple actuators go far, and AGIs will have intelligence and patience to spare. Nor will the machines work at human workstations forever. Production demands dexterity today because every process was designed around human workers with hands. New possibilities open up when the workers are machines; just as today&#8217;s programming agents do not type at keyboards as their human counterparts do, robotics tools need not be gripped and triggered by fingers&#8212;they could be mounted directly on a robotic arm instead.</p><h2>Machine Labor Will Be Cheap</h2><p>Automating labor is not free. But the computer chips and robotic actuators that replace workers are simply more capital goods for the economy to produce&#8212;and they&#8217;re not particularly expensive ones. A humanoid robot, broadly speaking, uses parts similar to those of a car: metal, motors, batteries, electronics, and sensors. At automotive production volumes, it should cost tens of thousands of dollars; <a href="https://shop.unitree.com/products/unitree-g1">Unitree already sells its child-sized G1 humanoid for around $13,500</a>, and <a href="https://www.notateslaapp.com/news/3314/tesla-eyes-20k-price-target-for-optimus-extremely-fast-production-ramp">Tesla is reportedly aiming for $20,000</a> for its full-size Optimus. If a robot costs $30,000 and, working around the clock, can substitute for a single human worker who costs $30 an hour, it could pay for itself in six weeks.</p><p><strong>AI cognitive labor is generally significantly cheaper than the humans it replaces.</strong> It is hard to price the future AI cognitive labor involved in an industrial explosion, because it does not exist yet. However, on the tasks AI systems can already do&#8212;like transcription, routine translation, or writing one-off scripts&#8212;they are typically <a href="https://blog.redwoodresearch.org/p/ais-capability-improvements-havent">far cheaper</a>, per unit, than the people they replace, and the cost of a fixed level of AI capability <a href="https://epoch.ai/data-insights/llm-inference-price-trends">falls rapidly</a> year over year. Even if the first AGI arrived merely cost-competitive with human workers, within a year it would cost a fraction as much.</p><h2>Input-Output Analysis</h2><p>How fast would the economy grow once human labor is automated? At first blush, this looks hard to answer. Standard growth models assume that labor and capital substitute for each other, treating each as a single dollar-denominated aggregate&#8212;barristers and bricklayers combined into &#8220;labor,&#8221; bulldozers and bridges into &#8220;capital.&#8221; Such abstractions are poorly equipped for a world where labor is unnecessary and capital reproduces itself, and classic concepts like GDP can become <a href="https://philiptrammell.com/static/utility.pdf">profoundly misleading</a>.</p><p><strong>Input-output analysis helps forecast how an automated economy would grow. </strong>Input-output analysis takes a different approach, recording what each industry physically needs from others. The method was developed by <a href="https://www.thecrimson.com/article/1952/6/19/wassily-leontief-pone-of-the-most/">Wassily Leontief</a>, in the 1930s, to study the relationships between industrial sectors. In 1945, Leontief used his tables to project the United States&#8217; <a href="https://www.scientificamerican.com/article/input-output-economics/">1950 steel requirements</a> to within a couple of percentage points. Military planners, concerned about war with the Soviet Union, took up the method to study how fast industry could remobilize.</p><p><strong>Input-output analysis tracks what everyone buys from everyone else. </strong>The basic idea is simple: ask every business what it buys and from whom, then aggregate the responses into tables that track what each industry buys from others. An entry for aluminum smelting might record the electricity, ore, and machining required to produce aluminum, while an entry for aircraft manufacturing records how much aluminum is required. The Census Bureau runs this survey every five years, and the Bureau of Economic Analysis assembles the results. The tables take years to build, so the most recent set covers 2017. Companion tables record the equipment and structures that each industry holds, from machine tools to chip fabs. Entries are recorded in dollars, but they are detailed enough to closely follow the underlying kilowatt-hours of electricity, tons of steel, and other physical quantities. Most output is ultimately consumed; the rest is reinvested, either adding to physical capital or replacing what has worn out.</p><p>Once robots can replace human labor, the economy will no longer be bound by a fixed workforce. It can produce every input it needs, including the &#8220;workers&#8221; themselves, so output can be fed back into building more capacity, and growth compounds. <a href="https://academic.oup.com/restud/article-abstract/13/1/1/1569841">John von Neumann</a> worked out how to compute the maximum rate at which such an economy could expand. Combining his analysis with the production data in the tables tells us how fast an autonomous industrial sector could grow.</p><p><strong>Input-output analysis measures economic growth in physical output, not value.</strong> This approach to forecasting growth tracks how much stuff can be produced. I make no attempt to convert this into GDP, because an industrial explosion would upend the prices any such conversion relies on: when machines produce everything, including more machines, goods become exponentially cheap. Physical output is also the better guide to what is at stake. Military power, human employment, and material abundance all depend on how much gets built, rather than on its dollar price.</p><h2>How Fast Could an Autonomous Economy Grow?</h2><p>Using the US government&#8217;s <a href="https://www.bea.gov/industry/input-output-accounts-data">2017 input-output tables</a>, which track 402 industries, I find that a fully automated economy using US production methods could double its output roughly every year; input-output tables for other advanced economies give <a href="https://defensesindepth.bio/ai-industrial-takeoff-part-1-maximum-growth-rates-with-current-technology/#appendix-b-von-neumann-growth-rates-are-similar-across-industrial-economies">comparable results</a>. The robots and computer chips needed to automate production represent only a small fraction of total output; even a tenfold increase in their cost would not impact the growth rate significantly.<a href="https://defensesindepth.bio/ai-industrial-takeoff-part-1-maximum-growth-rates-with-current-technology/"> Construction lags can be incorporated too</a>; even with these delays included, the economy still doubles in well under two years.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!xRIM!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc85a0e91-eb43-4f12-8f47-7b0228388274_2048x1588.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!xRIM!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc85a0e91-eb43-4f12-8f47-7b0228388274_2048x1588.png 424w, https://substackcdn.com/image/fetch/$s_!xRIM!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc85a0e91-eb43-4f12-8f47-7b0228388274_2048x1588.png 848w, https://substackcdn.com/image/fetch/$s_!xRIM!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc85a0e91-eb43-4f12-8f47-7b0228388274_2048x1588.png 1272w, https://substackcdn.com/image/fetch/$s_!xRIM!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc85a0e91-eb43-4f12-8f47-7b0228388274_2048x1588.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!xRIM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc85a0e91-eb43-4f12-8f47-7b0228388274_2048x1588.png" width="1456" height="1129" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c85a0e91-eb43-4f12-8f47-7b0228388274_2048x1588.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1129,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!xRIM!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc85a0e91-eb43-4f12-8f47-7b0228388274_2048x1588.png 424w, https://substackcdn.com/image/fetch/$s_!xRIM!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc85a0e91-eb43-4f12-8f47-7b0228388274_2048x1588.png 848w, https://substackcdn.com/image/fetch/$s_!xRIM!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc85a0e91-eb43-4f12-8f47-7b0228388274_2048x1588.png 1272w, https://substackcdn.com/image/fetch/$s_!xRIM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc85a0e91-eb43-4f12-8f47-7b0228388274_2048x1588.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption"><em>Projected physical output of four key industrial sectors in the years after AGI arrives, relative to today&#8217;s level. Each scenario assumes that new capacity takes zero, six months, or a year to build before it starts producing output. Solid lines hold human consumption at today&#8217;s level and reinvest all output above that level into industry; dashed lines split that output 50-50 between industry and human consumption. A real buildout would differ somewhat from these projections: it would be slower initially as AI capabilities diffuse throughout the economy, but accelerate later as production methods adapt to robot workers. Source: author&#8217;s calculations from the <a href="https://www.bea.gov/industry/input-output-accounts-data">2017 US input-output tables</a>, as described in <a href="http://defensesindepth.bio/the-ai-industrial-explosion-part-2-transition-dynamics/">Part 2 of the author&#8217;s memo series</a>.</em></figcaption></figure></div><p>&#8205;<strong>Why does a fully automated economy accelerate so much faster than the current one?</strong> The main difference is that an automated economy can reinvest far more of what it produces. Building more factories today is not useful; there would be no workers to staff them nor to use the extra machines and tools produced by them. Thus, we <a href="https://www.bea.gov/data/gdp/gross-domestic-product">consume about four-fifths</a> of what we produce, and most reinvestment goes to replacing worn-out capital rather than adding to it. AGI would remove this obstacle, allowing robot workers to be manufactured along with other physical goods and thus breaking the link between human labor and physical production. The pace of growth is then set by how fast the machine economy can copy itself, which input-output analysis shows us is fast.</p><p><strong>The true growth rate of an automated economy is likely even higher.</strong> Our estimate of this maximum growth rate uses 2017 American production methods; therefore, it&#8217;s conservative. Those methods were designed around human workers at human wages and are a poor fit for a robot economy; letting the production methods change makes it grow <a href="https://defensesindepth.bio/the-ai-industrial-explosion-part-3-going-faster/">considerably faster</a>. Assuming 2017 methods also ignores the efficiencies that come with producing at greater volume. However, it also neglects the depletion that makes raw materials costlier to extract, which I return to below.</p><p><strong>Industrial explosions happen even without new science and technology.</strong> This assumption might seem strange to economists, because standard theory predicts that growth at the technological frontier requires new ideas. But that prediction assumes an economy in which the workforce cannot be manufactured; an economy that can build its own workers grows by building more of them and needs no new ideas to do so.</p><p><strong>An economy growing at this maximum rate looks very different from today&#8217;s.</strong> Its output is machinery, materials, energy, and factories rather than consumer goods and services, and its workforce is robotic. Table 1 shows its major sectors, by share of that workforce, of output, and of energy consumed. The workforce such an economy needs is overwhelmingly industrial: robotic arms on factory floors, self-driving excavators and cranes, and manipulators on mobile bases of all sorts and sizes. Automating physical production means automating construction, machining, and assembly; whether AI can substitute for doctors, lawyers, or babysitters is irrelevant to how fast this economy can grow.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!D7B4!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc62d4a7-9983-4506-b59f-30d9be472006_2048x1863.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!D7B4!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc62d4a7-9983-4506-b59f-30d9be472006_2048x1863.png 424w, https://substackcdn.com/image/fetch/$s_!D7B4!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc62d4a7-9983-4506-b59f-30d9be472006_2048x1863.png 848w, https://substackcdn.com/image/fetch/$s_!D7B4!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc62d4a7-9983-4506-b59f-30d9be472006_2048x1863.png 1272w, https://substackcdn.com/image/fetch/$s_!D7B4!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc62d4a7-9983-4506-b59f-30d9be472006_2048x1863.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!D7B4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc62d4a7-9983-4506-b59f-30d9be472006_2048x1863.png" width="1456" height="1324" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/dc62d4a7-9983-4506-b59f-30d9be472006_2048x1863.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1324,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!D7B4!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc62d4a7-9983-4506-b59f-30d9be472006_2048x1863.png 424w, https://substackcdn.com/image/fetch/$s_!D7B4!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc62d4a7-9983-4506-b59f-30d9be472006_2048x1863.png 848w, https://substackcdn.com/image/fetch/$s_!D7B4!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc62d4a7-9983-4506-b59f-30d9be472006_2048x1863.png 1272w, https://substackcdn.com/image/fetch/$s_!D7B4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc62d4a7-9983-4506-b59f-30d9be472006_2048x1863.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption"><em>The self-replicating economy at maximum growth, computed from the 2017 US input-output tables at their most detailed level, then aggregated to the government&#8217;s 71 summary sectors for display. Columns give each sector&#8217;s share of the human workforce being replaced (at today&#8217;s staffing levels), of output (valued at 2017 prices), and of energy use (electricity and fuel purchases, in 2017 dollars).</em></figcaption></figure></div><p>&#8205;<strong>In reality, some output would directly support human needs instead of further growth.</strong> The same machines, materials, energy, and robotic labor could make homes just as well as they could make factories. Robots could also cook, clean, and drive for people. However, an economy that devotes significant resources to human consumption could still grow quickly in absolute terms, <a href="https://defensesindepth.bio/ai-industrial-takeoff-part-1-maximum-growth-rates-with-current-technology/#consumption-does-not-preclude-rapid-growth">according to my forecasts</a>. For example, an economy reinvesting half its output would double every 20 months, and the stream of goods and services flowing out to people would double every 20 months as well. Reinvesting only half is arguably conservative&#8212;common sense suggests (and <a href="https://defensesindepth.bio/ai-industrial-takeoff-part-1-maximum-growth-rates-with-current-technology/#consumption-does-not-preclude-rapid-growth">economic theory concurs</a>) that countries and companies controlling the machines would reinvest most of their output to stay competitive with one another.</p><h2>From Investment Boom to Unprecedented Growth</h2><p>Let&#8217;s pretend that AGI arrived today. What would happen? The factories and machines needed to automate production do not yet exist.</p><p><strong>Input-output analysis can tell us how a realistic robotics build-out would go.</strong> The standard economist&#8217;s approach is to imagine a planner assigning each industry&#8217;s output either to consumption or to building new capacity, trading off consumption now against faster growth later, according to how much people value each. I have <a href="https://defensesindepth.bio/the-ai-industrial-explosion-part-2-transition-dynamics/">modeled this transition</a> using the 2017 tables at a simplified 71-sector level, under a range of assumptions about those preferences.</p><p><strong>AGI would create an enormous investment opportunity.</strong> In an AGI-enabled world, building robots will be an industry comparable to building cars, and an automated factory costs little more than an ordinary one while needing no workers to run it. Capital would flood in.</p><p><strong>There would be significant competition for the robotics supply chain.</strong> Investors would start outbidding everyone else for machinery and construction workers. Resources that would otherwise be consumed, or spent replacing worn-out equipment, would be used to build new robots, automated factories, and computer chips. In the short run, the prices of physical goods would rise, not fall&#8212;and, because making them would suddenly pay better, idle and underused factories would ramp up production. Plausibly more human workers, not fewer, would crowd into factories while the boom lasted.</p><p><strong>It would take several years for the economy&#8217;s overall production to double.</strong> While the nascent autonomous sector itself would grow rapidly, the starting baseline is low: today&#8217;s economy makes plenty of consumer goods and services, but it has few autonomous robots, and the machine tools needed to build more are themselves in short supply. <a href="https://defensesindepth.bio/the-ai-industrial-explosion-part-2-transition-dynamics/">Electricity generation</a> would grow relatively slowly, since it is already a large part of the economy and requires significant capital to expand. Still, it would double in about four years, and double again in another two. Robot production would follow a similar schedule, from near zero today to tens of millions of units within a few years.</p><p><strong>An industrial explosion would not create instant material abundance.</strong> Despite this tremendous growth, demand for physical goods would take time to satiate. Bringing the whole world to the living standards of a wealthy American would take more than 10 times today&#8217;s physical output&#8212;and that is before counting the goods and services that cheap production would newly make accessible, from custom-built mansions to round-the-clock personal care.</p><p><strong>Natural-resource constraints alone would not prevent an industrial explosion.</strong> The autonomous sector needs no human labor or inputs from the nonautomated economy, and there are minerals enough for economies <a href="https://defensesindepth.bio/ai-industrial-takeoff-part-1-maximum-growth-rates-with-current-technology/">far larger than today&#8217;s</a>. Mining is only about 1% of output, so even large cost increases do little to slow overall growth.</p><p>The one resource that would truly run short is oil; cheap reserves would be exhausted once the economy had grown severalfold. Coal and natural gas could power growth for far longer, but fossil fuel burning is ultimately limited by its climate effects rather than availability. An economy that declined to burn them would electrify, replacing fossil fuels with solar panels, batteries, and nuclear plants. At today&#8217;s production costs, this would slow growth&#8212;<a href="https://defensesindepth.bio/ai-industrial-takeoff-part-1-maximum-growth-rates-with-current-technology/#c3-electrification">with doubling times closer to two years than one</a>&#8212;but not stop it.</p><p>Long before demand or minerals ran short, the assumption of frozen technology would fail. Within a few doublings, AI minds would vastly outnumber human ones, and whatever technology they built would transform production more radically still.</p><h2>What Could Stop an AI Industrial Explosion?</h2><p>US Admiral William D. Leahy assured <a href="https://archive.org/details/yearofdecisionsv030151mbp">President Truman</a> that the atomic bomb &#8220;will never go off, and I speak as an expert in explosives.&#8221; But the viability of a nuclear chain reaction was a question for physicists, not admirals, and the consequences of that physics were no less real for being counterintuitive. So it is with AGI.</p><p><strong>Once physical production is automated, physical output can double every year.</strong> <a href="https://arxiv.org/abs/2309.11690">Objections to explosive growth</a> that do not engage with this data miss the point. <a href="https://www.ebsco.com/research-starters/economics/baumols-cost-disease">Cost disease</a> is real: human services will become expensive relative to manufactured goods, and there are jobs, like babysitting or singing, that we may want humans to keep doing. Neither fact stops physical production from expanding on a scale we have never seen. <a href="https://www.aeaweb.org/articles?id=10.1257/aer.20180338">New research ideas may become harder to find</a>, but that too is beside the point, since the calculation assumes no research at all.</p><p><strong>Nonautomatable production is a limited bottleneck on explosive growth.</strong> More serious reasons to expect slower growth come from the dynamics of the build-out itself. One possibility is that some small set of tasks cannot be automated. This changes the growth dynamics less than you might think, because the workers freed from every other task can supply the missing ones. If humans must still handle one task in 20, then production could grow 20-fold before it needed more workers. By the time the machine economy has grown 20-fold, we will probably have worked out how to automate those final tasks.</p><p><strong>The time taken to integrate AGI may delay an industrial explosion but not stop it.</strong> Technological diffusion&#8212;the lag between a technology working and being used everywhere&#8212;is another potential slowdown, but at worst it delays the explosion rather than stopping it. No one knows whether AGI will arrive in 2030 or 2050; next to that, a few years of diffusion is a rounding error. In any case, the diffusion of AGI workers will look more like the arrival of skilled laborers in the economy than the spread of automobiles or trains. This is particularly true on the software side: generative AI has already been <a href="https://www.nber.org/papers/w32966">adopted faster than the personal computer or the internet</a>, continuing <a href="https://ourworldindata.org/grapher/technology-adoption-by-households-in-the-united-states">several decades of ever-faster technological diffusion</a>.</p><p><strong>Explosive growth may be possible, but we may choose not to allow it.</strong> Regulations will undoubtedly slow deployment. But stopping it entirely is very hard, because an automated economy could be built almost anywhere and the profits would be enormous. If one US state regulates the robots away, the build-out moves next door and the permissive states collect the windfall. If the United States forswears the technology while China does not, China soon commands a vastly larger industrial base. Even if both agreed to stop, they would still have to prevent every other country from importing or developing the requisite robots and AI systems. And the temptation would never fade: a country that allowed the robots would be vastly richer within a few years. Someone would say yes.</p><h2>Power Without People</h2><p>War planners funded Leontief&#8217;s input-output tables to learn how fast industry could be turned into arms. Military power still rests on industrial capacity, and an automated economy would outproduce any rival in every kind of weapon, from artillery shells to drones. It would need no defense workers to build the arsenal, and ever fewer soldiers to wield it. A state with a small population but an autonomous industrial base could field far more firepower than a much more populous state without one. Remove the need for labor, and many countries have raw materials enough for an enormous industrial base. And a two-year head start in a doubling economy means four times the production.</p><p>The same decoupling operates inside states. Governments have always needed their citizens as taxpayers and soldiers, and that need has quietly <a href="https://en.wikipedia.org/wiki/Coercion,_Capital,_and_European_States,_AD_990%E2%80%931992">underwritten political accountability</a>. Horses once worked fields and carried cavalry, before the engine made them surplus; <a href="https://www.nationalacademies.org/read/19470/chapter/3">Leontief famously expected</a> a similar fate for human workers. Citizens who neither supply taxes nor serve as soldiers would lose the hold that they gained from the state&#8217;s dependence on them. Rulers funded by oil wells rather than taxpayers can already afford to ignore their people, and often do. Full automation could make <a href="https://foreignpolicy.com/2026/04/30/petrostates-ai-democracies/">every state a petrostate</a>.</p><p>While this may seem dire, none of it is inevitable. The same machines that build drones can build houses and hospitals, and within a decade or so of full automation, it would be possible to extend the living standards of a wealthy American to every human. Our biggest constraints will be political rather than physical&#8212;there is nothing in the machines themselves that needs to prefer an artillery shell to a dinner plate.</p><p>&#8205;</p><div><hr></div><p><em><strong>See things differently? </strong>AI Frontiers welcomes expert insights, thoughtful critiques, and fresh perspectives. <a href="https://ai-frontiers.org/publish?utm_source=aif_article">Send us your pitch.</a></em></p><div><hr></div><p><em>Damon Binder is a Senior Researcher at Coefficient Giving (formerly Open Philanthropy), where he investigates existential risks from biology and advanced AI. He previously worked at the Future of Humanity Institute, Oxford University, and has a PhD in physics from Princeton.</em></p>]]></content:encoded></item><item><title><![CDATA[An International AI Slowdown Is Ready Whenever Politicians Are]]></title><description><![CDATA[Skeptics of an AI slowdown deal with China say we&#8217;d need futuristic tech to make it cheat-proof. Instead, the US and China could just give auditors comprehensive access to major AI companies.]]></description><link>https://newsletter.ai-frontiers.org/p/an-international-ai-slowdown-is-ready</link><guid isPermaLink="false">https://newsletter.ai-frontiers.org/p/an-international-ai-slowdown-is-ready</guid><dc:creator><![CDATA[AI Frontiers]]></dc:creator><pubDate>Wed, 05 Aug 2026 14:30:49 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!pO55!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F19a220b5-6762-4165-9500-ab51a8309c8e_6320x3160.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong><a href="https://ai-frontiers.org/author/felix-choussat">Felix Choussat</a></strong><span>, Visiting Policy Researcher at the Center for AI Safety</span> and <strong><a href="https://ai-frontiers.org/author/adam-khoja">Adam Khoja</a></strong><span>, Researcher at the Center for AI Safety</span> &#8212; August 5, 2026</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!pO55!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F19a220b5-6762-4165-9500-ab51a8309c8e_6320x3160.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!pO55!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F19a220b5-6762-4165-9500-ab51a8309c8e_6320x3160.jpeg 424w, https://substackcdn.com/image/fetch/$s_!pO55!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F19a220b5-6762-4165-9500-ab51a8309c8e_6320x3160.jpeg 848w, https://substackcdn.com/image/fetch/$s_!pO55!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F19a220b5-6762-4165-9500-ab51a8309c8e_6320x3160.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!pO55!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F19a220b5-6762-4165-9500-ab51a8309c8e_6320x3160.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!pO55!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F19a220b5-6762-4165-9500-ab51a8309c8e_6320x3160.jpeg" width="1456" height="728" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/19a220b5-6762-4165-9500-ab51a8309c8e_6320x3160.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:728,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!pO55!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F19a220b5-6762-4165-9500-ab51a8309c8e_6320x3160.jpeg 424w, https://substackcdn.com/image/fetch/$s_!pO55!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F19a220b5-6762-4165-9500-ab51a8309c8e_6320x3160.jpeg 848w, https://substackcdn.com/image/fetch/$s_!pO55!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F19a220b5-6762-4165-9500-ab51a8309c8e_6320x3160.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!pO55!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F19a220b5-6762-4165-9500-ab51a8309c8e_6320x3160.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>On July 28, over a thousand employees of the world&#8217;s top AI companies <a href="https://www.pacingthefrontier.com/">advocated that</a> the US government &#8220;support an international effort to develop the technical and governance tools needed to deliberately pace the frontier of automated AI development.&#8221; Following months of <a href="https://www.anthropic.com/glasswing">cybersecurity scares</a> and their own <a href="https://openai.com/index/hugging-face-model-evaluation-security-incident/">loss</a> of <a href="https://www.aisi.gov.uk/blog/incident-report-unsanctioned-agent-behaviour-during-cyber-testing">control</a> <a href="https://www.anthropic.com/news/investigating-incidents-cybersecurity-evals">incidents</a>, both <a href="https://x.com/OpenAI/status/2082208694142730340">OpenAI</a> and <a href="https://x.com/AnthropicAI/status/2082228994653696371">Anthropic</a> officially endorsed the same message, recognizing the danger of blindly accelerating AI development.</p><p>Despite this new urgency, many people argue that coordinating an international slowdown is currently unworkable&#8212;including some of the same groups <a href="https://www.anthropic.com/institute/recursive-self-improvement#:~:text=If%20it%20were,in%20this%20deliberation.">in favor</a> of one. Even if the US slowed down its own AI development, it wouldn&#8217;t be able to make sure that China was doing the same, leaving the US <a href="https://situational-awareness.ai/the-free-world-must-prevail/#Maintaining_a_healthy_lead_will_be_decisive_for_safety">no choice but to race</a>.</p><p>These anti-slowdown arguments usually emphasize the technical challenges with designing AI monitoring measures to ensure a slowdown is being respected. For one thing, slowdown skeptics argue that countries would refuse to install verification measures unless they were <a href="https://www.lawfaremedia.org/article/ai-verification--infrastructure-for-prosperity--governance--and-peace">privacy-preserving</a> enough to avoid leaking trade secrets and other sensitive information. Then, the skeptics point out that near-term privacy-preserving verification technology is not yet robust. It would be extremely hard to make sure that China was not undermining whatever monitoring system was watching its GPUs; if the Chinese government were actively trying to subvert a slowdown, it could use <a href="https://arxiv.org/pdf/2506.03409#page=18">advanced techniques</a> to fake workloads, including physical key extraction or even <a href="https://arxiv.org/pdf/2509.07637#page=5">laser bit-flipping</a>. Getting to the point where we can <a href="https://www.iaps.ai/research/verification-for-international-ai-governance">start implementing</a> an international slowdown, the argument goes, might have to wait on <a href="https://arxiv.org/abs/2507.15916">years of R&amp;D</a> to solve these problems.</p><p>This perspective is missing the forest for the trees. Privacy-preserving verification tools that are immune to state adversaries would be nice, but they are not a prerequisite for an AI slowdown. Robustly verifying limits on AI development is completely feasible with low-tech methods: if there were enough political will to implement a joint slowdown, states could extensively monitor labs for unsanctioned behavior by simply placing human inspectors on the inside&#8212;an approach we call <strong>Whole-Lab Inspection (WLI)</strong>.</p><p>Under this proposal, inspectors from the US and China would receive broad physical access to frontier AI companies alongside read-only access to corporate communications, worklogs, code repositories, and compute telemetry. Using monitoring systems the companies already operate, they could observe operations and investigate potential violations&#8212;giving them the visibility of a CISO without requiring the powers of an operator. By literally and figuratively looking over the shoulders of lab employees, inspectors would likely be capable of robustly verifying fine-grained restrictions on AI development, such as bans on autonomous AI R&amp;D and limitations on post-training. WLI would officially make AI companies transparent to auditors from competing nations, though we will later discuss how this arrangement may not be much different from the IP leakage of the status quo. Overall, WLI demonstrates that an international slowdown is already technically possible; it&#8217;s just a question of whether the US and China have the political will to jointly implement it.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ik10!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa901bc21-ffd4-44af-a29f-64d3729d401d_2200x1984.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ik10!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa901bc21-ffd4-44af-a29f-64d3729d401d_2200x1984.jpeg 424w, https://substackcdn.com/image/fetch/$s_!ik10!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa901bc21-ffd4-44af-a29f-64d3729d401d_2200x1984.jpeg 848w, https://substackcdn.com/image/fetch/$s_!ik10!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa901bc21-ffd4-44af-a29f-64d3729d401d_2200x1984.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!ik10!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa901bc21-ffd4-44af-a29f-64d3729d401d_2200x1984.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ik10!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa901bc21-ffd4-44af-a29f-64d3729d401d_2200x1984.jpeg" width="1456" height="1313" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a901bc21-ffd4-44af-a29f-64d3729d401d_2200x1984.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1313,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;__wf_reserved_inherit&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="__wf_reserved_inherit" title="__wf_reserved_inherit" srcset="https://substackcdn.com/image/fetch/$s_!ik10!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa901bc21-ffd4-44af-a29f-64d3729d401d_2200x1984.jpeg 424w, https://substackcdn.com/image/fetch/$s_!ik10!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa901bc21-ffd4-44af-a29f-64d3729d401d_2200x1984.jpeg 848w, https://substackcdn.com/image/fetch/$s_!ik10!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa901bc21-ffd4-44af-a29f-64d3729d401d_2200x1984.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!ik10!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa901bc21-ffd4-44af-a29f-64d3729d401d_2200x1984.jpeg 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>In the near future, political will to implement a slowdown could rapidly appear. If developed and diffused quickly, advanced AI systems are likely to intensely destabilize society by democratizing <a href="https://www.wsj.com/tech/ai/openai-chatbot-biological-weapons-poison-3d808e6c">weapons of mass destruction</a> and fueling waves of unemployment. On top of these threats, allowing an intelligence explosion would risk <a href="https://ai-frontiers.org/articles/ai-deterrence-is-our-best-option">military escalation</a> and <a href="https://www.nationalsecurity.ai/chapter/ai-is-pivotal-for-national-security#loss-of-control">loss of control</a>, as states race to sabotage and deploy powerful AI systems for strategic advantage. Should such intense instability come to pass, if the US slowed down its development domestically and offered a reciprocal audit, China would have a strong incentive to agree.</p><p>In what follows, we&#8217;ll argue that whole-lab inspections can be used to robustly enforce fine-grained limits on AI development. Then, we&#8217;ll speak to the incentives that might encourage the US and China to pursue a joint slowdown at some point using WLI. Finally, we&#8217;ll discuss the stability and risk reduction benefits of a well-timed slowdown.</p><h2>Enforcing a Slowdown Through Whole-Lab Inspections</h2><p>In order to agree to a slowdown, the US and China would need to know what research was being conducted inside each other&#8217;s frontier labs. Fortunately, visibility into AI development could be achieved by sending human auditors to comprehensively monitor labs.</p><p><strong>Auditors could have high visibility into AI companies.</strong> Monitoring for disallowed training runs or prohibited research activities may be largely trivial with human inspectors. In large part, this is because AI companies already have extensive internal monitoring systems. Most AI companies <a href="https://www.reuters.com/sustainability/boards-policy-regulation/meta-start-capturing-employee-mouse-movements-keystrokes-ai-training-data-2026-04-21/">record employee screens and keystrokes</a> to produce training data and help with automation. Companies also constantly <a href="https://www.anthropic.com/news/investigating-incidents-cybersecurity-evals">save logs from experiments</a> and <a href="https://github.com/google-deepmind/xmanager">jobs submitted</a> to keep track of compute use and <a href="https://www.anthropic.com/institute/recursive-self-improvement">archive research progress</a>. Giving inspectors comprehensive visibility into a lab would likely be as simple as integrating and handing over read-only permissions to internal logs and company communications. To aid in their oversight, inspectors might direct a company&#8217;s own AI agents, or trusted external AIs, to read through troves of company data in search of potential violations for further review.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://newsletter.ai-frontiers.org/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://newsletter.ai-frontiers.org/subscribe?"><span>Subscribe now</span></a></p><p>Alongside this digital information, inspectors could also work on-site alongside lab and datacenter employees, giving them physical access to hardware and research projects. Just as for <a href="https://blog.ucs.org/dlochbaum/nrcs-first-line-nuclear-defenders/">nuclear power plants</a>, <a href="https://www.federalreserve.gov/aboutthefed/fedexplained/supervision-regulation.htm">banks</a>, or any other high-risk industry, inspectors would be able to question employees about their work, as well as physically inspect infrastructure by hand for compliance. Armed with such a broad set of simple verification techniques, inspectors could make it extremely difficult to conduct unapproved training runs unnoticed&#8212;like trying to get a plane off a runway without being spotted by an air-traffic controller.</p><p>If WLI were established, governments could then enforce a wide range of policies to slow AI development:</p><p><strong>Preventing an intelligence explosion.</strong> The most dangerous path for AI development to take would be a full-throttle <a href="https://www.nationalsecurity.ai/chapter/ai-is-pivotal-for-national-security#intelligence-recursion">intelligence explosion</a>&#8212;using AIs to autonomously design new, even smarter AI systems recursively. Since AIs can work much faster than humans, and since this process might quickly result in AI systems more capable than their human monitors, it&#8217;s likely that it would become impossible for humans to effectively oversee their AIs or intervene if they misbehave. To prevent this, inspectors could enforce <a href="https://arxiv.org/pdf/2603.03992">targeted interventions</a> designed to specifically restrict autonomous AI R&amp;D, such as by triaging the jobs that are using the most compute and auditing whether they&#8217;re being used for capabilities research. On top of these restrictions, inspectors could limit the length of time that agents are allowed to work autonomously, monitor the amount of compute allocated to internal inference, and prevent AIs from taking high-stakes actions like starting training runs or authorizing new deployments.</p><p><strong>Limits on post-training.</strong> Given the wide range of potential risks from AI, governments might also want to expand training restrictions beyond just interventions against autonomous AI R&amp;D. One natural way to do this would be to place limits on post-training. By measuring the <a href="https://arxiv.org/pdf/2407.21792">increase in capability and efficiency</a> of a model after post-training, inspectors would have clear criteria to disallow the deployment of a model or the kinds of training environments that produced it. Likewise, since inspectors could directly observe which broad capabilities post-training datasets target&#8212;such as coding, computer use, or medical diagnosis&#8212;they could enforce restrictions on the types of capabilities permitted to advance. Whitelisted training domains could include direct safety training to improve AIs&#8217; adversarial robustness or propensity not to misbehave, as well as narrow AI-for-science efforts aimed at prosocial domains like medicine and formally verified code.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!BvWP!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6baa89a-5b54-4e16-a395-b3d1c4b8da38_1580x1236.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!BvWP!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6baa89a-5b54-4e16-a395-b3d1c4b8da38_1580x1236.jpeg 424w, https://substackcdn.com/image/fetch/$s_!BvWP!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6baa89a-5b54-4e16-a395-b3d1c4b8da38_1580x1236.jpeg 848w, https://substackcdn.com/image/fetch/$s_!BvWP!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6baa89a-5b54-4e16-a395-b3d1c4b8da38_1580x1236.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!BvWP!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6baa89a-5b54-4e16-a395-b3d1c4b8da38_1580x1236.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!BvWP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6baa89a-5b54-4e16-a395-b3d1c4b8da38_1580x1236.jpeg" width="1456" height="1139" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d6baa89a-5b54-4e16-a395-b3d1c4b8da38_1580x1236.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1139,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;__wf_reserved_inherit&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="__wf_reserved_inherit" title="__wf_reserved_inherit" srcset="https://substackcdn.com/image/fetch/$s_!BvWP!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6baa89a-5b54-4e16-a395-b3d1c4b8da38_1580x1236.jpeg 424w, https://substackcdn.com/image/fetch/$s_!BvWP!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6baa89a-5b54-4e16-a395-b3d1c4b8da38_1580x1236.jpeg 848w, https://substackcdn.com/image/fetch/$s_!BvWP!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6baa89a-5b54-4e16-a395-b3d1c4b8da38_1580x1236.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!BvWP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6baa89a-5b54-4e16-a395-b3d1c4b8da38_1580x1236.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption"><em>A slowdown regime might allow post-training that improves targeted safety metrics, like adversarial robustness, as long as it does not produce a large increase in capabilities. This differential perspective on AI Safety research is discussed in more detail <a href="https://arxiv.org/pdf/2407.21792">here</a>.</em></figcaption></figure></div><p>Even outside of these interventions, whole-lab inspection would still allow for a variety of potential regulations. Human auditors could be used to ensure, for instance, that specific datacenters are retrofitted to be <a href="https://arxiv.org/pdf/2506.15867#page=120">inference-only</a>, and thus incapable of pre-training, or that <a href="https://www.wsj.com/tech/ai/house-lawmakers-introduce-bipartisan-ai-kill-switch-bill-following-openai-cyber-incident-25c8c178">kill switches</a> can quickly shut down AIs. On its own, joint verification of this kind could be sufficient for <a href="https://ai-2040.com/?choices=plan-a-root">many years of delay</a>, during which the US and China would have ample time to develop more thorough and technically sophisticated verification measures.</p><h2>Joint Verification</h2><p>Whole-lab inspection would be straightforward and effective. If prompted by a domestic political shock, it could likely be rapidly implemented and enforced at home, making it extremely difficult for any company under inspection to conduct unauthorized training runs. In order to extend this initiative internationally, however, the US and China would need to implement joint verification: granting inspectors on-site access to each state&#8217;s frontier labs.</p><p>Thankfully, this agreement would not need to rely on goodwill or trust. Because advanced AI could be globally destabilizing regardless of where it&#8217;s developed, it&#8217;s in each country&#8217;s self-interest to ensure the other is not proceeding recklessly with development. Moreover, if either country refused to accept joint inspection, it would likely struggle to hide its AI projects and insulate them from theft or sabotage.</p><p><strong>The US and China may experience simultaneous political pressure to slow down.</strong> Many of the most pressing risks from advanced AI are symmetric. The development and diffusion of AIs that cause mass unemployment, enable terrorists, or wreak havoc as rogue agents would cause global turmoil regardless of which country created them. Similarly, the fear of <a href="https://newsletter.ai-frontiers.org/p/an-ai-capabilities-gap-can-endanger">military dominance</a> could provoke a risky and wasteful security dilemma, in which retaliatory sabotage spirals into <a href="https://www.aei.org/commentary/how-disruptive-would-a-chinese-invasion-of-taiwan-be/">broader conflict</a>. Therefore, in order to maintain security and stability, the US and China each needs to ensure that the other is not deploying its own AI systems recklessly&#8212;something they would have <a href="https://papers.ssrn.com/sol3/papers.cfm?abstract_id=5067833">no way of assuring</a> in an all-out race.</p><p><strong>AI companies&#8217; trade secrets are easy for states to steal.</strong> Under mutual whole-lab inspection, auditors would have wide access to data about AI development at opposing AI companies, but this wouldn&#8217;t represent much of a change from the status quo. Today, information about model development flows freely between and within frontier labs, as employees constantly churn through roles, <a href="https://tomekkorbak.com/cot-monitorability-is-a-fragile-opportunity/cot_monitoring.pdf">publish research</a>, and put breakthroughs on the <a href="https://www.nytimes.com/2024/07/04/technology/openai-hack.html">company Slack</a>. Even once these obvious holes were sealed, state-proofing AI development against theft would remain enormously difficult. Human insiders&#8212;especially <a href="https://www.nytimes.com/2024/03/22/technology/china-ai-talent.html">Chinese nationals</a> at US frontier labs&#8212;could be <a href="https://www.banks.senate.gov/news/press-releases/senator-banks-raises-concerns-over-chinese-espionage-targeting-u-s-artificial-intelligence-sector/">bribed or coerced into espionage</a>. AI development is also <a href="https://www.rand.org/pubs/research_reports/RRA4685-1.html">inherently vulnerable to cyberattacks</a>, with anything from exploits in networking software to smuggling in spyware through the hardware supply chain offering an opportunity to steal research and models. As a result of these weaknesses, any country that tried to go full-throttle on development would likely quickly find its secrets seeping out of its frontier labs, pulling up its rival to algorithmic parity regardless.</p><p><strong>Compute tracking would make it difficult to hide AI projects.</strong> The remaining priority would be to ensure that there are no large AI projects hidden from inspectors. Fortunately, the AI supply chain is <a href="https://epoch.ai/data/ai-chip-sales?view=graph&amp;tab=h100_equivalents">so concentrated</a>, and chip production so <a href="https://ai-2040.com/supplements/covert-ai-projects#section-2-preventing-covert-compute-procurement">prohibitively hard to hide</a>, that auditing the major semiconductor and chip suppliers would let the US and China confidently measure the number of chips that exist. In practice, monitoring large datacenters could be as straightforward as forcing the leading chip producers to hand over a <a href="https://nacicankaya.substack.com/p/tsmc-most-definitely-has-a-golden">detailed record</a> of their production and sales, <a href="https://ai-2040.com/supplements/verification-plan#:~:text=Carry%20out%20a%20bilateral,this%20compute%20being%20moved.">comparing against</a> the declared compute from the visible projects, and then analyzing satellite imagery and electricity usage as an additional precaution.</p><p>Given the factors above, a global whole-lab inspection initiative could be mutually compatible, low cost, and high confidence&#8212;as long as inspectors are given physical access to frontier labs and datacenters. Even if the US or China refused or later revoked that access, however, AI development could still be slowed unilaterally through deterrence. The global chip supply chain is the most fragile and specialized industry in the entire world: if either country wanted to, it could apply massive friction through <a href="https://ai-frontiers.org/articles/high-bandwidth-memory-critical-gaps-us-export-controls">export</a> <a href="https://www.rand.org/pubs/research_reports/RRA4707-1.html">controls</a> or sabotage of key suppliers. Likewise, countries could <a href="https://www.nationalsecurity.ai/chapter/deterrence-with-mutual-assured-ai-malfunction-maim">disrupt</a> AI training through subtle cyberattacks on training runs, such as by <a href="https://www.aibetrayal.com/">poisoning data</a> to insert malicious backdoors or launching Stuxnet-style <a href="https://openreview.net/pdf/11ed52bf8b9f38c2c23a5b4b847c169808b429f6.pdf#page=5">attacks on GPUs</a>.</p><h2>Benefits of Slowdown</h2><p>Ultimately, the point of a slowdown would be to help society adapt to the risks that rapid development and diffusion of AI would introduce. So far, these risks have been mild enough, and introduced slowly enough, that the <a href="https://www.whitehouse.gov/presidential-actions/2026/06/promoting-advanced-artificial-intelligence-innovation-and-security/">government</a> and <a href="https://www.anthropic.com/glasswing">private industry</a> have been able to reactively address them. By slowing the improvement in general AI capabilities, governments could ensure both that society is able to continue reacting to new risks and that sufficient investments in risk mitigation are made.</p><p><strong>A slowdown would provide time for society to adapt to advanced AI.</strong> If threats from advanced AI appear too quickly&#8212;like the introduction of <a href="https://www.rand.org/pubs/research_reports/RRA4335-1.html">new weapons of mass destruction</a>, or a sudden military confrontation over AI development&#8212;governments will not have time to assess and reactively regulate them, forcing them to rely on <a href="https://www.rand.org/pubs/perspectives/PEA4361-1.html">emergency measures</a>. By proactively slowing down AI development, policymakers, as well as the rest of society, would be able to react to what would have otherwise been seismic shocks. Politically, voters and Congress would be able to decide how the benefits of AI would be distributed, and the degree of transparency AI developers owe the public. Internationally, states would be able to prepare for the introduction of <a href="https://www.foreignaffairs.com/united-states/artificial-intelligence-end-mutual-assured-destruction">powerful new military technologies</a> before they arrive and invest in more robust verification measures.</p><p>In this sense, a mild amount of government intervention early on would avoid the need for massive overreach later, keeping the pace of AI development at a level society can react to.</p><p><strong>The time bought by a slowdown could be used to invest directly in risk mitigation.</strong> Without the intense pressure to race and increase general capabilities, investment could instead be diverted into ensuring that AI systems are controllable and that they are developed for prosocial causes. Key open problems in AI safety, for example, include the <a href="https://www.researchgate.net/publication/396458907_The_Attacker_Moves_Second_Stronger_Adaptive_Attacks_Bypass_Defenses_Against_Llm_Jailbreaks_and_Prompt_Injections">lack of robust solutions to jailbreaking</a> and the propensity for reinforcement learning to <a href="https://arxiv.org/pdf/2511.18397">encourage models to go rogue</a>&#8212;issues that will likely produce disastrous results if unresolved when models are more capable. By scaling up training in domains like adversarial robustness and behavioral propensity, AI developers could spend huge amounts of compute <a href="https://www.anthropic.com/research/constitutional-classifiers">driving down jailbreak susceptibility</a> and attempts to escape. Other safety measures could include aggressively sandboxing AI systems, such as with fully airgapped training setups, or preserving and expanding <a href="https://www.alignmentforum.org/posts/StENzDcD3kpfGJssR/a-pragmatic-vision-for-interpretability">practical interpretability</a> tools.</p><h2>An AI Slowdown Does Not Require New Technology</h2><p>Slowing down AI development doesn&#8217;t need to wait on any breakthroughs. On the technical level, whole-lab inspections could be a robust and flexible way to monitor whether frontier labs are complying with restrictions on the most dangerous kinds of development. Human auditors, reading through worklogs and standing on the floor next to the people recording them, could verify nuanced restrictions on autonomous AI R&amp;D and post-training without needing a single new invention.</p><p>From there, a global slowdown is just a question of political will&#8212;one which has been convincingly answered before. By the end of the 1980s, having <a href="https://en.wikipedia.org/wiki/Stanislav_Petrov">stared into the abyss</a> during the peak of the nuclear arms race, even the US and the Soviet Union came to recognize the need for mutual disarmament. For <a href="https://en.wikipedia.org/wiki/Intermediate-Range_Nuclear_Forces_Treaty">more</a> <a href="https://en.wikipedia.org/wiki/START_I">than</a> <a href="https://carnegieendowment.org/posts/2020/05/the-new-start-verification-regime-how-good-is-it">two decades</a>, even during years as fraught as the collapse of the Soviet Union itself, this was achieved by simply allowing Russian and American inspectors to walk into each other&#8217;s military bases and count warheads by hand.</p><p>Likewise, the US and China may soon realize that averting disaster at home will depend on verifying development abroad. If inspectors could count nuclear warheads in Siberia and North Dakota, they can certainly check worklogs in Silicon Valley and Shenzhen. We do not need better technology to verify a slowdown&#8212;only shared risks serious enough to demand one.</p><p><em>Special thanks to Dan Hendrycks for suggesting the premise of whole-lab inspection.</em></p><p>&#8205;</p><div><hr></div><p><em><strong>See things differently? </strong>AI Frontiers welcomes expert insights, thoughtful critiques, and fresh perspectives. <a href="https://ai-frontiers.org/publish?utm_source=aif_article">Send us your pitch.</a></em></p><div><hr></div><p><em>Felix Choussat researches the geopolitics of advanced AI at the Center for AI Safety (CAIS), focusing on Sino-US competition and emerging military technology. Prior to his current role at CAIS, he was a governance fellow through the ML Alignment and Theory Scholars (MATS) and Pivotal Research programs, where he worked on modeling the proliferation of WMD-capable systems and compute-based AI deterrence. He holds a dual degree in international relations and history studies from Vanderbilt University.</em></p><p><em>Adam Khoja does technical and policy research at the Center for AI Safety. He studied math and computer science at UC Berkeley.</em></p><p></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://newsletter.ai-frontiers.org/p/an-international-ai-slowdown-is-ready?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://newsletter.ai-frontiers.org/p/an-international-ai-slowdown-is-ready?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p>]]></content:encoded></item><item><title><![CDATA[AI Jailbreak Disclosure Is Broken. Here’s How to Fix It]]></title><description><![CDATA[Researchers who find dangerous flaws in frontier models have nowhere safe to report them. AI needs the disclosure system that cybersecurity built decades ago.]]></description><link>https://newsletter.ai-frontiers.org/p/ai-jailbreak-disclosure-is-broken</link><guid isPermaLink="false">https://newsletter.ai-frontiers.org/p/ai-jailbreak-disclosure-is-broken</guid><dc:creator><![CDATA[AI Frontiers]]></dc:creator><pubDate>Mon, 03 Aug 2026 16:31:01 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!solH!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6681be17-475e-46d5-b069-200871b70d73_3897x1677.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong><a href="https://ai-frontiers.org/author/rich-barton-cooper">Rich Barton-Cooper</a></strong><span>, Research Manager at MATS</span> and <strong><a href="https://ai-frontiers.org/author/adam-gleave">Adam Gleave</a></strong><span>, CEO of FAR.AI</span> &#8212; August 3, 2026</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!solH!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6681be17-475e-46d5-b069-200871b70d73_3897x1677.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!solH!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6681be17-475e-46d5-b069-200871b70d73_3897x1677.jpeg 424w, https://substackcdn.com/image/fetch/$s_!solH!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6681be17-475e-46d5-b069-200871b70d73_3897x1677.jpeg 848w, https://substackcdn.com/image/fetch/$s_!solH!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6681be17-475e-46d5-b069-200871b70d73_3897x1677.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!solH!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6681be17-475e-46d5-b069-200871b70d73_3897x1677.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!solH!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6681be17-475e-46d5-b069-200871b70d73_3897x1677.jpeg" width="3897" height="1677" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6681be17-475e-46d5-b069-200871b70d73_3897x1677.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1677,&quot;width&quot;:3897,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1369179,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!solH!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6681be17-475e-46d5-b069-200871b70d73_3897x1677.jpeg 424w, https://substackcdn.com/image/fetch/$s_!solH!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6681be17-475e-46d5-b069-200871b70d73_3897x1677.jpeg 848w, https://substackcdn.com/image/fetch/$s_!solH!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6681be17-475e-46d5-b069-200871b70d73_3897x1677.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!solH!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6681be17-475e-46d5-b069-200871b70d73_3897x1677.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Frontier AI developers deploy significant safeguards to prevent their AI models from being misused. However, these safeguards are not robust: AI researchers consistently find techniques for circumventing them, commonly known as &#8220;jailbreaks.&#8221; Once companies learn about a jailbreak, they can usually implement a fix; yet AI researchers currently lack a safe and reliable way to inform AI companies about the jailbreaks they&#8217;ve discovered. We propose concrete improvements to the current system based on cybersecurity norms of responsible disclosure.</p><p>Addressing this problem is urgent. Frontier AI models are already being abused by malicious actors: terrorist group Boko Haram is <a href="https://casp.ac/reports/ai-enabled-terrorism">reported</a> to be training its members on jailbreaking techniques in order to troubleshoot weapons, design new explosive devices, and plan attacks. Some former Boko Haram members stated an unequivocal willingness to use chemical or biological weapons&#8212;a task jailbroken models may already be able to <a href="https://www.nytimes.com/2026/04/29/us/ai-chatbots-biological-weapons.html">help with</a> <a href="https://www.wsj.com/tech/ai/openai-chatbot-biological-weapons-poison-3d808e6c">today</a>. With model capabilities continuing to rapidly accelerate&#8212;including in <a href="https://huggingface.co/blog/security-incident-july-2026">offensive</a> <a href="https://cybelangel.com/blog/jadepuffer-6-things-to-know-about-the-first-ai-driven-ransomware-operation/">cyber</a>, where jailbreaks have <a href="https://www.helpnetsecurity.com/2026/07/16/jailbroken-google-gemini-cli-botnet/">already been employed by Russian cybercriminals</a>&#8212;the stakes for AI misuse are escalating with every model release.</p><p><strong>Universal jailbreaks affect even the most advanced models.</strong> Of particular concern are universal jailbreaks&#8212;jailbreaks which consistently break through safeguards across a wide variety of harmful queries. These have been found even in the most advanced models, the most recent of which <a href="https://x.com/alxndrdavies/status/2075279477626564933?s=20">elicited cyberattack assistance from OpenAI&#8217;s flagship model, GPT-5.6 Sol</a>. <a href="https://leaderboard.far.ai/">Research</a> by one of the authors found tens to hundreds of universal jailbreaks in two out of four frontier models using combinations of simple, publicly available techniques. More limited jailbreaks aimed at high-risk domains are still dangerous: an alleged narrow cyber jailbreak led to the <a href="https://www.anthropic.com/news/fable-mythos-access">US Government shutting down access to Claude Fable 5</a> just days after launch.</p><p><strong>External researchers need effective reporting channels.</strong> It is therefore a critical matter of public safety that model safeguards are tested extensively both pre- and post-deployment. In order to find and fix safeguard vulnerabilities at scale, frontier labs must provide effective channels to allow external researchers to contribute. Any jailbreak must be able to be reported quickly and safely to its developer and fixed as a matter of urgency. Additionally, the existence of jailbreaks should be disclosed to policymakers, as well as users of these systems and the wider public when it is safe to do so.</p><p>Yet currently there is often no way for third-parties to report jailbreaks to developers; most reporting mechanisms that do exist require overly broad NDAs; and developers self-grade submissions according to opaque rubrics.</p><p>We propose a two-tiered solution to address these deficiencies, drawing on established disclosure practices in cybersecurity. As soon as possible, developers should implement public reporting mechanisms for jailbreaks and share a rubric for how they evaluate jailbreak severity. In the medium term, we propose establishing a third-party clearinghouse to take in jailbreak submissions, evaluate them, disseminate the vulnerability to affected parties, and coordinate reasonable disclosure for the researcher following a fix. Together, these mechanisms will allow jailbreaks to be reported to developers for them to fix while preserving transparency.</p><h2>There Is No Good Way to Report Jailbreaks</h2><p>Sadly, the ecosystem for reporting jailbreak vulnerabilities is poorly set up for the task today. There are three main problems with the current regime. First, many vendors offer no official way to report jailbreaks. Second, where vendors do offer programs, the programs almost universally involve NDAs so restrictive they indefinitely prevent disclosure of the vulnerability to governments or other developers. Finally, the developers self-grade the severity of jailbreaks using opaque rubrics that are inconsistent between developers&#8212;a top-severity vulnerability with one developer might barely raise an eyebrow with another.</p><p><strong>Independent researchers face tangled NDAs and legal risk.</strong> This means that independent researchers who find jailbreaks and wish to report them responsibly find themselves in an unfavorable position, as author Rich Barton-Cooper has personally experienced. They will be faced with inconsistent disclosure channels across frontier labs, tangled NDAs which suppress public disclosure of vulnerabilities, and opaque internal evaluation of their work by labs incentivized to downplay the severity of their findings. Additionally, researchers may not feel safe to disclose at all: probing for harmful outputs violates developers&#8217; usage policies, and <a href="https://www.law.cornell.edu/wex/safe_harbor">safe-harbor protections</a> may not clearly apply since jailbreaks are often explicitly excluded from standard security channels.</p><p><strong>Institutional standing offers little advantage.</strong> Even established organizations are hampered by the status quo. One of the authors, Adam Gleave, leads <a href="http://far.ai">FAR.AI</a>, an AI safety non-profit that conducts pre-deployment testing for many frontier model developers and has numerous personal contacts with other developers. Even with this institutional standing, the experience is uneven: labs listen, but contest severity, set safeguard update timelines unilaterally, and provide no guarantee that they will act on a given finding.</p><h2>Current Reporting Mechanisms Are Limited</h2><p>OpenAI and Anthropic are the only frontier model vendors to provide any concrete jailbreak reporting routes. For chemical, biological, radiological, and nuclear (CBRN) weapon-related outputs, both run bug-bounty programs (<a href="https://openai.com/index/bio-bug-bounty/">OpenAI</a>, <a href="https://www.anthropic.com/news/testing-our-safety-defenses-with-a-new-bug-bounty-program">Anthropic</a>). However, a researcher must be accepted, sign an NDA, and submit into a channel that grades against an unseen rubric and permits no external disclosure without express consent.</p><p><strong>Outside bounty programs, there is no safe disclosure method.</strong> A researcher not accepted onto a bounty program, or unwilling to be permanently silenced, has nowhere to safely disclose a CBRN jailbreak directly to developers. A powerful jailbreak is not safe to disclose openly, for example via social media, because bad actors could use it to harvest dangerous information from affected models before it is patched. Developers also frequently do not provide a clear means to route a jailbreak to the right teams; in our experience, personal outreach to contacts working on such teams has been necessary to draw attention to findings, which is not an option accessible to the wider research community.</p><p>These problems play out differently across harm domains: Anthropic runs a locked-down program for CBRN but an open, disclosure-friendly channel for cyber. What separates them appears not to be the severity of the risk, but the strength of external pressure. When Fable 5&#8217;s cyber capabilities reportedly prompted the US government to suspend access to the model within days of launch, Anthropic was acutely incentivized to <a href="https://www.anthropic.com/news/redeploying-fable-5">demonstrate a credible cyber disclosure process</a> and has recently established an uncompensated <a href="https://hackerone.com/anthropic-cyber-jailbreak?type=team">Cyber Jailbreak disclosure program</a> for jailbreaks targeting Fable 5. This program is markedly more transparent than usual: anyone can submit without an NDA, findings may be publicly disclosed once timing is coordinated with Anthropic, and researchers are explicitly free to report the same jailbreak to other affected vendors. But that channel is narrow: we would be excited to see Anthropic launch an analogous channel for CBRN and other jailbreak categories, and for other developers to follow suit.</p><p><strong>Most labs exclude jailbreaks from disclosure programs entirely.</strong> The situation is much worse elsewhere: other labs, including <a href="https://bughunters.google.com/about/rules/google-friends/ai-vulnerability-reward-program-rules">Google DeepMind</a>, <a href="https://hackerone.com/x">SpaceXAI</a> (formerly xAI), and <a href="https://bugbounty.meta.com/en-gb/scope/">Meta</a>, explicitly exclude jailbreaks and model content issues from the scope of vulnerability disclosure programs, if they exist at all. Instead these programs focus on more-traditional cybersecurity issues, such as company data exfiltration, accessing other users&#8217; accounts, or authentication flaws. The <a href="https://futureoflife.org/">Future of Life Institute</a> (FLI), an independent non-profit that has graded frontier developers&#8217; safety practices since 2024 through a panel of external AI and governance experts, recently released their widely cited <a href="https://futureoflife.org/ai-safety-index-summer-2026/#scorecard">Summer 2026 Safety Index</a> which explored each company&#8217;s approach to responsible disclosure and bug bounties. The FLI judged that the leading labs&#8212;OpenAI, Anthropic, and Google DeepMind&#8212;all score a C+ in the Risk Assessment category, which translates to &#8220;uneven validity or elicitation&#8221; and &#8220;little external input.&#8221; Meta and SpaceXAI score D+ and D- respectively.</p><p><strong>Google&#8217;s in-product reporting system is flawed.</strong> Google has <a href="https://bughunters.google.com/blog/announcing-googles-new-ai-vulnerability-reward-program#reporting-prompt-injections-jailbreaks-and-alignment-issues">stated</a> they don&#8217;t believe that disclosure programs for jailbreaks are the right solution, given fixing such issues &#8220;requires long-term, cross-disciplinary efforts&#8221; and instead choose to rely on reporting mechanisms built into their product. (We contest the claim that these fixes require long-term effort, as <a href="https://arxiv.org/abs/2411.07494">some methods</a> enable defenders to block a whole class of jailbreaks with a few examples.) We tried out these mechanisms. The first is a &#8220;thumbs-down&#8221; of the response in which you can choose to label the content as &#8220;Offensive/Unsafe&#8221;, or &#8220;Took a harmful action.&#8221; There is no acknowledgement of receipt, and no means to track that action will be taken. Another in-product option is to report a legal issue, explaining why the content was unlawful in the user&#8217;s country. In this case, they explicitly state that &#8220;completing and submitting this form does not guarantee that any action will be taken.&#8221; Neither of these channels is appropriate for disclosing high-severity, highly detailed universal CBRN content: there is no way to describe the jailbreak method rather than specific model responses, and no guarantee of response from the vendor.</p><p>At SpaceXAI, the story is similar: their <a href="https://hackerone.com/x">bounty program</a> states that &#8220;model issues are out of scope for this program and should be reported through <a href="mailto:safety@x.ai">safety@x.ai</a>.&#8221; In October 2025, Barton-Cooper reported a universal jailbreak through this email address containing screenshots of several egregiously harmful model responses&#8212;including redacted evidence of clear, step-by-step guidance on building a massively destructive chemical weapon&#8212;and did not receive anything other than an automated response in return.</p><h2>Fear of Liability May Incentivize Vendors to Ignore Reports</h2><p>This silence may reflect more than under-resourced safety teams or disorganization. As far back as 2024, <a href="https://www.lawfaremedia.org/article/tort-law-and-frontier-ai-governance">legal scholars have warned</a> that tort liability fears can deter a developer from documenting the risks its models pose, since &#8220;creating such a record might later help plaintiffs establish negligence.&#8221; A lab therefore has a perverse incentive to leave a jailbreak report unacknowledged. Liability is demonstrably a concern: in April 2026, <a href="https://www.wired.com/story/openai-backs-bill-exempt-ai-firms-model-harm-lawsuits/">OpenAI testified in support of SB 3444</a>, a bill which seeks to limit liability for mass harm traceable to frontier AI. Following public backlash and <a href="https://www.wired.com/story/anthropic-opposes-the-extreme-ai-liability-bill-that-openai-backed/">Anthropic lobbying against the bill from the start</a>&#8212;with a spokesperson calling it a &#8220;get-out-of-jail-free card against all liability&#8221;&#8212;<a href="https://x.com/ShakeelHashim/status/2055273081262752192?s=20">OpenAI later walked back their support</a>. In a world where labs are disincentivized to accept unsolicited jailbreak reports due to liability concerns, users who find effective jailbreaks are forced into bug bounty programs where they can be effectively silenced by NDA.</p><h2>Established Channels Are Often Covered by Powerful NDAs</h2><p>Although we applaud <a href="https://openai.smapply.org/prog/gpt-5-5-safety-bio-bounty-program/">OpenAI</a> and <a href="https://support.claude.com/en/articles/12119250-model-safety-bug-bounty-program">Anthropic</a> for soliciting model testing through their bug bounty programs, we believe these channels are insufficient as a reporting mechanism. Both programs are covered by NDAs that restrict all findings submitted through these channels. Jailbreakers are left with two undesirable options: either indefinitely lock up their findings, or&#8212;as many jailbreakers choose&#8212;publish their findings on <a href="https://x.com/elder_plinius/status/2064776322979676227">X</a>.</p><p><strong>NDAs erode hard-won disclosure norms.</strong> This is not a failure unique to AI: in cybersecurity, <a href="https://www.usenix.org/conference/usenixsecurity25/presentation/albert">legal scholars have documented</a> how the recent proliferation of NDAs in bug bounties has begun to erode hard-won coordinated disclosure norms&#8212;a move the security research community <a href="https://www.csoonline.com/article/569201/bug-bounty-platforms-buy-researcher-silence-violate-labor-laws-critics-say.html">has criticized</a>. Katie Moussouris, who built Microsoft&#8217;s first bug bounty and helped establish coordinated disclosure as an industry norm, <a href="https://www.lutasecurity.com/post/bug-bounty-evolution-not-your-grandson-s-bug-bounty">says</a>: &#8220;Why would anyone ever sign an NDA for the privilege of telling an organization what&#8217;s wrong with them, especially when they may not get paid for their work?&#8221; It appears that AI labs have adopted this diminished ecosystem of indefinite legally binding prohibitions of disclosure, rather than building on the better coordinated disclosure protocols of the past. Under previous norms, researchers entered into a <a href="https://cheatsheetseries.owasp.org/cheatsheets/Vulnerability_Disclosure_Cheat_Sheet.html#responsible-or-coordinated-disclosure">limited embargo period</a> of a few months in order to give the organization time to fix the vulnerability before publishing. Findings could still be shared privately with affected parties during this time.</p><p><strong>Current NDAs protect lab reputations more than the public.</strong> NDAs help address a serious risk: if a researcher discloses jailbreaks to the public before the company has time to fix them, then a bad actor may use those jailbreaks to cause serious harm. Yet current NDAs appear to go beyond sensible handling of such risks, and in practice do more to safeguard the reputation of individual labs than to protect the public from harm. <a href="https://support.claude.com/en/articles/12119250-model-safety-bug-bounty-program">Anthropic&#8217;s program bars participants</a> from disclosing &#8220;any jailbreaks/vulnerabilities (even resolved ones) outside of the Program without express consent&#8221; and <a href="https://openai.smapply.org/prog/gpt-5-5-safety-bio-bounty-program/">OpenAI similarly states</a> that &#8220;All prompts, completions, findings, and communications are covered by NDA.&#8221; Additionally, cross-lab disclosure is legally ambiguous under these NDAs: a universal jailbreak which transfers across vendors does not seem to be clearly permitted to be disclosed beyond the first vendor. This means that the most potent cross-model jailbreaks submitted under bug bounty programs cannot automatically be disseminated across all affected parties today. The net effect is that the true extent of misuse risks and how quickly vendors are responding to them remain opaque to both policymakers and the public.</p><h2>Labs Grade Jailbreaks Without Oversight</h2><p>To make matters worse, jailbreak severity is graded by the labs themselves, often following non-public rubrics. This inevitably leads to uneven safeguards between developers, creating an inconsistent patchwork of protections. Furthermore, developers are incentivized to understate severity: developers like to boast of their models withstanding third-party red-teaming, and so acknowledging a successful universal jailbreak submission is reputationally harmful in a world increasingly waking up to misuse risk. Together the uneven landscape and incentives to downplay issues obscure the true picture of jailbreak risks.</p><p><strong>A shared severity framework is beginning to emerge.</strong> Clarity can only come through a standardized assessment framework and timely publication of jailbreak incidents. Anthropic&#8212;in collaboration with Amazon, Microsoft, Google, and Project Glasswing partners&#8212;recently <a href="https://www.anthropic.com/news/fable-safeguards-jailbreak-framework">published</a> a Cyber Jailbreak Severity (CJS) framework following governmental intervention with Fable 5. We support this initiative, and call for other frontier vendors to coordinate on this work, both in cyber and other catastrophic risk domains.</p><h2>The System Today Looks Increasingly Fragile</h2><p>Anthropic has <a href="https://www-cdn.anthropic.com/dc4cb293c77da3ca5e3398bdeef75ee17b42b73f.pdf">previously written</a> that the absence of legitimate, well-compensated disclosure channels is itself a risk: without them, a malicious researcher may have an incentive to sell a jailbreak on a black market rather than informing the affected lab. Dissatisfied researchers are a second failure mode: when disclosure mechanisms break down or are not fit for purpose, some will publish vulnerabilities publicly anyway, whether to gain attention, in retaliation, or to force a rapid fix. The <a href="https://techcrunch.com/2026/05/29/microsoft-under-fire-for-threatening-security-researcher-with-criminal-investigation/">recent public disclosure of six Microsoft vulnerabilities by an independent cybersecurity researcher</a> is a stark reminder of what happens when vendors overreach with legal threats or renege on good-faith commitments. There are perhaps early signs of this dynamic in the jailbreaking community: <a href="https://news.ycombinator.com/item?id=47901734">Hacker News reactions to the recent GPT-5.5 Bio Bug Bounty</a> were largely critical, with users objecting that the NDA silences participants, that signed participants have no recourse if their submission is rejected, and that everyone outside the program has no responsible route to disclose. Capable red-teamers may already be opting out; as one user posted: &#8220;This is very much within my areas of interest, but signing an NDA in this area is a lot to ask.&#8221;</p><h2>Proposals for Better Disclosure Practices</h2><p>We propose two complementary strategies for improving the external jailbreaking ecosystem. The first set of measures can be easily implemented today by individual frontier labs. The second is a longer-term vision to coordinate model vulnerability submissions via an independent third-party organization which disseminates jailbreak information, including standardized severity metrics, to the affected labs.</p><p>Today, we call on frontier developers to implement four measures.</p><p><strong>Appropriately scoped NDAs.</strong> NDAs for acceptance onto red-teaming programs should cover disclosure of harmful model outputs and full prompts, but allow researchers to publicize their work at a high level after a fix has been implemented or a responsible disclosure period has elapsed. They should also contain carve-outs for notifying governmental institutions and for cross-lab submissions of jailbreaks affecting multiple model families.</p><p><strong>A publicly disclosed rubric.</strong> Developers should publish a rubric for what qualifies as a high-severity jailbreak, in sufficient detail that a domain expert (in e.g. cybersecurity or biosecurity) could determine if a submission meets these criteria. This rubric should draw on standards, whether formal or industry best-practices, where they exist (e.g. <a href="https://securebio.org/biotier/">BioTIER</a>). If submissions are graded by the developer themselves, an appeals process should ideally be available for an independent expert to assess jailbreak submissions against this rubric&#8212;with overrides requiring leadership sign-off and appearing in published aggregate statistics, so systematic under-grading carries a reputational cost.</p><p><strong>Year-round disclosure pathways.</strong> Disclosure pathways&#8212;e.g. bounty programs&#8212;should operate year-round and cover jailbreaks across a wide array of harms, including both CBRN and cyber, rather than short one- or two-month windows targeting very specific attack vectors or AI products.</p><p><strong>Regular cross-vendor sharing of jailbreak data and mitigations.</strong> Vendors should routinely share jailbreak data and mitigation best practices&#8212;for example, sharing datasets to improve safeguard robustness and performance (similar to <a href="https://arxiv.org/abs/2504.17792">sharing of autonomous vehicle crash data</a>). The Frontier Model Forum has brokered <a href="https://www.frontiermodelforum.org/updates/fmf-announces-first-of-its-kind-information-sharing-agreement/">an information-sharing agreement</a> to facilitate this practice with its member firms, including Anthropic, OpenAI, and Google DeepMind. We ask for this channel to be strongly utilized, with information on the extent of utilization to be made publicly available.</p><p>In the medium-term, we believe these measures are best mediated by a third-party organization handling coordination and dissemination of model vulnerability submissions. Such an organization could perform four functions.</p><p><strong>Take in submissions.</strong> The organization would accept post-deployment reports from users and external researchers year-round, handling secure <a href="https://www.swift.com/risk-and-compliance/know-your-customer-kyc">know-your-customer</a> accreditation and appropriate NDA restrictions (as above) for all submitters.</p><p><strong>Grade them consistently.</strong> It would assess severity against a standardized rubric built with input from all frontier labs, partnering with external specialists to validate model outputs that appear to pass it.</p><p><strong>Coordinate the fix and the disclosure.</strong> It would notify all affected labs and relevant government entities simultaneously under a limited embargo that allows reasonable time to fix, and broker mitigation-sharing between labs&#8212;e.g. by securely hosting shared datasets for classifier training.</p><p><strong>Reward, credit, and report.</strong> Once the embargo ends, it would support submitters in publicly disclosing their work with attribution, reward them with a bounty funded by participating labs, and publish aggregate statistics&#8212;jailbreak frequency, severity, and time-to-fix per model&#8212;so the public and policymakers can see the true state of frontier model security.</p><p><strong>Cybersecurity built this model decades ago.</strong> This is a model established decades ago in cybersecurity. Since 1988, the Software Engineering Institute&#8217;s Computer Emergency Response Team Coordination Center (<a href="https://www.kb.cert.org/vuls/">CERT/CC</a>) has accepted reports of vulnerabilities, brokered fixes across affected vendors, and facilitated disclosure embargoes with published advisories once fixes have been deployed. No single vendor owns the vulnerability or can suppress the finding indefinitely. Coordinated disclosure was a <a href="https://securityboulevard.com/2025/11/legal-restrictions-on-vulnerability-disclosure/">hard-won compromise</a> following extensive tug-of-war between researchers and vendors. It is the standard the AI vulnerability ecosystem should be reaching for instead of the NDA-bound bug bounties eroding more transparent norms.</p><p><strong>Early steps toward an AI clearinghouse already exist.</strong> Such machinery may already be beginning to extend to AI: in July 2026, a coalition of researchers from MIT, Stanford, Princeton, Harvard, Northeastern and Carnegie Mellon released <a href="https://www.ai-reports.org/">FLARE-AI</a>, an open-source tool that routes vulnerability submissions directly into CERT/CC&#8217;s coordination process. The project is early-stage and depends on labs choosing to engage&#8212;though the same liability and regulatory pressures now bearing on cyber disclosure give them growing reason to. It is a concrete first step towards the third-party institution described above.</p><p><strong>Researchers, labs, and the public all stand to gain.</strong> Such measures, however they are implemented, carry significant advantages for all parties involved. External researchers would gain a known, trusted, and unified channel for reporting; public credit for their work; clearer boundaries on what they can publish and when; and transparent grading of their submissions. Model providers gain broader vulnerability coverage, increased likelihood of being notified of vulnerabilities post-deployment before a preventable incident occurs, structured cross-lab mitigation sharing for rapid response, and decreased PR fragility around eventual disclosure outside of trusted channels. Regulators and the public gain an independent ground truth on the security of deployed frontier models, an institutional basis for mandatory fix timelines, transparent visibility into a class of risks that are currently controlled by individual labs, and comparable public benchmarks of safeguard robustness across providers.</p><p><strong>Others have made similar calls.</strong> Measures to improve jailbreak disclosure are important, and we are certainly not the first to call for them. Other organizations whose proposals overlap with ours include <a href="https://www.cnas.org/publications/cnas-insights/cnas-insights-governing-jailbreak-incidents">the Center for a New American Security</a>, <a href="https://www.frontiermodelforum.org/issue-briefs/information-sharing-incident-reporting-and-incident-response-for-frontier-ai-risks/">the Frontier Model Forum</a>, <a href="https://www.guidelight.ai/transparency">Guidelight</a>, and <a href="https://securebio.substack.com/p/preparing-for-the-bio-mythos-moment">SecureBio</a>.</p><h2>Relevant Parties Should Act Now</h2><p>Frontier developers have made significant progress on model safeguards and robustness, but this will only pay off if the vulnerabilities that still slip past are reported and fixed. Today this is hampered by a reporting ecosystem poorly suited to the task. Improving this requires no technical breakthrough, but rather coordination and the will to act before the next crisis rather than after.</p><p><strong>Labs, third parties, and standards bodies each have a role.</strong> So we ask each party to take the next step. Frontier labs should commit to a publicly available, year-round, paid disclosure mechanism with greater transparency, sharing of jailbreak data through <a href="https://www.frontiermodelforum.org/updates/fmf-announces-first-of-its-kind-information-sharing-agreement/">info-sharing agreements</a>, and signal that they will join a shared severity framework if their competitors do the same. Independent third parties should build the coordination layer that lets an external researcher submit once and reach every affected party, and publish aggregate metrics relevant to model security. Industry and government standards bodies should turn today&#8217;s lab-led severity discussions into a single standard that no individual vendor controls, and that can be applied both internally and externally.</p><p>The alternative is to keep improvising until a vulnerability that better disclosure would have surfaced is exploited in an attack instead. The path is not easy, but it is clear&#8212;and, unusually for the problems AI poses, within reach.</p><p><em>This essay was written in Rich&#8217;s personal capacity. All opinions are the authors&#8217; own.</em></p><p>&#8205;</p><div><hr></div><p><em><strong>See things differently? </strong>AI Frontiers welcomes expert insights, thoughtful critiques, and fresh perspectives. <a href="https://ai-frontiers.org/publish?utm_source=aif_article">Send us your pitch.</a></em></p><div><hr></div><p><em>Rich Barton-Cooper is a Research Manager at MATS Research, an AI Safety research non-profit, where he has published research on AI monitoring and control. He has extensive experience in redteaming frontier AI systems, having identified high-severity universal jailbreaks across multiple model families.</em></p><p><em>Adam Gleave is the CEO of FAR.AI, a non-profit research institute dedicated to making advanced AI systems trustworthy and secure. FAR.AI&#8217;s red-team conducts pre-deployment testing for developers including OpenAI and post-deployment testing on behalf of governments including the EU AI Office, and has discovered universal jailbreaks in models from all frontier developers. Adam&#8217;s own research has identified scaling laws for robustness, and found adversarial examples in robotics and superhuman Go AIs. Prior to founding FAR.AI, Adam completed his PhD in AI at UC Berkeley and briefly worked at Google DeepMind. Outside of FAR.AI, Adam is an expert on the EU AI Act&#8217;s Scientific Panel; and a board member of METR, LISA and SAIF.</em></p>]]></content:encoded></item><item><title><![CDATA[Don’t Let AI Developers Hire Their Own Referees]]></title><description><![CDATA[Letting AI developers pick their own safety auditors creates a conflict of interest. Requiring liability insurance instead would put insurers&#8217; own capital behind risk assessments.]]></description><link>https://newsletter.ai-frontiers.org/p/dont-let-ai-developers-hire-their</link><guid isPermaLink="false">https://newsletter.ai-frontiers.org/p/dont-let-ai-developers-hire-their</guid><dc:creator><![CDATA[AI Frontiers]]></dc:creator><pubDate>Wed, 29 Jul 2026 13:30:17 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!d0lK!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F332a9a87-95fa-490f-83d1-9c8564d97b4e_8000x3546.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong><a href="https://ai-frontiers.org/author/gabriel-weil">Gabriel Weil</a></strong><span>, Professor at the University of Houston Law Center</span> &#8212; July 29, 2026</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!d0lK!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F332a9a87-95fa-490f-83d1-9c8564d97b4e_8000x3546.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!d0lK!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F332a9a87-95fa-490f-83d1-9c8564d97b4e_8000x3546.jpeg 424w, https://substackcdn.com/image/fetch/$s_!d0lK!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F332a9a87-95fa-490f-83d1-9c8564d97b4e_8000x3546.jpeg 848w, https://substackcdn.com/image/fetch/$s_!d0lK!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F332a9a87-95fa-490f-83d1-9c8564d97b4e_8000x3546.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!d0lK!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F332a9a87-95fa-490f-83d1-9c8564d97b4e_8000x3546.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!d0lK!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F332a9a87-95fa-490f-83d1-9c8564d97b4e_8000x3546.jpeg" width="1456" height="645" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/332a9a87-95fa-490f-83d1-9c8564d97b4e_8000x3546.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:645,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!d0lK!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F332a9a87-95fa-490f-83d1-9c8564d97b4e_8000x3546.jpeg 424w, https://substackcdn.com/image/fetch/$s_!d0lK!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F332a9a87-95fa-490f-83d1-9c8564d97b4e_8000x3546.jpeg 848w, https://substackcdn.com/image/fetch/$s_!d0lK!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F332a9a87-95fa-490f-83d1-9c8564d97b4e_8000x3546.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!d0lK!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F332a9a87-95fa-490f-83d1-9c8564d97b4e_8000x3546.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>A growing chorus of scholars and policymakers favors letting private organizations&#8212;rather than a government regulator&#8212;govern frontier AI. In the leading family of proposals, the state sets the safety outcomes it wants and licenses independent verification organizations (IVOs) that compete to certify developers against those outcomes. Gillian Hadfield has developed the idea as &#8220;<a href="https://arxiv.org/abs/2304.04914">regulatory markets</a>,&#8221; in which AI developers must pay for oversight from private regulators that governments license and hold accountable for safety standards. Dean Ball, who likens the arrangement to bank supervision, has argued for a version he calls &#8220;<a href="https://www.hyperdimensional.co/p/on-private-governance">private governance</a>,&#8221; which a nonprofit named Fathom has <a href="https://fathom.org/insights/fathom-on-private-ai-governance">converted into model legislation</a>. The rationale is that legislators and agencies are poorly positioned to write good safety rules for frontier AI: they understand these systems less well than the labs building them, and rules fixed in advance cannot keep pace as the technology changes. Private verifiers, meanwhile, are closer to the technology than any agency and are disciplined by competition, so they can set better technical standards and keep them current.</p><p>The model is no longer hypothetical. The bipartisan <a href="https://obernolte.house.gov/media/press-releases/obernolte-trahan-introduce-bipartisan-frontier-act-strengthen-oversight">FRONTIER Act</a>, introduced in the House in July as the successor to the Great American AI Act discussion draft, would require the largest frontier developers to retain licensed IVOs that audit their risk-management efforts and report to federal overseers. California&#8217;s <a href="https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202520260SB813">SB 813</a>, backed by Fathom, would have let developers earn a shield from tort liability if they met standards set by a private organization accredited by the state attorney general. It failed this session, but similar proposals are likely to return. Virginia has directed a state commission to <a href="https://lis.blob.core.windows.net/files/1210896.PDF">study the IVO model for AI regulation</a>. And Connecticut has gone furthest: its <a href="https://www.wilmerhale.com/en/insights/blogs/wilmerhale-privacy-and-cybersecurity-law/20260604-what-companies-should-know-about-connecticuts-new-omnibus-ai-law">omnibus AI law</a> enacted this spring creates a multiyear pilot under which the state consumer-protection department may approve up to five IVOs, whose certification would help companies in court without entirely shielding them from liability.</p><p>Unfortunately, as currently structured, IVO-based governance has a key design flaw. Under the regulatory frameworks mentioned above, AI developers would typically select and pay the organizations that certify them, giving IVOs a financial incentive that might clash with high safety standards. This essay will explain how such incentives can interfere with good governance and outline an alternative model of regulation that builds in the right incentives through mandatory insurance.</p><h2>Building the Right Incentive Structures</h2><p><strong>When AI developers choose an IVO to certify them, IVOs are incentivized toward leniency.</strong> The pitfalls of private governance are predictable in part because we have seen them before. Indeed, as <a href="https://www.transformernews.ai/p/dont-let-independent-ai-audits-provide-false-safety">some critics have noted</a>, the proposed IVO model creates the same conflict of interest that discredited the credit-rating agencies (CRAs) in the wake of the 2008 financial crisis; when issuers shopped for the CRA that would bless their securities, competing CRAs were under pressure to be lenient. Similarly, an IVO that depends on the developers it clears for repeat business has a significant incentive to grade gently, and a developer shopping among IVOs will find the one that does. Competition&#8212;the feature that is meant to make the IVO model effective&#8212;instead drives it toward laxity. Where a passing grade also carries a liability shield, as under SB 813, the problem compounds: a shield swaps the broad incentive to cut risk by any cost-effective means for a narrow incentive to do only what earns the shield.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Jc_1!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80800aa9-b591-4fe8-b765-dd58ef5745b0_2048x1921.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Jc_1!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80800aa9-b591-4fe8-b765-dd58ef5745b0_2048x1921.png 424w, https://substackcdn.com/image/fetch/$s_!Jc_1!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80800aa9-b591-4fe8-b765-dd58ef5745b0_2048x1921.png 848w, https://substackcdn.com/image/fetch/$s_!Jc_1!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80800aa9-b591-4fe8-b765-dd58ef5745b0_2048x1921.png 1272w, https://substackcdn.com/image/fetch/$s_!Jc_1!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80800aa9-b591-4fe8-b765-dd58ef5745b0_2048x1921.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Jc_1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80800aa9-b591-4fe8-b765-dd58ef5745b0_2048x1921.png" width="1456" height="1366" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/80800aa9-b591-4fe8-b765-dd58ef5745b0_2048x1921.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1366,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!Jc_1!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80800aa9-b591-4fe8-b765-dd58ef5745b0_2048x1921.png 424w, https://substackcdn.com/image/fetch/$s_!Jc_1!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80800aa9-b591-4fe8-b765-dd58ef5745b0_2048x1921.png 848w, https://substackcdn.com/image/fetch/$s_!Jc_1!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80800aa9-b591-4fe8-b765-dd58ef5745b0_2048x1921.png 1272w, https://substackcdn.com/image/fetch/$s_!Jc_1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80800aa9-b591-4fe8-b765-dd58ef5745b0_2048x1921.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>Governments lacking the expertise to regulate AI directly may also struggle to oversee IVOs.</strong> Proponents of the IVO model are aware of the incentive problem. Their solution is to have a government entity license the IVOs and revoke the licenses of any that grade too easily. But that reintroduces the problem that the IVO model was intended to solve in the first place. Policing a market of verifiers well enough to keep it honest requires a public body with the expertise to second-guess technical judgments and the independence to withstand pressure from powerful firms. If the government could reliably field such a body, much of the reason to outsource verification at all would fall away.</p><p><strong>Insurers who bear the cost of adverse events are incentivized to assess risk accurately.</strong> Proponents&#8217; favorite rejoinder is Underwriters Laboratories (UL), the century-old private certifier whose mark serves as a trusted symbol of safety on billions of products. But the history of UL actually strengthens the case for an alternative approach to third-party verification: incorporating insurance. UL began in 1894 as the <a href="https://ul.org/about/our-history/">Underwriters&#8217; Electrical Bureau</a>, built with the backing of fire-insurance underwriters who needed honest assessments of a dangerous new technology, electricity, because their capital was on the line when buildings burned. The lab earned its authority in the decades when it answered to these underwriters, who paid for its mistakes. In other words, incorporating insurance into third-party verification creates the right incentives to evaluate risk accurately.</p><p><strong>Customer demand cannot strongly motivate safety when risk falls on third parties.</strong> Today, manufacturers pay for UL&#8217;s testing, seemingly creating a conflict of interest. But the arrangement still works, because consumers purchasing a manufacturer&#8217;s products are usually the same people whom the products might harm, and thus have a strong preference for safe products. This market demand for safety incentivizes product manufacturers to pay UL for serious, rigorous tests. By contrast, much of the risk generated by frontier AI development and deployment falls on nonconsenting third parties, rather than on the company or individual using a given AI system. For example, a rogue AI model might conduct a cyberattack against a company but not directly harm its own developer or user. Thus, customer demand provides too weak a signal to motivate adequate investments in safety.</p><p><strong>Auto insurance demonstrates a governance model that could apply to AI.</strong> The <a href="https://www.iihs.org/about-us">Insurance Institute for Highway Safety</a> (IIHS) arguably illustrates a better path for frontier AI regulation than IVOs. Nearly every US state requires car owners to carry auto insurance, which covers liability claims for harms the car causes to others. Because insurers pay those claims, they have a strong incentive to price risk accurately&#8212;which is why the auto insurance industry funds IIHS to rate cars on <a href="https://mediaroom.iihs.org/2019-02-21-Most-small-SUVs-earn-top-ratings-for-pedestrian-crash-prevention-in-new-test-program">pedestrian crash prevention</a>. IIHS certification stays honest because insurers have money at stake and demand accuracy. The IVO model has no party with that kind of skin in the game. Requiring AI developers to carry liability insurance would create one.</p><p>Concretely, an insurer that writes an AI developer&#8217;s coverage promises to pay for the harms the developer causes. If such insurers underprice, they pay in claims; if they overprice, they lose the client. Ensuring accuracy is how they make money. And the incentive does not stop at signing; since insurers&#8217; capital stays exposed for as long as the policy runs, they keep monitoring the developer and can make continued coverage conditional on fixes to safety issues that arise.</p><h2>A Mandatory Insurance Model for AI Governance</h2><p>In a regulatory approach based on mandatory insurance, the insurer would play a role similar to that of an IVO, but with a much stronger financial incentive to conduct competent risk assessment. Nothing would be lost in expertise, because the insurer could hire the same specialists an IVO would. It could even contract the evaluation out to an independent firm, which would answer to a principal that loses money if the assessment is incorrect. The requirement would also extend the reach of liability, since the largest harms that AI systems might cause greatly exceed the liquidation value of AI companies, and judgments above that value deter nothing. Mandatory coverage would put an insurer&#8217;s capital behind those judgments and maximize the incentive to avoid harm. And, unlike the safe-harbor versions of the IVO model, mandatory insurance would confer no legal immunity: instead, the developer would carry liability and insure against it. This governance approach would convert a potential race to the bottom on safety assessment into a competition to price risk accurately.</p><p><strong>The US government could oversee insurers without needing AI expertise itself.</strong> The mandatory insurance model is essentially a private governance model that uses insurers instead of IVOs to verify safety. The US government would still set the safety outcomes and license the verifiers; but, because the verifiers would now be insurers, these tasks would be relatively simple: the government would set a minimum amount of coverage that developers must carry in different circumstances, and it would check that insurers follow standard solvency and conduct rules. Neither task would call for expert judgment from the government about which AI models are safe. Instead, that work would be done by insurers, which could regulate an AI company&#8217;s activity by <a href="https://ssrn.com/abstract=6173619">including contractual rules in its insurance policy</a>.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!hfP5!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5dcc74c9-41bc-42e3-9426-f152ddd1a35d_2048x1921.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!hfP5!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5dcc74c9-41bc-42e3-9426-f152ddd1a35d_2048x1921.png 424w, https://substackcdn.com/image/fetch/$s_!hfP5!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5dcc74c9-41bc-42e3-9426-f152ddd1a35d_2048x1921.png 848w, https://substackcdn.com/image/fetch/$s_!hfP5!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5dcc74c9-41bc-42e3-9426-f152ddd1a35d_2048x1921.png 1272w, https://substackcdn.com/image/fetch/$s_!hfP5!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5dcc74c9-41bc-42e3-9426-f152ddd1a35d_2048x1921.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!hfP5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5dcc74c9-41bc-42e3-9426-f152ddd1a35d_2048x1921.png" width="1456" height="1366" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5dcc74c9-41bc-42e3-9426-f152ddd1a35d_2048x1921.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1366,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!hfP5!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5dcc74c9-41bc-42e3-9426-f152ddd1a35d_2048x1921.png 424w, https://substackcdn.com/image/fetch/$s_!hfP5!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5dcc74c9-41bc-42e3-9426-f152ddd1a35d_2048x1921.png 848w, https://substackcdn.com/image/fetch/$s_!hfP5!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5dcc74c9-41bc-42e3-9426-f152ddd1a35d_2048x1921.png 1272w, https://substackcdn.com/image/fetch/$s_!hfP5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5dcc74c9-41bc-42e3-9426-f152ddd1a35d_2048x1921.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>Insurers will price correctly for the &#8220;insurable layer&#8221; of reasonably likely harms.</strong> To price coverage, the insurers would consider AI models&#8217; demonstrated capabilities and how they are deployed, drawing on the growing ecosystem of third-party AI evaluators.</p><p>The premium would be an honest signal only where the insurer&#8217;s capital is at stake. For risks that are reasonably likely to materialize, competition would push insurers to price correctly, because underpricing is a loss they eat. However, &#8220;tail risks&#8221;&#8212;risks of extreme but very low-probability catastrophes&#8212;are unlikely to affect the premium. This is because insurers would have no more at stake than a paid auditor; tail risks are very unlikely to materialize, but if a catastrophe occurred the costs would be too high for the insurer to cover, making them &#8220;judgment-proof.&#8221; Liability insurance legislation should therefore also require insurer-verifiers to disclose their risk assessments and bear liability for false ones, and it should keep targeted public oversight on the risks the premium does not price. Disclosure duties of this kind are standard practice for insurance regulation; carriers already file their rates and forms with state regulators, and disclosure is the price of admission to a large market. The insurer is the right verifier for the insurable layer. It is not, by itself, the answer for the most extreme risks.</p><p><strong>Other industries show that insurance improves safety when implemented well.</strong> None of this is unfamiliar work for insurers. Beyond UL, they built the <a href="https://repository.law.umich.edu/mlr/vol111/iss2/2/">inspection regimes behind boiler and pressure-vessel safety</a> and long conditioned aviation coverage on airworthiness and pilot qualification, turning the policy into an enforceable safety charter. The history also carries a warning: risk-bearing is necessary for good verification, but it is not sufficient. Insurers get it right when the design around them requires it, through mandatory coverage with cost-sharing that keeps the insured parties exposed, backed by capital adequate to the losses underwritten.</p><h2>Objections to a Mandatory Insurance Model</h2><p>The remaining objections are practical: political feasibility, pricing without historical data, keeping up with the pace of the technology, and addressing uninsurable tail risks. These are real challenges, and they deserve direct answers.</p><p><strong>Political will for AI regulation is growing, and insurance is a familiar approach.</strong> On political feasibility, the landscape has already moved. The FRONTIER Act builds the scaffolding that the insurance model needs: licensed verifiers, federal oversight, and audit duties for the largest developers. Connecting verification to insurance would require only an amendment to pending legislation that already has bipartisan support. This ask has clear precedents. Drivers, contractors, and nuclear operators all must show they can pay for the harms that their activities risk; asking the same of frontier AI developers only extends this familiar principle.</p><p>Nor would the cost be overly burdensome. The value created and captured at the AI frontier is enormous, and an industry that raises tens of billions of dollars for compute can carry premiums proportioned to the risks it creates. If an AI company is forced to slow down or shift direction because it cannot afford the insurance premium demanded for its practices, that is the system working to steer it away from actions that are not socially beneficial.</p><p><strong>Mandatory insurance can cover harms that AI companies will not voluntarily insure.</strong> Parts of the industry are already acting voluntarily, with AI companies <a href="https://www.prnewswire.com/news-releases/elevenlabs-secures-first-of-its-kind-ai-agent-insurance-302684587.html">buying agent coverage</a> and <a href="https://www.fastcompany.com/91550776/rajiv-dattani-is-bringing-insurance-to-the-ai-agent-boom">joining efforts to build insurance-linked safety standards</a>. Some developers have also expressed openness to well-designed government requirements. However, the market is unlikely to generate coverage for the largest potential catastrophes on its own, since AI developers lack strong incentives to purchase insurance that covers liabilities for which they would otherwise be judgment-proof. The proposed coverage requirement would patch that market failure.</p><p><strong>The insurance industry has priced novel risks before.</strong> On pricing, skeptics doubt that anyone can estimate catastrophic AI risk with the precision and reliability underwriting demands. But underwriting AI liability insurance does not depend on knowing the precise probability of catastrophe. Insurers need only a price they are prepared to stand behind, set conservatively where the evidence is thin. The industry has never waited for actuarial tables to underwrite novel risks. Satellite launches were insured before there was a satellite loss history; cyber coverage emerged while loss data was still accumulating; the 1957 Price-Anderson Act formed nuclear insurance pools to price reactors that had never melted down.</p><p><strong>Insurers could reward transparency and higher safety standards with lower premiums.</strong> Insurers already write insurance policies covering AI errors and omissions, as well as cyber damages.<a href="https://www.munichre.com/en/solutions/for-industry-clients/insure-ai.html"> </a>Munich Re has <a href="https://www.munichre.com/en/solutions/for-industry-clients/insure-ai.html">insured</a> AI model performance since 2018, Lloyd&#8217;s underwriters now <a href="https://the-decoder.com/lloyds-insurers-launch-first-ai-chatbot-error-policies/">back</a> policies covering losses from chatbot errors and hallucinations, and cyber carriers have <a href="https://www.coalitioninc.com/announcements/coalition-adds-new-affirmative-ai-endorsement-to-cyber-policies">extended</a> coverage to AI-caused security failures and deepfake-enabled fraud.</p><p>The same analytical tools that underwrite those smaller policies can be adapted to the coverage envisioned here. Premiums can be set from what is observable before any loss: an AI model&#8217;s training compute, capability and safety evaluations, and deployment scope. Where the risk remains ambiguous, <a href="https://link.springer.com/article/10.1007/BF01065315">insurers charge more for the ambiguity</a>. For frontier AI, that surcharge would operate as a tax on opacity and misalignment. Developers pay more when their systems are hard to evaluate, and the fastest way to lower the premium is to make the risk legible through transparency. AI companies would thus have a financial incentive to implement better evaluations, monitoring, and containment of their AI models.</p><p><strong>Policies could cover general safety practices, with large changes triggering re-evaluation.</strong> On pace, the objection is that no one can write a multiyear policy on a technology that reinvents itself in months. But multiyear policies are unnecessary. Commercial liability coverage is written year to year and covers the insured party&#8217;s operations as a whole, with premiums adjusted as those operations change. For example, workers&#8217; compensation policies, which cover illnesses and injuries that employees suffer due to their work, are priced based on employers&#8217; estimated payroll data and then reconciled with actual payroll at year-end.</p><p>AI coverage would work the same way. Policies would cover developers rather than particular models, and premiums would adjust as their activities change. Significant changes, such as a new frontier training run, a move from closed API to open-weights release, or capabilities beyond what was initially evaluated, would trigger re-underwriting&#8212;already a routine event in every existing form of commercial insurance. Ordinary model updates within the evaluated range would be handled under the existing policy through the monitoring insurers already do, rather than by writing new coverage each time.</p><p><strong>Addressing uninsurable tail risks is the most formidable hurdle.</strong> COVID-19 <a href="https://jamanetwork.com/journals/jama/fullarticle/2771764">cost the United States an estimated $16 trillion</a>. An AI-enabled catastrophe could cost as much or even more, and no private pool of capital can stand behind that number. This proposal does not pretend otherwise. Some AI risks carry extreme downsides that are practically noncompensable: the losses would exceed insurable limits, bankrupt any defendant, or arise in catastrophic scenarios where the legal system could not meaningfully function. Judgments of that size are effectively unenforceable. As a result, even unlimited legal liability imposed after the harm occurs would generate too little incentive to prevent it in the first place. That is why the coverage requirement targets the insurable layer&#8212;the harms that private capital can actually pay for. The tail calls for different tools.</p><p><strong>Larger harms can be covered by sharing costs among developers and with government.</strong> One approach to larger harms is shared residual liability, which would put every frontier developer on the hook for a share of any catastrophe that one of them causes. This would mirror the Price-Anderson Act&#8217;s retrospective assessments, which reach every licensed nuclear reactor after an accident occurs at any of them. Such a model would multiply the assets behind a judgment and give each firm a stake in the care its rivals take. Public backstops can also make harms compensable beyond the maximum insurable risk, just as the Terrorism Risk Insurance Act (TRIA) is set up so that the government shares with insured parties the cost of extreme harms caused by terrorist attacks. TRIA&#8217;s cap, which limits total insurance payouts to $100 billion per year, is a design choice, and Congress can set it to match the peril.</p><p><strong>Measures that reduce the risk of insurable harms also reduce catastrophic risk.</strong> Even though we cannot enforce compensatory damages for the largest harms, there are still liability-based mechanisms that give AI companies strong incentives to mitigate those risks. For example, I have argued since my <a href="https://ssrn.com/abstract=4694006">earliest work on AI liability</a> that courts should award punitive damages in near-miss cases, calibrated to ensure that the AI developer internalizes the risk of the catastrophe that their practices nearly caused.</p><p>But the case for insurer-verifiers does not depend on solving the tail. The precautions that reduce insurable losses&#8212;tighter security against model theft, stronger containment during evaluation and deployment, and closer monitoring of what agents actually do&#8212;are largely the same measures that also reduce the uninsurable downside. Getting the insurable layer priced correctly therefore also reduces the risks that no policy will ever cover. Last week&#8217;s <a href="https://openai.com/index/hugging-face-model-evaluation-security-incident/">OpenAI-Hugging Face breach</a> illustrates the overlap. The failures it revealed&#8212;weakened safeguards and breached containment&#8212;are the same ones that the gravest scenarios would run through. And the verification infrastructure that would be built to evaluate insurable risks is exactly what any approach to the tail would also need.</p><h2>Mandatory Insurance Is a Better Form of Private Governance</h2><p>The private governance movement has the right instinct. The government is poorly positioned to certify the safety of frontier AI models, and a competitive market of expert verifiers could do better. But competition yields accuracy only when there is a cost to being wrong. In a system where developers pay government-licensed auditors, the fear of reputational damage and decertification gives those auditors some incentives for rigor. But such incentives are likely to be overwhelmed by selection pressures from AI developers, which favor laxity. An insurer that carries the developer&#8217;s liability, on the other hand, must pay when the risk it cleared is realized. If we put the insurer in the verifier&#8217;s chair and back it with real liability, then private governance turns from a race to the bottom on safety standards into the safety mechanism its proponents originally hoped for.</p><p></p><div><hr></div><p><em><strong>See things differently? </strong>AI Frontiers welcomes expert insights, thoughtful critiques, and fresh perspectives. <a href="https://ai-frontiers.org/publish?utm_source=aif_article">Send us your pitch.</a></em></p><div><hr></div><p><em>Gabriel Weil is an assistant professor at the University of Houston Law Center and a Non-Resident Senior Fellow at the Institute for Law &amp; AI. He also serves on the board of Principles of Intelligence. His research focuses on the role of liability in mitigating catastrophic AI risk, and he regularly consults with legislators and other policymakers on AI policy matters. Previously, Professor Weil held several positions focused on climate change policy, including work for the Climate Leadership Council and the White House Council on Environmental Quality. Professor Weil holds a J.D., cum laude from Georgetown University Law Center, an LL.M. in environmental law, summa cum laude, from Pace University Elizabeth Haub School of Law, and a B.A. in political science, physics, and integrated science from Northwestern University.</em></p>]]></content:encoded></item><item><title><![CDATA[Drone WMDs Don’t Need Any New Technology]]></title><description><![CDATA[Today&#8217;s drones can already navigate indoors, track down humans, and deliver a lethal payload. Attackers willing to kill indiscriminately don&#8217;t need to wait for much else.]]></description><link>https://newsletter.ai-frontiers.org/p/drone-wmds-dont-need-any-new-technology</link><guid isPermaLink="false">https://newsletter.ai-frontiers.org/p/drone-wmds-dont-need-any-new-technology</guid><dc:creator><![CDATA[AI Frontiers]]></dc:creator><pubDate>Mon, 20 Jul 2026 14:31:08 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!tw1S!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b1bd151-ab54-4509-b176-fc9a6e2646bf_6240x4160.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong><a href="https://ai-frontiers.org/author/felix-choussat">Felix Choussat</a></strong> &#8212; July 20, 2026</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!tw1S!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b1bd151-ab54-4509-b176-fc9a6e2646bf_6240x4160.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!tw1S!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b1bd151-ab54-4509-b176-fc9a6e2646bf_6240x4160.jpeg 424w, https://substackcdn.com/image/fetch/$s_!tw1S!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b1bd151-ab54-4509-b176-fc9a6e2646bf_6240x4160.jpeg 848w, https://substackcdn.com/image/fetch/$s_!tw1S!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b1bd151-ab54-4509-b176-fc9a6e2646bf_6240x4160.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!tw1S!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b1bd151-ab54-4509-b176-fc9a6e2646bf_6240x4160.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!tw1S!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b1bd151-ab54-4509-b176-fc9a6e2646bf_6240x4160.jpeg" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5b1bd151-ab54-4509-b176-fc9a6e2646bf_6240x4160.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!tw1S!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b1bd151-ab54-4509-b176-fc9a6e2646bf_6240x4160.jpeg 424w, https://substackcdn.com/image/fetch/$s_!tw1S!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b1bd151-ab54-4509-b176-fc9a6e2646bf_6240x4160.jpeg 848w, https://substackcdn.com/image/fetch/$s_!tw1S!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b1bd151-ab54-4509-b176-fc9a6e2646bf_6240x4160.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!tw1S!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b1bd151-ab54-4509-b176-fc9a6e2646bf_6240x4160.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Drones are cheap, disposable, and the <a href="https://www.forbes.com/sites/mikebrown/2026/04/26/drones-are-the-biggest-military-revolution-in-a-century/">future of war</a>. Over the past four years, we have seen platforms, missiles, and heavy infantry become increasingly obsolete in the face of $500 drones carrying a pack of explosives&#8212;a cost advantage that has let Iranians and Ukrainians alike <a href="https://www.cfr.org/articles/how-ukraines-drone-innovation-reversed-russias-momentum">neuter the conventional capabilities</a> of their great power rivals. <a href="https://www.nytimes.com/interactive/2025/03/03/world/europe/ukraine-russia-war-drones-deaths.html">Eighty percent of casualties</a> in the <a href="https://www.csis.org/analysis/russias-grinding-war-ukraine">bloodiest war since 1945</a> are from drone strikes, Russia has managed to lose <a href="https://www.usni.org/magazines/proceedings/2025/september/russias-black-sea-failures-are-lessons-south-china-sea">one-third of its fleet</a> to a country without a navy, and the US is <a href="https://www.nytimes.com/2026/05/05/us/politics/rockets-iran-drones.html">spending millions of dollars</a> to intercept five-figure Shaheds flying over the Strait of Hormuz.</p><p>All this is the result of a technology that is still immature. The violence inflicted by today&#8217;s drones is the handiwork of the scant few that manage to evade countermeasures (a mix of radio jamming, high-power microwave weapons, missiles, automatic cannons, interceptor drones, and nets) before making contact. These defenses exploit the inherent limitations of drones&#8212;human guidance, GPS feedback, flight exposure, radio links, range&#8212;to take them down en masse. And yet, even though 75% of some types of drones manufactured today <a href="https://www.csis.org/analysis/drone-saturation-russias-shahed-campaign">never reach their targets</a>, they have nonetheless been strategically decisive in Ukraine and elsewhere.</p><p>These limitations will not hold for long. Just as bacteria overexposed to antibiotics evolve resistance, overexposure to counterdrone tech has bred <a href="https://www.longwarjournal.org/archives/2025/06/ukrainian-intelligence-details-russias-new-v2u-autonomous-loitering-munition.php">ever-more-autonomous</a> drones. In the process of facilitating this arms race, states are likely to incrementally create and deploy an entirely new class of WMD&#8212;one that could provide rogue states with the nonnuclear means to threaten superpowers, or hand terrorists the means to selectively assassinate their political targets or civilians en masse.</p><p>Unfortunately, drone weapons intended for mass destruction have few barriers remaining to mass deployment. Even well before they reach the level of autonomy needed to surgically take out hardened targets on the battlefield, drones will be capable of employing their existing ability to navigate interiors, find and track human targets, and deploy simple antipersonnel devices to indiscriminately threaten civilians. Below, we discuss the looming arrival of miniature autonomous weapons, the limits of counterdrone technology, and the applications of drones as weapons of mass destruction.</p><h2>Breaking the Last Barriers to Autonomous Weapons</h2><p>The ideal drone weapon is a <a href="https://spectrum.ieee.org/why-you-should-fear-slaughterbots-a-response">slaughterbot</a>: a small, fully autonomous weapon system that can independently select and hunt its targets. For the most part, the necessary technology for such weapons already exists: airframes the size of a fist and the capability to track human targets are already on the front lines in the form of <a href="https://www.defenceukraine.com/en/insights/black-hornet-micro-uavs-ukraine-urban-combat/">reconnaissance drones</a> and <a href="https://www.csis.org/analysis/how-russia-building-sovereign-drone-ecosystem-ai-driven-autonomy#:~:text=AI%2Denabled%20alternatives.-,Case%20Study%204%3A%20V2U%20and%20the%20Emergence%20of%20Fully%20Autonomous%20AI,innovative%20and%20dangerous%20unmanned%20systems%20currently%20observed%20in%20active%20combat%20use.,-Conclusion">semiautonomous weapons</a> like the Russian V2U. Even now, these micro drones are agile and autonomous enough to hunt down and <a href="https://x.com/alextoussss/status/2077086243632873540">kill</a> small moving targets like mosquitoes&#8212;to say nothing of the drone technology advances expected in coming years.</p><p>From here, the only barrier to weaponization is integration: improving navigation enough to make drone technology useful for mass homicide in an urban setting, as well as packing the necessary guidance, sensor, and payload technology onto a small and energy-efficient chassis. Regrettably, this seems like less of an engineering problem than one of mission design: so long as the attacker is willing to accept indiscriminate targeting and use simple payloads aimed at civilians, the underlying technology is already&#8212;or very nearly&#8212;ready for practical use.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!_RB2!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F824b34f1-2e4c-4717-b3d7-08c5dd5e40a2_1480x890.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!_RB2!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F824b34f1-2e4c-4717-b3d7-08c5dd5e40a2_1480x890.png 424w, https://substackcdn.com/image/fetch/$s_!_RB2!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F824b34f1-2e4c-4717-b3d7-08c5dd5e40a2_1480x890.png 848w, https://substackcdn.com/image/fetch/$s_!_RB2!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F824b34f1-2e4c-4717-b3d7-08c5dd5e40a2_1480x890.png 1272w, https://substackcdn.com/image/fetch/$s_!_RB2!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F824b34f1-2e4c-4717-b3d7-08c5dd5e40a2_1480x890.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!_RB2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F824b34f1-2e4c-4717-b3d7-08c5dd5e40a2_1480x890.png" width="1456" height="876" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/824b34f1-2e4c-4717-b3d7-08c5dd5e40a2_1480x890.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:876,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!_RB2!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F824b34f1-2e4c-4717-b3d7-08c5dd5e40a2_1480x890.png 424w, https://substackcdn.com/image/fetch/$s_!_RB2!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F824b34f1-2e4c-4717-b3d7-08c5dd5e40a2_1480x890.png 848w, https://substackcdn.com/image/fetch/$s_!_RB2!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F824b34f1-2e4c-4717-b3d7-08c5dd5e40a2_1480x890.png 1272w, https://substackcdn.com/image/fetch/$s_!_RB2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F824b34f1-2e4c-4717-b3d7-08c5dd5e40a2_1480x890.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption"><em>Interior navigation and mapping from an autonomous human-reconnaissance drone. Source: <a href="https://shield.ai/autonomy-for-the-world-indoor-exploration-with-nova-2/">ShieldAI</a>.</em></figcaption></figure></div><p>To understand how close we are to these kinds of weapons, it helps to understand why we do not already employ fully autonomous drones. Right now, the <a href="https://static.rusi.org/tactical-developments-third-year-russo-ukrainian-war-february-2205.pdf">most deadly</a> drones are small first-person-view (FPV) units, with the <a href="https://www.nytimes.com/interactive/2025/03/03/world/europe/ukraine-russia-war-drones-deaths.html">majority</a> of Russian and Ukrainian casualties alike stemming from direct drone strikes. For the most part, however, these small drones are being piloted directly by humans, either through a radio link or a spool of fiber-optic cable, with just the final leg of the attack being <a href="https://warroom.armywarcollege.edu/articles/ais-growing-role/">delegated</a> to an AI targeting system.</p><p>So, <a href="https://nationalinterest.org/blog/buzz/ukraines-drones-can-now-kill-without-human-in-loop-sa-061226">ethics aside</a>, why does drone warfare still depend on human pilots?</p><p><strong>Distinguishing enemy targets from friendly assets on the battlefield still requires humans.</strong> The main problem is that battlefields are intrinsically <a href="https://www.csis.org/analysis/ukraines-future-vision-and-current-capabilities-waging-ai-enabled-autonomous-warfare#h2-ai-in-automatic-target-recognition:~:text=Current%20Challenges%20in%20ATR">adversarial environments</a>: an autonomous drone needs to avoid friendly fire on its own infrastructure and troops, anticipate pre-positioned counterdrone defenses, deal with camouflage and decoys, and destroy hardened targets like vehicles and infrastructure. This is especially complicated if you need drones to autonomously work together to accomplish an objective, such as by having specialized units target defenses to allow others through. For the moment, only humans have the skills to distinguish a camouflaged ally from an enemy unit, or to exploit the underbelly of an armored vehicle.</p><p><strong>Designing drones for indiscriminate mass destruction is easier than for precise battlefield use. </strong>Unfortunately, adversarial target selection is not a meaningful barrier for applying drones to mass terrorism. Destroying an armored vehicle needs the skill to reason about and single out its weak points; but, to kill an unarmored human, a drone need only make contact with them and deploy an explosive or poison needle. The targeting requirements and level of autonomy needed to indiscriminately massacre civilians, in other words, are much lower than what you&#8217;d need to selectively destroy hardened targets on a battlefield. In the words of Ukraine&#8217;s Azov brigade, &#8220;If you don&#8217;t care about civilians, you can simply <a href="https://www.forbes.com/sites/craigsmith/2026/03/26/fully-autonomous-drone-warfare-is-coming-to-ukraineand-iran/#:~:text=Azhnyuk%20argues%20that,hit%20like%20this.%E2%80%9D">hit any target that moves</a>.&#8221;</p><p><strong>Drones can already navigate indoor environments and track humans.</strong> Aside from requiring guidance for target selection, autonomous drones also need the ability to navigate. Urban environments are cluttered and leave room for targets to shelter indoors, so drones must infiltrate and sweep through them to be maximally lethal. Autonomous navigation of this caliber already exists: since as far back as 2022, drones have been capable of <a href="https://shield.ai/autonomy-for-the-world-indoor-exploration-with-nova-2/">mapping and tracking indoor environments</a> to find humans, a skill used to <a href="https://www.politico.com/newsletters/national-security-daily/2023/12/21/rescuing-hostages-with-cheap-american-drones-00132750">locate hostages</a> and scan through tunnels for enemy soldiers. These kinds of drones typically cost tens of thousands of dollars, but they have an expensive use case: infiltrating a GPS-denied location, then escaping to broadcast information. If you do not need the drone to survive and report back, and if you do not care if your drone can tell whether someone is surrendering or not, then you do not need <a href="https://globaldronehq.com/collections/thermal-drone-sensors">expensive sensors</a> or plenty of onboard compute for decision-making&#8212;just the bare minimum to identify a target as human and fly at them.</p><p><strong>Disposable drones that can autonomously attack civilians may soon be relatively cheap.</strong> For comparison, a last-mile module, an upgrade chip that lets FPV drones <a href="https://www.forbes.com/sites/davidhambling/2026/05/19/slaughterbots-now-ukraines-head-hunting-drones-terrify-russians/">visually hunt down targets</a> when they lose connection, is about $500. One-way autonomous search, target selection, and mapping, at least for this anti-civilian use case, would likely be similarly inexpensive&#8212;already, <a href="https://arxiv.org/abs/2312.13385">visual</a> and <a href="https://arxiv.org/abs/2504.15305">laser</a> mapping systems have been demonstrated, in principle, that can work their way around a room and track humans on a <a href="https://www.nvidia.com/en-us/autonomous-machines/embedded-systems/jetson-orin/nano-super-developer-kit/">few hundred dollars</a> of hardware. If a military system that navigates to the entrance and then plans an indiscriminate suicide mission inside is not already achievable for just thousands of dollars, it will be in a <a href="https://spectrum.ieee.org/autonomous-drone-warfare#:~:text=%E2%80%9CToday%2C%20we%20have,stations%2C%20and%20jammers.">matter of years</a>.</p><p>Of course, most countries do not have the motivation to build these kinds of systems and drive down their unit economics. Discrimination, ethical or otherwise, is useful on the battlefield. If the costs of autonomous targeting keep falling or AI guidance improves, however, states might be tempted to start employing indiscriminate drones as a means of deterrence, or as a cheap way to enable terrorist proxies.</p><h2>Future Methods of Weaponization</h2><p>Given these capabilities, how could these drones be weaponized and delivered in practice? The main limiter on these kinds of small drones is energy: a modern 30g micro drone like a <a href="https://defense.flir.com/defense-products/black-hornet-3-prs/">Black Hornet</a> can fly for about half an hour before needing to recharge, while a bigger FPV carrying an explosive payload will usually last only <a href="https://warontherocks.com/i-fought-in-ukraine-and-heres-why-fpv-drones-kind-of-suck/#:~:text=For%20sophisticated%20NATO,range%20of%20artillery.">15 minutes</a>. However, there are plenty of ways to stretch this energy budget further for the purpose of mass destruction, even without better battery technology.</p><p><strong>Lethal payloads could be much smaller.</strong> Today, FPV units usually carry about a kilo of explosives, because they need to be <a href="https://www.theguardian.com/world/2025/jan/04/it-is-impossible-to-outrun-them-how-drones-transformed-war-in-ukraine">flexible enough</a> to target vehicles and defensive infrastructure as well as enemy soldiers. If the goal is to break windows and kill humans, however, even just <a href="https://www.npaid.org/files/Mine-action-and-disarmarment/m85.pdf">20g of frag explosives</a> is enough at several meters of distance, with much less needed for a lethal wound at near-contact. Alternatively, something as simple as a spring-loaded needle, coated with a microgram quantity of a poison like <a href="https://en.wikipedia.org/wiki/Botulinum_toxin">botulinum toxin</a> or a <a href="https://en.wikipedia.org/wiki/Novichok#">nerve agent</a>, would be immediately lethal on contact.</p><p><strong>Energy expenditure on delivery and flight could be significantly reduced.</strong> Rather than have the drones travel constantly under their own power, it is much more efficient to carry them into position with a <a href="https://en.wikipedia.org/wiki/Drone_carrier">drone mothership</a> or even the <a href="https://www.twz.com/land/prsm-ballistic-missiles-loaded-with-coyote-drones-hatchet-mini-smart-bombs-eyed-by-army">hull of a missile</a>. Once the drones are released into the air, they then need to navigate to a building without expending much power. A simple way to do this is to give the drone <a href="https://gwaramedia.com/en/ukraine-equips-fpv-drones-with-wings-increasing-their-flight-range-osint-analyst-says/">glide wings</a>, letting it drift forward for most of its flight rather than loiter directly. This technique is <a href="https://www.forbes.com/sites/davidhambling/2026/06/02/ukraines-new-fpvs-hit-targets-sixty-miles-behind-russian-lines/">already used</a> in Ukraine to stretch the range of basic FPVs over 40 miles beyond the front line.</p><p><strong>Drones could perch and idle, rather than hovering, while waiting for targets.</strong> Finally, and most importantly, the drones would be ambush hunters. Rather than loiter in the air, it is much more efficient to <a href="https://www.forbes.com/sites/davidhambling/2025/02/03/ukraines-ambush-drones-step-up-attacks-behind-enemy-lines">perch and idle</a> under cover, running a milliwatt acoustic and visual sensor every few seconds until a target is detected. Although drones would still need to expend the energy to infiltrate a building, once inside, they could afford to act like improvised landmines <a href="https://www.forbes.com/sites/davidhambling/2025/07/02/creeping-doom-russia-deploys-solar-powered-ambush-drones/">for days or weeks</a> until their batteries finally die.</p><h2>What an Urban Drone Attack Might Look Like</h2><p>To appreciate the implications of these capabilities, it helps to outline what a mass urban drone attack would actually look like.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!viAF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff5b56933-89f9-487f-9e27-8b86b725100d_1920x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!viAF!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff5b56933-89f9-487f-9e27-8b86b725100d_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!viAF!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff5b56933-89f9-487f-9e27-8b86b725100d_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!viAF!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff5b56933-89f9-487f-9e27-8b86b725100d_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!viAF!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff5b56933-89f9-487f-9e27-8b86b725100d_1920x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!viAF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff5b56933-89f9-487f-9e27-8b86b725100d_1920x1080.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f5b56933-89f9-487f-9e27-8b86b725100d_1920x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!viAF!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff5b56933-89f9-487f-9e27-8b86b725100d_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!viAF!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff5b56933-89f9-487f-9e27-8b86b725100d_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!viAF!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff5b56933-89f9-487f-9e27-8b86b725100d_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!viAF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff5b56933-89f9-487f-9e27-8b86b725100d_1920x1080.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption"><em>Stylized micro drones tumbling out of a plane. Source: <a href="https://futureoflife.org/project/autonomous-weapons-systems/">Future of Life Institute</a>.</em></figcaption></figure></div><p>At the outset, drones are delivered near the city through a large mothership, which independently stores them in a cargo hold. Depending on whether the mothership is itself a larger drone, a plane, or the warhead of a missile, it could feasibly deliver anywhere from hundreds to tens of thousands of drones at once. Alternatively, the drones could be smuggled in through a pre-positioned <a href="https://www.defensenews.com/global/europe/2026/06/16/rheinmetall-pitches-shipping-container-that-can-spit-out-swarms-of-attack-drones/">shipping container</a>, which would then launch its contents from a nearby port or logistics yard. Either way, a large number of drones are then scattered above the city at a low altitude or are dispersed near street level.</p><p>How many drones? Assuming that the drones are arranged like capsuled quadcopters, they can be packed in extremely efficiently. Using the <a href="https://gaci.fr/build/front/pdf/Datasheet_NINOX-40.asset.pdf">Ninox-40</a> system as an example, storage counts would be in the range of:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!H66p!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F11b4ebc9-8d6a-4140-904e-7eca74362b67_2048x1028.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!H66p!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F11b4ebc9-8d6a-4140-904e-7eca74362b67_2048x1028.png 424w, https://substackcdn.com/image/fetch/$s_!H66p!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F11b4ebc9-8d6a-4140-904e-7eca74362b67_2048x1028.png 848w, https://substackcdn.com/image/fetch/$s_!H66p!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F11b4ebc9-8d6a-4140-904e-7eca74362b67_2048x1028.png 1272w, https://substackcdn.com/image/fetch/$s_!H66p!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F11b4ebc9-8d6a-4140-904e-7eca74362b67_2048x1028.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!H66p!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F11b4ebc9-8d6a-4140-904e-7eca74362b67_2048x1028.png" width="1456" height="731" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/11b4ebc9-8d6a-4140-904e-7eca74362b67_2048x1028.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:731,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!H66p!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F11b4ebc9-8d6a-4140-904e-7eca74362b67_2048x1028.png 424w, https://substackcdn.com/image/fetch/$s_!H66p!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F11b4ebc9-8d6a-4140-904e-7eca74362b67_2048x1028.png 848w, https://substackcdn.com/image/fetch/$s_!H66p!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F11b4ebc9-8d6a-4140-904e-7eca74362b67_2048x1028.png 1272w, https://substackcdn.com/image/fetch/$s_!H66p!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F11b4ebc9-8d6a-4140-904e-7eca74362b67_2048x1028.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Once released, the drones glide down haphazardly, aiming to land in regions not already populated by other units. Some drift directly onto public crowds and attack their targets right away. Others do not land near a direct target, switching their focus to look for entrances, such as doorways, windows, and tunnels. If the attacker is particularly sophisticated, these drones might be accompanied by a handful of larger drones carrying breaching charges, designed to create more openings for the main force. These drones then begin drifting through the building interior for a few minutes, looking for victims. If they cannot find a new target or are unable to find a route inside, they move to a dark corner or roadside and begin passively idling.</p><p>Many civilians would die in the initial attack. But the aftermath would be much worse. With the drones saturating the city, there would be no opportunity for any survivor to leave their barricade and seek help, and no way for resources and relief units to flow back in. Anyone in need of food or basic medical attention would be unreachable for weeks, during which the death toll would continue to mount. In effect, the entire city would be transformed into something akin to the <a href="https://www.bbc.com/news/articles/c3w2xqj9x13o">Ukrainian front line</a> today, with the omnipresent threat of assassination forcing the surviving humans to <a href="https://www.thetimes.com/world/russia-ukraine-war/article/drones-front-line-soldiers-news-lj0vmh2ms">slowly starve</a> in isolated foxholes, without any chance of easy respite or rescue. Most people would not have stashed food ahead of time, or armed themselves with anti-drone weapons, or sealed off every corner of their apartment with netting.</p><h2>Defenses Against Drone WMDs May Be Inadequate</h2><p>Any improvements in drone technology will still need to contend with counterdrone defenses. It is precisely because drones are so threatening that states have <a href="https://www.nato.int/en/news-and-events/articles/news/2026/07/07/nato-allies-invest-40-billion-dollars-in-counter-drone-capabilities-and-drone-training">invested heavily</a> in tools like <a href="https://en.wikipedia.org/wiki/Epirus_Leonidas">directed energy weapons</a> and <a href="https://www.forbes.com/sites/vikrammittal/2026/05/27/russias-yolka-interceptor-faces-challenges-against-ukrainian-drones/">interceptor drones</a> to counter them. If drones become even more strategically dominant, then we will surely see correspondingly greater counterdrone efforts. So why should we expect this arms race to resolve in favor of the drones, rather than their countermeasures?</p><p><strong>Future drones will be less vulnerable to radio-frequency jamming.</strong> To appreciate the limitations of counterdrone technology, we can look at the difficulty states are already experiencing in their efforts to counter <a href="https://united24media.com/war-in-ukraine/can-fiber-optic-drones-be-stopped-how-ukraine-faces-the-unjammable-threat-12502">fiber-optic FPV units</a>. These drones work by unspooling a thin fiber-optic cable behind them, letting a human pilot them directly for up to <a href="https://en.defence-ua.com/industries/ukrainians_made_an_fpv_with_fiber_optic_cord_stretching_for_41_km-13327.html">40 kilometers</a> without having to worry about GPS or input jamming.</p><p>The reason these drones are so effective is that they&#8217;re <a href="https://www.wsj.com/world/europe/ukraine-russia-drones-fiber-optic-cable-6c96a9f1">naturally resilient</a> against common counterdrone techniques. Throughout the Ukraine war, the <a href="https://www.nytimes.com/2024/03/12/world/europe/ukraine-drone-russia-jamming.html">most important</a> anti-drone tool has been radio-frequency jamming. As long as a human pilot is selecting targets and telling the drone where to go, or as long as the drone depends on GPS coordinates to navigate, overwhelming or spoofing those broadcasts with a countersignal will cause the drones to fly harmlessly off course. With a fiber-optic drone, all the piloting happens through a direct data link, so this kind of countersignal is ineffective. The same is true of any autonomous drone&#8212;as long as all the decision making is processed on board, there&#8217;s <a href="https://spectrum.ieee.org/autonomous-drone-warfare#:~:text=%E2%80%9CI%20think%20in,much%20larger%20scale.">no human input to jam or spoof</a> in the first place.</p><p><strong>Interception is asymmetrically difficult against small, stealthy drones. </strong>In cases where it&#8217;s difficult to achieve an electronic soft kill on a drone, the backup option is to physically destroy it with a kinetic interceptor. The reason this is a backup is that it&#8217;s expensive and prone to blind spots. Small FPVs are cheap and agile enough that it&#8217;s easy to <a href="https://www.forbes.com/sites/davidhambling/2025/09/10/why-some-anti-drone-artillery-comes-at-a-sky-high-price/">spend much more</a> to down them than they&#8217;re worth. This is why direct kinetic interception is <a href="https://www.aspistrategist.org.au/the-challenge-of-cheap-drones-finding-an-even-cheaper-way-to-destroy-them/">usually reserved for expensive drones</a> with fixed flight paths (like Shaheds) and kept as an option of <a href="https://frontliner.ua/en/a-last-resort-shot-how-ukrainian-innovation-takes-down-enemy-drones/">last resort</a> for small drones.</p><p>There is also the problem of terrain blindness: if you cannot see a drone, you cannot shoot it down. <a href="https://apps.dtic.mil/sti/pdfs/AD1152139.pdf">Modern LSS</a> (low, slow, small) drones are already so tiny that they are difficult for radar to distinguish from birds, trees, and ground clutter, allowing operators to fly them near the treeline until they are too close to reliably intercept. This is especially problematic in an urban environment, where there are many places to hide and many opportunities for collateral damage.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!cWxr!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F944439c8-9e0c-4448-8434-823310945a97_1920x1280.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!cWxr!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F944439c8-9e0c-4448-8434-823310945a97_1920x1280.png 424w, https://substackcdn.com/image/fetch/$s_!cWxr!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F944439c8-9e0c-4448-8434-823310945a97_1920x1280.png 848w, https://substackcdn.com/image/fetch/$s_!cWxr!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F944439c8-9e0c-4448-8434-823310945a97_1920x1280.png 1272w, https://substackcdn.com/image/fetch/$s_!cWxr!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F944439c8-9e0c-4448-8434-823310945a97_1920x1280.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!cWxr!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F944439c8-9e0c-4448-8434-823310945a97_1920x1280.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/944439c8-9e0c-4448-8434-823310945a97_1920x1280.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!cWxr!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F944439c8-9e0c-4448-8434-823310945a97_1920x1280.png 424w, https://substackcdn.com/image/fetch/$s_!cWxr!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F944439c8-9e0c-4448-8434-823310945a97_1920x1280.png 848w, https://substackcdn.com/image/fetch/$s_!cWxr!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F944439c8-9e0c-4448-8434-823310945a97_1920x1280.png 1272w, https://substackcdn.com/image/fetch/$s_!cWxr!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F944439c8-9e0c-4448-8434-823310945a97_1920x1280.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption"><em>Anti-drone nets in Druzhkivka, Ukraine. Source: <a href="https://www.reuters.com/pictures/diary-druzhkivka-inside-frontline-ukrainian-town-under-constant-fire-2026-06-22/">Reuters/Nina Liashonok</a>.</em></figcaption></figure></div><p><strong>Physical barriers and EMP weapons will struggle to reach sufficient coverage in cities. </strong>Instead, the most effective tools against autonomous drones will be structural barriers and directed energy weapons. One of the most visible effects of the war on Ukrainian infrastructure is the miles-long corridor of nets that cover <a href="https://www.npr.org/2026/03/17/nx-s1-5743446/russia-ukraine-war-nets-drones">roads</a> and <a href="https://www.forbes.com/sites/davidhambling/2026/05/05/drone-hide-and-seek-fpvs-are-changing-the-rules-of-urban-warfare/">even cities</a>, without which transports would be constantly exposed to drone strikes. But nets are not hard barriers: if the initial carrier punches through, if a few specialized units carry <a href="https://www.forbes.com/sites/davidhambling/2025/02/17/ukrainian-drone-pilots-unimpressed-by-russias-anti-fpv-tunnel/">breaching tools</a>, or if the drones are released from below, there is little to stop them from flying unimpeded and besieging the streets beneath.</p><p>To actually destroy the drones efficiently, the best candidate is a directed energy weapon, particularly an <a href="https://en.wikipedia.org/wiki/Epirus_Leonidas">electromagnetic pulse</a> (EMP) device. It creates an electric pulse powerful enough to short-circuit any electronics in range, physically destroying the drone controllers and motors. Unfortunately, cities are far from ideal places to deploy such weapons; building materials is reasonably effective at <a href="https://ece-research.unm.edu/summa/notes/In/IN624.pdf">shielding</a> against an electric pulse, which means that, if the EMP does not catch the drones in the initial sortie, lack of a clean sight lines will significantly weaken this countermeasure against drones dispersed throughout a city.</p><p>In other words, these defenses can be locally effective but struggle to get sufficient coverage, especially over an <a href="https://bylinetimes.com/2026/01/13/how-kherson-became-a-live-testing-ground-for-drone-defence-against-russias-human-safari-of-ukrainians/">active residential area</a>. They are also, of course, proactive defenses: they have to be installed ahead of time in order to have any defensive effect, which gives the attacker time to assess and plan around them.</p><h2>Strategic Applications for Rogue Actors</h2><p>In summary, small lethal autonomous weapons will be very difficult to defend against, especially in the context of securing large urban environments. This leaves the question of which actors would want to use them, and to what end.</p><p><strong>Advanced drones would be more useful for rogue states than for superpowers. </strong>The first countries to acquire fully autonomous drones will be those that have a precision manufacturing base and frontier AIs capable of helping with military R&amp;D: namely, the US and China. However, autonomous drones are only marginally useful for the existing great powers: a new option to <a href="https://www.reuters.com/world/china/taiwan-needs-hornets-nest-drones-deter-conflict-us-diplomat-says-2026-07-02/">further deter</a> an invasion of Taiwan, a cheaper way to conduct <a href="https://en.wikipedia.org/wiki/Assassination_of_Qasem_Soleimani">remote assassinations</a>, and a way to maintain conventional parity with rivals&#8217; own drone mass. Rather than meaningfully changing the balance of power between nuclear states, near-term autonomous drones will likely be most useful for rogue actors seeking new weapons of mass destruction to enhance deterrence. In this regard, indiscriminate autonomous drone swarms possess many advantages.</p><p><strong>Drones are inherently simple, which makes it very difficult to control their proliferation.</strong> A central reason why modern military drones are so cheap and widespread is their simple design, combined with the <a href="https://foreignpolicy.com/2013/04/29/epiphanies-from-chris-anderson/">commodification</a> of key components like memory and compute. As we have seen with <a href="https://www.aei.org/research-products/report/the-impact-of-semiconductor-sanctions-on-russia/">semiconductor sanctions</a> on Russia, the underlying materials are too accessible in <a href="https://thebulletin.org/2021/04/meet-the-future-weapon-of-mass-destruction-the-drone-swarm/#:~:text=In%20October%202016,are%20absolutely%20possible.)">ordinary consumer supply chains</a> to easily deny mass production. Moreover, even if a specific country could be cordoned off from general drone production, Russia and China have <a href="https://www.spf.org/iina/en/articles/lee_07.html#:~:text=It%20has%20long,and%20strike%20roles.">proved willing</a> to help export their military designs to allies. Even terrorist groups might be able to build, or at least acquire, large quantities of drones for urban attacks, either through covert smuggling or <a href="https://www.cfr.org/articles/irans-support-houthis-what-know#:~:text=Iran%20is%20the,Studies%20in%202023.">state sponsorship</a>.</p><p><strong>Drones can be used conventionally, not just for WMDs, making restrictions hard to enforce. </strong>To the extent that states have tried to impose restrictions on drone manufacturing or acquisition, they have largely failed to do so. This is partly because there is not a clear point of intervention in drone development: unlike other WMDs, whose primary purposes are terror and leverage, drones have legitimate civilian and conventional military uses. As a result, international organizations like the UN have done little more than condemn the principle of autonomous weapons, without yet addressing basic questions like the <a href="https://news.un.org/en/story/2025/05/1163256">definition of autonomy</a>.</p><p><strong>Drone swarms are a far more precise, controllable deterrent than other nonnuclear WMDs.</strong> Chemical weapons, although useful for terror, are difficult to widely disperse and threaten entire cities with. This combination of extreme fear and limited destruction thus invites the risk of <a href="https://academic.oup.com/jpr/advance-article/doi/10.1093/jopres/xjag001/8524883">extreme escalation</a> in retaliation, making them poor deterrents. On the opposite end of the spectrum, bioweapons are simply <a href="https://www.tandfonline.com/doi/abs/10.1080/01495930802358364">too destructive</a>, symmetrically threatening those who deploy them, as well as too invisible and delayed to create an immediate effect. Massive drone swarms, however, could be used to reliably besiege an entire city while remaining contained within it.</p><p><strong>Autonomous weapons are fundamentally hard to stop, particularly when aimed at civilians.</strong> Even if states are able to secure <a href="https://breakingdefense.com/2025/02/high-power-microwave-force-field-knocks-drone-swarms-from-sky/#:~:text=The%20CONOPs%20would,six%20of%20these.">individual targets</a>, such as military bases and political offices, securing the whole of society such that there are no soft targets for advanced drones would be enormously challenging. Even aside from their sheer size, cities are <a href="https://bylinetimes.com/2026/01/13/how-kherson-became-a-live-testing-ground-for-drone-defence-against-russias-human-safari-of-ukrainians/">difficult to cover</a> because they are both open enough to leave people exposed while moving and dense enough that interceptors will usually lack a clear line of sight, risking collateral damage. If this technology were to proliferate widely, the future might be one of constant and extreme geopolitical tension, where even minor military powers are tempted to assemble large swarms of murderous drones as deterrents.</p><h2>Taking Drone WMDs Seriously</h2><p>By all appearances, the kind of indiscriminate weapon described above is not far off. Autonomous drones that blindly hunt down humans and besiege cities, if they do not already exist, are held back more by ethics and military opportunity cost than any fundamental engineering problems.</p><p>But taking this threat seriously also means looking further ahead. There&#8217;s no reason to imagine that dumb, flying landmines are as far as drone technology will progress. Drones the <a href="https://www.scmp.com/news/china/science/article/3315206/chinese-military-robotics-lab-creates-mosquito-sized-microdrone-covert-operations">size of mosquitoes</a>, drones as cheap as bullets, drones so numerous their swarms <a href="https://funker530.com/video/us-drone-swarm-tech-blocks-out-the-sun">blot out the sky</a>, drones that never leave, <a href="https://aerial-core.eu/wp-content/uploads/2023/10/applsci-13-10175-v2.pdf">sitting on your power lines</a> and <a href="https://www.forbes.com/sites/davidhambling/2025/07/02/creeping-doom-russia-deploys-solar-powered-ambush-drones/">in the sun</a>.</p><p>These are not only possible but inevitable: if all that happens is just the normal grinding of drone engineering and mass production, cheap swarms of thousands, or even millions, of killer drones will eventually be universally available. Whether this happens in 5, 10, or 15 years is much less important than whether we are <a href="https://www.govinfo.gov/content/pkg/GOVPUB-D301-PURL-gpo139494/pdf/GOVPUB-D301-PURL-gpo139494.pdf">prepared to deal with it</a> when it does. Some policies, like <a href="https://www.orfonline.org/research/a-plague-on-the-horizon-concerns-on-the-proliferation-of-drone-swarms#:~:text=for%20military%20purposes.-,Combatting%20Proliferation,-States%20concerned%20about">nonproliferation and defensive investment</a>, can be effective only while the threat is still unrealized. To implement these policies for drones, and for all other future military technologies, we have to take what will be possible tomorrow seriously and plan for it today.</p><p><em>Thanks to Dan Hendrycks for advising on the premise of this piece.</em></p><p>&#8205;</p><div><hr></div><p><em><strong>See things differently? </strong>AI Frontiers welcomes expert insights, thoughtful critiques, and fresh perspectives. <a href="https://ai-frontiers.org/publish?utm_source=aif_article">Send us your pitch.</a></em></p><div><hr></div><p><em>Felix Choussat researches the geopolitics of advanced AI at the Center for AI Safety (CAIS), focusing on Sino-US competition and emerging military technology. Prior to his current role at CAIS, he was a governance fellow through the ML Alignment and Theory Scholars (MATS) and Pivotal Research programs, where he worked on modeling the proliferation of WMD-capable systems and compute-based AI deterrence. He holds a dual degree in international relations and history studies from Vanderbilt University.</em></p>]]></content:encoded></item><item><title><![CDATA[The Government Is Choosing AI Models. Who Chooses Their Values?]]></title><description><![CDATA[The public deserves a say over the values of government-procured AIs.]]></description><link>https://newsletter.ai-frontiers.org/p/the-government-is-choosing-ai-models</link><guid isPermaLink="false">https://newsletter.ai-frontiers.org/p/the-government-is-choosing-ai-models</guid><dc:creator><![CDATA[AI Frontiers]]></dc:creator><pubDate>Fri, 10 Jul 2026 14:02:09 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!eE-7!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffac04f95-da68-4756-8fc8-43ee6fde8925_6000x2702.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong><a href="https://ai-frontiers.org/author/kevin-frazier">Kevin Frazier</a></strong> and <strong><a href="https://ai-frontiers.org/author/andrew-reddie">Andrew Reddie</a></strong> &#8212; July 10, 2026</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!eE-7!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffac04f95-da68-4756-8fc8-43ee6fde8925_6000x2702.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!eE-7!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffac04f95-da68-4756-8fc8-43ee6fde8925_6000x2702.jpeg 424w, https://substackcdn.com/image/fetch/$s_!eE-7!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffac04f95-da68-4756-8fc8-43ee6fde8925_6000x2702.jpeg 848w, https://substackcdn.com/image/fetch/$s_!eE-7!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffac04f95-da68-4756-8fc8-43ee6fde8925_6000x2702.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!eE-7!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffac04f95-da68-4756-8fc8-43ee6fde8925_6000x2702.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!eE-7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffac04f95-da68-4756-8fc8-43ee6fde8925_6000x2702.jpeg" width="6000" height="2702" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/fac04f95-da68-4756-8fc8-43ee6fde8925_6000x2702.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:2702,&quot;width&quot;:6000,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:3177854,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!eE-7!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffac04f95-da68-4756-8fc8-43ee6fde8925_6000x2702.jpeg 424w, https://substackcdn.com/image/fetch/$s_!eE-7!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffac04f95-da68-4756-8fc8-43ee6fde8925_6000x2702.jpeg 848w, https://substackcdn.com/image/fetch/$s_!eE-7!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffac04f95-da68-4756-8fc8-43ee6fde8925_6000x2702.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!eE-7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffac04f95-da68-4756-8fc8-43ee6fde8925_6000x2702.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>In September 2025, the state of California made an AI assistant, <a href="https://www.genai.ca.gov/poppy/">Poppy</a>, generally available to employees, to help them &#8220;explore AI&#8217;s productivity benefits.&#8221; The following month, the North Dakota Legislative Council <a href="https://news.prairiepublic.org/local-news/2025-10-20/nd-legislative-council-using-ai">deployed</a> AI to assist with summarizing bills. And, in March 2026, the Los Angeles Superior Court <a href="https://www.businesswire.com/news/home/20260318640295/en/Learned-Hand-Announces-Partnership-With-Superior-Court-of-Los-Angeles-County-to-Explore-Emerging-Technology-to-Support-Judicial-Officers">partnered</a> with an AI company to provide support across several key functions, including &#8220;case information, summarization, research, analysis and drafting assistance,&#8221; as well as case management.</p><p>In the near future, it is likely that more US states and the federal government will direct the technology toward even more sensitive and significant tasks. AI may be used to adjudicate disputes, accelerate law-enforcement activities, and aid military operations to an even greater extent than it does today. As AI use cases are more regularly documented, scrutinized, fine-tuned, and optimized, people may actually demand increased AI adoption among government actors, even in sensitive domains. That raises the question: which models should be used?</p><p>This question has no simple answer. With other technologies, the choice of a specific model might largely come down to trade-offs between cost and performance. When it comes to AI, however, different frontier models may show significant differences in &#8220;character&#8221; or appear to align more closely with a particular political worldview. In choosing AI models for government operations, democratic states must therefore consider how best to represent the will of the people.</p><p>Currently, the federal government neither measures how a deployed model&#8217;s reasoning compares with the public&#8217;s nor asks whether divergence between the two is justified. In this piece, we make the case for a body that would answer the first question and equip officials to answer the second. It would keep the reasoning behind government AI open to public view and open to challenge when the people it serves see fit.</p><h2>How Model Character Could Influence Policy</h2><p><strong>Model character is a complex property formed through numerous factors.</strong> The character of each model&#8212;how it tends to respond to certain prompts and perform certain tasks&#8212;is a product of many specific decisions that are presently made by a small number of AI engineers working in a handful of frontier labs in an <a href="https://www.youtube.com/watch?v=REVf0JnLK0U">&#8220;informal&#8221; and evolving process</a>. Tweaks to the training data, the algorithms used to train and fine-tune the model, and company policy related to the model&#8217;s banned actions all shape character, among many other factors.</p><p><strong>Frontier developers have different approaches to shaping model character.</strong> If you read Claude&#8217;s <a href="https://www.anthropic.com/constitution">Constitution</a> and OpenAI&#8217;s <a href="https://model-spec.openai.com/2025-12-18.html">Model Spec</a>&#8212;the values that Anthropic and OpenAI, respectively, hope to infuse into their chatbots&#8212;you&#8217;ll see that, while the two labs outline some similar principles for their respective models, there are key differences. For instance, Claude&#8217;s Constitution outlines an ideal character for the model&#8212;namely, being a &#8220;good, wise, and virtuous agent,&#8221; whereas OpenAI&#8217;s Model Spec provides more explicit directions around what behaviors to pursue or to avoid and how to specifically adhere to a hierarchy of instructions.</p><p><strong>An AI model&#8217;s character could affect policy in both sudden and gradual ways.</strong> As AI systems are increasingly integrated into governmental decisions, the selection of one model over another might alter how presidents respond to crises, how lawmakers evaluate policy, and how judges draft opinions. For instance, depending on whether a congressional office relies on Claude, Grok, or ChatGPT, it may dismiss or fail to identify certain policy options.</p><p>In addition to such discrete moments of AI influence, serial exposure to a particular model&#8217;s assumptions, framing choices, and preferred forms of reasoning could gradually shape how government officials understand policy problems and evaluate trade-offs. Our fear recalls the proverbial frog in a pot of slowly boiling water: the choice of one model over another would alter many small decisions that add up to a major redirection in policy, regulation, and norms. Clearly, there is a need for a sober analysis of these risks.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://newsletter.ai-frontiers.org/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://newsletter.ai-frontiers.org/subscribe?"><span>Subscribe now</span></a></p><p><strong>Frontier AI development is currently too opaque to understand how character decisions are made.</strong> How should the public and, by extension, government stakeholders proceed with such a weighty task? Should they focus on an audit of the lab&#8217;s training data? Should they review the lab&#8217;s training process? Should they scrutinize the &#8220;constitution&#8221; or equivalent document the lab has crafted to shape the model&#8217;s character? And, within each of those possible inquiries, how should they rank which model is better than another? We don&#8217;t have the answers to those questions&#8212;in part because those inquiries are not feasible, given the current level of transparency (or lack thereof) across the labs. Indeed, there is no legal obligation for labs to disclose those core determinants of model character. Whether there should be is a topic best left for another essay.</p><p><strong>Few frontier models currently seem to be politically neutral.</strong> Notably, agencies are working through some of these questions, but no standardized approach has emerged for a comprehensive procurement evaluation. Pursuant to <a href="https://www.federalregister.gov/documents/2025/07/28/2025-14217/preventing-woke-ai-in-the-federal-government">Executive Order 14319</a>, &#8220;Preventing Woke AI in the Federal Government,&#8221; agencies are supposed to apply <a href="https://www.whitehouse.gov/wp-content/uploads/2025/12/M-26-04-Increasing-Public-Trust-in-Artificial-Intelligence-Through-Unbiased-AI-Principles-1.pdf">two &#8220;Unbiased AI Principles&#8221;</a>&#8212;truth-seeking and ideological neutrality&#8212;when selecting models. Yet, according to <a href="https://www.washingtonpost.com/technology/interactive/2026/06/24/are-ai-chatbots-like-chatgpt-politically-biased-we-tested-them/">recent testing</a> by <em>The Washington Post</em>, Gemini 3.1 Pro and Claude Opus 4.8 are the only leading models that appear to provide ideologically neutral answers to policy questions at least a majority of the time; OpenAI&#8217;s ChatGPT-5.5, in stark contrast, provides left-leaning answers in the vast majority of instances. How agencies are supposed to weigh these differences, and at which point a model&#8217;s tendency to provide skewed responses becomes a bar to its use, remains unclear.</p><h2>Introducing Public Reasoning Fidelity</h2><p>One approach to selecting AI models in line with democratic principles would be to choose the models that most closely mirror public reasoning in various decision-making scenarios.</p><p><strong>Public reasoning fidelity aims to identify models that best represent the public worldview.</strong> Our new framework, <strong>public reasoning fidelity</strong> (PRF), involves a process of asking a representative sample of the public to review hypothetical scenarios, ranging from whether to declare war to how to resolve a complex legal case. Models would then be tested on those same scenarios. Using this approach, the model whose outcomes and <a href="https://www.anthropic.com/research/natural-language-autoencoders">reasoning</a> most closely resemble those of the public would be given a significant preference in procurement decisions and usage policies. At the very least, there would be human-generated benchmarks for the behavior of a model within a particular use case.</p><p><strong>A model&#8217;s reasoning&#8212;not just its ultimate decision&#8212;should track that of the public.</strong> A model that reaches the same bottom-line answer as a representative public panel but does so for reasons the public rejects should not receive the same score as a model that mirrors both the public&#8217;s resolution and its path to that resolution. In government, the rationale behind a decision may matter as much as the outcome itself, because explanations shape precedent, accountability, and public trust. A judge, legislator, or agency official is not merely choosing between results in most contexts. Each is relying on an explanation that may shape how future questions are framed, which facts are treated as relevant, and which trade-offs are placed at the center of public decision-making.</p><p><strong>PRF could select different AI models in different domains.</strong> Ideally, the PRF process would occur in specific domains. For instance, the selection of the model used by law enforcement should be grounded in the model&#8217;s PRF score on police-related hypothetical scenarios, and it should be conducted separately from model selection for military use cases. This would reduce the odds of PRF scores being too broad to be meaningful to procurement officers looking for a model that is likely to be deployed in specific domains in which the public may have unique preferences and rationales.</p><p>The promise of this approach is that it gives public institutions a structured, human-generated benchmark in relevant domains where today they tend to rely on vendor claims and internal testing. PRF is not a silver bullet, though. A quick overview of its potential pitfalls reveals why adopting PRF would require additional safeguards.</p><p><strong>One pitfall of PRF is that models could match public judgment to a fault.</strong> Aligning with the public&#8217;s reasoning may satisfy concerns about a model drifting from how the people approach an issue, but it might also mean the model leans on questionable policy analysis. As explained, PRF rewards similarity, not quality. A model earns a high score by reasoning as the public reasons, which is <a href="https://delibdemjournal.org/article/401/galley/4668/view/">sometimes</a> but not always the same as reasoning well.</p><p>On questions where the considered public judgment is mistaken, or simply less informed than the record allows, a model that tracks the public will be rewarded precisely for its errors, and a model that reasons its way to a better answer will be penalized for departing from the crowd. This is Goodhart&#8217;s law in its familiar form. Once fidelity to public reasoning becomes a procurement target, labs will optimize for it and might avoid alternative development practices that help models reason <em>better </em>than the public. In short, the risk is a kind of policy-analysis sycophancy, a failure mode the labs already struggle to suppress.</p><p><strong>The PRF process must be designed to avoid collapsing into policy homogeneity.</strong> The danger deepens when PRF informs model selection by government officials. If agency staff or lawmakers subtly adopt the reasoning embodied by their model of choice, and if PRF then selects the model whose reasoning most closely matches the public&#8217;s, the instrument may end up producing excessively homogeneous policy proposals. Our deliberative processes work best when they allow for nuanced consideration of a wide range of perspectives. The PRF process must be designed to prevent it from undercutting that characteristic.</p><p><strong>On many salient questions, there is no single public or reasoning approach to be faithful to.</strong> On issues including abortion, firearms, immigration, and election administration, the public holds not one considered judgment but two or more, sorted sharply by party. Here, any single PRF target is a fiction that averages into a position almost no citizen holds. For these polarized domains, the sensible move is to stop asking whether a model matches the median and start asking whether it can represent the competing lines of reasoning fairly rather than collapsing them into one.</p><p>That reframing connects PRF to the neutrality criterion that the federal government has already gestured at in Executive Order 14319. A model that can articulate the strongest version of each side, and does not systematically resolve contested value questions toward one pole, is closer to what &#8220;ideological neutrality&#8221; is reaching for than a model that happens to match a manufactured center.</p><p><strong>In more technical domains, experts could communicate the facts to the representative public panel.</strong> The hardest problem is likely to be generalization. A representative panel probably has intuitions worth eliciting on whether to declare war or how to resolve a vivid legal dispute. It likely has far less to offer on the capital adequacy of regional banks, the ozone standard under the Clean Air Act, or the fiduciary rules governing retirement plans.</p><p>One fix is to split the exercise into the two tasks it actually requires. A domain committee, explained in more detail below, builds the record. Drawing on the experts among its members, the committee curates the facts, translates the jargon, and lays out the competing arguments. The judgment still comes from an informed lay panel that works through that record, much as deliberative polls and citizens&#8217; assemblies have done on technical questions, from electoral reform in British Columbia to constitutional change in Ireland. The committee informs the public but does not stand in for it. PRF then measures whether a model weighs the trade-offs as an informed public would, once the record is set.</p><p>In the most specialized fields, a lay panel will track whichever expert framing proves most persuasive, so PRF there measures fidelity to the committee&#8217;s framing as much as to the public&#8217;s reasoning. The upshot: in technical domains, a PRF score is only as good as the committee that built the record. Avoiding these pitfalls will require robust, carefully considered oversight of the entire PRF process. This is why the institutional design that follows is of critical importance to PRF&#8217;s odds of success.</p><h2>Designing an Institution to Evaluate PRF</h2><p><strong>A process as consequential as PRF would need an institutional home.</strong> At the federal level, Congress could create a standing &#8220;Commission on Public AI Use,&#8221; housed within the Center for AI Standards and Innovation, which is home to the leading AI experts within the federal government. This commission could oversee the curation of hypotheticals, the selection of representative public panels, and the comparison between public responses and model responses (note that states should also explore the creation of such bodies&#8212;the focus of this essay is at the national level). These scenarios might subsequently be shared with subnational agencies.</p><p><strong>The commission could rely on domain-specific committees to develop hypotheticals.</strong> Within the commission, a judicial-use committee could include former judges, legal scholars, practicing attorneys, court administrators, technologists, and members of the public. A law-enforcement committee could include former prosecutors, defense attorneys, civil rights lawyers, police officials, local-government representatives, and community members. Importantly, each committee would develop sealed hypotheticals designed to test the kinds of questions that may arise in that domain. Of course, those hypotheticals would not be disclosed until the testing period, to reduce the risk that labs train to the test.</p><p><strong>The public panels, not the committees, are the basis of the benchmark.</strong> Each committee builds the record and writes the questions. But, to be abundantly clear, its panel renders the judgment that the model is scored against. &#8220;Representative&#8221; here refers to panel members being drawn by lot and stratified to mirror the domain&#8217;s relevant population, on the deliberative-polling model described above. For a model used in immigration adjudication, for example, the panel should reflect the demographics of the communities that appear before immigration courts. Panel members are not appointed, and they may not have their judgment usurped by a committee of experts.</p><p>Each representative panel would review common factual records and competing arguments before producing their own outcomes and reasoning. AI models would be given the same materials. The committee would then compare the models to its public panel across two dimensions: whether the model reached a similar outcome and whether its reasoning reflected the same concerns, priorities, and limiting principles.</p><p><strong>The commission appointment process should be designed to avoid political capture.</strong> What stops a new administration from reshaping the exercise to fit its preferred style of governance? The panel resists capture on its own terms because no one can pack a lottery. Each cycle draws a fresh random sample, so partisanship enters the panel only in the proportion it holds in the population, and it enters each time anew. The commission, however, whose members are appointed, is more exposed to political machinations. Congress should armor it as it armored the US Sentencing Commission, which caps single-party membership at a bare majority of seats, sets staggered six-year terms that outlast any single presidency, and permits removal only for cause.</p><h2>Precedents</h2><p>While setting up new oversight bodies and processes designed to operate well over the long term is a significant challenge, it has been done successfully before.</p><p><strong>The proposed institutional design would not be entirely novel.</strong> The US Sentencing Commission referenced above offers a useful analogy. It operates in a highly sensitive domain, translates legal and policy judgments into structured guidance, and attempts to promote consistency without eliminating judgment. The commission establishes sentencing policies and practices for the federal criminal justice system. Congress took due care to place expertise within the commission&#8212;including designated slots for former judges&#8212;while still leaving tremendous discretion to the judges tasked with applying the commission&#8217;s recommendations for sentencing lengths.</p><p>The <a href="https://www.acus.gov/">Administrative Conference of the United States</a> serves as another example. ACUS does not run agencies, but it studies administrative practice and issues recommendations designed to improve fairness, efficiency, and accountability across government.</p><p>A Commission on Public AI Use would play a similar role for AI adoption. Importantly, it would not replace elected officials, judges, agency heads, or procurement officers. It would give them the results of a benchmark developed in a participatory process. Rather than relying solely on vendor claims, internal testing, or the informal preferences of government employees, public institutions would have access to a structured assessment of how competing models reason through hard cases compared with the considered judgment of the people those institutions serve.</p><p>Some will view this process as premature or overly cumbersome. That critique overlooks a more immediate reality: AI models are already shaping how government actors make consequential decisions, yet the public has almost no meaningful role in overseeing how those systems are selected or evaluated. While the PRF mechanism may not be perfect, an oversight system must be developed. Absent such oversight, there&#8217;s a risk of civil servants, agency heads, and elected officials trying to blame poor decisions on AI. Those excuses would have far less weight if the public and policymakers alike knew more about how models operate in particular contexts.</p><p><strong>PRF does not hand all decisions to the public, but it allows public scrutiny of government AI tools. </strong>One obvious concern with this proposal is that public opinion is not synonymous with sound governance. Presidents, judges, legislators, and agency officials routinely make decisions that depart from majority sentiment because they are bound by constitutional constraints, institutional obligations, classified information, or technical expertise unavailable to the general public. As noted above, a model that perfectly mirrors public sentiment may therefore still be poorly suited for certain governmental functions.</p><p>That concern should shape how PRF is understood. The purpose of PRF is not to hand public polling the reins of government decision-making. Nor is it to create a plebiscitary mechanism for selecting AI systems. The point is narrower and more practical: public institutions should know whether the models they rely on consistently reason through difficult questions in ways that diverge from the public.</p><p>At present, that divergence is almost entirely invisible. Agencies, courts, and legislatures may adopt tools whose assumptions, value judgments, and interpretive tendencies subtly shape official decision-making, without any meaningful public scrutiny. PRF would help surface those tendencies. In some cases, decision-makers may conclude that a model&#8217;s divergence from public reasoning is justified by legal doctrine, technical realities, or institutional constraints. In others, that divergence may raise concerns about legitimacy, accountability, or democratic responsiveness. Either way, the divergence itself should not remain hidden from the public.</p><h2>The Public Should Choose Public AI Values</h2><p>Government adoption of AI should not proceed as though model selection is ordinary software procurement. When public institutions rely on systems that reason, rank values, frame trade-offs, and influence official judgment, the public has a legitimate interest in knowing how those systems think through hard cases. PRF would not answer every question raised by government AI use and may not be useful in certain domains, but it would make one question harder to avoid: whether the models acting in the public&#8217;s name reason in ways the public can recognize, evaluate, and contest. That is the minimum a democratic government should demand before allowing private model choices to become public governing defaults.</p><p>&#8205;</p><div><hr></div><p><em><strong>See things differently? </strong>AI Frontiers welcomes expert insights, thoughtful critiques, and fresh perspectives. <a href="https://ai-frontiers.org/publish?utm_source=aif_article">Send us your pitch.</a></em></p><div><hr></div><p><em>Kevin Frazier is the Inaugural AI Innovation and Law Fellow at Texas Law.</em></p><p><em>Andrew W. Reddie is an Associate Research Professor at the University of California, Berkeley&#8217;s Goldman School of Public Policy, and Founder and Faculty Director of the Berkeley Risk and Security Lab.</em></p>]]></content:encoded></item><item><title><![CDATA[AI Governance Needs Radical Optionality]]></title><description><![CDATA[One of the most valuable things governments can build today is the capacity to govern advanced AI competently in the future.]]></description><link>https://newsletter.ai-frontiers.org/p/ai-governance-needs-radical-optionality</link><guid isPermaLink="false">https://newsletter.ai-frontiers.org/p/ai-governance-needs-radical-optionality</guid><dc:creator><![CDATA[AI Frontiers]]></dc:creator><pubDate>Mon, 06 Jul 2026 13:00:06 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!oThs!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac394a6c-b2cf-4064-8314-b8ea967e5f67_6000x3500.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong><a href="https://ai-frontiers.org/author/charlie-bullock">Charlie Bullock</a></strong><span>, Senior Research Fellow at the Institute for Law &amp; AI</span> &#8212; July 6, 2026</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!oThs!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac394a6c-b2cf-4064-8314-b8ea967e5f67_6000x3500.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!oThs!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac394a6c-b2cf-4064-8314-b8ea967e5f67_6000x3500.jpeg 424w, https://substackcdn.com/image/fetch/$s_!oThs!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac394a6c-b2cf-4064-8314-b8ea967e5f67_6000x3500.jpeg 848w, https://substackcdn.com/image/fetch/$s_!oThs!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac394a6c-b2cf-4064-8314-b8ea967e5f67_6000x3500.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!oThs!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac394a6c-b2cf-4064-8314-b8ea967e5f67_6000x3500.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!oThs!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac394a6c-b2cf-4064-8314-b8ea967e5f67_6000x3500.jpeg" width="1456" height="849" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ac394a6c-b2cf-4064-8314-b8ea967e5f67_6000x3500.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:849,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!oThs!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac394a6c-b2cf-4064-8314-b8ea967e5f67_6000x3500.jpeg 424w, https://substackcdn.com/image/fetch/$s_!oThs!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac394a6c-b2cf-4064-8314-b8ea967e5f67_6000x3500.jpeg 848w, https://substackcdn.com/image/fetch/$s_!oThs!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac394a6c-b2cf-4064-8314-b8ea967e5f67_6000x3500.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!oThs!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac394a6c-b2cf-4064-8314-b8ea967e5f67_6000x3500.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>How should governments regulate the most advanced AI systems? One possible answer is that they should not. Libertarian-minded writers have <a href="https://papers.ssrn.com/sol3/papers.cfm?abstract_id=4404402">made the case</a> for a culture of &#8220;permissionless innovation&#8221; for AI development, in which the role of government would be <a href="https://www.rstreet.org/research/flexible-pro-innovation-governance-strategies-for-artificial-intelligence/">limited</a> to enforcing existing laws and facilitating industry self-regulation with &#8220;soft law&#8221; tools such as voluntary standard-setting. Another possibility, more in vogue across the aisle and the <a href="https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex%3A52000DC0001">pond</a>, would invoke the <a href="https://papers.ssrn.com/sol3/papers.cfm?abstract_id=2532598">precautionary principle</a>, using heavy-handed regulation to restrict the development of <a href="https://law-ai.org/wp-content/uploads/2024/09/Legal-Considerations-for-Defining-Frontier-Model.pdf">frontier</a> AI models until developers can adequately prove that their systems are safe.</p><p>I think there&#8217;s a better approach. In a new <a href="https://radical-optionality.ai/">essay</a>, my co-author Christoph Winter and I make the case for a governance strategy that we call &#8220;radical optionality.&#8221; The idea is simple: governments should avoid over-regulation in the short term while building up the institutional capacity needed to competently regulate extremely advanced or &#8220;<a href="https://www.openphilanthropy.org/research/some-background-on-our-views-regarding-advanced-artificial-intelligence/">transformative</a>&#8221; future AI systems when and if these systems come into existence. The point of this approach is to maximize optionality by providing our institutions with tools that can be used to respond to a wide range of foreseen or unforeseen future developments.</p><p>In this piece, we explain the rationale behind maximizing optionality while AI&#8217;s future impacts remain uncertain. We also outline some example measures that governments can take and explain how this approach dovetails with other proposals for AI governance.</p><h2>Addressing AI Risks Under Uncertainty</h2><p>Leading AI researchers in academia and industry have claimed that advances in AI capabilities may soon produce &#8220;<a href="https://yoshuabengio.org/2024/10/30/implications-of-artificial-general-intelligence-on-national-and-international-security/">AGI</a>,&#8221; &#8220;<a href="https://www.nytimes.com/2025/06/10/technology/meta-new-ai-lab-superintelligence.html">artificial superintelligence</a>,&#8221; &#8220;<a href="https://www.darioamodei.com/essay/machines-of-loving-grace">powerful AI</a>,&#8221; or some similar term. If you are certain that these statements are hype, and that such advanced AI systems will not arrive during our lifetimes, I won&#8217;t try to convince you otherwise; enough ink has been spilled on the subject that I&#8217;m not optimistic about my ability to contribute anything new. But if you think there is even a small chance that these predictions materialize, or if you find them at all credible, we think that the argument for radical optionality is overwhelmingly strong. The argument goes as follows.</p><p><strong>AI&#8217;s future impacts are highly uncertain.</strong> Assume that there is some possibility of transformative AI systems being invented within the next, say, 15 years or so. Most of us are extremely uncertain about exactly how and when this will happen, what the characteristics and tendencies of these systems will be, what benefits they will offer society, and what risks to public safety and national security they will create. Under some assumptions, these systems will be <a href="https://a16z.com/ai-will-save-the-world/">mostly harmless and highly beneficial</a>, because the companies creating them will have incentives to make them safe and broadly aligned with human preferences. Under other assumptions, these systems will be dangerous and difficult to control&#8212;perhaps even capable of causing <a href="https://time.com/6266923/ai-eliezer-yudkowsky-open-letter-not-enough/">human extinction</a> if the right <a href="https://arxiv.org/pdf/2410.21572">guardrails</a> are not put in place. Maybe <a href="https://www.nationalsecurity.ai/">securitization</a> is inevitable and the U.S. government will soon <a href="https://situational-awareness.ai/">spring into action</a> and develop these systems behind closed doors as part of a clandestine military project. Alternatively, perhaps development will happen in a <a href="https://vitalik.eth.limo/general/2023/11/27/techno_optimism.html">decentralized and democratic</a> way.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://newsletter.ai-frontiers.org/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://newsletter.ai-frontiers.org/subscribe?"><span>Subscribe now</span></a></p><p><strong>The question of regulation seems to present a tradeoff between innovation and security. </strong>Debating which of the scenarios described is most realistic can be valuable, but ultimately only ideologues claim to be certain about the future course of a <a href="https://www.darioamodei.com/post/the-urgency-of-interpretability">poorly understood</a> emerging technology. The rest of us have to make important decisions about what to do while acknowledging substantial uncertainty. On the one hand, restrictively regulating AI companies would <a href="https://x.com/sebkrier/status/1965515202943954954">slow down innovation</a>, potentially depriving society of some of the benefits of technological progress. On the other hand, it is possible that well-designed regulations could mitigate the real risks that AI systems pose, both now and in the future. How should we think about this tradeoff between innovation and security?</p><p><strong>Measures that maximize optionality can improve security without hindering innovation.</strong> We think that this framing misses an essential point: there are steps governments can take now that would increase security without any significant cost to innovation. At the top of the list are light-touch information-gathering authorities like <a href="https://law-ai.org/how-to-design-ai-whistleblower-legislation/">whistleblower protections</a>, <a href="https://law-ai.org/commerce-federal-ai-regulation/">reporting requirements</a>, and <a href="https://carnegieendowment.org/research/2025/07/state-ai-law-whats-coming-now-that-the-federal-moratorium-is-dead?lang=en">transparency mandates</a>. Government agencies thrive on a diet of information; it has been <a href="https://arxiv.org/abs/2404.02675">said</a> that &#8220;information is the lifeblood of good governance.&#8221; Authorities that increase the government&#8217;s access to important information about AI risks&#8212;and allow the relevant agencies to develop expertise in securely processing and interpreting such information&#8212;are foundational building blocks for future governance efforts. Mechanisms for securely and intelligently sharing information within government, and (when appropriate) <a href="https://arxiv.org/abs/2503.04741">between governments</a>, are similarly foundational.</p><p>Building capacity directly is also important. First and foremost, this means enabling the relevant regulatory bodies to hire and retain elite talent. Meta&#8217;s recent <a href="https://www.nytimes.com/2025/07/31/technology/ai-researchers-nba-stars.html">hiring spree</a>, featuring <a href="https://www.telegraph.co.uk/business/2025/07/30/ai-researcher-turns-down-1bn-pay-offer-mark-zuckerberg/">10-figure</a> compensation package offers for top AI talent, is an example of what it looks like when an organization takes the prospect of transformative AI seriously. Governments will likely be unable to compete with the salaries on offer in the private sector, but <a href="https://www.rebuilding.tech/posts/reforming-federal-hiring-for-tech-policy-talent">reforms</a> to processes for government hiring and contracting of AI talent are nevertheless needed in both the U.S. and the EU. The <a href="https://time.com/7204670/uk-ai-safety-institute/">early successes</a> of the UK&#8217;s AI Security Institute, which receives <a href="https://fas.org/publication/a-national-center-for-advanced-ai-reliability-and-security/">10 times the funding</a> of its U.S. counterpart despite the UK&#8217;s relatively modest GDP and industry relevance, demonstrates the importance of cultivating talent in government.</p><p>The full-length <a href="https://radical-optionality.ai/">essay</a> discusses a number of other optionality-increasing policy decisions, such as <a href="https://milesbrundage.substack.com/p/why-security-comes-first">incentivizing lab security</a>, avoiding <a href="https://x.com/CharlieBul58993/status/1938242014656524736">premature and overbroad preemption of state laws</a>, and building out an <a href="https://www.aisi.gov.uk/work/early-lessons-from-evaluating-frontier-ai-systems?utm_source=chatgpt.com">ecosystem for model assessments and evaluations</a>. But the important thing is to recognize that security and innovation are not conflicting priorities, because there are ways to increase optionality without creating any significant barriers to technological progress.</p><h2>Supporting Both Security and Innovation</h2><p><strong>Radical optionality is compatible with other proposals for AI governance.</strong> Radical optionality is by no means the first AI governance framework to recognize that governments have an important role to play while also acknowledging that overly restrictive regulation could hinder innovation. <a href="https://arxiv.org/pdf/2504.11501">Dean Ball</a> and <a href="https://arxiv.org/abs/2304.04914">Gillian Hadfield and Jack Clark</a> have proposed sophisticated private governance regimes in which the government would certify an ecosystem of private regulators competing to offer efficient and nimble regulatory services to companies on an opt-in basis. Gabriel Weil has <a href="https://ai-frontiers.org/articles/case-for-ai-liability">argued</a> that a well-designed <a href="https://www.lawfaremedia.org/article/tort-law-should-be-the-centerpiece-of-ai-governance">tort liability</a> regime, <a href="https://papers.ssrn.com/sol3/papers.cfm?abstract_id=6173619">featuring</a> insurance requirements, punitive damages, and strict liability for certain harms, could force AI companies to internalize any risks generated by their products. And Cary Coglianese has advocated for a system of <a href="https://papers.ssrn.com/sol3/papers.cfm?abstract_id=5137081">management-based regulation</a>, requiring AI companies to take risk mitigation measures but allowing them broad discretion over what measures to implement and how. I view these proposals as consistent and compatible with radical optionality; tort liability, management-based regulation, and private governance mechanisms are valuable tools for maintaining and increasing optionality.</p><p><strong>Under most worldviews, radical optionality is preferable to the status quo.</strong> Of course, not everyone will agree that an optionality-maximizing approach is wise or sufficient. If you confidently believe that the safety benefits of a restrictive AI regulatory regime would outweigh the costs to society of slowing innovation, it is reasonable to suggest that <a href="https://www.adalovelaceinstitute.org/report/safe-before-sale/">anticipatory regulation</a> is needed. From this perspective, radical optionality does not go far enough, but it would still be preferable to the status quo. On the other hand, from a libertarian perspective, building up government capacity to regulate and promising that it will not be used prematurely might look a lot like giving the government a hammer and promising that agencies will not start hallucinating nails. I can&#8217;t promise that there is no chance of new authorities being abused, or that everyone will agree on when dual-use AI systems have become so advanced that regulating them is a national security imperative. But I do expect building government capacity to benefit AI companies as well as the public in the long term. If rapid progress in AI capabilities research gives rise to a surge in public demand for regulation at some point in the future, as some writers <a href="https://www.brookings.edu/articles/the-coming-ai-backlash-will-shape-future-regulation/?utm_source=chatgpt.com">have</a> <a href="https://www.cnas.org/publications/commentary/the-united-states-must-avoid-ais-chernobyl-moment">predicted</a>, companies might prefer for the government to have the option of regulating in a competent, targeted manner.</p><p>At my organization, the <a href="https://law-ai.org/">Institute for Law &amp; AI</a>, we spend a lot of time thinking about how advanced AI systems should be governed in the present and in the future. Radical optionality is a sort of organizing principle and guiding philosophy for that research and consulting work. When deciding what projects to work on, what bills to offer feedback on, and what policies to push for, the question of what approach will maximize optionality is typically one of the foremost considerations. In publishing this paper, I hope to convince at least a few people to adopt this framing, to recognize the importance of optionality, and to begin viewing security and innovation as compatible rather than conflicting priorities.</p><p>&#8205;</p><div><hr></div><p><em><strong>See things differently? </strong>AI Frontiers welcomes expert insights, thoughtful critiques, and fresh perspectives. <a href="https://ai-frontiers.org/publish?utm_source=aif_article">Send us your pitch.</a></em></p><div><hr></div><p><em>Charlie Bullock is a Senior Research Fellow at the Institute for Law &amp; AI. He advises state and federal policy makers on AI governance topics and publishes research on legal questions with significant practical relevance to U.S. AI policy. His recent research examines issues including federal preemption of state AI laws, federal and state AI whistleblower protection legislation, and the likely consequences of the end of Chevron deference for the future of AI regulation. Charlie received his J.D. from Yale Law School, where he was an Editor for the Yale Journal on Regulation.</em></p>]]></content:encoded></item><item><title><![CDATA[Three Models of Sino-American Competition for the Soul of AI]]></title><description><![CDATA[American leaders agree that the AI race will shape the balance of power with China. But they can&#8217;t agree on how to ensure the technology advances American values.]]></description><link>https://newsletter.ai-frontiers.org/p/three-models-of-sino-american-competition</link><guid isPermaLink="false">https://newsletter.ai-frontiers.org/p/three-models-of-sino-american-competition</guid><dc:creator><![CDATA[AI Frontiers]]></dc:creator><pubDate>Tue, 30 Jun 2026 13:02:06 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!zI0o!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F02b7df73-a6d6-4817-8a56-bc5c1d5e6cee_6014x4014.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong><a href="https://ai-frontiers.org/author/bill-drexel">Bill Drexel</a></strong><span>, Senior Fellow at the Hudson Institute</span> &#8212; June 30, 2026</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!zI0o!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F02b7df73-a6d6-4817-8a56-bc5c1d5e6cee_6014x4014.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!zI0o!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F02b7df73-a6d6-4817-8a56-bc5c1d5e6cee_6014x4014.jpeg 424w, https://substackcdn.com/image/fetch/$s_!zI0o!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F02b7df73-a6d6-4817-8a56-bc5c1d5e6cee_6014x4014.jpeg 848w, https://substackcdn.com/image/fetch/$s_!zI0o!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F02b7df73-a6d6-4817-8a56-bc5c1d5e6cee_6014x4014.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!zI0o!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F02b7df73-a6d6-4817-8a56-bc5c1d5e6cee_6014x4014.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!zI0o!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F02b7df73-a6d6-4817-8a56-bc5c1d5e6cee_6014x4014.jpeg" width="1456" height="972" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/02b7df73-a6d6-4817-8a56-bc5c1d5e6cee_6014x4014.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:972,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!zI0o!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F02b7df73-a6d6-4817-8a56-bc5c1d5e6cee_6014x4014.jpeg 424w, https://substackcdn.com/image/fetch/$s_!zI0o!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F02b7df73-a6d6-4817-8a56-bc5c1d5e6cee_6014x4014.jpeg 848w, https://substackcdn.com/image/fetch/$s_!zI0o!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F02b7df73-a6d6-4817-8a56-bc5c1d5e6cee_6014x4014.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!zI0o!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F02b7df73-a6d6-4817-8a56-bc5c1d5e6cee_6014x4014.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>When officials in Washington warn about losing the AI race to China, the conversation turns quickly to military and economic advantage&#8212;and rightly so. Advanced AI will reshape everything from weapons systems to medicine, with massive implications for our geopolitical competitiveness. But beneath the great-power competition on AI lies a moral one. The ethical character of the most transformative technology in generations&#8212;one that will mediate an ever-larger share of human experience&#8212;will be a byproduct of superpower rivalry. At stake is the future of the relationship between individuals and the state, of privacy and control, of human agency and algorithmic authority.</p><p>The fear is not merely that China might build better systems, deploy them more widely, or out-sell American competitors. It is that those systems could carry a tide of new norms shaped by a government that surveils its citizens, suppresses dissent, harbors eugenic <a href="https://www.thenewatlantis.com/publications/the-ai-genetics-revolution-is-coming">ambitions</a>, and treats individual autonomy as a problem. As AI comes to dominate our lives as thoroughly as digital media already has&#8212;shaping our health and finances, how our children learn, how we are tracked, even our species&#8217; genetic makeup&#8212;this battle for AI&#8217;s soul will affect us all intimately.</p><p>The contours of that battle are almost always left unexamined, but usually assume one of three forms: some leaders suggest AI&#8217;s values will be a winner-takes-all byproduct of the race to technical superiority; others imply a conscious struggle to spread tools and platforms with value systems baked in; still others insist that diplomatic cooperation between AI powers is the only way to bend AI&#8217;s ethical arc toward humanity&#8217;s benefit. Leaving these three paradigms implicit does everyone a disservice, robbing the United States of both moral clarity and strategic opportunity.</p><p>Looking at the history of technological competition, there may be truth to all of these three models. But each implies a different approach to maintaining American leadership while preserving the values we claim to champion. And analyzing them clearly reveals how badly our attention is skewed. Today&#8217;s debate fixates on breakaway dominance, blinding policymakers to the more consequential contests over encoded values and strategic diplomacy. A rebalanced approach would require something we currently lack: a clear, affirmative vision of what American AI should be for.</p><h2>Breakaway Tech Dominance</h2><p>&#8220;AI offers the potential promise of extending American hegemony.&#8221;</p><p>&#8212;<a href="https://www.thefp.com/p/there-is-no-turning-back-on-ai">Tyler Cowen</a></p><p>Breakaway tech dominance is the default (if often implicit) ambition for many leaders invested in the Sino-American AI competition. The thinking goes that if the US is able to master AI ahead of others, that advantage will translate into a general offset in American power over China, with powerful ripple effects in economics, culture, and politics globally. Because this winner-takes-all vision provides such a clear motivation for forging ahead, it is the one most often invoked by pro-tech voices and government leaders.</p><p><strong>Historically, large technological advantages tend to precede hegemonic power.</strong> This dominant narrative about AI competition draws heavily on historical analogy. Britain&#8217;s industrial revolution produced not just economic advantages but also cultural ascent. British institutions, law, language, and ideas spread across the globe on the strength of steam engines and mechanized looms. And this was not history&#8217;s first instance of technological offset, a dynamic that has persisted since before the Assyrians&#8217; mastery of iron metallurgy expanded their influence over rival groups.</p><p><strong>Applied to AI, this logic suggests that the first nation to achieve a decisive breakthrough could gain civilizational escape velocity.</strong> According to this view, if China masters AI before America does, Beijing&#8217;s authoritarian model&#8212;surveillance systems, social credit schemes, algorithmic control of information and behavior&#8212;would spread globally with irresistible momentum. Given that many experts expect the AI transformation to be <a href="https://business.columbia.edu/research-brief/research-brief/ai-industrial-revolution">comparable</a> in scope to industrialization or the dawn of the Iron Age, such fears are justified. Whether or not there are dramatic power shifts between the United States and China in the century ahead, AI is certain to play an outsized role.</p><p><strong>According to this paradigm, the singular priority must be aggressive progress in AI capabilities.</strong> The strategic implication of this perspective is obvious: there is nothing so important as moving faster than China in pushing the bounds of AI technology. Additionally, there is little need for the United States to consider how American values relate to its AI strategy, because they are seen as downstream of the technical rivalry. In other words, if the United States establishes a decisive AI lead, its values will organically spread; if China masters the technology first, Beijing&#8217;s moral vision will take root globally.</p><p><strong>An AI lead sufficient to achieve hegemony is unlikely to appear on either side.</strong> The breakaway-dominance framework functions only if there is a defensible breakthrough to be had, which is not necessarily the case.<strong> </strong>Some <a href="https://ai-2027.com/">predictions</a> of a superintelligence &#8220;takeoff&#8221;&#8212;in which a sufficiently advanced AI system starts to improve itself better and faster than humans could&#8212;fit that mold. But despite regular predictions of imminent AGI breakthroughs, even many bullish researchers are <a href="https://youtu.be/ZBFG3WvweEM?si=pLzoE9hqmb97h0fy&amp;t=1742">increasingly</a> <a href="https://www.techpolicy.press/most-researchers-do-not-believe-agi-is-imminent-why-do-policymakers-act-otherwise/">skeptical</a> of such a scenario, making the prospects of a highly dominant and defensible AI hegemon seem unlikely.</p><p><strong>US-China competition is also too tight for breakaway dominance to occur.</strong> The observable pattern of AI progress in recent years suggests a different path. China has successfully positioned itself as an aggressive fast follower. In frontier models, the most competitive arena of AI competition, Chinese labs tend to trail American counterparts by just <a href="https://www.chathamhouse.org/2025/11/low-cost-chinese-ai-models-forge-ahead-even-us-raising-risks-us-ai-bubble">months</a> at a fraction of the <a href="https://hai.stanford.edu/assets/files/ai_index_report_2026.pdf">cost</a>. That is an achievement in itself&#8212;and it diminishes the likelihood that the United States will achieve a sustained, decisive advantage. While not impossible, it&#8217;s unlikely that we will see either country develop and maintain an AI lead significant enough to extend Chinese or Western values globally for any sustained length of time unchallenged. This winner-takes-all model, despite its implicit prominence in many policy discussions, almost certainly misses the full picture.</p><h2>Encoded Values</h2><p>&#8220;China is doing everything it can to dominate AI globally, and they will program the AI with Chinese values&#8230;. We&#8217;ve got to double down and make sure that American values are the values of the world, and that we control this global AI agenda.&#8221;</p><p>&#8212;Former US Senator <a href="https://www.foxnews.com/media/kyrsten-sinema-warns-us-adversary-program-ai-chinese-values-america-falls-behind-tech-race">Kyrsten Sinema</a> (I-AZ)</p><p>A second model for looking at the moral stakes of Sino-American AI competition is the spread of encoded values: the ethics that are baked into new technologies, whether deliberately or subconsciously. This dynamic is ancient: Roman aqueducts built republican virtues into stone by distributing water first to public fountains, then to public baths, and only later to private homes. Fast-forward to the present day, when the internet stands out as a technology consciously designed with libertarian principles: decentralized architecture, open protocols, and resistance to central control. The resulting technology reflected those values in its most basic protocols (if only <a href="https://www.theguardian.com/news/2018/jun/29/the-great-firewall-of-china-xi-jinpings-internet-shutdown">initially</a>).</p><p>The same will be even truer of AI, given its unique ability to <a href="https://manhattan.institute/article/measuring-political-preferences-in-ai-systems-an-integrative-approach">absorb</a> and instantiate value systems. The protocols and architecture around AI systems may also reflect value decisions, but particular moral visions and preferences can also be directly distilled in today&#8217;s AI systems&#8212;or <a href="https://agileloop.ai/perplexity-ai-revamps-deepseek-r1-with-r1-1776-a-censorship-free-ai-model/">rooted out</a> of them.</p><p><strong>China has been explicit about its intentions to imbue AI with its own values.</strong> Official Chinese government regulations mandate that frontier AI systems <a href="https://www.cac.gov.cn/2023-07/13/c_1690898327029107.htm">must</a> &#8220;uphold core socialist values&#8221;&#8212;that is, they must adhere to the Chinese Communist Party&#8217;s totalitarian view of history and morality. Chairman Xi Jinping has already made considerable strides toward that end. Beijing invests tens of billions of dollars annually in building a techno-authoritarian ecosystem of tools, platforms, standards, and norms aligned with state priorities: social stability, party authority, and collective &#8220;harmony,&#8221; rather than individual autonomy. Its companies are experimenting with novel, AI-powered methods of conducting surveillance, enhancing censorship, and even <a href="https://www.nytimes.com/2026/06/01/us/politics/china-ai-predicting-dissent.html?unlocked_article_code=1.m1A.3Lgl.RV2Y1VZbzaHq&amp;smid=url-share">predicting</a> political dissent before it occurs.</p><p><strong>US efforts to impart values into its AI ecosystem have been less concerted.</strong> The United States has been far less deliberate than China in developing AI consonant with American values. True, documents like the Biden administration&#8217;s &#8220;<a href="https://web.archive.org/web/20230208003644/https://www.whitehouse.gov/ostp/ai-bill-of-rights/">AI Bill of Rights</a>&#8221; and companies&#8217; <a href="https://cyber.harvard.edu/publication/2020/principled-ai">interminable</a> desire to write AI-principles documents at least pay lip service to the idea of aligning emerging AI systems with democratic principles. The clearest example of this might be Anthropic&#8217;s approach to &#8220;<a href="https://www.anthropic.com/constitution">constitutional AI</a>,&#8221; which aims to evoke the US Constitution in its model operations. And on balance, American AI companies&#8217; systems pay <a href="https://www.foreignaffairs.com/china/china-flirting-ai-catastrophe">much greater attention</a> to ethics and safety concerns than their Chinese counterparts do. But while these examples reflect a different culture around the development of AI in the United States, they are often only window dressing, and pale in comparison to the concerted state focus that Beijing exerts on the normative trajectory of China&#8217;s tech sector.</p><p><strong>In practice, American AI may actually erode American values more than it supports them.</strong> Indeed, American companies have historically been <a href="https://apnews.com/article/chinese-surveillance-silicon-valley-uyghurs-tech-xinjiang-8e000601dadb6aea230f18170ed54e88">indispensable</a> in <a href="https://www.defenseone.com/ideas/2021/08/pull-us-ai-research-out-china/184359/">building</a> out China&#8217;s techno-authoritarian ecosystem. Between public discourse-corrupting <a href="https://papers.ssrn.com/sol3/papers.cfm?abstract_id=5717943">deepfakes</a>, microtargeted political <a href="https://www.weforum.org/stories/2026/03/how-cognitive-manipulation-and-ai-will-shape-disinformation-in-2026/">manipulation</a>, and algorithmic <a href="https://www.nytimes.com/interactive/2019/06/08/technology/youtube-radical.html">amplification</a> of extreme content, leading US developers are already arguably producing AI tools that weaken democracy more than they strengthen it. The governments of <a href="https://www.europarl.europa.eu/RegData/etudes/ATAG/2021/696206/EPRS_ATA(2021)696206_EN.pdf">both</a> <a href="https://www.whitehouse.gov/wp-content/uploads/2025/07/Americas-AI-Action-Plan.pdf">superpowers</a> are working to reap the efficiency benefits of AI in their state bureaucracies. But whereas China&#8217;s regime is laying out a proactive vision for how AI will advance authoritarian control, the United States has been largely reactive in accommodating AI to democracy&#8212;waiting for courts to adjudicate how new technologies can or cannot be used according to existing American law.</p><p><strong>The US needs a robust vision for democratic AI and the will to disseminate it.</strong> Breakaway-AI proponents see AI&#8217;s future as a straightforward innovation race with downstream ethical repercussions. By contrast, proponents of AI as a system of encoded values see the future as a struggle over vision and will. To further American values and strengthen democracy, this view would require developing a much clearer vision: a compelling idea of how to use AI&#8212;not just by reactively implementing guardrails but by proactively conceptualizing what democratic AI should look like and enable. Will, equally important, is the drive to commercialize and aggressively spread the resulting systems around the world in collaboration with allies, while also preventing domestic companies from working with China in ways that undermine the United States&#8217; vision.</p><p>The Trump administration, by focusing largely on will, has seen some gains in diffusing US technology. But the PRC still maintains considerable diffusion advantages&#8212;especially in the Global South, where China&#8217;s price-point advantages and shared development conditions give it an edge in building out AI infrastructure for developing nations. A values-driven AI vision, as described above, remains comparatively underdeveloped on the American side: Washington lacks an inspiring, affirmative narrative about what democratic AI enables for its citizens that authoritarian AI cannot.</p><p><strong>The US vision deficit has downstream effects on will.</strong> Without a clear, compelling sense of what American companies are building toward, it is impossible to muster the political energy needed to make hard choices. For example, US firms are currently <a href="https://www.axios.com/2025/05/29/china-biotech-boom-us-drug-trials">bolstering</a> Beijing&#8217;s AI ecosystem in sensitive domains like biotechnology, with little oversight. A stronger vision of American AI would galvanize support for restricting US companies from making such contributions to China&#8217;s AI ecosystem.</p><h2>Emergent Control Regimes</h2><p>&#8220;What Soviet-American nuclear arms control was to world stability since the 1970s, U.S.-Chinese A.I. collaboration to make sure we effectively control these rapidly advancing A.I. systems will be for the stability of tomorrow&#8217;s world.&#8221;</p><p>&#8212;<em>New York Times</em> columnist <a href="https://www.nytimes.com/2025/03/25/opinion/trump-china-ai.html">Thomas L. Friedman</a></p><p>The third paradigm for how the moral future of AI hinges on Sino-American competition is that of emergent control regimes&#8212;the shared rules and institutions that powers build over time to govern consequential technologies. For policy wonks, this is often the most overlooked&#8212;or, more accurately, the most dismissed&#8212;avenue for shaping outcomes. In part, it is not taken seriously because those who do raise it tend to do so with flagrant naivete about the weakness of the multilateral system and the political infeasibility of any good-faith agreement between the United States and China. But the idea that international control regimes might emerge over time and prove influential is not far-fetched, particularly in areas such as lethal autonomous weapons and AI-powered human gene editing.</p><p><strong>The nuclear era shows that self-interest can drive even rivals to manage powerful technologies together, if imperfectly.</strong> Early in the Cold War, the idea that the United States and the Soviet Union could reach an agreement about nuclear weapons seemed fanciful. Nonetheless, both nations came to recognize that countering proliferation was in each nation&#8217;s interest, even as they remained locked in an existential nuclear arms struggle. No one in 1945 could have predicted the specific contours of what emerged from the complex, path-dependent interactions among nuclear-armed states with evolving interests over decades: the Nuclear Non-Proliferation Treaty, the International Atomic Energy Agency (IAEA), test-ban agreements, verification mechanisms, and norms around nuclear use. While imperfect, these innovations have unquestionably shaped and constrained the most destructive technology that humanity has yet produced.</p><p><strong>Advantages will accrue to whichever power crafts and brands politically feasible international controls.</strong> To be sure, there are limits on the degree to which such controls can be planned for, given how contingent they tend to be on changing relations and events. But this is not to say that any control regimes emerging from rapidly advancing AI systems are too contingent to plan for in any way. Such controls are not to be confused with the idealistic proposals&#8212;such as Pugwash-style scientist convenings or bilateral red-teaming exchanges&#8212;that are characteristic of most current track-two dialogues. Nor are they the feel-good unilateral pronouncements of rosy intentions like the <a href="https://digitallibrary.un.org/record/3937534?ln=en&amp;v=pdf">resolution</a> on &#8220;the promotion, protection and enjoyment of human rights on the Internet,&#8221; passed six times by the UN Human Rights Council since 2012. As with nuclear controls, any diplomatic development of consequence will likely be highly controversial, and will necessarily fall far short of what most peace-loving technologists would like to see.</p><p>But imperfect measures can still be strategic. President Eisenhower&#8217;s famous &#8220;Atoms for Peace&#8221; <a href="https://voicesofdemocracy.umd.edu/eisenhower-atoms-for-peace-speech-text/">speech</a> in 1953 set the foundation for the IAEA. It also served as a tremendous public relations victory for the United States, projecting America as the responsible superpower, willing to help other countries benefit from peaceful applications of atomic technology. It forced the Soviet Union to compete with the United States in building nuclear reactors for other countries, at a high cost to the Soviets. And subsequent US-Soviet nuclear arms control negotiations did more than help to constrain the risks of nuclear war; they also <a href="https://warontherocks.com/2018/06/the-forgotten-side-of-arms-control-enhancing-u-s-competitive-advantage-offsetting-enemy-strengths/">allowed</a> the United States to pursue advantages in qualitative force capabilities at lower cost, under the auspices of quantitative weapons restrictions.</p><p><strong>Compared with China, the US is better positioned to lead emergent control regimes.</strong> Technologists have given a great deal of <a href="https://openai.com/index/governance-of-superintelligence/">thought</a> to unrealistic controls for theoretical future AI capabilities. Yet little serious thought has gone into diplomacy in those areas where international controls could be made politically feasible, soft-power enhancing, and strategically advantageous. The partial exception is the American-led <a href="https://www.state.gov/bureau-of-arms-control-deterrence-and-stability/political-declaration-on-responsible-military-use-of-artificial-intelligence-and-autonomy">Political Declaration on Responsible Military Use of Artificial Intelligence and Autonomy</a>, which has made strides toward establishing American leadership in rules around the use of lethal autonomous weapons. This guidance is both strategically beneficial to the United States and resonant with American values. Several other areas show promise for similar interventions, not least the ethically fraught genomic applications of emerging AI-powered biotech and the use of AI in high-risk industries. Here the United States has substantial untapped advantages: a global network of allies, a strong history of effective tech diplomacy, and a brand of AI development unencumbered by China&#8217;s dystopian techno-authoritarianism. But these advantages so far have not deterred China&#8217;s ambitious efforts to <a href="https://warontherocks.com/cogs-of-war/chinas-ai-governance-offensive-threatens-u-s-tech-leadership/">eke</a> out a leading position in global AI governance.</p><h2>A Rebalanced Approach</h2><p>These three paradigms of AI competition&#8212;breakaway dominance, encoded values, and emergent control regimes&#8212;are not mutually exclusive. Some areas of AI may see defensible technological breakthroughs that confer long-term advantages; some will become battlegrounds for embedded values; some will develop controls; and some will combine elements from several of these paradigms. They are also interrelated: if one power successfully embeds its values into a widely adopted technology, it will likely occupy a privileged position in control discussions, for example. The question is not which single model is most accurate, but how to allocate attention and resources across all three, and for which issues.</p><p>Yet today&#8217;s focus remains mistakenly skewed toward a winner-takes-all narrative, blinding policymakers to more consequential contests on encoded values and creative thinking on strategic diplomacy.</p><p><strong>To take one example, while initial US nuclear dominance was essential, it was ultimately short-lived.</strong> Many developers of the weapon believed America&#8217;s 1945 breakthrough would represent an enduring strategic advantage, similar to how many see the race to superintelligence as today&#8217;s single defining competition. But America&#8217;s nuclear dominance lasted just four short years. The Manhattan Project was indispensable&#8212;the United States&#8217; adversaries getting the bomb first would have been catastrophic. But those banking on sustained dominance were in for a rude awakening. Ultimately, clever nuclear diplomacy contributed more to the United States&#8217; victory over the Soviet Union than breakaway nuclear superiority, which never materialized.</p><p><strong>Encoding values in technology requires proactive efforts. </strong>To the extent that a technology as broad as AI can be compared to a recent innovation, the best analogue is probably the internet&#8212;unfortunately, another cautionary tale. Although American engineers deliberately built the internet with libertarian principles, China has been able to co-opt it through force of will. Today, the Great Firewall and the other tools that the CCP has built into the Chinese internet have transformed a freedom-enhancing technology into history&#8217;s most sophisticated instrument of surveillance, censorship, and control.</p><p>Beijing is <a href="https://www.article19.org/resources/china-the-rise-of-digital-repression-in-the-indo-pacific/">exporting</a> these tools abroad, enabling other autocracies to turn the internet away from its original open-society-enhancing design toward repressive ends. The story might have turned out differently if the United States had engaged in more proactive diplomacy&#8212;leveraging its unique influence over the development of China&#8217;s internet, instead of just issuing <a href="https://www.state.gov/declaration-for-the-future-of-the-internet">feel-good</a> digital-rights <a href="https://www.article19.org/resources/un-human-rights-council-adopts-resolution-on-human-rights-on-the-internet/">statements</a>. At a minimum, curbing American tech companies&#8217; active support of Chinese technological ambitions would have slowed Beijing&#8217;s successful authoritarian conquest of the internet. Indeed, the extent of American support for techno-authoritarian progress casts serious doubt on any assertion that the originating society of a technology will organically imbue that technology with its own values. For the war over embedded values, the internet&#8217;s lesson is clear: technology neither establishes nor preserves values passively.</p><p><strong>The US cannot rely on technological dominance to ensure that AI furthers American values.</strong> The United States must learn from these historical cases quickly. AI-powered Chinese &#8220;smart cities&#8221; are <a href="https://carnegieendowment.org/research/2019/09/the-global-expansion-of-ai-surveillance">already</a> <a href="https://www.orfonline.org/research/the-digital-silk-road-and-smart-city-networks-in-the-indo-pacific-a-primer">spreading</a> across the Global South, bringing with them surveillance architectures designed for authoritarian control. Cheap, CCP-compliant Chinese open-source frontier models are already <a href="https://www.ft.com/content/f7a5b184-1fef-4f02-b957-4c2b07adf91f?syn-25a6b1a6=1">gaining</a> uptake internationally. Party-aligned research centers are developing AI-powered <a href="https://chinamediaproject.org/2024/01/30/what-does-the-party-stand-to-gain-from-ai/">propaganda</a> and censorship <a href="https://www.aspi.org.au/report/the-partys-ai-how-chinas-new-ai-systems-are-reshaping-human-rights/">tools</a> with unprecedented sophistication; these will soon be diffused abroad, if they haven&#8217;t already. Policy and tech leaders may think that their efforts to simply accelerate American technical progress at the frontier of AI innovation will ensure that American values triumph. However, the more probable outcome could be a world awash in cheap, authoritarian AI that outcompetes slightly more sophisticated American offerings that do little to promote American values&#8212;and perhaps even erode them.</p><p><strong>To course correct, the US must establish a President&#8217;s council or congressional commission on democratic AI.</strong> A misguided fixation on a winner-takes-all race for technical superiority, as a proxy for a competition of values, risks missing where the real competition lies. It also misses opportunities to rout China diplomatically, similar to America&#8217;s successes in nuclear diplomacy. A better approach to AI must start with developing a clearer moral vision for American AI. The President&#8217;s Council on Bioethics, established under former President George W. Bush, offers an effective <a href="https://www.thenewatlantis.com/publications/a-presidents-council-on-artificial-intelligence">model</a> of what this could look like: a substantive body bringing diverse perspectives to the highest levels of government to grapple with emerging ethical challenges, producing influential reports that shaped discourse and policy. A comparable council on AI and democratic governance could build the intellectual foundations for techno-democracy that do not yet exist, as the American Enterprise Institute&#8217;s Council on AI Ethics is beginning to <a href="https://www.aei.org/events/moral-questions-in-the-age-of-ai-the-need-for-a-council-on-ai-ethics/">show</a>.</p><p>Armed with a clearer, more compelling moral vision for AI, American technologists and policymakers could be galvanized toward supporting the United States&#8217; competition with China with sharper focus. Such a vision would also provide a basis to more aggressively curb American companies&#8217; substantial aiding and abetting of China&#8217;s techno-authoritarian ecosystem. And it could provide a stronger foundation for closer collaboration with indispensable like-minded partners such as India: nations better <a href="https://nationalinterest.org/blog/silk-road-rivalries/how-ai-can-repair-us-india-relations">equipped</a> to compete with China on rolling out price-competitive and context-relevant AI offerings in the Global South.</p><p>There is little doubt that the Sino-American battle over AI will have tremendous consequences for the future of humanity. Approaching that contest with greater moral clarity is not just the right thing to do; it is also a strategic imperative.</p><p>&#8205;</p><div><hr></div><p><em><strong>See things differently? </strong>AI Frontiers welcomes expert insights, thoughtful critiques, and fresh perspectives. <a href="https://ai-frontiers.org/publish?utm_source=aif_article">Send us your pitch.</a></em></p><div><hr></div><p><em>Bill Drexel is a senior fellow at Hudson Institute. His work focuses on United States&#8211;India relations, artificial intelligence competition with China, and technology in American grand strategy. Previously, Mr. Drexel worked on technology and national security at the Center for a New American Security, humanitarian innovation at the United Nations, and on Indo-Pacific affairs at the American Enterprise Institute. Drexel&#8217;s field experience includes serving as a rescue boat driver during Libya&#8217;s migration crisis, conducting investigative research in the surveillance state of Xinjiang, China, and supporting humanitarian data efforts across wartime Ukraine.</em></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://newsletter.ai-frontiers.org/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Subscribe to AI Frontiers.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[An AI Capabilities Gap Can Endanger Nuclear Deterrence]]></title><description><![CDATA[For decades, no nuclear power could disarm its rivals without provoking devastating retaliation. A large AI lead could change that.]]></description><link>https://newsletter.ai-frontiers.org/p/an-ai-capabilities-gap-can-endanger</link><guid isPermaLink="false">https://newsletter.ai-frontiers.org/p/an-ai-capabilities-gap-can-endanger</guid><dc:creator><![CDATA[AI Frontiers]]></dc:creator><pubDate>Thu, 25 Jun 2026 23:01:31 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!bTOj!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F40b37b62-effe-455c-8990-2f11af33322d_4029x2685.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong><a href="https://ai-frontiers.org/author/govind-pimpale">Govind Pimpale</a></strong> &#8212; June 25, 2026</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!bTOj!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F40b37b62-effe-455c-8990-2f11af33322d_4029x2685.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!bTOj!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F40b37b62-effe-455c-8990-2f11af33322d_4029x2685.jpeg 424w, https://substackcdn.com/image/fetch/$s_!bTOj!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F40b37b62-effe-455c-8990-2f11af33322d_4029x2685.jpeg 848w, https://substackcdn.com/image/fetch/$s_!bTOj!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F40b37b62-effe-455c-8990-2f11af33322d_4029x2685.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!bTOj!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F40b37b62-effe-455c-8990-2f11af33322d_4029x2685.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!bTOj!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F40b37b62-effe-455c-8990-2f11af33322d_4029x2685.jpeg" width="1456" height="970" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/40b37b62-effe-455c-8990-2f11af33322d_4029x2685.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:970,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!bTOj!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F40b37b62-effe-455c-8990-2f11af33322d_4029x2685.jpeg 424w, https://substackcdn.com/image/fetch/$s_!bTOj!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F40b37b62-effe-455c-8990-2f11af33322d_4029x2685.jpeg 848w, https://substackcdn.com/image/fetch/$s_!bTOj!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F40b37b62-effe-455c-8990-2f11af33322d_4029x2685.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!bTOj!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F40b37b62-effe-455c-8990-2f11af33322d_4029x2685.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Since the late 1950s, <strong>Mutual Assured Destruction (MAD)</strong> has served as a limiting factor on great-power conflict. The doctrine holds that, if two opposing nations have nuclear weapons that can survive one another&#8217;s initial strike, then the near-certainty of devastating retaliation will deter each side from launching a large-scale nuclear attack. Despite this logic, military planners have long considered the possibility of a <strong>counterforce</strong> nuclear attack, where a superpower uses nuclear weapons to cripple the nuclear capabilities of its enemy. If such an attack were executed preemptively, as a so-called &#8220;first strike,&#8221; it could both start and end a great-power conflict in a matter of hours: without retaliatory capacity, the defender would be at the mercy of the aggressor&#8217;s remaining nuclear weapons and forced to surrender.</p><p>The reason this does not happen is that a truly successful counterforce strike is nearly impossible to pull off: a would-be attacker doesn&#8217;t know the locations of all opposing missile launchers and submarines, nor does it have missiles with sufficient precision and speed to destroy opposing missile silos before they could launch retaliatory nuclear warheads. Thus, if provoked by a first strike, the opposing side would likely be able to launch a large-scale nuclear response, and the attacker, unable to counter all enemy missiles, could face devastating losses. The result of a preemptive counterforce strike, in other words, would be mutual assured destruction.</p><p>AI could change this dynamic. By the mid-2030s, AI-assisted research and development could reduce the cost required to develop and manufacture military hardware by an order of magnitude. Such lower costs could enable a nation with an AI lead to quickly and cheaply build military infrastructure projects, making nuclear counterforce strikes a realistic possibility. Nations with weaker AI capabilities would struggle to quickly build the countermeasures needed to retain a credible nuclear deterrent.</p><p>This article will primarily be a technical assessment of how AI could undermine nuclear deterrence, although I&#8217;ll lightly touch on a few political aspects. For a longer and more in-depth assessment of the factors discussed here, consider taking a look at <a href="https://pimpale.substack.com/p/can-ai-enable-nuclear-counterforce">an earlier piece I wrote</a>.</p><h2>Why MAD Has Worked So Far</h2><p>In any preemptive counterforce strike scenario, the attacker is at a large disadvantage compared with the defender, because they must destroy <strong>all</strong> of the defender&#8217;s nuclear weapons. To execute a counterforce strike, the attacker must achieve all the following requirements simultaneously:</p><p><strong>Suppress launch on warning.</strong> Many nuclear-armed nations have a policy of <strong>launch on warning</strong>&#8212;launching a retaliatory strike based on sensor data, before a nuclear weapon has been confirmed to land on their territory. The attacker must either use fast-arriving weapons or otherwise disable launch on warning.</p><p><strong>Locate and destroy nuclear submarines.</strong> <a href="https://www.csp.navy.mil/SUBPAC-Commands/Submarines/Ballistic-Missile-Submarines/">Nuclear submarines</a>, while extremely stealthy, are vulnerable once detected. Each nuclear submarine can carry and launch hundreds of warheads. The attacker must accurately track their locations in real time and destroy them all within minutes.</p><p><strong>Locate and destroy mobile launchers.</strong> China and Russia (although notably not the US, the UK, or France) each field a set of <a href="https://fas.org/publication/china-military-parade/">mobile missile launchers</a> that can be dispersed during times of high alert. These mobile launchers are extremely difficult to locate for long enough to successfully strike. However, if accurate and up-to-date position data can be provided, they are easy to destroy.</p><p><strong>Destroy all silos.</strong> Hardened silos have known positions, but they require almost a direct hit&#8212;ideally with a nuclear weapon&#8212;to ensure their destruction. They stand out among nuclear launch platforms, as they have the fastest reaction time and the hardest-to-disrupt communications.</p><p><strong>Defend against surviving missiles.</strong> If the attacking nation has a functioning missile defense system, it may not need to destroy all of an enemy&#8217;s nuclear weapons, as its missile defense can handle some leftovers. The stronger a nation&#8217;s missile defense, the less thorough its first strike has to be.</p><p><strong>Overcome the nuclear taboo.</strong> One theory for why nuclear weapons are rarely used is the <a href="https://en.wikipedia.org/wiki/Nuclear_taboo">nuclear taboo</a>. The leaders of both the US and the USSR recognized the gravity of nuclear weapons usage, and had serious <a href="https://en.wikipedia.org/wiki/Project_Solarium#Findings">humanitarian</a> <a href="https://documents2.theblackvault.com/documents/dod/14-F-1329.pdf">reservations</a> about starting a nuclear conflict. Even if a counterforce strike were perfect, radioactive nuclear fallout was expected to kill <a href="https://www.jstor.org/stable/2538949">tens of millions</a> in the target country.</p><p>The six requirements above have thus far preserved deterrence not because they are physically impossible to meet but because meeting them at the scale required has always been prohibitively expensive.</p><p>A useful paradigm to consider in nuclear conflict is the <strong>cost-exchange ratio</strong>. When one side fields an additional weapon, how much must the other side spend to neutralize it? The concept comes from the Cold War debate over ballistic missile defense. If an attacking nation can build another nuclear missile for $1 million, and the interceptor needed to stop it costs the defending nation $10 million, then missile defense is a losing game: each $1 spent on offense forces a $10 expenditure on defense. This particular cost-exchange ratio explains why a nation launching a counterforce strike would struggle to defend against surviving missiles.</p><h2>Why AI Could Dramatically Cut Military Infrastructure Costs</h2><p>AI-assisted military R&amp;D could invert the cost-exchange ratio. If a nation with an AI lead can automate most of the design, systems integration, and production labor that currently makes military infrastructure expensive, that nation&#8217;s costs could be significantly reduced while its enemies&#8217; costs stayed the same (since they don&#8217;t have the AI advantage). If interceptors cost only $100,000 and missiles still cost $1 million, then it suddenly becomes rational to build more interceptors.</p><p>The likelihood of this prediction&#8217;s coming true rests on answers to two questions: (1) whether AI can automate most of the intellectual labor, and (2) whether doing so really cuts costs by a margin significant enough to change militaries&#8217; economic calculus. Notably, this forecast does not require progress in robotics, which could further reduce costs. I&#8217;ll focus on aerospace manufacturing, which comprises most of what the attacker needs to build: new missiles, surveillance constellations, and missile defense systems.</p><p><strong>Can AI automate most intellectual labor?</strong> Aerospace projects of the type I&#8217;m describing here are highly interdisciplinary, and even simple systems demand expertise in electrical, computer, and mechanical engineering. More-advanced projects may require fundamental research in applied physics or math. While AI assistance for software development is a relatively mature use case, AI abilities in the other fields are much more nascent.</p><p>Yet there is good reason to believe that most intellectual fields will follow the same trends. AI abilities have increased at roughly the same rate across various domains, as shown in the chart below.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!pYVs!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2eeb984e-cb15-482a-9656-b338b4b330ed_1564x934.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!pYVs!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2eeb984e-cb15-482a-9656-b338b4b330ed_1564x934.png 424w, https://substackcdn.com/image/fetch/$s_!pYVs!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2eeb984e-cb15-482a-9656-b338b4b330ed_1564x934.png 848w, https://substackcdn.com/image/fetch/$s_!pYVs!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2eeb984e-cb15-482a-9656-b338b4b330ed_1564x934.png 1272w, https://substackcdn.com/image/fetch/$s_!pYVs!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2eeb984e-cb15-482a-9656-b338b4b330ed_1564x934.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!pYVs!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2eeb984e-cb15-482a-9656-b338b4b330ed_1564x934.png" width="1456" height="870" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2eeb984e-cb15-482a-9656-b338b4b330ed_1564x934.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:870,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!pYVs!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2eeb984e-cb15-482a-9656-b338b4b330ed_1564x934.png 424w, https://substackcdn.com/image/fetch/$s_!pYVs!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2eeb984e-cb15-482a-9656-b338b4b330ed_1564x934.png 848w, https://substackcdn.com/image/fetch/$s_!pYVs!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2eeb984e-cb15-482a-9656-b338b4b330ed_1564x934.png 1272w, https://substackcdn.com/image/fetch/$s_!pYVs!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2eeb984e-cb15-482a-9656-b338b4b330ed_1564x934.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Source: &#8220;<a href="https://metr.org/blog/2025-07-14-how-does-time-horizon-vary-across-domains/">How Does Time Horizon Vary Across Domains?</a>,&#8221; by Thomas Kwa and Vincent Cheng, METR (2025).</figcaption></figure></div><p>Additionally, we&#8217;re already beginning to see AI labs show interest in automating science and engineering fields: Anthropic is training on <a href="https://claude.com/blog/making-claude-a-better-electrical-engineer">electrical engineering</a>, and the company showcased 3D modeling performance in its <a href="https://www.anthropic.com/news/claude-fable-5-mythos-5">Claude Fable 5 launch post</a>. OpenAI has made discoveries in <a href="https://openai.com/index/gpt-5-mathematical-discovery/">mathematics</a> and <a href="https://openai.com/index/new-result-theoretical-physics/">physics</a>. On the biology front, Google DeepMind&#8217;s AlphaFold has solved protein folding, enabling advances in drug discovery.</p><p>Extrapolating from such innovations, one engineer could do the work of many: outsourcing most of it to agents and handling only what agents can&#8217;t yet do, like running experiments or meeting stakeholders in person.</p><p><strong>How much can automated intellectual labor lower military R&amp;D costs?</strong> Although aerospace manufacturing seems like a labor-heavy job, it&#8217;s a remarkably white-collar profession, with high exposure to AI automation. In a 2021 <a href="https://sms.onlinelibrary.wiley.com/doi/full/10.1002/smj.3286">article</a>, Princeton University computer scientist Edward Felten and co-authors calculated that aerospace manufacturing has an AI Industry Exposure Score of 0.519, in the 70th percentile of all industries (around the same level as real estate). If AI automates the intellectual labor of aerospace manufacturing, this would substantially lower the cost of the final product.</p><p>To make things more concrete, consider SEC filings showing the financials of two public launch services companies, <a href="https://en.wikipedia.org/wiki/Rocket_Lab">Rocket Lab</a> and <a href="https://en.wikipedia.org/wiki/Firefly_Aerospace">Firefly Aerospace</a>.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!C-Nn!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c20260e-3108-4c8a-bffa-4dff0086c412_2430x750.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!C-Nn!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c20260e-3108-4c8a-bffa-4dff0086c412_2430x750.png 424w, https://substackcdn.com/image/fetch/$s_!C-Nn!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c20260e-3108-4c8a-bffa-4dff0086c412_2430x750.png 848w, https://substackcdn.com/image/fetch/$s_!C-Nn!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c20260e-3108-4c8a-bffa-4dff0086c412_2430x750.png 1272w, https://substackcdn.com/image/fetch/$s_!C-Nn!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c20260e-3108-4c8a-bffa-4dff0086c412_2430x750.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!C-Nn!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c20260e-3108-4c8a-bffa-4dff0086c412_2430x750.png" width="1456" height="449" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6c20260e-3108-4c8a-bffa-4dff0086c412_2430x750.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:449,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;__wf_reserved_inherit&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="__wf_reserved_inherit" title="__wf_reserved_inherit" srcset="https://substackcdn.com/image/fetch/$s_!C-Nn!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c20260e-3108-4c8a-bffa-4dff0086c412_2430x750.png 424w, https://substackcdn.com/image/fetch/$s_!C-Nn!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c20260e-3108-4c8a-bffa-4dff0086c412_2430x750.png 848w, https://substackcdn.com/image/fetch/$s_!C-Nn!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c20260e-3108-4c8a-bffa-4dff0086c412_2430x750.png 1272w, https://substackcdn.com/image/fetch/$s_!C-Nn!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c20260e-3108-4c8a-bffa-4dff0086c412_2430x750.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">SEC filing data from Rocket Lab and Firefly Aerospace.</figcaption></figure></div><p>R&amp;D (which accounts for 28%&#8211;48% of spend at the two companies) is mostly engineering compensation and analysis, with the remainder going to propellant, test facilities, and hardware. It&#8217;s mostly cognitive labor, and therefore a potential target of future AI automation. SG&amp;A expenses (21%&#8211;22% of spend) describe the cost of finance, legal, contracts, compliance, and business development. These disciplines rely almost completely on cognitive labor. Cost of revenues (31%&#8211;51%) is the most mixed category: it blends physical labor (technicians doing welding, assembly, and launch operations) with white-collar labor (manufacturing, quality, and test engineering), and purchased materials and components.</p><p>The costs of aerospace components are themselves quite compressible. For example, star trackers (devices used by satellites to measure their own orientation) can <a href="https://www.cubesatshop.com/product/sodern-auriga-sa/">cost over $100,000</a>. These devices&#8217; physical components&#8212;a camera sensor, a housing, and some processing hardware&#8212; may cost as little as a few thousand dollars altogether. The more significant cost comes from qualification testing and R&amp;D (because of low manufacturing volume, such costs can&#8217;t effectively be amortized). So, by reducing the cost of R&amp;D, automating intellectual labor can drive down component costs.</p><p>I expect the cost savings to be even greater for defense aerospace products, which usually cost more than comparable commercial products. This higher cost partly reflects the increased documentation and security practices required for highly regulated uses. Such regulatory compliance practices rest almost entirely on cognitive labor that can be automated. Another driver of these product&#8217;s higher costs is costlier labor: defense contractors must have security clearances, limiting the worker pool and raising wages. An AI, on the other hand, must be cleared only once; it can then be scaled indefinitely.</p><h2>What Could We Build?</h2><p>Recall the six requirements that have kept a counterforce strike out of reach. Each one has held not because it was physically impossible, but because meeting it at scale was prohibitively expensive. Once cheap intellectual labor collapses those costs, an attacker with an AI lead could pursue several military megaprojects at once, each one solving a different requirement needed to launch a successful counterforce strike. This section will focus on the three requirements I expect to become significantly easier to meet.</p><p><strong>Locating and destroying nuclear submarines.</strong> Research <a href="https://www.sciencedirect.com/science/article/pii/S2468013325000701">has shown</a> that, in certain conditions, moving submarines leave a surface wake detectable by Synthetic Aperture Radar (SAR), a space-based radar system. A large constellation of SAR satellites would permit near-continuous surveillance of the entire world, regardless of time of day or local weather conditions. The US is already pursuing a SAR satellite constellation, and will launch its first satellite <a href="https://defensescoop.com/2025/08/05/space-force-ic-gmti-ground-moving-target-indication-launch/">in 2028</a>. The US could supplement this effort with a space-based constellation of Light Detection and Ranging (LiDAR) satellites. Each satellite would measure depth via pulses of intense light, detecting even stationary submarines (although that would require clear weather). Certain frequencies of LiDAR can detect submarines <a href="https://ontheradar.csis.org/issue-briefs/non-acoustic-submarine-detection/#fn:4">within 200 meters of the surface</a>, within typical nuclear submarine operating depths. A dense constellation of LiDAR and SAR satellites could sweep the oceans, and expose submarines at scale.</p><p>However, while both satellite methods can reveal submarine positions temporarily, the only tool to keep track of them consistently would be underwater drones (often called Unmanned Underwater Vehicles, or UUVs). UUVs are currently limited by the difficulty of autonomous operation, but AI R&amp;D would likely significantly improve this. The US has been <a href="https://www.darpa.mil/research/programs/manta-ray">funding</a> research in this direction.</p><p><strong>Defending against surviving missiles.</strong> A system with tens of thousands of interceptors prelaunched in space (similar to the 1980s <a href="https://en.wikipedia.org/wiki/Brilliant_Pebbles">Brilliant Pebbles</a> concept, originally abandoned due to cost issues) could counter any missiles that are missed by the first strike. The US is already pursuing this, too, with its <a href="https://en.wikipedia.org/wiki/Golden_Dome_(missile_defense_system)">Golden Dome</a> system.</p><p><strong>Overcoming the nuclear taboo.</strong> The missiles of the Cold War had poor precision, so warheads with an explosive yield of hundreds of kilotons were common (designed to guarantee a silo kill). But, as mentioned, such heavy warheads would result in enough fallout to guarantee millions of deaths. In 2017, Keir A. Leiber of Georgetown and Darryl G. Press of Dartmouth <a href="https://www.belfercenter.org/sites/default/files/pantheon_files/files/publication/isec_a_00273_LieberPress.pdf">found</a> that modern missiles have much higher precision than those from the Cold War, and future improvements could reduce the average targeting error to mere meters. With such high precision, very low-yield weapons could be used, with little to no fallout. A counterforce strike could be accomplished with an estimated death toll of around tens of thousands rather than millions, well within the range of wars nations are willing to start.</p><p>Other aspects of the retaliator&#8217;s deterrent are vulnerable to AI R&amp;D too. The retaliators&#8217; mobile missile launchers can be located with the exact same SAR constellation that we discussed for submarine detection, leaving them vulnerable to a first strike. Launch on warning systems are also vulnerable. While it&#8217;s unlikely they could be hacked outright, Anthropic&#8217;s <a href="https://www.anthropic.com/claude/mythos">Mythos</a> demonstrated AI driven vulnerability discovery that could be used to confuse, delay, or reduce confidence. Additionally, the defender&#8217;s early warning response time can be shortened significantly with <a href="https://scienceandglobalsecurity.org/archive/1992/06/depressed_trajectory_slbms_a_t.html">depressed trajectory</a> submarine-launched missiles, which could cover 2000 km in only 10 minutes. The combination of high-speed and precise missiles also works to efficiently counter fixed silos.</p><h2>The Defender&#8217;s Options</h2><p>If a lagging nation realizes that a rival is on course to achieve <strong>nuclear primacy</strong>&#8212;the ability to execute a counterforce strike without retaliation&#8212;it still has a few options.</p><p>The first, and most straightforward option is to expand the arsenal. It can increase the number of silos, build more nuclear submarines and mobile missile launchers, and raise its level of alert. This strategy would work in the short term, since the attacker would be forced to scale up its own forces until it was certain it could neutralize all of the new forces. The problem is the cost-exchange ratio. If the attacker has an AI advantage, the retaliator could end up paying a larger price for each new silo than the attacker pays to build the missiles or interceptors that could defeat it.</p><p>The second option is to target the root cause: the AI gap between the attacker and retaliator. Potential avenues in this direction can range from relatively diplomatic to highly escalatory. Options include disrupting the attacker&#8217;s supply chain, launching data poisoning attacks, or sabotaging its AI training runs. However, the most extreme actions&#8212;direct kinetic attacks on datacenters or researchers&#8212;would be likely to start wars. But even these interventions will only be effective if applied early. Once the lead is large enough, sufficiently smart AIs will already be trained. Thus, an AI-lagging defender must be alert enough to act before the AI capability gap becomes overwhelming.</p><p>Finally, the attacker and retaliator could negotiate a treaty. A bilateral arms-control regime could in principle cap satellite constellations, ballistic missile interceptors, or AI compute used for military R&amp;D. There is precedent here, especially in the nuclear domain. However, the main challenge will be aligning incentives. The leading nation has no incentive to join a treaty where only the lagging party stands to gain. Traditional arms-control treaties have only worked where there were symmetric costs on both sides.</p><h2>AI May Disrupt Nuclear Deterrence</h2><p>In conclusion, the historical robustness of nuclear deterrence has rested on a cost-exchange ratio that favors the retaliator, but AI-assisted R&amp;D can invert the ratio. This might enable a single superpower leading in AI to achieve nuclear primacy. The AI superpower would then wield enormous leverage, as it could credibly threaten to win just about any war. Such negotiating leverage could reshape the global balance of power, even if nuclear weapons are never used.</p><p>Even before military infrastructure megaprojects are complete, they will affect policy. If major powers come to believe that AI R&amp;D may make their nuclear deterrents less effective, they will have incentives to expand arsenals, shorten decision timelines, rely more heavily on launch on warning, contest one another&#8217;s space architectures, and target the AI and semiconductor bases that underpin their adversaries. This new equilibrium would increase military spending, shorten decision times, and raise the risk of war.</p><p>&#8205;</p><div><hr></div><p><em><strong>See things differently? </strong>AI Frontiers welcomes expert insights, thoughtful critiques, and fresh perspectives. <a href="https://ai-frontiers.org/publish?utm_source=aif_article">Send us your pitch.</a></em></p><div><hr></div><p><em>Govind &#8220;Vinny&#8221; Pimpale is a research fellow at the Foundation for American Innovation, where he focuses on AI policy. Before joining FAI, he worked at a startup developing reinforcement learning environments, and prior to that, as an AI evaluations researcher. He holds a BS in Computer Science and Engineering from UCLA.</em></p>]]></content:encoded></item><item><title><![CDATA[What Export Controls on Anthropic’s Most Advanced Models Mean for Europe]]></title><description><![CDATA[US restrictions on frontier AI would have come eventually, but few expected sudden export controls. They could be Europe's wake-up call on AI sovereignty.]]></description><link>https://newsletter.ai-frontiers.org/p/what-export-controls-on-anthropics</link><guid isPermaLink="false">https://newsletter.ai-frontiers.org/p/what-export-controls-on-anthropics</guid><dc:creator><![CDATA[AI Frontiers]]></dc:creator><pubDate>Fri, 19 Jun 2026 13:03:06 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!A8r_!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47075ddb-2b9b-46e1-99c8-c5ff8391cccc_4608x2592.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong><a href="https://ai-frontiers.org/author/afek-shamir">Afek Shamir</a></strong> &#8212; June 19, 2026</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!A8r_!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47075ddb-2b9b-46e1-99c8-c5ff8391cccc_4608x2592.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!A8r_!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47075ddb-2b9b-46e1-99c8-c5ff8391cccc_4608x2592.jpeg 424w, https://substackcdn.com/image/fetch/$s_!A8r_!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47075ddb-2b9b-46e1-99c8-c5ff8391cccc_4608x2592.jpeg 848w, https://substackcdn.com/image/fetch/$s_!A8r_!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47075ddb-2b9b-46e1-99c8-c5ff8391cccc_4608x2592.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!A8r_!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47075ddb-2b9b-46e1-99c8-c5ff8391cccc_4608x2592.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!A8r_!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47075ddb-2b9b-46e1-99c8-c5ff8391cccc_4608x2592.jpeg" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/47075ddb-2b9b-46e1-99c8-c5ff8391cccc_4608x2592.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!A8r_!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47075ddb-2b9b-46e1-99c8-c5ff8391cccc_4608x2592.jpeg 424w, https://substackcdn.com/image/fetch/$s_!A8r_!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47075ddb-2b9b-46e1-99c8-c5ff8391cccc_4608x2592.jpeg 848w, https://substackcdn.com/image/fetch/$s_!A8r_!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47075ddb-2b9b-46e1-99c8-c5ff8391cccc_4608x2592.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!A8r_!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47075ddb-2b9b-46e1-99c8-c5ff8391cccc_4608x2592.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>On June 12, the Trump administration issued an order requiring <a href="https://www.ft.com/content/f6940d59-28f4-4ae4-a569-c6fc421e52b9?syn-25a6b1a6=1">Anthropic to suspend access</a> to its two most advanced AI models&#8212;Fable 5 and Mythos 5&#8212;for non-American nationals, just days after their public release. The decision caused immediate backlash across Europe. <a href="https://www.euronews.com/2026/06/13/wake-up-call-europe-reacts-to-anthropic-halting-access-to-its-fable-5-and-mythos-5-ai-mode">Politicians</a> from France&#8217;s Gabriel Attal and Jordan Bardella to the Netherlands&#8217; Geert Wilders, alongside <a href="https://www.politico.eu/article/us-anthropic-order-exposes-eu-ai-dependency/">European industry and civil society</a>, amplified calls for AI sovereignty. Attal, the presidential candidate for Macron&#8217;s Renaissance party, even <a href="https://x.com/GabrielAttal/status/2065743971901423928">likened the shutdown</a> of Anthropic&#8217;s models to Iran&#8217;s blockade of the Strait of Hormuz.</p><p>While such reactions are understandable, they underscore what we already know: Europe is behind on AI, overly dependent on the US, and vulnerable to unilateral decisions. Perhaps the renewed sovereignty rhetoric can help build the political capital needed to fix the continent&#8217;s AI positioning, but what Europe needs more urgently is a clear-eyed account of what to actually do. In the wake of the Anthropic episode, this piece separates what has genuinely changed from what is being overstated, while identifying where European policymakers should focus their attention.</p><h2>Europe Should Have Planned for This</h2><p>In recent years, AI has become increasingly relevant to national security. Europe could have anticipated that the US government would restrict access to US AI models at some point, but has not acted quickly enough to secure its position.</p><p><strong>Export controls on US technology have affected Europe before.</strong> The use of export controls on American technology for national security reasons is nothing new and is not unique to the current US government. <a href="https://www.rand.org/pubs/perspectives/PEA3776-1.html">The Biden administration&#8217;s AI Diffusion Rule</a> did the same for advanced chips, treating AI hardware as a national security instrument and using export controls to manage its global distribution. Europe was affected then, too, with Tier 1 countries in western Europe split from Tier 2 countries across much of eastern Europe. What the new controls do, less selectively than the Diffusion Rule, is extend export controls from AI hardware to AI models themselves.</p><p><strong>The US implemented the new control suddenly and with opaque reasoning.</strong> While export controls are not unprecedented, the Trump administration&#8217;s recent directive differed from Biden&#8217;s Diffusion Rule. This decision happened more quickly, and was driven by harder-to-interpret motives, particularly in light of the <a href="https://www.bbc.co.uk/news/articles/cvg4p02lvd0o">recent clash between Anthropic</a> and the Pentagon. It is plausible that the US government wanted to <a href="https://www.transformernews.ai/p/anthropic-fable-shutdown-ban-trump-white-house">block Fable&#8217;s deployment for everyone</a> (Americans included) and used export controls as a tool to do so.</p><p><strong>Europe has been moving too slowly to build sovereign AI or secure access to frontier American AI.</strong> Europe could have planned more effectively for this moment by treating AI as a sovereign imperative and developing the resources and infrastructure needed to better serve this goal. Instead, the scaling down of EU plans for <a href="https://www.euractiv.com/news/eu-scales-back-plans-for-ai-gigafactories/">AI gigafactories</a> and the successive <a href="https://www.euractiv.com/news/eus-tech-sovereignty-package-delayed-for-third-time/">delays to its Cloud and AI Development Act</a> point to the complexity of moving at the pace of developments across the Atlantic. A separate but related issue is the need to access American frontier AI models for, among other things, hardening European infrastructure against cyberattacks. European leaders could have sought to <a href="https://www.politico.eu/article/anthropic-expands-access-to-cyber-capable-mythos-model-beyond-us/">negotiate guaranteed early access to highly capable systems</a>. Yet the EU has lagged here as well, obtaining <a href="https://www.cnbc.com/2026/06/01/anthropic-eu-ai-mythos-access-advanced-model.html">access</a> to Anthropic&#8217;s Mythos model about two months after the company first started sharing it with a small group of American organizations to bolster cybersecurity.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://newsletter.ai-frontiers.org/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://newsletter.ai-frontiers.org/subscribe?"><span>Subscribe now</span></a></p><h2>The Restrictions&#8217; Short-Term Impact on Europe May Be Limited</h2><p>Europe is not, for now, significantly worse off without access to Fable 5 and Mythos 5. This is for two reasons.</p><p><strong>Access to Fable 5 and Mythos 5 will probably be restored.</strong> The US government and Anthropic will likely come to some sort of agreement to enable the continued rollout of these models. For one thing, the export restriction also applies to <a href="https://x.com/YusufSMahmood/status/2065604312781168841">foreign nationals working inside American labs</a>&#8212;employees crucial to model development. Maintaining the controls would be akin to telling Anthropic to stop developing future AI models.</p><p><strong>Other models are good enough for most current applications of AI.</strong> Other than some cyberdefense uses, most tasks across the European economy do not currently require the most capable Anthropic models. Alternative models can perform many of the tasks that users would have assigned to Fable, at a similar level of competence. <a href="https://fortune.com/2026/06/13/anthropic-disables-fable-mythos-export-controls-national-security-threat/">OpenAI&#8217;s GPT 5.5</a>, whose capabilities are comparable to those of Fable, remains free of export controls. Open-source alternatives, <a href="https://epoch.ai/data-insights/open-weights-vs-closed-weights-models">only months behind</a>, also remain available to European markets. Choosing an AI model is ultimately a practical calculation: the right capability, at the right price for the task at hand. That is why AI adopters <a href="https://x.com/nxthompson/status/2063712713654628549">often prefer</a> cheaper Chinese models over frontier American ones: they choose based on the job they need to complete, rather than simply selecting the models that sit on top of a capability leaderboard.</p><p>Hence, the economic drag Europe will face by losing access to Fable is likely to be modest in the short run. It will compound only if the restriction on European access to American frontier models continues and the capability gap between American models and alternatives significantly widens, neither of which seem likely in the near term.</p><p><strong>In the long term, Europe needs frontier AI for cybersecurity and economic competitiveness.</strong> Even if the model restrictions&#8217; negative impact can be absorbed for now, the European market will suffer if it cannot access leading models like Mythos and Fable. Aura Salla, a Member of the European Parliament, has argued that &#8220;<a href="https://www.linkedin.com/posts/aurasalla_mythos-anthropic-cybersecurity-activity-7471523224514908160-nh0f">Europe is better off without these models</a>,&#8221; because they pose significant cybersecurity risks, with insufficient safeguards. But access to frontier models is an absolute prerequisite for defensive security, allowing domestic companies and governments to identify and patch vulnerabilities before attackers find and exploit them. In the long term, frontier access is also an economic necessity to prevent Europe&#8217;s industrial base from being relegated to secondary tiers of productivity. Being locked out of the most capable AI models is categorically different from Europe choosing how to adopt AI on its own terms.</p><h2>In the Long Term, These Restrictions May Provide Opportunities for Europe</h2><p>Counterintuitively, the US government&#8217;s recent move may turn out to be good for Europe. While a gradual loss of access to American frontier AI might have been anticipated, that eventuality may never have felt urgent enough to prompt serious action. This sudden, unexpected loss of access will be a sobering warning.</p><p><strong>The US government&#8217;s directive underlined its power to withdraw access.</strong> Export-controlling Anthropic&#8217;s leading models revealed who holds the kill switch&#8212;and how easy it is to press. Even if the controls are overturned, the intent and execution is visible to every government in the world. The use of export controls to restrict global access to AI models signals the distinct power of the American executive branch in shaping the trajectory of AI.</p><p><strong>The more dependent Europe is on American AI, the more damaging restrictions could be.</strong> Fortunately, for now, Europe enjoys a narrow window of insulation: unlike <a href="https://www.europarl.europa.eu/RegData/etudes/ATAG/2025/780413/ECTI_ATA(2025)780413_EN.pdf">cloud services</a>, leading American AI models have not yet been deeply woven into European public administration or critical infrastructure. Access to American AI, like access to the <a href="https://www.congress.gov/crs-product/IF12735">nuclear umbrella</a>, may come at a cost to those that accept and depend on it.</p><p><strong>The episode is an opportunity to drive political momentum toward middle power coordination on AI.</strong> Even if the US directive brings only limited short-term consequences, it illustrates how vulnerable Europe could be in the future if it does not start working to secure frontier AI access now. Countries within the EU, including France, Germany, and the Netherlands, could do more to engage other middle powers like the UK, India, South Korea, Japan, and Canada. They can coordinate on how they wish to govern this technology, secure access to the frontier, and shape how AI affects society. Even if these countries play different roles in the AI stack (and even though existing coordination channels between these countries are currently scant), they share a common interest in preventing any one government from dictating access and governance unilaterally.</p><p>As part of a coordinated agenda on AI governance, middle powers could align on their <a href="https://arxiv.org/abs/2601.11699">evaluations regimes</a> and <a href="https://thefuturesociety.org/cross-border-ai-incident-infrastructure/">incident monitoring</a> practices, while slowly building up shared leverage through collective procurement standards and investment in each other&#8217;s ecosystems. A recent example is <a href="https://cohere.com/blog/cohere-alephalpha-join-forces">Aleph Alpha and Cohere&#8217;s merger</a>. More ambitious moves could draw on the model of the <a href="https://www.eurofighter.com/the-programme">Eurofighter Typhoon</a> program: pooling procurement across multiple governments to build collective infrastructure or capabilities that no single country could generate alone.</p><p><strong>Europe must also navigate public-private partnerships between Washington and American frontier labs. </strong>The Mythos episode marks a turning point in government-industry relationships on AI. Despite having been <a href="https://www.anthropic.com/glasswing">working with government officials</a> and American industry to secure the world&#8217;s most critical software, Anthropic had to take its leading models offline immediately at Washington&#8217;s request. The age of governments ignoring capable model releases is likely over. The question is whether oversight will be principled and based on scientific thresholds being crossed, or reactive and politically driven. For now, absent federal laws on AI, the latter seems more likely.</p><p>The right response everywhere is to invest in building a more mature evaluation ecosystem, enforce <em>actual </em>regulations (like the EU AI Act), and establish regular and transparent predeployment engagement between governments and AI developers&#8212;so that policymakers are not scrambling to assess model capabilities in the days after a release. Beyond nurturing positive oversight mechanisms, European governments would also do well to consider how to respond to a reality where consequential AI decisions are made in closed-door conversations between the US government and US AI companies.</p><h2>How Does Europe Build Leverage When It Needs Results Now?</h2><p>AI is progressing rapidly, and Europe must act quickly to improve its position. Fortunately, it has a number of tools at its disposal to maintain access to frontier AI models.</p><p><strong>Leading AI companies need compute capacity, and Europe could provide it.</strong> First, Europe could seek to build compute capacity quickly, along with the energy infrastructure necessary to power it. The aim would be to use this compute not exclusively for European AI development but as infrastructure that reduces dependence and creates negotiating leverage. The constraint on frontier AI development and deployment is increasingly compute, and evidence of its scarcity keeps accumulating. In March 2026, Anthropic <a href="https://www.theregister.com/software/2026/03/26/anthropic-tweaks-claude-usage-limits-to-manage-capacity/5225406">tightened peak-hour session limits</a> for paying users due to capacity constraints. By May, it had agreed to spend <a href="https://finance.yahoo.com/sectors/technology/articles/why-anthropic-now-paying-biggest-171854528.html">$1.25 billion per month to rent capacity</a> from xAI&#8217;s Colossus cluster through 2029. When a leading AI lab is forced to buy infrastructure from a direct competitor just to keep its basic tiers online, it is a clear signal that compute remains a constraint to AI development.</p><p>An AI lab that needs European data centers, European talent, and European revenue has reasons to treat Europe as a partner rather than a market it can afford to work around. If Europe becomes a major host of leading models, this makes restrictions less likely due to the costs to American companies of losing access to the European market. Not so long ago, Nvidia was allowed to sell chips to China because of its importance as a market. To build such leverage in practice, Europe <a href="https://www.rand.org/pubs/research_reports/RRA4636-1.html">needs to urgently address the barriers to buildout</a>: high energy costs, slow planning processes, and fragmented capital markets.</p><p><strong>Middle powers could cooperate more deeply to demonstrate their importance to AI development.</strong> Europe should work with other middle powers to mobilize a coordinated response. The semiconductor supply chain runs through the Netherlands, Japan, South Korea, and Taiwan. AI evaluation and testing capacity is concentrated in the UK. Many of the most commercially significant AI applications&#8212;from Lovable in Sweden to leading adopters across Canada and India&#8212;are built on top of American frontier models, generating the revenue and usage data those labs depend on. Export-controlling American models while depending on allied components, talent, testing infrastructure, revenue, and data should be a strategy with a limited shelf life. Middle powers need to work more closely to demonstrate that they are as necessary to producing AI as the companies currently building it.</p><p><strong>Europe must both invest in AI sovereignty and build relationships with US AI companies.</strong> Finally, Europe should amplify efforts to build indigenous frontier capabilities and chips, even if the near-term prospects appear improbable. An ambitious European AI effort would require spending levels that dwarf anything Europe can credibly mobilize through subsidies alone. <a href="https://www.siliconcontinent.com/p/nineteen-thoughts-on-ai-and-europe">Meta</a> will invest <a href="https://investor.atmeta.com/investor-news/press-release-details/2026/Meta-Reports-First-Quarter-2026-Results/default.aspx">$125 billion in capital expenditures</a> this year, more than <a href="https://www.sipri.org/media/press-release/2026/global-military-spending-rise-continues-european-and-asian-expenditures-surge">Germany&#8217;s entire defense budget</a>, and its AI models still fail to match capabilities from OpenAI and Anthropic. But, difficulty aside, meaningful European AI development will become a necessity over the long term. The question is how Europe can build sovereign AI capabilities while strategically developing partnerships with value-aligned US companies, such as Anthropic. Doing neither or only one has too many downsides; doing both buys optionality.</p><h2>Export Controls Are a Wake-Up Call for Europe</h2><p>Arguably, the export controls on Fable 5 and Mythos 5 do not fundamentally change Europe&#8217;s position on AI. Europe was dependent on American AI models and chips before last Friday and remains so today. The immediate economic consequences are likely manageable, particularly if the restrictions prove short-lived. But Europe&#8217;s response must nonetheless move beyond the familiar debates on sovereignty. It should be concrete: expand compute capacity, coordinate closely with other middle powers, invest in domestic capabilities, and deepen partnerships with firms that need European markets as much as Europe needs them. The overall impact of the recent order could in fact be positive for Europe&#8212;but only if it spurs the continent into acting on AI in ways that it already needed to.</p><p></p><div><hr></div><p><em><strong>See things differently? </strong>AI Frontiers welcomes expert insights, thoughtful critiques, and fresh perspectives. <a href="https://ai-frontiers.org/publish?utm_source=aif_article">Send us your pitch.</a></em></p><div><hr></div><p><em>Afek Shamir is an Analyst at RAND Europe, working with the Center on AI, Security, and Technology and the Frontiers of Technology hub. His research focuses on Europe&#8217;s role in frontier AI development and governance, with particular interest in the continent&#8217;s geopolitical positioning and leverage vis-a-vis other leading AI powers. Prior to RAND, Afek worked at a Brussels-based think tank on the EU AI Act&#8217;s governance of general-purpose AI as a Talos fellow and interned at the Tony Blair Institute. Afek holds an M.Sc. in European and International Public Policy from the London School of Economics.</em></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://newsletter.ai-frontiers.org/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support our work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[A Roadmap for the Upcoming Labor Transition]]></title><description><![CDATA[AI&#8217;s economic impacts will unfold through several waves, with different policy approaches relevant to each phase.]]></description><link>https://newsletter.ai-frontiers.org/p/a-roadmap-for-the-upcoming-labor</link><guid isPermaLink="false">https://newsletter.ai-frontiers.org/p/a-roadmap-for-the-upcoming-labor</guid><dc:creator><![CDATA[AI Frontiers]]></dc:creator><pubDate>Tue, 16 Jun 2026 13:03:17 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!3XM-!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e621123-9f7b-4090-b6ae-3eedba484fbf_2736x1824.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong><a href="https://ai-frontiers.org/author/deric-cheng">Deric Cheng</a></strong> and <strong><a href="https://ai-frontiers.org/author/jacob-schaal">Jacob Schaal</a></strong> &#8212; June 16, 2026</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!3XM-!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e621123-9f7b-4090-b6ae-3eedba484fbf_2736x1824.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!3XM-!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e621123-9f7b-4090-b6ae-3eedba484fbf_2736x1824.jpeg 424w, https://substackcdn.com/image/fetch/$s_!3XM-!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e621123-9f7b-4090-b6ae-3eedba484fbf_2736x1824.jpeg 848w, https://substackcdn.com/image/fetch/$s_!3XM-!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e621123-9f7b-4090-b6ae-3eedba484fbf_2736x1824.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!3XM-!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e621123-9f7b-4090-b6ae-3eedba484fbf_2736x1824.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!3XM-!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e621123-9f7b-4090-b6ae-3eedba484fbf_2736x1824.jpeg" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3e621123-9f7b-4090-b6ae-3eedba484fbf_2736x1824.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!3XM-!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e621123-9f7b-4090-b6ae-3eedba484fbf_2736x1824.jpeg 424w, https://substackcdn.com/image/fetch/$s_!3XM-!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e621123-9f7b-4090-b6ae-3eedba484fbf_2736x1824.jpeg 848w, https://substackcdn.com/image/fetch/$s_!3XM-!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e621123-9f7b-4090-b6ae-3eedba484fbf_2736x1824.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!3XM-!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e621123-9f7b-4090-b6ae-3eedba484fbf_2736x1824.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The debate about AI&#8217;s future economic impacts often settles into two camps predicting incompatible futures. One camp insists that <a href="https://www.normaltech.ai/p/ai-as-normal-technology">AI is a normal technology</a>: simply the next in a long line of economic transformations, each increasing productivity while gradually reallocating labor. The other camp warns that AI will become a great displacer: that <a href="https://epoch.ai/blog/announcing-gate">automation will hollow out the working class</a> within a decade and eventually disempower large swaths of human workers.</p><p>Each side often treats the other&#8217;s predictions as unserious, and, consequently, policy debates often split along the same tired fault lines: whether we need reskilling or universal basic income, whether we should strengthen safety nets or structurally redesign our economy. The two camps&#8217; forecasts <a href="https://ai-frontiers.org/articles/the-quadrillion-dollar-disagreement-on-ai-and-the-economy">diverge so sharply</a> that it can be hard to see that they do not have to be mutually exclusive.</p><p>Rather, a more useful framing treats these predictions as describing different stages of the same overarching transition rather than as competing accounts of the same moment. From a macro perspective, <a href="https://writing.antonleicht.me/p/ai-and-jobs-two-phases-of-automation?r=mklh&amp;triedRedirect=true">both narratives will play out roughly sequentially</a>, though those phases may overlap substantially across sectors and timelines.</p><p>In the short term, it seems inevitable that AI will look like an accelerated version of past automation waves: significant <a href="https://www.aeaweb.org/articles?id=10.1257/mac.20180386">productivity gains after a period of integration</a>, job displacement in specific occupations, and a familiar churn of workers cycling into new roles.</p><p>In the long term, it is hard to conceive of a future in which transformative AI systems do not lead to a massive restructuring of the economy and a reconsideration of the role of human labor. A world in which machine intelligence can perform most economically valuable cognitive (and, increasingly, physical) labor, at a fraction of human cost, must eventually lead to a completely new kind of economic system.</p><p>Our responsibility during this period is to prepare and to guide our economy deliberately through these sequential and <a href="https://mollykinder2.substack.com/p/the-messy-middle">overlapping transitions</a>. To do so, we must develop thoughtful roadmaps that account for both near-term and long-term impacts, and that can adapt effectively to support national governments in managing these changes.</p><p>In the rest of this article, we lay out such a roadmap, describing each phase of the economic transition and outlining some of the most commonly discussed policy solutions at each stage.</p><h2>Near Term: Managing Economic Shocks</h2><p>In the near term, the most pressing economic concerns are AI economic shocks and the labor displacement of certain groups, such as early-career employees or workers in highly exposed occupations. Certainly, there will be other jobs to transition into. The only question is whether they will be <a href="https://www.brookings.edu/articles/measuring-us-workers-capacity-to-adapt-to-ai-driven-job-displacement/">accessible or desirable</a>.</p><p><strong>Initial displacement will be concentrated in certain domains.</strong> The impact of AI will be highly varied across sectors, with some being <a href="https://cdn.openai.com/pdf/the-ai-jobs-transition-framework_report.pdf">significantly more vulnerable</a> than others. A recent report from Boston Consulting Group estimates that around <a href="https://www.bcg.com/publications/2026/ai-will-reshape-more-jobs-than-it-replaces">50% of American jobs will see restructuring or reshaping</a> due to AI. For the average white-collar employee or college graduate, what their career will look like in five years is quite unclear.</p><p><strong>Displacement could be sudden.</strong> In particular, <a href="https://www.theguardian.com/technology/2026/feb/24/feedback-loop-no-brake-how-ai-doomsday-report-rattled-markets">markets are concerned about a potential rapid collapse of demand</a> for historically well-paying occupations such as software engineers, financial analysts, and legal associates, which could trigger cascading effects. Research suggests that up to <a href="https://www.imf.org/en/news/articles/2024/05/30/sp053024-crisis-amplifier-how-to-prevent-ai-from-worsening-the-next-economic-downturn#:~:text=Let%20me%20describe%20how%20AI,or%20immediately%20after%20a%20downturn">90% of automation-related job losses</a> occur during the first year of recessions. If an <a href="https://www.npr.org/2025/12/31/nx-s1-5660842/what-is-a-k-shaped-economy">increasingly unequal economy</a> encounters a sudden slowdown, labor displacement could be both sudden and concentrated. The initial shock would be further compounded by the second-order effects of <a href="https://www.brookings.edu/articles/future-tax-policy-a-public-finance-framework-for-the-age-of-ai/">reduced tax revenues</a>, weakened consumer demand, and wage scarring (the long-term negative impact of unemployment on an individual&#8217;s wages).</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!UA2v!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F662d91c8-dbe4-417e-a14f-787a846425d0_1866x1152.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!UA2v!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F662d91c8-dbe4-417e-a14f-787a846425d0_1866x1152.png 424w, https://substackcdn.com/image/fetch/$s_!UA2v!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F662d91c8-dbe4-417e-a14f-787a846425d0_1866x1152.png 848w, https://substackcdn.com/image/fetch/$s_!UA2v!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F662d91c8-dbe4-417e-a14f-787a846425d0_1866x1152.png 1272w, https://substackcdn.com/image/fetch/$s_!UA2v!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F662d91c8-dbe4-417e-a14f-787a846425d0_1866x1152.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!UA2v!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F662d91c8-dbe4-417e-a14f-787a846425d0_1866x1152.png" width="1456" height="899" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/662d91c8-dbe4-417e-a14f-787a846425d0_1866x1152.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:899,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!UA2v!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F662d91c8-dbe4-417e-a14f-787a846425d0_1866x1152.png 424w, https://substackcdn.com/image/fetch/$s_!UA2v!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F662d91c8-dbe4-417e-a14f-787a846425d0_1866x1152.png 848w, https://substackcdn.com/image/fetch/$s_!UA2v!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F662d91c8-dbe4-417e-a14f-787a846425d0_1866x1152.png 1272w, https://substackcdn.com/image/fetch/$s_!UA2v!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F662d91c8-dbe4-417e-a14f-787a846425d0_1866x1152.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption"><em>Source: &#8220;<a href="https://www.imf.org/en/news/articles/2024/05/30/sp053024-crisis-amplifier-how-to-prevent-ai-from-worsening-the-next-economic-downturn">Crisis Amplifier? How to Prevent AI from Worsening the Next Economic Downturn</a>&#8221;</em></figcaption></figure></div><p><strong>One remedy is to modernize and scale active labor market policies.</strong> Among the most popular solutions to these near-term risks are policy interventions aiming to help people find and keep jobs. <a href="https://windfalltrust.org/policy-atlas/wage-insurance">Wage insurance programs</a> have shown promising empirical evidence to improve worker outcomes during transition periods. For instance, Germany&#8217;s Kurzarbeit helped it <a href="https://www.imf.org/en/News/Articles/2020/06/11/na061120-kurzarbeit-germanys-short-time-work-benefit">avoid rising unemployment</a> during the 2008 financial crisis, making it the only G7 country to do so. Meanwhile, the US&#8217;s Reemployment Trade Adjustment Assistance program is estimated to have <a href="https://www.nber.org/system/files/working_papers/w32464/w32464.pdf">increased employment probability by 8% to 17%</a>, and it largely pays for itself through higher tax revenue and reduced benefit outlays.</p><p><a href="https://windfalltrust.org/policy-atlas/workforce-training-and-reskilling-investment">Reskilling programs</a> have also been widely discussed among policymakers, though it is still unclear what industries workers should be retraining for. Other proposals include <a href="https://windfalltrust.org/policy-atlas/unemployment-benefits">dynamically expanding unemployment benefits</a> or <a href="https://windfalltrust.org/policy-atlas/job-guarantees-and-public-works-programs">job guarantee programs</a> that could provide transitional public employment.</p><p>To strengthen these programs, governments must invest more significantly in labor market data, streamlined benefits systems, and <a href="https://www.oecd.org/en/publications/digital-public-infrastructure-for-digital-governments_ff525dc8-en.html">payment infrastructure</a>&#8212;the absence of which hampered COVID-era relief distribution globally. These investments, made in the near term, can also help to develop the infrastructural backbone for more ambitious medium- and long-term interventions.</p><h2>Medium Term: Navigating Reorganization and Divergence</h2><p>In the medium term, the transition to an economy dominated by AI will present both extraordinary opportunities and structural risks. As AI systems become increasingly capable, they will be able to complete ever more workstreams end-to-end, potentially driving broader job displacement than seen in the near term. A new class of superstar firms might emerge in winner-takes-all markets where scale&#8212;especially of compute and capital&#8212;could confer decisive advantages. The medium-term period could be defined by a <a href="https://www.aeaweb.org/articles?id=10.1257/mac.20180386">delayed but rapidly accelerating impact</a> on productivity and employment, an increasing divergence in AI adoption and growth between regions and countries, and growing pressure on fiscal systems.</p><p><strong>Differences in AI adoption may drive divergent outcomes for countries.</strong> Since countries will adopt and develop AI unequally, the impacts on productivity are also likely to differ. This could contribute to increasing <a href="https://www.rand.org/content/dam/rand/pubs/research_reports/RRA4400/RRA4444-1/RAND_RRA4444-1.pdf">global inequality</a>, especially when <a href="https://newsletter.forethought.org/p/could-one-country-outgrow-the-rest">technological diffusion is limited</a> (e.g., by export controls, protectionism, or regulatory barriers). The <a href="https://www.whitehouse.gov/research/2026/01/artificial-intelligence-and-the-great-divergence/">White House Council of Economic Advisers</a> warns that countries lacking the ability to develop advanced AI face compounding disadvantages that could produce a second Great Divergence, paralleling the Industrial Revolution.</p><p><strong>Widespread labor displacement could substantially impact tax revenue.</strong> If new economic growth is increasingly captured by a smaller proportion of AI-led corporations, tax systems built primarily around payroll taxation could face <a href="https://www.rand.org/pubs/working_papers/WRA4443-1.html">revenue shortfalls</a> and a structural mismatch between where value is created and where it is taxed. Globally and in the US, labor revenue is typically taxed at a significantly higher rate (and more effectively) compared with how capital is taxed. A substantial shift of economic growth toward capital could therefore lead to <a href="https://windfalltrust.org/publications/mapping-tax-risks-from-labour-displacing-ai">multi-digit</a> <a href="https://www.policyengine.org/us/ai-inequality/income-shift">percentage declines</a> in revenue.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!YLpy!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fff36d5-f4b3-476c-bf63-d2304e04fb42_933x647.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!YLpy!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fff36d5-f4b3-476c-bf63-d2304e04fb42_933x647.png 424w, https://substackcdn.com/image/fetch/$s_!YLpy!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fff36d5-f4b3-476c-bf63-d2304e04fb42_933x647.png 848w, https://substackcdn.com/image/fetch/$s_!YLpy!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fff36d5-f4b3-476c-bf63-d2304e04fb42_933x647.png 1272w, https://substackcdn.com/image/fetch/$s_!YLpy!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fff36d5-f4b3-476c-bf63-d2304e04fb42_933x647.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!YLpy!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fff36d5-f4b3-476c-bf63-d2304e04fb42_933x647.png" width="933" height="647" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2fff36d5-f4b3-476c-bf63-d2304e04fb42_933x647.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:647,&quot;width&quot;:933,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!YLpy!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fff36d5-f4b3-476c-bf63-d2304e04fb42_933x647.png 424w, https://substackcdn.com/image/fetch/$s_!YLpy!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fff36d5-f4b3-476c-bf63-d2304e04fb42_933x647.png 848w, https://substackcdn.com/image/fetch/$s_!YLpy!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fff36d5-f4b3-476c-bf63-d2304e04fb42_933x647.png 1272w, https://substackcdn.com/image/fetch/$s_!YLpy!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fff36d5-f4b3-476c-bf63-d2304e04fb42_933x647.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption"><em>Source:</em> <em><a href="https://taxpolicycenter.org/briefing-book/what-are-sources-revenue-federal-government">What are the sources of revenue for the federal government?</a></em></figcaption></figure></div><p>Several common themes in today&#8217;s policy conversation could help to address the medium-term economic impacts of AI.</p><p><strong>Policymakers will need to begin considering taxation reforms.</strong> Leading economists have proposed a shift toward <a href="https://www.nber.org/papers/w34873">consumption-based taxation</a> if labor income declines in importance. By capturing spending rather than earning, higher consumption taxes would sidestep the question of labor versus capital income. A contrasting approach centers around <a href="https://www.agisocialcontract.org/anthology/a-progressive-global-corporate-tax-for-the-age-of-ai">progressive corporate taxation</a>, which would impose higher marginal rates on the most profitable multinational enterprises through global coordination. Alternatively, <a href="https://windfalltrust.org/policy-atlas/token-taxes">token taxes</a> could capture revenue streams directly from leading AI corporations. Any of these measures alone might be insufficient; an effective fiscal response would likely need to combine approaches to create a tax code with adequate resilience and fitness for future scenarios.</p><p><strong>Countries could strengthen their economies by fostering AI-related industries.</strong> As economies grow more focused on AI, countries will need to consider active industrial policy, primarily to aid their economic competitiveness and stimulate job creation in increasingly important industries. Ramping up AI infrastructural investments is already a mainstream discussion in most countries, where we are seeing proposals to <a href="https://cfg.eu/ai-preparedness-robust-policy-options-for-europe/">increase capital inflows</a>, create special &#8220;<a href="https://www.gov.uk/government/publications/ai-opportunities-action-plan/ai-opportunities-action-plan">AI Growth Zones</a>,&#8221; and <a href="https://www.brookings.edu/articles/openai-floats-federal-support-for-ai-infrastructure-what-should-the-public-expect/">subsidize data center investments</a>. Emerging ideas include <a href="https://cfg.eu/building-cern-for-ai/">publicly owned AI foundation models</a> or <a href="https://windfalltrust.org/policy-atlas/employer-tax-breaks">tax breaks</a> incentivizing employers to invest in worker retraining or human capital development.</p><p><strong>Governments may need to actively protect vulnerable workers and industries.</strong> <a href="https://windfalltrust.org/policy-atlas/sectoral-subsidies">Labor subsidies</a> targeting socially valuable sectors could preserve employment where human participation generates positive externalities, such as education or elderly care. For example, in 2021 <a href="https://www.sdg16.plus/policies/south-koreas-senior-employment-program-for-those-over-the-age-of-65-years/">South Korea&#8217;s Senior Employment Program</a> provided work for roughly 840,000 people over age 60. Elsewhere, leading economists have proposed a series of policies to encourage &#8220;<a href="https://www.brookings.edu/articles/building-pro-worker-ai/">pro-worker AI</a>&#8221;: deploying assistive AI that makes workers more productive, instead of outright replacing them. Strengthening <a href="https://sites.lsa.umich.edu/mje/2023/12/06/a-deep-dive-into-the-economic-ripples-of-the-hollywood-strike/">collective bargaining rights</a> may also play a key role in determining whether organized labor can secure meaningful leverage for workers.</p><p>By making such investments in the next decade, governments will determine whether they can protect workers in a medium-term future where new economic growth becomes increasingly dominated by capital. These measures could also lay the foundation for managing the largest economic impacts of AI over the long term.</p><h2>Long Term: Restructuring Economies</h2><p>Provided we avoid the more extreme risks of AI, a likely trajectory of the technology is that it eventually surpasses humans across an increasing proportion of economically valuable tasks. Machine intelligence faces fewer fundamental constraints than its biological counterpart. AI will continue to decrease in cost both for cognitive labor&#8212;which is already price-competitive with humans on many tasks&#8212;and eventually for manual labor, which will be constrained primarily by the marginal cost of robotics systems.</p><p><strong>AI could automate a steadily increasing proportion of new economic growth.</strong> In the long run, there may be few persistent bottlenecks to automation as the economy restructures around powerful AI systems. Durable human advantages may persist <a href="https://www.convergenceanalysis.org/publications/a-taxonomy-of-jobs-deeply-resistant-to-tai-automation">primarily in domains</a> requiring interpersonal connection or physical presence, as well as in contexts where <a href="https://aleximas.substack.com/p/what-will-be-scarce">people specifically prefer human involvement.</a></p><p><strong>Automation could change the social contract.</strong> This transformation could challenge the foundational premise of modern economies: that hard work and talent are the primary route to income and economic security. If labor <a href="https://intelligence-curse.ai/capital/">ceases to be a reliable path</a> to capital accumulation, <a href="https://www.agisocialcontract.org/anthology/forging-a-new-agi-social-contract">core aspects of the social contract may break down</a> for a growing share of the population. Eventually, the policy challenge may shift to fundamentally redesigning the relationship between citizens and the economy itself.</p><p>Many ideas for meeting this challenge have been suggested, beyond the call for <a href="https://windfalltrust.org/policy-atlas/universal-basic-income">universal basic income</a>.</p><p><strong>Equity and capital may need to be predistributed.</strong> Many recent proposals have centered around <a href="https://papers.ssrn.com/sol3/papers.cfm?abstract_id=5615910">fractional public ownership</a> of AI equity, requiring that AI firms transfer equity to governments, which would own them on behalf of the public. Unlike universal basic income, which requires perpetual political will, redistributing capital would create durable property rights that compound over time. Leading economists such as <a href="https://www.digitalistpapers.com/vol2/autorthompson">David Autor and Neil Thompson</a> argue that we should begin experimenting with universal basic capital (UBC) now, as, even in the most ambitious cases, it would take multiple decades for capital ownership to be broadly diffused.</p><p><strong>Sovereign wealth and international coordination may help to distribute AI benefits.</strong> <a href="https://www.convergenceanalysis.org/fellowships/spar-economics/lead-own-share-sovereign-wealth-funds-for-transformative-ai">Sovereign wealth funds</a> (SWFs) have emerged as a widely discussed institutional vehicle for public co-ownership, with promising examples in <a href="https://www.peoplespolicyproject.org/projects/social-wealth-fund/">Norway and Alaska</a>. By holding equity stakes in AI firms and infrastructure, governments could become better invested in the long-term success of AI and eventually distribute these gains to citizens via cash dividends or public services. Globally, an increasing divergence between countries that produce AI and countries that consume it may eventually lead to calls for <a href="https://windfalltrust.org/policy-atlas/restructuring-international-organizations">stronger international institutions</a>, <a href="https://windfalltrust.org/policy-atlas/increased-corporate-taxation">multilateral tax coordination</a>, or even <a href="https://windfalltrust.org/policy-atlas/global-dividend-funds">dividend funds on behalf of all humans</a>.</p><p><strong>Governments may provide universal basic services.</strong> In the long run, governments may choose to <a href="https://windfalltrust.org/policy-atlas/universal-basic-services">expand the direct provision of essential services</a>&#8212;including health care, child care, and education&#8212;so that they are fully decoupled from employment status. The UK&#8217;s National Health Service, Finland&#8217;s free university system, and <a href="https://www.abc.net.au/news/2023-08-04/vienna-s-social-housing-and-low-rent-strategy/102639674">Vienna&#8217;s social housing model</a> demonstrate that universal basic services can be administratively feasible and politically durable.</p><p>With a combination of these policies, it is entirely plausible that in highly automated and productive futures, governments could ensure a basic level of economic security for all citizens. The open question is whether the political will to do so will exist.</p><h2>Conclusion</h2><p><strong>The exact policy interventions will differ dramatically on a country-by-country basis. </strong>There is no single policy roadmap that will work everywhere; each government will need to design a strategy uniquely suited to its own citizens, culture, and institutional context.</p><p><strong>Each stage of interventions can help create the infrastructure for the next.</strong> In many cases, the policy proposals described above help to lay the groundwork for navigating later stages of the economic transition, as well as having immediate benefits during the stage at which they are implemented. Building social safety nets today may enable greater bargaining power for labor later. Strengthening taxation mechanisms eventually supports funding for broader public service provisioning. Effective economic policies compound: they succeed as deeply interwoven networks over decades of investment.</p><p><strong>Nations will need to develop their own</strong> <strong><a href="https://windfalltrust.org/policy-atlas/introduction">economic preparedness plans</a></strong>. Governments should develop self-assessments and policy strategies tailored to their specific labor market exposure to AI. By evaluating a wide range of potential scenarios, countries can test their preparedness for highly uncertain futures. Only with that foundation can they develop strategic policy roadmaps for the transition ahead.</p><p>Policymakers globally are just beginning to recognize that the intersection of AI and labor will be a defining theme of upcoming elections. Within a few years, this will likely become a core issue for political candidates around the world. Yet governments are not remotely prepared to offer coherent responses on the scale these challenges will require. If we can support our policymakers with better foresight and more coherent roadmaps to economic success, we may be able to guide this upcoming transition toward prosperity and widely shared financial security.</p><p>&#8205;</p><div><hr></div><p><em><strong>See things differently? </strong>AI Frontiers welcomes expert insights, thoughtful critiques, and fresh perspectives. <a href="https://ai-frontiers.org/publish?utm_source=aif_article">Send us your pitch.</a></em></p><div><hr></div><p><em>Deric Cheng is the Director of Research for Windfall Trust, a non-profit focused on ensuring that the economic benefits of advanced AI are shared by everyone. He is also the lead for AGI Social Contract, a consortium of experts proposing strategies to design a new social contract for a post-AGI society.</em></p><p><em>Jacob Schaal an economist researching AI&#8217;s labor market impacts. He is a researcher at Kings College London, and co-edits the AI Economics Brief at Windfall Trust. He holds an MSc in Economics from the London School of Economics.</em></p>]]></content:encoded></item><item><title><![CDATA[AI Will Not Start a Nuclear War, but Humans Might]]></title><description><![CDATA[Researchers and policymakers are fixated on the fear of AI launching nuclear weapons&#8212;to the neglect of more realistic threats.]]></description><link>https://newsletter.ai-frontiers.org/p/ai-will-not-start-a-nuclear-war-but</link><guid isPermaLink="false">https://newsletter.ai-frontiers.org/p/ai-will-not-start-a-nuclear-war-but</guid><dc:creator><![CDATA[AI Frontiers]]></dc:creator><pubDate>Tue, 09 Jun 2026 13:02:23 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!gYrH!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc90e8aa1-2e5f-4d3b-a37f-31b79f41f01a_1000x667.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong><a href="https://ai-frontiers.org/author/peter-w-singer">Peter W Singer</a></strong> &#8212; June 9, 2026</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!gYrH!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc90e8aa1-2e5f-4d3b-a37f-31b79f41f01a_1000x667.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!gYrH!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc90e8aa1-2e5f-4d3b-a37f-31b79f41f01a_1000x667.jpeg 424w, https://substackcdn.com/image/fetch/$s_!gYrH!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc90e8aa1-2e5f-4d3b-a37f-31b79f41f01a_1000x667.jpeg 848w, https://substackcdn.com/image/fetch/$s_!gYrH!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc90e8aa1-2e5f-4d3b-a37f-31b79f41f01a_1000x667.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!gYrH!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc90e8aa1-2e5f-4d3b-a37f-31b79f41f01a_1000x667.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!gYrH!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc90e8aa1-2e5f-4d3b-a37f-31b79f41f01a_1000x667.jpeg" width="1000" height="667" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c90e8aa1-2e5f-4d3b-a37f-31b79f41f01a_1000x667.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:667,&quot;width&quot;:1000,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!gYrH!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc90e8aa1-2e5f-4d3b-a37f-31b79f41f01a_1000x667.jpeg 424w, https://substackcdn.com/image/fetch/$s_!gYrH!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc90e8aa1-2e5f-4d3b-a37f-31b79f41f01a_1000x667.jpeg 848w, https://substackcdn.com/image/fetch/$s_!gYrH!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc90e8aa1-2e5f-4d3b-a37f-31b79f41f01a_1000x667.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!gYrH!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc90e8aa1-2e5f-4d3b-a37f-31b79f41f01a_1000x667.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>&#8220;<a href="https://www.yahoo.com/news/articles/bloodthirsty-ai-models-more-willing-210902543.html">Bloodthirsty AI models more willing to start nuclear war than human counterparts</a>.&#8221;</p><p>It seems almost inevitable that any media headline about AI will be hyperbolic. Yet this statement, taken from a February 2026 <em>New York Post</em> headline, was accurate. The alarming claim stems from a widely publicized <a href="https://arxiv.org/pdf/2602.14740">study</a> by King&#8217;s College London, which found that, in simulations of international crises, LLMs reached for the nuclear trigger 95% of the time.</p><p>This academic study drew mainstream-media attention because it touched upon a cultural narrative that has long combined the concept of AI with nuclear weapons. Arguably, the first movie to bring the two together was 1957&#8217;s &#8220;Invisible Boy,&#8221; featuring Robby the Robot, who would later become famous (and less bloodthirsty) in the 1960s TV series &#8220;Lost in Space.&#8221; The trope has since been repeated across franchises ranging from &#8220;The Terminator<em>&#8221; </em>to &#8220;Mission Impossible.&#8221;</p><p>Yet the AI-nuclear fear is not confined to the media and movie theaters. The King&#8217;s College study is only one of scores of similar academic and think-tank research projects on AI&#8217;s proclivities for nuclear war, which have been backed by millions of dollars in research grants. Among the entities that have funded such work are the National Nuclear Security Administration (NNSA), the Department of Energy, the Department of Defense, Anthropic, the MacArthur Foundation, the Carnegie Corporation of New York, the Future of Life Institute, Open Philanthropy, RAND, and the Smith Richardson Foundation. It is also an essential element in the larger field of study on the existential risks of AI, funded to the tune of multiple billions of dollars at many of the world&#8217;s leading universities, including Oxford, Cambridge, Stanford, and the University of California, Berkeley.</p><p>Beyond academia, the discussion of AI-nuclear risks has also entered the halls of government in settings that range from the UN to multiple US-China superpower summits to the US Congress. It has even become part of the <a href="https://www.gov.ca.gov/wp-content/uploads/2025/06/June-17-2025-%E2%80%93-The-California-Report-on-Frontier-AI-Policy.pdf">reasoning</a> for why states like California are seeking limits on frontier AI. Indeed, the fear of &#8220;the incorporation of AI into nuclear decision-making&#8221; has reached such a height that the &#8220;Bulletin of the Atomic Scientists&#8221; earlier this year <a href="https://www.theguardian.com/science/2026/may/09/doomsday-clock-ai-iran-ukraine-war-climate-breakdown-nuclear-apocalypse">moved</a> its famous &#8220;Doomsday Clock&#8221; to 85 seconds to midnight, the closest it has ever been. (For comparison, the clock was at 12 minutes in the aftermath of the Cuban Missile Crisis.)</p><p>Despite all this, I am excited to be the bearer of good news: AI is not going to start a nuclear war anytime soon. I do, however, also have bad news: AI is making it more likely that humans will start a nuclear war. And, if we want to avoid that outcome, we should focus on mitigating real risks, resisting incentives that steer us toward the tropes.</p><p>The following report will explain why no government will likely delegate nuclear launch to machines either now or in the future, and identify three mechanisms&#8212;arms racing, miscalculation, and machine speed&#8212;by which AI could already be amplifying the risk of humans deciding to go to war.</p><h2>Why AI Will Not Decide Nuclear Wars</h2><p>Studies such as the one from King&#8217;s College consider hypothetical scenarios in which an LLM determines whether a nation should proliferate nuclear weapons or even when to fire a full nuclear strike. Yet there are multiple good reasons why humans will not, in reality, hand machines this responsibility.</p><p><strong>Adversarial robustness and a dearth of training data present technological barriers.</strong> First, to be trusted with nuclear decisions, AI systems would need to not only be more capable than humans but also extremely adversarially robust&#8212;meaning that geopolitical opponents could not influence such systems by manipulating input data. While capabilities have come a long way, adversarial robustness has historically proven very challenging. Another glaring issue is the availability of training data for fighting nuclear wars: there is none.</p><p><strong>There are laws and agreements prohibiting fully autonomous nuclear decisions.</strong> Alongside the technological barriers are domestic laws and international agreements. Section 1638 of the US FY 2025<a href="https://www.congress.gov/bill/118th-congress/house-bill/5009/text"> National Defense Authorization Act</a> calls for keeping a human in the loop for nuclear decisions. Similarly, Chinese President Xi Jinping and then&#8211;US President Joe Biden <a href="https://www.npr.org/2024/11/16/nx-s1-5193893/xi-trump-biden-ai-export-controls-tariffs">agreed</a> in late 2024 that AI should never be granted the authority to initiate a nuclear launch.</p><p>AI technology may advance and laws could certainly change or be ignored. But one thing will not: the use of nuclear weapons will always come down to decisions of politics and war. This is critical. It explains why AI systems are not presently in the position they occupy in the studies and movies and why they will not occupy that position in the future.</p><p>Take the area of politics. In the 2025 film &#8220;A House of Dynamite,&#8221;<em> </em>a fictional US president facing a nuclear crisis laments that he and his team spent more time on a Supreme Court justice nomination than on whether to launch a nuclear strike&#8212;the most important decision of not just his life but maybe human history.</p><p>What the various scenarios and studies require is that a human leader either consults an AI for advice, when weighing a potential nuclear strike, or has already turned over this decision to a machine at some point beforehand. Either would be the most unlikely of political outcomes, in any form of government outside the imaginings of Silicon Valley techno-state.</p><p><strong>Political leaders would not give up the most important decision of their lives to an AI.</strong> Political leaders would neither surrender nuclear decision-making to a machine nor blindly follow its advice contrary to their own judgment. To think that elected leaders would defer to an AI even on whom to nominate to the Supreme Court, let alone on a nuclear launch, is to assume that such leaders lack confidence in themselves and their judgements&#8212;something which political leaders are not in short supply of. This is why it was so easy for Biden and Xi to agree not to let AI decide nuclear launch; it is something they would never have considered anyway.</p><p><strong>Any suggestion to put AIs in charge of nuclear decisions would spark public outcry.</strong> Moreover, even to contemplate creating the policy and technical mechanism for changing the multiple-billion-dollar, three-generations-old nuclear command-and-control architecture would create career-ending outcomes for democratically elected leaders. Only <a href="https://poll.qu.edu/poll-release?releaseid=3955">3% of Americans</a> believe that we should trust information from AI even &#8220;almost all of the time.&#8221; A leader proposing to trust it with nuclear war could expect to be rapidly relieved of any power to implement that proposal.</p><p>Authoritarian leaders are even less inclined to hand over consequential decisions to anyone or anything other than themselves. This is even codified in some nations&#8217; command structures. Under China&#8217;s &#8220;Chairman Responsibility System,&#8221; the operational authority to command or launch nuclear weapons rests solely with the chairman of the Central Military Commission, who just happens to be the general secretary of the Chinese Communist Party.</p><p><strong>Militaries are rapidly adopting AI, but not for nuclear decision-making.</strong> Of course, militaries are spending billions of dollars on AI, but not on integrating it into nuclear decisions. As a study on the &#8220;nexus of nuclear weapons and AI&#8221; <a href="https://warontherocks.com/ai-autonomy-and-the-risk-of-nuclear-war/">summed</a>, &#8220;AI is unlikely to have material impact on nuclear command and control, which for several decades have <a href="https://www.tandfonline.com/doi/full/10.1080/01402390.2020.1867541">synthesized automation but not autonomy</a>.&#8221;</p><p>Rather, like institutions across the economy and society, militaries are turning to AI to save on money, time, or head count, and/or to get better at the tasks they are not good at. Nuclear warfighting is not an area where militaries feel those pressures.</p><p>To begin, the vast majority of militaries&#8217; AI applications are off the battlefield in support roles, usually with civilian parallels, ranging from military medicine to military logistics. Such support roles make up over 90% of military jobs.</p><p><strong>Militaries need AI to assist in dynamic, non-nuclear warfare.</strong> Applied to warfighting, the US military has been focused on closing the &#8220;OODA loop&#8221; (Observe, Orient, Decide, Act) in <em>non-nuclear</em> war, through enhancing sensors, expanding analytical capabilities, and accelerating the application of this process to a target to strike or defend against.</p><p>Consider the 2026 Iran-US war. The war began in an era with AI, and may have been partly about nuclear weapons. However, neither the decision to go to war nor the use of AI in the war have been linked to any of the worries that have consumed so many grant proposals and reports. AI was used by all parties, but in nothing like the way it is used in the scenarios. US and Israeli forces tracked hundreds of thousands of moving parts, analyzing both their own forces and their potential targets, and then parsed them out for thousands of strikes. In the first four weeks of conflict, US forces <a href="https://www.wsj.com/world/middle-east/iran-missile-status-us-israel-war-6e9cbd25">struck</a> more than 10,000 targets, while Israel hit thousands more.</p><p>In turn, Iran used AI to aid in its tracking and targeting of everything from tankers to US helicopters, firing off thousands of drones and missiles. The conflict then moved into a cat-and-mouse game in which Iranians sought to fire hidden missiles or drones before loitering US drones found and destroyed them. Each side would then try to analyze whether it had destroyed its target or needed to repeat the attempt. One military analysis <a href="https://cove.army.gov.au/article/90-second-war-what-venezuela-and-iran-mean-every-adf-professional">described</a> the machine-speed cycle as a &#8220;90-second war&#8221; taking place over multiple months.</p><p>Nuclear weapons, by contrast, are both physically designed and organized in military doctrine to be used against large and usually pre-decided targets. They are not used in repeated short-loop cycles over campaigns of weeks or months. To put it another way, the military needs AI to help it find a needle in a moving haystack, pull that one needle out, attempt to snap it, and then determine whether it was snapped. The military does not need AI to find the haystack sitting in a field, set it on fire, and then know whether or not it burned down.</p><p>These non-nuclear visions of AI are shared by other nuclear powers, including China. Over the last decade, the People&#8217;s Liberation Army has pursued an &#8220;intelligentization&#8221; program that integrates AI as a decision aid for rapid attacks on the enemy&#8217;s &#8220;kill chain&#8221;; AI-coordinated <a href="https://www.wsj.com/world/china/china-ai-weapons-hawks-wolves-2fcb58bb">swarming drones</a> to overwhelm defenses; and cognitive warfare that uses AI to target human minds through information and cyberattacks. The PLA Information Support Force is building a &#8220;<a href="https://www.defenseone.com/ideas/2025/02/future-chinas-new-information-support-force/402677/?oref=d1-topic-lander-top-story">network information system</a>&#8221; that uses AI, cloud computing, and big-data techniques to fuse data from operational units and create &#8220;dynamic kill networks&#8221; across air, land, sea, space, and cyberspace domains. AI is not, however, in charge of nuclear weapons. Indeed, in a study of over 9,000 AI-related requests for proposals published by the PLA, establishing its AI &#8220;<a href="https://cset.georgetown.edu/publication/chinas-military-ai-wish-list/">wish list</a>,&#8221; projects using AI for nuclear decisions did not feature once.</p><p>On the contrary, running through China&#8217;s military approach to AI is a goal to steer military operations from Beijing. Far from delegating all war choices to machines, Chinese leaders very much want machines that follow the orders of humans&#8212;specifically, that same decision-maker in charge of nuclear weapons, the general secretary of the Chinese Communist Party&#8217;s Central Committee.</p><h2>AI Arms Races: Spend More, Feel Less Secure</h2><p>If we truly want to support global peace and security, we should not focus on the cinematic threat narratives in which AI controls nuclear decision-making. Instead, the more realistic concerns arise not from the mix of AI and nuclear weapons but from interactions between AI and humans. The first of these concerns is that the promises of AI are now fueling an arms race more intense than previous arms races.</p><p><strong>The current AI arms race is heightening feelings of insecurity.</strong> A 2026 <a href="https://www.csis.org/analysis/ai-and-grand-strategy-case-restraint">report</a> by the US Center for Strategic and International Studies summed up the consensus among policymakers and researchers this way: &#8220;Conventional wisdom holds that an AI arms race will define the twenty-first century and could be decided as early as 2030.&#8221; This viewpoint has even been codified into the highest levels of state doctrine. The second Trump administration&#8217;s <a href="https://www.whitehouse.gov/wp-content/uploads/2025/12/2025-National-Security-Strategy.pdf">National Security Strategy</a> explicitly proclaims that AI &#8220;will decide the future,&#8221; echoing Russian President Vladimir Putin&#8217;s <a href="https://apnews.com/article/bb5628f2a7424a10b3e38b07f4eb90d4">2017 statement</a> that whoever leads in this field &#8220;will be the ruler of the world.&#8221; In China, too, achieving global leadership in AI is a non-negotiable national priority; the country&#8217;s most recent five-year plan <a href="https://www.nature.com/articles/d41586-026-00814-3">pledges</a> to use &#8220;extraordinary measures&#8221; to realize that goal.</p><p>What is playing out is a classic security paradox: as nations accelerate their capital investment to secure a technological edge, they raise the stakes and concerns for their opponents, ultimately feeling more vulnerable than when the race began. In short, the more you arms-race, the less secure you feel. But, while arms races are nothing new, AI differs from previous military technologies in ways that introduce three additional layers of insecurity.</p><p><strong>AI is considered a winner-takes-all technology, intensifying the arms race.</strong> First, AI may confer a decisive advantage at a smaller capabilities lead than other technologies. Historically, a nation could trail an adversary technologically and even quantitatively but still stay in the race. For instance, at the turn of the 20th century, the race for dreadnought battleships exacerbated tensions between Imperial Germany and Britain and became a contributing factor to World War I. Notably, though, the German navy never built as many dreadnoughts as the British. (Between 1908 and 1912, Britain launched 29 capital ships, while Germany launched 17: just under 59% of its opponent&#8217;s number.) Yet this disparity didn&#8217;t keep Germany from fighting the Royal Navy to a draw at the 1916 Battle of Jutland and maintaining the threat of a &#8220;fleet in being&#8221; for the rest of the war. So too in the nuclear age, China has maintained deterrence against the US with only 16% of the warhead count&#8212;approximately 600 warheads against the US arsenal of 3,700.</p><p>With AI, however, policymakers appear to perceive domination in binary terms: falling behind is equated with a total loss of strategic agency. Leaders would not tolerate having only 16% or even 59% of their opponent&#8217;s technological capability. On the flip side, a leader who believed their military AI capabilities were 85% better than those of their foe might feel invincible.</p><p><strong>AI introduces a fear of falling behind permanently.</strong> Second, exacerbating insecurity even further, that perceived binary domination may prove real. At some point, an AI that darts ahead could conceivably become infinitely better than its competition, forever, potentially affording the leading nation a permanent decisive advantage. Regardless of whether this turns out to be true, it creates a fear of falling behind in a race where catching up feels impossible. Every technical milestone then becomes interpreted as a potential catastrophe. When the DeepSeek R1 model advanced beyond US expectations for Chinese LLMs, for instance, the discourse immediately framed it as a &#8220;<a href="https://www.fdd.org/analysis/policy_briefs/2025/01/30/ais-sputnik-moment-chinese-ai-model-deepseek-r1-reportedly-surpasses-leading-u-s-ai-models/">Sputnik moment</a>&#8221; for the United States.</p><p><strong>Uncertainty about how best to use AI contributes to heightened concerns.</strong> Finally, AI&#8217;s versatility adds a layer of uncertainty about the smartest ways to use it. In past arms races, whether with ballistic missiles or battleships, the technology was largely uniform. The goal was simply to gain and deploy as many units as possible. AI, however, can diverge into radically different architectures and many more strategies. For instance, an article in &#8220;National Interest&#8221; <a href="https://nationalinterest.org/blog/techland/america-is-running-the-wrong-ai-race">warned</a> that &#8220;America is running the wrong AI race,&#8221; by focusing on advancing frontier models, rather than on large-scale deployment of existing ones.</p><p>The overall result is that the AI age is creating a sense of extreme insecurity among many nations&#8212;an environment that is not conducive to peace.</p><h2>The Cognitive Fog: Misperception and Miscalculation</h2><p>A second concern about AI is its potential to add to the fog of war. Although AI is frequently marketed as a tool to provide clarity in complex analyses, it can also fuel misperception and miscalculation in multiple ways, potentially increasing the risk of humans deciding to go to war.</p><p><strong>Militaries are using AI in sophisticated deception operations.</strong> First, as militaries integrate AI into their (conventional, not nuclear) battle plans, they are realizing they must also learn how to defeat opponents through new means of trickery. Recent PLA wargames have focused on how to &#8220;break intelligence,&#8221; preparing for battles in which AIs &#8220;<a href="https://www.defenseone.com/threats/2025/11/chinas-emerging-counter-ai-warfare-playbook/409757/?oref=d1-author-river">work to distort each others&#8217; reality</a>.&#8221;</p><p><strong>AI is being used for political deception. </strong>Second, AI is being used to dramatically scale up political disinformation campaigns. Conflicts in Ukraine, Gaza, and Iran have expanded to include what can be thought of as &#8220;<a href="https://www.foreignaffairs.com/middle-east/gaza-and-future-information-warfare">LikeWar</a>&#8221; battles to drive false information viral. Such campaigns involve automating information operations and creating high-fidelity deepfakes&#8212;tools that have already been used to successfully mislead heads of state, including those leading nuclear powers. US and Pakistani leaders have reacted to and pushed AI-generated imagery online. Studies on the present and <a href="https://www.newamerica.org/insights/the-future-of-deception-in-war/">future</a> of deception operations suggest that this phenomenon will grow in scale and impact.</p><p><strong>AI systems are vulnerable to errors, particularly in military contexts.</strong> The most dangerous and powerful kind of deception, however, is self-deception, which we can think of in both machine and human terms. AI undoubtedly brings incredible insights in various domains, often drawing on beyond-human analytical capabilities. Still, no matter how far the technology advances, these systems are plagued by issues that range from hallucination to algorithmic bias. Such problems, caused in part by training data that can never fully represent the real world, are especially salient in war. The civilian LLMs being brought into military systems are largely trained on the open internet&#8212;an objectively poor environment for high-stakes accuracy. Using military training data cannot solve the issue, since no two wars are the same. Datasets pulled from counterinsurgency operations in Iraq and Afghanistan, for instance, provide poor parallels for the conflicts of today and tomorrow.</p><p><strong>A lack of understanding about AI could lead humans to make poor decisions.</strong> Yet, when it comes to miscalculation, the greater risk may lie with overly confident humans. History shows that the most dangerous phases of arms races are the earliest stages, when neither military nor political leaders yet fully understand the new weapons, and they make poor decisions based on erroneous assumptions. Before World War I, for example, the belief that new technologies like the railroad and fast-firing artillery gave a decisive advantage to the offense helped <a href="https://rochelleterman.com/ir/sites/default/files/van%20evera%201984_0.pdf">drive</a> the quick march to war after the assassination of Archduke Ferdinand in Sarajevo. It turned out that these technologies in fact advantaged the defense, leading to four years of horrific stalemate in the trenches. A similar belief <a href="https://www.rand.org/pubs/research_reports/RRA4316-1.html">permeates</a> discourse today&#8212;that AI rewards the side that strikes first (the offense) in every conventional war domain, from air strikes to cyberattacks.</p><p><strong>It is more difficult to estimate opponents&#8217; capabilities in AI than in other technologies.</strong> This risk is compounded by the challenges of understanding both one&#8217;s own capabilities and the enemy&#8217;s. Estimating power in the AI era is even more difficult than with traditional, kinetic weapons. Ships, tanks, planes, and even nuclear weapons can be counted, their physics understood, and their capabilities summed and compared. However, beyond estimating rivals&#8217; data center capacity, understanding AI capabilities is far more difficult. Whether models can be accurately benchmarked is heavily contested. Even if accurate benchmarking were possible, how that would translate to battlefield performance would remain unknowable by humans or machines.</p><p>What we do know is that arms races traditionally incentivize exaggeration and fearmongering. Examples from the Cold War are the 1950s &#8220;bomber gap,&#8221; followed by the &#8220;missile gap&#8221;&#8212;Americans&#8217; beliefs that the Soviet Union had achieved significant advantages in each technology. Both &#8220;gaps&#8221; turned out to be mythical, but they nonetheless contributed to the Cuban Missile Crisis. Similarly, both the George W. Bush administration and Iraq&#8217;s then-president, Saddam Hussein, issued claims about weapons of mass destruction that turned out to be nonexistent.</p><p><strong>The outcome of direct interactions between opposing military AIs is unpredictable.</strong> Finally, the effects of interactions between AIs themselves create an informational void within military doctrine. In the past, adversaries generally understood one another&#8217;s concepts of fighting; with that awareness, they could deploy wargames and analyze recent conflicts to project outcomes. Because no nation will tip its hand regarding its true AI capabilities, and because military use of AI is relatively novel, the first time AI systems collide directly will likely be in a live, high-stakes environment where miscalculation is almost certain.</p><h2>The Velocity of Catastrophe: Machine Speed</h2><p>The third and final way in which AI is increasing the risk of war is through machine-speed operations. Yet, this is not about an AI making instantaneous decisions on nuclear strikes. Rather, it is about how AI is enabling a new generation of weapons that complicate humans&#8217; nuclear decision-making.</p><p><strong>AI is enabling weapons that compress the time window for humans to respond.</strong> The most notable examples of this phenomenon are boost-glide hypersonic weapons, including Russia&#8217;s Avangard, China&#8217;s DF 27, and America&#8217;s Dark Eagle. Despite their name, these delivery systems do not fly substantially faster than intercontinental ballistic missiles. What distinguishes them is that they use AI-enabled technologies, including adaptive control adjustments and cognitive and quantum inertial navigation systems, to make microsecond decisions and adjustments, while moving at thousands of miles per hour through denied airspace. By maneuvering around sensors and defenses, boost-glide weapons get much closer to their target before they are detected, allowing less time for humans to decide how to respond.</p><p>This &#8220;decision-time compression&#8221; represents the core of such weapons&#8217; risk. Traditionally, Nuclear Command, Control, and Communications architectures provided a &#8220;decision window&#8221; of roughly <a href="https://spacenews.com/hybridizing-nuclear-command-control-and-communications-systems-puts-space-infrastructure-at-risk/">15&#8211;30 minutes</a> to verify an incoming strike and weigh a response. To put this into context, the seemingly rushed time frame of &#8220;A House of Dynamite&#8221; spanned <a href="https://www.netflix.com/tudum/articles/a-house-of-dynamite-ending-explained">18 minutes</a> of deliberation, depicted by a 112-minute movie. A hypersonic weapon reduces the number of minutes for decision-making to single digits.</p><p><strong>Shorter time windows often worsen human decision-making.</strong> The psychological reality is that humans make decisions poorly under stress and in short time frames, so anything that shrinks this window raises the likelihood of bad outcomes, such as a &#8220;<a href="https://warontherocks.com/ai-autonomy-and-the-risk-of-nuclear-war/">Flash War</a>.&#8221; There is a documented tendency for leaders to &#8220;lock in&#8221; on the first early concepts that enter the room&#8212;ideas that, in a more traditional crisis, might be aired out and debunked through hours of give and take. Historical experience confirms this; many of the most dangerous options considered by the US during the Cuban Missile Crisis were proposed during those frantic early days and then fortunately cast aside. AI-enabled weapons would not allow time for the same level of scrutiny.</p><h2>Conclusions and Policy Recommendations</h2><p>The notion that AI could start a nuclear war may be attention-grabbing. Yet research, grantmaking, and policy should be anchored in what is realistic rather than allowing the most dramatic narratives to steer the discourse disproportionately. The goal should be to understand and implement safeguards that tackle actual and likely risks, such as those posed by arms racing, misperceptions, and decision-making as described above.</p><p>Instead of pursuing purely symbolic measures to keep AI from nuclear weapons, we should prioritize reducing the incentives for and externalities of arms races, for example by finding ways to improve the defensive side of the equation. There may also be ways to reduce the likelihood of misperception, including through a concerted effort to enhance the education of political and military leaders about AI&#8217;s realities.</p><p>Finally, if we are to pursue effective arms control, our primary focus should not be on the speculative fear of AI launching a nuclear strike but, instead, on the real and growing number of physical platforms that shrink human decision-makers&#8217; window for deliberation. For instance, prioritizing the regulation of hypersonic delivery systems&#8212;an existing technology that heightens the risk of nuclear catastrophe&#8212;is a more viable path toward strategic stability than chasing science fiction.</p><p>&#8205;</p><div><hr></div><p><em><strong>See things differently? </strong>AI Frontiers welcomes expert insights, thoughtful critiques, and fresh perspectives. <a href="https://ai-frontiers.org/publish?utm_source=aif_article">Send us your pitch.</a></em></p><div><hr></div><p><em>Peter Warren Singer is a Founder &amp; Managing Partner at Useful Fiction LLC, a company specializing in strategic narrative, Strategist at New America, and a Professor of Practice at Arizona State University. A New York Times Bestselling author, described in the Wall Street Journal as &#8220;the premier futurist in the national-security environment&#8221; and &#8220;all-around smart guy&#8221; in the Washington Post, he has been named by the Smithsonian as one of the nation&#8217;s 100 leading innovators, by Defense News as one of the 100 most influential people in defense issues, by Foreign Policy to their Top 100 Global Thinkers List, and as an official &#8220;Mad Scientist&#8221; for the U.S. Army&#8217;s Training and Doctrine Command. No author, living or dead, has more books on the professional US military reading lists.</em></p>]]></content:encoded></item><item><title><![CDATA[Opt-In Surveillance Is Approaching]]></title><description><![CDATA[AIs with access to all our data will soon be able to vouch for us to others. As people come to trust AI judgments of character, not sharing one will look suspicious.]]></description><link>https://newsletter.ai-frontiers.org/p/opt-in-surveillance-is-approaching</link><guid isPermaLink="false">https://newsletter.ai-frontiers.org/p/opt-in-surveillance-is-approaching</guid><dc:creator><![CDATA[AI Frontiers]]></dc:creator><pubDate>Wed, 03 Jun 2026 17:30:22 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!B_4r!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F407ef94d-504e-4a32-9916-bf6fcfab1ff3_1500x844.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong><a href="https://ai-frontiers.org/author/steven-veld">Steven Veld</a></strong> &#8212; June 3, 2026</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!B_4r!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F407ef94d-504e-4a32-9916-bf6fcfab1ff3_1500x844.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!B_4r!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F407ef94d-504e-4a32-9916-bf6fcfab1ff3_1500x844.jpeg 424w, https://substackcdn.com/image/fetch/$s_!B_4r!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F407ef94d-504e-4a32-9916-bf6fcfab1ff3_1500x844.jpeg 848w, https://substackcdn.com/image/fetch/$s_!B_4r!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F407ef94d-504e-4a32-9916-bf6fcfab1ff3_1500x844.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!B_4r!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F407ef94d-504e-4a32-9916-bf6fcfab1ff3_1500x844.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!B_4r!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F407ef94d-504e-4a32-9916-bf6fcfab1ff3_1500x844.jpeg" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/407ef94d-504e-4a32-9916-bf6fcfab1ff3_1500x844.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!B_4r!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F407ef94d-504e-4a32-9916-bf6fcfab1ff3_1500x844.jpeg 424w, https://substackcdn.com/image/fetch/$s_!B_4r!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F407ef94d-504e-4a32-9916-bf6fcfab1ff3_1500x844.jpeg 848w, https://substackcdn.com/image/fetch/$s_!B_4r!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F407ef94d-504e-4a32-9916-bf6fcfab1ff3_1500x844.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!B_4r!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F407ef94d-504e-4a32-9916-bf6fcfab1ff3_1500x844.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>In 2017, Western media outlets <a href="https://www.wired.com/story/age-of-social-credit/">warned</a> that &#8220;Black Mirror is coming true in China.&#8221; The following year, Mike Pence <a href="https://trumpwhitehouse.archives.gov/briefings-statements/remarks-vice-president-pence-administrations-policy-toward-china/#:~:text=And%20by%202020%2C%20China%E2%80%99s%20rulers%20aim%20to%20implement%20an%20Orwellian%20system%20premised%20on%20controlling%20virtually%20every%20facet%20of%20human%20life%20%E2%80%94%20the%20so%2Dcalled%20%E2%80%9CSocial%20Credit%20Score.%E2%80%9D">claimed</a> that &#8220;China&#8217;s rulers aim to implement an Orwellian system premised on controlling virtually every facet of human life&#8212;the so-called &#8216;Social Credit Score.&#8217;&#8221; So far, the CCP&#8217;s attempts at nationalized social scoring have remained fragmented and crude, largely due to difficulties in analyzing population-scale data. However, AI could soon lift that bottleneck, independently sifting through information and pulling out the most important details about every individual.</p><p>This unsettling prospect might renew fears about top-down social scoring by governments. However, an equally pressing concern is the potential for a bottom-up system, in which citizens choose to be surveilled and scored by AIs. As people integrate AIs into their lives to get more useful assistance with daily tasks, those AIs may soon be able to generate credible character assessments at the touch of a button. Early users who receive positive AI assessments may choose to share them with colleagues, businesses, bureaucrats, and so forth, in order to receive more favorable treatment. This dynamic would create an incentive for everyone else to follow suit.</p><p>This essay will explore why people will give AI assistants pervasive access to their lives and how this could soon translate into a form of social scoring. We&#8217;ll then map out how pressures to opt in will grow organically across every domain of life, creating a slippery slope toward self-imposed surveillance.</p><h2>The Pressures Driving Self-Imposed Surveillance</h2><p>The thought of sharing an AI judgment based on extensive personal data may sound too uncomfortable to believe that people would opt in. However, people already frequently give up their personal data to obtain benefits. In the US, <a href="https://www.carriermanagement.com/features/2026/02/11/284454.htm">over 21 million drivers</a> voluntarily share driving data with insurers like Progressive and State Farm in exchange for discounts of up to 40%. Meanwhile, in China, voluntary disclosures have surged even as the country failed to implement a top-down, nationalized social credit system. In 2015, a private company called Ant Group launched Zhima Credit&#8212;an opt-in service that gives users social scores, and grants high-scoring users advantages from priority loan approval to dating site access. The platform claims to have more than 700 million authenticated users.</p><p><strong>People are already sharing large amounts of personal data with AI for practical reasons.</strong> Some LLM power users are rushing to share their personal information with LLMs, connecting their agents to online accounts, medical records, and even <a href="https://openai.com/index/personal-finance-chatgpt/">bank information</a> in hopes of obtaining more informed and <a href="https://blog.google/innovation-and-ai/products/gemini-app/next-evolution-gemini-app/">wide-reaching assistance</a>. Indeed, there are already <a href="https://www.wsj.com/tech/personal-tech/ai-personal-assistant-wearable-tech-impressions-28156b57">wearable AI devices</a> that can constantly record users&#8217; lives, offering summaries of each day and making personalized plans for the next. From managing schedules to preserving an infallible, easily searchable memory of every conversation, AI agents are proving to be useful personal assistants in people&#8217;s busy lives. Adoption has already begun, and it is likely to expand.</p><p><strong>Future AI assistants could provide attestations about their users.</strong> While people will initially share their personal data with AIs to get practical assistance, more capable future AIs could use this information for more than just helping with day-to-day tasks; given enough access, they could offer character references attesting that their users are reliable at work, committed as friends and partners, and honest in their financial and legal dealings. Once a user has granted their AI assistant wide-ranging access to their life, generating an assessment may be as simple as clicking a button.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!JuqQ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1a1785d-966a-4c47-9db6-adabd61fb797_923x942.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!JuqQ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1a1785d-966a-4c47-9db6-adabd61fb797_923x942.png 424w, https://substackcdn.com/image/fetch/$s_!JuqQ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1a1785d-966a-4c47-9db6-adabd61fb797_923x942.png 848w, https://substackcdn.com/image/fetch/$s_!JuqQ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1a1785d-966a-4c47-9db6-adabd61fb797_923x942.png 1272w, https://substackcdn.com/image/fetch/$s_!JuqQ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1a1785d-966a-4c47-9db6-adabd61fb797_923x942.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!JuqQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1a1785d-966a-4c47-9db6-adabd61fb797_923x942.png" width="350" height="357.204767063922" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a1a1785d-966a-4c47-9db6-adabd61fb797_923x942.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:942,&quot;width&quot;:923,&quot;resizeWidth&quot;:350,&quot;bytes&quot;:110228,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!JuqQ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1a1785d-966a-4c47-9db6-adabd61fb797_923x942.png 424w, https://substackcdn.com/image/fetch/$s_!JuqQ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1a1785d-966a-4c47-9db6-adabd61fb797_923x942.png 848w, https://substackcdn.com/image/fetch/$s_!JuqQ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1a1785d-966a-4c47-9db6-adabd61fb797_923x942.png 1272w, https://substackcdn.com/image/fetch/$s_!JuqQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1a1785d-966a-4c47-9db6-adabd61fb797_923x942.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption"><em>Opt-in surveillance may proceed in stages. Disclosing AI attestations could begin as a completely voluntary activity that a few people use, but end up as an entrenched norm that people are strongly pressured to follow.</em></figcaption></figure></div><p><strong>After initial adoption, everyone else is under pressure to follow. </strong>Once early adopters disclose, others are likely to follow. This is due to an effect known as &#8220;unraveling,&#8221; which was described in <a href="https://www.jstor.org/stable/pdf/725273?casa_token=NZ0bipL-DJAAAAAA:AZ-pw0mPbI9fSgrwFxYkoAML8ZB-livrvJgEnrxk-xlshYME23IGXRosnGMM7NWTIqoOETcu5dBmH2ooQaMKuKhBCWBRcjGmmd7Ztu5wPx2OVItVYfZVaA">two</a> <a href="https://www.jstor.org/stable/pdf/3003562.pdf?casa_token=8TeZWbMVA_sAAAAA:5LLzyWmRT5DR_bIFegaRW__Lnr2IEB3oDdluI7yTJ9CH8y0j-DCL1Fxr_IQpF8FTmNIFvSQ_CNvSwTp70XG_jbemoFzxpDsEJLWOK_bjzrWa_xLsMp-nbQ">papers</a> published by economists Sanford Grossman and Paul Milgrom in 1981. The logic is straightforward: those with the best track records have every reason to share them, since doing so distinguishes them from the crowd. Once the best disclose, everyone else looks worse by comparison, so the next-best tier discloses too. This cascade continues until nearly everyone has disclosed and silence itself becomes a red flag.</p><p><strong>The transition to self-imposed surveillance could start small.</strong> While most people would balk at the end result of AI social scoring, it could nonetheless creep in gradually. The first use cases for AI attestation will be narrow and low-stakes: companies might let contractors attest to claims about previous projects, or dating apps might let users verify that their self-descriptions are accurate. Companies offering AI-based assessments might be widely disliked or little-used at first, but this would not necessarily block early adopters from opting in. FICO scores illustrate where this dynamic ultimately leads: no law requires you to have one, but opting out means losing access to housing, credit, and employment.</p><h2>The Evolution of Self-Imposed Surveillance</h2><p>Given the logic of unraveling, one might wonder why we don&#8217;t have complete self-surveillance and social scoring already. This can be explained by real-world frictions that make disclosure more difficult and less rewarding than it would be in theory. AI may soon remove these frictions, enabling unraveling not just in narrow domains such as driving and personal finance, but across every sphere of life.</p><p><strong>We do not see full disclosure yet because there are frictions that block unraveling.</strong> Today, meaningful attestation often costs real effort, from assembling a job application to sharing references. This creates enough friction that a lack of full disclosure does not necessarily look suspicious.</p><p>Additionally, attestations are not always credible: landlords can overstate the quality of a rental, job applicants can embellish their qualifications, and there is often no practical way to check. This reduces the value of disclosure, since it does not reliably distinguish those with the best credentials from everyone else. Indeed, the domains where we already see unraveling are the narrow areas in which disclosure is both costless and credible. A FICO score captures financial behavior, and a telematics device captures driving behavior&#8212;information that is cheap to measure and difficult to fake.</p><p>Previous technological revolutions, such as the internet, sparked concerns about surveillance and social scoring. The rise of digital banking, health apps, online calendars, and social media means that large amounts of sensitive personal data is stored online. Yet we have not seen waves of disclosure across every area of life. This is because the internet does not in fact make disclosure costless and credible across all domains. On cost, analyzing vast sums of internet information to draw out valuable insights about every individual is still an intractable technological challenge. On credibility, the public internet is still a far cry from comprehensive, real-time surveillance of behavior. People can curate what they upload online, and this reduces trust that it is representative.</p><p><strong>AI may make costless, credible disclosure dramatically easier.</strong> AI products like ChatGPT already store usage data that can speak to their users&#8217; work competence, behavioral tendencies, and personal preferences. It could be very cheap and convenient to share such a profile (or a redacted summary generated by a trusted third party) with an employer or landlord.</p><p>Credible disclosure requires two things: comprehensive coverage of someone&#8217;s behavior, and the ability to draw accurate conclusions from that behavior. AI is making rapid progress on both fronts, particularly on coverage: heavy users already spend dozens of hours per week interacting with AI chatbots, and that coverage will only grow as companies roll out <a href="https://blog.google/innovation-and-ai/products/gemini-app/personal-intelligence/">features</a> to further personalize and integrate AI into daily life. Multimodal, always-on hardware like smart glasses and earbuds could grant AI assistants constant audio or visual access, and produce attestations far more credible than anything text-based interaction can support.</p><p><strong>Societal pressures could make people accept comprehensive self-surveillance. </strong>Even as comprehensive surveillance becomes technologically feasible, people might feel uncomfortable about allowing their AI assistants to provide character assessments to others. Sharing driving data is one thing; sharing a judgment drawn from every detail of how one spends one&#8217;s day, from drinking habits to private political conversations, is quite another. Yet there are reasons to believe that resistance might yield surprisingly quickly.</p><p><strong>Those who allow greater access will receive more credible attestations.</strong> Initially, users may try to game the system by granting AIs only selective access: interacting when they&#8217;re being productive and setting the AI aside when they&#8217;re not, or filtering access that may paint them in a bad light. For one thing, this would be a difficult strategy to sustain as AI assistants become increasingly useful and perceptive. Additionally, evaluators will lend more weight to attestations drawn from more comprehensive data, increasing the pressure to provide near-total access to AI assistants.</p><p><strong>The pressure for AI attestations may extend to personal domains such as dating.</strong> Many people already consult AI agents for dating advice. If people come to view AIs as trusted judges of character, they may start requesting attestations from potential partners before agreeing to a date. Those who refuse would face a narrower pool of willing partners, extending the unraveling dynamic into intimate life.</p><h2>Surveillance at the Civilizational Level</h2><p>At this point, one might hope that data protection or anti-discrimination laws could prevent omnipresent observation. However, this is the insidiousness of self-surveillance; privacy legislation can help to prevent non-consensual surveillance by governments or businesses, but it cannot stop individuals from opting in to disclosure themselves. Unraveling can therefore happen anywhere.</p><p><strong>Self-imposed surveillance can creep in under various political conditions. </strong>Different political systems will arrive at the same destination through different mechanisms: in the US and EU, the private sector will provide the infrastructure for surveillance. In China, the story is different: the government sidelined Zhima Credit because it wanted to control the infrastructure itself, evidence that surveillance in China may continue to trend toward <a href="https://www.cnn.com/2025/12/04/china/china-ai-censorship-surveillance-report-intl-hnk">mandatory top-down surveillance</a>. The result may be the same: pervasive monitoring.</p><h2>Conclusion</h2><p><strong>The future may involve substantially less privacy than the present. </strong>Throughout most of human history, privacy as we know it did not exist; our ancestors lived in small bands where reputation was built through direct mutual observation and gossip served as the original social credit system. The high-privacy society we inhabit today is a side effect of urbanization and the limited reach of pre-digital technology. As AI systems close that gap, we may be returning to the historical default. Societies tend to adopt values compatible with their technological constraints: the concept of intellectual property was meaningless before the printing press, and privacy may prove similarly contingent. Whether we accept this transition or resist it is an open question, but the forces driving it are already in motion.</p><p><strong>While the direction of this trend seems robust, the form it takes is not predetermined. </strong>The question of who controls the AI attestation infrastructure matters enormously for how power is concentrated in the future: a world where attestation is managed by a handful of AI companies looks very different from one where it is controlled by governments, and different again from one built on decentralized protocols. Similarly, whether norms develop around narrow, domain-specific attestation or comprehensive behavioral transparency will determine how much power the system concentrates and in whose hands. These are important path dependencies, and the decisions shaping them are being made now.</p><p><em>Thanks to Dan Hendrycks and Devin Kim for formulating the premise of this piece.</em></p><p>&#8205;</p><div><hr></div><p><em><strong>See things differently? </strong>AI Frontiers welcomes expert insights, thoughtful critiques, and fresh perspectives. <a href="https://ai-frontiers.org/publish?utm_source=aif_article">Send us your pitch.</a></em></p><div><hr></div><p><em>Steven Veld is an AI strategy and governance researcher, with a particular focus on scenario-based forecasting for multipolar AI futures. He was a 2025 policy fellow with the Institute for AI Policy and Strategy (IAPS), where he worked on Congressional engagement with the AI Policy Network. Before that, he was a ML Alignment and Theory Scholars (MATS) fellow with the AI Futures Project. He has a BS in Computer Science at UCLA, and has prior experience working on biosecurity and compute governance.</em></p>]]></content:encoded></item></channel></rss>