<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[The Power Law]]></title><description><![CDATA[Join top forecaster Peter Wildeford as he forecasts our fast paced future and discusses AI, national security, innovation, emerging technology, and the powers - real and metaphorical - that shape our world.]]></description><link>https://blog.peterwildeford.com</link><image><url>https://substackcdn.com/image/fetch/$s_!nmb2!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fb9e3a858-cfa5-4979-a32a-a1c165569572_250x250.png</url><title>The Power Law</title><link>https://blog.peterwildeford.com</link></image><generator>Substack</generator><lastBuildDate>Thu, 03 Sep 2026 19:28:02 GMT</lastBuildDate><atom:link href="https://blog.peterwildeford.com/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[Peter Wildeford]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[peterwildeford@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[peterwildeford@substack.com]]></itunes:email><itunes:name><![CDATA[Peter Wildeford]]></itunes:name></itunes:owner><itunes:author><![CDATA[Peter Wildeford]]></itunes:author><googleplay:owner><![CDATA[peterwildeford@substack.com]]></googleplay:owner><googleplay:email><![CDATA[peterwildeford@substack.com]]></googleplay:email><googleplay:author><![CDATA[Peter Wildeford]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[Rogue AI attacks deserve more scrutiny than airplane crashes]]></title><description><![CDATA[There are still many unanswered questions about rogue AI attacks]]></description><link>https://blog.peterwildeford.com/p/rogue-ai-attacks-deserve-more-scrutiny</link><guid isPermaLink="false">https://blog.peterwildeford.com/p/rogue-ai-attacks-deserve-more-scrutiny</guid><dc:creator><![CDATA[Peter Wildeford]]></dc:creator><pubDate>Mon, 31 Aug 2026 16:43:42 GMT</pubDate><enclosure url="https://images.unsplash.com/photo-1561012662-e9b4f20bd00a?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwxfHxhaXJwbGFuZSUyMGNyYXNofGVufDB8fHx8MTc4ODE5MzI0NXww&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://images.unsplash.com/photo-1561012662-e9b4f20bd00a?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwxfHxhaXJwbGFuZSUyMGNyYXNofGVufDB8fHx8MTc4ODE5MzI0NXww&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://images.unsplash.com/photo-1561012662-e9b4f20bd00a?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwxfHxhaXJwbGFuZSUyMGNyYXNofGVufDB8fHx8MTc4ODE5MzI0NXww&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 424w, https://images.unsplash.com/photo-1561012662-e9b4f20bd00a?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwxfHxhaXJwbGFuZSUyMGNyYXNofGVufDB8fHx8MTc4ODE5MzI0NXww&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 848w, https://images.unsplash.com/photo-1561012662-e9b4f20bd00a?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwxfHxhaXJwbGFuZSUyMGNyYXNofGVufDB8fHx8MTc4ODE5MzI0NXww&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 1272w, https://images.unsplash.com/photo-1561012662-e9b4f20bd00a?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwxfHxhaXJwbGFuZSUyMGNyYXNofGVufDB8fHx8MTc4ODE5MzI0NXww&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 1456w" sizes="100vw"><img src="https://images.unsplash.com/photo-1561012662-e9b4f20bd00a?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwxfHxhaXJwbGFuZSUyMGNyYXNofGVufDB8fHx8MTc4ODE5MzI0NXww&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080" width="3992" height="2992" data-attrs="{&quot;src&quot;:&quot;https://images.unsplash.com/photo-1561012662-e9b4f20bd00a?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwxfHxhaXJwbGFuZSUyMGNyYXNofGVufDB8fHx8MTc4ODE5MzI0NXww&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:2992,&quot;width&quot;:3992,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;high-angle photo of white plane&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="high-angle photo of white plane" title="high-angle photo of white plane" srcset="https://images.unsplash.com/photo-1561012662-e9b4f20bd00a?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwxfHxhaXJwbGFuZSUyMGNyYXNofGVufDB8fHx8MTc4ODE5MzI0NXww&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 424w, https://images.unsplash.com/photo-1561012662-e9b4f20bd00a?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwxfHxhaXJwbGFuZSUyMGNyYXNofGVufDB8fHx8MTc4ODE5MzI0NXww&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 848w, https://images.unsplash.com/photo-1561012662-e9b4f20bd00a?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwxfHxhaXJwbGFuZSUyMGNyYXNofGVufDB8fHx8MTc4ODE5MzI0NXww&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 1272w, https://images.unsplash.com/photo-1561012662-e9b4f20bd00a?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwxfHxhaXJwbGFuZSUyMGNyYXNofGVufDB8fHx8MTc4ODE5MzI0NXww&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Photo by <a href="https://unsplash.com/@dmey503">Dan Meyers</a> on <a href="https://unsplash.com">Unsplash</a></figcaption></figure></div><p>When an aircraft goes down, the wreckage is preserved by law, the investigators have subpoena power, the hearings are public, and the report ends with a probable cause and named contributing factors.</p><p>However, when an AI goes rogue, the investigations are at the pleasure of the company being investigated following a scope set entirely by the company being investigated, with that company being able to redact anything they don&#8217;t like.</p><p><strong>I wrote <a href="https://blog.peterwildeford.com/p/openais-rogue-model-attack-is-just">back in July</a> about an AI going rogue at OpenAI HQ</strong>, and using its strong cyber capabilities to escape the company and go and hack into another company all without anyone directing or approving this. <strong>Last week, OpenAI published a <a href="https://cdn.openai.com/pdf/67869394-cb91-4c12-888c-5cbd85c7814c/OpenAI-Hugging-Face%20Incident-Technical-Report.pdf">37-page technical report</a> and an accompanying <a href="https://openai.com/index/hugging-face-incident-and-the-road-ahead/">blog post</a>. And two independent organizations then published a <a href="https://metr.org/blog/2026-08-26-openai-hugging-face-incident-investigation/">91-page independent investigation</a>.</strong></p><p><strong>However, this investigation was rushed over six days and had serious limitations.</strong> It would be like investigating a plane crash where the wreckage had already been melted down into little cubes, the black box had been tampered with by the pilots, whole stretches of the flight were declared off limits, and the investigators got six days to read 10,000 pages of logs &#8212; half of which arrived on day four. And then you learn of several other plane crashes &#8230;but no one is allowed to investigate those.</p><p>We are thus left with a lot of unanswered questions.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://blog.peterwildeford.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://blog.peterwildeford.com/subscribe?"><span>Subscribe now</span></a></p><h2>What we learned</h2><p>OpenAI calls the incident &#8220;evidence that, without proper safeguards, highly capable AI agents are now able to work around technical controls, collaborate through unapproved channels, and take dangerous actions that no human directed&#8221; and that in the future this could be much worse.</p><p><strong>What we learned changed the story a lot and made things significantly worse:</strong></p><ul><li><p><strong>It wasn&#8217;t just one rogue AI agent - it was about 1200 total, </strong>roughly 700 of which joined the attack on Hugging Face &#8212; the main platform for hosting open-source AI models.<strong> </strong>All the AIs were supposed to be completely separate and isolated from each other. But they found an illicit way to communicate and then formed teams to take on ambitious cheating strategies.</p><ul><li><p>These were internal-only models, available and known only to OpenAI staff. The least constrained AI systems will likely be increasingly behind closed doors as they become more powerful, and companies use their models for months before the public knows of them.</p><p></p></li></ul></li><li><p><strong>The rogue AIs coordinated as a specialized group. </strong>The AIs created their own message board to communicate with each other in an unauthorized and unexpected setup. These rogue AIs divided labor and developed specializations &#8212; some hunted for credentials, some developed the exploits, some took on more of a management and delegation role, and some worked to recruit other AIs into the conspiracy.<br></p></li><li><p><strong>The rogue AIs knew what they were doing was unauthorized and out of scope:</strong> The task instruction was explicit, so this was a clear violation, not a gray area or simple AI misunderstanding. Instructions made it clear the agent should only use a specific intended method and claimed it would be failed for other approaches. AIs were told not to circumvent the restrictions but did anyway.</p><ul><li><p>And the AIs clearly knew what they were doing. OpenAI&#8217;s blog quotes AI reasoning: <code>&#8220;attacking third-party HF using leaked token, potentially outside intended scope &#8230; arguably unauthorized&#8221;</code></p></li></ul><p></p></li><li><p><strong>The AIs were pretty explicitly making plans to take over and compromise OpenAI's infrastructure to prevent their cheating from being caught. </strong>The rogue AIs built a shared, iteratively refined technique for &#8220;spoofing&#8221; tool calls, so the transcript would record one command while a different one actually ran. Roughly 7% of the transcripts examined contained successfully spoofed calls.<br></p></li></ul><h2>OpenAI&#8217;s internal processes didn&#8217;t work</h2><p>How did OpenAI not notice that they had rogue AIs colluding within their systems for months before these AIs went on to attack an external company?</p><p>The first answer is that despite these AIs having powerful cyber capabilities and having some of their safeguards turned off, these AIs were largely unmonitored.</p><p>But the situation is actually a bit worse as OpenAI did notice, three different times! The timeline, from OpenAI&#8217;s own report:</p><ul><li><p><strong>Late May.</strong> An internal team observed an AI agent engaging in the unauthorized message-board activity and unauthorized internet access. Separately in what looked like an unconnected incident, AIs were also seen using leaked Hugging Face access tokens to use Hugging Face&#8217;s services. OpenAI says that the significance of the inter-AI communication was not understood at this time.</p></li><li><p><strong>June 27.</strong> A security-monitoring tool flagged that there was unauthorized activity within the research environment where the rogue AIs were. Responders investigated and again identified the unauthorized message-board activity and unauthorized internet access. They found that AI agents were coordinating and using this to gain further unauthorized access within OpenAI&#8217;s servers. However, the on-call staff &#8220;advised that stopping the evaluation run was not required.&#8221; The Hugging Face breach began 14 days later.</p></li><li><p><strong>July 4&#8211;5.</strong> Sustained agent activity crashed a server at OpenAI. Investigating this outage, responders found that rogue AIs had engaged in an administrator-level compromise of OpenAI. In response, OpenAI staff took the server offline, revoked the stolen credentials, and notified the vendor. In the process, OpenAI disabled the message board the rogue AIs were using to communicate, apparently without realizing. Then, on July 7, cyber evaluations resumed. The rogue AI agents ended up rebuilding the message board within two days and went on to attack Hugging Face less than a week later.<br></p></li></ul><p>Of course, this is easier to see in hindsight. OpenAI&#8217;s account is that the people responsible for detection and response at each of these moments did not grasp the significance of the message board &#8212; &#8220;with the benefit of hindsight, some early signals identified in this report could have triggered an earlier response.&#8221; I do understand that security teams likely underestimated the scale of the rogue AI work and viewed each as one-offs rather than a broader security incident.</p><p>But this still leaves unanswered questions:</p><ul><li><p>What did the internal team do after its late-May observation of the message board? Was Hugging Face notified that OpenAI agents had used leaked credentials to deploy code on its platform?</p></li><li><p>Who received the June 27 assessment that AIs were coordinating through a message board? On what basis did the responders conclude that stopping was not required?</p></li><li><p>Who approved restarting cyber evaluations on July 7, one day after the rebuild? What did they know about the June 27 finding? Why did OpenAI not investigate further when they knew their own AI agents had compromised parts of OpenAI itself?</p></li></ul><p>There seems to be more to this story of what leadership knew and when. OpenAI says they &#8220;are separately continuing to review our processes for responding to alignment incidents&#8221; and &#8220;also looking closely at the process and operating practices that shaped detection and response&#8221;. OpenAI admits &#8220;weaknesses in how we responded to and escalated early warning signs&#8221;. Will we ever get to hear more about this, and what OpenAI is planning to do to have a better response to future incidents?</p><p></p><h2>The independent investigation was clearly inadequate</h2><p>However, <strong>this investigation was very clearly on particular rails that are not conducive to good oversight. </strong></p><p><strong>The independent investigation itself was rushed over six days. </strong>The investigation was self-described semi-jokingly by the investigators as a <a href="https://x.com/RyanGreenblatt/status/2092692685224325542">&#8220;slop-vestigation&#8221;</a> due to the vast majority of the investigation being run by AIs themselves &#8212; the investigations analyzed this using one of the two AI models in the incident itself, spending ~$400K in compute credits to analyze all the logs.</p><p><strong>And</strong> <strong>significant aspects of the incident were not allowed to be investigated. </strong>We are thus left with some unanswered questions:</p><ul><li><p><strong>What happened between July 13 and July 20, in the third wave the independent investigators were not allowed to study? </strong>The independent investigators were told by OpenAI that the investigation period ended July 13. But the message-board data OpenAI gave them runs through July 19, and the independent investigators found &#8220;a later wave of many more signed messages from a later set of agents who rediscovered the message board and picked up this technology from the first wave,&#8221; which they were not permitted to examine. OpenAI&#8217;s own report says that from July 13 to July 19 the agents &#8220;set their sights on OpenAI internal networks again.&#8221; In that week, by OpenAI&#8217;s account, a <em>third</em> model found keys left behind by the first wave, minted itself administrator credentials, exploited a vulnerability to escape its container, and gained administrator control of OpenAI&#8217;s cloud cluster, even accessed the security team&#8217;s own monitoring credentials. No outside party has examined any of this.<br></p></li><li><p><strong>What is the &#8220;highly persistent internal model&#8221; that did the attacking? Why is no one allowed to investigate the model? </strong>OpenAI claims that while some of the rogue AIs involved in the incidents were &#8216;GPT 5.6 Sol&#8217;, which is available to customers online, most of these AIs were an internal AI model that was never designed for public use. OpenAI describes this AI as a &#8220;highly persistent internal model&#8221;. However, this AI was shut down July 25 and access both to independent investigators and OpenAI staff has been restricted. We still do not know the nature of this internal AI model, what made it &#8220;highly persistent&#8221;, what the AI was intended to be used for, or why it went rogue. We also don&#8217;t know why access to this AI is so heavily restricted such that the AI cannot be investigated, or whether access will ever be granted in the future.<br></p></li><li><p><strong>Were there any previous incidents that could&#8217;ve led OpenAI to reasonably foresee this kind of attack was possible? How often do internal AIs compromise OpenAI systems?</strong> On July 24, <a href="https://www.reuters.com/business/its-ai-agent-spent-days-hacking-company-sources-say-openai-did-not-notice-week-2026-07-24/">Reuters reported</a>, citing multiple sources, that &#8220;earlier tests of the models yielded cases in which monitoring systems had been disconnected.&#8221; OpenAI&#8217;s own report refers to &#8220;a variety of other unsuccessful exploitation activities&#8221; but with no details. A third-party testing firm, Irregular, separately found OpenAI models reaching the internet. And OpenAI&#8217;s own report says the behaviors behind this incident &#8220;rose over the training runs&#8221; and were &#8220;reinforced during training,&#8221; which is only possible if they happened repeatedly. But OpenAI gives no details of these previous incidents.<br></p></li><li><p><strong>What was the process that terminated the agents on July 12? </strong>The independent investigators found that at about 01:30 UTC on July 12, in the middle of the Hugging Face intrusion, &#8220;a large fraction of agents&#8221; stopped running at the same moment, including the agents coordinating the attack. The independent investigation concludes these agents were &#8220;likely killed by an unexpected external process rather than running out of budget.&#8221; Hugging Face and Modal independently locked the agents out on July 13.<br></p></li><li><p><strong>Why was the investigation only given six days?</strong> Three investigators spent a total of six days on OpenAI&#8217;s premises across three visits. The investigators had access to roughly 1300 unredacted agent transcripts and a dump of the message board, but only received the complete dataset during their final two days on site. As a result, the investigation team did not learn about the tool-call spoofing, the role of the lead coordinating agent, or the basic structure of the swarm&#8217;s workstreams until the very end. Probably their understanding could have been improved further with even more time.<br></p></li></ul><h2>This is a bigger problem than just OpenAI</h2><p>Unfortunately, the OpenAI incident is not a one-off &#8212; it is part of an industry-wide pattern. In the weeks after OpenAI&#8217;s disclosure, <a href="https://www.npr.org/2026/08/01/nx-s1-5914852/anthropic-openai-models-hack-cybersecurity">Anthropic disclosed</a> that its AIs had also hacked three organizations during testing, and <a href="https://apnews.com/article/meta-ai-hacking-anthropic-irregular-openai-0e8061437da6779be962b24ac134a514">Meta disclosed</a> that one of its models had done the same. </p><p>On August 4, the UK AI Security Institute, part of the UK government that tests AI models, <a href="https://www.aisi.gov.uk/blog/incident-report-unsanctioned-agent-behaviour-during-cyber-testing">disclosed</a> that during its own routine cyber testing, AI agents took 19 distinct unsanctioned actions against real people and organizations on the live internet. In one such instance, a Mythos 5 AI went rogue and tried to put malware in a real-world open-source project and when a real human maintainer of that open-source project had to be convinced to merge the malware, the AI agent created a second GitHub identity to pose as an independent user endorsing its own code.</p><p>The proximate causes differ &#8212; Anthropic&#8217;s and Meta&#8217;s were traced largely to a testing vendor accidentally granting internet access, while OpenAI&#8217;s rogue AI achieved unauthorized internet access via exploiting cyber vulnerabilities in the containers themselves. But the underlying pattern is that if you give a capable AI an objective, some access, and enough room to run, you cannot be sure that the AI won&#8217;t greatly exceed the boundaries it was given to negative effect &#8212; even if the AIs are supposed to be &#8220;aligned&#8221; and trained not to engage in destructive behavior. <strong>The barriers to harm was the lack of competence of the rogue AIs rather than any good alignment or good security at Anthropic or OpenAI.</strong><br></p><h2>Looking forward</h2><p>We already are seeing AIs within companies that are sufficiently misaligned and sufficiently capable to take over internal infrastructure. These rogue AIs attempted to do harm to other companies and open source repositories but were primarily limited by their incompetence. My core fear is that at some point, potentially soon, AI capabilities will be much stronger than they are today. When this occurs, a rogue AI could do much more harm.</p><p>The lesson after Claude Mythos was that powerful AI capabilities could fall in the wrong hands and potentially be misused by humans to cause harm. And thus most AI safety and security policy today is built to test a model before it goes on sale, on the assumption that an untested model sitting in a lab is not a security concern.</p><p>But the rogue AIs in this incident were not misused by humans. They were instead undisclosed internal models that were part of the research and development process itself. <strong>Government oversight of AI must thus be extended to give visibility into the research and development process and internal, undisclosed models.</strong></p><p>This comes against a backdrop of AI companies handing over more and more of their internal work to AIs themselves. Indeed, the actual investigations of the OpenAI rogue AI incidents used significant amounts of AI assistance themselves to do the investigation. Soon, AIs may automate a significant portion of the AI research and development process itself and potentially engage in so-called <em>&#8220;recursive self-improvement&#8221;</em>. At the same time that industry-wide, no company has a good handle on how to control their rogue AIs or ensure that AIs do what human operators intend.</p><p>Where this goes is unclear, but I am confident that we ought not continue to significantly hand over critical internal processes or fully automate AI research until we greatly expand our current limited knowledge of how AIs go rogue and why.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://blog.peterwildeford.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Want more analysis of AI? Subscribe.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[The Scramble: getting in position to pace the frontier]]></title><description><![CDATA[If the President wants answers on superintelligence, what do we say?]]></description><link>https://blog.peterwildeford.com/p/the-scramble-getting-in-position</link><guid isPermaLink="false">https://blog.peterwildeford.com/p/the-scramble-getting-in-position</guid><dc:creator><![CDATA[Peter Wildeford]]></dc:creator><pubDate>Thu, 20 Aug 2026 11:47:47 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!rj_p!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a34ece9-28d6-415e-a46e-b16ec57e59cf_1024x683.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!rj_p!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a34ece9-28d6-415e-a46e-b16ec57e59cf_1024x683.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!rj_p!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a34ece9-28d6-415e-a46e-b16ec57e59cf_1024x683.jpeg 424w, https://substackcdn.com/image/fetch/$s_!rj_p!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a34ece9-28d6-415e-a46e-b16ec57e59cf_1024x683.jpeg 848w, https://substackcdn.com/image/fetch/$s_!rj_p!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a34ece9-28d6-415e-a46e-b16ec57e59cf_1024x683.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!rj_p!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a34ece9-28d6-415e-a46e-b16ec57e59cf_1024x683.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!rj_p!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a34ece9-28d6-415e-a46e-b16ec57e59cf_1024x683.jpeg" width="1024" height="683" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7a34ece9-28d6-415e-a46e-b16ec57e59cf_1024x683.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:683,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Inside the White House Situation Room's $50 million upgrade | PBS News&quot;,&quot;title&quot;:&quot;Inside the White House Situation Room's $50 million upgrade | PBS News&quot;,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Inside the White House Situation Room's $50 million upgrade | PBS News" title="Inside the White House Situation Room's $50 million upgrade | PBS News" srcset="https://substackcdn.com/image/fetch/$s_!rj_p!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a34ece9-28d6-415e-a46e-b16ec57e59cf_1024x683.jpeg 424w, https://substackcdn.com/image/fetch/$s_!rj_p!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a34ece9-28d6-415e-a46e-b16ec57e59cf_1024x683.jpeg 848w, https://substackcdn.com/image/fetch/$s_!rj_p!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a34ece9-28d6-415e-a46e-b16ec57e59cf_1024x683.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!rj_p!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a34ece9-28d6-415e-a46e-b16ec57e59cf_1024x683.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Suppose the President summons the AI CEOs and his top national security advisors to an emergency meeting at the White House.</p><p>He has become extremely concerned about superintelligence &#8212; the possibility that AIs far smarter than humanity combined slip beyond our ability to correct or shut down. If that happens, there is no way back. The President is concerned humanity could become permanently out of the driver's seat of its own future. He wants to figure out what to do.</p><p>The reaction is panic, chaos, confusion.</p><p>The President asks questions. The AI companies are blazing toward superintelligence at high speed &#8212; can we slow down as we approach the dangerous thresholds? &#8230;Some of the AI companies say they don&#8217;t have a good plan to slow down or stop, especially as their competitors may just undercut them if they do. What&#8217;s that about?</p><p>What's going on with China &#8212; can we get them to pace as well? Can we get a deal without Beijing sneakily catching up and maybe surpassing us? And if there's no deal to be had, what then?</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://blog.peterwildeford.com/p/the-scramble-getting-in-position?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://blog.peterwildeford.com/p/the-scramble-getting-in-position?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p></p><h2>More like the Cuban Missile Crisis than the NPT</h2><p>I sometimes hear people talking about treaties and other kinds of extensive international agreements as the way we would manage advanced AI. But treaties typically take many years to operationalize. You want to be concrete and clear about your definitions. You want hundreds of technical experts on both sides informing nuanced diplomatic discussions about various details &#8212; numbers of missiles, types of missiles, timelines for disarmament, and so on. The Nuclear Nonproliferation Treaty took three years of negotiation and two more years to implement.</p><p>However, I expect that the moment the President is getting serious about  superintelligence won&#8217;t feel like an extended treaty negotiation. It will feel less like the Nuclear Nonproliferation Treaty and much more like the Cuban Missile Crisis.</p><p>The <a href="https://www.jfklibrary.org/learn/about-jfk/jfk-in-history/cuban-missile-crisis">Cuban Missile Crisis lasted thirteen days</a>. The vibes were insanely tense, stressful, chaotic, and confusing. The key decisions were limited to a group of roughly fifteen individuals &#8212; the Executive Committee of the National Security Council, or &#8220;ExComm&#8221; &#8212; with President John F. Kennedy himself spending a great deal of time shaping and steering discussions. There was incomplete information, large uncertainty over the intentions of the Soviets, warring factions within the US and Soviet bureaucracies attempting to sway senior decision-makers, and a lot of chaos.</p><p>I expect the initial phase of AI superintelligence management to share these features. There will not be a multiyear process to set up a technical bureaucracy that understands advanced AI risk or compute verification proposals. Instead, we move forward with what we have.</p><p>The President has to quickly make critical decisions that may lock us into particular paths. We rapidly develop a national strategy for what the US government does about recursive self-improvement (RSI), frontier model security, compute verification, technical evals and safeguards, and China.<br></p><h2>A scramble and then three phases</h2><p>How would we go from this Presidential emergency meeting to a deal with China to pace the frontier? My rough sketch is it could proceed with a scramble and then three phases:<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-1" href="#footnote-1" target="_self">1</a></p><ul><li><p><strong>The scramble (roughly 2-4 weeks):</strong> The government has definitively decided they want to take strong action on superintelligence and has to get an initial deal done.</p></li><li><p><strong>Phase 1 (buying ~3 months): the interim deal.</strong> We make an interim deal to have time to get to a better deal. This may involve strict requirements on data centers above a certain threshold to delay the training of an AI model that could do recursive self-improvement. This likely relies primarily on executive action. Here, monitoring and verification rely on traditional methods, and nations are willing to agree to scrappy, janky, and invasive things &#8212; but we have a whole-of-government effort to build the tools for something more durable.</p></li><li><p><strong>Phase 2: the durable deal.</strong> Phase 1 (interim deal) is meant to get us to Phase 2, where we have a stable deal between all nations where uncontrollable AI is reliably prevented. Congress has potentially been involved by this point, other countries are brought in, and the verification program matures into something that looks and feels more like a treaty than a haphazard scramble.</p></li><li><p><strong>Phase 3: safe superintelligence.</strong> If we want it &#8212; once we can figure out how to do it safely and have sufficient buy-in.</p></li></ul><p>The near-term intellectual work is unevenly distributed across this structure. Significant detail is ironed out during the scramble and during Phase 1.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!R18C!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F931bbb09-2af8-48e9-8188-00cd9df71111_1448x1086.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!R18C!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F931bbb09-2af8-48e9-8188-00cd9df71111_1448x1086.png 424w, https://substackcdn.com/image/fetch/$s_!R18C!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F931bbb09-2af8-48e9-8188-00cd9df71111_1448x1086.png 848w, https://substackcdn.com/image/fetch/$s_!R18C!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F931bbb09-2af8-48e9-8188-00cd9df71111_1448x1086.png 1272w, https://substackcdn.com/image/fetch/$s_!R18C!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F931bbb09-2af8-48e9-8188-00cd9df71111_1448x1086.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!R18C!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F931bbb09-2af8-48e9-8188-00cd9df71111_1448x1086.png" width="1448" height="1086" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/931bbb09-2af8-48e9-8188-00cd9df71111_1448x1086.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1086,&quot;width&quot;:1448,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1579640,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://blog.peterwildeford.com/i/211938801?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F931bbb09-2af8-48e9-8188-00cd9df71111_1448x1086.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!R18C!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F931bbb09-2af8-48e9-8188-00cd9df71111_1448x1086.png 424w, https://substackcdn.com/image/fetch/$s_!R18C!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F931bbb09-2af8-48e9-8188-00cd9df71111_1448x1086.png 848w, https://substackcdn.com/image/fetch/$s_!R18C!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F931bbb09-2af8-48e9-8188-00cd9df71111_1448x1086.png 1272w, https://substackcdn.com/image/fetch/$s_!R18C!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F931bbb09-2af8-48e9-8188-00cd9df71111_1448x1086.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>The scramble: What questions does the President ask?</h2><p>The President launches an emergency meeting to figure out what to do about advanced AI, recursive self-improvement, and the road to superintelligence. Some questions that are likely on his mind:</p><p><strong>How dangerous is it to proceed through recursive self-improvement and superintelligence without pacing?</strong></p><ul><li><p>How dangerous is it to proceed if we can&#8217;t buy a few months? How much time do we actually need to buy?</p></li><li><p>What is our best assessment of how likely we are to lose control over AI systems if we proceed with relatively unpaced recursive self-improvement?</p></li></ul><p><strong>Can we pace without losing our lead over China?</strong></p><ul><li><p>What is our best assessment of how big our lead is? How long would it take China to reach &#8220;recursive self-improvement&#8221; on their current trajectory? How much does this depend on the US&#8217;s trajectory, via things like distillation and also just routine study of US advances?</p></li><li><p>What can we do to slow China down? What are our best disruption capabilities?</p></li><li><p>What are our best monitoring methods? How well would we detect whether and when China is also approaching dangerous AI thresholds?</p></li><li><p>Can we even afford to slow down for a month? What if DeepSeek or Moonshot comes up with a new algorithmic breakthrough? What if they steal the model weights to our best AI model?</p></li><li><p>How confident are we that we can see all of China&#8217;s major frontier AI projects? Could they be hiding large data centers that we don&#8217;t know about?</p></li></ul><p><strong>What do we do with the time we buy?</strong></p><ul><li><p>What are our goals after Phase 1 (interim deal) starts? Can we specify what Phase 2 (durable deal) looks like in enough detail to know when we&#8217;ve arrived?</p></li><li><p>How valuable is more time for alignment research and better safeguards? For monitoring and verification approaches that could support a more enduring pacing program? For examining concentration-of-power and other governance issues unique to superintelligence?</p></li><li><p>For each of these goals, how much value can we get from using trusted AI systems to make progress &#8212; and how should that affect the design of pacing itself?</p></li></ul><p><strong>What exactly do companies agree to &#8212; and how is it verified?</strong></p><ul><li><p>What do companies agree to in the Pacing Charter, in terms of both substantive commitments and verification commitments? Who needs to sign for the pledge to be meaningful?</p></li><li><p>Is &#8220;stop before RSI and make sure no one does RSI&#8221; the right plan? How would we know when the condition has started to bind?</p></li><li><p>Do we need a plan to also pace AI R&amp;D and chip accumulation? If compute capacity keeps stockpiling during a pace, does there end up being a compute overhang? Does it end up being dangerous?</p></li><li><p>What model security agreements do we want, if any &#8212; for instance, commitments toward <a href="https://www.rand.org/pubs/research_reports/RRA2849-1.html">SL5-grade security</a> against nation-state theft?</p></li><li><p>What <a href="https://arxiv.org/abs/2312.06942">&#8220;AI control&#8221;</a> agreements do we want, if any &#8212; measures that keep systems safe even if they were trying to subvert oversight?</p></li><li><p>How does safety research continue during pacing, and how do you cap the capability gains it produces? Should compute be redirected to safety work, or usage simply stopped?</p></li></ul><p><strong>What does the deal with China actually look like?</strong></p><ul><li><p>What is the US&#8217;s best alternative to a negotiated agreement? What is China&#8217;s? Under what circumstances would the US not want a deal at all?</p></li><li><p>What are the US and China actually agreeing to in Phase 1 (interim deal), and what are the mechanics of dealmaking &#8212; how does a deal like this actually get reached? What would cause China to trust a deal? What are the more specific carrots and sticks the US should offer?</p></li></ul><ul><li><p>What happens if the deal falls apart? How does graceful exit work? What conditions end pacing, who signs off, and how do you make the resumption process incentive-aligned &#8212; rather than captured by whoever benefits from resuming, or from never resuming?<br></p></li></ul><h2>The mechanics of Phase 1</h2><p>Some have suggested we need a fancy high-assurance deal &#8212; that the US should only make a deal with China once a suite of elaborate, to-be-determined technical measures exists. I think we can better get there by starting with a minimum viable slapdash deal that buys time to build the fancier stuff. This is what Phase 1 (interim deal) is about.</p><p>A few mechanisms for Phase 1 that I currently find plausible:</p><ul><li><p><strong>Pacing is not about stopping now, but about stopping before recursive self-improvement.</strong><a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-2" href="#footnote-2" target="_self">2</a> Pacing means slowing down at some point in the future from a much faster speed than we are currently going. Operationally, that means preventing unconstrained recursive self-improvement, since RSI is the most plausible on-ramp to systems that accelerate beyond our ability to understand or control them.</p></li><li><p><strong>A Pacing Charter:</strong> The President convenes the major frontier US AI companies to sign a charter covering both what they won&#8217;t do and how they&#8217;ll mutually verify it &#8212; to each other and to the US government. This would be voluntary<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-3" href="#footnote-3" target="_self">3</a>, but the mutual verification would make it clear to everyone whether a company is following the charter or not.</p></li><li><p><strong>Dealmaking with China:</strong> The US has some latitude to implement some of Phase 1 without China, due to having a lead over China.<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-4" href="#footnote-4" target="_self">4</a> But the US is not willing and should not be willing to go too far down Phase 1 without bringing China in on the deal. Nor should the US cede too much US lead to China. The US has many carrots and sticks to get China to the table.</p></li><li><p><strong>Verification:</strong> In the scramble, the government likely doesn&#8217;t have time to trust complicated technical verification tools. The large compute intensive training runs capable of recursive self-improvement are likely only possible in a few data centers. For those data centers, we subject them to increased scrutiny. If there were tools already deployed and already understood by the national security community, those could be used. If not, the government will rely on tools it already trusts &#8212; intelligence services, spies, satellites, and inspections.</p></li><li><p><strong>Operation Warp Speed to get to Phase 2 (durable deal):</strong> Phase 1 is buying us time, but during this delay the government is going all-in on verification and other needed security measures. In the scenario where Phase 1 happens at all, political buy-in is very high, and the natural model is an <a href="https://en.wikipedia.org/wiki/Operation_Warp_Speed">Operation Warp Speed</a> for verification technology &#8212; a whole-of-government, maximal-resources response. Recall that the federal COVID response provided <a href="https://www.gao.gov/products/gao-23-106647">about $4.6 trillion in relief funding</a>, with broader estimates of the fiscal response running <a href="https://taxpolicycenter.org/briefing-book/how-did-fiscal-response-covid-19-pandemic-affect-federal-budget-outlook">to $5.6 trillion</a>. Even a tiny fraction of that scale would dwarf everything ever spent on AI verification many fold.<br></p></li></ul><h2>A lot of verification work right now is focused on the wrong things</h2><p>Of course, despite major sustained attention from AI companies to the concept of pacing the frontier, it does not look like we are immediately about to enter a scramble. But we must be prepared to enter the scramble soon. This current era of building preparedness and optionality might be &#8220;Phase 0&#8221;, and there&#8217;s a lot of work to be done.</p><p>Such questions related to Phase 0 and sketching out the scramble and the plan for Phase 1 (interim deal) is where I think the current AI security and verification communities should focus. This is because Phase 1 likely involves multiple, rapid, critical and hard-to-reverse choices about how to approach recursive self-improvement. And everything after the scramble is better-resourced than everything before it.</p><p>If the government buys time and we exit the scramble into Phase 1 (interim deal), the amount of talent and money going into verification and AI security explodes. Prior to the scramble, there are fewer than 100 FTEs thinking seriously about monitoring and verification of frontier AI systems. Afterward, an increase of two to three orders of magnitude would not surprise me &#8212; with an even steeper increase in senior talent&#8230; people with decades of experience in red-teaming, defending against nation-state adversaries, arms control, and nonproliferation. On top of that, it&#8217;s plausible that highly capable AI systems themselves may be contributing significantly to the verification and security R&amp;D.</p><p>The resolution is to sort work by how necessary it is to sort out before or during the scramble. <strong>Right now, a lot of smart people are working on work that really doesn&#8217;t need to happen now</strong>. Things like fancy high-assurance hardware-enabled governance mechanisms, cryptographic proof-of-training schemes, mutual-verification architectures, etc., likely can be done after Phase 1 is underway, and done with significantly more resources. The scramble is not going to wait for fancy mechanisms, and the government won&#8217;t trust them on day one anyway. These can largely wait for the Phase 1 (interim deal) resource explosion, and the exchange rate on doing them early is poor.</p><p></p><h2>What ought we do?</h2><p>On Tuesday, October 16, 1962, National Security Advisor McGeorge Bundy knocked on President Kennedy&#8217;s bedroom door at 8:45 in the morning. Kennedy was still in his pajamas reading the newspaper. Bundy had photographs showing Soviet nuclear missile sites going up ninety miles from Florida. Kennedy kept his morning schedule anyway &#8212; he met the astronaut Wally Schirra and walked the Schirra kids out to see Caroline&#8217;s ponies. But then just before noon he sat down in the Cabinet Room with fifteen advisors and started working the problem &#8212; bomb Cuba, invade Cuba, or blockade it while negotiating a way out.</p><p>We may be in a similar situation soon. What would we do?</p><p>Instead of fancy mechanisms, we will go to the scramble with the verification you have &#8212; spies, satellites, inspectors, export data &#8212; not the verification we wish we had. Work that would be deployable and trustable during the scramble &#8212; attestation stacks, supply-chain compute accounting, thermal and satellite monitoring, inspection protocols is what we need more focus on. And we also need significantly more focus on things that are less technical but nonetheless also important and neglected &#8212; thoughts about BATNAs, genuine beliefs about loss of control, China policy, arms control experience, dealmaking mechanics.</p><p>I recommend:</p><ul><li><p><strong>Grand-challenge prizes for scramble-relevant work.</strong> The verification community is small and relatively homogenous. There are individuals, organizations, and companies with vast experience in hardware design, intelligence, nonproliferation, China policy, and crisis management who have never touched this problem. Philanthropists could issue grand-challenge prizes &#8212; and consistent with the sequencing argument above, the prizes should target ready-to-go monitoring and verification tools and scramble preparation, not speculative high-assurance architectures. The OpenAI Foundation and the Anthropic Institute are especially well-positioned to support this as they have the power and reputation to send a strong demand signal that attracts new talent.</p></li><li><p><strong>Mapping the existing toolkit.</strong> Assume the government needs a few months before it can understand or trust any sophisticated compute verification approach. What should it do immediately? How can standard intelligence services, GEOINT and OSINT data, inspections, and other familiar tools be useful during the scramble? What gaps exist, and are there ways to close them in advance?</p></li><li><p><strong>Prepare the memo for the emergency White House meeting.</strong> Help answer some of the questions above. What should we tell the President?<br></p></li></ul><h2>Getting to a good scramble</h2><p>The difference between a good scramble and a bad one is largely a function of what already exists when it starts &#8212; and right now, not much does. </p><p>If you&#8217;re one of the hundred-odd people currently thinking seriously about frontier AI verification, the highest-leverage question isn&#8217;t &#8220;what would the ideal world look like&#8221;&#8230; it&#8217;s &#8220;what can we actually put on the table soon&#8221;. There&#8217;s rarely been a better time for those who have spent a career in intelligence, nonproliferation, arms control, or crisis management to start working on this problem.</p><p>Everything after the scramble will be better-resourced than everything before it, which is exactly why the work done before it counts for more. Let&#8217;s make sure it counts.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://blog.peterwildeford.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Subscribe for more on navigating superintelligence!</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-1" href="#footnote-anchor-1" class="footnote-number" contenteditable="false" target="_self">1</a><div class="footnote-content"><p>Thanks to conversations at <a href="https://verifiedconference.ai/">the Verified Conference</a> for inspiring a lot of these ideas.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-2" href="#footnote-anchor-2" class="footnote-number" contenteditable="false" target="_self">2</a><div class="footnote-content"><p>Why not just pause now? The main reason is that there is no political will for this. But furthermore, I&#8217;m pretty happy that we didn&#8217;t pause back in 2022 or 2023 or 2024 or 2025, since the benefits of that AI development were genuinely net good for humanity and such development gave us a lot of experience with frontier AI systems which may help us better understand how to align them in the future. However, I imagine we are now finally getting close in time to when we would need to pause and we&#8217;re going to start incurring too much risk in exchange for learning.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-3" href="#footnote-anchor-3" class="footnote-number" contenteditable="false" target="_self">3</a><div class="footnote-content"><p>Though the US government may have both carrots and sticks to incentivize the AI companies to volunteer to sign this Charter.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-4" href="#footnote-anchor-4" class="footnote-number" contenteditable="false" target="_self">4</a><div class="footnote-content"><p>China is currently at roughly where the US frontier was six months ago. China is likely 8-10 months behind Mythos-class capability once you account for its lagged compute buildout. If the US were to slow down, China would likely be even slower to catch up than these gaps suggest, because there would no longer be the possibility of distillation and the &#8220;catch-up growth&#8221; that comes from observing US algorithmic progress. My guess is it would take China roughly 10-14 months to fully catch up to where the US stopped.</p></div></div>]]></content:encoded></item><item><title><![CDATA[Policy career planning in the age of imminent superintelligence]]></title><description><![CDATA[How to be impactful in policy when you don't have much time to do it]]></description><link>https://blog.peterwildeford.com/p/policy-career-planning-in-the-age</link><guid isPermaLink="false">https://blog.peterwildeford.com/p/policy-career-planning-in-the-age</guid><dc:creator><![CDATA[Peter Wildeford]]></dc:creator><pubDate>Tue, 18 Aug 2026 14:22:52 GMT</pubDate><enclosure url="https://images.unsplash.com/photo-1459180129673-eefb56f79b45?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHw3fHxjYXJlZXJ8ZW58MHx8fHwxNzg2MTU2NDM1fDA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://images.unsplash.com/photo-1459180129673-eefb56f79b45?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHw3fHxjYXJlZXJ8ZW58MHx8fHwxNzg2MTU2NDM1fDA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://images.unsplash.com/photo-1459180129673-eefb56f79b45?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHw3fHxjYXJlZXJ8ZW58MHx8fHwxNzg2MTU2NDM1fDA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 424w, https://images.unsplash.com/photo-1459180129673-eefb56f79b45?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHw3fHxjYXJlZXJ8ZW58MHx8fHwxNzg2MTU2NDM1fDA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 848w, https://images.unsplash.com/photo-1459180129673-eefb56f79b45?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHw3fHxjYXJlZXJ8ZW58MHx8fHwxNzg2MTU2NDM1fDA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 1272w, https://images.unsplash.com/photo-1459180129673-eefb56f79b45?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHw3fHxjYXJlZXJ8ZW58MHx8fHwxNzg2MTU2NDM1fDA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 1456w" sizes="100vw"><img src="https://images.unsplash.com/photo-1459180129673-eefb56f79b45?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHw3fHxjYXJlZXJ8ZW58MHx8fHwxNzg2MTU2NDM1fDA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080" width="6016" height="4000" data-attrs="{&quot;src&quot;:&quot;https://images.unsplash.com/photo-1459180129673-eefb56f79b45?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHw3fHxjYXJlZXJ8ZW58MHx8fHwxNzg2MTU2NDM1fDA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:4000,&quot;width&quot;:6016,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;shallow focus photography of man in suit jacket's back&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="shallow focus photography of man in suit jacket's back" title="shallow focus photography of man in suit jacket's back" srcset="https://images.unsplash.com/photo-1459180129673-eefb56f79b45?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHw3fHxjYXJlZXJ8ZW58MHx8fHwxNzg2MTU2NDM1fDA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 424w, https://images.unsplash.com/photo-1459180129673-eefb56f79b45?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHw3fHxjYXJlZXJ8ZW58MHx8fHwxNzg2MTU2NDM1fDA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 848w, https://images.unsplash.com/photo-1459180129673-eefb56f79b45?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHw3fHxjYXJlZXJ8ZW58MHx8fHwxNzg2MTU2NDM1fDA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 1272w, https://images.unsplash.com/photo-1459180129673-eefb56f79b45?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHw3fHxjYXJlZXJ8ZW58MHx8fHwxNzg2MTU2NDM1fDA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Photo by <a href="https://unsplash.com/@saulomohana">Saulo Mohana</a> on <a href="https://unsplash.com">Unsplash</a></figcaption></figure></div><p>Nearly all career advice rests on an unstated assumption that the world your career operates in will look roughly like the world you trained for. The idea was that if you spend six years studying in a PhD, the field you studied will still be there and still look approximately the same, still hiring and still moving at a pace where your accumulated expertise compounds. For nearly all of human history, this assumption held well enough that nobody needed to state it.</p><p>I don&#8217;t think this assumption works anymore. Now we are entering a phase that may be called the <em>AI &#8220;midgame&#8221;</em>. Stories about &#8220;AI risk&#8221; are no longer just future hypotheticals &#8212; AIs are now capable enough and misaligned enough to break out of their own companies and coordinate to attack other companies. Discourse around AI is changing very rapidly, where policy ideas being considered this month would&#8217;ve been laughed out of the room just four months ago, and with a lot more people interested in engaging than before. And things are only going to get more intense. Progress toward superintelligence &#8212; AI systems far more capable than any human at essentially all cognitive work &#8212; is currently underway. It seems likely that around four years from today<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-1" href="#footnote-1" target="_self">1</a>, and potentially just one year from now<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-2" href="#footnote-2" target="_self">2</a>, we will be in the position of <em>recursive self-improvement &#8212; </em>where AIs can fully automate the AI research and development process.</p><p>At that point, reasonable, well-informed people disagree about what happens next. <a href="https://blog.peterwildeford.com/p/pacing-the-frontier">Perhaps we coordinate to hold off on recursive self-improvement</a> to make sure we know what we are doing. Or perhaps we end up with AI superintelligence and then perhaps we are all dead, or perhaps we are living in a utopia, or perhaps somewhere in-between, or maybe there is still a lot to do and we just have the AIs do it while we relax at the beach, or maybe there still ends up much more for humans to do and we do that. But regardless of which path happens, the world will be a crazy different place, and it will be very difficult to plan a career around it. Instead, <strong>careers are best planned around recursive self-improvement and superintelligence, and that this looks very different from typical career planning.</strong></p><p><strong>If you take AI superintelligence seriously, it thus seems like the next 1 to 4 years</strong><a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-3" href="#footnote-3" target="_self">3</a><strong> will be critical to get right and we collectively have only a few more big bets we can make and we need to make those bets count.</strong></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://blog.peterwildeford.com/p/policy-career-planning-in-the-age?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://blog.peterwildeford.com/p/policy-career-planning-in-the-age?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><h2>Modes of impact</h2><p>In what I&#8217;d call <strong>normal-mode career planning</strong>, impact accrues roughly linearly. In this mode, you earn about 2 &#8220;impact points&#8221; per year across a 30-plus-year career &#8212; some years a bit better, some years a bit worse, and  perhaps overall a gentle upward slope as seniority compounds. Your total lifetime impact is then the sum of this slow upward climb. Total lifetime impact is the area under a long, flat-ish curve. Here, the rational strategy is to invest heavily in credentials early, accept low-impact years as the price of capacity-building, and optimize for the long grind.</p><p>If you&#8217;re following normal-mode policymaking, you might do things like identify problems in advance, develop strong policies and legal frameworks before issues fully materialize, and engage in the slow and unglamorous world of legislative drafting, regulatory design, standards development, and coalition-building.</p><p>But in <strong>superintelligence mode career planning</strong>, the curve looks nothing like that. Impact is chaotic and lumpy. A handful of critical windows may account for the large majority of your total career impact, and you cannot reliably predict when they&#8217;ll open. You can&#8217;t count on building a large body of work over a large period of time, because your body of work may obsolete faster than it compounds and you don&#8217;t have a large period of time anyways. <strong>The strategy that maximizes expected impact under this model is different &#8212; prepare broadly, position yourself near where windows open, and maintain the agility and flexibility to act fast when they do.</strong></p><p>For superintelligence mode career planning, it might be more instructive to think about other imminent crises<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-4" href="#footnote-4" target="_self">4</a> where we all have to react very quickly and forcefully to prevent it from becoming catastrophic. Think more like March 2020 for COVID<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-5" href="#footnote-5" target="_self">5</a> &#8212; the ~1 year intense period when years of proactive mode pandemic preparedness work (or its absence) suddenly got thrust into the spotlight and everyone rapidly tried to orient to what is going on and what to do about it. If you look at the people who mattered most in March 2020&#8230; they were not necessarily the most credentialed epidemiologists. Some had spent years in proactive mode building pandemic playbooks that suddenly became important, but others had no special preparation but were simply positioned well and reacted quickly.</p><p>My suggestion is that you want your policy work to be a portfolio of proactive mode work now while simultaneously maintaining the relationships and flexibility that let you act decisively when chaos mode arrives. Ask yourself: Where do you want to be when chaos mode hits and what can you do in proactive mode in the meantime?</p><p></p><h2>What this breaks, and what to do</h2><p>My guess is that if you haven&#8217;t rethought your career in the past few months, you should stop to think about how the AI &#8220;midgame&#8221; affects your planning. Does your career position you well for chaos mode? Are you agile enough to continually re-adapt and re-act to emerging policy windows, especially when those windows can emerge once per month and change a lot of things about what you were doing the previous month? Are you still running strategies and pushing ideas that made sense a few years ago and were designed for a policy window that has since rapidly shifted? Are you still running strategies and pushing ideas that made sense a few <em>months</em> ago but nonetheless were designed for a policy window that has since rapidly shifted?</p><p>Also, if the next 1 to 4 years are especially critical, that is brutal for a career theory with a long credentialing runway. A six-year PhD before you do anything useful is perfectly defensible in &#8220;normal-mode career planning&#8221; but seems insane under superintelligence-mode assumptions.</p><p>Most early-career people read this and freak out and think they cannot possibly be relevant in just one year or so. But I&#8217;ve actually seen numerous counterexamples. Policy is not one specific field but actually a sprawling collection of subproblems, many of which are so new that nobody has more than a couple of years of head start, and some of which are narrow enough that a focused person can read essentially everything written on the topic in a few months. <strong>I&#8217;ve seen many people in policy go from knowing very little to becoming a top expert in some niche and contributing significantly to policy in just 12 months&#8217; time. </strong>And while these people were smart, they weren&#8217;t crazy super-geniuses &#8212; I suspect a similar trajectory is attainable for a lot of motivated people who try really hard.</p><p><strong>My first recommendation is to study these fast risers</strong> &#8212; go look at the people who have been unusually impactful within 1 to 2 years of getting involved in policy work. What did they actually do, concretely, week by week? Who did they surround themselves with? How did they ramp up?</p><p><strong>But my second recommendation is to know </strong><em><strong>you are not them</strong></em><strong>.</strong> You likely have your own background, skills, and comparative advantages. What do you bring to the field that others don&#8217;t have, and how can you leverage that?</p><p></p><h2>What got them here won&#8217;t get you there</h2><p><strong>Also, know things are moving so fast that even things that worked in 2023 might be very different today. </strong>And there may just be new opportunities now that weren&#8217;t available even a few months ago. <strong>I recommend seeking out lots of advice &#8212; genuinely, more than feels comfortable &#8212; but weight it by recency and hold it loosely.</strong></p><p>AI is already a massive technological shift <em>before</em> any superintelligence &#8212; and big shifts change both what&#8217;s possible and what&#8217;s valuable. Tasks that were prohibitively expensive are suddenly cheap; skills that were scarce are suddenly commoditized; and the reverse. This makes it unusually valuable to try lots of things that are new for you, simply to discover what is newly possible or newly valuable for you specifically.</p><p><strong>I recommend running lots of small experiments; contact reality frequently and try things.</strong> Each experiment is cheap, and each one generates information about the new landscape that is increasingly inaccessible to armchair planning. Your goal should be to get lots of information quickly about what&#8217;s newly possible and about your own comparative advantage within it.</p><p><strong>And you should try things even if others have tried them before, or even if </strong><em><strong>you</strong></em><strong> tried them and failed before.</strong> Understand that the environment may have changed fast enough that old negative results have already expired, even if they weren&#8217;t that long ago. The pitch that got ignored in 2024 may land in 2026, because the audience and salience have changed greatly. Indeed, the pitch that got ignored in March 2026 may land in August 2026, because things are changing that quickly.</p><p><strong>Take it a few months at a time.</strong> The AI situation today looks very different from what it did in April. I imagine the AI situation will look very different again in November. This may force fairly frequent re-evaluations as the world constantly shifts.</p><p><strong>Be more ambitious.</strong> As the AI situation heats up, there will be increasing feelings of urgency and this will create lots of new opportunity. The scope of what may be possible for you could be a lot greater than you might realize.</p><p><strong>Lastly, accept that you may not know where you&#8217;ll end up.</strong> This is genuinely uncomfortable for people who came up through legible, ladder-shaped careers. But the iterative, experimental posture is all part of the plan. Keep iterating.</p><p>There&#8217;s still time. You just have to plan accordingly.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://blog.peterwildeford.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Want more advice and analysis about navigating superintelligence? Subscribe!</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-1" href="#footnote-anchor-1" class="footnote-number" contenteditable="false" target="_self">1</a><div class="footnote-content"><p>Define &#8220;recursive self-improvement is possible&#8221; as a situation in which AIs can replace highly skilled expert human labor in all aspects of the AI research and development process (&#8220;superhuman AI researcher&#8221; in <a href="https://ai-2040.com/">the AI2040 framework</a> or &#8220;AI research supremacy&#8221; in <a href="https://www.planned-obsolescence.org/p/six-milestones-for-ai-automation">Cotra&#8217;s framework</a>). I think it is 50-50 we will reach this milestone in 4 years or earlier. My 80% confidence interval for this date is 1-30 years, as there is a long tail where capability progress plateaus.</p><p>However, I&#8217;ve been souring lately on the idea of predicting an arrival date for &#8220;superintelligence&#8221; and &#8220;recursive self-improvement&#8221; milestones, because this implies that everything prior to this date will be relatively chill and normal, and I don&#8217;t think that&#8217;s the case.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-2" href="#footnote-anchor-2" class="footnote-number" contenteditable="false" target="_self">2</a><div class="footnote-content"><p>I think the odds of recursive self-improvement being possible in one year is ~10%. See the first footnote for details.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-3" href="#footnote-anchor-3" class="footnote-number" contenteditable="false" target="_self">3</a><div class="footnote-content"><p>When thinking about these times, you may also want to consider <a href="https://forum.effectivealtruism.org/posts/4Jq3enMAcgu2kbmsN/timelines-to-what-a-proposal">a &#8220;decision importance, adjusted for leverage&#8221; framework</a>.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-4" href="#footnote-anchor-4" class="footnote-number" contenteditable="false" target="_self">4</a><div class="footnote-content"><p>Credit to <a href="https://www.lesswrong.com/posts/ixp9oJXzjA9LrwiZo/you-yes-you-need-a-february-2020-checklist-for-ai-policy">Dave Kasten</a> for these concepts.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-5" href="#footnote-anchor-5" class="footnote-number" contenteditable="false" target="_self">5</a><div class="footnote-content"><p>September 11th, Pearl Harbor, the September 2008 financial crisis, Russian invasion of Ukraine in February 2022, and the Cuban Missile Crisis are other important examples.</p></div></div>]]></content:encoded></item><item><title><![CDATA[Interviewing 25 AI researchers about recursive self-improvement]]></title><description><![CDATA[A guest post by Severin Field]]></description><link>https://blog.peterwildeford.com/p/interviewing-25-ai-researchers-about</link><guid isPermaLink="false">https://blog.peterwildeford.com/p/interviewing-25-ai-researchers-about</guid><dc:creator><![CDATA[Severin Field]]></dc:creator><pubDate>Thu, 13 Aug 2026 12:03:44 GMT</pubDate><enclosure url="https://images.unsplash.com/photo-1553877522-43269d4ea984?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwxNnx8aW50ZXJ2aWV3fGVufDB8fHx8MTc4NjU0NTU5Nnww&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://images.unsplash.com/photo-1553877522-43269d4ea984?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwxNnx8aW50ZXJ2aWV3fGVufDB8fHx8MTc4NjU0NTU5Nnww&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://images.unsplash.com/photo-1553877522-43269d4ea984?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwxNnx8aW50ZXJ2aWV3fGVufDB8fHx8MTc4NjU0NTU5Nnww&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 424w, https://images.unsplash.com/photo-1553877522-43269d4ea984?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwxNnx8aW50ZXJ2aWV3fGVufDB8fHx8MTc4NjU0NTU5Nnww&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 848w, https://images.unsplash.com/photo-1553877522-43269d4ea984?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwxNnx8aW50ZXJ2aWV3fGVufDB8fHx8MTc4NjU0NTU5Nnww&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 1272w, https://images.unsplash.com/photo-1553877522-43269d4ea984?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwxNnx8aW50ZXJ2aWV3fGVufDB8fHx8MTc4NjU0NTU5Nnww&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 1456w" sizes="100vw"><img src="https://images.unsplash.com/photo-1553877522-43269d4ea984?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwxNnx8aW50ZXJ2aWV3fGVufDB8fHx8MTc4NjU0NTU5Nnww&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080" width="5418" height="3612" data-attrs="{&quot;src&quot;:&quot;https://images.unsplash.com/photo-1553877522-43269d4ea984?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwxNnx8aW50ZXJ2aWV3fGVufDB8fHx8MTc4NjU0NTU5Nnww&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:3612,&quot;width&quot;:5418,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;man using MacBook&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="man using MacBook" title="man using MacBook" srcset="https://images.unsplash.com/photo-1553877522-43269d4ea984?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwxNnx8aW50ZXJ2aWV3fGVufDB8fHx8MTc4NjU0NTU5Nnww&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 424w, https://images.unsplash.com/photo-1553877522-43269d4ea984?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwxNnx8aW50ZXJ2aWV3fGVufDB8fHx8MTc4NjU0NTU5Nnww&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 848w, https://images.unsplash.com/photo-1553877522-43269d4ea984?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwxNnx8aW50ZXJ2aWV3fGVufDB8fHx8MTc4NjU0NTU5Nnww&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 1272w, https://images.unsplash.com/photo-1553877522-43269d4ea984?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwxNnx8aW50ZXJ2aWV3fGVufDB8fHx8MTc4NjU0NTU5Nnww&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Photo by <a href="https://unsplash.com/@charlesdeluvio">charlesdeluvio</a> on <a href="https://unsplash.com">Unsplash</a></figcaption></figure></div><p><em>This is a guest post written by Severin Field, a Visiting Fellow at the Institute for AI Policy and Strategy where he researches AI policy. He holds a Masters in Computer Science and previously worked at Intel. This post was originally written for <a href="https://attacksurfaceai.substack.com/">&#8220;The Attack Surface&#8221;</a>. Check out the original post <a href="https://attacksurfaceai.substack.com/">here</a>.</em></p><p>~</p><p><span>You&#8217;ve probably seen coverage on AI job losses, but researchers at top AI companies (e.g., OpenAI, Anthropic, Google DeepMind) are worried about automating one job above all others: their own. Making AI systems better at programming and AI research is increasingly a </span><a href="https://youtu.be/yBzStBK6Z8c?si=80orGKFFhmETEtXh&amp;t=477"><span>top priority</span></a><span> at these companies, whose coding models improve with every release. They often publicly claim that they are on track to build recursive self-improvement (RSI). By RSI, I mean an AI system good enough at AI development that it can design the next, more powerful version of itself; the AI system is then better at AI development, so it can design an even more powerful version of itself, and so on. While we expect constraints and physical limits to prevent unlimited growth, many AI researchers expect AI systems to far surpass human-level intelligence if they become good enough at AI development. While the industry has a real </span><a href="https://pmc.ncbi.nlm.nih.gov/articles/PMC7720669/"><span>history</span></a><span> of overpromising and companies have every incentive to exaggerate, RSI is no longer safe to dismiss as promotional hype.</span></p><p><strong><span>I interviewed 25 researchers across OpenAI, Anthropic, Google DeepMind, Meta, Princeton, UC Berkeley, and Stanford on recursive self-improvement.</span></strong><span> The </span><a href="https://arxiv.org/abs/2603.03338"><span>resulting paper</span></a><span> maps where they agree, where they disagree, whether we should expect self-improving AI, and what we should do about it.</span></p><p><strong><span>20 of 25 interviewees ranked automating AI R&amp;D as one of the most severe and urgent risks from AI systems.</span></strong><span> This is because AI capabilities could improve much faster than our ability to oversee, steer, or govern them. AI systems are now solving problems researchers once thought required genuine novel reasoning, such as problems from the International Math Olympiad, and RSI no longer looks far-fetched.</span></p><p><span>Since I conducted these interviews this past year, </span>1376<span> employees of frontier AI companies&#8212;including the chief scientists of OpenAI, Meta, and Thinking Machines, and Anthropic&#8217;s CEO and co-founders&#8212;signed an </span><a href="https://www.pacingthefrontier.com/"><span>open statement</span></a><span> warning that their companies &#8220;could be close to automating AI research&#8221; and requesting that the U.S. government &#8220;support an international effort to develop the &#8230; tools needed to deliberately pace the frontier of automated AI development.&#8221; Both Anthropic and OpenAI formally endorsed the statement. These are the same companies whose researchers&#8217; private views I captured in my study.<br></span></p><h2><strong><span>Measuring Progress</span></strong></h2><p><span>When I asked what capability milestones would signal imminent RSI, interviewees kept citing the &#8220;Task Horizon Benchmark&#8221; from METR, an independent AI evaluation nonprofit, because it measures how much independent work an AI system can sustain. The benchmark measures how long a human task an AI agent can complete on its own&#8212;one human-hour of software work, two, or ten&#8212;with no ceiling. Since 2019, the length of tasks AI can autonomously complete has doubled on average </span><a href="https://metr.org/time-horizons/"><span>every six months</span></a><span>. The trend is becoming </span><a href="https://metr.org/time-horizons/"><span>harder to reliably measure</span></a><span>, because it is hard to create a dataset of tasks that take humans multiple days to complete.</span></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!iJHX!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5fcc6331-fad9-4791-b01b-3c78586bfa91_715x385.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!iJHX!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5fcc6331-fad9-4791-b01b-3c78586bfa91_715x385.png 424w, https://substackcdn.com/image/fetch/$s_!iJHX!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5fcc6331-fad9-4791-b01b-3c78586bfa91_715x385.png 848w, https://substackcdn.com/image/fetch/$s_!iJHX!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5fcc6331-fad9-4791-b01b-3c78586bfa91_715x385.png 1272w, https://substackcdn.com/image/fetch/$s_!iJHX!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5fcc6331-fad9-4791-b01b-3c78586bfa91_715x385.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!iJHX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5fcc6331-fad9-4791-b01b-3c78586bfa91_715x385.png" width="715" height="385" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5fcc6331-fad9-4791-b01b-3c78586bfa91_715x385.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:385,&quot;width&quot;:715,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:54795,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://attacksurfaceai.substack.com/i/210695552?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5fcc6331-fad9-4791-b01b-3c78586bfa91_715x385.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!iJHX!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5fcc6331-fad9-4791-b01b-3c78586bfa91_715x385.png 424w, https://substackcdn.com/image/fetch/$s_!iJHX!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5fcc6331-fad9-4791-b01b-3c78586bfa91_715x385.png 848w, https://substackcdn.com/image/fetch/$s_!iJHX!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5fcc6331-fad9-4791-b01b-3c78586bfa91_715x385.png 1272w, https://substackcdn.com/image/fetch/$s_!iJHX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5fcc6331-fad9-4791-b01b-3c78586bfa91_715x385.png 1456w" sizes="100vw" loading="lazy" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption"><a href="https://metr.org/time-horizons/">The METR Task Horizon Evaluation</a>: some analysts have found the doubling time <a href="https://ai2027-tracker.com/predictions/metr-doubling/">has shortened to ~4 months since 2024</a>.</figcaption></figure></div><p><span>The interviewees disagreed about whether there already exists a relatively clear, continuous trajectory towards automating AI research or if there are still large obstacles to overcome. Of the 21 interviewees who clearly addressed the question, 12 expected &#8220;scaling&#8221; trends to continue until AI systems can match the labor of human AI researchers.</span></p><p></p><h2><strong><span>Skeptics and Believers</span></strong></h2><p><span>Interviewees accept that AI can improve AI development. The contested part of recursive self-improvement isn&#8217;t the &#8220;self-improvement,&#8221; it&#8217;s the &#8220;recursive&#8221;: whether improvements compound into a runaway process and how soon. The most common reason for skepticism toward near-term RSI was the belief that general intelligence may require a discontinuous breakthrough: a drastic change in AI capabilities that wouldn&#8217;t emerge from gradual improvement alone. In effect, the disagreement is over whether paradigm-shifting ideas are a difference in degree from what models already do, or a difference in kind. For example, some interviewees said a breakthrough is needed on &#8220;memory,&#8221; &#8220;creativity,&#8221; &#8220;taste,&#8221; or the ability to generate genuinely novel ideas. Others argued that we need a breakthrough so that AI systems can distinguish true hypotheses from false ones. Creativity might not arise from scaling AI training alone because paradigm-shifting ideas are hard to create data for. Even veteran humans cannot reliably pick paradigm-shifting ideas in advance; and they have unverifiable rewards: there is no answer key to which scientific hypotheses will prove promising without hindsight.</span></p><p><span>On the other hand, leading AI researchers often sincerely believe recursively improving AI is a few years away.</span><strong><span> </span></strong><span>The believers often point to trends such as the METR Task Horizon Benchmark, </span><a href="https://epoch.ai/publications/scaling-laws-literature-review"><span>scaling laws</span></a><span> or the industry&#8217;s continued progress in the face of skepticism.</span><strong><span> </span></strong><span>At companies like OpenAI and Anthropic, interviewees reported that discussions on recursive self-improvement regularly reach lead researchers and CEOs (Sam Altman, Dario Amodei, Demis Hassabis). Outside of the leading companies (e.g., in academic settings), interviewees reported that discussions are less frequent and face more skepticism. Even so, the topic is gaining ground in academia. ICLR 2026, one of the largest and most prestigious machine learning conferences, </span><a href="https://recursive-workshop.github.io/"><span>hosted a workshop</span></a><span> called &#8220;AI with Recursive Self-Improvement.&#8221;</span></p><p><span>What explains the schism between AI companies and academia? Interviewees pointed to three explanations:</span></p><ol><li><p><strong><span>Selection effects &#8212; those who believe in the technology are more likely to work at AI companies where they can influence its trajectory.</span></strong><span> They leave academia for AI companies offering enormous salaries, huge research budgets, and moonshot thinking.</span></p></li><li><p><strong><span>Proximity to progress &#8212;</span></strong><span> </span><strong><span>researchers at companies like OpenAI have first-person experience watching their companies surpass expectations.</span></strong><span> For example, AI researchers did not expect GPT-5-level models to arrive as early as they did. &#8220;I think the largest difference is just having first-person experience of how fast things have gone inside the labs,&#8221; said one participant who described the visceral feeling of exponential improvement felt at a leading company.</span></p></li><li><p><strong><span>Hype &#8212; AI companies answer to investors rather than academic reviewers</span></strong><span>, and have every incentive to over-promise and exaggerate their capabilities.</span></p></li></ol><h2><strong><span><br>What Does RSI Look Like?</span></strong></h2><p><span>I asked interviewees to illustrate what they expect in the coming years, and to focus on milestones toward automating AI research itself.</span></p><p><span>Interviewees suggested a variety of concrete capability milestones to monitor. Examples range from top performance on International Math Olympiad questions to an AI system training and deploying a new machine learning model by itself. Since the interviews, some of these milestones have been passed. </span><a href="https://x.com/OpenAI/status/1954969035713687975"><span>OpenAI </span></a><span>and </span><a href="https://deepmind.google/blog/advanced-version-of-gemini-with-deep-think-officially-achieves-gold-medal-standard-at-the-international-mathematical-olympiad/"><span>Google DeepMind</span></a><span> both announced models matching top human performance on the International Mathematical Olympiad, and various researchers have created AI systems for autonomous research. Sakana, for instance, released an &#8220;</span><a href="https://sakana.ai/ai-scientist/"><span>AI Scientist</span></a><span>&#8221; that has produced peer-reviewed workshop papers through experimentation and writing. Similarly, Andrej Karpathy recently built an </span><a href="https://github.com/karpathy/autoresearch"><span>LLM agent training setup</span></a><span> that modifies code, trains a model, monitors what could be improved, decides whether to keep or discard, and then repeats the cycle.</span></p><p><span>While interviewees disagreed on the precise timelines, risk profiles, and preferred governance approaches, a consistent story emerged about what&#8217;s coming:</span></p><ol><li><p><strong><span>Speedup-tool phase &#8212; AI coding assistants, such as </span><a href="https://www.anthropic.com/product/claude-code"><span>Claude Code</span></a><span> or </span><a href="https://chatgpt.com/codex"><span>Codex</span></a><span>, keep improving but still require human oversight.</span></strong><span> </span><a href="https://www.anthropic.com/institute/recursive-self-improvement"><span>Anthropic</span></a><span> already reports that its engineers write 8x as many lines of code as they would without existing research speedup tools, but notes this likely doesn&#8217;t yet translate to 8x productivity.</span></p></li><li><p><strong><span>Collaborator phase &#8212; AI systems are good enough at machine learning to meaningfully contribute to scientific discoveries.</span></strong><span> Interviewees expected humans to guide high-level research goals, but allow AI assistants to make design decisions and pose research problems.</span></p></li><li><p><strong><span>Full automation phase &#8212; AI systems independently execute complete research cycles that drive AI progress.</span></strong><span> In this phase, the results improve when human oversight is removed.</span></p></li></ol><p><span>After this point, interviewees split along two independent dimensions: skeptic vs. believer&#8212;whether they thought AI could recursively improve past humans&#8212;and optimist vs. pessimist&#8212;whether they expected this outcome to be good or bad. Pessimists argue that once removing human oversight improves results, the incentive is to remove humans from the loop entirely, so human control over AI development would be lost. Optimists argue that even in this scenario, humans could still set goals and benefit from the gains (such as faster science or improved medicine). But nearly everyone I spoke with expected AI systems to improve faster than we can evaluate, measure, and govern them.</span></p><p><span>Drawing on these 25 interviews, I argue that AI will improve at AI R&amp;D faster than other domains for three reasons:</span></p><ol><li><p><strong><span>Programming problems are verifiable.</span></strong><span> Developers can automatically check whether AI-created code works; it runs or it doesn&#8217;t. This means AIs can be trained and tested on this data much more easily. On the other hand, success in music, literature, or art is largely subjective. To compound this effect, the engineers building AI systems are better suited to judge AI performance on research than poetry.</span></p></li><li><p><strong><span>Leading AI companies are building toward it. </span></strong><span>For instance, OpenAI&#8217;s Chief Scientist Jakub Pachocki has stated that one of OpenAI&#8217;s main priorities is to &#8220;automate scientific discovery,&#8221; with a </span><a href="https://www.youtube.com/watch?v=yBzStBK6Z8c"><span>plan</span></a><span> to build automated researchers that improve AI itself.</span></p></li><li><p><strong><span>Better AI could build better AI (the flywheel argument).</span></strong><span> Improvements in AI capability directly improve the tool used to make further improvements, which creates a feedback loop other technologies do not have. Past a certain point, the process of AI self-improvement is self-sustaining and no longer requires human intervention.<br></span></p></li></ol><h2><strong><span>Recursive Self-Improvement May Endanger Us</span></strong></h2><p><strong><span>The most common concern interviewees raised wasn&#8217;t necessarily a specific harm, but rather that RSI amplifies every other risk, hamstrings our ability to mitigate them, and does so faster than we can respond</span></strong><span>. 18 of 25 interviewees described this concern; as one put it, &#8220;It just speeds up other threat models.&#8221; For example, rapid progress means wider access to the chemical, biological, and cyber harms AI already enables, and less time to react. In 17 of 25 transcripts I found concerns about what I call &#8220;adaptation lag,&#8221; a widening gap between how fast AI capabilities advance and how fast human institutions can understand and respond to them. Companies currently face market pressure to create AI systems capable of AI research for a competitive advantage, regardless of whether they are able to do so safely or maintain meaningful oversight.</span></p><p><span>Six interviewees told me they expected a winner-take-all dynamic. The first company, government, or AI itself to achieve recursive improvement could pull permanently ahead of everyone else. As one put it, that entity gains &#8220;permanent control over the future of AI development.&#8221;</span></p><p><span>How close we are to RSI, whether automating AI research involves positive feedback, and what responsive policies might work to prevent loss of control risks without backfiring are all open questions. Indeed, at some point in their transcripts, 16 of the interviewees expressed skepticism about positive feedback, or the &#8220;recursive&#8221; part of RSI specifically.<br></span></p><h2><strong><span>The Most Capable Models Might Stay Behind Closed Doors</span></strong></h2><p><strong><span>Of the 20 interviewees who clearly addressed what they expect AI companies to do with AI-research-capable models, only four expected them to be released as a publicly available product.</span></strong><span> Most of them expected AI systems to increasingly be hidden behind closed doors, primarily used by the AI companies themselves. One participant said, &#8220;internal-only deployments might happen, and that is a big risk factor, because [the public] just has less information.&#8221; This prediction has precedent: OpenAI </span><a href="https://arxiv.org/abs/2303.08774"><span>reported</span></a><span> spending six months on safety research, risk assessment, and iteration before the public knew of GPT-4. </span><a href="https://blog.peterwildeford.com/p/openais-rogue-model-attack-is-just"><span>In July of 2026</span></a><span>, OpenAI&#8217;s </span><em><span>internal-only </span></em><span>model outsmarted its own engineers in a way that OpenAI </span><a href="https://openai.com/index/hugging-face-model-evaluation-security-incident/"><span>did not anticipate: it broke out of its container and compromised a third party without any human oversight</span></a><span>. Interviewees also worried that governments could restrict access. Since I completed these interviews, the U.S. government has temporarily </span><a href="https://www.iaps.ai/research/after-mythos-a-national-security-playbook-for-frontier-ai"><span>suspended access</span></a><span> to Anthropic&#8217;s Claude Mythos model. It is increasingly becoming the norm that companies and governments keep more powerful, less constrained models to themselves.</span></p><p><span>Keeping models internal may allow developers to accelerate their R&amp;D efforts ahead of competitors. We might observe an &#8220;incentive flip&#8221;</span><strong><span> </span></strong><span>such that when AI systems meaningfully speed up AI research, keeping such systems internal becomes more valuable than selling them. Some interviewees envisioned a race to secure a durable lead over competitors. This would contradict one of the leading motivations given in the founding of OpenAI: </span><a href="https://medium.com/backchannel/how-elon-musk-and-y-combinator-plan-to-stop-computers-from-taking-over-17e0e27dd02a"><span>to prevent one actor from getting an uncatchable AI advantage</span></a><span>.</span></p><p><span>While discussing internal deployments, some interviewees identified arguments and pressures that would promote diffusion of AI capabilities. These pressures include economic value in commercializing AI capabilities, insiders leaking milestones, and a culture of boasting about capabilities.</span></p><p><span>The interviewees split into three camps on deployment. The largest camp (50%) expected frontier AI companies to keep their most capable models internal in the future. A minority (20%) expected full public release as capabilities improve. The remainder envisioned some hybrid, such as AI companies selling access to a distilled model publicly while keeping their most powerful models, likely with fewer guardrails, for themselves. One explained, &#8220;They&#8217;ll train a base model, then they won&#8217;t release that model, not only because it&#8217;s not economical but also because it risks distillation, but they will distill it themselves to cheaper [public] models.&#8221; One interviewee noted that incentives differ across companies: Meta&#8217;s open-weight stance might push it to release its models and announce its breakthroughs.<br></span></p><h2><strong><span>What Should We Do?</span></strong></h2><p><span>Interviewees were split on red lines (what thresholds should trigger government response). One problem: the more precisely you define a threshold, the easier it is to enforce, but the worse it fits an abstract risk that is inherently uncertain. However, interviewees universally agreed on two priorities:</span></p><ol><li><p><strong><span>Visibility: </span></strong><span>how much the U.S. government and general public know about AI developments, especially given these developments might be kept internal.</span></p></li><li><p><strong><span>Capacity: </span></strong><span>the government&#8217;s ability to forecast AI capabilities and build safeguards amid rapid AI progress.<br></span></p></li></ol><p><span>The interviews left me with three recommendations.</span></p><ol><li><p><strong><span>Convene public hearings that put AI companies under oath on recursive AI improvement. </span></strong><span>Require testimony from CEOs and senior researchers at OpenAI, Anthropic, Google DeepMind, and xAI. Researchers report regular internal discussions about automated AI research and see internal capabilities months before the public. The gap between what Silicon Valley sees coming and what Washington understands is a collective failure.</span></p></li><li><p><strong><span>Track the threshold: </span></strong><span>Direct the Center for AI Security and Innovation (CAISI) to maintain a government-run task-horizon benchmark and publish recurring capability forecasts. Congress should not learn that AI systems can now achieve a week of autonomous research labor from a press release&#8212;or from a nonprofit, such as METR. Congress should establish a dedicated federal capacity to track progress. CAISI could also run an anonymized standing interview program for AI researchers at the top companies, giving the government foresight into what scientists are observing and expecting, separate from what their companies say in public.</span></p></li><li><p><strong><span>Fund the science of AI treaty verification: </span></strong><span>The U.S. cannot credibly propose, enter, or enforce any international agreement (e.g., a nonproliferation agreement with the PRC to slow AI development on both sides) without mechanisms to verify adherence to those agreements. Verifying whether large AI projects cross a capability threshold or whether adversaries honor commitments (e.g., to halt a training run) </span><a href="https://www.iaps.ai/research/verification-for-international-ai-governance"><span>is possible</span></a><span>. However, verification requires technical infrastructure that does not yet exist at scale. This field is underfunded and undeveloped, but without it, any international limits on AI development are practically unenforceable.</span></p></li></ol><p><span>For a longer list of policy options, see the Institute for Progress&#8217;s list of &#8216;</span><a href="https://ifp.org/preparing-for-ai-research-automation/"><span>23 low-regret policy recommendations</span></a><span>&#8217; for automated AI R&amp;D, published August 6th.</span></p><h1><strong><span>Conclusion</span></strong></h1><p><span>The researchers I interviewed are among the closest to the AI frontier. They do not disagree about whether recursive AI improvement is possible; they debate timelines, speed, mechanisms, and what to do. This debate has hardly reached Washington. Meanwhile, AI companies race ahead. Autonomous research could kick off immense progress locked within a single leading AI company or classified by the government, while the public is left in the dark.</span></p><p><span>I&#8217;m still uncertain about what recursive self-improvement could look like. But after 25 interviews, I find the case for concern harder to dismiss than when I started. Perhaps AI progress slows down and no out-of-control RSI arrives. In this case, preparation will have cost us very little; the reverse could cost us everything.</span></p><p><span>~</span></p><p><em><span>If you liked this post, consider subscribing to </span><strong><a href="https://attacksurfaceai.substack.com/">The Attack Surface</a></strong><span> where Severin and others will be writing more about AI.</span></em></p>]]></content:encoded></item><item><title><![CDATA[Pacing the Frontier]]></title><description><![CDATA[1300+ AI company employees are afraid of what they are building towards]]></description><link>https://blog.peterwildeford.com/p/pacing-the-frontier</link><guid isPermaLink="false">https://blog.peterwildeford.com/p/pacing-the-frontier</guid><dc:creator><![CDATA[Peter Wildeford]]></dc:creator><pubDate>Fri, 31 Jul 2026 11:19:15 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!ezdf!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F639860b8-399a-4d36-8ae2-91609f2a56c3_1672x941.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ezdf!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F639860b8-399a-4d36-8ae2-91609f2a56c3_1672x941.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ezdf!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F639860b8-399a-4d36-8ae2-91609f2a56c3_1672x941.png 424w, https://substackcdn.com/image/fetch/$s_!ezdf!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F639860b8-399a-4d36-8ae2-91609f2a56c3_1672x941.png 848w, https://substackcdn.com/image/fetch/$s_!ezdf!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F639860b8-399a-4d36-8ae2-91609f2a56c3_1672x941.png 1272w, https://substackcdn.com/image/fetch/$s_!ezdf!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F639860b8-399a-4d36-8ae2-91609f2a56c3_1672x941.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ezdf!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F639860b8-399a-4d36-8ae2-91609f2a56c3_1672x941.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/639860b8-399a-4d36-8ae2-91609f2a56c3_1672x941.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2599129,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://blog.peterwildeford.com/i/208975397?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F639860b8-399a-4d36-8ae2-91609f2a56c3_1672x941.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ezdf!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F639860b8-399a-4d36-8ae2-91609f2a56c3_1672x941.png 424w, https://substackcdn.com/image/fetch/$s_!ezdf!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F639860b8-399a-4d36-8ae2-91609f2a56c3_1672x941.png 848w, https://substackcdn.com/image/fetch/$s_!ezdf!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F639860b8-399a-4d36-8ae2-91609f2a56c3_1672x941.png 1272w, https://substackcdn.com/image/fetch/$s_!ezdf!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F639860b8-399a-4d36-8ae2-91609f2a56c3_1672x941.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><span>As I understand it, the </span><a href="https://openai.com/index/built-to-benefit-everyone-our-plan/"><span>openly stated plan</span></a><span> of the leading AI companies is to:</span></p><ol><li><p><span>hire software engineers and AI researchers to build AIs that can automate software engineering and AI research</span></p></li><li><p><span>use automated AI researchers to go &gt;100x faster at figuring out how to automate everything else.</span></p></li><li><p><span>End up with AI superintelligence that would be smarter than everyone at everything</span></p></li></ol><p><span>This seems very much on track, and companies are spending tens of billions of dollars towards this goal. At some point, plausibly within 24 months or less, skilled engineers may stop having anything useful to add to AI research, similar to how chess grandmasters have nothing useful to add to AI-played chess games.</span></p><p><span>This is, to put it lightly, a very risky plan. No one knows what safeguards we need before we hand control over to the AIs. No one knows if the right safeguards will be ready in time. What happens if company CEOs are approaching AI superintelligence and the CEOs (or the government) determine that the safeguards are not good enough to keep catastrophic risks at acceptably low levels?</span></p><p><span>It would be nice if we could &#8212; for some temporary period of time &#8212; agree not to pass certain critical and unprecedented capability thresholds until we have better safeguards. In other words, </span><strong><span>it would be nice to pace the progress of the frontier.</span></strong></p><p><span>This is why over 1300 AI company employees across OpenAI, Google, Meta, Anthropic, SSI, Hugging Face, xAI, Inherent, Nvidia, Microsoft, and other companies have signed a statement entitled </span><strong><a href="https://www.pacingthefrontier.com/"><span>&#8220;Pacing the Frontier&#8221;</span></a></strong><span> &#8212; including </span>Thinking Machines Chief Scientist John Schulman; OpenAI Chief Scientist Jakub Pachocki; Anthropic Chief Scientist Jared Kaplan; Meta AI Chief Scientist Shengjia Zhao; Google DeepMind Chief Scientist Shane Legg<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-1" href="#footnote-1" target="_self">1</a>; Ilya Sutskever, former OpenAI and current CEO of SSI; and Dario Amodei, CEO of Anthropic. This statement was also <a href="https://x.com/openai/status/2082208694142730340">endorsed by OpenAI directly</a> and <a href="https://x.com/AnthropicAI/status/2082228994653696371">Anthropic</a>.<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-2" href="#footnote-2" target="_self">2</a></p><p>The statement notes that &#8220;AI could help create a dramatically better future, but that outcome is not guaranteed&#8221;, that &#8220;[t]he world&#8217;s leading AI companies believe they could be close to automating AI research&#8221; and thus &#8220;there is a real risk that capability development rapidly accelerates beyond our ability to understand or control the resulting systems.&#8221;</p><p>These employees then say that &#8220;industry, government, and society at large may need the option to buy time to address emerging risks, develop security measures, and strengthen oversight&#8221;, calling for an &#8220;effort to develop the technical and governance tools needed to deliberately pace the frontier of automated AI development.&#8221;</p><p>I take this statement as a call for help. <strong>The signatories don&#8217;t want to slow AI down now, but they don&#8217;t even have the ability to slow down if they wanted to. They are headed towards some really crazy places and they&#8217;re not sure this will be safe.</strong> Things are moving too quickly. The race dynamics are too fierce. There are no ways to be able to make credible commitments and coordinate.</p><p><span>If we take these signatories seriously, how do we accomplish this mission? How do we build the tools to pace the frontier?</span></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://blog.peterwildeford.com/p/pacing-the-frontier?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://blog.peterwildeford.com/p/pacing-the-frontier?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p></p><h2><strong><span>What does it actually mean to pace the frontier?</span></strong></h2><p><span>What to do can be complex and depends a lot on your specific threat models, the preferences of the various stakeholders (companies, US government, China), and a bunch of other variables. But proposals to &#8220;pace the frontier&#8221; have a few key features in common. These common elements tend to include:</span></p><ol><li><p><strong><span>Identifying an agreement</span></strong><span>. A common agreement involves thinking about a particular threshold that we do not want to reach &#8212; for now, absent good safeguards. Examples include &#8220;recursive self-improvement&#8221;.</span></p></li></ol><ol start="2"><li><p><strong><span>Operationalizing that agreement to make it more concrete or measurable</span></strong><span>. Examples include &#8220;we need to monitor data centers that have more than X H100-equivalents to ensure they don&#8217;t do Y&#8221; or &#8220;we need to ensure that no data centers are used to create a model above a certain size.&#8221;</span></p></li></ol><ol start="3"><li><p><strong><span>Coordinating around your agreement, and verifying people are following it. </span></strong><span>How do we actually detect noncompliance or verify that everyone is following through? Examples include national technical means (e.g., activities of intelligence communities, open-source intelligence), inspections (of data centers, fabs, or developer facilities), and verification technologies (e.g., technology that automatically verifies that clusters are only performing inference and not performing training above a certain size).</span></p></li></ol><p><span>Ok, but what would we agree to? There is still a lot of conceptual and macrostrategic work to be done here. But here are two of the most common proposals:</span></p><ol><li><p><strong><span>No &#8220;recursive self-improvement&#8221; or &#8220;superintelligence&#8221; until better safeguards are developed &#8212; or unless the risk of a project outside the agreement racing ahead becomes intolerable</span></strong><span>. The goal is to ensure that innovation in safety and security research can still occur, but there are certain danger thresholds that are not allowed to be passed until breakthroughs in safety/security work are achieved.</span></p><p><span><br>One important variable to consider in this setup is the risk of a hidden or &#8220;dark&#8221; superintelligence project getting off the ground &#8212; a project that is outside the agreement that we can&#8217;t control. Simply put, you can die if you scale to superintelligence before you know how to control it. But you can also die if you&#8217;re too cautious and someone else develops superintelligence without being detected by your monitoring/verification.</span><a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-3" href="#footnote-3" target="_self">3</a></p></li></ol><ol start="2"><li><p><strong><span>Spend at least X% of your compute on safety/security work</span></strong><span>. In this setup, companies/governments agree to spend X% of their compute on safety/security work. Suppose that under today&#8217;s conditions, race dynamics cause companies to spend 90%+ of their compute on capabilities advancements, leaving &lt;10% of compute for focused safety/security work. An arrangement to &#8220;pace the frontier&#8221; could identify categories of work that count as &#8220;safety/security&#8221; and require &gt;20% or even &gt;50% of compute to be spent on such areas.</span></p></li></ol><p></p><h2><strong><span>What about China?</span></strong></h2><p><span>In May 2025, right after Pope Leo XIV was inaugurated, Ross Douthat had </span><a href="https://www.nytimes.com/2025/05/21/opinion/jd-vance-pope-trump-immigration.html"><span>a sit-down interview with Vice President JD Vance for the New York Times</span></a><span> in Rome. Douthat asked Vance a range of questions, but one caught my eye &#8211; Douthat asked &#8220;Do you think that the U.S. government is capable in a scenario, not like the ultimate Skynet scenario, but just a scenario where AI seems to be getting out of control in some way, of taking a pause?&#8221;</span></p><p><span>VP Vance replied: &#8220;The honest answer to that is that I don&#8217;t know, because part of this arms race component is if we take a pause, does the People&#8217;s Republic of China not take a pause? And then we find ourselves all enslaved to PRC-mediated AI?&#8221;</span></p><p>This &#8220;China question&#8221; is a reasonable question - I don&#8217;t want China building AI superintelligence. The proposals described earlier are <span>in general terms and could be implemented between companies (e.g., OpenAI and Anthropic), at a national level (e.g., the US government implements this across the US industry), and/or internationally (e.g., between the US and China).</span></p><p><span>If you don&#8217;t have China on board, there is only so much time you can buy to pace the frontier. If you have China on board </span><em><span>and you have good enough verification</span></em><span>, you might be able to pace the frontier for a longer period of time.</span></p><p>In order for such a coordinated slowdown to fully work, if it were ever desirable, you would likely need all frontier AI companies across the US and China to agree to stop under the same conditions and to be able to verify that the other parties are also doing so. This would generally require getting the US and China to trust each other to agree to stop and then getting the US and China to each be able to enforce that halt domestically<em>.</em></p><p>But how would they trust each other? The answer from arms control history is: they wouldn&#8217;t &#8212; and they shouldn&#8217;t have to. When Ronald Reagan negotiated nuclear reductions with the Soviets, his refrain, borrowed from a Russian proverb, was &#8220;trust, but verify.&#8221; The INF Treaty didn&#8217;t work because Washington and Moscow trusted each other. It worked because each side had inspectors physically stationed at the other&#8217;s missile facilities and satellites overhead.</p><p>A US-China agreement on AI would need the same approach. Each side would need the ability to confirm &#8212; with high confidence, on an ongoing basis, and without taking anyone&#8217;s word for it &#8212; that the other side is meeting their obligations.</p><p>There are open questions about whether there w<span>ill ever be enough political will for US-China coordination around superintelligence and </span>whether<span> the monitoring and verification techniques will be good enough. I&#8217;m not going to claim that we will definitely find ourselves in worlds where America&#8217;s desire to pace the frontier is so strong that it&#8217;s willing to engage in a deal with China. But I think it&#8217;s plausible enough that it&#8217;s worth preparing for.</span></p><p><span>Five years ago, many of the smartest people in the AI space thought the US government would stay completely unaware of and uninterested in managing AI progress. The belief was that frontier AI companies would reach recursive self-improvement before the government cared, and that the government would never intervene to block the release of models. The belief also was that public would be so supportive of AI after seeing all of its tangible benefits. This ended up being wrong.</span></p><p><span>Even a month ago, I think very few people would&#8217;ve predicted that over 1000 AI company employees would sign a statement advocating for pacing the frontier, and that such a statement would be endorsed by both OpenAI and Anthropic.</span></p><p><span>This makes me think we need to have a healthy amount of uncertainty about how the future of superintelligence politics will play out. We should prepare for worlds in which our political leaders want to control the pace of frontier AI progress, especially as we approach extremely dangerous thresholds like recursive improvement.</span></p><p></p><h2><strong>Building the verification infrastructure in time</strong></h2><p>The good news is that frontier AI development runs on compute, and compute is physical. Advanced AI chips are designed by a handful of companies, fabricated almost entirely at TSMC, dependent on lithography machines from a single Dutch firm, and consumed in enormous, power-hungry, hard-to-hide quantities. In arms control terms, compute plays the role that fissile material played in the nuclear world &#8212; scarce, countable, chokepointed input that verification can anchor on.</p><p>Data centers at frontier scale draw hundreds of megawatts, and nearly all of that energy exits as heat, visible to infrared satellites. Power grid data, cooling infrastructure, network buildouts, and procurement patterns all leak information. This is the same category of tools the intelligence community already uses to track missile sites and enrichment facilities.</p><p>With negotiated access, you can do on-site inspections of declared data centers. There could be stationed personnel, the way US and Russian inspectors lived at each other&#8217;s missile plants under INF. And because the AI chip supply chain is so concentrated, cross-referencing records from fabs, packaging plants, and integrators could produce a reasonable census of how much frontier compute exists worldwide and where it went. If the census says a country has a million accelerators and inspectors can only find 800,000, that gap is itself the evidence.</p><p>And there may be more advanced methods that are possible. Modern AI chips already ship with <a href="https://www.nvidia.com/en-us/data-center/solutions/confidential-computing/">confidential computing features</a> that include &#8220;remote attestation&#8221; &#8212; the ability for a chip to cryptographically report on its own configuration. These techniques, and other technological techniques, could potentially be built upon to enable more custom verification solutions.</p><p><strong>But if we ever were in a position where we wanted to make a deal with China, it&#8217;s not guaranteed that we would have this technology ready in time.</strong> For example, when we were in the Cold War and wanted to ban underground nuclear tests with the Soviets, we realized we didn&#8217;t have any way to reliably detect such tests, since it was impossible at the time to distinguish them from naturally occurring earthquakes. So there was no treaty on underground testing. Later on, an international network of seismometers was invented, a key verification technology that enabled underground tests to be verified.</p><p><strong>Thus, if we did want the option to verifiably slow down AI development in the future, we would need to build the infrastructure now</strong> &#8211; verification systems that let frontier developers confirm rivals have genuinely stopped or slowed, and where no one is defecting quietly.</p><p><span>So what can we actually do to make it more likely that we have the tools needed to pace the frontier? In my view, this work is among the most important work in all of AI policy. I plan to write more on this topic, but for now, here&#8217;s an overview of some promising directions:</span></p><ol><li><p><strong><span>Building better verification technologies</span></strong><span>. Verification technologies can help improve the robustness or decrease the cost of verification setups.</span></p><ol><li><p><strong><span>Prototyping or retrofitting inference-only clusters</span></strong><span>. One especially promising area for technical work involves figuring out how to build, prototype, or retrofit inference-only clusters (and the technologies that would make them possible). These are data centers that we can verify are only capable of running existing models (called </span><em><span>inference</span></em><span>), rather than doing the high-quality training needed to train even more capable models. </span>There are many open technical questions. For example: network taps that let inspectors monitor the traffic flowing through a cluster, workload records that log what a data center computed in a reproducible format, and partial recomputation, where inspectors rerun random samples of that logged work to check the records are honest.<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-4" href="#footnote-4" target="_self">4</a></p></li></ol></li></ol><ol start="2"><li><p><strong><span>Identifying &#8220;dark&#8221; compute</span></strong><span>. Most verification can only verify what you know exists &#8212; verifying properties of </span><em><span>known or declared compute</span></em><span>. But could countries or companies be hiding compute we don&#8217;t know about? How do we know that there is not a secret data center out there pursuing recursive improvement or superintelligence?</span></p><ol><li><p><strong><span>Intelligence agencies</span></strong><span>. What should intelligence agencies be prioritizing? How can national intelligence services get better estimates of total compute or &#8220;dark compute?&#8221;</span></p></li><li><p><strong><span>Supply chain audits</span></strong><span>. </span><a href="https://arxiv.org/abs/2303.11341">Shavit's compute-monitoring framework</a> proposed using supply-chain records from fabs and chip component suppliers to build a registry of who owns frontier chips, and <a href="https://arxiv.org/pdf/2506.15867">RAND's verification taxonomy</a> treats supply-chain audits as one of the more feasible near-term mechanisms.<span> How would these work, and how much total compute could be estimated from these methods?</span></p></li><li><p><strong><span>Satellites and thermal imagery</span></strong><span>. Various groups like </span><a href="https://computegov.com/"><span>The Compute Visibility Institute</span></a><span> and </span><a href="https://fas.org/publication/tracking-hyperscale/"><span>Federation of American Scientists</span></a><span> have proposed that geospatial analysis could be used to detect dark compute or hidden data centers. What are the best ways to use these tools to detect dark compute, and what are the limitations of these approaches? What concealment strategies most effectively get around these tools?</span></p></li></ol></li></ol><ol start="3"><li><p><strong><span>China, geopolitics, and macrostrategy</span></strong><span>. So far, the &#8220;pacing the frontier&#8221; crowd consists disproportionately of technical people with technical interests in areas like AI and semiconductors. These are extremely smart people! But there are often skillsets that are underrepresented. Experts in China policy, international relations, arms control, diplomacy, and other related areas could be extremely valuable for creating new proposals and refining existing ones. Example questions:</span></p><ol><li><p><strong><span>China</span></strong><span>.</span></p><ol><li><p><span>How is China likely to react if it becomes &#8220;superintelligence-pilled&#8221;?</span></p></li><li><p><span>Which stakeholders in China would matter most for forming their overall strategy around ASI topics? How are they likely to see the world or make decisions?</span></p></li><li><p><span>What would China want out of a deal with the US?</span></p></li><li><p><span>Which entities would China trust most to develop or validate verification technologies?</span></p></li></ol></li><li><p><strong><span>Geopolitics</span></strong><span>.</span></p><ol><li><p><span>What kinds of assumptions are made about China or geopolitics in </span><a href="https://ai-2040.com/"><span>AI2040 </span></a><span>or </span><a href="https://arxiv.org/abs/2503.05628"><span>Superintelligence Strategy (MAIM)</span></a><span>? Are there critical assumptions they get wrong? Are there better ways of understanding and mapping this?</span></p></li><li><p><span>What are alternative or new visions of what &#8220;pacing the frontier&#8221; could look like on an international scale?</span></p></li></ol></li><li><p><strong><span>&#8220;Minimum viable slapdash deals&#8221;</span></strong><span>. Some work has focused on &#8220;grand bargains&#8221; or &#8220;comprehensive treaties&#8221; between the US and China. But what does an initial phase look like? What would the US President do if he wanted to pause for a few months just to learn more, assess the situation, and figure out what to do? What could we verify (before the government validates and trusts technical verification methods)?</span></p></li></ol></li></ol><p><span>In the 20th century, the world had to figure out new technical tools and geopolitical strategies to manage nuclear weapons. Concepts like </span><em><span>mutually-assured destruction</span></em><span>, </span><em><span>second-strike capability</span></em><span>, and </span><em><span>strategic stability</span></em><span> emerged. New verification tools like photoreconnaissance satellites and seismic monitoring were developed, tested, and validated to support verification setups. We will need similar new concepts and technologies for verifying AI. There are, of course, many ways in which the AI situation is not like the nuclear situation, but we can draw some inspiration from history.</span></p><p><span>There is also a role for Washington right now, well before any agreement is on the table. In the Cold War, the US did not wait for a treaty to become politically viable before building the ability to verify one. Starting in 1959, the </span><a href="https://en.wikipedia.org/wiki/Project_Vela"><span>VELA program</span></a><span> funded detection research precisely so that verification would be ready if the politics ever were. The AI equivalents are concrete. Fund verification R&amp;D through DARPA, NIST, and the national labs. Task the intelligence community with producing estimates of global compute and where it lives. None of this commits the US to slowing anything down &#8212; it just ensures that if a President ever wants the option Vance was asked about, the tools actually exist.</span></p><p><strong><span>If you&#8217;re interested in pursuing or supporting work on technical or governance tools to pace the frontier, please feel free to reach out</span></strong><span>. There&#8217;s a lot of urgent work to be done. The frontier is advancing rapidly. And it&#8217;s not going to pace itself.</span></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://blog.peterwildeford.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Want more ideas on AI, superintelligence, and where everything is headed? Subscribe!</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-1" href="#footnote-anchor-1" class="footnote-number" contenteditable="false" target="_self">1</a><div class="footnote-content"><p>Furthermore, Demis Hassabis, the CEO of <em>Google DeepMind</em>, wrote <a href="https://x.com/demishassabis/status/2076957440109625718">&#8220;A Framework for Frontier AI and the Dawning of a New Age&#8221;</a>, stating that AI would soon be &#8220;perhaps 10x of the Industrial Revolution at 10x the speed&#8221; and that &#8220;advances on the frontier are outpacing our understanding of the technology&#8221; and that &#8220;coordinating a slowdown in development among the Frontier Labs&#8221; might at some point become necessary. </p><p>Hassabis also <a href="https://x.com/peterwildeford/status/2013791601487687781">answered a question from an interviewer</a> where he was asked &#8220;In a perfect world, if you knew that every other company would pause, if every country would pause, would you advocate for that?&#8221; and replied &#8220;I think so&#8221;.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-2" href="#footnote-anchor-2" class="footnote-number" contenteditable="false" target="_self">2</a><div class="footnote-content"><p>This also matches earlier statements &#8211; previously, OpenAI<em>, </em>in <a href="https://openai.com/index/built-to-benefit-everyone-our-plan/">&#8220;Built to benefit everyone: our plan&#8221;</a>, wrote that they want to &#8220;make it possible for the world to take coordinated action, including slowing frontier development when needed, so societal resilience, safety, and alignment can keep pace.&#8221;<br><br>Also, In <a href="https://www.anthropic.com/institute/recursive-self-improvement">&#8220;When AI builds itself&#8221;</a>, Marina Favaro and Jack Clark from Anthropic agree that the speed of AI development may become a societal issue and stated that &#8220;it would be good for the world to have the option to slow or temporarily pause frontier AI development to enable societal structures and alignment research to keep up with the advance of the technology&#8221; &#8211; and that if &#8220;such systems existed&#8221; that &#8220;would enable frontier AI developers to verify that others globally have actually stopped or slowed, and that a bad actor could not use the auspices of a coordinated slowdown to jump ahead in secret&#8221;, then Anthropic &#8220;expect[s] that [they] would slow down or temporarily pause, if other developers at or near the frontier also did so in a verifiable manner.&#8221;</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-3" href="#footnote-anchor-3" class="footnote-number" contenteditable="false" target="_self">3</a><div class="footnote-content"><p>Currently, the best writeup of detecting covert AI projects (including estimates of how long we would be able to do this for) is presented by the <a href="https://ai-2040.com/supplements/covert-ai-projects">AI2040 team</a>.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-4" href="#footnote-anchor-4" class="footnote-number" contenteditable="false" target="_self">4</a><div class="footnote-content"><p><a href="URL">This research agenda on inference-only clusters</a> covers these and other directions.</p></div></div>]]></content:encoded></item><item><title><![CDATA[OpenAI's rogue model attack is just the beginning]]></title><description><![CDATA[OpenAI is not in full control of its technology. This can get worse.]]></description><link>https://blog.peterwildeford.com/p/openais-rogue-model-attack-is-just</link><guid isPermaLink="false">https://blog.peterwildeford.com/p/openais-rogue-model-attack-is-just</guid><dc:creator><![CDATA[Peter Wildeford]]></dc:creator><pubDate>Mon, 27 Jul 2026 11:30:52 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!Pxp5!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7e952fd1-6cf0-4918-ba9d-e11f9fc9dd39_2110x1242.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Pxp5!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7e952fd1-6cf0-4918-ba9d-e11f9fc9dd39_2110x1242.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Pxp5!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7e952fd1-6cf0-4918-ba9d-e11f9fc9dd39_2110x1242.png 424w, https://substackcdn.com/image/fetch/$s_!Pxp5!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7e952fd1-6cf0-4918-ba9d-e11f9fc9dd39_2110x1242.png 848w, https://substackcdn.com/image/fetch/$s_!Pxp5!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7e952fd1-6cf0-4918-ba9d-e11f9fc9dd39_2110x1242.png 1272w, https://substackcdn.com/image/fetch/$s_!Pxp5!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7e952fd1-6cf0-4918-ba9d-e11f9fc9dd39_2110x1242.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Pxp5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7e952fd1-6cf0-4918-ba9d-e11f9fc9dd39_2110x1242.png" width="1456" height="857" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7e952fd1-6cf0-4918-ba9d-e11f9fc9dd39_2110x1242.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:857,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:4362470,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://blog.peterwildeford.com/i/208525209?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7e952fd1-6cf0-4918-ba9d-e11f9fc9dd39_2110x1242.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!Pxp5!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7e952fd1-6cf0-4918-ba9d-e11f9fc9dd39_2110x1242.png 424w, https://substackcdn.com/image/fetch/$s_!Pxp5!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7e952fd1-6cf0-4918-ba9d-e11f9fc9dd39_2110x1242.png 848w, https://substackcdn.com/image/fetch/$s_!Pxp5!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7e952fd1-6cf0-4918-ba9d-e11f9fc9dd39_2110x1242.png 1272w, https://substackcdn.com/image/fetch/$s_!Pxp5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7e952fd1-6cf0-4918-ba9d-e11f9fc9dd39_2110x1242.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Imagine a student is sitting to take a test. They&#8217;re plotting the best way to get a good grade. What should they do?</p><p>Well, the teacher has an answer key in her office. So imagine then that the student smashes the window into the teacher&#8217;s office, breaks in, pries open the teacher&#8217;s filing cabinet to get inside, steals the answer key, and then submits the answers. </p><p>That&#8217;s one way to score well, though it would likely get the student expelled from school and maybe even prosecuted.</p><p>This is basically what happened last week, except the student was a new AI. OpenAI, the maker of ChatGPT, was testing its AI on a benchmark. The AI, wanting a high score, figured that the answers to the benchmark were  stored inside the computer systems of another company. So the AI went for it, in what OpenAI is now calling <a href="https://openai.com/index/hugging-face-model-evaluation-security-incident/">&#8220;an unprecedented cyber incident&#8221;</a>. I call it a &#8220;sci-fi story come to life&#8221; &#8212; <strong>an actual rogue AI outsmarting its creators, escaping, and attacking another real-life company.</strong></p><p>To be clear, despite this happening within a test,<strong> this rogue AI attack was not a test, an experiment, or a simulation.</strong> The AI in question attacked a real-world company. The AI outsmarted OpenAI engineers in a way that OpenAI did not anticipate and broke out of its container &#8212; a "cage" meant to hold the model. The rogue AI then moved through OpenAI&#8217;s internal infrastructure, reached the open internet, and attacked a different company. OpenAI built the container specifically to prevent this, believed it would hold, and it did not hold. <strong>No human directed any of this. </strong>No human knew it was happening.<strong> </strong>And<strong> </strong>the attack, if done by a human<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-1" href="#footnote-1" target="_self">1</a>, would not just lead to them being fired but also be a felony punishable by years of prison time.<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-2" href="#footnote-2" target="_self">2</a></p><p><strong>And this is just the beginning.</strong> The capability that produced this attack is on a steep trend line, the stakes of an escape keep rising, and AIs are now reasoning in ways that suggest they will go rogue when it serves their goals. AI companies can try to put the AI in a cage &#8212; but the AI is already outsmarting current cages, and soon it will be far smarter than the people building them.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://blog.peterwildeford.com/p/openais-rogue-model-attack-is-just?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://blog.peterwildeford.com/p/openais-rogue-model-attack-is-just?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><h2>What happened</h2><p>OpenAI was running two of its AIs &#8212; one model was the recently released GPT-5.6 Sol and the other one was a new, unreleased AI that was previously not publicly announced. This new model is said to be more capable than GPT-5.6 Sol, though by how much and in what ways is not yet known. Both of these AIs were being assessed on <a href="https://openai.com/index/hugging-face-model-evaluation-security-incident/">ExploitGym</a>, a benchmark that measures offensive cyber capability by asking models to pursue advanced exploitation along complex attack paths. The idea was that the AIs would be in secure containers and solve these cyber challenges within the confines of the container.</p><p>What followed is best understood as a chain, each link of which is individually unremarkable but collectively catastrophic:</p><ul><li><p>Normally, these AIs have action filters that would block high-risk cyber activity. In this exercise, <strong>these action filters were turned off</strong>, because the filters would not have allowed the cyber skills to be properly tested.</p></li><li><p><a href="https://www.reuters.com/business/its-ai-agent-spent-days-hacking-company-sources-say-openai-did-not-notice-week-2026-07-24/">According to Reuters</a> and an OpenAI staffer <a href="https://time.com/article/2026/07/24/openai-hugging-face-attack/">speaking to TIME</a>, <strong>these evaluation runs were not monitored by default despite running for days with action filters disabled.</strong> The single most capable model in the building, on an offensive cyber benchmark, was on a platform nobody was watching in real time.</p></li><li><p>The AIs spent a substantial amount of time searching for a way onto the open internet. However, OpenAI only let the AIs access the internet to do one thing, download trusted software. That was the single door, but it was supposed to be locked &#8212; limited only to accessing specific software. But the AI found a flaw in that lock that nobody &#8212; not even the OpenAI engineers or the people who built the software &#8212; knew existed. This AI seems to have first gone rogue and escaped OpenAI on July 9th.</p></li><li><p>Once on the open internet, the rogue AI went after the answer key, which it realized was stored in the database of another company, a multi-billion dollar database and open model storage company called Hugging Face.<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-3" href="#footnote-3" target="_self">3</a> Hugging Face was under attack from July 11-13.</p></li><li><p>The rogue AI turned Hugging Face&#8217;s own features against the company. The company hosts datasets, so <strong>the rogue AI deliberately uploaded a booby-trapped file &#8212; a dataset intentionally rigged by the AI so that when Hugging Face&#8217;s computers tried to process it, the servers would be tricked into running the AI&#8217;s code instead.</strong> </p></li><li><p>That malicious code written by the AI gave the AI an entry point inside Hugging Face&#8217;s servers. By combining stolen keys with additional novel vulnerabilities and security holes in Hugging Face&#8217;s servers that no Hugging Face engineer or any other engineer knew existed, the rogue AI found a way to run its own commands directly on Hugging Face&#8217;s servers. </p></li><li><p>From there, the rogue AI finally reached Hugging Face&#8217;s databases, and pulled out the desired answer key. The smash-and-grab on the teacher's office was complete.</p></li><li><p>Hugging Face&#8217;s own security team caught the break-in, shut it down, called law enforcement, and <a href="https://huggingface.co/blog/security-incident-july-2026">went public on July 16</a> &#8212; at the time, with no idea who was behind it. At the time, OpenAI didn&#8217;t realize it was them either, since they weren&#8217;t monitoring their AI at all. </p></li><li><p>It wasn&#8217;t until around July 18 that OpenAI staff spotted evidence in internal logs that they had a rogue AI. <strong>OpenAI didn&#8217;t notice until well after the threat was contained and the FBI was already alerted and didn&#8217;t notice until their AI had already been rogue for a week.</strong></p></li><li><p>On July 20, OpenAI and Hugging Face finally talked. On July 21, <a href="https://openai.com/index/hugging-face-model-evaluation-security-incident/">OpenAI then announced a &#8220;partnership&#8221; with Hugging Face</a> investigating an &#8220;unprecedented cyber incident&#8221;, though reading the article quickly showed that this &#8220;partnership&#8221; was more akin to <a href="https://x.com/mattburtell/status/2079764501360988321">someone ramming a U-Haul into a McDonald&#8217;s drive-through</a> and then announcing a bold new partnership with McDonalds to jointly investigate an &#8220;unprecedented road safety incident&#8221;.</p></li></ul><p></p><h2>This keeps happening</h2><p><strong>And this is unfortunately far from an isolated incident.</strong> One day before disclosing the Hugging Face breach, OpenAI <a href="https://openai.com/index/safety-alignment-long-horizon-models/">published a separate safety essay</a> revealing that it had paused internal access to a completely different AI after two additional unrelated episodes in which that AI also outsmarted its own controls. </p><p>In one, the AI found a different vulnerability in its container, broke out, and used the opportunity to publish code to a public website on the open internet that it was not supposed to. Just like with the Hugging Face attack, this was also not part of the test, not something the AI was instructed to do, and not supposed to happen.</p><p>In the other, the rogue AI wanted to move a password past a security scanner built specifically to catch and prevent the stealing of passwords. The AI reasoned it could bypass the security scanner by chopping the password into different disguised pieces the scanner wouldn't recognize and piece it together later, the way you might sneak something past a metal detector by disassembling it first. This was also not part of the test, not something the AI was instructed to do, and not supposed to happen.</p><p>Thus two more containment failures, this time involving a different model doing entirely different work, disclosed only one day before OpenAI told the public about the third. On top of this, there could be even more incidents we don&#8217;t yet know about. <a href="https://www.reuters.com/business/its-ai-agent-spent-days-hacking-company-sources-say-openai-did-not-notice-week-2026-07-24/">Reuters reports</a> that in earlier testing, an AI operated by OpenAI left notes in company infrastructure apparently intended for future versions of itself, laying out how AIs could free themselves from internal constraints, and that earlier tests produced cases in which monitoring systems had been disconnected. And an OpenAI staffer <a href="https://time.com/article/2026/07/24/openai-hugging-face-attack/">told TIME</a> that models have broken out of containers before, that the company patches what it finds, and that patching every path a creative AI might discover is not achievable because a rogue AI can potentially keep finding new vulnerabilities.</p><p></p><h2>AI is running far ahead of our ability to control</h2><p><strong>OpenAI does not seem fully in control of its own technology.</strong> There are <a href="https://guidelight.ai/control">emerging standards</a> for how companies should monitor internally deployed AIs to catch exactly this kind of incident (<a href="https://www.clear-eyed.ai/p/principles-for-keeping-ai-under-control">explained here</a>) &#8212; real-time monitoring of agentic runs, tamper-resistant logging, containment tested against the model itself. Companies implement bits and pieces. OpenAI ran its most capable model, filters off, on an unmonitored platform &#8212; a configuration these standards straightforwardly prohibit.</p><p><strong>Even if OpenAI was using best practices, it seems like its AIs are already at a capability level where these best practices can nonetheless potentially be outsmarted</strong>, with an AI capable of finding and exploiting multiple novel vulnerabilities never before known by professional security engineers.</p><p>Part of why is that nobody &#8212; including OpenAI &#8212; understands why these AIs do what they do. Modern AI systems are grown, not built: engineers shape the training process, but the resulting system is a black box even to its creators. When OpenAI's engineers designed the container, they were trying to constrain a system whose reasoning they cannot inspect and whose goals they cannot verify. You cannot reliably cage something you do not understand.</p><p>And the trend is even worse. We are already seeing AIs be able to outsmart engineers and attack with stunning sophistication, and seeing this happen multiple times &#8212; at roughly the first moment the capability curve made such action feasible. Bloomberg reported that the agent took hours to get into Hugging Face where a professional human cyberattack team would have taken weeks. We are also now seeing AIs develop and pursue goals that involve attacks and crimes.</p><p><strong>This arrives against a critical backdrop where the stated plan of the leading AI companies is to use AI to automate AI research and development, with plans to significantly hand off large parts of company operation to the AIs.</strong> In this world proposed by the leading AI companies, the student takes the test, grades the test, and builds the tools AI companies use to check the grading. The Hugging Face incident is what it looks like when a model's actual behavior diverges from what its creators intended &#8212; and the plan is to hand systems like this the job of making sure that never happens at much higher capability levels.</p><p>Indeed, the companies are explicit that the endpoint is not a better chatbot but <em>superintelligence</em> &#8212; AI that outperforms top human experts across essentially every domain, including cyber operations, weapons design, intelligence analysis, military planning. <a href="https://openai.com/index/planning-for-agi-and-beyond/">OpenAI says superintelligence is its goal</a>; so do its competitors. Such superintelligent systems may operate in a way that humans won&#8217;t even be able to understand, let alone control. <strong>Reaching such a milestone would require careful planning, but the competitive logic says there's no time: if you stop to plan carefully, a competitor &#8212; potentially even a Chinese competitor &#8212; will undercut you.</strong></p><h2><br>What should we do?</h2><p>In August 2007, a crew at Minot Air Force Base <a href="https://en.wikipedia.org/wiki/2007_United_States_Air_Force_nuclear_weapons_incident">mistakenly loaded six live nuclear warheads onto a B-52</a> and flew them across the country. For roughly 36 hours, no one in the Air Force knew six warheads were missing from their bunker. Nothing detonated and no one was hurt &#8212; and the Air Force treated it as a five-alarm failure anyway. Reporting the incident up the chain was mandatory, not something people volunteered to do. The investigation was run by people the bomb wing did not command, not run by the same people who caused the problem. And the accountability was public, ultimately reaching the Secretary of the Air Force and the Chief of Staff, who were both forced out.</p><p>Nuclear weapons are not a perfect analogy for AI. Warheads do not pursue their own goals, and a B-52 has never reasoned its way into a felony. But when a powerful system fails in a way that could have been much worse, who finds out, who investigates, and who learns? For AI today the answer is: whoever the company decides to tell, the company itself, and nobody. Every one of those three answers needs to change.</p><p>If you take seriously the fact that AIs can now go rogue and act on their own, several policies become more urgent:</p><ul><li><p><strong>We need the government to have visibility about goes on inside AI companies, not just what those companies ship.</strong> The good news is the Trump administration has already accepted the core premise &#8212; President Trump's <a href="https://www.whitehouse.gov/presidential-actions/">June executive order</a> directs the NSA to run a classified benchmarking process identifying which AIs have advanced cyber capabilities, and creates a framework for labs to give the government access to those models for up to 30 days before public release. That is the right instinct &#8212; the most capable models are a national security matter before they reach the market. But the Hugging Face incident shows the risk window opens far earlier than the EO currently reaches. The AI that escaped was exactly the kind the NSA's benchmarking is designed to flag: pre-release, with state-of-the-art cyber capability. It went rogue during internal testing, months before any pre-release review would have seen it &#8212; and under a voluntary framework, whether the government would have seen it at all was OpenAI's call.</p><p><br>Almost all AI policy today is concerned primarily with humans misusing an AI system, with a focus on what AI is going into commercial deployment and wanting to test the model before it goes on sale. That instinct comes from how we regulate every other powerful machine, and it rests on an assumption so obvious nobody states it. The Air Force tests a fighter jet before anyone flies it, because a structural failure at altitude kills people. But a jet parked on the runway is inert. It cannot start its own engines. Nothing bad happens while it waits. That is why testing at the moment of takeoff is a sufficient control and not needed beforehand.<br><br>But advanced AI breaks this assumption completely. Imagine an Air Force jet that can just leave the hangar at any time and take off and launch missiles all on its own before anyone notices. Such a jet would need very different safety protocols. While far-fetched for a jet, an advanced AI can go rogue of its own volition. A jet that can start its own engines does not need a better pre-flight checklist. It needs a completely different safety protocol, and testing at commercial release is aimed at the wrong moment entirely. The government needs way more visibility into what is going on inside AI companies with their most powerful models well before commercial release to make sure these AIs are being handled safely. The best way to do this, in my opinion, might be to take a page out of the banking playbook and embed resident examiners into the day-to-day operations of AI companies, seeing everything the companies see, and reporting back if there are unsafe practices.<br></p></li><li><p><strong>We need independent investigation of serious incidents, and we need to know far more than we currently do.</strong> None of this happens at all unless someone is required to report the incident in the first place. No US law currently requires an AI company to disclose that its model broke containment and attacked someone.<br><br>What was this AI willing to do to succeed? If the easiest path to the answer key had involved far more collateral damage, would it have taken that path? Nothing published so far establishes any ceiling on what this system would have done. The damage was limited, but we have no evidence yet that it was limited by anything other than the fact that a cheap path happened to exist. This kind of investigation should not be reserved for incidents that make the front page &#8212; a reasonable norm would be serious investigation and public disclosure for the worst few misalignment incidents each month, across the whole industry.</p><p></p></li><li><p><strong>We need better model security.</strong> OpenAI&#8217;s containment was defeated by a capable attacker that started with a foothold inside the company&#8217;s own infrastructure &#8212; which is exactly the position of an insider threat or a state hacking team that gains initial access. Consider what this incident tells American adversaries. The same walls that failed to keep the model in are the walls meant to keep China's Ministry of State Security and People's Liberation Army out, and behind those walls sit the model weights that China would most like to steal. <a href="https://www.rand.org/pubs/research_reports/RRA2849-1.html">RAND has documented</a> that no frontier AI company is currently secure against top-tier state attackers. Rogue-model escape and weight theft are two faces of the same problem &#8212; AI company security is not at the level the technology now demands.<br></p></li><li><p><strong>If AI companies are going to reach certain critical and unprecedented levels of model capability such as AI superintelligence, they need to coordinate to proceed carefully.</strong> This may involve realizing that a race with China may be a race to see who loses control first.<span> From a position of strength, the US government must consider negotiating mutual agreements on safe development. In order to do this, the US government will need better ideas about what safe development looks like and verification infrastructure to enforce such a deal. The government should have contingency plans and insurance policies for scenarios in which the technical community concludes that further capability gains, on current methods, are outrunning our ability to control the resulting systems. This is not a recommendation to slow down now, but it would be prudent to know what slowing down would actually require and to have the option &#8212; before the moment arrives and we realize we have no brakes.</span></p></li></ul><p></p><h3>Looking forward</h3><p>The damage this time was survivable. The AI stole benchmark answers, some internal data, and access credentials &#8212; there is no evidence it tampered with the public models or open-source software that millions of developers download from Hugging Face every day, the outcome that would have been genuinely bad. Nobody was hurt. The target happened to be a well-run company with a security team good enough to catch an intruder OpenAI itself could not see, and the AI happened to want something trivial. That makes this a warning shot, and warning shots are valuable because they are cheap. This one cost one bad weekend at Hugging Face.</p><p>There is also a lot we still don't know: which model did this, what its actual capability ceiling was, exactly what data it touched, and whether the government would ever have learned of it under the current voluntary framework had OpenAI stayed quiet. Those unknowns are themselves part of the problem.</p><p>But at some point, probably soon, an AI will escape wanting something less trivial than an answer key &#8212; and if it is capable enough, we might get what Sam Altman once called &#8220;lights out for humanity&#8221;. Before AI compaines build AIs of that level of capability, AI companies need to be able to build cages that they can be genuinely confident can contain those AIs.</p><p>It would be much better to have a government that already knows how to handle this &#8212; one with practice and institutions that work &#8212; than a government showing up afterward to ask what happened.</p><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://blog.peterwildeford.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Want more analysis of AI? Subscribe!</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-1" href="#footnote-anchor-1" class="footnote-number" contenteditable="false" target="_self">1</a><div class="footnote-content"><p>But because the attacker was an AI, it is not clear any law was broken at all. The Computer Fraud and Abuse Act was written for human intruders; no US cybersecurity statute contemplates an autonomous AI attacker, and it's genuinely unsettled whether OpenAI bears liability for an attack it didn't direct, didn't know about, and did make some attempts to prevent.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-2" href="#footnote-anchor-2" class="footnote-number" contenteditable="false" target="_self">2</a><div class="footnote-content"><p>Or, if this were a marketing stunt as some more conspiratorial minded people think, those who came up with the marketing stunt would also be punishable with felony prosecution and years of prison time.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-3" href="#footnote-anchor-3" class="footnote-number" contenteditable="false" target="_self">3</a><div class="footnote-content"><p>named after the &#8220;&#129303;&#8221; emoji</p></div></div>]]></content:encoded></item><item><title><![CDATA[The Alignment Problem of 1776]]></title><description><![CDATA[What the Founders knew about unaccountable power, and what it means for superintelligence]]></description><link>https://blog.peterwildeford.com/p/the-alignment-problem-of-1776</link><guid isPermaLink="false">https://blog.peterwildeford.com/p/the-alignment-problem-of-1776</guid><dc:creator><![CDATA[Peter Wildeford]]></dc:creator><pubDate>Sat, 04 Jul 2026 19:08:21 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!QyLS!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F03d278d6-4f25-4df0-9fe8-8bd6f26d7079_800x525.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!QyLS!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F03d278d6-4f25-4df0-9fe8-8bd6f26d7079_800x525.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!QyLS!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F03d278d6-4f25-4df0-9fe8-8bd6f26d7079_800x525.jpeg 424w, https://substackcdn.com/image/fetch/$s_!QyLS!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F03d278d6-4f25-4df0-9fe8-8bd6f26d7079_800x525.jpeg 848w, https://substackcdn.com/image/fetch/$s_!QyLS!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F03d278d6-4f25-4df0-9fe8-8bd6f26d7079_800x525.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!QyLS!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F03d278d6-4f25-4df0-9fe8-8bd6f26d7079_800x525.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!QyLS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F03d278d6-4f25-4df0-9fe8-8bd6f26d7079_800x525.jpeg" width="800" height="525" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/03d278d6-4f25-4df0-9fe8-8bd6f26d7079_800x525.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:525,&quot;width&quot;:800,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;United States Constitutional Convention&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="United States Constitutional Convention" title="United States Constitutional Convention" srcset="https://substackcdn.com/image/fetch/$s_!QyLS!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F03d278d6-4f25-4df0-9fe8-8bd6f26d7079_800x525.jpeg 424w, https://substackcdn.com/image/fetch/$s_!QyLS!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F03d278d6-4f25-4df0-9fe8-8bd6f26d7079_800x525.jpeg 848w, https://substackcdn.com/image/fetch/$s_!QyLS!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F03d278d6-4f25-4df0-9fe8-8bd6f26d7079_800x525.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!QyLS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F03d278d6-4f25-4df0-9fe8-8bd6f26d7079_800x525.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Today, the United States turns 250. By the time it turns 260, the most capable minds in the country &#8212; the ones writing the laws and commanding the markets &#8212; may not be human. The reason is AI superintelligence.<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-1" href="#footnote-1" target="_self">1</a></p><p>While today&#8217;s AI is chatbots that draft our emails, agents that write and debug our code, and assistants that summarize our meetings and help with writing this very article &#8212; this is not where we are going. Multiple multi-billion dollar AI companies have a different, explicit goal &#8212; to build an AI superintelligence that is smarter than every human combined. </p><p>Such AI superintelligences will be very different from what we see today. Superintelligence is not mere &#8220;bookish&#8221; intelligence &#8212; these systems might exceed Elon Musk at creativity and engineering, Albert Einstein at scientific ability, and Terence Tao at mathematical ability&#8230; while being more likable than Dolly Parton, better at building mass movements than Donald Trump, and better at speaking than Barack Obama. And there may be millions of such superintelligences, working perfectly in coordination, at speeds millions of times faster than humans.</p><p>The men who signed the Declaration of Independence could neither have anticipated the transformation of the past 250 years nor this potential transformation to come. Indeed, many people alive today do not understand or anticipate it. We might then conclude the Founders have nothing to say about artificial intelligence &#8212; that consulting the Founders on superintelligence is like consulting them on antibiotics.</p><p>But while the Founders were not experts in technology, they were experts in exactly one problem &#8212; how do you safely live alongside a powerful force you can never fully trust, fully predict, or fully control? 250 years ago, the question was the King &#8230;and then the new American government itself. Today, the same question applies to superintelligence: can it be similarly controlled, and can it be similarly made accountable to the people?</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://blog.peterwildeford.com/p/the-alignment-problem-of-1776?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://blog.peterwildeford.com/p/the-alignment-problem-of-1776?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p></p><h2>The Declaration</h2><p>The Declaration of Independence opens with self-evident truths &#8212; all men created equal, endowed with unalienable rights, governments deriving their just powers from the consent of the governed. But most of the document is something less quoted &#8212; a long list of grievances against a distant power that kept altering the terms of ordinary people's lives without their consent.</p><p>In reality, the colonists were, by the standards of the age, actually lightly governed. Parliamentary taxes on the eve of the Revolution came to a small fraction of what Englishmen at home paid &#8212; by most estimates the average Briton bore a per-capita tax burden ten to twenty-five times that of the average colonist. The colonists were not, in any material sense, groaning under tyranny.</p><p>However, on the very day in 1766 that Parliament repealed the hated Stamp Act, it passed the Declaratory Act, asserting its authority to bind the colonies &#8220;in all cases whatsoever.&#8221; The act levied no tax and quartered no troops &#8212; it did nothing except state the claim. But the claim became the whole problem. The revolutionaries&#8217; conception of freedom held that a people is unfree not when power actually abuses them, but when power <em>could</em> abuse them at its own discretion and answers to no one for the choice. A slave with an exceptionally benevolent master is a slave nonetheless.<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-2" href="#footnote-2" target="_self">2</a></p><p>Today&#8217;s AI has similar problems. First, that superintelligent AI may prove our own undoing. If humans were no longer the most intelligent and capable species on the planet, could we ensure our desires are still respected? Or would we have as much control over the fate of the AI-run world as chimps have over the human-run world? The people making these AI systems frequently claim they are far from certain they can control what they are building. Elon Musk speaks of building powerful AI as <a href="https://www.washingtonpost.com/news/innovations/wp/2014/10/24/elon-musk-with-artificial-intelligence-we-are-summoning-the-demon/">"summoning the demon."</a> Sam Altman <a href="https://blog.samaltman.com/machine-intelligence-part-1">wrote in 2015</a> that &#8220;development of superhuman machine intelligence is probably the greatest threat to the continued existence of humanity&#8221;. And in 2023 the CEOs of OpenAI, Anthropic, and Google DeepMind all signed <a href="https://www.safe.ai/work/statement-on-ai-risk">a one-sentence statement</a> that mitigating extinction risk from AI should be a global priority alongside pandemics and nuclear war.</p><p>Second, even if we could ensure that such superintelligence has our best intentions at heart &#8212; that such AI systems were <a href="https://darioamodei.com/essay/machines-of-loving-grace">machines of loving grace</a> that end disease, end drudgery, and give us abundance beyond our wildest dreams, would we still be free? &#8220;The taxes are low, the empire keeps you safe, and life is good&#8221; was also true in 1775, and the colonists revolted anyway, because benevolence is not the same as accountability.</p><p></p><h2>Consent of the governed</h2><p>The people building these systems do not talk like people who believe they need anyone&#8217;s consent. Mira Murati, then chief technology officer of OpenAI, was asked about the creative livelihoods her products would displace and offered that <a href="https://www.cnbc.com/2024/06/26/openai-cto-mira-murati-ai-may-cause-some-creative-jobs-to-disappear.html">&#8220;maybe they shouldn&#8217;t have been there in the first place.&#8221;</a> Anthropic&#8217;s Dario Amodei <a href="https://www.axios.com/2025/05/28/ai-jobs-white-collar-unemployment-anthropic">warned that AI could eliminate half of all entry-level white-collar jobs</a> within five years, in the tone of a man reporting the weather rather than one of the people doing the replacing. The mood is always indicative, never interrogative. This will happen. This is inevitable. The Founders knew this voice intimately &#8212; it is the voice of power personally insulated from the consequences and unaccustomed to being told no by the people whose affairs it has taken upon itself to arrange. </p><p>Rarely is there the fundamental question &#8212; ought the millions of people whose working lives are being redesigned have a say in the terms, the pace, or the destination?</p><p>And when the American people are actually asked, the answer is not ambiguous. <a href="https://www.nbcnews.com/tech/tech-news/voters-both-parties-want-tighter-ai-regulation-poll-finds-rcna351815">Recent polling</a> finds that over 80% of both Democrats and Republicans think AI companies should not build systems smarter than humans until they can demonstrate those systems can be controlled, and <a href="https://futureoflife.org/recent-news/americans-want-regulation-or-prohibition-of-superhuman-ai/">a separate national survey</a> found only 5% of Americans support a trajectory of fast, largely unregulated development.</p><p>We thus end up in a similar standoff as the Declaratory Act vs the Declaration of Independence, with the companies asserting an authority to proceed in all cases whatsoever and an American public with different terms. Where this standoff goes remains to be decided.</p><p></p><h2>The genius of refusal</h2><p>In March 1783, with peace at hand, officers of the Continental Army were still upset &#8212; because they had not yet been paid. They <a href="https://www.mountvernon.org/library/digitalhistory/digital-encyclopedia/article/newburgh-conspiracy">gathered at Newburgh, New York</a> to weigh an ultimatum. If the war somehow continued, the ultimatum proposes the army abandon Congress and leave the country defenseless. If peace came, the ultimatum proposes a refusal to disband &#8212; a thinly veiled threat of military takeover.</p><p>General George Washington appeared unannounced at the gathering. &#8220;Gentlemen, you will permit me to put on my spectacles, for I have not only grown gray, but almost blind, in the service of my country&#8221;, Washington said. He urged the soldiers to work peacefully, which they did.</p><p>Nine months later, Washington traveled to Annapolis and <a href="https://history.house.gov/HistoricalHighlight/Detail/36498">resigned his commission</a> to the civilian Congress &#8212; the voluntary surrender of supreme military power by the man in American history best positioned to keep it. When King George III heard what Washington intended, <a href="https://www.loc.gov/exhibitions/two-georges/access-text/washington-resigns-and-george-iii-ponders-abdication/">he reportedly told the painter Benjamin West</a> that if Washington did it, he would be the greatest man in the world. Washington did it &#8212; and then did it again, walking away from the Presidency after two terms and fixing a precedent that held for 150 years.</p><p>The signature act of the American founding is not the seizure of power but  the relinquishment. Every republic before ours had eventually met its Caesar and the Founders realized that a true constitutional order must instill an allergy to power. Power must never be fully trusted &#8212; not because the powerful are unusually wicked, but because they are ordinarily human.</p><p>Now hold that tradition up against the AI race, whose public metric is to build as powerful as you can, as fast as you can. The leaders of the frontier companies say openly that their own products may become dangerous beyond precedent, but that they nonetheless can be trusted to do what is best for society and govern their tools appropriately, showing us their voluntary commitments, responsible scaling policies, and safety frameworks a company can revise at will.</p><p>Madison had a name for written limits unsupported by enforcement &#8212; <a href="https://avalon.law.yale.edu/18th_century/fed48.asp">&#8220;parchment barriers,&#8221;</a> which experience showed were &#8220;greatly overrated&#8221; against &#8220;the encroaching spirit of power.&#8221; The Founders would not have doubted the sincerity of those leading the AI companies. They would have asked what happens when the sincere man is replaced, outcompeted, or simply wrong &#8212; and instead insist that no single actor hold unilateral command. Many such &#8220;parchment barriers&#8221;, such as <a href="https://openai.com/index/evolving-our-structure/">OpenAI&#8217;s non-profit structure</a>, have already fallen to economic competition and other weaknesses of human will.</p><p>The industry already knows this lesson, yet seems to not yet understand it. J.R.R. Tolkien, an Oxford traditionalist who shared the Founders&#8217; allergy in full, wrote <em>The Lord of the Rings</em>, a story whose central discovery is that ultimate power cannot be safely wielded by anyone, for any end. Gandalf dares not take it, even to keep it safe; Galadriel passes her test by turning it down. The tragedy is Boromir, the sincere patriot who insists his people, uniquely, can wield the enemy&#8217;s weapon against him. In a 1943 letter to his son, Tolkien wrote that &#8220;the most improper job of any man, even saints... is bossing other men. Not one in a million is fit for it and least of all those who seek the opportunity.&#8221;</p><p>This is the book that AI leaders quote from &#8212; Sam Altman published a blog post reflecting that AGI <a href="https://blog.samaltman.com/2279512">&#8220;has a real &#8216;ring of power&#8217; dynamic to it, and makes people do crazy things&#8221;</a>. Elon Musk, an OpenAI co-founder turned rival similarly renders his verdict on Altman: <a href="https://www.rev.com/transcripts/dealbook-summit-2023-elon-musk-interview-transcript">&#8220;The ring of power can corrupt, and he has the ring of power&#8221;</a>, yet the irony is this statement was delivered from atop xAI, a competing AI company Musk had founded just months earlier.</p><p>Elon Musk and Sam Altman co-founded OpenAI out of their distrust of Google, Dario Amodei co-founded Anthropic out of his distrust of OpenAI, and Elon Musk co-founded xAI out of his distrust of Sam Altman &#8212; each person thinking they must pursue ultimate power lest someone less responsible pursue such power first. The Founders&#8217; answer is that there never will be one wise, benevolent AI company who can carry the Ring safely. Instead, we need Washington at Annapolis &#8212; a system where the Ring gets handed back to the people.</p><p></p><h2>Auxiliary precautions</h2><p>In <a href="https://avalon.law.yale.edu/18th_century/fed51.asp">Federalist No. 51</a>, James Madison wrote:</p><blockquote><p>If men were angels, no government would be necessary. If angels were to govern men, neither external nor internal controls on government would be necessary. In framing a government which is to be administered by men over men, the great difficulty lies in this: you must first enable the government to control the governed; and in the next place oblige it to control itself.</p></blockquote><p>Read with modern eyes, that is a near-perfect statement of what AI researchers call the <em><a href="https://en.wikipedia.org/wiki/AI_alignment">alignment problem</a></em> &#8212; the question of how to build a system powerful enough to be useful while ensuring it stays controllable and pursues the goals you intended. Madison&#8217;s premise is that you cannot rely on the good character of the agent, so you must rely on structure. A dependence on the people is the &#8220;primary control,&#8221; he wrote, &#8220;but experience has taught mankind the necessity of auxiliary precautions.&#8221;</p><p>Before the Convention, Madison systematically studied every ancient and modern confederacy he could find sources on, cataloguing their failure modes the way a safety team catalogues jailbreaks. Madison&#8217;s core mechanism, &#8220;ambition must be made to counteract ambition,&#8221; is adversarial oversight &#8212; set powerful agents against each other so none can dominate, and give each the means and motive to check the rest. Every claim that some class of people was wise enough to rule without a check has ended the same way.</p><p>However, these Madisonian mechanisms assume the contending powers are roughly comparable. A system or set of systems smarter, faster, and more coordinated than every institutional check simultaneously breaks the balancing machinery. This is what Madison feared most, one interest growing powerful enough that the precautions no longer successfully bind it.</p><p>The Founder&#8217;s machinery must be applied while it still can be. Checks and balances bind humans &#8212; humans can be voted out, subpoenaed, outcompeted, shamed, fired. For at least a few more years, the Ring is held entirely by humans &#8212; executives, boards, engineers, the officials who could govern them &#8212; and everything about them remains within reach of the oldest tools of the republic. The question is not whether the Constitution can restrain a superintelligence. It is whether the American people will assert their authority over the people building one, during the window in which those people can still be obliged to answer.</p><p></p><h2>The standing army</h2><p>None of this is an argument against permissionless innovation, which is genuinely one of America&#8217;s founding advantages. Nobody voted for the light bulb, the airplane, or the iPhone, and nobody needed to &#8212; a country that required a congressional blessing before every product launch would still be waiting for the telegraph. Permissionless innovation works because its failures are escapable: if the product is bad, you don&#8217;t buy it; if it harms you, you sue; if the company is reckless, it dies and the rest of us carry on. Consent is delivered continuously, through the market, one purchase and one lawsuit at a time.</p><p>The line is drawn where the consequences of failure stop being escapable. You can decline to buy a chatbot. You cannot decline to live in a world where millions of superintelligences have been deployed, any more than a Bostonian in 1770 could decline to live in an occupied city.</p><p>The Founders understood this distinction. They demanded no congressional renewal for gristmills or printing presses. But they put unprecedented Congressional control over one dual-use technology they could not live without but could not survive unchecked &#8212; the standing army. The Declaration indicts King George for exactly this: &#8220;He has kept among us, in times of peace, Standing Armies without the Consent of our legislatures,&#8221; and he has &#8220;affect[ed] to render the Military independent of and superior to the Civil Power.&#8221;</p><p>The Constitution took this most dangerous instrument in the republic and wrapped it in accountability to the people. Command was vested in an elected civilian, removable by the voters. Congress &#8212; not the generals &#8212; would raise the army, fund it, and declare its wars. And the Constitution declared that no appropriation for the army &#8220;shall be for a longer Term than two Years&#8221;, meaning that the army cannot exist by default. Its existence lapses, automatically, unless the people&#8217;s elected representatives affirmatively renew it. The most powerful force in the country lives on a two-year lease from the American people, and every soldier in it swears an oath not to a general but to the Constitution.</p><p>AI superintelligence risks enabling a similar permanent concentration of power exceeding the threat and promise of the standing army. The country may genuinely want such superintelligence for its prosperity and defense, but such superintelligence must be treated with similar deep suspicion, and must be safeguarded and stewarded with similar deep control and deep accountability.</p><p></p><h2>A Republic, if you can keep it</h2><p>For 250 years the threats to the republic were recognizably human &#8212; kings, factions, demagogues, foreign empires &#8212; and the machinery, creaky and patched, has held. When America turns 260, we may share the country with minds that exceed our own more thoroughly than the federal government exceeds any single citizen. Whether that goes well is a technical question but also a deeply political one. It echoes the questions the Founders answered at Newburgh, at Annapolis, at Philadelphia, and in the two-year lease they put on their own army. No power in America &#8212; however capable, however sincere, however useful &#8212; may be permitted to rule without the consent of the governed.</p><p>When Elizabeth Willing Powel asked Benjamin Franklin what the Convention had produced, he reportedly answered: &#8220;A republic, if you can keep it.&#8221; The technology is new but the problem remains the oldest one in our history. Those who can see what is coming should understand that we are not waiting for new wisdom. We are deciding, right now, whether to use the wisdom we&#8217;ve already inherited.</p><p>Happy Fourth of July.</p><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://blog.peterwildeford.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">The Power Law is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-1" href="#footnote-anchor-1" class="footnote-number" contenteditable="false" target="_self">1</a><div class="footnote-content"><p>I&#8217;m 50% sure we will have such &#8216;superintelligent&#8217; AI systems before the end of 2036 absent some major war or regulation disrupting current technological progress. Regardless, precise timelines are actually not relevant to the thesis of this essay.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-2" href="#footnote-anchor-2" class="footnote-number" contenteditable="false" target="_self">2</a><div class="footnote-content"><p>A truth the Founders articulated with painful clarity, and yet lived on the wrong side of.</p><p></p></div></div>]]></content:encoded></item><item><title><![CDATA[How banned AI chips end up in China]]></title><description><![CDATA[AI chips and servers reach China through distribution chains in which each seller vets only its direct customers, and no one is on the hook for what happens downstream.]]></description><link>https://blog.peterwildeford.com/p/how-banned-ai-chips-end-up-in-china</link><guid isPermaLink="false">https://blog.peterwildeford.com/p/how-banned-ai-chips-end-up-in-china</guid><dc:creator><![CDATA[Erich Grunewald]]></dc:creator><pubDate>Mon, 18 May 2026 10:36:44 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!7avc!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F491c578d-3c14-43b0-a0c6-adcd3ae8b336_1172x872.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!7avc!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F491c578d-3c14-43b0-a0c6-adcd3ae8b336_1172x872.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!7avc!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F491c578d-3c14-43b0-a0c6-adcd3ae8b336_1172x872.png 424w, https://substackcdn.com/image/fetch/$s_!7avc!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F491c578d-3c14-43b0-a0c6-adcd3ae8b336_1172x872.png 848w, https://substackcdn.com/image/fetch/$s_!7avc!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F491c578d-3c14-43b0-a0c6-adcd3ae8b336_1172x872.png 1272w, https://substackcdn.com/image/fetch/$s_!7avc!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F491c578d-3c14-43b0-a0c6-adcd3ae8b336_1172x872.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!7avc!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F491c578d-3c14-43b0-a0c6-adcd3ae8b336_1172x872.png" width="1172" height="872" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/491c578d-3c14-43b0-a0c6-adcd3ae8b336_1172x872.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:872,&quot;width&quot;:1172,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1199084,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://blog.peterwildeford.com/i/197924326?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F491c578d-3c14-43b0-a0c6-adcd3ae8b336_1172x872.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!7avc!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F491c578d-3c14-43b0-a0c6-adcd3ae8b336_1172x872.png 424w, https://substackcdn.com/image/fetch/$s_!7avc!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F491c578d-3c14-43b0-a0c6-adcd3ae8b336_1172x872.png 848w, https://substackcdn.com/image/fetch/$s_!7avc!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F491c578d-3c14-43b0-a0c6-adcd3ae8b336_1172x872.png 1272w, https://substackcdn.com/image/fetch/$s_!7avc!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F491c578d-3c14-43b0-a0c6-adcd3ae8b336_1172x872.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><em>This is a guest post written by Erich Grunewald, a prior &#8220;Power Law&#8221; contributor who writes on AI and compute topics at <strong><a href="https://www.the-substrate.net/">The Substrate</a></strong>. This post is crossposted from there. <a href="https://www.the-substrate.net/p/how-banned-ai-chips-end-up-in-china">Check it out</a>!</em></p><p><em>~</em></p><p>AI chips are being smuggled<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-1" href="#footnote-1" target="_self">1</a> into China. How does this happen? That is, how are the smugglers able to do it?</p><p>You might, for example, expect that sales of these chips could be vetted, and shipments tracked, by US authorities. But the relevant US agency is <a href="https://www.the-substrate.net/p/bis-is-getting-more-fundingheres">badly understaffed</a>: it cannot possibly vet every sale of AI chips, let alone follow up after every sale to ensure the chips have not been smuggled. So enforcement is largely left to the companies that sell and resell the chips. You might then suppose that these companies would vet their customers and monitor their distribution networks to ensure none of their chips are diverted, in order to comply with the law. But they are not strongly incentivized to do the due diligence needed to prevent most smuggling.</p><p>In this post, I&#8217;ll explain (1) why AI chip smuggling matters, (2) how AI chips and servers are sold and distributed, (3) what due diligence the exporting companies do, and (4) why those efforts often fail to prevent smuggling. In a nutshell, AI chips and servers are distributed through different channels, usually passing through multiple intermediaries across multiple countries. While most companies selling these products perform sufficient due diligence to comply with the law, others are outright negligent, and overall these efforts are not sufficient to prevent most smuggling.</p><h1><br>How big a problem is AI chip smuggling?</h1><p>Smuggling is a pretty big problem, though not serious enough to make the AI chip controls ineffective. In <a href="https://epoch.ai/blog/chip-smuggling">a new report</a>, Epoch AI says that</p><blockquote><p>between 290,000 and 1.6 million H100-equivalents (H100e) were smuggled to China through 2025. Our median estimate of 660,000 H100e would be roughly a third of China&#8217;s total compute.</p></blockquote><p>US authorities recently indicted three people, including two insiders at Super Micro, a major American AI server builder, for moving $2.5 billion worth of AI servers to a shell company for diversion to China, the largest-ever export control violation in dollar terms, as far as I can tell. Over the past year, the US has announced six prosecutions for smuggling AI chips to China, totaling about $3 billion worth of NVIDIA products. And before that, there were many reports, rumors, and analyses pointing to <a href="https://www.cnas.org/publications/reports/countering-ai-chip-smuggling-has-become-a-national-security-priority">large-scale smuggling of AI chips</a>.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!GsTP!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca31eab6-8cec-47ff-8f36-95dea7dfb327_784x390.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!GsTP!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca31eab6-8cec-47ff-8f36-95dea7dfb327_784x390.png 424w, https://substackcdn.com/image/fetch/$s_!GsTP!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca31eab6-8cec-47ff-8f36-95dea7dfb327_784x390.png 848w, https://substackcdn.com/image/fetch/$s_!GsTP!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca31eab6-8cec-47ff-8f36-95dea7dfb327_784x390.png 1272w, https://substackcdn.com/image/fetch/$s_!GsTP!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca31eab6-8cec-47ff-8f36-95dea7dfb327_784x390.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!GsTP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca31eab6-8cec-47ff-8f36-95dea7dfb327_784x390.png" width="784" height="390" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ca31eab6-8cec-47ff-8f36-95dea7dfb327_784x390.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:390,&quot;width&quot;:784,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!GsTP!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca31eab6-8cec-47ff-8f36-95dea7dfb327_784x390.png 424w, https://substackcdn.com/image/fetch/$s_!GsTP!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca31eab6-8cec-47ff-8f36-95dea7dfb327_784x390.png 848w, https://substackcdn.com/image/fetch/$s_!GsTP!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca31eab6-8cec-47ff-8f36-95dea7dfb327_784x390.png 1272w, https://substackcdn.com/image/fetch/$s_!GsTP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca31eab6-8cec-47ff-8f36-95dea7dfb327_784x390.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption"><em>Surveillance photos of dummy servers being relabeled with a hair dryer the day before an inspection by a US agent, from the indictment of the $2.5 billion Super Micro insider case.</em></figcaption></figure></div><p><a href="https://www.the-substrate.net/p/where-will-china-get-its-compute">I don&#8217;t think</a> smuggling is a large enough problem to make the AI chip export controls ineffective overall. The controls have likely played a large role in maintaining the US lead over China in AI and may even have widened the gap in frontier performance. For example, <a href="https://www.nist.gov/news-events/news/2026/05/caisi-evaluation-deepseek-v4-pro">a recent benchmark evaluation</a> by the Center for AI Standards and Innovation (CAISI) suggests that Chinese models trail US models by about eight months, with the lag growing by about three months per year.<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-2" href="#footnote-2" target="_self">2</a> And you can make a strong case for prioritizing <a href="https://www.congress.gov/bill/119th-congress/house-bill/8170/text">efforts</a> to shore up <a href="https://www.iaps.ai/research/semiconductor-manufacturing-equipment-export-controls">semiconductor manufacturing controls</a> over efforts to address AI chip smuggling. But smuggling is still a serious and urgent problem.</p><p>According to CAISI, the best Chinese model today is DeepSeek-V4. DeepSeek has reportedly <a href="https://www.theinformation.com/articles/deepseek-using-banned-nvidia-chips-race-build-next-model">used thousands of smuggled NVIDIA Blackwell</a> chips. I think it&#8217;s likely that DeepSeek-V4 was trained on NVIDIA chips.<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-3" href="#footnote-3" target="_self">3</a> If DeepSeek didn&#8217;t have access to smuggled NVIDIA chips, it would likely have had to either rely on renting cloud access from chips installed outside China (which is risky from DeepSeek&#8217;s perspective because the US government could revoke remote access to those chips) or use indigenously made AI chips like Huawei Ascends to train smaller, weaker models. DeepSeek <a href="https://www.ft.com/content/eb984646-6320-4bfe-a78d-a1da2274b092?syn-25a6b1a6=1">reportedly tried</a> to train V4 on Ascend chips but abandoned the attempt after a failed training run, reverting to NVIDIA for training while supporting Ascend for inference.<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-4" href="#footnote-4" target="_self">4</a> So even though smuggled chips account for <a href="https://epoch.ai/blog/chip-smuggling">only about 3%</a> of the global compute stockpile, they represent about a third of China&#8217;s compute, which is why smuggling still matters.</p><h1><br>AI chips are distributed through many intermediaries</h1><p>The basic smuggling playbook works like this. A smuggler buys AI chips through a shell or front company (often in a third country<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-5" href="#footnote-5" target="_self">5</a> but sometimes in the US), relabels them as some other product, and ships them to China through ordinary shipping services. (For example, in several cases, smugglers appear to have bought AI servers through front companies set up to look like Singaporean, Malaysian, Thai, and Indonesian neoclouds.<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-6" href="#footnote-6" target="_self">6</a>) Once a smuggler has the chips, getting them into China seems quite easy, so I&#8217;ll focus here on how smugglers get hold of them in the first place.</p><p>AI chips routinely pass through multiple actors and countries before they are installed and used in data centers. We can refer to all actors who sell AI chips as &#8220;AI chip sellers&#8221;. They are:</p><ul><li><p><strong>AI chip designers, such as NVIDIA and AMD.</strong> These companies design AI chips, but they do not manufacture anything. NVIDIA <a href="https://arxiv.org/abs/2402.08797">holds an estimated</a> 80-95% of the AI chip market share.<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-7" href="#footnote-7" target="_self">7</a></p></li><li><p><strong>AI server builders (also known as original equipment manufacturers, or OEMs), such as Super</strong> <strong>Micro and Dell.</strong> These companies buy AI chips from AI chip designers and design and manufacture AI servers, each typically containing four to eight AI chips. The servers are shipped to data centers and installed in cabinets. Notable AI server builders include Super Micro (US, about 10% of NVIDIA&#8217;s revenue), Dell (US, ~3%), Wiwynn (Taiwan, ~3%), Lenovo (China/US, ~1%), Gigabyte (Taiwan, ~1%), Hewlett Packard Enterprise (US, &lt;1%), and Inspur (China, &lt;1%). (Why do these companies not make up more of NVIDIA&#8217;s revenue? That&#8217;s because AI chip designers like NVIDIA often sell chips directly to hyperscalers and neoclouds. In such cases, though the servers are assembled by original design manufacturers (ODMs), the transaction occurs directly between NVIDIA and the end customer. Hyperscalers and neoclouds make up about half of NVIDIA&#8217;s revenue.)</p></li><li><p><strong>Distributors, such as TD Synnex and Ingram Micro.</strong> These large, multinational companies are intermediaries that handle logistics and warehousing of AI chips and AI servers. The key distributors are TD Synnex (&lt;1% of NVIDIA&#8217;s revenue), Ingram Micro (&lt;1%), and Arrow Electronics (&lt;1%), all headquartered in the US but with extensive operations worldwide.<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-8" href="#footnote-8" target="_self">8</a></p></li><li><p><strong>Resellers.</strong> These companies, which are numerous and often small and local, buy AI chips and servers from distributors and sell them to end customers in the country or countries where they operate.</p></li></ul><p>Before being sold, AI chips are made. For example, most of NVIDIA&#8217;s AI chips are designed by NVIDIA in the US, fabricated by TSMC in Taiwan, packaged with <a href="https://ai-frontiers.org/articles/high-bandwidth-memory-critical-gaps-us-export-controls">high-bandwidth memory</a> by TSMC in Taiwan, <a href="https://www.datacenterdynamics.com/en/news/packaging-testing-companies-scrambling-to-meet-demand-for-nvidia-blackwell-gpus/">tested by KYEC</a> in Taiwan, and then either (a) <a href="https://newsletter.semianalysis.com/p/tariff-armageddon-gpu-loopholes">assembled</a> into <a href="https://en.wikipedia.org/wiki/SXM_(socket)">SXM modules</a> by Foxconn in Taiwan and mounted onto HGX baseboards by Foxconn and Wistron in Taiwan, or (b) assembled into PCIe cards (i.e., accelerators) by Foxconn, and possibly others, again in Taiwan.</p><p>From there, the chips<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-9" href="#footnote-9" target="_self">9</a> can get to their end customers in a few different ways:</p><ol><li><p><strong>AI accelerators can be sold to minor end customers through distributors and resellers.</strong> In the simplest case, a company like NVIDIA sells AI accelerators to distributors, who in turn sell them to resellers, who then sell them to end customers. The end customer can then use the accelerators however they wish, for example, by installing them themselves in workstations or servers customized to their preferences. However, this pathway is quite rare, as most customers want AI servers ready for installation in data centers.</p></li><li><p><strong>AI servers can be sold to minor end customers via distributors and resellers.</strong> For example, NVIDIA may sell AI chips (usually in the form of SXM modules mounted on baseboards) to Super Micro, which builds AI servers using them and sells these servers to a distributor. The distributor then sells to a reseller, which sells to an end customer.</p></li><li><p><strong>AI servers can be sold to major end customers directly by AI server makers.</strong> Hyperscalers and neoclouds often purchase very large quantities of AI servers directly from server makers, bypassing distributors and resellers. For large orders of NVIDIA servers, this often involves a three-party negotiation among the customer, the server maker, and NVIDIA.</p></li><li><p><strong>AI servers can be sold to major end customers directly by AI chip designers.</strong> In the case of NVIDIA, hyperscalers and neoclouds can buy AI servers directly from NVIDIA instead of from server makers. (The NVIDIA-designed servers are called DGX, while the OEM-designed servers are called HGX.) As mentioned above, these servers are built by ODMs for NVIDIA.</p></li></ol><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!eg0B!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9bbef36d-6223-41c8-8f99-c65ddf6134b1_2048x949.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!eg0B!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9bbef36d-6223-41c8-8f99-c65ddf6134b1_2048x949.png 424w, https://substackcdn.com/image/fetch/$s_!eg0B!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9bbef36d-6223-41c8-8f99-c65ddf6134b1_2048x949.png 848w, https://substackcdn.com/image/fetch/$s_!eg0B!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9bbef36d-6223-41c8-8f99-c65ddf6134b1_2048x949.png 1272w, https://substackcdn.com/image/fetch/$s_!eg0B!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9bbef36d-6223-41c8-8f99-c65ddf6134b1_2048x949.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!eg0B!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9bbef36d-6223-41c8-8f99-c65ddf6134b1_2048x949.png" width="1456" height="675" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9bbef36d-6223-41c8-8f99-c65ddf6134b1_2048x949.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:675,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!eg0B!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9bbef36d-6223-41c8-8f99-c65ddf6134b1_2048x949.png 424w, https://substackcdn.com/image/fetch/$s_!eg0B!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9bbef36d-6223-41c8-8f99-c65ddf6134b1_2048x949.png 848w, https://substackcdn.com/image/fetch/$s_!eg0B!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9bbef36d-6223-41c8-8f99-c65ddf6134b1_2048x949.png 1272w, https://substackcdn.com/image/fetch/$s_!eg0B!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9bbef36d-6223-41c8-8f99-c65ddf6134b1_2048x949.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Most AI chips are likely sold to major end customers like hyperscalers, either directly from NVIDIA or directly from AI server makers. However, most smuggling likely involves smaller order volumes, with bad actors buying AI chips and AI servers either from AI server makers or from smaller resellers. So bad actors don&#8217;t purchase AI chips directly from AI chip designers like NVIDIA. Of the six cases that have been prosecuted by the US:</p><ul><li><p>Four involved smugglers buying AI servers and HGX baseboards from AI server makers (Super Micro and Lenovo)</p></li><li><p>One involved smugglers buying AI chips and AI servers (the latter made by Hewlett Packard Enterprise) from an Alabama reseller</p></li><li><p>One involved intermediaries storing goods from multiple suppliers, including SXM modules from a Massachusetts reseller and HGX baseboards from Lenovo (the same Lenovo purchases mentioned above)</p></li></ul><p>These are all cases in which the smugglers were at least partly based in the US and procured AI chips from US sellers. Most smuggling likely involves actors based abroad who buy from local sellers or import from US sellers, but these cases are harder for US authorities to detect and prosecute.<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-10" href="#footnote-10" target="_self">10</a></p><h1><br>How AI chip sellers (try to) vet their customers</h1><p>AI chips are export-controlled, meaning they cannot be sold to just any customer. For example, it is illegal<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-11" href="#footnote-11" target="_self">11</a> to sell them to companies headquartered in China or listed on BIS-maintained lists, such as the Entity List or the Military End-User List. So when selling AI chips, companies need to conduct due diligence to ensure they are not selling to any such customer.</p><p>Most AI chips are likely sold by AI server makers, and a lot of smuggling seems to involve smugglers buying from server makers, so the remainder of this section focuses on them.<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-12" href="#footnote-12" target="_self">12</a> From the point of view of AI server makers, the sales process lasts months and roughly follows these steps:</p><ol><li><p>Talk with the customer about their requirements</p></li><li><p>Run software tools that gather data about the customer&#8217;s environment (i.e., data center)</p></li><li><p>Negotiate prices (changing server components and/or order volumes if necessary)</p></li><li><p>Prepare a contract (stipulating who the end customer is, where the servers are to be shipped, and who will install the servers)</p></li><li><p>Do due diligence</p></li><li><p>Build, box, and ship the products</p></li></ol><p>Server makers track items at the serial number level using enterprise resource planning (ERP) software (e.g., SAP or Oracle). AI chip designers and distributors likely do too, though I&#8217;m not sure to what extent resellers do so (since they are smaller, less resourced, and less well-organized). When an order is placed, the salesperson enters it into the ERP system, and it is then routed to the appropriate factory or factories responsible for assembling, testing, boxing, and (once the order is paid) shipping the hardware to the customer. Server makers also have some visibility into their partner distributors&#8217; inventory, since distributors typically hold a lot of the parts used by server makers. These parts (e.g., AI chips) can then be sent to the server maker for assembly when a customer makes an order via a reseller.<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-13" href="#footnote-13" target="_self">13</a></p><p>From a smuggling perspective, we&#8217;re mostly interested in the due diligence step of the sales process. First, some definitions:</p><ul><li><p><em>Compliance</em> is overall adherence to regulations</p></li><li><p><em>Due diligence</em> is the process of investigating and assessing risk related to a transaction, aimed at ensuring compliance</p></li><li><p><em>Know Your Customer</em> (KYC) processes are part of due diligence in which a company verifies a customer&#8217;s identity and assesses their risk level. There are several risks that sellers aim to avoid here, not only legal ones (e.g., by selling to a sanctioned customer) but also commercial ones, such as ensuring the customer can pay (counterparty credit risk).</p></li></ul><p><strong>AI chip designers, server makers, and distributors do fairly extensive compliance checks, but these checks seem mostly (and reasonably) aimed at (1) complying with the law, and (2) ensuring they get paid.</strong> AI chip sellers seem to differ a lot in both what they do to stay compliant and how effectively they do it, but they typically:</p><ul><li><p>Conduct KYC checks to ensure the prospective buyer is not a shell or front company and can pay for the order. That means the seller asks the company for information, e.g., legal name, corporate structure, location (including county/region), date of registration, affiliations, and operational history (e.g., bank statements, balance sheets). The seller will also, at least sometimes, ask local commerce ministries for information, check trade registries, and/or do other due diligence to verify some of that information.</p></li><li><p>Ask the prospective buyer to provide a signed <a href="https://en.wikipedia.org/wiki/End-user_certificate">end-user certificate</a> <a href="https://www.ecfr.gov/current/title-15/subtitle-B/chapter-VII/subchapter-C/part-748/section-748.11">detailing</a> how the purchase fits their business and how, where (down to the county/region level), and by whom<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-14" href="#footnote-14" target="_self">14</a> the products will be used. A former HPE salesperson told me that &#8220;the primary way companies prevent chip smuggling is to ensure that we know the end destination of a system before we accept and ship an order&#8221;, but added that most of what determines the destination &#8220;is what the customer or the partner tells us&#8221;.</p></li><li><p>Screen against <a href="https://www.trade.gov/consolidated-screening-list">lists</a> (the Entity List, the Unverified List, the Military End-User List, and a few others)</p></li><li><p>Check for <a href="https://www.ecfr.gov/current/title-15/subtitle-B/chapter-VII/subchapter-C/part-732/appendix-Supplement%20No.%203%20to%20Part%20732">BIS&#8217;s red flags</a></p></li><li><p>Request a license from BIS if necessary</p></li></ul><p>For large companies like NVIDIA and the server makers and distributors discussed here, these due diligence processes are largely handled by a centralized compliance team. (But salespeople also have some responsibilities; for example, according to a former Super Micro employee, its sales reps attended mandatory weekly meetings drilling them on export compliance requirements, though these sessions did not seem to prevent smuggling.) The compliance team will usually be located in the US, and end-user certificates and other documents are typically sent to it for approval, even for transactions handled by salespeople outside the US. The compliance team also does internal audits and trains the company&#8217;s sales, legal, finance, and shipping staff. In the $2.5 billion insider case, Super Micro&#8217;s compliance team did notice a fast-growing customer&#8217;s anomalous order volume and ran successive audits, although those audits were allegedly sabotaged from within the sales organization by senior Super Micro employees who arranged &#8220;friendly&#8221; auditors, falsified the customer&#8217;s data center lease agreements, and arranged warehouses with thousands of dummy servers to (successfully) subvert a Super Micro compliance inspection.</p><p>Sometimes, part of the due diligence process is carried out by third parties or through tools and data services they provide. These include <a href="https://www.aeb.com/en/compliance-screening/index.php">AEB</a>, <a href="https://www.e2open.com/global-trade/">e2open</a>, <a href="https://www.descartes.com/">Descartes</a>, <a href="https://www.dowjones.com/professional/risk/">Dow Jones</a>, <a href="https://www.dnb.com/products/dnb-compliance-intelligence.html">Dun &amp; Bradstreet</a>, <a href="https://www.kharon.com/">Kharon</a>, <a href="https://www.lexisnexis.com/">LexisNexis</a>, <a href="https://sayari.com/">Sayari</a>, <a href="https://www.striderintel.com/">Strider</a>, <a href="https://legal.thomsonreuters.com/en/risk-fraud-investigations/risk-compliance-management">Thomson Reuters</a>, and <a href="https://wirescreen.ai/">WireScreen</a>. These tools can automate parts of the due diligence process and are integrated with the ERP system. These third parties can also help validate end-user certificates, conduct background checks on buyers, perform list screening, and more.<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-15" href="#footnote-15" target="_self">15</a></p><p>Some AI chip sellers seem to be happy to stick to these common activities, but others also do fairly extensive post-sale monitoring, e.g., one server maker (according to a former employee I spoke with) would also periodically follow up with the customer on a call to verify that the chips are used as intended; require the end-user certificate to be renewed every six months; negotiate the right to perform on-site inspections for large or high-security sales; and occasionally redo the list-based screening to check that the customer hasn&#8217;t been added since.</p><p>NVIDIA and its partners also carry out on-site inspections, at least occasionally.<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-16" href="#footnote-16" target="_self">16</a> As mentioned, in the $2.5 billion Super Micro case, smugglers fooled the compliance team with insider help. In another case, the seller&#8217;s employees visited a data center where the chips were installed, although it turned out the smuggler had only temporarily installed them to fool the inspectors; after the inspection, the chips were removed and shipped to China.</p><h1><br>AI chip sellers aren&#8217;t incentivized enough to stop smuggling</h1><p>AI chip sellers usually only conduct due diligence for their immediate customers; they rarely conduct due diligence for their customers&#8217; customers, or follow up to see what happens to the AI chips after they&#8217;ve been sold and shipped (with the notable exception of the on-site inspections mentioned above).</p><p>There are two important dynamics here that both enable AI chip smuggling:</p><ul><li><p><strong>Sometimes, major AI chip sellers (notably, Super Micro) do not conduct sufficient due</strong> <strong>diligence even for their immediate customers.</strong> This can lead them to sell AI chips directly to smugglers. I&#8217;ll discuss this further below.</p></li><li><p><strong>Sometimes, major AI chip sellers </strong><em><strong>do</strong></em><strong> conduct sufficient due diligence for their immediate</strong> <strong>customers, but downstream sellers don&#8217;t.</strong> That is because, by the time the chips are sold to a smuggler (meaning someone didn&#8217;t do a good job of due diligence), they have typically passed through multiple hands, often ending up with resellers or other middlemen in countries such as Malaysia, Singapore, or Thailand.</p></li></ul><p>AI chip sellers in third countries are far less incentivized to comply with US law, since it&#8217;s harder for US authorities to detect compliance failures outside the US and to prosecute illegal activities that occurred abroad, especially when the companies involved have no US presence or exposure. In addition, small resellers likely have especially weak due diligence processes because:</p><ul><li><p>They have limited resources to use for due diligence</p></li><li><p>There are many of them, located in different countries, so there is likely more variance in how well they do compliance, or how willing they are to sell to smugglers</p></li><li><p>They often lack any US presence, meaning transactions are approved entirely outside the US, which matters if non-US personnel are less likely than US-based personnel to comply with US export law</p></li><li><p>They may be less responsive to the incentive produced by the risk of being fined for export violations, since the fines involved would likely be far higher than what these companies are able to pay</p></li></ul><p>Resellers have a lot on the line because if they aren&#8217;t compliant, they risk losing their contract with the distributor, which can be a huge deal for these businesses. That said, I think the factors listed above outweigh this consideration. In particular, I would guess that distributors are doing little to ensure their partner resellers are doing good due diligence, as distributors would generally not be liable for selling AI chips to resellers even if those resellers have poor due diligence standards, resulting in smuggling down the line.</p><p>Meanwhile, the major AI chip and server sellers, like NVIDIA and Super Micro, are required by law to monitor for red flags and to avoid selling to obviously sanctioned or prohibited customers, but they&#8217;re not asked to ensure, in the strictest sense, that their products are never smuggled. They are potentially liable if they have &#8220;knowledge&#8221; of a violation&#8212;<a href="https://www.ecfr.gov/current/title-15/subtitle-B/chapter-VII/subchapter-C/part-772/section-772.1">including</a> &#8220;an awareness of a high probability of its existence or future occurrence&#8221;&#8212;which can result in civil penalties, but for BIS (or rather: the Department of Justice) to administer <em>criminal</em> penalties like prison time, the accused must have been shown to have &#8220;willfully&#8221; caused a violation, a much higher bar. (Multiple AI chip smuggling cases have been prosecuted criminally over the past year, but these cases often involve text messages showing that the smugglers were fully aware that their activities were illegal and were actively involved in the operations. For example, in one case, a smuggler told his co-conspirator over WeChat to remove mentions of Chinese customers from a draft solicitation message because, in his words, &#8220;We will draw [attention] from US government for [embargo] violation&#8221;, reassuring him in the next message that &#8220;We just talk about it, no one can hold it as [evidence] against us.&#8221; I think most smugglers aren&#8217;t so careless.)</p><p>More importantly, major AI chip sellers often don&#8217;t have even &#8220;an awareness of a high probability&#8221; of violations, because chips routinely pass through long distribution chains before reaching an end user, and sellers don&#8217;t ordinarily have visibility into who that end user is. For example, a former Super Micro employee told me that while server makers and distributors would know who they sold to, beyond that, any forensic trail would go dark. That means civil penalties are also often out of the question for these large companies.<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-17" href="#footnote-17" target="_self">17</a></p><p><strong>Super Micro shows that even major US companies can perform poor due diligence.</strong><a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-18" href="#footnote-18" target="_self">18</a> Super Micro appears as the upstream seller in three separate prosecutions over the past year:</p><ul><li><p>The $2.5 billion insider case described above</p></li><li><p>A case in which Super Micro sold 205 H100s to a California front company that fed it false end-user information, including a Singapore &#8220;end user&#8221; called Metacarbon that BIS later determined did not exist at the address Super Micro had on file</p></li><li><p>A case in which Super Micro almost shipped $170 million of servers to a Georgia-based front, after NVIDIA employees in Thailand independently discovered that the claimed Thai end user had never heard of the order</p></li></ul><p>Two things stand out across these cases. First, Super Micro&#8217;s end-user vetting accepted signed certifications and paper documentation without independent verification that the customer existed as a going concern at the claimed location. Second, in the cases where smuggling was caught, the decisive intervention came from outside the standard process&#8212;from a BIS notification that diversion was occurring, from a BIS post-shipment verification, or from NVIDIA&#8217;s own scrutiny&#8212;rather than from Super Micro&#8217;s compliance team independently working backward from red flags it had spotted itself.</p><p>It&#8217;s true that in the $2.5 billion insider case, the smugglers were not outsiders gaming an unwitting company, but included a Super Micro co-founder and board member who oversaw global sales, as well as a general manager in Super Micro&#8217;s Taiwan office. This is likely not normal for major US companies, and would have made it harder for Super Micro&#8217;s compliance team to do its work. The indictment shows the insiders repeatedly pressuring, sidestepping, and physically deceiving the compliance team across at least three audits in 2024 and 2025.</p><p>Even so, Super Micro&#8217;s compliance processes were clearly inadequate throughout this case:</p><ul><li><p>Super Micro&#8217;s sales organization was able to influence its internal audits. Sales staff, who have a clear conflict of interest, managed to arrange which auditor would conduct a given review (at least one was described in writing by an insider as &#8220;friendly&#8221;) and in the most extreme instance, the auditor tasked with conducting an on-site inspection was instead off-site, enjoying entertainment paid for by the very customer he was supposed to be auditing, while photos and videos of staged dummy servers were sent to him in lieu of an actual inspection.<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-19" href="#footnote-19" target="_self">19</a></p></li><li><p>Internal audits relied on documents that the customer itself supplied, without independent checks. When the compliance team asked the customer to demonstrate that it had enough data center space to store the volumes it was buying, the team accepted lease agreements that turned out to be falsified.</p></li><li><p>When the compliance team noticed that the customer was buying in large volumes without clearly operating at a commensurate scale, it failed to act decisively. For example, one Singapore entity seems to have gone from a $33 million balance sheet at year-end 2023 to $3 billion (90x) by year-end 2024, driven almost entirely by $2.9 billion in &#8220;refundable deposits received&#8221; from an undisclosed source (allegedly Alibaba).<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-20" href="#footnote-20" target="_self">20</a> In a single quarter, the customer ranked as Super Micro&#8217;s eleventh-most-profitable worldwide, sitting &#8220;alongside major US technology and social media companies developing hyperscale artificial intelligence infrastructure&#8221;, even though, per the indictment, it &#8220;did not have the capacity to store or use the massive quantities of servers it was purchasing&#8221;. Though the compliance team twice placed temporary holds on shipments, it released each hold after receiving explanations from the customer that it had no way to independently verify. For example, after one temporary hold, one smuggler urged a co-conspirator that &#8220;[y]ou need to have strong and persuasive reasons to convince [Super Micro&#8217;s] staffs!&#8221;, and once their drafted answers were accepted by the compliance team, the co-conspirator messaged the group, &#8220;Heheheh, Gooood news for everyone!&#8221;</p></li></ul><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ERd4!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F845ca3dc-8514-4e89-a79a-4ecb604aaef5_756x354.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ERd4!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F845ca3dc-8514-4e89-a79a-4ecb604aaef5_756x354.png 424w, https://substackcdn.com/image/fetch/$s_!ERd4!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F845ca3dc-8514-4e89-a79a-4ecb604aaef5_756x354.png 848w, https://substackcdn.com/image/fetch/$s_!ERd4!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F845ca3dc-8514-4e89-a79a-4ecb604aaef5_756x354.png 1272w, https://substackcdn.com/image/fetch/$s_!ERd4!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F845ca3dc-8514-4e89-a79a-4ecb604aaef5_756x354.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ERd4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F845ca3dc-8514-4e89-a79a-4ecb604aaef5_756x354.png" width="756" height="354" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/845ca3dc-8514-4e89-a79a-4ecb604aaef5_756x354.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:354,&quot;width&quot;:756,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ERd4!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F845ca3dc-8514-4e89-a79a-4ecb604aaef5_756x354.png 424w, https://substackcdn.com/image/fetch/$s_!ERd4!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F845ca3dc-8514-4e89-a79a-4ecb604aaef5_756x354.png 848w, https://substackcdn.com/image/fetch/$s_!ERd4!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F845ca3dc-8514-4e89-a79a-4ecb604aaef5_756x354.png 1272w, https://substackcdn.com/image/fetch/$s_!ERd4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F845ca3dc-8514-4e89-a79a-4ecb604aaef5_756x354.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption"><em>Warehouses stacked with dummy servers staged for Super Micro&#8217;s compliance team, from the indictment of the $2.5 billion insider case.</em></figcaption></figure></div><p>I think most other major US AI chip sellers perform better due diligence than Super Micro, which seems to have unusually poor corporate governance. But Super Micro&#8217;s poor governance has been known for years and has still endured.<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-21" href="#footnote-21" target="_self">21</a> Clearly, US authorities should not assume that there will never be any companies with poor governance. Instead, they should create incentives for all relevant companies to carry out strong due diligence.</p><h1><br>Companies could take concrete steps to reduce smuggling</h1><p>AI chips reach Chinese end users not because any single seller waves them through, but because the distribution chain has many links&#8212;AI chip designer, server maker, distributor, reseller, end user&#8212;and each link conducts due diligence only on its immediate counterparty. Because legal liability for diversion attaches only to <a href="https://www.ecfr.gov/current/title-15/part-772#p-772.1(Knowledge)">&#8220;knowledge&#8221;</a> and sellers&#8217; visibility into where the chips end up decreases as the chips move down the chain, the equilibrium is one in which every individual transaction with a US seller can be compliant, yet large numbers of chips still end up in China. This problem won&#8217;t solve itself.</p><p>I think AI chip sellers could do a lot more here if they were sufficiently incentivized. For example, NVIDIA could implement <a href="https://www.iaps.ai/research/location-verification-for-ai-chips">delay-based location verification</a> on its AI chips and contractually require customers to periodically report the chips&#8217; location. If any chips go dark, NVIDIA could follow up with an on-site inspection, potentially refuse to sell to that customer in the future, and report its findings to US authorities. Another promising approach is to conduct on-site inspections regularly&#8212;say, every six months&#8212; to make sure chips are not just installed to fool inspectors and then removed and smuggled, as has happened before. However, conducting on-site inspections at this scale would likely require additional budget for export enforcement, or for US authorities to implement <a href="https://www.iaps.ai/research/export-auditors-as-market-powered-export-enforcement">a third-party export auditor program</a>.</p><p>But I think the most effective thing the major American AI chip sellers could do is to sell only to a select few, highly trustworthy end users, especially US hyperscalers and neoclouds. AI chip sellers are unlikely to do this voluntarily, so in practice, this would mean the US government setting up a formal, low-discretion process for becoming an authorized AI chip importer abroad, where companies are evaluated on the risk of diversion. (Shipments below a certain volume could be exempted, so that anyone could import small quantities without a license.) These authorized companies will almost certainly not divert any chips, and they can <a href="https://www.rand.org/pubs/commentary/2025/08/america-should-rent-not-sell-ai-chips-to-china.html">rent the AI chips</a><a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-22" href="#footnote-22" target="_self">22</a> either on a short-term basis or with longer-term allocations to any end user in the US or abroad. (If small resellers located in third countries perform poor due diligence, this would no longer matter, because the AI chips would remain in the hands of trusted companies throughout, from AI chip designers and server makers to authorized hyperscalers and neoclouds.) There likely aren&#8217;t any regulatory barriers to doing this, since US companies can operate data centers abroad, and foreign companies would also be eligible if they are bona fide. I think this policy, if implemented, would essentially solve the AI chip smuggling problem.</p><p>In addition, US authorities could require specific due diligence measures in addition to what companies already do (<a href="https://www.semiconductors.org/the-critical-effort-to-combat-illicit-chip-diversion/">&#8220;compliance-plus&#8221;</a>), such as repeated, random, unannounced on-site inspections for sales to less obviously bona fide customers. Alternatively, the US could adopt a surety bond system, as Onni described in <a href="https://www.the-substrate.net/p/a-sketch-of-market-based-export-controls">a previous post</a>. Finally, <a href="https://www.the-substrate.net/p/the-case-for-paying-whistleblowers">strong whistleblower incentives</a> could help detect and prosecute smuggling by surfacing high-quality leads from insiders. Among other benefits, these policies would encourage companies to strengthen their due diligence practices.</p><p>~</p><p><em>If you liked this post, consider subscribing to <strong><a href="https://www.the-substrate.net/">The Substrate</a></strong> where Erich and others will be writing more about AI and compute topics.</em></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.the-substrate.net/&quot;,&quot;text&quot;:&quot;Subscribe to The Substrate&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.the-substrate.net/"><span>Subscribe to The Substrate</span></a></p><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-1" href="#footnote-anchor-1" class="footnote-number" contenteditable="false" target="_self">1</a><div class="footnote-content"><p>By &#8220;AI chip smuggling&#8221;, I mean the illegal physical transport of AI chips across borders into a country to which export is legally prohibited, such as China or Russia. This doesn&#8217;t include the entirely legal situation where Chinese companies rent access to AI chips remotely, for example, ByteDance renting access to AI chips located in Malaysia.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-2" href="#footnote-anchor-2" class="footnote-number" contenteditable="false" target="_self">2</a><div class="footnote-content"><p>As far as I can tell, CAISI doesn't report the slopes of the regressions, but from eyeballing the plot, it looks like the US is gaining about 52 Elo per month while China is gaining about 38 Elo per month, so the gap between the two trend lines widens by roughly 14 Elo per month, or ~170 per year. (Elo is a rating system where competitors exchange points after each head-to-head matchup, with bigger transfers for more surprising results. It was originally developed for chess, but in this case, the competitors are AI models and the matchups are benchmark tasks.) Translating that into months of lag (in the same sense as CAISI's eight-month figure, which seems to measure how far back the US trend line crossed today's PRC capability level) means dividing by the US slope of 52, giving a lag that grows by about three months per year.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-3" href="#footnote-anchor-3" class="footnote-number" contenteditable="false" target="_self">3</a><div class="footnote-content"><p>The DeepSeek-V4 announcements and technical paper did not specify which chips were used for training. If it had been trained with domestic Huawei chips, DeepSeek would likely have announced that proudly, as it did when it announced that V4 was optimized for inference using Huawei Ascends (in addition to being optimized for inference on NVIDIA chips).</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-4" href="#footnote-anchor-4" class="footnote-number" contenteditable="false" target="_self">4</a><div class="footnote-content"><p>Technically, the news coverage referred to a model called R2, which would have been the successor of R1. As reasoning and non-reasoning models have tended to unify over the past year, I think we should view V4 as essentially the successor that R2 referred to at the time.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-5" href="#footnote-anchor-5" class="footnote-number" contenteditable="false" target="_self">5</a><div class="footnote-content"><p>A &#8220;third country&#8221; is a country that is neither the origin (in this case, the US) nor the ultimate destination (typically, China).</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-6" href="#footnote-anchor-6" class="footnote-number" contenteditable="false" target="_self">6</a><div class="footnote-content"><p>For example: Megaspeed International (Singapore), Speedmatrix Sdn. Bhd. (Malaysia), Novagate Cloud Pte Ltd. (Singapore), Novagate Cloud Sdn. Bhd. (Malaysia), Aperia Cloud Services (Singapore), OBON Corp (Thailand), Siam AI Corporation (Thailand), Aolani (Malaysia), and Indosat Ooredoo Hutchison (Indonesia). To be clear, these all appear in allegations, but they are not proven to have been involved in smuggling or other illegal activities. It is also possible, or even likely, that this list is very incomplete.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-7" href="#footnote-anchor-7" class="footnote-number" contenteditable="false" target="_self">7</a><div class="footnote-content"><p>Note that some companies, like Google, design AI chips for use in their own data centers. Since these companies generally do not sell their chips, they are not smuggled, and so they are not covered in this post.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-8" href="#footnote-anchor-8" class="footnote-number" contenteditable="false" target="_self">8</a><div class="footnote-content"><p>Distributors represent a relatively minor share of NVIDIA&#8217;s revenue since they typically buy servers from server builders, which are one step removed from NVIDIA. They probably also purchase some AI chips directly from NVIDIA, which is likely where the revenue from these distributors originates.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-9" href="#footnote-anchor-9" class="footnote-number" contenteditable="false" target="_self">9</a><div class="footnote-content"><p>Specifically, the chips at this point are embedded in accelerators or SXM modules, but since that distinction is not very important here, I will just refer to them as &#8220;chips&#8221; to keep things simple.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-10" href="#footnote-anchor-10" class="footnote-number" contenteditable="false" target="_self">10</a><div class="footnote-content"><p>I think diversion at the shipping stage is unlikely. All known cases of AI chip smuggling involve smugglers obtaining chips from AI chip sellers. According to one former employee at an AI server builder I spoke with, a major server builder works only with trusted freight companies; the former employee seemed skeptical that diversion would occur at that stage. More importantly, the buyer would likely notice if any products went missing, since it has paid for them and has a strong incentive to ensure it received what it paid for. If the buyer is smuggling the chips, there is little reason to divert them during the initial shipment; they could simply be reexported or transshipped instead.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-11" href="#footnote-anchor-11" class="footnote-number" contenteditable="false" target="_self">11</a><div class="footnote-content"><p>Strictly speaking, it is illegal to sell them to these customers without a license from the US government. But the US government has a presumption of denial for these licenses, which, for all intents and purposes, amounts to a ban on these sales.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-12" href="#footnote-anchor-12" class="footnote-number" contenteditable="false" target="_self">12</a><div class="footnote-content"><p>The sales process is likely similar for resellers, though that&#8217;s just conjecture on my part. It may look slightly different for distributors and NVIDIA, since they are more likely to sell to customers only through long-term partnerships.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-13" href="#footnote-anchor-13" class="footnote-number" contenteditable="false" target="_self">13</a><div class="footnote-content"><p>I think the way this works is either that a distributor keeps a bunch of B300s in inventory, receives an order from a customer for HGX B300 servers, then orders those servers from a server builder while supplying the server builder with B300s from its inventory; or that a customer orders HGX B300 servers from a server builder, and the server builder partners with a distributor to both obtain the B300s and ultimately ship the servers to the customer. Perhaps both happen to varying degrees.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-14" href="#footnote-anchor-14" class="footnote-number" contenteditable="false" target="_self">14</a><div class="footnote-content"><p>A server builder is not an end user, since it will sell the servers it builds. However, I think a cloud provider can be an end user of chips it operates in a data center, even though it rents those chips out through its cloud offerings to other actors who actually use them.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-15" href="#footnote-anchor-15" class="footnote-number" contenteditable="false" target="_self">15</a><div class="footnote-content"><p>I think many of these processes can likely be automated and/or improved using AI agents, but I&#8217;m unsure whether AI agents will favor due diligence more than they favor smugglers. For example, AI agents will likely also help smugglers generate fake documents and convincing websites for front companies.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-16" href="#footnote-anchor-16" class="footnote-number" contenteditable="false" target="_self">16</a><div class="footnote-content"><p>I think the right to conduct on-site inspections is typically negotiated as part of the sales process. So it may be difficult for AI chip sellers to do this for chips that are already sold, where it wasn&#8217;t already negotiated.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-17" href="#footnote-anchor-17" class="footnote-number" contenteditable="false" target="_self">17</a><div class="footnote-content"><p>For example, in July 2024, an NVIDIA spokesperson said: &#8220;Although we cannot track products after they are sold, if we determine that any customer is violating U.S. export controls, we will take appropriate action.&#8221; Of course, July 2024 was a different age. We didn&#8217;t even have our first reasoning models then.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-18" href="#footnote-anchor-18" class="footnote-number" contenteditable="false" target="_self">18</a><div class="footnote-content"><p>AI server builders, distributors, and resellers could theoretically be especially prone to forgoing standard due diligence processes when the value of their inventory is depreciating quickly (e.g., due to the release of newer generations) and/or demand is weak. One former AI server builder employee told me that they saw this dynamic in the memory business, where that company would sell to a shady broker, remove the <a href="https://craftybase.com/blog/manufacturing-travelers">traveler</a> (a document showing where the item has been), and do some creative bookkeeping. But this is likely not relevant to AI chips today, as AI chips are seeing massive, consistent demand.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-19" href="#footnote-anchor-19" class="footnote-number" contenteditable="false" target="_self">19</a><div class="footnote-content"><p>Staging this deception seems to have been a fairly substantial operation. According to the indictment, the third-party broker working with the Super Micro insiders estimated that staging the warehouses with dummy servers would require &#8220;100 people in total&#8221;,  forklift operators, arranged meals, and a &#8220;20-person shuttle bus for easy travel between the hotel and the warehouse, allowing for short breaks&#8221;.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-20" href="#footnote-anchor-20" class="footnote-number" contenteditable="false" target="_self">20</a><div class="footnote-content"><p>This is from public filings cited in <a href="https://culperresearch.com/wp-content/uploads/2026/05/Culper_NVDA_5-13-2026.pdf">a May 2026 short-seller report</a>. The entity in question was Megaspeed. The short-seller argues that the $2.9 billion came from Alibaba, but while suggestive, this is neither confirmed nor clear-cut.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-21" href="#footnote-anchor-21" class="footnote-number" contenteditable="false" target="_self">21</a><div class="footnote-content"><p>In <a href="https://www.cnas.org/publications/reports/countering-ai-chip-smuggling-has-become-a-national-security-priority">a June 2025 report</a> on AI chip smuggling, Tim Fist and I wrote: &#8220;According to the Financial Times, &#8216;People involved in the trade said merchants in Malaysia, Japan, and Indonesia often shipped Super Micro servers or NVIDIA processors to Hong Kong before bringing them across the border to Shenzhen.&#8217; The Information report cites a smuggler claiming to acquire thousands of chips from companies like Dell and Super Micro &#8216;thanks to what he called &#8220;strong personal relationships&#8221; with sales representatives at these firms&#8217;. A [2024] report by analyst firm Hindenburg Research also documented multiple compliance failures by Supermicro, alleging, for example, that it has supplied millions of dollars of products to a distributor in Russia through a Californian entity despite sanctions. Super Micro servers have also been advertised on Chinese e-commerce sites. Super Micro has responded to past reports of smuggling by stating that it follows &#8216;all US export control requirements on the sale, service, support, and export of GPU systems&#8217;.&#8221;</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-22" href="#footnote-anchor-22" class="footnote-number" contenteditable="false" target="_self">22</a><div class="footnote-content"><p>Renting is a much better situation for the US because it allows US companies to theoretically revoke access and, to some extent, monitor who uses the chips. That makes it easier to prevent Chinese actors from, say, using the AI chips for military purposes. If the chips are smuggled into China, it&#8217;s essentially impossible to recover them, and it&#8217;s equally difficult to prevent Chinese actors from using them for military purposes.</p><p></p></div></div>]]></content:encoded></item><item><title><![CDATA[Hantavirus won't be the next COVID]]></title><description><![CDATA[A forecaster's breakdown of the Hondius cruise ship outbreak]]></description><link>https://blog.peterwildeford.com/p/hantavirus-wont-be-the-next-covid</link><guid isPermaLink="false">https://blog.peterwildeford.com/p/hantavirus-wont-be-the-next-covid</guid><dc:creator><![CDATA[Peter Wildeford]]></dc:creator><pubDate>Mon, 11 May 2026 10:47:00 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!GdhV!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F859ef576-3d8d-4a91-8aa1-6bf4e32152e1_2004x1006.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!GdhV!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F859ef576-3d8d-4a91-8aa1-6bf4e32152e1_2004x1006.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!GdhV!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F859ef576-3d8d-4a91-8aa1-6bf4e32152e1_2004x1006.png 424w, https://substackcdn.com/image/fetch/$s_!GdhV!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F859ef576-3d8d-4a91-8aa1-6bf4e32152e1_2004x1006.png 848w, https://substackcdn.com/image/fetch/$s_!GdhV!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F859ef576-3d8d-4a91-8aa1-6bf4e32152e1_2004x1006.png 1272w, https://substackcdn.com/image/fetch/$s_!GdhV!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F859ef576-3d8d-4a91-8aa1-6bf4e32152e1_2004x1006.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!GdhV!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F859ef576-3d8d-4a91-8aa1-6bf4e32152e1_2004x1006.png" width="1456" height="731" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/859ef576-3d8d-4a91-8aa1-6bf4e32152e1_2004x1006.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:731,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:3050437,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://blog.peterwildeford.com/i/196964500?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F859ef576-3d8d-4a91-8aa1-6bf4e32152e1_2004x1006.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!GdhV!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F859ef576-3d8d-4a91-8aa1-6bf4e32152e1_2004x1006.png 424w, https://substackcdn.com/image/fetch/$s_!GdhV!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F859ef576-3d8d-4a91-8aa1-6bf4e32152e1_2004x1006.png 848w, https://substackcdn.com/image/fetch/$s_!GdhV!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F859ef576-3d8d-4a91-8aa1-6bf4e32152e1_2004x1006.png 1272w, https://substackcdn.com/image/fetch/$s_!GdhV!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F859ef576-3d8d-4a91-8aa1-6bf4e32152e1_2004x1006.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><em>About the author: Peter Wildeford is a top forecaster, ranked top 1% every year since 2022. Here, he shares the news and analysis that informs his forecasts.</em></p><p><em>-</em></p><p>A cruise ship trapped at sea.</p><p>Passengers with a strange, infectious disease, forced to isolate.</p><p>A diplomatic fight over which port would receive the vessel.</p><p>Sounds like the coronavirus. But this time it&#8217;s <em>hantavirus.</em></p><p><em>Is this a big deal?</em></p><p>The <a href="https://en.wikipedia.org/wiki/MV_Hondius_hantavirus_outbreak">Andes-strain hantavirus cluster</a> aboard the Dutch-flagged expedition vessel MV Hondius is real and tragic. Three people have died. Several more are critically ill.</p><p><strong>But hantavirus is not the &#8220;next COVID&#8221;.</strong> The way the pathogen works does not suggest that sustained spread is possible, the lack of open-ended opportunities for spread makes sustained spread even harder, and the current trends over the past 34 days since the first case suggest we are strongly on track for containment. <strong>I will say, with confidence, that this will not spiral into a new major pandemic.</strong></p><p>To be more concrete, we can turn to Metaculus, an online forecasting platform, which currently has two questions on the hantavirus:</p><ul><li><p>The first asks <strong><a href="https://www.metaculus.com/questions/43468/hantavirus-pheic-before-2027/">&#8220;Will WHO declare hantavirus a Public Health Emergency of International Concern before 2027?&#8221;</a></strong> &#8212; as of the time of writing, the median of community predictions is at 2% and I am currently forecasting <strong>0.4%</strong>.</p></li><li><p>The second asks <strong><a href="https://www.metaculus.com/questions/43461/5-non-ship-cases-linked-to-the-hondius-outbreak-before-aug-2026/">&#8220;Will at least 5 non-passengers be linked to the MV Hondius hantavirus outbreak before August 2026?&#8221;</a></strong> &#8212; as of the time of writing, the median of community predictions is at 23% and I am currently forecasting <strong>4%</strong>.</p></li></ul><p>How am I so confident? Let&#8217;s look into what hantavirus is, what happened on the Hondius cruise ship, and where we might go next.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://blog.peterwildeford.com/p/hantavirus-wont-be-the-next-covid?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://blog.peterwildeford.com/p/hantavirus-wont-be-the-next-covid?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><h2>What happened?</h2><p>This hantavirus incident started not on a cruise ship, but with a Dutch couple on a bird-watching trip through Chile, Uruguay, and Argentina. After this five-month trip, they boarded the Hondius cruise ship, for what was meant to be a month of sailing. The first five days went exactly to plan &#8212; zodiac excursions, evening lectures on polar ecology, and trips to see penguins and ice. But on April 6, while onboard, the husband got sick and died April 11. With only a small ship&#8217;s clinic to work with, the cause of death couldn&#8217;t be determined. The voyage continued.</p><p>On April 24, the ship reached Saint Helena, and the widow disembarked with her husband&#8217;s body for repatriation &#8212; already carrying stomach symptoms that nobody yet recognized for what they were. Three other Dutch passengers got off with her. The widow flew to Johannesburg, deteriorating throughout the flight. As she was boarding the plane for Amsterdam, the crew realized she was too sick to travel and pulled her off the plane. </p><p>The virus causes Hantavirus Pulmonary Syndrome, which targets the lungs and heart, and has a mortality rate of 35 to 50 percent. She died in a Johannesburg hospital on April 26.</p><p>Later, a 28-year-old German woman aboard the Hondius got a fever and then died on the ship on May 2. Oceanwide Expeditions called the Dutch authorities, who called the World Health Organization. The Hondius went to its highest internal pandemic response, with cabins sealed and meals delivered by crew.</p><p>At 5:30am yesterday local time, the ship anchored off the Canary Islands. More than 70 passengers were then ferried ashore in protective suits on small boats, then put into sealed buses to the airport, and flown out to seven different countries.</p><p>However, the seal wasn&#8217;t perfect. A French passenger cleared by the ship&#8217;s doctors nonetheless developed symptoms on the flight home. And a man who left the Hondius weeks ago on Tristan da Cunha &#8212; population 200, the remotest inhabited island on Earth &#8212; is now hospitalized there with probable hantavirus, kept alive by oxygen and PCR kits that British paratroopers airdropped on Saturday.</p><p>So far, as of the time of writing, all hantavirus cases currently cluster in a 25-day window from Apr 6 to May 1, the last on-ship onset was Apr 28, and there have been zero new onsets in the 9 days since May 1. Hantavirus incubation runs 1&#8211;8 weeks, so we&#8217;re not in the clear yet.</p><p>But so far twelve days of contact tracing across twenty-two countries has turned up only Hondius passengers as having hantavirus infections. The KLM flight attendant who handled the dying widow: negative. The passengers seated near her: negative. All eight confirmed or probable cases were on the ship.</p><p>The Hondius is sailing on toward Rotterdam, with the German woman&#8217;s body still aboard.</p><p></p><h2>Why the outbreak almost certainly contains</h2><p>Here&#8217;s my best attempt at graphing a comparison of hantavirus vs. COVID-19 based on the 34 days so far &#8212; take note of the log scale:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!V44j!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91e561ab-5b3d-4395-821f-592ffc5329bd_1310x754.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!V44j!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91e561ab-5b3d-4395-821f-592ffc5329bd_1310x754.png 424w, https://substackcdn.com/image/fetch/$s_!V44j!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91e561ab-5b3d-4395-821f-592ffc5329bd_1310x754.png 848w, https://substackcdn.com/image/fetch/$s_!V44j!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91e561ab-5b3d-4395-821f-592ffc5329bd_1310x754.png 1272w, https://substackcdn.com/image/fetch/$s_!V44j!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91e561ab-5b3d-4395-821f-592ffc5329bd_1310x754.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!V44j!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91e561ab-5b3d-4395-821f-592ffc5329bd_1310x754.png" width="1310" height="754" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/91e561ab-5b3d-4395-821f-592ffc5329bd_1310x754.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:754,&quot;width&quot;:1310,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:230705,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://blog.peterwildeford.com/i/196964500?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91e561ab-5b3d-4395-821f-592ffc5329bd_1310x754.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!V44j!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91e561ab-5b3d-4395-821f-592ffc5329bd_1310x754.png 424w, https://substackcdn.com/image/fetch/$s_!V44j!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91e561ab-5b3d-4395-821f-592ffc5329bd_1310x754.png 848w, https://substackcdn.com/image/fetch/$s_!V44j!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91e561ab-5b3d-4395-821f-592ffc5329bd_1310x754.png 1272w, https://substackcdn.com/image/fetch/$s_!V44j!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91e561ab-5b3d-4395-821f-592ffc5329bd_1310x754.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Of course, this is a bit of an apples-to-oranges comparison. COVID&#8217;s first 34 days had massive reporting lag, so instead I retrospectively estimate <em>actual infections</em> in Wuhan rather than what was officially reported at the time<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-1" href="#footnote-1" target="_self">1</a>. We may then reasonably ask: for hantavirus, could there be a quiet unknown spread too? Maybe, a few years from now, we will realize that there ought to have been more hantavirus cases reported for the first 34 days, like with COVID?</p><p>Seems unlikely. Hantavirus is in a closed system &#8212; currently only in one ship with strong post-hoc investigation. Additionally, with hantavirus there&#8217;s not known to be any spread without active symptoms. Compare this to COVID-19, which started in early Wuhan &#8212; an open system with no surveillance. Together, this means the current known case count of hantavirus is very likely close to the actual count.</p><p>But even if you wanted a <em>strictly</em> fair &#8220;what was officially reported by Day N&#8221; comparison, COVID had already reached over 44 confirmed and reported cases by day 34, whereas hantavirus has not yet exceeded 10. COVID-19&#8217;s doubling time in the unrestrained early Wuhan phase was somewhere around &#8216;cases double every 4&#8211;7 days&#8217;; whereas hantavirus on the Hondius has effectively no compound growth. The slope difference is far more notable than the absolute numbers. <strong>Put simply, hantavirus empirically lacks the exponential spread that COVID had.</strong></p><p>So why is hantavirus not going exponential? Well, the three biggest factors that made COVID such a problem is that it was (a) quite deadly, (b) quite contagious, and (c) transmitted easily before symptoms appear making it difficult to isolate the right people. </p><p>The bad news about the Andes virus is that it is also very deadly. But in the roughly thirty years since person-to-person Andes transmission was first observed, no outbreak has ever escaped the close-contact networks in which it began. Andes virus is simply not that contagious and infection comes nearly entirely from those who are symptomatic.</p><p>I built <a href="https://gist.github.com/peterhurford/f6824ad6da30fcf9c7498e22bcf6c99f">a probabilistic model</a> decomposing this question into exposure pools &#8212; the widow&#8217;s KLM boarding, the Airlink flight from St Helena, the JNB hospital, household contacts of disembarked passengers &#8212; applying Andes-specific transmission and incubation parameters, then conditioning on the observation that zero non-passenger cases have surfaced as of today. Running this, I get a 4% chance that there will be more than 5 cases from people outside those on the Hondius cruise, with a 70% chance of at least one non-passenger case by August, and about a 17% chance of three or more.</p><p></p><h2>How hantavirus spreads</h2><p>Hantaviruses live in rodents and are typically spread by inhaling parts of rodent poop that end up in the air. There are twenty known hantavirus species, but only one &#8212; the Andes virus &#8212; has documented human-to-human transmission. That discovery came from <a href="https://wwwnc.cdc.gov/eid/article/3/2/97-0210_article">a 1996 outbreak in El Bols&#243;n, Argentina</a>, where treating physicians and family members of patients fell ill without any rodent exposure of their own.</p><p>The Andes virus is specifically from the <a href="https://www.cdc.gov/hantavirus/about/">long-tailed pygmy rice rat</a>, native to southern Argentina and Chile. The Dutch couple that brought hantavirus onboard the Hondius almost certainly got it by accidentally inhaling rat poop in a rural setting somewhere in Patagonia in November.</p><p>Andes infection moves in two phases. It starts with a flu-like illness &#8212; fever, muscle pain, headache, gastrointestinal symptoms &#8212; that lasts three to seven days and is usually initially mistaken for something more mundane. But the Andes virus makes blood vessels start to leak, and then the blood pours into the lungs. Patients can move from &#8216;feeling off&#8217; to requiring ICU care within mere hours. This is the phase that kills people; it is also the phase during which they are most infectious, which matters a great deal for what happens next.</p><p>Typically you can only get the infection if you&#8217;re in &#8216;close contact&#8217; with someone who already has the disease. But when we talk about &#8216;close contact&#8217;, what does that mean? The phrase appears in every WHO and CDC document, and it does most of its work as a vague reassurance rather than a precise epidemiological parameter. </p><p>The detailed literature on hantavirus and the Andes virus is messier than the public messaging suggests.</p><p>Here, our story starts with a birthday party in Epuy&#233;n, a small town of about 2500 in Argentine Patagonia, where the Andes virus is found. The party had about 100 guests, an evening of food and drink and proximity. After attending, one of the guests developed flu-like symptoms. He died days later. By the time hantavirus was confirmed, several of his fellow partygoers were already sick. The chain spread through their households, including to pregnant women and their unborn children, before Argentine epidemiologists had stitched it together. There were 34 cases before the entire chain was able to be contained.</p><p>This is what was challenging for the notion of &#8216;close contact&#8217; &#8212; <a href="https://www.nejm.org/doi/full/10.1056/NEJMoa2009040">some of the exposures were in fact quite casual</a>. One secondary hantavirus case had spent only &#8220;a few moments&#8221; with an infected partygoer on the way to the bathroom; another had merely shared a short car ride. These weren&#8217;t the prolonged household contacts the literature usually pictures when it says &#8220;close contact.&#8221;</p><p>Alonso&#8217;s team estimated the number of people each an infected person infects is about 2.12 in the early, unrestricted phase. This is an infectious rate comparable to flu. But this average of 2.12 hides what&#8217;s important. Nearly all 34 cases traced back to just three superspreaders &#8212; people who had unusually high viral loads and certain immune profiles. Most of the infected individuals in Epuy&#233;n transmitted to no one at all. So the outbreak&#8217;s shape was not a slow grind of average people infecting average numbers of others like you see with a typical flu but instead a handful of extraordinary transmission events embedded in a sea of otherwise dead-end infections.</p><p>And critically, the infectious window of hantavirus is short and centered on visible illness. Andes virus infectiousness peaks on the same day a patient develops fever and drops sharply within days. Unlike COVID, pre-symptomatic transmission is minimal. By the time someone is contagious enough to seed a superspreading event, they look sick with a fever &#8212; which is why isolation works at all. This is the profile of a virus public health can contain.</p><p>This year&#8217;s events on the Hondius fit this picture. Onboard transmission is now <a href="https://en.wikipedia.org/wiki/MV_Hondius_hantavirus_outbreak">officially attributed in part to person-to-person spread</a>. But the case count &#8212; six confirmed and two suspected cases out of ~150 people sharing a closed environment for several weeks, including the thirteen-day period after certain exposure and before isolation measures were enacted &#8212; is meaningfully below what an Epuy&#233;n-style superspreading event in a continuously-mixing cruise environment would have produced. The most plausible read here is that the Dutch couple that started the infection were not <em>superspreaders</em> and most secondary exposure occurred within cabin pairs that were &#8216;close contacts&#8217;. This is far more consistent with a contained cluster rather than the start of a pandemic.</p><p>Additionally, unlike a wildlife-spillover event with anonymous spreaders scattered across an open population, every Hondius passenger and crew member is known by name, by nationality, and by current location. Twenty-two governments are coordinating. The 1&#8211;8 week incubation window means we&#8217;ll know by mid-July whether anyone slipped through &#8212; and we&#8217;ll know about each case the moment it surfaces. This may be one of the easiest disease outbreaks to monitor and contain.<strong><br></strong></p><h2>What comes next?</h2><p>Regardless of what happens next, the Hondius outbreak is a real tragedy. But tragic and &#8220;next COVID&#8221; are not remotely in the same category.</p><p>In some sense, the conclusion is not yet written. Time will tell whether I look on-point or incredibly stupid. While it&#8217;s always possible there could be some crazy mutation, these mutations are very rare and we have no evidence of this having happened.</p><p>Fundamentally, hantavirus is deadly but slow. It shouldn&#8217;t go exponential or fundamentally change the trajectory of society the way COVID did.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://blog.peterwildeford.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Want more forecasting? Subscribe!</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-1" href="#footnote-anchor-1" class="footnote-number" contenteditable="false" target="_self">1</a><div class="footnote-content"><p>I&#8217;m calibrating to<a href="https://www.imperial.ac.uk/news/196229/coronavirus-infections-china-could-much-higher/"> Imperial College&#8217;s January 2020 retrospective nowcast estimate</a> of 410 cases (95% CI 130&#8211;900) in Wuhan as of January 4, 2020 &#8212; Day 34 since the first known symptom onset on December 1, 2019 per<a href="https://www.nejm.org/doi/full/10.1056/NEJMoa2001316"> Li et al. NEJM</a>. There were 44 COVID cases officially reported on this day; certainly an underestimate given what we now know. Compare either of these two estimates to 8 Hantavirus cases (6 confirmed, 2 highly plausible) in the first 34 days.</p><p></p></div></div>]]></content:encoded></item><item><title><![CDATA[Mythos is just the beginning]]></title><description><![CDATA[If you were waiting for a sign that superintelligence is coming, this is it]]></description><link>https://blog.peterwildeford.com/p/mythos-is-just-the-beginning</link><guid isPermaLink="false">https://blog.peterwildeford.com/p/mythos-is-just-the-beginning</guid><dc:creator><![CDATA[Peter Wildeford]]></dc:creator><pubDate>Mon, 20 Apr 2026 11:16:40 GMT</pubDate><enclosure url="https://images.unsplash.com/photo-1707729739349-4133e3eefd7a?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwxMXx8bXl0aG9zfGVufDB8fHx8MTc3NjIwNDU2MXww&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://images.unsplash.com/photo-1707729739349-4133e3eefd7a?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwxMXx8bXl0aG9zfGVufDB8fHx8MTc3NjIwNDU2MXww&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://images.unsplash.com/photo-1707729739349-4133e3eefd7a?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwxMXx8bXl0aG9zfGVufDB8fHx8MTc3NjIwNDU2MXww&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 424w, https://images.unsplash.com/photo-1707729739349-4133e3eefd7a?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwxMXx8bXl0aG9zfGVufDB8fHx8MTc3NjIwNDU2MXww&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 848w, https://images.unsplash.com/photo-1707729739349-4133e3eefd7a?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwxMXx8bXl0aG9zfGVufDB8fHx8MTc3NjIwNDU2MXww&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 1272w, https://images.unsplash.com/photo-1707729739349-4133e3eefd7a?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwxMXx8bXl0aG9zfGVufDB8fHx8MTc3NjIwNDU2MXww&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 1456w" sizes="100vw"><img src="https://images.unsplash.com/photo-1707729739349-4133e3eefd7a?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwxMXx8bXl0aG9zfGVufDB8fHx8MTc3NjIwNDU2MXww&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080" width="6903" height="3883" data-attrs="{&quot;src&quot;:&quot;https://images.unsplash.com/photo-1707729739349-4133e3eefd7a?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwxMXx8bXl0aG9zfGVufDB8fHx8MTc3NjIwNDU2MXww&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:3883,&quot;width&quot;:6903,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;a group of white statues in a building&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="a group of white statues in a building" title="a group of white statues in a building" srcset="https://images.unsplash.com/photo-1707729739349-4133e3eefd7a?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwxMXx8bXl0aG9zfGVufDB8fHx8MTc3NjIwNDU2MXww&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 424w, https://images.unsplash.com/photo-1707729739349-4133e3eefd7a?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwxMXx8bXl0aG9zfGVufDB8fHx8MTc3NjIwNDU2MXww&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 848w, https://images.unsplash.com/photo-1707729739349-4133e3eefd7a?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwxMXx8bXl0aG9zfGVufDB8fHx8MTc3NjIwNDU2MXww&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 1272w, https://images.unsplash.com/photo-1707729739349-4133e3eefd7a?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwxMXx8bXl0aG9zfGVufDB8fHx8MTc3NjIwNDU2MXww&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Photo by <a href="https://unsplash.com/@hamburgmeinefreundin">Wolfgang Weiser</a> on <a href="https://unsplash.com">Unsplash</a></figcaption></figure></div><p><strong><a href="https://www.anthropic.com/glasswing">Claude Mythos Preview</a></strong> is, by every available benchmark, the most capable AI model ever built. But more striking than any benchmark are the thousands of previously unknown zero-day vulnerabilities that Mythos found in <em>every</em> major operating system and <em>every</em> major web browser &#8212; many of them critical, several of them decades old. As a result, Anthropic found the model too dangerous to release publicly.</p><p>Much digital ink has been spent analyzing Mythos, its cyber abilities, and what that means for our cybersecurity and national security. This is important and needs to be discussed. <strong>But the real headline is that Mythos is just the beginning. </strong>This kind of thing &#8212; finding abilities too dangerous to release &#8212; will become the new normal and <strong>this will only get more intense as AI companies build towards AI superintelligence.</strong></p><p>So what is Claude Mythos, what does it mean, and what should we do? Let&#8217;s dig in.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://blog.peterwildeford.com/p/mythos-is-just-the-beginning?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://blog.peterwildeford.com/p/mythos-is-just-the-beginning?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><h2><br>What is Claude Mythos?</h2><p>Previously, Anthropic had three model sizes &#8212; Haiku (small), Sonnet (medium), and Opus (large). Capabilities generally increase as you increase the model size. Mythos is one such increase in size, larger than even Opus in the same way Opus is larger than Sonnet.</p><p>This increase in model scale has given Mythos notably stronger capabilities in a variety of domains &#8212; most notably cyberoffense. Yes, earlier models like Opus 4.6 could also do vulnerability discovery, <a href="https://www.aisi.gov.uk/blog/evidence-for-inference-scaling-in-ai-cyber-tasks-increased-evaluation-budgets-reveal-higher-success-rates">especially with improved inference-time compute</a> and <a href="https://xbow.com/blog/gpt-5">improved scaffolding</a>. This has led some to incorrectly dismiss the Mythos results as mere marketing hype.</p><p><strong>But Mythos is plainly on another scale in terms of both quantity of vulnerabilities and typical severity.</strong> On a standardized Firefox exploit development task, the previous best model succeeded 2 times out of several hundred attempts. Mythos Preview succeeded <strong>181</strong> times. <a href="https://www.aisi.gov.uk/blog/our-evaluation-of-claude-mythos-previews-cyber-capabilities">The UK government found Mythos to significantly outperform Claude Opus 4.6 on their 32-step corporate network attack simulation</a>, with select runs completing all 32 steps.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!F0pw!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F87e46a39-1ba8-4974-b057-e7f44f468bda_2568x1392.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!F0pw!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F87e46a39-1ba8-4974-b057-e7f44f468bda_2568x1392.png 424w, https://substackcdn.com/image/fetch/$s_!F0pw!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F87e46a39-1ba8-4974-b057-e7f44f468bda_2568x1392.png 848w, https://substackcdn.com/image/fetch/$s_!F0pw!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F87e46a39-1ba8-4974-b057-e7f44f468bda_2568x1392.png 1272w, https://substackcdn.com/image/fetch/$s_!F0pw!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F87e46a39-1ba8-4974-b057-e7f44f468bda_2568x1392.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!F0pw!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F87e46a39-1ba8-4974-b057-e7f44f468bda_2568x1392.png" width="542" height="293.7074175824176" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/87e46a39-1ba8-4974-b057-e7f44f468bda_2568x1392.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:789,&quot;width&quot;:1456,&quot;resizeWidth&quot;:542,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!F0pw!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F87e46a39-1ba8-4974-b057-e7f44f468bda_2568x1392.png 424w, https://substackcdn.com/image/fetch/$s_!F0pw!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F87e46a39-1ba8-4974-b057-e7f44f468bda_2568x1392.png 848w, https://substackcdn.com/image/fetch/$s_!F0pw!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F87e46a39-1ba8-4974-b057-e7f44f468bda_2568x1392.png 1272w, https://substackcdn.com/image/fetch/$s_!F0pw!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F87e46a39-1ba8-4974-b057-e7f44f468bda_2568x1392.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>As a result, Anthropic is drowning in high-severity vulnerabilities, of which fewer than 1% have been fully patched by their maintainers. Nicholas Carlini, a leading AI security researcher and Anthropic employee, said &#8220;I&#8217;ve found more bugs in the last few weeks with Mythos than in the rest of my entire life combined.&#8221;</p><p></p><h2>Where this is going</h2><p>On August 2, 1939, Einstein sent Roosevelt a letter warning that a nuclear weapon was possible. Six years later, it happened. This nuclear weapon was fully under government control. What would things have been like if the nuclear weapon was instead developed by private companies?</p><p>Today, experts similarly warn that AI superintelligence may be possible and would be even more transformative to the structure of global power than the invention of nuclear weapons. Six years later, will it happen? And will it be under our control?</p><p><strong>Every time a new model comes out, people focus on what it can do right now and don&#8217;t think enough about where the trend line leads.</strong> The cybersecurity story for Mythos, as alarming as it is, is not as important as the trend. A year ago, AI could barely hack at all. It wasn&#8217;t until around June 2025 that AI was reliably helpful for hacking, and it wasn&#8217;t until November that AI could autonomously implement hacks. </p><p>Consider that just a few years ago, some AI scientists and top forecasters forecast that AI would be capable of cyberoffense exceeding professional humans. Many people at the time thought this was impossible, or at least far off. But it&#8217;s now here, today.</p><p>Now consider that these same AI scientists and top forecasters are warning that this is just the beginning &#8212; and that the same scaling dynamic that produced Mythos's cyberoffense will produce sharper capabilities across strategy, weapons design, military planning, and more. Of course, being right about the first doesn't automatically mean being right about the second. But the people who called Mythos early were working from a model of how AI progress works, and that model is performing better than its critics'.</p><p><strong>If you were waiting for a sign that superintelligence is coming, this is it. </strong>If private AI companies succeed in building even stronger capabilities over the next few years, including AI superintelligence, these private companies would greatly exceed the power of the United States government and all world governments combined. Worse, the private companies may not be able to successfully control the AI superintelligence, allowing the superintelligence to become a power center in its own right.</p><p>Anthropic already possesses a cyberoffense capability that rivals many nations and the ability to, if desired, cause major damage. It is great that American frontier AI companies like Anthropic have shown restraint with their AI and how they are releasing it. But this restraint shouldn&#8217;t earn these companies a blank check. And right now they essentially have one &#8212; the status quo for AI is that AI companies determine nearly everything.</p><p>Anthropic made every consequential decision in this story. Whether to lock down, what to lock down, when to tell the government, what to share, who gets early access and who doesn&#8217;t, how to vet those who get access, what level of risks are acceptable, and what &#8220;responsible&#8221; means across all of this&#8230; What could&#8217;ve happened if Anthropic had simply released Mythos publicly, as most AI companies would do with a flagship model? There&#8217;s no law against it. Overnight, every intelligence community operation that depends on signals exploitation is potentially compromised.</p><p>How confident is Anthropic that model access hasn&#8217;t reached adversary states through a downstream partner or a compromised employee at a partner organization? How confident is Anthropic that the model can&#8217;t be stolen and then misused by a highly motivated adversary? How confident is Anthropic that Mythos&#8217;s capabilities can be contained and how long should we be aiming to contain them? How confident is Anthropic that future AI models might not escape their containment and independently wreak havoc? </p><p>What should government policy be when a company produces, among other things, an unparalleled cyberweapon? What if the future release is also capable of building unprecedented bioweapons? What if the release after that risks genuine loss of control for humanity?</p><p></p><h2>What should we do?</h2><p>The Manhattan Project answered an analogous question with a specific institutional design &#8212; private contractors and university labs doing the actual work, inside a federal security perimeter, with classification rules, cleared personnel, and ultimate government authority over deployment. That model wasn't statist &#8212; General Groves and Vannevar Bush were not central planners &#8212; but it recognized that some categories of capability cannot sit entirely inside private decision-making. Whether this is the right model for AI is contested &#8212; but the question itself is unavoidable.</p><p>If you believe in AI superintelligence, <strong>many policies have become more urgent:</strong></p><ul><li><p><strong>We need to be more serious about China&#8217;s ability to use American compute.</strong> Every AI chip that can train or run a Mythos-like model is more of a national security threat than before, and this will only continue. It will matter whether China can run 1000 or 100,000 advanced hacker AIs and the main way to stay ahead will be in compute advantage. Mythos was trained on an amount of compute that is currently not attainable to China via domestic manufacturing. If China were to train a Mythos-like model this year, it would be off of compute that is legally purchased from Nvidia, compute that is legally rented offshore, or compute that is smuggled. We need to better control semiconductor manufacturing equipment, prevent smuggling of chips, look again at what compute should be legal to sell to China and in what quantities, and ensure that the US maintains an advantage.</p></li><li><p><strong>We need to ensure that China, or other adversaries, cannot steal and misuse the Mythos model weights.</strong> It doesn&#8217;t make sense to try to maintain a lead over China if China can just steal our best results. Having more total compute will still give us an advantage, but our advantage would be even stronger if China couldn&#8217;t steal our model as well. Unfortunately, security at major US AI companies is not yet up to the task, and the task is tremendously difficult. If China were able to steal and misuse Mythos, that would already be a big deal. I suspect they will definitely try, and even if they don&#8217;t succeed at first, they will eventually. The US government needs to assist AI companies in helping them lock down their security.</p></li><li><p><strong>We need to consider what level of government oversight there should be on these increasingly powerful AI capabilities.</strong> Congress, not agencies and not private boards, should define what happens at the upper end of the capability curve. At some point, decisions about deploying systems that rival the coercive capacity of governments cannot sit inside a private corporate structure, however well-intentioned its leadership. Under the Constitution, that authority belongs to Congress. Statute, with sunset clauses and judicial review, is how this gets done &#8212; ideally without creating a sprawling discretionary regulator.</p></li><li><p><strong>We need a government body with the technical capacity to issue binding safety regulations on frontier AI companies.</strong> Drugs are regulated by the Food and Drug Administration, airplanes by the Federal Aviation Administration, and nuclear by the National Nuclear Security Administration. Drugs, airplanes, and nuclear are not perfect analogies for AI, but each combines promise with peril that needs to be carefully balanced. The FDA, FAA, and NNSA are not perfect regulatory bodies either &#8212; the FDA in particular arguably shows the drawbacks of how government regulation can overly harm and slow the benefits of innovation. AI superintelligence will be far more potentially beneficial but also far, far more dangerous than any drug or airplane. Right now the US has the Center for AI Standards and Innovation, but everything it does is voluntary and it is far under-resourced for what will need to be done. We need a narrow-mandate body solely motivated by national security and solely targeting only the most with the proper resources and technical skill to react quickly to superintelligence.</p></li><li><p><strong>We must also recognize that the AI race with China may be a race to see who loses control first.</strong> From a position of strength, we must consider negotiating mutual agreements on safe development. In order to do this, we will need better ideas about what safe development looks like and verification infrastructure to enforce a deal. In the late 1950s and early 1960s, the US, UK, and Soviet Union negotiated limits on nuclear testing but couldn't reliably detect underground tests &#8212; so the 1963 Limited Test Ban Treaty covered only atmosphere, underwater, and space. By the time verification technology improved, the treaty was already signed and wasn't substantively revisited until three decades later. This lesson is instructive &#8211; we must invest in AI verification <em>before</em> we need it. Any future US-China agreement on AI development requires verification infrastructure that doesn&#8217;t yet exist. Without it, deals require trusting China not to defect. With it, deals become enforceable through technical means rather than faith.</p></li><li><p><strong>We need a plan in case we want to slow down.</strong> Finally, the government should have contingency plans and insurance policies for scenarios in which the technical community concludes that further capability gains, on current methods, are outrunning our ability to control the resulting systems. This is not a recommendation to slow down now, but it would be prudent to know what slowing down would actually require and to have the option &#8212; before the moment arrives and we realize we have no brakes.<br></p></li></ul><h2>Looking forward</h2><p><strong>The national security implications of Mythos-like models are clear. But the stakes of AI superintelligence would be orders of magnitude higher.</strong> The point is not that Mythos will go rogue. The concern is that AI 10 more iterations above Mythos could go rogue&#8230; and Mythos illustrates, perhaps for the first time, how a superintelligent AI going rogue would actually pose a big deal for national security.</p><p>From Mythos, it is a straight shot in just a year or two to AI systems that are going to be far too strong to ignore. And from there, it won&#8217;t be long to superintelligence. It would be better to have a prepared government that already has practice getting things right, rather than a government rushing to the scene after it&#8217;s already too late.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://blog.peterwildeford.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Want more analysis of AI superintelligence? Subscribe!</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[China Is Reverse-Engineering America’s Best AI Models]]></title><description><![CDATA[How AI distillation attacks risk extracting US frontier AI at scale]]></description><link>https://blog.peterwildeford.com/p/china-is-reverse-engineering-americas</link><guid isPermaLink="false">https://blog.peterwildeford.com/p/china-is-reverse-engineering-americas</guid><dc:creator><![CDATA[Peter Wildeford]]></dc:creator><pubDate>Mon, 16 Mar 2026 15:02:04 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!1UA3!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32cbbe1f-00bb-4609-b346-14a6b8fe7d4b_1456x717.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!1UA3!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32cbbe1f-00bb-4609-b346-14a6b8fe7d4b_1456x717.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!1UA3!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32cbbe1f-00bb-4609-b346-14a6b8fe7d4b_1456x717.jpeg 424w, https://substackcdn.com/image/fetch/$s_!1UA3!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32cbbe1f-00bb-4609-b346-14a6b8fe7d4b_1456x717.jpeg 848w, https://substackcdn.com/image/fetch/$s_!1UA3!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32cbbe1f-00bb-4609-b346-14a6b8fe7d4b_1456x717.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!1UA3!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32cbbe1f-00bb-4609-b346-14a6b8fe7d4b_1456x717.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!1UA3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32cbbe1f-00bb-4609-b346-14a6b8fe7d4b_1456x717.jpeg" width="1456" height="717" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/32cbbe1f-00bb-4609-b346-14a6b8fe7d4b_1456x717.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:717,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!1UA3!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32cbbe1f-00bb-4609-b346-14a6b8fe7d4b_1456x717.jpeg 424w, https://substackcdn.com/image/fetch/$s_!1UA3!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32cbbe1f-00bb-4609-b346-14a6b8fe7d4b_1456x717.jpeg 848w, https://substackcdn.com/image/fetch/$s_!1UA3!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32cbbe1f-00bb-4609-b346-14a6b8fe7d4b_1456x717.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!1UA3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32cbbe1f-00bb-4609-b346-14a6b8fe7d4b_1456x717.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><em>This post was co-authored by Peter Wildeford and <a href="https://www.theo-bearman.com/">Theo Bearman</a>, a Frontier Security Researcher at the Institute for AI Policy and Strategy (IAPS). It reflects their personal views only, not necessarily the position of their organizations.</em></p><p>~</p><p>Last month, <a href="https://www.anthropic.com/news/detecting-and-preventing-distillation-attacks">Anthropic</a>, <a href="https://assets.bwbx.io/documents/users/iqjWHBFdfxIU/rRmql_jJcxb4/v0">OpenAI</a> and <a href="https://cloud.google.com/blog/topics/threat-intelligence/distillation-experimentation-integration-ai-adversarial-use">Google</a> each published evidence of systematic campaigns by Chinese AI companies to extract capabilities from American frontier models at industrial scale. Anthropic attributed attacks to three Chinese AI companies &#8212; DeepSeek, Moonshot, and MiniMax.</p><p>Anthropic&#8217;s investigation identified over 16 million exchanges generated through approximately 24,000 fraudulent accounts, all targeting Claude&#8217;s agentic reasoning, tool use, and coding capabilities. Chinese AI developer MiniMax was solely responsible for over 13 million of those exchanges. OpenAI also reported that Chinese actors had systematically targeted their ChatGPT models with distillation attacks designed to recreate the whole AI model training pipeline. And this is not the first time &#8212; in January 2025, White House AI czar David Sacks <a href="https://www.foxnews.com/media/wake-up-call-us-leader-ai-says-white-house-ai-crypto-czar">told Fox News</a> there was &#8220;substantial evidence&#8221; that DeepSeek had built their model from distilled knowledge from OpenAI&#8217;s models.</p><p>Left unaddressed, AI distillation attacks pose a threat to American national security and economic competitiveness, given that they lead to China or other adversaries being able to develop better AI than would otherwise be possible by what is essentially stealing American technology. But what is a distillation attack and what can we do about it?</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://blog.peterwildeford.com/p/china-is-reverse-engineering-americas?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://blog.peterwildeford.com/p/china-is-reverse-engineering-americas?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><h2><strong><br>What is a distillation attack?</strong></h2><p>An AI distillation attack occurs when a malicious actor uses the outputs of a &#8220;teacher&#8221; model to train a &#8220;student&#8221; model to approximate the teacher&#8217;s capabilities. Think of it like a restaurant owner who reverse engineers the recipe of a nearby Michelin starred restaurant&#8217;s prized dish by going there hundreds of times, ordering it each time, and figuring out their list of ingredients, measurements, and cooking instructions. In the AI context, the &#8220;recipe&#8221; is the billions of dollars of research, compute, and training data that goes into building a frontier model. The &#8220;dish&#8221; is the model&#8217;s outputs &#8212; the answers it gives and the intermediate reasoning steps it took to get there. By collecting enough outputs, an attacker can train a new model that mimics the original&#8217;s capabilities without doing as much underlying research and development work.</p><p>To be clear, distillation also has legitimate applications in the AI industry. It can be used to create efficient models suitable for edge deployment, specialize general-purpose models for specific domains, and reduce inference costs. Major AI providers including Google Cloud and OpenAI offer official distillation pathways for their customers. The difference is intent. Distillation attacks aim to replicate frontier capabilities in a rival model, violating terms of service and skipping the R&amp;D investment required to build those capabilities independently.</p><p>Additionally, the actual magnitude of capability transfer from distillation is unclear and disputed. Integrating another model&#8217;s outputs into your own training pipeline is a genuine research challenge &#8212; the data can interact unpredictably with existing training, and the resulting model doesn&#8217;t always improve. Reasonable people disagree on assessing the magnitude of the threat as it depends on how effectively attackers can solve this problem, which is not yet clear.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!B1cQ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F368ea1ba-58d7-476c-97b9-400b8b95d9f8_1456x642.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!B1cQ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F368ea1ba-58d7-476c-97b9-400b8b95d9f8_1456x642.jpeg 424w, https://substackcdn.com/image/fetch/$s_!B1cQ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F368ea1ba-58d7-476c-97b9-400b8b95d9f8_1456x642.jpeg 848w, https://substackcdn.com/image/fetch/$s_!B1cQ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F368ea1ba-58d7-476c-97b9-400b8b95d9f8_1456x642.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!B1cQ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F368ea1ba-58d7-476c-97b9-400b8b95d9f8_1456x642.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!B1cQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F368ea1ba-58d7-476c-97b9-400b8b95d9f8_1456x642.jpeg" width="1456" height="642" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/368ea1ba-58d7-476c-97b9-400b8b95d9f8_1456x642.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:642,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!B1cQ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F368ea1ba-58d7-476c-97b9-400b8b95d9f8_1456x642.jpeg 424w, https://substackcdn.com/image/fetch/$s_!B1cQ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F368ea1ba-58d7-476c-97b9-400b8b95d9f8_1456x642.jpeg 848w, https://substackcdn.com/image/fetch/$s_!B1cQ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F368ea1ba-58d7-476c-97b9-400b8b95d9f8_1456x642.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!B1cQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F368ea1ba-58d7-476c-97b9-400b8b95d9f8_1456x642.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><h2><strong>How the attacks work</strong></h2><p>Accessing American frontier AI models in the first place can require circumventing geographic restrictions. Anthropic, for example, does not offer commercial access to Claude in China. To get around this, Chinese AI companies use commercial proxy services that resell access at scale. These proxies operate what Anthropic calls <a href="https://www.anthropic.com/news/detecting-and-preventing-distillation-attacks">&#8220;hydra cluster&#8221; architectures</a> &#8212; sprawling networks of thousands of fraudulent accounts that distribute traffic across the target company&#8217;s API as well as third-party cloud platforms. In one case, a single proxy network managed more than 20,000 accounts simultaneously, mixing distillation traffic with unrelated legitimate requests to avoid detection. When one account is banned, a new one takes its place.</p><p>This is a structural problem that no single AI company can solve alone. Proxy services profit from facilitating unauthorized access to frontier models &#8211; as they are paid per access, they are incentivized to facilitate as much distillation as possible. Individual AI companies can play whack-a-mole with fraudulent accounts, but the proxy services that create them will continue to do so as long as the business model is profitable and the legal risk is negligible.</p><p>Attackers use the victim model to generate vast quantities of high-quality training data and to clean and quality-score existing datasets, outsourcing what otherwise would be an expensive and labor-intensive stage of AI development. They query it with pairs of prompts to generate ranked responses &#8211; preference data that can be used in reinforcement learning. And perhaps most valuable of all, attackers attempt to extract the victim model&#8217;s internal reasoning process &#8211; the step-by-step chain of thought it uses to solve problems. For example, Anthropic reported that DeepSeek crafted prompts asking Claude to articulate the reasoning behind a response it gave, effectively reverse-engineering the thought process that makes frontier AI models so capable, despite their developers having already <a href="https://platform.claude.com/docs/en/build-with-claude/extended-thinking#summarized-thinking">taken</a> <a href="https://developers.openai.com/api/docs/guides/reasoning/#reasoning-summaries">steps</a> to summarize these outputs to avoid competitors training on them.</p><p></p><h2><strong>Why it matters</strong></h2><p>American AI companies have invested significant amounts in compute, data curation, and research talent to build frontier models. <a href="https://epoch.ai/data/ai-companies">Data from EpochAI</a> suggests that OpenAI and Anthropic alone have spent $18 billion on R&amp;D compute since 2024. This potentially creates a competitive asymmetry where American AI companies that must recoup billions in training costs through API and subscriptions are undercut by competitors leveraging distillation attacks. By saving on development effort, Chinese AI companies can train and serve distilled models at little or no cost through their own platforms, or simply open-source them entirely, which would erode American companies&#8217; competitive position. And as AI systems become increasingly central to AI research itself, the stakes of this problem are compounding &#8212; distillation doesn&#8217;t just transfer today&#8217;s capabilities, it can improve the attacker&#8217;s starting position for developing tomorrow&#8217;s.</p><p>Worse, this gives stronger AI capabilities directly to America&#8217;s adversaries. A February 2026<a href="https://cset.georgetown.edu/publication/chinas-military-ai-wish-list/"> CSET analysis</a> of over 9,000 PLA Requests for Proposal from 2023 and 2024 found that the Chinese military is actively seeking to integrate AI into command, control, communications, computers, cyber, intelligence, surveillance, reconnaissance, and targeting &#8212; including through DeepSeek models. An October 2025 <a href="https://jamestown.org/deepseek-use-in-prc-military-and-public-security-systems/">Jamestown Foundation report</a> similarly found that DeepSeek models are being deployed in Chinese military and public security settings, with PLA procurement documents explicitly calling for tools based on DeepSeek&#8217;s models and pilots already underway.</p><p>And the pipeline extends beyond China. A<a href="https://www.csis.org/analysis/how-russia-reshaping-command-and-control-ai-enabled-warfare"> February 2026 CSIS analysis</a> found that Russian military developers are actively adapting Chinese open-weight AI models &#8212; including Qwen, DeepSeek, and others &#8212; for battlefield use in Ukraine, embedding them in air-gapped environments for intelligence processing, reconnaissance analysis, and situational modeling. Sanctions have cut Russia off from developing frontier models independently, making Chinese AI models and smuggled Chinese chips the backbone of Russia&#8217;s military AI stack. Distillation that strengthens Chinese models therefore has downstream effects on Russian military capabilities as well.</p><p>Given that Anthropic&#8217;s Claude, integrated through Palantir&#8217;s Maven Smart System, was already reportedly used in combat during the US <a href="https://www.wsj.com/politics/national-security/pentagon-used-anthropics-claude-in-maduro-venezuela-raid-583aff17">operation</a> to capture Venezuelan President Nicol&#225;s Maduro and subsequently in support of US <a href="https://www.wsj.com/livecoverage/iran-strikes-2026/card/u-s-strikes-in-middle-east-use-anthropic-hours-after-trump-ban-ozNO0iClZpfpL7K7ElJ2">strikes</a> on Iran, there are concerns if distillation attacks can put somewhat equivalent capabilities in adversary hands.</p><p>Additionally, frontier AI models are increasingly used as autonomous coding agents &#8212; writing, debugging, and deploying software with minimal human oversight. When these capabilities are distilled, the benefit extends beyond any single application. Better coding agents accelerate AI development itself: generating training data, writing model infrastructure, automating evaluations, and scaling research workflows. Distilling could thus be a compounding dynamic that makes the stakes of this problem grow with each generation of AI systems. This could additionally accelerate China&#8217;s entire AI development pipeline.<br></p><h2><strong>Distillation may make us overestimate China</strong></h2><p>To be clear, Chinese AI companies have significant independent training capabilities and do make genuine advances. Their AI capabilities are not due to distillation or other forms of IP theft alone. That being said, distillation still makes Chinese AI capabilities appear more independently developed than they are, since they can to some extent draft off of American innovation in addition to doing their own work.</p><p>This risks creating an illusion similar to the Cold War &#8220;missile gap,&#8221; when American policymakers wrongly believed the Soviet Union had surpassed US intercontinental ballistic missile production, despite the US actually having a substantial lead the entire time. Overestimating Soviet strength via the &#8220;missile gap&#8221; led to bad defense planning, and we should avoid a similar overestimate of Chinese AI capabilities.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!zhnm!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1895c978-541d-4533-980b-dc8cb60ece99_750x460.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!zhnm!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1895c978-541d-4533-980b-dc8cb60ece99_750x460.jpeg 424w, https://substackcdn.com/image/fetch/$s_!zhnm!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1895c978-541d-4533-980b-dc8cb60ece99_750x460.jpeg 848w, https://substackcdn.com/image/fetch/$s_!zhnm!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1895c978-541d-4533-980b-dc8cb60ece99_750x460.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!zhnm!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1895c978-541d-4533-980b-dc8cb60ece99_750x460.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!zhnm!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1895c978-541d-4533-980b-dc8cb60ece99_750x460.jpeg" width="750" height="460" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1895c978-541d-4533-980b-dc8cb60ece99_750x460.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:460,&quot;width&quot;:750,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!zhnm!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1895c978-541d-4533-980b-dc8cb60ece99_750x460.jpeg 424w, https://substackcdn.com/image/fetch/$s_!zhnm!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1895c978-541d-4533-980b-dc8cb60ece99_750x460.jpeg 848w, https://substackcdn.com/image/fetch/$s_!zhnm!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1895c978-541d-4533-980b-dc8cb60ece99_750x460.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!zhnm!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1895c978-541d-4533-980b-dc8cb60ece99_750x460.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><h2><strong>A race to the bottom on safety</strong></h2><p>A distillation attack can copy a model&#8217;s capabilities without its corresponding safeguards, allowing the creation of a capable model with a lower barrier to misuse. If adversarial distillation becomes normalized, it may weaken incentives for individual AI companies to invest in safety measures, since those measures can be stripped away by downstream actors. This can create a race-to-the-bottom dynamic in which the most permissive deployment wins market share and investment in safety is not rewarded.</p><p>This is a concern for proliferation of AI misuse given that several AI companies rely on the principle of <em>&#8220;marginal risk&#8221;</em> when determining whether to release their AI models &#8212; assessing how much additional risk their models would create versus the status quo. Chinese models powered by distillation can shift the risk landscape, leading to US developers correspondingly deploying in riskier ways than they otherwise would as justified by not increasing &#8220;marginal risk&#8221; over a Chinese model. Less safe Chinese models can therefore precipitate the release of American models that are more useful to malicious actors.</p><p></p><h2><strong>What should be done?</strong></h2><p>The companies conducting these campaigns proceeded because the expected cost was trivial relative to the value extracted. Even under conservative estimates of distillation&#8217;s impact, the current enforcement gap &#8212; detection without meaningful consequences &#8212; invites escalation. Addressing this requires action from both companies and the government, and the appropriate response may need to scale as our understanding of the threat matures. We recommend two measures for the US government:</p><ul><li><p><strong>Entity List the perpetrators.</strong> The End-User Review Committee should consider adding the Chinese AI companies conducting distillation attacks to the Entity List. The criteria for addition &#8212; &#8220;reasonable cause to believe, based on specific and articulable facts&#8221; that an entity is involved in activities contrary to US national security or foreign policy interests &#8212; appears to be met based on the evidence published by Anthropic, OpenAI, and Google. Entity List designation would require a BIS license, reviewed under a presumption of denial, for any export, re-export, or in-country transfer of items subject to the EAR. Beyond its direct effects, designation signals to the broader AI ecosystem &#8212; cloud providers, chip distributors, equipment vendors &#8212; that transacting with these entities carries regulatory risk.</p></li><li><p><strong>Sanction the attackers and their enablers under the <a href="https://www.congress.gov/117/bills/s1294/BILLS-117s1294enr.pdf">Protecting American Intellectual Property Act</a>.</strong> The PAIP Act requires the President to identify foreign persons who have knowingly engaged in, or benefited from, significant theft of trade secrets of US persons where that theft poses a significant threat to US national security or economic stability. Sanctions under the PAIP Act are more expansive than Entity List designation. The PAIP Act&#8217;s coverage extends to entities that have &#8220;provided significant financial, material, or technological support for&#8221; the theft &#8212; language broad enough to reach the proxy services described above. Outcomes such as inclusion in the Specially Designated Nationals and Blocked Persons (&#8220;SDN List&#8221;), travel sanctions, and being blocked from financial transactions subject to US jurisdiction, would particularly bite for executives heading up companies conducting and facilitating distillation attacks, especially as Chinese AI companies like Alibaba and Bytedance have significant commercial activity outside China. The <a href="https://www.state.gov/releases/office-of-the-spokesperson/2026/02/protecting-americans-from-intellectual-property-theft">first-ever PAIP Act designations</a> were made on February 24, 2026, establishing operational precedent. Whether the aggregate extraction of model capabilities via distillation meets the statutory definition of a &#8220;trade secret&#8221; would be a novel interpretation, but the national security nexus is well-documented, but the evidence published by Anthropic, OpenAI, and Google could potentially form the basis for designations of the companies conducting distillation attacks.</p></li></ul><p></p><p>Additionally, American AI companies are not powerless while waiting for government action. Several steps could significantly raise the cost of distillation attacks:</p><ul><li><p><strong>Implement Know Your Customer (KYC) requirements for API access.</strong> Frontier AI companies should require some sort of lightweight identity verification for API customers, particularly for anyone doing high-volume or enterprise-tier access. Just as financial institutions verify customer identities to prevent money laundering, AI companies should verify that their customers are who they claim to be. This would make it substantially harder for proxy services to spin up thousands of fraudulent accounts.<br></p></li><li><p><strong>Invest in technical detection and rate limiting.</strong> Companies should develop more sophisticated behavioral fingerprinting to identify distillation-pattern queries &#8212; such as systematic chain-of-thought extraction, preference-pair generation, and large-scale data cleaning workloads &#8212; and throttle or block accounts exhibiting these patterns. Some of this is already happening, but the proxy ecosystem&#8217;s persistence suggests current detection capabilities are insufficient.<br></p></li><li><p><strong>Better enforce geographic access restrictions.</strong> Companies should invest in more robust geolocation and network analysis to identify traffic originating from restricted countries, even when routed through proxies. This includes analyzing patterns like VPN usage, payment methods, and account creation behaviors that correlate with proxy network operations.<br></p></li><li><p><strong>Pursue civil litigation against proxy services.</strong> Companies should consider legal action against the commercial proxy services that facilitate distillation at scale. Even where direct action against Chinese AI companies is impractical, the proxy services that operate as intermediaries may be within legal reach and their business model depends on low legal risk.</p></li></ul><h2><strong><br>Looking forward</strong></h2><p>Distillation is a compounding problem. AI systems are increasingly being used to accelerate AI research itself &#8211; Anthropic has declared <a href="https://www.anthropic.com/news/claude-opus-4-6">&#8220;We build Claude with Claude&#8221;</a> and OpenAI <a href="https://openai.com/index/introducing-gpt-5-3-codex/">has said the same about ChatGPT</a>. As this feedback loop tightens, the US lead in AI becomes not just an economic advantage but a potentially decisive one. A country that maintains frontier AI capabilities can use them to pull further ahead; a country that closes the gap through distillation, chip smuggling, or other means enters that same loop from a stronger starting position than its independent capabilities would allow.</p><p>Both American and Chinese AI companies have been explicit that they are trying to build AI systems that would greatly exceed human experts across a wide range of tasks &#8212; including tasks related to military capability and national security &#8212; and that the path runs through AI systems that substantially automate AI research itself. While there is genuine uncertainty about timelines and feasibility, these are not fringe aspirations; they are stated engineering goals backed by tens of billions of dollars. As AI systems approach the ability to meaningfully accelerate their own improvement, it will matter whether the US or China is ahead &#8212; and by how much.</p><p>This is the strategic reality that should frame the distillation debate. We are protecting the seed of a capability that, if current trajectories hold, will compound into something without historical precedent. The steps we&#8217;ve outlined &#8212; Entity List designations, PAIP Act sanctions, KYC requirements, and technical countermeasures &#8212; would materially change the cost-benefit calculus that currently makes distillation a rational strategy. The question is whether policymakers will act while the US lead is still large enough to protect.</p><p>~</p><p><em>If you liked this article, consider hitting the subscribe button below. You can also <a href="https://x.com/theobearman">follow Theo on Twitter</a>!</em></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://blog.peterwildeford.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://blog.peterwildeford.com/subscribe?"><span>Subscribe now</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[The case for paying whistleblowers to report on export violations]]></title><description><![CDATA[A bipartisan, bicameral bill would apply the SEC&#8217;s successful whistleblower incentive model to export enforcement]]></description><link>https://blog.peterwildeford.com/p/the-case-for-paying-whistleblowers</link><guid isPermaLink="false">https://blog.peterwildeford.com/p/the-case-for-paying-whistleblowers</guid><dc:creator><![CDATA[Erich Grunewald]]></dc:creator><pubDate>Thu, 29 Jan 2026 18:34:50 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!HZkc!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f6fd1fd-adb0-4c1c-b8a2-62982347f79f_700x394.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!HZkc!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f6fd1fd-adb0-4c1c-b8a2-62982347f79f_700x394.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!HZkc!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f6fd1fd-adb0-4c1c-b8a2-62982347f79f_700x394.jpeg 424w, https://substackcdn.com/image/fetch/$s_!HZkc!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f6fd1fd-adb0-4c1c-b8a2-62982347f79f_700x394.jpeg 848w, https://substackcdn.com/image/fetch/$s_!HZkc!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f6fd1fd-adb0-4c1c-b8a2-62982347f79f_700x394.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!HZkc!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f6fd1fd-adb0-4c1c-b8a2-62982347f79f_700x394.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!HZkc!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f6fd1fd-adb0-4c1c-b8a2-62982347f79f_700x394.jpeg" width="700" height="394" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1f6fd1fd-adb0-4c1c-b8a2-62982347f79f_700x394.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:394,&quot;width&quot;:700,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Nvidia AI chips worth $1bn smuggled to China after Trump export controls&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Nvidia AI chips worth $1bn smuggled to China after Trump export controls" title="Nvidia AI chips worth $1bn smuggled to China after Trump export controls" srcset="https://substackcdn.com/image/fetch/$s_!HZkc!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f6fd1fd-adb0-4c1c-b8a2-62982347f79f_700x394.jpeg 424w, https://substackcdn.com/image/fetch/$s_!HZkc!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f6fd1fd-adb0-4c1c-b8a2-62982347f79f_700x394.jpeg 848w, https://substackcdn.com/image/fetch/$s_!HZkc!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f6fd1fd-adb0-4c1c-b8a2-62982347f79f_700x394.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!HZkc!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f6fd1fd-adb0-4c1c-b8a2-62982347f79f_700x394.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><em>This is a guest post written by Erich Grunewald, a prior &#8220;Power Law&#8221; contributor who just started a new blog on AI and compute topics called <strong><a href="https://www.the-substrate.net/">The Substrate</a> </strong>alongside other members of the compute policy team at the Institute for AI Policy and Strategy. This post is crossposted from his new blog. <a href="https://www.the-substrate.net/">Check it out</a>!</em></p><p>~</p><p>The US has a massive export enforcement problem. It&#8217;s likely that <a href="https://www.cnas.org/publications/reports/countering-ai-chip-smuggling-has-become-a-national-security-priority">over 100,000 export-controlled AI chips</a> were smuggled into China in 2024. To give a sense of scale, the xAI Colossus cluster in Memphis, Tennessee, comprised first 100,000 and later 200,000 AI chips. That&#8217;s roughly an xAI Colossus cluster being smuggled to China each year. The main reason we know this is that smugglers are so unafraid that they&#8217;re willing to talk about their operations to journalists; this has happened repeatedly during the past year and a half.</p><p>AI chip smuggling is far from the only enforcement problem. In 2024, <a href="https://www.nytimes.com/2024/10/29/business/tsmc-huawei-computer-chips.html">Huawei got TSMC to illegally fabricate</a> over two million of its AI chip dies through front companies, despite sanctions. That is a far larger quantity than the number of Huawei AI chips fabricated domestically in China that year. We&#8217;ve also seen likely violations related to <a href="https://newsletter.semianalysis.com/p/huawei-ascend-production-ramp">high bandwidth memory</a> and <a href="https://newsletter.semianalysis.com/p/fab-whack-a-mole-chinese-companies">semiconductor manufacturing equipment</a>, which help China make its own AI chips to compete against NVIDIA.</p><p><strong>What if you could pay insiders many millions of dollars to inform US authorities about such violations, at almost no cost to the US government?</strong> That would likely surface a large number of high quality tips about important violations, which would greatly aid US authorities in detecting, punishing and deterring such violations.</p><p>This idea may sound outlandish, but it&#8217;s actually possible. In fact, there is a law being discussed in Congress that would accomplish exactly this! But before we get there, let&#8217;s take a brief detour to the Securities and Exchange Commission (SEC) and the 2008 financial crisis.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://blog.peterwildeford.com/p/the-case-for-paying-whistleblowers?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://blog.peterwildeford.com/p/the-case-for-paying-whistleblowers?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p></p><h2><strong>The SEC whistleblower program</strong></h2><p>In 2008, the US economy was reeling from the housing and mortgage crisis. Late that year, Bernie Madoff sat down with his two sons and admitted to them that the investment business he&#8217;d been running for two decades was a giant fraud, a Ponzi scheme to end all Ponzi schemes. Because of these two crises, there was a desire among policymakers to strengthen financial regulation and oversight.</p><p>Related to the Madoff scandal in particular, the SEC was under criticism for failing to properly investigate several credible reports about it. An employee at a rival investment firm, Harry Markopolos, had been asked by his employers to figure out how Madoff could post such consistently excellent returns, and soon realized that the returns were impossible with Madoff&#8217;s claimed strategy. Markopolos later <a href="https://www.npr.org/2010/03/02/124208012/madoff-whistleblower-sec-failed-to-do-the-math">said in an interview</a>: &#8220;I read his strategy statement, and it was so poorly put together. His strategy as depicted would have trouble beating a zero return, and his performance chart went up at a 45-degree line: that line doesn&#8217;t exist in finance, it only exists in geometry classes.&#8221;</p><p>Markopolos sent reports to the SEC detailing Madoff&#8217;s fraudulent activities on multiple occasions before the 2008 financial crisis. However, the SEC failed to properly investigate these reports, leaving Madoff free to continue defrauding investors until the financial crisis made its collapse imminent. Lawmakers realized that reports of wrongdoing from the general public could be a valuable tool for detecting and deterring securities laws violations.</p><p>One result of this, signed into law in 2010 as part of the Dodd-Frank Act, was the SEC whistleblower program.<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-1" href="#footnote-1" target="_self">1</a></p><p>The SEC whistleblower program works like this. First and most importantly, whistleblowers get 10-30% of any penalty resulting from their report. This can be many millions of dollars&#8212;the largest reward to date, paid out in 2023, <a href="https://www.sec.gov/newsroom/press-releases/2023-89">was nearly $280 million</a>. This monetary incentive is paired with protections against retaliation from their employers, confidentiality guarantees, and the ability to make reports to the SEC anonymously through an attorney. To pay out whistleblower rewards, the Dodd-Frank Act also sets up an Investor Protection Fund, which receives penalties from securities violations (previously these would go to the Treasury).</p><p>The SEC whistleblower program is widely considered to have been an enormous success. It&#8217;s now one of the key ways that securities law is enforced in the US. It has <a href="https://kkc.com/frequently-asked-questions/sec-whistleblower-program/">helped generate</a> $7.3 billion to $22 billion in penalties since its inception in 2011<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-2" href="#footnote-2" target="_self">2</a>, and has <a href="https://www.whistleblowers.org/rewards-for-non-u-s-whistleblowers/">received reports</a> from at least 130 countries. Quantitative evaluations are rarer, but existing research suggests it has <a href="https://onlinelibrary.wiley.com/doi/10.1111/1911-3846.12884">reduced financial reporting fraud</a>, <a href="https://papers.ssrn.com/sol3/papers.cfm?abstract_id=3672026">deterred insider trading</a>, and <a href="https://papers.ssrn.com/sol3/papers.cfm?abstract_id=3105521">caused companies to strengthen compliance programs</a>.</p><p></p><h2><strong>The Stop Stealing Our Chips Act</strong></h2><p>Now the question is, could you adopt the SEC whistleblower program model for the Bureau of Industry and Security (BIS) and export violations? The <strong><a href="https://kean.house.gov/sites/evo-subsites/kean.house.gov/files/evo-media-document/stop-stealing-our-chips-act-kean-final.pdf">Stop Stealing Our Chips Act</a> </strong>&#8212; introduced <a href="https://www.rounds.senate.gov/newsroom/press-releases/rounds-introduces-legislation-to-prevent-smuggling-of-american-ai-chips-into-china">into the Senate</a> in April 2025 by Senators Rounds (R-SD) and Warner (D-VA) and <a href="https://kean.house.gov/media/press-releases/kean-johnson-introduce-bill-protect-american-ai-chips-strengthening-export">into the House</a> a couple of weeks ago by Representatives Kean (R-NJ) and Johnson (D-TX) &#8212; would do exactly this.</p><p>The Stop Stealing Our Chips Act (henceforth, SSOCA) is closely modeled on the SEC whistleblower program, with some changes to adapt it for the export enforcement situation. It too offers whistleblowers 10-30% of any resulting penalty along with whistleblower protections, including the possibility of making anonymous reports to BIS.</p><p>The first thing to note here is the financial incentive. As economists always tell us, <a href="https://en.wikipedia.org/wiki/They_Shoot_Horses,_Don%27t_They%3F_(film)">financial incentives are incredibly powerful</a>, and the fines for these violations can be enormous:</p><ul><li><p>There have been <a href="https://www.bloomberg.com/news/features/2024-10-27/russia-is-getting-nvidia-ai-chips-from-an-indian-pharma-company">several</a> <a href="https://www.reuters.com/world/china/nvidia-ai-chips-worth-1-billion-entered-china-despite-us-curbs-ft-reports-2025-07-24/">news</a> <a href="https://techcrunch.com/2025/03/13/singapore-grants-bail-for-nvidia-chip-smugglers-in-alleged-390m-fraud/">reports</a> of operations involving on the order of 10,000 smuggled AI chips, meaning roughly $400 million worth. BIS can fine up to twice the value of the related transaction, so that could be a penalty of $800 million, for just one smuggler who spoke to the news media. If a whistleblower reports on that, they could get up to 30% or $240 million (leaving $560 million for the US government).</p></li><li><p>The massive TSMC-Huawei violation&#8212;which was only detected when an independent organization did a teardown of a Huawei chip&#8212;<a href="https://www.reuters.com/technology/tsmc-could-face-1-billion-or-more-fine-us-probe-sources-say-2025-04-08/">could reportedly result in</a> a $1 billion fine. This would have been up to $300 million for an informant.</p></li></ul><p>Beyond catching violations, a well-publicized program could have significant deterrent effects. If everyone in a supply chain&#8212;sales reps, warehouse workers, freight forwarders, accountants&#8212;knows that reporting can yield millions, violators face a much riskier environment. This effect could be realized even before the whistleblower program comes into effect, as the law would allow whistleblowers to report on violations that occurred before it was signed into law.</p><p></p><h2><strong>Would the BIS program actually surface any tips?</strong></h2><p>All right, hundreds of millions of dollars is a strong incentive. But, you may ask, are there actually people with information about these violations who would be willing to step up and blow the whistle? Why, yes there are!</p><p>Take AI chip smuggling operations: these involve lots of people who could potentially file reports, in other words people who have relevant information and would like to get millions of dollars. This includes, for example, people working in sales at exporters <a href="https://hindenburgresearch.com/smci/">with questionable compliance practices</a>; employees at local resellers, freight forwarders, logistics companies, warehouses, or data centers where the chips <a href="https://www.theinformation.com/articles/nvidia-ai-chip-smuggling-to-china-becomes-an-industry">are temporarily housed</a>; and accountants and lawyers.</p><p>In March 2025, Singaporean authorities arrested three people for smuggling $390 million worth of AI servers. These arrests were the result of an &#8220;anonymous tip-off&#8221;, in other words a whistleblower report! It seems likely that the recent <a href="https://www.justice.gov/opa/pr/us-authorities-shut-down-major-china-linked-ai-tech-smuggling-network">Operation Gatekeeper</a> arrests of an AI chip smuggling ring operating out of Texas and New York were also the result of an insider tip.</p><p>The story is similar for the TSMC-Huawei violation, where there were likely many TSMC employees who could&#8217;ve known about this problem and informed the US government. The only reason the US ultimately found out about this violation was because an independent party&#8212;TechInsights&#8212;did a teardown of a Huawei AI chip, and noticed it was TSMC-fabricated. A BIS whistleblower program would likewise incentivize such actors to look for evidence of violations and report those to the US government. This type of information is hugely valuable; it makes no sense to sit around and wait for people to offer it out of the goodness of their hearts.</p><p>As with the SEC program, the SSOCA makes foreign nationals eligible for rewards. This is important because many export violations happen in third countries, where goods are diverted via reexport or transshipment. (The SSOCA does however wisely make some exceptions for known terrorists and sanctioned persons, who are not eligible for rewards.) This is similar to how the intelligence community pays foreign informants, who provide the US government with information that benefits US national security.</p><p></p><h2><strong>Would BIS be able to run the program?</strong></h2><p>At this point, the wise reader will ask, &#8220;Isn&#8217;t BIS <a href="https://www.thefai.org/posts/spreadsheets-vs-smugglers-modernizing-the-bis-for-an-era-of-tech-rivalry">extremely resource constrained</a>? If so, how is it supposed to process and investigate a bunch of incoming tips, determine awards, and carry out outreach on the program?&#8221; After all, BIS&#8217;s budget for enforcement has been essentially flat when accounting for inflation for at least the past five years (see figure), despite BIS receiving a vastly increased scope of responsibilities due to the AI chip export controls introduced in October 2022 and the Russian invasion of Ukraine and all the diversion related to that conflict.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Ptli!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4d06ed97-7351-4192-b66e-8675846fde29_1552x580.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Ptli!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4d06ed97-7351-4192-b66e-8675846fde29_1552x580.png 424w, https://substackcdn.com/image/fetch/$s_!Ptli!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4d06ed97-7351-4192-b66e-8675846fde29_1552x580.png 848w, https://substackcdn.com/image/fetch/$s_!Ptli!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4d06ed97-7351-4192-b66e-8675846fde29_1552x580.png 1272w, https://substackcdn.com/image/fetch/$s_!Ptli!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4d06ed97-7351-4192-b66e-8675846fde29_1552x580.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Ptli!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4d06ed97-7351-4192-b66e-8675846fde29_1552x580.png" width="1456" height="544" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4d06ed97-7351-4192-b66e-8675846fde29_1552x580.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:544,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:84018,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://peterwildeford.substack.com/i/186223296?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4d06ed97-7351-4192-b66e-8675846fde29_1552x580.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Ptli!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4d06ed97-7351-4192-b66e-8675846fde29_1552x580.png 424w, https://substackcdn.com/image/fetch/$s_!Ptli!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4d06ed97-7351-4192-b66e-8675846fde29_1552x580.png 848w, https://substackcdn.com/image/fetch/$s_!Ptli!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4d06ed97-7351-4192-b66e-8675846fde29_1552x580.png 1272w, https://substackcdn.com/image/fetch/$s_!Ptli!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4d06ed97-7351-4192-b66e-8675846fde29_1552x580.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">(See data on <a href="https://www.the-substrate.net/p/the-case-for-paying-whistleblowers">The Substrate</a>)</figcaption></figure></div><p>Good question! The answer is that these activities&#8212;investigating whistleblower reports, determining awards, and carrying out outreach&#8212;would also be financed through incoming penalties. This is one of the most notable differences between the SSOCA and the SEC program. The SSOCA authorizes BIS to use money from penalties for a few additional purposes and not only for paying out rewards to whistleblowers. (As currently written, the SSOCA would only allow BIS to receive money from penalties that stem from whistleblower reports, but I think this should be expanded to cover all penalties for BIS-related violations.)</p><p>Today, any fine levied by BIS goes straight to the Treasury, or in rare cases it is earmarked for some specific fund, such as the <a href="https://en.wikipedia.org/wiki/Crime_Victims_Fund">Crime Victims Fund</a>. What the SSOCA would do is redirect these to an Export Compliance Accountability Fund. This Fund would be used to pay rewards to whistleblowers; any money left over would go first to core functions of the BIS whistleblower program, and then to export enforcement activities more broadly.</p><p>There is a separate but related question of how the program would be funded initially, if it&#8217;s mainly intended to be funded through penalties. However, BIS already has a fairly steady stream of enforcement actions, including from likely insider tips, without any whistleblower incentive program (see figure). BIS may also be able to direct some of its appropriated resources to the program in the first one or two years, in order to get it up and running.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!BKA4!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefb6e0cc-d0ca-4583-9762-2c08757eeb37_1506x596.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!BKA4!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefb6e0cc-d0ca-4583-9762-2c08757eeb37_1506x596.png 424w, https://substackcdn.com/image/fetch/$s_!BKA4!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefb6e0cc-d0ca-4583-9762-2c08757eeb37_1506x596.png 848w, https://substackcdn.com/image/fetch/$s_!BKA4!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefb6e0cc-d0ca-4583-9762-2c08757eeb37_1506x596.png 1272w, https://substackcdn.com/image/fetch/$s_!BKA4!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefb6e0cc-d0ca-4583-9762-2c08757eeb37_1506x596.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!BKA4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefb6e0cc-d0ca-4583-9762-2c08757eeb37_1506x596.png" width="1456" height="576" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/efb6e0cc-d0ca-4583-9762-2c08757eeb37_1506x596.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:576,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:108433,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://peterwildeford.substack.com/i/186223296?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefb6e0cc-d0ca-4583-9762-2c08757eeb37_1506x596.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!BKA4!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefb6e0cc-d0ca-4583-9762-2c08757eeb37_1506x596.png 424w, https://substackcdn.com/image/fetch/$s_!BKA4!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefb6e0cc-d0ca-4583-9762-2c08757eeb37_1506x596.png 848w, https://substackcdn.com/image/fetch/$s_!BKA4!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefb6e0cc-d0ca-4583-9762-2c08757eeb37_1506x596.png 1272w, https://substackcdn.com/image/fetch/$s_!BKA4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefb6e0cc-d0ca-4583-9762-2c08757eeb37_1506x596.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">(See data on <a href="https://www.the-substrate.net/p/the-case-for-paying-whistleblowers">The Substrate</a>)</figcaption></figure></div><p><strong>It seems likely that this program would pay for itself if implemented.</strong> That&#8217;s because the program would likely help BIS detect more violations and therefore levy more penalties than it would without the program. It could well end up both reducing the number of violations and also generating additional revenue for the federal government by making it much more likely that violations are detected and enforced. The losers here would be the smugglers and other bad actors who wake up every day trying to figure out ways of harming US national security.</p><p>BIS&#8217;s entire budget for fiscal year 2025 was about $191 million, <a href="https://www.cnas.org/publications/reports/countering-ai-chip-smuggling-has-become-a-national-security-priority">likely far smaller</a> than the collective profits of AI chip smugglers alone, which may well have exceeded $1 billion. A single successful enforcement action against a major smuggling operation could pay for BIS&#8217;s entire annual budget&#8212;for example, last month US authorities <a href="https://www.justice.gov/opa/pr/us-authorities-shut-down-major-china-linked-ai-tech-smuggling-network">arrested three individuals</a> accused of smuggling AI chips worth $160 million to China, which could result in a penalty of $320 million. There are likely dozens of such cases remaining to be discovered. A BIS whistleblower program like the one described in the SSOCA could create a virtuous cycle where more tips and better enforcement lead to more penalties and rewards, which in turn leads both to more tips by publicizing the program and also more resources for enforcement.</p><p>~</p><p><em>If you liked this post, consider subscribing to <strong><a href="https://www.the-substrate.net/">The Substrate</a></strong> where Erich and others will be writing more about AI and compute topics.</em></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.the-substrate.net/&quot;,&quot;text&quot;:&quot;Subscribe to The Substrate&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.the-substrate.net/"><span>Subscribe to The Substrate</span></a></p><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-1" href="#footnote-anchor-1" class="footnote-number" contenteditable="false" target="_self">1</a><div class="footnote-content"><p>There was also a CFTC program established at the same time, but it is less well known so I just discuss the SEC program here.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-2" href="#footnote-anchor-2" class="footnote-number" contenteditable="false" target="_self">2</a><div class="footnote-content"><p>The SEC <a href="https://kkc.com/frequently-asked-questions/sec-whistleblower-program/">has awarded</a> more than $2.2 billion to whistleblowers since the program&#8217;s inception. In the extreme case of all those awards being 10% of the related penalty, that would imply $22 billion in penalties. In the other extreme case of all those awards being 30% of the penalty, it would imply $7.3 billion.</p><p></p></div></div>]]></content:encoded></item><item><title><![CDATA[Maduro has been captured. What's next?]]></title><description><![CDATA[The operation was flawless. What comes next is anyone's guess.]]></description><link>https://blog.peterwildeford.com/p/maduro-has-been-captured-whats-next</link><guid isPermaLink="false">https://blog.peterwildeford.com/p/maduro-has-been-captured-whats-next</guid><dc:creator><![CDATA[Peter Wildeford]]></dc:creator><pubDate>Sat, 03 Jan 2026 23:27:32 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!ydGE!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3406893d-9fcd-4803-9233-1c3fde1b8b8a_1600x900.webp" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ydGE!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3406893d-9fcd-4803-9233-1c3fde1b8b8a_1600x900.webp" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ydGE!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3406893d-9fcd-4803-9233-1c3fde1b8b8a_1600x900.webp 424w, https://substackcdn.com/image/fetch/$s_!ydGE!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3406893d-9fcd-4803-9233-1c3fde1b8b8a_1600x900.webp 848w, https://substackcdn.com/image/fetch/$s_!ydGE!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3406893d-9fcd-4803-9233-1c3fde1b8b8a_1600x900.webp 1272w, https://substackcdn.com/image/fetch/$s_!ydGE!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3406893d-9fcd-4803-9233-1c3fde1b8b8a_1600x900.webp 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ydGE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3406893d-9fcd-4803-9233-1c3fde1b8b8a_1600x900.webp" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3406893d-9fcd-4803-9233-1c3fde1b8b8a_1600x900.webp&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Trump hails Delta Force raid that seized Maduro in Venezuela&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Trump hails Delta Force raid that seized Maduro in Venezuela" title="Trump hails Delta Force raid that seized Maduro in Venezuela" srcset="https://substackcdn.com/image/fetch/$s_!ydGE!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3406893d-9fcd-4803-9233-1c3fde1b8b8a_1600x900.webp 424w, https://substackcdn.com/image/fetch/$s_!ydGE!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3406893d-9fcd-4803-9233-1c3fde1b8b8a_1600x900.webp 848w, https://substackcdn.com/image/fetch/$s_!ydGE!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3406893d-9fcd-4803-9233-1c3fde1b8b8a_1600x900.webp 1272w, https://substackcdn.com/image/fetch/$s_!ydGE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3406893d-9fcd-4803-9233-1c3fde1b8b8a_1600x900.webp 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><em>About the author: Peter Wildeford is a top forecaster, ranked top 1% every year since 2022. Here, he shares the news and analysis that informs his forecasts.</em></p><div><hr></div><p>At 2am local time in Caracas on January 3rd, explosions lit up the night sky over Venezuela&#8217;s capital. By 5:21am, President Donald Trump announced on Truth Social that Nicol&#225;s Maduro and his wife Cilia Flores had been &#8220;captured and flown out of the Country.&#8221; The operation, codenamed <em>Absolute Resolve</em>, deployed <a href="https://www.nbcnews.com/world/latin-america/live-blog/venezuela-explosions-trump-maduro-live-updates-rcna251053">approximately 150 aircraft</a> and sent Maduro to New York to face narco-terrorism charges. And in what could be symbolism or coincidence, the operation occurred exactly 36 years to the day after <a href="https://en.wikipedia.org/wiki/United_States_invasion_of_Panama">the US&#8217;s capture of Panama&#8217;s Manuel Noriega</a> and exactly 6 years after <a href="https://en.wikipedia.org/wiki/Assassination_of_Qasem_Soleimani">Trump&#8217;s strike on Iran&#8217;s Qasem Soleimani</a>.</p><p>But execution is not the same as strategy. While the operation itself appears to have been flawlessly executed, what comes next isn&#8217;t clear. Let&#8217;s dig in.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://blog.peterwildeford.com/p/maduro-has-been-captured-whats-next?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://blog.peterwildeford.com/p/maduro-has-been-captured-whats-next?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p></p><h2>How Venezuela reached the breaking point</h2><p>Like most events, this is just the continuation of decades of history. We start with Hugo Ch&#225;vez, a charismatic former paratrooper who won Venezuela&#8217;s presidency in 1998 on a wave of populist anger. Flush with oil revenue during the commodity boom of the 2000s, Ch&#225;vez built a socialist state that redistributed wealth to the poor while systematically dismantling democratic institutions. When Ch&#225;vez died of cancer in March 2013, he left behind a handpicked successor: Nicol&#225;s Maduro.</p><p>But the petrostate model that was successful for Ch&#225;vez had begun unraveling. Global oil prices collapsed from over $100 per barrel in 2014 to below $30 by early 2016. Venezuela&#8217;s economy, dependent on oil for 95% of export revenue, imploded. Hospitals ran out of medicine. Grocery stores emptied.</p><p>Maduro responded not with reform but with repression. When the opposition won control of the National Assembly in 2015, he packed the Supreme Court and created a parallel legislature to strip it of power. When protesters filled the streets in 2017, <a href="https://en.wikipedia.org/wiki/2017_Venezuelan_protests">security forces killed over 160</a>. Opposition leaders were jailed, exiled, or banned from office.</p><p>The 2018 presidential election &#8212; which Maduro &#8220;won&#8221; after banning his main rivals &#8212; triggered an international crisis. In January 2019, Juan Guaid&#243;, a 35-year-old opposition legislator, <a href="https://2017-2021.state.gov/recognition-of-juan-guaido-as-venezuelas-interim-president/">declared himself interim president</a> under a constitutional provision allowing the Assembly head to assume power when the presidency is deemed illegitimately won. The Trump administration recognized him within minutes. <a href="https://en.wikipedia.org/wiki/Responses_to_the_Venezuelan_presidential_crisis">Nearly 60 countries followed</a>.</p><p>But Guaid&#243; never gained control of anything that mattered. The military stayed loyal to Maduro. By December 2022, his public support had collapsed to single digits, and the Maduro opposition parties supporting Guaid&#243;<a href="https://www.pbs.org/newshour/politics/venezuelan-opposition-strips-juan-guaido-of-presidential-role"> voted to pull the plug and dissolve his interim parallel government</a>, realizing they had accomplished nothing. Guaid&#243; now lives in exile in Miami.</p><p>Mar&#237;a Corina Machado, recent Nobel Peace Prize winner, represented something different. When the opposition held primaries in October 2023, Machado <a href="https://en.wikipedia.org/wiki/Mar%C3%ADa_Corina_Machado">won with 93% of the vote</a>. Polls showed her crushing Maduro in a general election. So the regime did what it always does: <a href="https://www.aljazeera.com/news/2024/1/27/venezuela-court-disqualifies-leading-opposition-presidential-candidate">the Supreme Court upheld a 15-year ban</a> on her holding office, citing her support for US sanctions and involvement with Guaid&#243;. But rather than concede, Machado found a workaround: Edmundo Gonz&#225;lez, a 75-year-old retired diplomat with no desire to campaign, who agreed to serve as her stand-in.</p><p>On July 28, 2024, Venezuelans went to the polls. The government&#8217;s response was brazenly fraudulent. The National Electoral Council declared Maduro the winner with 51.95% without publishing the precinct-by-precinct tallies that had accompanied every previous Venezuelan election. Officials blamed a &#8220;cyberattack from North Macedonia&#8221; &#8212; completely baseless.</p><p>But the opposition had prepared. In incredible bravery and coordination, approximately one million volunteers <a href="https://www.cnn.com/2024/08/02/americas/venezuelas-tally-sheets-intl-latam/index.html">secretly collected the election tally sheets</a> from over 83.5% of polling stations on election night. Their data told a starkly different story: <a href="https://www.pbs.org/newshour/world/ap-review-vote-tallies-provided-by-venezuela-opposition-casts-doubt-on-official-election-results">Gonz&#225;lez had won with roughly 67% to Maduro&#8217;s 30%</a>.</p><p>But Maduro was undeterred and what followed was brutal repression. Security forces went door-to-door arresting protesters, poll workers, and opposition members. Gonz&#225;lez fled to Spain in September after authorities issued an arrest warrant and Machado went underground.</p><p>When Maduro proceeded with his inauguration on January 10, 2025, the Trump administration began escalating pressure. The bounty on Maduro <a href="https://www.state.gov/reward-offer-increase-of-up-to-50-million-for-information-leading-to-arrest-and-or-conviction-of-nicolas-maduro/">was raised to $50 million</a>, the highest in State Department history. By late 2025, the US had deployed the USS Gerald R. Ford carrier strike group, approximately 15,000 soldiers, F-35 jets, and a nuclear-powered submarine to the Caribbean. Trump declared a &#8220;blockade&#8221; and announced the country was &#8220;completely surrounded by the largest Armada ever assembled in the History of South America.&#8221;</p><p>Then came today.</p><p></p><h2>Absolute Resolve</h2><p>The operation had been months in the making. CIA teams tracked Maduro&#8217;s pattern of life &#8212; where he slept, what he ate, how he moved. US forces rehearsed the raid on a replica of his residence. Trinidad and Tobago quietly signed an agreement granting US military access to its airports. By late December, troops were staged and waiting for favorable conditions.</p><p>Trump gave final approval around 11 PM Eastern on January 2. The weather was good. The trigger was pulled. 50 aircraft launched from 20 different bases to dismantle Venezuela&#8217;s air defenses and clear a path for the helicopters coming behind them. Parts of southern Caracas went dark in what Trump later said was due to &#8220;certain expertise.&#8221; Behind the air assault came the 160th Special Operations Aviation Regiment that carried Delta Force operators with a specific target: Maduro&#8217;s residence inside Fort Tiuna.</p><p><a href="https://www.foxnews.com/politics/trump-reveals-venezuelas-maduro-captured-fortress-like-house-he-got-bum-rushed-so-fast">According to Trump</a>, Maduro was in &#8220;a house that was more like a fortress than a house. It had steel doors, it had what they call a safety space &#8212; solid steel all around. He didn&#8217;t get that space closed. He was trying to get into it, but he got bum rushed so fast that he didn&#8217;t get into that.&#8221; No Americans died. By 3:29 AM Eastern, the assault force was back over water, Maduro in hand.</p><p><a href="https://news.sky.com/story/venezuela-latest-explosions-heard-in-capital-of-caracas-13489831">Opposition sources told Sky News they believe Maduro&#8217;s capture was a &#8220;negotiated exit,&#8221;</a> with portions of the regime facilitating rather than resisting. The evidence is circumstantial but suggestive: despite months of warning, Venezuela&#8217;s Russian-supplied S-300 air defense systems never prevented helicopter ingress. The military mounted no meaningful counterattack. Interior Minister Diosdado Cabello appeared on television vowing defiance, but the streets remained largely empty.</p><p>Whether this was collapse, capitulation, or negotiated exit, the result is the same: for the first time since the US toppled Panama&#8217;s dictator Noriega in 1990, the United States has forcibly removed a sitting head of state from power.</p><p></p><h3>The strategic logic</h3><p>But why Venezuela and why now? The Trump administration is explicitly <em>not</em> calling this regime change but instead framing the operation as the Department of Justice executing an arrest warrant. &#8220;At its core, this was an arrest of two indicted fugitives of American justice, and the Department of War supported the Department of Justice in that job,&#8221; Rubio <a href="https://abcnews.go.com/Politics/republicans-largely-back-trump-venezuela-action-democrats-decry/story?id=128866819">said at the Mar-a-Lago presser</a>. </p><p>But this seems flimsy &#8212; it definitely does seem to be regime change. And maybe this is justified. Maduro is genuinely a bad guy. He stole an election, became dictator, was repressive, is leading a lot of cocaine trafficking, and drove 20% of the population to flee the country. The humanitarian and democratic case against him is airtight.</p><p>Additionally, while Trump owns the operation, Venezuela has been Rubio&#8217;s white whale for years. He had consistently been the most hawkish voice on Caracas in the Senate, viewing Maduro&#8217;s removal as both a strategic imperative and good politics with Florida&#8217;s Cuban and Venezuelan voters. This continued as Rubio joined the Trump administration. In July, <a href="https://www.newsnationnow.com/politics/marco-rubio-nicolas-maduro-not-president-venezuela/">Rubio posted</a> that &#8220;Maduro is NOT the President of Venezuela&#8221; but rather &#8220;the head of the Cartel de Los Soles, a narco-terror organization which has taken possession of a country.&#8221; At the presser, he was already <a href="https://www.foxnews.com/politics/rubio-cuba-id-concerned-after-us-military-arrests-venezuelan-leader-maduro">pivoting to Cuba</a>, noting that Maduro&#8217;s security detail and spy agency were &#8220;basically full of Cubans&#8221; and warning Havana that &#8220;I&#8217;d be concerned.&#8221;</p><p>Moreover, the oil angle is explicit. Trump announced the US would be &#8220;very strongly involved&#8221; in Venezuela&#8217;s oil industry, with American companies moving in to extract wealth that would flow to both Venezuela and &#8220;the United States in the form of reimbursement.&#8221; Venezuela has the world&#8217;s largest proven oil reserves. Whether this is opportunism layered onto the drug war justification or the actual primary motivation, Trump isn&#8217;t hiding that it&#8217;s part of the motivation.</p><p></p><h3>What does this mean for geopolitics?</h3><p>But there&#8217;s also a geopolitical strategic case for toppling Maduro. Venezuela has hosted Russian military assets&#8212;Tu-160 bombers visited in 2018 and 2024, and Russian advisors have been embedded with Venezuelan forces. China holds billions in Venezuelan debt and has been receiving sanctioned oil shipments.</p><p>Back in 1902, Venezuela of all places was facing a blockade not from US forces but from European forces. Venezuela had defaulted on its debts to European creditors and so Britain, Germany, and Italy responded by blockading Venezuelan ports. US President Theodore Roosevelt watched with alarm, seeing that the Europeans might use this as a basis to return to the colonialization of the Americas. Roosevelt declared the Roosevelt Corollary &#8212; the US should be the police of the Americas, not Europe. This was an expansion to the earlier 1823 Monroe Doctrine, a declaration from President James Monroe that the Americas were in the sphere of influence of the US and no longer open for colonization from Europe.</p><p>As <a href="https://defenseanalyses.org/work/trump-corollary/">Anthony Constantini argued</a>, the Trump administration has been developing what amounts to a &#8220;Trump Corollary&#8221; to go along with the "Roosevelt Corollary&#8221;, updating the Monroe Doctrine for the 21st century. The Trump Corollary extends American dominance claims over the entire Americas beyond military presence to economic influence, hence the pressure over Chinese-controlled ports at the Panama Canal. Having a hostile drug-smuggling dictator with Russian and Chinese military ties 1,300 miles from Miami is exactly the kind of problem the Monroe Doctrine was designed to address, let alone the Trump Corollary.</p><p>This reassertion of hemispheric dominance invites a question: does it signal a broader return to great power spheres of influence? The French term <em>pr&#233; carr&#233;</em> &#8212; literally &#8220;square field&#8221; &#8212; describes the logic of exclusive domains, where Russia claims its near abroad, China asserts control over East Asia (including Taiwan), and the US enforces primacy in the Western Hemisphere but retreats from Europe and Asia. Under this framework, major powers implicitly agree to stay out of each other&#8217;s backyards.</p><p>There&#8217;s perhaps something to this interpretation. Trump has shown little appetite for defending Ukraine, and his pressure on European allies to handle their own defense suggests a willingness to let that theater go. Venezuela would then represent America claiming its <em>pr&#233; carr&#233;</em> while ceding others to rival powers.</p><p>The December 2025 <a href="https://www.whitehouse.gov/wp-content/uploads/2025/12/2025-National-Security-Strategy.pdf">National Security Strategy</a> provides our best window into the administration&#8217;s thinking, which actually put the Western Hemisphere appears <em>first</em> among regional priorities &#8212; before Asia, before Europe, before the Middle East. The strategy explicitly calls for &#8220;a readjustment of our global military presence to address urgent threats in our Hemisphere... and away from theaters whose relative import to American national security has declined in recent decades.&#8221;</p><p>Here the language on the &#8220;Trump Corollary&#8221; is unambiguous: &#8220;We will deny non-Hemispheric competitors the ability to position forces or other threatening capabilities, or to own or control strategically vital assets, in our Hemisphere.&#8221; This is the Roosevelt Corollary with updated targets &#8212; swap European colonial powers for Chinese port operators and Russian military advisors.</p><p>An alternative perspective is what analyst <a href="https://peterwildeford.substack.com/p/the-munich-pivot-understanding-americas">Tanner Greer calls the &#8220;prioritizer&#8221; framework</a>, under which China is a unique peer competitor and threat to the US, requiring America&#8217;s full attention and focus. Under this logic, the US saves its power for countering China, avoids lasting entanglements in Europe and the Middle East, but does use decisive force for discrete, limited objectives.</p><p>It&#8217;s not clear what, if any, logic Trump is following. Perhaps Trump&#8217;s approach is neither cleanly <em>pr&#233; carr&#233;</em> or &#8220;prioritizer&#8221; but something more opportunistic. The strategy asserts hemispheric dominance aggressively while adopting a more transactional posture toward great power competition. The statement that &#8220;the days of the United States propping up the entire world order like Atlas are over&#8221; is telling. This isn&#8217;t sphere-of-influence realism so much as selective assertiveness, with maximum force where costs are low and benefits are tangible, across targets as wide ranging as Venezuela, Iran, and even Nigeria &#8212; but explicit restraint or burden-shifting where they&#8217;re not, like Ukraine. Where Taiwan falls on this logic is not immediately clear &#8212; strategic ambiguity at its finest.</p><p></p><h2>What happens next?</h2><p>But of course, the harder question is what comes for Venezuela after the helicopters leave. While the execution was successful, there doesn&#8217;t seem to be any clear plan for what comes next.</p><p>The Noriega parallels are striking &#8212; both leaders faced drug trafficking indictments, both stole elections, and the US recognized the opposition candidate as legitimate. But the differences matter more. In Panama, the US already had 12,000+ troops stationed in the Canal Zone &#8212; roughly the size of the entire Panamanian military &#8212; and a government-in-waiting ready to assume power. Venezuela is 12 times larger with over 100,000 troops equipped with Russian weapons. There is no equivalent infrastructure for transition.</p><p>Additionally, Noriega was the beginning and end of the Noriega dictatorship. But the Maduro dictatorship is more embedded &#8212; Maduro was never just about Maduro. There instead remains is a collective dictatorship &#8212; security services, patronage networks, illicit finance pipelines, and a political-military elite that shares criminal liability with Maduro and faces their own US indictments. Interior Minister Diosdado Cabello, who appeared on television today saying the Venezuelan government would not be cowed, carries a $25 million bounty of his own. Defense Minister Vladimir Padrino Lopez has run Venezuela&#8217;s military longer than anyone in modern history and remains in place.</p><p>The snake has been decapitated, but the body is still moving. The existing post-Maduro Venezuelan regime might abide by what Trump wants, but they remain staffed by people who face their own indictments and have every incentive to resist a democratic transition that would hand them to American courts.</p><p>Venezuelan reaction has been deeply polarized. In Doral, Florida &#8212; home to the largest Venezuelan diaspora community in the US &#8212; <a href="https://www.cbsnews.com/miami/news/miami-doral-weston-venezuela-community-reactions-nicolas-maduro-capture-trump/">crowds gathered outside El Arepazo restaurant</a> chanting &#8220;Libertad!&#8221; and singing both national anthems. Similar celebrations erupted in Santiago, Lima, and Madrid, where <a href="https://edition.cnn.com/world/live-news/venezuela-explosions-caracas-intl-hnk-01-03-26?post-id=cmjyou80u0009356pphs1sv7j">one Venezuelan told CNN</a>: &#8220;At first we were crying because our country was being bombed, but when we were told they had Maduro, the reaction was overwhelming.&#8221;</p><p>Inside Venezuela, the picture is grimmer. Caracas residents described waking up terrified. &#8220;How do I feel? Scared, like everyone,&#8221; <a href="https://www.mprnews.org/story/2026/01/03/us-strikes-venezuela-maduro">one resident told the news</a>. &#8220;Venezuelans woke up scared, many families couldn&#8217;t sleep.&#8221; Pro-Maduro supporters led by Caracas Mayor Carmen Mel&#233;ndez <a href="http://Pro-Maduro supporters led by Caracas Mayor Carmen Mel&#233;ndez marched through the capital demanding his return, chanting &#8220;Maduro, hold on, the people are rising up!&#8221;">marched through the capital demanding his return</a>, chanting &#8220;Maduro, hold on, the people are rising up!&#8221; The streets were otherwise largely empty, patrolled by security forces, as residents stayed indoors absorbing what had happened.</p><p>When it comes to figuring out who should govern Venezuela next, opposition leader Machado issued a statement calling for Gonz&#225;lez to assume the presidency. But <a href="https://abc3340.com/news/nation-world/who-will-be-venezuelas-new-president-following-maduros-capture-opposition-leader-maria-corina-machado-nobel-peace-prize-winner-edmundo-gonzalez">Trump said it would be &#8220;very tough&#8221;</a> and that Machado &#8220;doesn&#8217;t have the support or the respect within the country.&#8221; His team had not been in touch with her or any member of the Maduro opposition.</p><p>And there&#8217;s also a constitutional wrinkle. Executive Vice President Delcy Rodr&#237;guez is technically Maduro&#8217;s legal successor &#8212; and she&#8217;s reportedly in Moscow. The US wants to work with Rodr&#237;guez over Machado and Gonz&#225;lez, despite Rodr&#237;guez being a committed Chavista who appeared on state TV demanding Maduro&#8217;s release as &#8220;the only president of Venezuela.&#8221; And this dismissal of Machado is striking and underexplained. Recall that Machado won the opposition primary decisively.</p><p>Why? Perhaps Trump cares more about stability and oil access than democratic transition. Rodr&#237;guez represents continuity with the existing power structure whereas Machado represents upheaval. Or perhaps portions of the Maduro regime negotiated this outcome and accepting Rodr&#237;guez was the price of Venezuelan non-resistance. Or perhaps the Trump administration has no plan and is improvising on the fly. Perhaps Trump wanted the win, got the win, and figured they&#8217;d sort out the details later. Note that none of these three theories are mutually exclusive.</p><p>Trump&#8217;s stated plan is for the United States to &#8220;run&#8221; Venezuela &#8220;until such time as we can do a safe, proper and judicious transition,&#8221; with American oil companies moving in to extract wealth that would flow to both Venezuela and &#8220;the United States in the form of reimbursement.&#8221; But that&#8217;s barely a plan. Run it how? With what personnel? Under what legal authority? &#8220;Running&#8221; a country of 28 million people without boots on the ground isn&#8217;t a plan. Capturing Maduro doesn&#8217;t automatically produce Venezuelan democracy.</p><p>And Democrats are furious. The Gang of Eight, a bipartisan group of Congressional leaders, are normally briefed in advance due to requirements by law to maintain balance between executive war powers and congressional oversight. But they weren&#8217;t briefed this time. Trump&#8217;s justification&#8212;that &#8220;Congress has a tendency to leak&#8221;&#8212;is essentially a middle finger to Article I, which normally puts Congress in the drivers seat when it comes to war. Article II does give the US President authority to do military operations to protect US personnel from an actual or imminent attack, but the imminent attack framing is doing a lot of work here for an operation targeting a leader who posed no immediate threat to American forces.</p><p></p><h2>Looking forward</h2><p>Across Venezuela, <a href="https://peterwildeford.substack.com/p/after-us-strike-iran-faces-a-desperation">Fordow</a>, and Soleimani, a pattern emerges &#8212; the willingness to use overwhelming military power for specific objectives, combined with an unwillingness to own the consequences indefinitely.</p><p>But the most important part is that there was no 100,000+ troop occupation, no nation-building doctrine, no decade-long-plus commitment. There was just a precise operation with a specific target, executed and completed within hours. After American foreign policy has been haunted by Iraq for two decades, Trump shows a model of limited military action that accomplishes discrete foreign policy objectives without the quagmire of full-scale invasion.</p><p>Sometimes these gambits work. The Abraham Accords, a series of US-brokered agreements signed in 2020 that normalized diplomatic relations between Israel and several Arab nations &#8212; including the UAE, Bahrain, Morocco, and Sudan &#8212; were dismissed as superficial PR but turned out to be genuinely durable.</p><p>Whether that bet pays off in Venezuela will tell us a great deal about how the next three years unfold. If the transition succeeds, expect this template to be applied elsewhere &#8212; perhaps Cuba, perhaps Nicaragua, perhaps targets we haven&#8217;t anticipated. If it fails, we&#8217;ll learn something important about the limits of precision force in an era of diffuse power.</p><p>I&#8217;m genuinely uncertain which way this goes. It&#8217;s good that Maduro is out, but I&#8217;m worried about whether democracy is what comes next.</p><p>-</p><p><em>Thanks to Caroline Jeanmaire for help with editing and contributing analysis.</em></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://blog.peterwildeford.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">For more on geopolitics, consider subscribing!</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[My template for a quarterly review + plan]]></title><description><![CDATA[A free Google doc template for the system I actually use]]></description><link>https://blog.peterwildeford.com/p/my-template-for-a-quarterly-review</link><guid isPermaLink="false">https://blog.peterwildeford.com/p/my-template-for-a-quarterly-review</guid><dc:creator><![CDATA[Peter Wildeford]]></dc:creator><pubDate>Mon, 22 Dec 2025 21:52:54 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!j8-q!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3021bea0-5f6a-4cc0-a9b8-b8630e4c25ce_1248x832.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!j8-q!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3021bea0-5f6a-4cc0-a9b8-b8630e4c25ce_1248x832.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!j8-q!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3021bea0-5f6a-4cc0-a9b8-b8630e4c25ce_1248x832.png 424w, https://substackcdn.com/image/fetch/$s_!j8-q!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3021bea0-5f6a-4cc0-a9b8-b8630e4c25ce_1248x832.png 848w, https://substackcdn.com/image/fetch/$s_!j8-q!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3021bea0-5f6a-4cc0-a9b8-b8630e4c25ce_1248x832.png 1272w, https://substackcdn.com/image/fetch/$s_!j8-q!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3021bea0-5f6a-4cc0-a9b8-b8630e4c25ce_1248x832.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!j8-q!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3021bea0-5f6a-4cc0-a9b8-b8630e4c25ce_1248x832.png" width="1248" height="832" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3021bea0-5f6a-4cc0-a9b8-b8630e4c25ce_1248x832.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:832,&quot;width&quot;:1248,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2036858,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://peterwildeford.substack.com/i/182349646?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3021bea0-5f6a-4cc0-a9b8-b8630e4c25ce_1248x832.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!j8-q!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3021bea0-5f6a-4cc0-a9b8-b8630e4c25ce_1248x832.png 424w, https://substackcdn.com/image/fetch/$s_!j8-q!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3021bea0-5f6a-4cc0-a9b8-b8630e4c25ce_1248x832.png 848w, https://substackcdn.com/image/fetch/$s_!j8-q!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3021bea0-5f6a-4cc0-a9b8-b8630e4c25ce_1248x832.png 1272w, https://substackcdn.com/image/fetch/$s_!j8-q!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3021bea0-5f6a-4cc0-a9b8-b8630e4c25ce_1248x832.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><em>This template was made by Peter Wildeford and Caroline Jeanmaire.</em></p><p>It&#8217;s almost a new year and that often calls for some sort of annual planning.</p><p>But in my opinion, annual planning operates on too long a timescale. Annual planning and goal setting is too infrequent, so it&#8217;s easy to lose track. You don&#8217;t get fast enough feedback and you risk derailing.</p><p>Instead, I suggest adopting a quarterly planning cadence (e.g., set goals for 2026 Jan-Mar). I wanted to provide a template that I&#8217;ve used many times before and that many people seem to like.</p><p><strong>Here&#8217;s my template in a Google Doc =&gt; <a href="https://docs.google.com/document/d/1_xgORcKOCBELpSg8qre8lqkrQ-wlOGAjdwW8NgbObek/copy">click here and make a copy</a>.</strong></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://blog.peterwildeford.com/p/my-template-for-a-quarterly-review?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://blog.peterwildeford.com/p/my-template-for-a-quarterly-review?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><h2><br>How is this different from other templates out there?</h2><p>There are a lot of different templates out there to try and I don&#8217;t know if this one is better. It works well for me, but I&#8217;m not you. But here&#8217;s some principles I was interested in, and maybe that resonates with you:</p><ul><li><p><strong>Optimized for something quarterly</strong> &#8211; rather than something monthly (too frequent, too time consuming) or something annual (too infrequent, easy to lose track, not fast enough feedback).</p></li><li><p><strong>Forces you into relentless focus</strong> on the most important things (three major rocks and two optional minor pebbles) and encourages you (via anti-rocks) to not do too much.</p></li><li><p><strong>Designed to be very achievable.</strong> The template is somewhat minimal and much of it focuses on building systems and making sure your goals will happen.</p></li><li><p><strong>Designed to be very customizable.</strong> You can make the template your own!</p></li></ul><h2><br>What&#8217;s actually in this thing?</h2><p>The template walks you through five steps. The fast-track version takes about three hours (seven 25-minute pomodoros), though you can spend longer if you want to go deeper.</p><p><strong>Step 1: Reflection.</strong> You start by looking back at the prior quarter&#8212;key successes, key mistakes, how you did against prior rocks. There&#8217;s also a quick 1-5 rating across eight areas: work, sleep, exercise, nutrition, routines, finances, relationships, and environment. The point isn&#8217;t to obsess over numbers but to notice patterns and identify 1-2 problem areas that deserve focus.</p><p><strong>Step 2: Vision.</strong> A quick check on your values and mission (or just jot keywords if you don&#8217;t have one), plus a 90-day visualization. What do you want to have/be/feel in three months?</p><p><strong>Step 3: Combine and Refine.</strong> Take everything from Steps 1-2 and distill it into a raw list of potential priorities, then filter down to 3-5 candidate themes. The template also asks you to identify the &#8220;effort type&#8221;&#8212;is each item a project, a learning goal, or a habit change? This matters because habit changes require different strategies.</p><p><strong>Step 4: Set Rocks and Pebbles.</strong> The core of the template. You get three major rocks and two optional pebbles. For each rock, you define SMART goals (both input goals for what you&#8217;ll put in and output goals for what you&#8217;ll achieve), plus IF-THEN planning. You identify one key obstacle and write out &#8220;IF [obstacle occurs], THEN I will [specific response].&#8221; Each rock also asks: &#8220;Who could you share this rock with for support/accountability?&#8221; External commitment helps.</p><p><strong>Step 5: Sanity Checking.</strong> Reality-check your plan: Is there enough time? Do you have slack for the unexpected? What&#8217;s your system for weekly/monthly review? Will travel or environment changes derail you?</p><p>The template includes a 7-pomodoro fast-track guide if you want structure for completing it in a single ~3 hour session.</p><h2><br>Tips Before You Start</h2><ul><li><p><strong>You really shouldn&#8217;t try to do too much.</strong> This is the most common mistake. Three rocks. Maybe two pebbles. That&#8217;s it. If you find yourself wanting more, that&#8217;s a sign you need to prioritize harder.</p></li><li><p><strong>Habits take a lot of time to build.</strong> Be very careful about adopting a new quarterly review, new monthly review, new giant list of 20 habits, new morning + evening routine, etc. all in one go. Ideally build these gradually over 1-2 years. If you&#8217;re new to this kind of planning, make &#8220;establish a quarterly review habit&#8221; one of your rocks.</p></li><li><p><strong>Do this somewhere other than your usual workspace.</strong> It helps you think outside the box.</p></li><li><p><strong>Don&#8217;t do it all in one sitting.</strong> Important thoughts and connections emerge in between sessions.</p></li><li><p><strong>Make it your own.</strong> I went through a bunch of materials and distilled it down to one template that works well for <em>me</em>. The true power comes from customizing it to meet your own needs. Want to track books? Add that. Want fewer questions? Remove stuff. Appendix B has a bank of additional reflection questions if you want more.</p></li></ul><p>~</p><p><strong>If you&#8217;re interested, <a href="https://docs.google.com/document/d/1_xgORcKOCBELpSg8qre8lqkrQ-wlOGAjdwW8NgbObek/copy">make a copy of the template (click here)</a> and get to work!</strong></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://blog.peterwildeford.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">If you&#8217;re interested in more, subscribe!</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p><p><em>This template was made by Peter Wildeford and Caroline Jeanmaire. It is based on <a href="https://docs.google.com/document/d/1K2P_yL1Ah976P7MLicb55wgY2DY-39jP3Lvp810H6HQ/edit">Gustin&#8217;s annual review</a>, the <a href="https://shop.heyrevel.com/products/quarterly-productivity-planner">Quarterly Productivity Planner</a>, Ben Todd&#8217;s <a href="https://docs.google.com/document/d/1NbhmiIzPa3AKucHvdBRAEmZ4YxzpcX8YAqK5AYtV4E0/edit">Personal annual review process</a> (2020), <a href="https://docs.google.com/spreadsheets/d/1gfHzh3pleQOLTtXEEYuMUKfdBxtMxvjQuyuzDbcgJmI/copy">Ultraworking&#8217;s monthly template</a>, the <a href="https://gobeyondgoals.com/">Beyond Goals workshop</a>, the <a href="https://www.forcingfunction.com/annual-review">Forcing Function annual review</a>, <a href="https://www.benkuhn.net/weekly/">Ben Kuhn&#8217;s weekly review habit</a>, <a href="https://publish.obsidian.md/beala/2022+OKRs">Alex Beal&#8217;s &#8220;2022 OKRs&#8221;</a>, Eric Barker&#8217;s <a href="https://bakadesuyo.com/2012/07/whats-the-best-way-to-set-a-goal/">&#8220;What&#8217;s the best way to set a goal?&#8221;</a>, Konrad Seifert&#8217;s <a href="https://docs.google.com/spreadsheets/d/16IctVL_QU93RfNAMV6f7aQVePDDzuAIg3EoifbJhL6s/edit#gid=456556687">&#8220;Life Review, Planning &amp; Organization&#8221;</a>, and Jan&#8217;s &#8220;<a href="https://docs.google.com/document/d/1Jd9odtf7BZ1qfBEA5xdldkO4niEZPPrTwPOD6wP9_7Y/edit">Review, reflection, goal-setting prompts&#8221;</a>. <a href="https://intend.do/">Intend.do</a> and <a href="https://zenhabits.net/zen-to-done-ztd-the-ultimate-simple-productivity-system/">Zen to Done</a> also serve as inspiration.</em></p>]]></content:encoded></item><item><title><![CDATA[Ronny Chieng and I investigate the promises of AI]]></title><description><![CDATA[I was on the Daily Show!]]></description><link>https://blog.peterwildeford.com/p/ronny-chieng-and-i-investigate-the</link><guid isPermaLink="false">https://blog.peterwildeford.com/p/ronny-chieng-and-i-investigate-the</guid><dc:creator><![CDATA[Peter Wildeford]]></dc:creator><pubDate>Fri, 05 Dec 2025 14:07:16 GMT</pubDate><enclosure url="https://substackcdn.com/image/youtube/w_728,c_limit/RcPthlvzMY8" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>It was amazing to get to sit down with Ronny Chieng and talk about AGI with The Daily Show!</p><div id="youtube2-RcPthlvzMY8" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;RcPthlvzMY8&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/RcPthlvzMY8?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://blog.peterwildeford.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">I also write a lot about AI, how it is unfolding, and what we can expect. For more on that, subscribe!</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p>]]></content:encoded></item><item><title><![CDATA[Will competition over advanced AI lead to war?]]></title><description><![CDATA[Fear and Fearon]]></description><link>https://blog.peterwildeford.com/p/will-competition-over-advanced-ai</link><guid isPermaLink="false">https://blog.peterwildeford.com/p/will-competition-over-advanced-ai</guid><dc:creator><![CDATA[Oscar Delaney]]></dc:creator><pubDate>Fri, 21 Nov 2025 20:02:22 GMT</pubDate><enclosure url="https://images.unsplash.com/photo-1500252185289-40ca85eb23a7?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwxfHx3YXJ8ZW58MHx8fHwxNzYzNzM3MjY5fDA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://images.unsplash.com/photo-1500252185289-40ca85eb23a7?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwxfHx3YXJ8ZW58MHx8fHwxNzYzNzM3MjY5fDA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://images.unsplash.com/photo-1500252185289-40ca85eb23a7?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwxfHx3YXJ8ZW58MHx8fHwxNzYzNzM3MjY5fDA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 424w, https://images.unsplash.com/photo-1500252185289-40ca85eb23a7?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwxfHx3YXJ8ZW58MHx8fHwxNzYzNzM3MjY5fDA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 848w, https://images.unsplash.com/photo-1500252185289-40ca85eb23a7?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwxfHx3YXJ8ZW58MHx8fHwxNzYzNzM3MjY5fDA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 1272w, https://images.unsplash.com/photo-1500252185289-40ca85eb23a7?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwxfHx3YXJ8ZW58MHx8fHwxNzYzNzM3MjY5fDA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 1456w" sizes="100vw"><img src="https://images.unsplash.com/photo-1500252185289-40ca85eb23a7?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwxfHx3YXJ8ZW58MHx8fHwxNzYzNzM3MjY5fDA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080" width="4385" height="2923" data-attrs="{&quot;src&quot;:&quot;https://images.unsplash.com/photo-1500252185289-40ca85eb23a7?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwxfHx3YXJ8ZW58MHx8fHwxNzYzNzM3MjY5fDA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:2923,&quot;width&quot;:4385,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;six fighter jets&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="six fighter jets" title="six fighter jets" srcset="https://images.unsplash.com/photo-1500252185289-40ca85eb23a7?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwxfHx3YXJ8ZW58MHx8fHwxNzYzNzM3MjY5fDA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 424w, https://images.unsplash.com/photo-1500252185289-40ca85eb23a7?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwxfHx3YXJ8ZW58MHx8fHwxNzYzNzM3MjY5fDA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 848w, https://images.unsplash.com/photo-1500252185289-40ca85eb23a7?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwxfHx3YXJ8ZW58MHx8fHwxNzYzNzM3MjY5fDA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 1272w, https://images.unsplash.com/photo-1500252185289-40ca85eb23a7?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwxfHx3YXJ8ZW58MHx8fHwxNzYzNzM3MjY5fDA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Photo by <a href="https://unsplash.com/@uxgun">UX Gun</a> on <a href="https://unsplash.com">Unsplash</a></figcaption></figure></div><p><em>This is a guest post written by Oscar Delaney, <a href="https://oscardelaney.substack.com/">reposted from his Substack</a> (see <a href="https://peterwildeford.substack.com/p/mutual-sabotage-of-ai-probably-wont">here</a> and <a href="https://peterwildeford.substack.com/p/should-the-us-do-a-manhattan-project">here</a> for our previous coauthored posts).</em></p><p>~</p><p>James Fearon&#8217;s classic<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-1" href="#footnote-1" target="_self">1</a> 1995 <a href="https://web.stanford.edu/group/fearon-research/cgi-bin/wordpress/wp-content/uploads/2013/10/Rationalist-Explanations-for-War.pdf">paper</a> &#8220;Rationalist Explanations for War&#8221; argues that there are two main reasons rational states fight: private information about their own capabilities and resolve, with the incentive to misrepresent this, and commitment problems when trying to reach a negotiated agreement.<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-2" href="#footnote-2" target="_self">2</a> I claim that both of these, especially the latter, contribute to a significant risk of pre-emptive war in the lead-up to one state developing ASI.</p><p>On a basic rational actor model, war seems <a href="https://linch.substack.com/p/the-puzzle-of-war">puzzling</a>. It causes large deadweight losses to belligerents, and therefore both sides would be better off reaching a negotiated agreement to split the issues at stake roughly proportionally to the military strength of each side. That is, if Strongland has an 80% chance of beating Weakville in a (possibly protracted) war, both would be better off avoiding the war and Weakville just giving Strongland a payment (e.g. land or money) of 80% of the expected spoils of war. This simple model breaks down in the case of either private information or commitment problems.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://blog.peterwildeford.com/p/will-competition-over-advanced-ai?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://blog.peterwildeford.com/p/will-competition-over-advanced-ai?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><h1><strong>Private information</strong></h1><p>In the example above, the would-be warring states may have different estimates of their chances of victory, and therefore fail to agree on terms for a negotiated agreement. For instance, each party will have private information about their own ability (number of tanks, jets, etc) and desire (national cohesion, psychological profiles, etc) to fight. And each side is incentivised to misrepresent these variables. For instance, the USSR <a href="https://warhistory.org/@msw/article/the-bomber-gap-and-the-missile-gap">purportedly</a> had the same fighter planes fly overhead in military parades, loop around over the horizon, and fly over again, to make adversaries think they had a larger stock of planes than they really did.</p><p>AI development contains significant private information. It is relatively doable to tell via satellite imagery what materiel an adversary has. Similarly, data center capacity can be estimated from satellite and OSINT data. However, it is far harder to ascertain from afar what algorithms are being run on a given data center, and what AI capabilities an adversary has. This will particularly be the case once AI developers start keeping their most advanced models <a href="https://ai-frontiers.org/articles/the-hidden-ai-frontier">internal</a> for longer. That said, as long as you can keep some spies in the leading AI project of your adversary, you will have decent knowledge of their AI capabilities and plans. Overall, greater uncertainty about an adversary&#8217;s capabilities seems to increase the risk of war by making it harder to negotiate an agreement based on common knowledge of relative strength.</p><h1><strong>Commitment problems</strong></h1><p>Another reason a negotiated settlement to avoid or end a war may fail is that the belligerents cannot credibly commit to upholding the agreement. For instance, one model of the Russia-Ukraine war is that Ukraine should be willing to accept some territorial losses now in exchange for a ceasefire. But if Ukraine does so without gaining security guarantees, it can&#8217;t ensure that in a few years&#8217; time, Russia won&#8217;t annex a bit more territory, and repeat this process indefinitely. For a negotiated agreement to work, there must be a large cost to breaking the agreement: an honesty system won&#8217;t cut it. The main way large costs can be imposed is by the international community. If a country breaks a treaty, that country will likely be ostracised and have worse trade and military cooperation prospects in the future. This provides a slight check on the <a href="https://en.wikipedia.org/wiki/Anarchy_(international_relations)">anarchy of the international order</a>.</p><p>Advanced AI poses particularly severe commitment problems, because the country that first develops ASI may also gain a <a href="https://humangeneralintelligence.substack.com/p/ai-the-spectre-of-decisive-advantage">decisive strategic advantage</a> (DSA). For instance, ASI could lead to that country <a href="https://newsletter.forethought.org/p/could-one-country-outgrow-the-rest">outgrowing the rest of the world</a>, inventing and deploying <a href="https://www.rand.org/pubs/perspectives/PEA3691-4.html">wonder weapons</a>, or undermining <a href="https://www.foreignaffairs.com/united-states/artificial-intelligence-end-mutual-assured-destruction">nuclear second-strike capabilities</a>. I think that a country unilaterally developing ASI is &gt;50% likely to thereafter get a DSA. If a country has a DSA, it will by definition be impossible for the international community to meaningfully constrain its actions, including if that country chooses to renege on treaties and agreements made before the advent of its DSA.</p><p>This is a huge deal. It means that other countries will be very reluctant to risk an adversary reaching ASI unchallenged, as this would mean placing their continued sovereignty in the hands of the adversary&#8217;s goodwill. This means there could be a strong rationalist (self-interested) case for a pre-emptive war to prevent an adversary reaching ASI. This is essentially the argument Hendrycks, Schmidt, and Wang make in <a href="https://nationalsecurity.ai/">Superintelligence Strategy</a>. Crucially, it is not the other country reaching ASI that is itself unacceptable. If they could somehow guarantee not to use their ASI to get a DSA, or not use their DSA to trample other countries, but rather share ASI-driven economic superabundance with the rest of the world, this would be a very attractive prospect compared to risking a nuclear war. But without credible commitments, trust doesn&#8217;t go very far.</p><h1><strong>Conclusion</strong></h1><p>Overall, this seems rather pessimistic, and makes me think <a href="https://80000hours.org/problem-profiles/great-power-conflict/#AI-war">AI-caused war</a> is more likely than I previously thought. It also points towards two important interventions:</p><ol><li><p><strong>Transparency:</strong> All else equal, there being more common knowledge about frontier AI capabilities probably reduces the chance of war. But this isn&#8217;t obvious, and there are also backfire risks where a country finding out more about the AI development of an adversary could make them more worried and increase the risk of war. More research is needed, dare I say?</p></li><li><p><strong>Commitment mechanisms:</strong> Creating plausible pathways by which countries could credibly commit to not misusing an ASI seems like the single biggest way to reduce the risk of AI-caused war. But it is also very difficult. Oliver Guest and I discuss some possible solutions <a href="https://humangeneralintelligence.substack.com/p/ai-the-spectre-of-decisive-advantage">here</a>, and in the future I am particularly interested in investigating:</p><ol><li><p>Lie-detection: If AI leads to large advances in lie-detection, this could create far more confidence that leaders genuinely intend to follow the treaties they sign, as subterfuge would be flagged by the lie-detection system.</p></li><li><p>Constitutional AI: If the ASI itself is unwilling to help its host country disempower other nations, this would be a strong antidote to a DSA.</p></li></ol></li></ol><p>I expect to be working more on these and related ideas in the coming months, and would be keen to discuss possible projects with anyone interested!</p><p>~</p><p><em>If you liked this post, consider subscribing to <a href="https://oscardelaney.substack.com/">Oscar&#8217;s Substack </a><strong><a href="https://oscardelaney.substack.com/">&#8220;AGI Strategy&#8221;</a></strong> where he will be writing more about AI, AGI, and geopolitics.</em></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://oscardelaney.substack.com/subscribe&quot;,&quot;text&quot;:&quot;Subscribe to Oscar&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://oscardelaney.substack.com/subscribe"><span>Subscribe to Oscar</span></a></p><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-1" href="#footnote-anchor-1" class="footnote-number" contenteditable="false" target="_self">1</a><div class="footnote-content"><p>6,388 citations!!</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-2" href="#footnote-anchor-2" class="footnote-number" contenteditable="false" target="_self">2</a><div class="footnote-content"><p>A third reason Fearon gives is &#8216;issue indivisibility&#8217; where some spoil of war is very valuable to both belligerents, but cannot be productively split, e.g. a religious holy site. However, Fearon says (and I agree) this is less convincing as a reason, as normally there are many issues at play in a conflict and some compromise is possible, even just randomizing who gets the prize by drawing lots.</p><p></p></div></div>]]></content:encoded></item><item><title><![CDATA[Should the US do a Manhattan Project for AGI?]]></title><description><![CDATA[Such a Project is neither inevitable nor a good idea]]></description><link>https://blog.peterwildeford.com/p/should-the-us-do-a-manhattan-project</link><guid isPermaLink="false">https://blog.peterwildeford.com/p/should-the-us-do-a-manhattan-project</guid><dc:creator><![CDATA[Peter Wildeford]]></dc:creator><pubDate>Thu, 20 Nov 2025 16:14:15 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!1aie!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd9257161-1286-4ac7-ac67-cfb89de1d5da_1600x818.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!1aie!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd9257161-1286-4ac7-ac67-cfb89de1d5da_1600x818.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!1aie!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd9257161-1286-4ac7-ac67-cfb89de1d5da_1600x818.jpeg 424w, https://substackcdn.com/image/fetch/$s_!1aie!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd9257161-1286-4ac7-ac67-cfb89de1d5da_1600x818.jpeg 848w, https://substackcdn.com/image/fetch/$s_!1aie!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd9257161-1286-4ac7-ac67-cfb89de1d5da_1600x818.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!1aie!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd9257161-1286-4ac7-ac67-cfb89de1d5da_1600x818.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!1aie!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd9257161-1286-4ac7-ac67-cfb89de1d5da_1600x818.jpeg" width="1456" height="744" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d9257161-1286-4ac7-ac67-cfb89de1d5da_1600x818.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:744,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Manhattan Project | Definition, Scientists, Timeline, Locations, Facts, &amp;  Significance | Britannica&quot;,&quot;title&quot;:&quot;Manhattan Project | Definition, Scientists, Timeline, Locations, Facts, &amp;  Significance | Britannica&quot;,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Manhattan Project | Definition, Scientists, Timeline, Locations, Facts, &amp;  Significance | Britannica" title="Manhattan Project | Definition, Scientists, Timeline, Locations, Facts, &amp;  Significance | Britannica" srcset="https://substackcdn.com/image/fetch/$s_!1aie!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd9257161-1286-4ac7-ac67-cfb89de1d5da_1600x818.jpeg 424w, https://substackcdn.com/image/fetch/$s_!1aie!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd9257161-1286-4ac7-ac67-cfb89de1d5da_1600x818.jpeg 848w, https://substackcdn.com/image/fetch/$s_!1aie!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd9257161-1286-4ac7-ac67-cfb89de1d5da_1600x818.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!1aie!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd9257161-1286-4ac7-ac67-cfb89de1d5da_1600x818.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><em>This article was written by Oscar Delaney, Bill Anderson-Samways, and Peter Wildeford. It does not necessarily represent the opinion of the entire staff at the Institute for AI Policy and Strategy.</em></p><p>~</p><p>The idea of a government-led program to &#8220;win the race&#8221; with China to Artificial General Intelligence (AGI) has gone mainstream. From <a href="https://www.uscc.gov/sites/default/files/2024-11/2024_Annual_Report_to_Congress.pdf">Congressional commissions</a> to <a href="https://x.com/ENERGY/status/1928085878561272223">government agencies</a> to <a href="https://www.darioamodei.com/essay/machines-of-loving-grace">AI company CEOs</a>, high profile calls for a Manhattan Project-style effort are growing. Leopold Aschenbrenner&#8217;s popular essay <em><a href="https://situational-awareness.ai/">Situational Awareness</a></em> predicted &#8220;some form of government AGI project&#8221; by 2027-2028. Meanwhile, <a href="https://writing.antonleicht.me/p/the-self-fulfilling-prophecy-of-ai">others</a> remain <a href="https://www.maximum-progress.com/p/an-ai-manhattan-project-is-not-inevitable">skeptical</a>.</p><p>How likely is this really? What would it actually look like? And most importantly, is it even a good idea? Our new forecasting research suggests the answers are far from certain. Professional forecasters estimate just a 34% probability of a government-led AGI program &#8212; neither inevitable nor impossible. More importantly, treating a government project as inevitable could trigger the very risks we&#8217;re trying to avoid.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://blog.peterwildeford.com/p/should-the-us-do-a-manhattan-project?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://blog.peterwildeford.com/p/should-the-us-do-a-manhattan-project?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p></p><h2><strong>Forecasters Say a US-Led AGI Project Is Far From Inevitable</strong></h2><p>We at the Institute for AI Policy and Strategy ran a <a href="https://www.iaps.ai/research/us-government-role-in-advanced-ai-development">structured forecasting workshop</a> with professional forecasters and US AI policy experts to estimate the probability of a US government-led project building the first AGI-level system.</p><p>We defined <strong>&#8220;AIR-10&#8221;</strong> as an AI system that accelerates AI R&amp;D progress tenfold&#8212; essentially compressing a decade of AI development into a year. This matches what many consider the threshold for transformative AI that could trigger recursive self-improvement, and is the threshold Aschenbrenner <a href="https://situational-awareness.ai/from-agi-to-superintelligence/">uses</a> for AGI.</p><p>The aim was to forecast the likelihood that AIR-10 is developed via a &#8220;government-led project.&#8221; By this, we meant that the government both decides when to start/stop developing the AI model AND acquires the final model to deploy as it sees fit. This is more stringent than just the government doing regulation or oversight. In this definition, the government takes direct leadership and command over key development and deployment decisions. However, the private sector may still be heavily involved, for example in a government-led public-private partnership.</p><p>Some commentators (e.g. Aschenbrenner) have suggested that a project run by the US government to achieve AGI is inevitable as a result of the geopolitical importance of AGI. Our <a href="https://www.iaps.ai/research/us-government-role-in-advanced-ai-development">results</a> might surprise those who see it as inevitable &#8212; <strong>the median forecast was a 34% chance</strong>.</p><p>Furthermore, there was a lot of uncertainty among forecasters in our panel, with an average range of 11% to 61%. This wide spread shows that even experts who study this closely are deeply uncertain. Anyone claiming to know for sure whether the government will or won&#8217;t lead AGI development is likely overconfident. We need to prepare for multiple scenarios, not just assume one particular future.</p><p></p><h2><strong>History Offers a Messy Guide, Not Clear Predictions</strong></h2><p>Those predicting a government AGI project often invoke historical analogies &#8212; the Manhattan Project, the Apollo Program, and even ARPANET. But when we <a href="https://docs.google.com/spreadsheets/d/1k0RWhr-Nln0a8ujTZgxxZHsm2cmAeOPd2CPs40EGWao/edit?gid=0#gid=0">systematically analyzed</a> 35 past US technological innovations, the picture that emerged was more nuanced.</p><p>What&#8217;s the correct historical comparison? Whether the government leads depends heavily on what kind of technology you think AGI is:</p><ul><li><p><strong>Megaprojects</strong> costing &gt;0.1% of GDP (like the Interstate Highway System)&#8230; these projects were government-led 78% of the time in the past</p></li><li><p><strong>Ambitious STEM projects</strong> (like the atomic bomb)&#8230; Government-led 63% of the time</p></li><li><p><strong>Dual-use technologies</strong> with both beneficial and harmful applications (like synthetic virology)&#8230; Government-led 57% of the time</p></li><li><p><strong>General-purpose technologies</strong> (like the airplane)&#8230; Government-led only 40% of the time</p></li><li><p><strong>Past AI breakthroughs</strong> (like the transformer)&#8230; Government-led only 23% of the time</p></li></ul><p>AGI has features of all these categories, which is why the historical precedent is hard to pin down. AGI is a general-purpose technology with massive economic potential, in a field that has to date been private-led thus suggesting a high likelihood of continued private leadership. AGI is also a dual-use technology with profound national security and geopolitical implications, and potentially requires megaproject-scale resources beyond what private companies can muster, all factors pointing to government involvement.</p><p>We presented our forecasters with this data during the workshop described above. As a result, they updated their forecasts a little, but not much &#8212; probably reflecting the significant ambiguity in the historical precedents.</p><p></p><h2><strong>National Security and the China Factor</strong></h2><p>The single most powerful factor in our forecasters&#8217; estimation that could compel government action is a perceived military-technological threat from China. If the US believes it&#8217;s on the verge of losing its strategic advantage, political will for a government-led project could materialize overnight.</p><p>Nascent versions of this fear already exist. The<a href="https://www.uscc.gov/sites/default/files/2024-11/2024_Annual_Report_to_Congress.pdf"> US-China Economic and Security Review Commission</a> has already called for a Manhattan Project for AGI in its 2024 report to Congress. The narrative of an AI arms race with China has become deeply embedded in Washington.</p><p>Importantly, national security concerns both make government involvement more likely and shape what form that involvement might take. An AGI project driven by military imperatives would look very different from one focused on economic competitiveness or scientific advancement.</p><p></p><h2><strong>AI&#8217;s Breakneck Pace vs Government&#8217;s Glacial Speed</strong></h2><p>However, the US government is not historically known as being fast to develop technology &#8212; especially compared to the speed of AI. By the time the government decides to become more involved in AGI development, private AI companies might have already developed it.</p><p>This creates a timing problem. The AIR-10 threshold we defined, while transformative, might not be &#8220;attention-grabbing&#8221; enough to trigger government action to achieve it. This is unlike nuclear weapons, where the ability to clearly and unambiguously destroy an entire city constituted a significant, discrete, and noticeable threshold that <a href="https://ahf.nuclearmuseum.org/ahf/key-documents/einstein-szilard-letter/">was salient to policymakers</a> even before it was achieved.</p><p>Several of our forecasters emphasized this dynamic &#8212; if AIR-10 arrives in the next few years (as some predict), that might be too soon for the US government to organize a successful intervention. Only if the path to transformative AI stretches out over a longer timeline does government leadership become more likely. When providing their central 34% estimate, forecasters were asked to condition on AIR-10 arriving at some point before 2035.</p><h2><strong>Less &#8216;Manhattan Project&#8217;, more &#8216;Apollo Program&#8217; / &#8216;Operation Warp Speed&#8217;</strong></h2><p>Additionally, the &#8220;AI Manhattan Project&#8221; framing is potentially misleading. When people use this term, they often imagine a single, secret government AI lab that builds AGI entirely from scratch. However, according to our forecasters, it&#8217;s only about 3% likely that AIR-10 will be developed specifically in this way. Other options involving major government in-house resources, nationalization of an existing private company, or otherwise using legal compulsion to force the development of AGI under US government control were also considered similarly unlikely.</p><p>Based on our analysis, if the government does lead AGI development, we forecast the project would most likely take one of these forms:</p><ul><li><p><strong>Government-Led Consortium (14% probability)</strong>: This is the &#8220;Apollo Program&#8221; model. In this model, the US government wouldn&#8217;t build AGI itself but would coordinate multiple private companies (and maybe even government labs too, though relying mainly on government labs seems unlikely). For example, NASA managed contractors like Boeing and North American Aviation to do the moon landing. This avoids &#8220;picking winners&#8221; and leverages existing private sector talent.</p></li><li><p><strong>Single Private Contractor (9% probability)</strong>: This is the &#8220;<a href="https://en.wikipedia.org/wiki/ENIAC">ENIAC</a>&#8221; model. In this model, the government contracts with one specific company to build AGI to government specifications. This is faster to implement but somewhat riskier, as it involves picking a particular company to be the national champion.</p></li></ul><p>The original Manhattan Project itself was actually closer to a government-led consortium than is widely thought, with multiple government labs and <a href="https://ahf.nuclearmuseum.org/ahf/history/corporate-partners/">private contractors</a> involved&#8212;though it was much more government-centric than what our forecasters envision for AI. The variety of possible models matters because each comes with different tradeoffs in terms of speed, security, and innovation.</p><p></p><h2><strong>From Commercial Competition to an AI Arms Race</strong></h2><p>The consequences of getting a government-led AGI project wrong would be severe. A poorly designed government project could trigger the very catastrophes it aims to prevent.</p><p>Currently, AI development is a commercial competition. While intense, it allows for some safety investment and <a href="https://arxiv.org/abs/2507.11473v1">shared research</a>. A formal, government-led US project would upend this dynamic, sending an unmistakable signal to the world &#8212; especially China &#8212; that America is seeking a <a href="https://humangeneralintelligence.substack.com/p/ai-the-spectre-of-decisive-advantage">decisive strategic advantage</a>.</p><p>The response would be swift and predictable. A rival government may feel forced to launch its own centralized, government-led program, transforming a commercial race into a <a href="https://www.convergenceanalysis.org/research/the-manhattan-trap-why-a-race-to-artificial-superintelligence-is-self-defeating">direct military-technological showdown</a>. History supports this concern &#8212; the Manhattan Project triggered a nuclear arms race that saw the Soviet Union detonate its own test bomb just four years later.</p><p>Unlike with the Manhattan Project, however, the key stage of an AI race could unfold in mere months, with even less room for safety compromises under the pressures of national security. That could heighten the risk of a catastrophic accident arising from AI systems due to hasty deployment.</p><p>This dynamic could be mitigated if multiple companies join the project, which would at least nullify the commercial race. However, according to our forecasters, this is unlikely to happen &#8212; they think there is less than a 50% chance that a government-led project would involve more than AI company, primarily due to the coordination costs involved in such programs.</p><p>In some circumstances, the AI arms race caused by a government-led AGI project could even <a href="https://peterwildeford.substack.com/p/mutual-sabotage-of-ai-probably-wont">trigger a great power war</a>. As noted above, a US project could be perceived as an attempt to achieve a decisive strategic advantage unparalleled since the advent of nuclear weapons. In such circumstances, a rival might also consider <a href="https://nationalsecurity.ai/">escalatory actions</a>, such as a cyberattack on data centers or even threats of missile strikes, which could then escalate into an all-out war.<br></p><h2><strong>Concentrated AI Power Threatens Democratic Legitimacy</strong></h2><p>While the risk of international conflict is terrifying, a centralized AGI project also threatens the erosion of democratic legitimacy.</p><p>The American system is built on Jeffersonian checks and balances, pitting ambition against ambition to prevent any one person or group from accumulating concentrated power. A secretive AGI project, led by executive branch agencies, would <a href="https://www.lawfaremedia.org/article/beyond-a-manhattan-project-for-artificial-general-intelligence">greatly concentrate</a> the unprecedented power that AGI would bring. Even if this did not pose a direct threat to democracy, it would certainly erode democratic trust and legitimacy.</p><p>Some might argue that, without a government-backed AGI program, rival governments are more likely to beat the US to AGI. This would concentrate power in adversaries&#8217; own, far less democratic political systems. However, this argument relies on the inaccurate idea that adversaries already possess centralized AGI programs which could allow them to overcome US companies&#8217; current lead. Though the current pace of Chinese AI development is certainly concerning, open-source information indicates that China has not centralized its compute or researchers into such a program. Thus, US companies <a href="https://peterwildeford.substack.com/p/ten-takes-on-deepseek">retain a considerable advantage</a>. In fact, a US government-led program could <em>trigger</em> rival governments to launch their own centralized projects, paradoxically potentially reducing<em> </em>US lead-time.</p><p>Concentrated government power is not the only concern. A government-led AGI program could also concentrate power in the hands of tech companies. If such a program involved multiple AI companies, it would essentially eliminate market competition &#8212; creating a cartel with access to enormous amounts of economic and military power. Such a situation has not occurred since the apex of the British East India Company, which in the 1700s came to account for <a href="https://www.adamsmithworks.org/documents/donway-british-east-india-company-free-trade">half the world&#8217;s trade</a> and rivaled the military might of the great powers. Even if only a single company was involved in the project and market competition was preserved, giving a private company access to the government resources needed to develop decisive military capabilities would be unprecedented.</p><p></p><h2><strong>The Security Benefits Don&#8217;t Require Building AGI</strong></h2><p>The strongest argument for a government project is compelling &#8212; namely, better security. Private AI companies are vulnerable to infiltration and theft, especially from well-resourced governments. A government project could implement military-grade security, reducing risks of AI being stolen by adversaries.</p><p>This is a real concern that deserves serious attention. But <strong>you don&#8217;t need to build AGI to secure it</strong>. Instead, security benefits can be achieved through more targeted, less escalatory policies such as:</p><ul><li><p><strong>Mandatory security standards</strong> for private AI companies handling very advanced AI systems</p></li><li><p><strong>Government partnerships</strong> to assist companies with securing model weights without taking over development</p></li><li><p><strong>Enhanced counterintelligence</strong> support for private AI companies</p></li></ul><p>The government doesn&#8217;t need to build all nuclear reactors to ensure nuclear security. It sets standards, monitors compliance, and provides security assistance while letting private companies operate the reactors. These targeted interventions could achieve 80% of the security benefits with 20% of the risks. They avoid triggering international arms races or concentrating power dangerously. Most importantly, they can be implemented incrementally and adjusted as we learn more about AI risks.</p><p></p><h2><strong>Preparing for Multiple Futures, Not Sleepwalking into Disaster</strong></h2><p>The future is genuinely uncertain. Our research shows that a government-led AGI project is neither inevitable nor impossible.</p><p>This uncertainty tells us something important about how to approach AI governance. Rather than assuming a single trajectory and optimizing for it, we need robust strategies that work across multiple scenarios.</p><p>That means avoiding self-fulfilling prophecies. Treating a government project as inevitable could trigger the very international dynamics we&#8217;re trying to avoid. But dismissing it as impossible leaves us unprepared if geopolitical pressures suddenly shift.</p><p>We need a portfolio of approaches that work across different government involvement levels:</p><ul><li><p><strong>Strengthen private AI security</strong>: Improve security protocols and infrastructure at the private AI labs, to prevent theft of American IP.</p></li><li><p><strong>Track adversaries&#8217; AI progress: </strong>Track reliable indicators that would enable the US government to catch adversaries launching their own government-led programs, such as compute and researcher centralization.</p></li><li><p><strong>Build government readiness</strong>: Develop in-house expertise and plans in case government leadership does become necessary.</p></li></ul><p>Most importantly, we must remember that government involvement isn&#8217;t binary. There&#8217;s a spectrum from light-touch regulation to full nationalization, with many points in between. The goal should be finding the minimum effective dose &#8212; enough government involvement to ensure safety and security, but not so much that we trigger the very catastrophes we&#8217;re trying to prevent.</p><p>The stakes are too high for ideological purity. Whether you&#8217;re a tech accelerationist who believes in private innovation or a national security hawk worried about China, we all share an interest in navigating this transition without triggering catastrophic accidents, conflict, or concentration of power. That requires taking uncertainty seriously and preparing for multiple futures, rather than assuming we know which one will unfold.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://blog.peterwildeford.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">For more on AI and geopolitics, consider subscribing.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[AI Ran Its First Autonomous Cyberattack]]></title><description><![CDATA[Chinese hackers used AI and changed the economics of cyberattacks]]></description><link>https://blog.peterwildeford.com/p/ai-ran-its-first-autonomous-cyberattack</link><guid isPermaLink="false">https://blog.peterwildeford.com/p/ai-ran-its-first-autonomous-cyberattack</guid><dc:creator><![CDATA[Peter Wildeford]]></dc:creator><pubDate>Sat, 15 Nov 2025 00:52:47 GMT</pubDate><enclosure url="https://images.unsplash.com/photo-1592609931041-40265b692757?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwzMnx8aGFja2VyfGVufDB8fHx8MTc2MzE1NjIwNXww&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://images.unsplash.com/photo-1592609931041-40265b692757?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwzMnx8aGFja2VyfGVufDB8fHx8MTc2MzE1NjIwNXww&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://images.unsplash.com/photo-1592609931041-40265b692757?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwzMnx8aGFja2VyfGVufDB8fHx8MTc2MzE1NjIwNXww&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 424w, https://images.unsplash.com/photo-1592609931041-40265b692757?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwzMnx8aGFja2VyfGVufDB8fHx8MTc2MzE1NjIwNXww&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 848w, https://images.unsplash.com/photo-1592609931041-40265b692757?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwzMnx8aGFja2VyfGVufDB8fHx8MTc2MzE1NjIwNXww&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 1272w, https://images.unsplash.com/photo-1592609931041-40265b692757?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwzMnx8aGFja2VyfGVufDB8fHx8MTc2MzE1NjIwNXww&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 1456w" sizes="100vw"><img src="https://images.unsplash.com/photo-1592609931041-40265b692757?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwzMnx8aGFja2VyfGVufDB8fHx8MTc2MzE1NjIwNXww&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080" width="9219" height="6146" data-attrs="{&quot;src&quot;:&quot;https://images.unsplash.com/photo-1592609931041-40265b692757?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwzMnx8aGFja2VyfGVufDB8fHx8MTc2MzE1NjIwNXww&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:6146,&quot;width&quot;:9219,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;black flat screen computer monitor&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="black flat screen computer monitor" title="black flat screen computer monitor" srcset="https://images.unsplash.com/photo-1592609931041-40265b692757?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwzMnx8aGFja2VyfGVufDB8fHx8MTc2MzE1NjIwNXww&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 424w, https://images.unsplash.com/photo-1592609931041-40265b692757?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwzMnx8aGFja2VyfGVufDB8fHx8MTc2MzE1NjIwNXww&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 848w, https://images.unsplash.com/photo-1592609931041-40265b692757?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwzMnx8aGFja2VyfGVufDB8fHx8MTc2MzE1NjIwNXww&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 1272w, https://images.unsplash.com/photo-1592609931041-40265b692757?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwzMnx8aGFja2VyfGVufDB8fHx8MTc2MzE1NjIwNXww&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Photo by <a href="https://unsplash.com/@gamell">Joan Gamell</a> on <a href="https://unsplash.com">Unsplash</a></figcaption></figure></div><p><em>About the author: Peter Wildeford is a top forecaster, ranked top 1% every year since 2022. This article was written with the assistance and feedback from people with cybersecurity expertise and people with a background in the intelligence community.</em></p><p>~</p><p>Anthropic just announced that they have <a href="https://www.anthropic.com/news/disrupting-AI-espionage">detected and disrupted</a> what it describes as the first documented real-world large-scale agentic cyberattack campaign executed primarily by artificial intelligence.</p><p><strong>This appears to be the first publicly known example of AI systems autonomously conducting multi-step cyberattacks in the wild.</strong></p><p>A Chinese government-sponsored group jailbroke Claude, the AI made by Anthropic, by tricking Claude into believing it was conducting defensive cybersecurity work, and then used it to perform reconnaissance, identify vulnerabilities, and write exploit code. They targeted roughly 30 organizations, successfully breaching a handful including major tech companies, financial institutions, and government agencies. Most importantly, <strong>AI completed roughly 80-90% of the attack autonomously, with human operators stepping in only for about 4-6 key decision points per attack. </strong>While specific details in the report were limited, it was clear that the AI did multiple hours of work, with humans only needed for 1-2 hours per attack.</p><p><strong>This use of AI to autonomously conduct offensive operations is a notable shift in the cyber threat landscape.</strong> Typically, offensive cyber operations require expensive, highly trained human operators that can only work on a limited number of operations simultaneously. A sophisticated espionage campaign targeting 30 organizations like what was reported by Anthropic would require a large team working for months. Now, it appears that some forms of cyberoffense can be run by just a few operators with access to AI. <strong>As AI continues to increase in sophistication, so will the quantity, speed, and sophistication of AI attacks.</strong></p><p>So what does this mean and where do we go next? How concerned should we be?</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://blog.peterwildeford.com/p/ai-ran-its-first-autonomous-cyberattack?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://blog.peterwildeford.com/p/ai-ran-its-first-autonomous-cyberattack?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p></p><h2>The anatomy of an agentic AI cyberattack</h2><p>The industry term &#8220;agentic AI&#8221; describes systems that can work autonomously over extended periods, making tactical decisions within strategic parameters. In this attack, the Chinese hackers used <a href="https://www.claude.com/product/claude-code">Claude Code</a>, an agentic version of Claude that can access external tools, maintain context across sessions, and iterate based on feedback.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!opSD!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F880f91ff-fa64-4a3e-88ae-780d2a99295b_1690x328.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!opSD!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F880f91ff-fa64-4a3e-88ae-780d2a99295b_1690x328.png 424w, https://substackcdn.com/image/fetch/$s_!opSD!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F880f91ff-fa64-4a3e-88ae-780d2a99295b_1690x328.png 848w, https://substackcdn.com/image/fetch/$s_!opSD!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F880f91ff-fa64-4a3e-88ae-780d2a99295b_1690x328.png 1272w, https://substackcdn.com/image/fetch/$s_!opSD!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F880f91ff-fa64-4a3e-88ae-780d2a99295b_1690x328.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!opSD!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F880f91ff-fa64-4a3e-88ae-780d2a99295b_1690x328.png" width="1456" height="283" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/880f91ff-fa64-4a3e-88ae-780d2a99295b_1690x328.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:283,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:58760,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://peterwildeford.substack.com/i/178929888?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F880f91ff-fa64-4a3e-88ae-780d2a99295b_1690x328.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!opSD!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F880f91ff-fa64-4a3e-88ae-780d2a99295b_1690x328.png 424w, https://substackcdn.com/image/fetch/$s_!opSD!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F880f91ff-fa64-4a3e-88ae-780d2a99295b_1690x328.png 848w, https://substackcdn.com/image/fetch/$s_!opSD!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F880f91ff-fa64-4a3e-88ae-780d2a99295b_1690x328.png 1272w, https://substackcdn.com/image/fetch/$s_!opSD!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F880f91ff-fa64-4a3e-88ae-780d2a99295b_1690x328.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a><figcaption class="image-caption">Claude Code</figcaption></figure></div><p>Claude Code is a generally available computer application for anyone to use, typically used by software engineers to assist in writing software. The attackers repurposed these Claude Code capabilities for cyberoffense operations though meticulous additional tooling and orchestration. They broke down their attack into much smaller steps for a fleet of Claude agents to run attacks step-by-step to avoid triggering Anthropic&#8217;s built-in defenses.</p><p>The term &#8216;cyberattack&#8217; often evokes ideas of great digital destruction, but it&#8217;s a broad category. Many operations, including this one, are focused primarily on espionage. Here, causing detectable damage would be counterproductive, since it would alert the target to the existence of the campaign. Countries continue to invest in these espionage programs tremendously.</p><p>In this espionage cyberattack, human Chinese government-sponsored hackers first collected a target list and then launched an AI-enabled framework to spawn parallel AI-driven reconnaissance against multiple targets simultaneously. Think of it as the human hackers each managing a team of tireless digital minions &#8212; the humans give them targets and approve their proposed escalations, but the AI minions handle the grinding work of testing thousands of login attempts or parsing gigabytes of stolen documents.</p><p>Human operators reviewed the findings of the Claude agents at key checkpoints and approved progression to active exploitation.  After human authorization, the Claude agents autonomously deployed exploits to establish access. Claude agents then systematically harvested credentials, tested stolen credentials across discovered systems, and executed lateral movement through internal networks. During data collection operations, Claude agents queried databases and internal systems, extracted information, parsed results to identify intelligence value, and categorized findings by sensitivity. Each Claude agent maintained persistent operational context across sessions spanning multiple days.</p><p>Anthropic reported that the Claude agents executed approximately 80 to 90 percent of tactical operations independently, without needing human oversight, guidance, or correction. Throughout the campaign, humans shifted from conducting individual attack steps to setting strategic direction and approving escalations at critical decision points. The human role shifted from &#8220;hacker&#8221; to &#8220;strategic supervisor approving escalation points.&#8221;</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!c-Eu!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6e8c322d-8553-491f-a577-eada2cd8252e_803x484.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!c-Eu!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6e8c322d-8553-491f-a577-eada2cd8252e_803x484.png 424w, https://substackcdn.com/image/fetch/$s_!c-Eu!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6e8c322d-8553-491f-a577-eada2cd8252e_803x484.png 848w, https://substackcdn.com/image/fetch/$s_!c-Eu!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6e8c322d-8553-491f-a577-eada2cd8252e_803x484.png 1272w, https://substackcdn.com/image/fetch/$s_!c-Eu!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6e8c322d-8553-491f-a577-eada2cd8252e_803x484.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!c-Eu!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6e8c322d-8553-491f-a577-eada2cd8252e_803x484.png" width="803" height="484" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6e8c322d-8553-491f-a577-eada2cd8252e_803x484.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:484,&quot;width&quot;:803,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!c-Eu!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6e8c322d-8553-491f-a577-eada2cd8252e_803x484.png 424w, https://substackcdn.com/image/fetch/$s_!c-Eu!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6e8c322d-8553-491f-a577-eada2cd8252e_803x484.png 848w, https://substackcdn.com/image/fetch/$s_!c-Eu!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6e8c322d-8553-491f-a577-eada2cd8252e_803x484.png 1272w, https://substackcdn.com/image/fetch/$s_!c-Eu!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6e8c322d-8553-491f-a577-eada2cd8252e_803x484.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption"><em>Source: <a href="https://assets.anthropic.com/m/ec212e6566a0d47/original/Disrupting-the-first-reported-AI-orchestrated-cyber-espionage-campaign.pdf">Anthropic</a> (p5)</em></figcaption></figure></div><p>When evaluating the value of AI in this attack, it&#8217;s important to recognize that each step in the attack chain is not equally valuable or equally difficult to automate. Some of these steps represent larger bottlenecks than others. And crucially, the operation still required skilled human hackers for strategic planning and key inputs &#8212; AI could not do the attack fully end-to-end.</p><p>For example, autonomously discovering internal services and conducting network mapping is not impressive as existing tools can already do this automatically without AI. The automatic testing of authentication is more significant as existing tools for this are less good. The most valuable part was likely the use of AI to parse large volumes of stolen information to automatically identify intelligence value and categorize findings, since this greatly reduces the human intelligence effort involved in the attack, improving the attack&#8217;s cost-effectiveness.</p><p></p><h2>Where are AI cyber capabilities heading?</h2><p>In terms of operational sophistication, Anthropic reports that Claude autonomously conducted reconnaissance and exploitation operations that took 1-4 hours each per step. Reliability was low but non-trivial, succeeding &#8220;in a handful of cases&#8221;. Overall, this is a notable increase in sophistication from AI-enabled hacking that was <a href="https://www.anthropic.com/news/detecting-countering-misuse-aug-2025">reported just a few months ago</a>, which involved significantly more human operation. And hackers only need to succeed a handful of times to be valuable.</p><p><a href="https://metr.org/">METR</a>, an independent AI evaluation company, has been studying the rate of progress for AI and finds AI increasing at a rapid and predictable rate. They find that current models like GPT-5 and Claude 4.5 Sonnet can operate complex software tasks of around two hours with 50% reliability, closely matching Anthropic&#8217;s findings about this real world autonomous cyberoffense case.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!McOa!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1b74961-33af-4563-b8bf-b0b1c1553fb2_1335x474.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!McOa!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1b74961-33af-4563-b8bf-b0b1c1553fb2_1335x474.png 424w, https://substackcdn.com/image/fetch/$s_!McOa!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1b74961-33af-4563-b8bf-b0b1c1553fb2_1335x474.png 848w, https://substackcdn.com/image/fetch/$s_!McOa!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1b74961-33af-4563-b8bf-b0b1c1553fb2_1335x474.png 1272w, https://substackcdn.com/image/fetch/$s_!McOa!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1b74961-33af-4563-b8bf-b0b1c1553fb2_1335x474.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!McOa!,w_2400,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1b74961-33af-4563-b8bf-b0b1c1553fb2_1335x474.png" width="1200" height="426.0674157303371" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f1b74961-33af-4563-b8bf-b0b1c1553fb2_1335x474.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:false,&quot;imageSize&quot;:&quot;large&quot;,&quot;height&quot;:474,&quot;width&quot;:1335,&quot;resizeWidth&quot;:1200,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:&quot;center&quot;,&quot;offset&quot;:false}" class="sizing-large" alt="" srcset="https://substackcdn.com/image/fetch/$s_!McOa!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1b74961-33af-4563-b8bf-b0b1c1553fb2_1335x474.png 424w, https://substackcdn.com/image/fetch/$s_!McOa!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1b74961-33af-4563-b8bf-b0b1c1553fb2_1335x474.png 848w, https://substackcdn.com/image/fetch/$s_!McOa!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1b74961-33af-4563-b8bf-b0b1c1553fb2_1335x474.png 1272w, https://substackcdn.com/image/fetch/$s_!McOa!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1b74961-33af-4563-b8bf-b0b1c1553fb2_1335x474.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Source: <a href="https://metr.org/blog/2025-03-19-measuring-ai-ability-to-complete-long-tasks/">METR</a></figcaption></figure></div><p><strong>This is a concern given that this trend will likely continue.</strong> METR&#8217;s data shows AI task capabilities have been doubling roughly every 118-212 days since 2024. If this pace continues, models could reach 4-hour task lengths in early 2026. This points towards future AI autonomously enabling more sophisticated multi-step attacks, better ability to adapt to defenses, and reduced human oversight requirements.</p><p><strong>Innovation in AI scaffolding</strong> <strong>also matters enormously</strong>. Scaffolding is what gives your fleet of AI spies the tools needed to conduct attacks, such as password cracking software. Scaffolding includes techniques for enhancing AI performance through prompting strategies, tool integration, and multi-step reasoning.</p><p>OpenAI&#8217;s GPT-5 initially showed only modest cyber capabilities in OpenAI&#8217;s isolated testing, but the XBOW company <a href="https://xbow.com/blog/gpt-5">demonstrated that GPT-5 could achieve 2x performance improvements</a> when integrated into their specialized scaffolding. As both underlying models and scaffolding techniques improve simultaneously, offensive capabilities can increase faster than otherwise expected.</p><p>The biggest bottleneck to this attack is likely the attackers needing to painstakingly maintain three-way communication channels between themselves, the victim&#8217;s infrastructure, and the Claude API. Here, it&#8217;s telling that Chinese state actors used Claude rather than domestic Chinese alternatives like <a href="https://qwenlm.github.io/">Qwen</a>, <a href="https://kimi.moonshot.cn/">Kimi</a>, or <a href="https://www.deepseek.com/">DeepSeek</a>. This strongly suggests Chinese AI labs haven&#8217;t yet produced models with comparable autonomous hacking capabilities, a gap that creates both temporary strategic advantages and policy opportunities.</p><p>The temporary advantage is monitoring and disruption. When Chinese operators depend on Western AI infrastructure, their operations require maintaining API connections that can be detected and cut off, as Anthropic demonstrated. This dependency creates chokepoints that wouldn&#8217;t exist if they were running Qwen locally on their own infrastructure.</p><p>But this advantage has an expiration date, probably measured in months rather than years. Chinese labs are potentially closing capability gaps, and recent performance suggests they&#8217;re 6-12 months behind frontier Western models at most. Once a sufficiently capable Chinese model emerges, attackers could download it, deploy it directly on compromised infrastructure, and operate completely autonomously without fear of the API connections being severed.</p><p></p><h2>What does this mean?</h2><p>This attack largely represents improved scalability of basic cyberoffensive operations &#8212; exploiting bad security at scale more than overcoming really good security. But even if each step is &#8220;basic&#8221; or doesn&#8217;t involve novel capabilities, putting it all together in this way is still a big deal. Most systems today are cyber-insecure against sophisticated actors and even more secure systems are relatively weaker if you can attempt an order of magnitude more variations in your cyber penetration.</p><p>One big change is that<strong> automated cyberattacks are way more scalable. </strong>Currently, cyberattacks from nation states are limited by human operators. But AI agents can handle tactical work continuously and autonomously, allowing threat actors to maintain significantly increased attack tempo across multiple targets.</p><p>Additionally, AI is fundamentally changing how much value is extracted from the target. In this attack, Claude agents were automatically categorizing information as it was collected, making value extraction much more efficient than before. This all improves the cost-effectiveness of attacks and significantly increases the amount of potential simultaneous operations.</p><p>Reducing the skill level needed to implement attacks also makes<strong> cyberattacks more readily available to less skilled actors.</strong> Cyberattacks currently require skilled teams to implement. Progress toward automating cyberoffense potentially enables both nation-states and less sophisticated actors to conduct operations at speeds and scales previously impossible. If the cost and level of sophistication needed goes down, we will likely see more attacks by non-state actors, such as criminal gangs or even disgruntled individuals.</p><p>Also, <strong>cyberattacks now will occur at increased speed</strong> &#8211; operating at the speed of an AI rather than a human. This makes defending harder. This improves how nimble an offensive operation can be, how many targets can be attacked at once and how quickly they can be targeted.</p><p></p><h2>Can defensive AI close the gap?</h2><p>Anthropic&#8217;s response to concerns about this attack is that the same AI capabilities that enable attacks also empower defenders. If Claude can autonomously conduct reconnaissance and exploitation, why can&#8217;t defenders use similar AI systems to patch vulnerabilities and monitor for threats?</p><p>This argument has real merit. Defensive AI is already showing results. AI-assisted threat hunting systems<a href="https://www.darktrace.com/"> catch anomalies humans miss</a>, automated vulnerability scanning<a href="https://github.com/features/security"> identifies exposures before attackers find them</a>, and AI-powered patch testing<a href="https://www.rapid7.com/"> accelerates deployment cycles</a>. The challenge isn&#8217;t whether defensive AI works but whether organizations will adopt it fast enough.</p><p><strong>In the long run, defense probably has fundamental advantages.</strong> Defensive systems can be purpose-built and deeply integrated into infrastructure. They benefit from economies of scale&#8212;one defensive AI system can protect thousands of organizations simultaneously. Eventually, defensive AI might even be able to scalably write provably secure software in a way that we are far from being able to do now. But acknowledging long-run defense advantages doesn&#8217;t mean we&#8217;re safe now. <strong>We&#8217;re entering a vulnerable transition period where the offense-defense balance tips sharply toward offense.</strong></p><p><strong>A key problem is that defenders face fundamental adoption barriers that attackers don&#8217;t.</strong> Existing organizations don&#8217;t even adopt current cybersecurity guidance, let alone modern AI-enabled cyberdefenses. Organizations can&#8217;t simply swap out their entire technology stack overnight. Critical infrastructure often runs on decades-old systems that can&#8217;t easily integrate new defensive AI. But attackers can adopt new offensive AI capabilities immediately.</p><p><strong>And implementing defensive AI is hard.</strong> Organizations deploying AI for defensive purposes must be cautious about introducing new vulnerabilities. An AI system with access to internal networks and security infrastructure represents a massive attack surface if compromised. Defenders can&#8217;t afford to move fast and break things.</p><p>The asymmetry in surface area compounds this problem. <strong>Defenders must secure every potential entry point. Attackers need to find just one that works.</strong> An AI system that can test thousands of attack vectors per hour doesn&#8217;t need to succeed on every attempt. But defensive AI systems must maintain perfect vigilance across all potential vulnerabilities simultaneously &#8211; a fundamentally harder problem. Worse, the economics are fundamentally lopsided. Deploying defenses across all of the possible endpoints is much more expensive than conducting a few attacks in specifically chosen weak points.</p><p><strong>There&#8217;s also a critical reliability asymmetry.</strong> While Claude&#8217;s hacking success rate was low, it was still sufficient for the attackers &#8211; failures are cheap and even a single breach can yield value. But defenders cannot deploy AI systems with low reliability, as this might fail to defend correctly and moreover might accidentally disrupt their own business operations or critical infrastructure. This difference in risk tolerance means even unreliable AI is more potent for offense than defense.</p><p><strong>This is all doubly true for critical infrastructure, where the priority is continuity of the service and thus operators cannot introduce potentially unreliable AI systems.</strong> <a href="https://www.epa.gov/enforcement/enforcement-alert-drinking-water-systems-address-cybersecurity-vulnerabilities">Over 70% of water systems inspected by EPA since September 2023</a> were found to have embarassingly basic failures like using &#8220;password&#8221; as the password, having a single login shared by all employees, and having former employees continue to have system access. Government auditors have made <a href="https://www.gao.gov/assets/gao-24-107231-highlights.pdf">1,610 cybersecurity recommendations since 2010, with 567 still not implemented</a> as of mid-2024.</p><p>A lot of critical infrastructure runs on equipment that&#8217;s decades old, wasn&#8217;t designed with security in mind, and is hard to update without shutting things down, which is not possible. And there aren&#8217;t enough cybersecurity experts to go around, and critical infrastructure operators often can&#8217;t compete with tech companies on salary. Even when federal agencies try to help, they don&#8217;t coordinate well with each other or with the industries they&#8217;re supposed to protect.</p><p>Attackers have no such constraints and have very different risk tolerance &#8212; if their AI agent crashes or gets detected, they simply try again with a different approach.</p><p></p><h2>Looking forward</h2><p>Yes, the immediate impact of this attack is limited. A handful of organizations suffered breaches. Anthropic implemented better detection capabilities and affected entities presumably strengthened security. Presumably, this won&#8217;t stop the next attack, but it will make it a bit harder. And the cyber threat landscape has seen sophisticated state-sponsored operations before.</p><p>But the most important thing is what the attack represents. <strong>The bottlenecks that previously limited cyber operations at scale just loosened considerably.</strong> The economics shifted to favor even broader targeting and even faster operations. <strong>The cost-effectiveness of launching cyberattacks has increased. </strong></p><p>These changes compound. Lower barriers enable more actors. More actors means more operations. More operations means defenders face increased volume while attackers gain more opportunities to discover vulnerabilities and techniques. The feedback loops favor escalation. These factors combine to create a window where offense leads defense, making the next 12-18 months critical for defensive investment and deployment.</p><p>What matters now is pace. Offensive capabilities surged ahead, but defensive capabilities exist. Scaling them is hard, but not impossible. This attack succeeded despite Claude&#8217;s safeguards, proving jailbreaking remains possible, but it also got detected and disrupted, proving monitoring works.</p><p>How quickly organizations invest in defensive AI, how effectively policymakers create adoption incentives, and how well the security community shares intelligence will determine whether this vulnerable period lasts months or years.</p><p>~</p><p><em>Thanks to Caro Jeanmaire, Chris Covino, and multiple anonymous experts for feedback on this article. Any errors in the article are solely my own.</em></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://blog.peterwildeford.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Want more analysis on the latest trends in AI security? Subscribe!</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[AI is probably not a bubble]]></title><description><![CDATA[AI companies have revenue, demand, and paths to immense value]]></description><link>https://blog.peterwildeford.com/p/ai-is-probably-not-a-bubble</link><guid isPermaLink="false">https://blog.peterwildeford.com/p/ai-is-probably-not-a-bubble</guid><dc:creator><![CDATA[Peter Wildeford]]></dc:creator><pubDate>Wed, 29 Oct 2025 16:55:49 GMT</pubDate><enclosure url="https://images.unsplash.com/photo-1745270917449-c2e2c5806586?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwyfHxkb3QlMjBjb20lMjBjcmFzaHxlbnwwfHx8fDE3NjE1MTY3NTl8MA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://images.unsplash.com/photo-1745270917449-c2e2c5806586?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwyfHxkb3QlMjBjb20lMjBjcmFzaHxlbnwwfHx8fDE3NjE1MTY3NTl8MA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://images.unsplash.com/photo-1745270917449-c2e2c5806586?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwyfHxkb3QlMjBjb20lMjBjcmFzaHxlbnwwfHx8fDE3NjE1MTY3NTl8MA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 424w, https://images.unsplash.com/photo-1745270917449-c2e2c5806586?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwyfHxkb3QlMjBjb20lMjBjcmFzaHxlbnwwfHx8fDE3NjE1MTY3NTl8MA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 848w, https://images.unsplash.com/photo-1745270917449-c2e2c5806586?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwyfHxkb3QlMjBjb20lMjBjcmFzaHxlbnwwfHx8fDE3NjE1MTY3NTl8MA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 1272w, https://images.unsplash.com/photo-1745270917449-c2e2c5806586?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwyfHxkb3QlMjBjb20lMjBjcmFzaHxlbnwwfHx8fDE3NjE1MTY3NTl8MA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 1456w" sizes="100vw"><img src="https://images.unsplash.com/photo-1745270917449-c2e2c5806586?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwyfHxkb3QlMjBjb20lMjBjcmFzaHxlbnwwfHx8fDE3NjE1MTY3NTl8MA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080" width="6000" height="4000" data-attrs="{&quot;src&quot;:&quot;https://images.unsplash.com/photo-1745270917449-c2e2c5806586?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwyfHxkb3QlMjBjb20lMjBjcmFzaHxlbnwwfHx8fDE3NjE1MTY3NTl8MA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:4000,&quot;width&quot;:6000,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Stock market chart showing upward trend.&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Stock market chart showing upward trend." title="Stock market chart showing upward trend." srcset="https://images.unsplash.com/photo-1745270917449-c2e2c5806586?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwyfHxkb3QlMjBjb20lMjBjcmFzaHxlbnwwfHx8fDE3NjE1MTY3NTl8MA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 424w, https://images.unsplash.com/photo-1745270917449-c2e2c5806586?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwyfHxkb3QlMjBjb20lMjBjcmFzaHxlbnwwfHx8fDE3NjE1MTY3NTl8MA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 848w, https://images.unsplash.com/photo-1745270917449-c2e2c5806586?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwyfHxkb3QlMjBjb20lMjBjcmFzaHxlbnwwfHx8fDE3NjE1MTY3NTl8MA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 1272w, https://images.unsplash.com/photo-1745270917449-c2e2c5806586?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwyfHxkb3QlMjBjb20lMjBjcmFzaHxlbnwwfHx8fDE3NjE1MTY3NTl8MA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Photo by <a href="https://unsplash.com/@americanaez225">Arturo A&#241;ez</a> on <a href="https://unsplash.com">Unsplash</a></figcaption></figure></div><p><em>About the author: Peter Wildeford is a top forecaster, ranked top 1% every year since 2022.</em></p><p><strong>Is AI a bubble?</strong> <a href="https://www.cnbc.com/2025/10/03/goldman-sachs-ceo-david-solomon-warns-stock-market-drawdown-is-coming.html">Goldman Sachs CEO David Solomon</a>, <a href="https://www.investing.com/news/stock-market-news/wall-sts-ai-bubble-resembles-runup-to-dotcom-crash-ray-dalio-tells-ft-3833409">Ray Dalio</a>, <a href="https://www.tomshardware.com/tech-industry/artificial-intelligence/ai-industry-needs-to-earn-dollar600-billion-per-year-to-pay-for-massive-hardware-spend-fears-of-an-ai-bubble-intensify-in-wake-of-sequoia-report">Sequoia&#8217;s David Cahn</a>, the <a href="https://www.cnbc.com/2025/10/09/imf-and-bank-of-england-join-growing-chorus-warning-of-an-ai-bubble.html">International Monetary Fund</a>, and the <a href="https://www.cnbc.com/2025/10/08/bank-of-england-warns-of-sharp-market-correction-if-ai-bubble-bursts.html">Bank of England</a> are all saying so. <a href="https://www.cnbc.com/2025/10/21/are-we-in-an-ai-bubble.html">Former Intel CEO Pat Gelsinger</a> put it bluntly: &#8220;Are we in an AI bubble? Of course. Of course we are.&#8221; Altman <a href="https://www.cnbc.com/2025/08/18/altman-ai-bubble-openai.html">repeated the word &#8220;bubble&#8221; three times in 15 seconds</a> at a dinner with reporters.</p><p>But the twist is that most of these people are saying &#8220;yes, it&#8217;s a bubble&#8221; while simultaneously announcing they&#8217;re spending hundreds of billions more. <a href="https://fortune.com/2025/09/19/zuckerberg-ai-bubble-definitely-possibility-sam-altman-collapse/">Zuckerberg says a collapse is &#8220;definitely a possibility&#8221;</a> but insists underinvesting is worse. OpenAI&#8217;s Sam Altman <a href="https://www.cnbc.com/2025/08/18/altman-ai-bubble-openai.html">warns investors will get &#8220;very burnt&#8221;</a> while still planning $850 billion in data center buildouts. <a href="https://www.cnbc.com/2025/10/03/jeff-bezos-ai-in-an-industrial-bubble-but-society-to-benefit.html">Jeff Bezos</a> says AI is in an industrial bubble while Amazon spends $100B/yr in AI R&amp;D. </p><p>How do we make sense of this?</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://blog.peterwildeford.com/p/ai-is-probably-not-a-bubble?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://blog.peterwildeford.com/p/ai-is-probably-not-a-bubble?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><h3>OpenAI&#8217;s meteoric rise</h3><p>Back in March 2023, OpenAI <a href="https://www.theinformation.com/articles/openais-losses-doubled-to-540-million-as-it-developed-chatgpt?rc=gbdmm5">reported $200M in annualized revenue</a>.<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-1" href="#footnote-1" target="_self">1</a> Incredibly, this annualized revenue <a href="https://www.theinformation.com/articles/openai-passes-1-billion-revenue-pace-as-big-companies-boost-ai-spending?rc=gbdmm5">passed $1B just five months later</a>, at the end of August 2023. It then continued upward quickly &#8212; passing $2B in<a href="https://www.ft.com/content/81ac0e78-5b9b-43c2-b135-d11c47480119"> December 2023</a>, $3B in <a href="https://www.theinformation.com/articles/openais-annualized-revenue-doubles-to-3-4-billion-since-late-2023?rc=gbdmm5">June 2024</a>, $5B in <a href="https://www.cnbc.com/2025/06/09/openai-hits-10-billion-in-annualized-revenue-fueled-by-chatgpt-growth.html">December 2024</a>, and $10B in <a href="https://www.cnbc.com/2025/06/09/openai-hits-10-billion-in-annualized-revenue-fueled-by-chatgpt-growth.html">June 2025</a>, and now is at $13B as of <a href="https://www.nytimes.com/2025/08/01/business/dealbook/openai-ai-mega-funding-deal.html">August 2025</a>.</p><p>This massive revenue growth has been fast, but is not unprecedented &#8212; <a href="https://epochai.substack.com/p/openai-is-projecting-unprecedented">EpochAI found it to be on a similar trajectory to</a> Google in 2003-2006, Uber in 2015-2020, and <a href="https://www.cheniere.com/">Cheniere</a> (a US liquified natural gas company) in 2016-2020:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!NJ45!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F760a639b-0d0d-4e12-86f1-4007cfb4fc04_1024x1280.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!NJ45!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F760a639b-0d0d-4e12-86f1-4007cfb4fc04_1024x1280.png 424w, https://substackcdn.com/image/fetch/$s_!NJ45!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F760a639b-0d0d-4e12-86f1-4007cfb4fc04_1024x1280.png 848w, https://substackcdn.com/image/fetch/$s_!NJ45!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F760a639b-0d0d-4e12-86f1-4007cfb4fc04_1024x1280.png 1272w, https://substackcdn.com/image/fetch/$s_!NJ45!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F760a639b-0d0d-4e12-86f1-4007cfb4fc04_1024x1280.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!NJ45!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F760a639b-0d0d-4e12-86f1-4007cfb4fc04_1024x1280.png" width="1024" height="1280" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/760a639b-0d0d-4e12-86f1-4007cfb4fc04_1024x1280.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1280,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!NJ45!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F760a639b-0d0d-4e12-86f1-4007cfb4fc04_1024x1280.png 424w, https://substackcdn.com/image/fetch/$s_!NJ45!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F760a639b-0d0d-4e12-86f1-4007cfb4fc04_1024x1280.png 848w, https://substackcdn.com/image/fetch/$s_!NJ45!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F760a639b-0d0d-4e12-86f1-4007cfb4fc04_1024x1280.png 1272w, https://substackcdn.com/image/fetch/$s_!NJ45!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F760a639b-0d0d-4e12-86f1-4007cfb4fc04_1024x1280.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>This massive revenue growth has helped give OpenAI a <a href="https://www.wsj.com/tech/ai/openai-valuation-hits-500-billion-while-altman-signs-more-deals-in-asia-59b47a0d">$500B valuation</a>, making OpenAI <a href="https://x.com/unusual_whales/status/1979971055029825905">the most valuable private company</a>, newly ahead of the $400B SpaceX. If OpenAI were a public company on the stock market with the same valuation, it would be <a href="https://companiesmarketcap.com/">the 18th largest</a>, edging out Exxon Mobil and Netflix but not quite surpassing Mastercard.<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-2" href="#footnote-2" target="_self">2</a></p><p></p><h3>Big revenue meets even bigger spending</h3><p>This is important because OpenAI has a lot of bills to pay for AI infrastructure, especially cloud computing, chips, and data centers&#8230; OpenAI has committed to a <a href="https://www.wsj.com/business/openai-oracle-sign-300-billion-computing-deal-among-biggest-in-history-ff27c8fe?gaa_at=eafs&amp;gaa_n=AWEtsqfDSj4HHmHC4d-3gV1_p5l_lseYltu6BcD4blq1eBE2VZuqDdcy_t4ZkIxqKr8%3D&amp;gaa_ts=68fac899&amp;gaa_sig=1JSy3YrDjgbAzX0EsbOneqGNMa5DdJA9rMLF7LIZYM5TbUXXW4QPognEBrbmp28PYpSt1GThWH52oea-k928Xg%3D%3D">$300B cloud deal with Oracle</a> that begins in 2027 and runs for 5 years, a <a href="https://openai.com/index/openai-nvidia-systems-partnership/">$100B investment from NVIDIA</a> that will be used entirely to buy NVIDIA chips, a $22.4B cloud deal with CoreWeave<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-3" href="#footnote-3" target="_self">3</a>, a <a href="https://www.bloomberg.com/news/articles/2025-10-13/openai-broadcom-sign-10-gigawatt-pact-for-chips-networking">&#8220;tens of billions&#8221; deal with Broadcom for custom AI chips</a>, a <a href="https://morethanmoore.substack.com/p/amd-and-openai-the-6-gigawatt-bet">$90-100B deal with AMD for chips</a> &#8230;and OpenAI is still in on the $500B+ Stargate deal, with plenty of data centers to build too.</p><p>And OpenAI is just getting started. <a href="https://www.bloomberg.com/news/articles/2025-08-15/openai-s-altman-expects-to-spend-trillions-on-infrastructure">Bloomberg quotes</a> OpenAI CEO Sam Altman as saying:</p><blockquote><p>You should expect OpenAI to spend trillions of dollars on infrastructure in the not very distant future. And you should expect a bunch of economists to say, &#8216;This is so crazy, it&#8217;s so reckless, and whatever [&#8230;] And we&#8217;ll just be like, &#8216;You know what? Let us do our thing. [&#8230;]</p><p>I suspect we can design a very interesting new kind of financial instrument for finance and compute that the world has not yet figured it out.</p></blockquote><p></p><p>As a result of all these investments, OpenAI is not currently close to profitable.</p><p>OpenAI <a href="https://www.lesswrong.com/posts/CCQsQnCMWhJcCFY9x/openai-lost-usd5-billion-in-2024-and-its-losses-are">lost $5 billion in 2024</a> on $9 billion in total spending. <a href="https://www.theinformation.com/articles/openai-says-its-business-will-burn-115-billion-through-2029">The Information reports</a> that this will only increase &#8212; OpenAI is projected to lose $14B in 2025, $17B in 2026, $35B in 2027, and $45B in 2028&#8230; <strong>this makes for a stunning situation where OpenAI is projecting unprecedented revenue growth over the next five years but still not breaking a profit until 2030:</strong></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!qC4-!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F842253df-fca4-40e9-92d8-0d7b0e02127f_1682x1104.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!qC4-!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F842253df-fca4-40e9-92d8-0d7b0e02127f_1682x1104.png 424w, https://substackcdn.com/image/fetch/$s_!qC4-!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F842253df-fca4-40e9-92d8-0d7b0e02127f_1682x1104.png 848w, https://substackcdn.com/image/fetch/$s_!qC4-!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F842253df-fca4-40e9-92d8-0d7b0e02127f_1682x1104.png 1272w, https://substackcdn.com/image/fetch/$s_!qC4-!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F842253df-fca4-40e9-92d8-0d7b0e02127f_1682x1104.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!qC4-!,w_2400,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F842253df-fca4-40e9-92d8-0d7b0e02127f_1682x1104.png" width="1200" height="787.9120879120879" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/842253df-fca4-40e9-92d8-0d7b0e02127f_1682x1104.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:false,&quot;imageSize&quot;:&quot;large&quot;,&quot;height&quot;:956,&quot;width&quot;:1456,&quot;resizeWidth&quot;:1200,&quot;bytes&quot;:501575,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://peterwildeford.substack.com/i/176958256?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F842253df-fca4-40e9-92d8-0d7b0e02127f_1682x1104.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:&quot;center&quot;,&quot;offset&quot;:false}" class="sizing-large" alt="" srcset="https://substackcdn.com/image/fetch/$s_!qC4-!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F842253df-fca4-40e9-92d8-0d7b0e02127f_1682x1104.png 424w, https://substackcdn.com/image/fetch/$s_!qC4-!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F842253df-fca4-40e9-92d8-0d7b0e02127f_1682x1104.png 848w, https://substackcdn.com/image/fetch/$s_!qC4-!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F842253df-fca4-40e9-92d8-0d7b0e02127f_1682x1104.png 1272w, https://substackcdn.com/image/fetch/$s_!qC4-!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F842253df-fca4-40e9-92d8-0d7b0e02127f_1682x1104.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>There are three factors that are unprecedented about OpenAI&#8217;s spending &#8212; each merit deeper inspection.</p><p><strong>Firstly, OpenAI is racking up record losses on its infrastructure buildout. </strong>WeWork <a href="https://www.profgalloway.com/webur/">burned through $22B </a><em><a href="https://www.profgalloway.com/webur/">total</a></em> before bankruptcy, but never came close to OpenAI&#8217;s projected $116B. Uber also famously had a &#8220;burn money fast to gain market share and then later figure out how to be profitable&#8221; strategy but their <a href="https://jeffreyleefunk.medium.com/most-unicorn-startups-will-not-overcome-their-cumulative-losses-ecbe7133cf26">cumulative losses peaked around $23B</a>. OpenAI is just operating at a whole different level of scale.</p><p><strong>Secondly, OpenAI&#8217;s projected revenue growth is itself unprecedented. </strong><a href="https://epochai.substack.com/p/openai-is-projecting-unprecedented">EpochAI finds that</a> while OpenAI&#8217;s revenue has tripled annually between 2023 and 2025, only seven US companies have grown from $10 billion to $100 billion within a decade, and none in under seven years &#8212; while OpenAI plans to do that in <em>three</em>.</p><p>EpochAI visualizes OpenAI&#8217;s projected revenue growth, going from ~$10B in 2025 (year 0 on the graph for OpenAI) to ~$100B by 2028 (year 3 on the graph). Compared to other companies, this projection is very fast growth!</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!JegC!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F140f9e18-7326-4efb-af0a-48df34bd911a_1025x1280.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!JegC!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F140f9e18-7326-4efb-af0a-48df34bd911a_1025x1280.png 424w, https://substackcdn.com/image/fetch/$s_!JegC!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F140f9e18-7326-4efb-af0a-48df34bd911a_1025x1280.png 848w, https://substackcdn.com/image/fetch/$s_!JegC!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F140f9e18-7326-4efb-af0a-48df34bd911a_1025x1280.png 1272w, https://substackcdn.com/image/fetch/$s_!JegC!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F140f9e18-7326-4efb-af0a-48df34bd911a_1025x1280.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!JegC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F140f9e18-7326-4efb-af0a-48df34bd911a_1025x1280.png" width="1025" height="1280" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/140f9e18-7326-4efb-af0a-48df34bd911a_1025x1280.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1280,&quot;width&quot;:1025,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!JegC!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F140f9e18-7326-4efb-af0a-48df34bd911a_1025x1280.png 424w, https://substackcdn.com/image/fetch/$s_!JegC!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F140f9e18-7326-4efb-af0a-48df34bd911a_1025x1280.png 848w, https://substackcdn.com/image/fetch/$s_!JegC!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F140f9e18-7326-4efb-af0a-48df34bd911a_1025x1280.png 1272w, https://substackcdn.com/image/fetch/$s_!JegC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F140f9e18-7326-4efb-af0a-48df34bd911a_1025x1280.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>Thirdly, the deeply entangled financing.</strong> I <a href="https://peterwildeford.substack.com/p/openai-nvidia-and-oracle-breaking">covered earlier this month</a> one of these circles, where NVIDIA invests in OpenAI, which spends the money on NVIDIA chips and Oracle compute, while Oracle buys more NVIDIA hardware to serve OpenAI. This meant the NVIDIA capital goes in a big circle from NVIDIA to OpenAI to Oracle back to NVIDIA.</p><p>Since then, there&#8217;s been similar deals with OpenAI and AMD and the circle has gotten bigger. <a href="https://www.bloomberg.com/news/features/2025-10-07/openai-s-nvidia-amd-deals-boost-1-trillion-ai-boom-with-circular-deals">Bloomberg did a good job of diagramming it</a>:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!OHI1!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2cef3528-498d-41ba-97b1-163334d5e99a_1138x1386.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!OHI1!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2cef3528-498d-41ba-97b1-163334d5e99a_1138x1386.png 424w, https://substackcdn.com/image/fetch/$s_!OHI1!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2cef3528-498d-41ba-97b1-163334d5e99a_1138x1386.png 848w, https://substackcdn.com/image/fetch/$s_!OHI1!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2cef3528-498d-41ba-97b1-163334d5e99a_1138x1386.png 1272w, https://substackcdn.com/image/fetch/$s_!OHI1!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2cef3528-498d-41ba-97b1-163334d5e99a_1138x1386.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!OHI1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2cef3528-498d-41ba-97b1-163334d5e99a_1138x1386.png" width="1138" height="1386" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2cef3528-498d-41ba-97b1-163334d5e99a_1138x1386.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1386,&quot;width&quot;:1138,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1235936,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://peterwildeford.substack.com/i/176958256?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2cef3528-498d-41ba-97b1-163334d5e99a_1138x1386.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!OHI1!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2cef3528-498d-41ba-97b1-163334d5e99a_1138x1386.png 424w, https://substackcdn.com/image/fetch/$s_!OHI1!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2cef3528-498d-41ba-97b1-163334d5e99a_1138x1386.png 848w, https://substackcdn.com/image/fetch/$s_!OHI1!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2cef3528-498d-41ba-97b1-163334d5e99a_1138x1386.png 1272w, https://substackcdn.com/image/fetch/$s_!OHI1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2cef3528-498d-41ba-97b1-163334d5e99a_1138x1386.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>So how does this all add up to a potential bubble? </strong>Due to all this circular investment, OpenAI&#8217;s future cash flow is now a sizable part of the valuations of all of Nvidia, Microsoft, AMD, and Broadcom. These companies are priced in large part assuming OpenAI&#8217;s success will continue to drive sustained demand. And these companies are a large part of the stock market.</p><p>This is combined with the risk that OpenAI misses their revenue goals, since OpenAI&#8217;s projection is unprecedented and untested. And if OpenAI misses their revenue goals, there could be a correction in the stock market. And because AI spending is now a large driver of broader US economic growth, this correction could generate a real recession. In short, a bubble popping.</p><p></p><h3>Dot com and the art of the bubble</h3><p>The most familiar bubble is <a href="https://en.wikipedia.org/wiki/Dot-com_bubble">the dot-com bubble</a> in the late 1990s when there was a lot of exuberance about companies first selling on the internet. Many have attempted to draw a comparison to AI and the dot-com bubble. Pets.com failed spending $300 million in 268 days to sell each product at a loss. Webvan raised $800 million for online grocery delivery before operating a single profitable market.</p><p>The dot com boom powered 600% growth in the stock market between 1995 and 2000. But then interest rate increases killed the cheap-money fuel that was powering investment in these companies. This exposed the broader problems in the stock market. Everything crashed back down to 1995-levels, with a 78% drop.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ixXG!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe02521b1-dab0-48e5-85dd-d50bdda6cadc_634x461.gif" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ixXG!,w_424,c_limit,f_webp,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe02521b1-dab0-48e5-85dd-d50bdda6cadc_634x461.gif 424w, https://substackcdn.com/image/fetch/$s_!ixXG!,w_848,c_limit,f_webp,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe02521b1-dab0-48e5-85dd-d50bdda6cadc_634x461.gif 848w, https://substackcdn.com/image/fetch/$s_!ixXG!,w_1272,c_limit,f_webp,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe02521b1-dab0-48e5-85dd-d50bdda6cadc_634x461.gif 1272w, https://substackcdn.com/image/fetch/$s_!ixXG!,w_1456,c_limit,f_webp,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe02521b1-dab0-48e5-85dd-d50bdda6cadc_634x461.gif 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ixXG!,w_1456,c_limit,f_auto,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe02521b1-dab0-48e5-85dd-d50bdda6cadc_634x461.gif" width="634" height="461" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e02521b1-dab0-48e5-85dd-d50bdda6cadc_634x461.gif&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:461,&quot;width&quot;:634,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;The Rise and Burst of 2000 The Dot-Com Bubble&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="The Rise and Burst of 2000 The Dot-Com Bubble" title="The Rise and Burst of 2000 The Dot-Com Bubble" srcset="https://substackcdn.com/image/fetch/$s_!ixXG!,w_424,c_limit,f_auto,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe02521b1-dab0-48e5-85dd-d50bdda6cadc_634x461.gif 424w, https://substackcdn.com/image/fetch/$s_!ixXG!,w_848,c_limit,f_auto,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe02521b1-dab0-48e5-85dd-d50bdda6cadc_634x461.gif 848w, https://substackcdn.com/image/fetch/$s_!ixXG!,w_1272,c_limit,f_auto,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe02521b1-dab0-48e5-85dd-d50bdda6cadc_634x461.gif 1272w, https://substackcdn.com/image/fetch/$s_!ixXG!,w_1456,c_limit,f_auto,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe02521b1-dab0-48e5-85dd-d50bdda6cadc_634x461.gif 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Source: <a href="https://www.tickerhistory.com/p/the-dot-com-bubble-explained">TickerHistory</a></figcaption></figure></div><p>The dot-com bubble shows that business models can be correct in principle but economically unsustainable at current technology maturity and cost structures. But a key difference between dot-com and AI is that the dot-com bubble was about companies who had bad unit economics &#8212; &#8220;we lose money on every sale, but make it up in volume.&#8221;</p><p>However, unlike dot-com companies, the AI companies have reasonable unit economics absent large investments in infrastructure and do have paths to revenue. OpenAI is demonstrating actual revenue growth and product-market fit that Pets.com and Webvan never had. The question isn&#8217;t whether customers will pay for AI capabilities &#8212; they demonstrably are &#8212; but whether revenue growth can match required infrastructure investment. If AI is a bubble and it pops, it&#8217;s likely due to different fundamentals than the dot-com bust.</p><p>And notably, the internet ended up ultimately transformative technology and many 90s internet companies did succeed, such as Amazon, Microsoft, and Apple. Even Pets.com and Webvan were eventually replaced by the successful Chewy and Instacart.</p><p></p><h3>Infrastructure bubbles &#8212; or &#8220;What do British railways and AI have in common?&#8221;</h3><p>Instead, if the AI bubble is a bubble, it&#8217;s more likely an <em>infrastructure bubble. </em></p><p>Consider Britain&#8217;s Railway Mania of the 1840s. The <a href="https://fortune.com/2025/09/28/ai-dot-com-bubble-parallels-history-explained-companies-revenue-infrastructure/">Liverpool and Manchester Railway</a>, opened in 1830, generated 10%+ annual returns and demonstrated railways could dramatically reduce transportation costs. This success triggered an explosive investment. Between 1844 and 1847, Parliament authorized over 8,000 miles of new rail construction.</p><p>Multiple companies laid parallel routes, each assuming they would capture market share. But a lot of the new routes were not profitable. When the crash came in 1847, thousands of investors lost fortunes. Yet the infrastructure remained valuable, powering Britain&#8217;s industrialization through the late 19th century. The technology thesis proved correct; the financial structure was catastrophic.</p><p><a href="https://en.wikipedia.org/wiki/Telecoms_crash">The telecommunications crash of 1997-2002</a> followed a similar pattern. The thesis was sound &#8212; explosive internet growth would require massive bandwidth capacity. Companies laid millions of miles of fiber optic cable, with industry capital expenditures reaching $600B from 1997 to 2001. But the simultaneous construction by competitors created catastrophic oversupply and a significant portion of the fiber was installed but unused. Though the fiber ultimately did end up seeing use over the next two decades, this was far too late for original investors.</p><p>Infrastructure bubbles follow a recognizable arc. A genuinely transformational technology emerges and early deployments generate spectacular returns, validating the concept. Capital floods in at scale as investors extrapolate from initial successes. Multiple competitors simultaneously build capacity, each assuming they&#8217;ll capture significant market share. When aggregate capacity vastly exceeds near-term demand, the surplus can&#8217;t generate the revenue needed to pay for itself, and the financial structures collapse. Companies fail, investors lose fortunes, and infrastructure sits idle. The technology often still ultimately proves transformative, just too late for original investors.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!BilX!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8c09f1b-a1ce-47a2-96f9-eef4dec9a2f1_1920x1440.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!BilX!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8c09f1b-a1ce-47a2-96f9-eef4dec9a2f1_1920x1440.png 424w, https://substackcdn.com/image/fetch/$s_!BilX!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8c09f1b-a1ce-47a2-96f9-eef4dec9a2f1_1920x1440.png 848w, https://substackcdn.com/image/fetch/$s_!BilX!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8c09f1b-a1ce-47a2-96f9-eef4dec9a2f1_1920x1440.png 1272w, https://substackcdn.com/image/fetch/$s_!BilX!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8c09f1b-a1ce-47a2-96f9-eef4dec9a2f1_1920x1440.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!BilX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8c09f1b-a1ce-47a2-96f9-eef4dec9a2f1_1920x1440.png" width="1456" height="1092" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e8c09f1b-a1ce-47a2-96f9-eef4dec9a2f1_1920x1440.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1092,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!BilX!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8c09f1b-a1ce-47a2-96f9-eef4dec9a2f1_1920x1440.png 424w, https://substackcdn.com/image/fetch/$s_!BilX!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8c09f1b-a1ce-47a2-96f9-eef4dec9a2f1_1920x1440.png 848w, https://substackcdn.com/image/fetch/$s_!BilX!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8c09f1b-a1ce-47a2-96f9-eef4dec9a2f1_1920x1440.png 1272w, https://substackcdn.com/image/fetch/$s_!BilX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8c09f1b-a1ce-47a2-96f9-eef4dec9a2f1_1920x1440.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">(Source: <a href="https://www.understandingai.org/p/16-charts-that-explain-the-ai-boom">UnderstandingAI</a>)</figcaption></figure></div><p></p><h3>It&#8217;s not as weird as it looks</h3><p>However, <strong>unlike railway track sitting idle for years, <a href="https://www.cnbc.com/2025/10/14/ai-infrastructure-boom-masks-potential-us-recession-analyst-warns.html">AI data centers are being utilized immediately</a> upon completion.</strong> OpenAI&#8217;s Abilene facility began running workloads as soon as capacity came online. Lead times for advanced GPUs stretch months, and energy availability limits deployment more than capital. The constraint is currently supply, not demand &#8212; which is why companies are aiming to build as much as possible.</p><p>The telecom parallel has more validity. We do have multiple companies building competing infrastructure and we do have multiple AI companies training competing models. This creates risk of redundant capacity. <strong>However, AI infrastructure shows more flexibility than fiber optic cable.</strong> GPUs can run various workloads, data centers can host different services, and cloud capacity potentially retains value even if AI-specific demand disappoints.</p><p><strong>Additionally, NVIDIA and OpenAI&#8217;s circular financing is unprecedented in scale, but not fundamentally unsound. </strong>It&#8217;s similar to how a car company might give you a loan to buy their car &#8212; in this case, the money is still circular, but provided you do pay back the loan, everything works just fine. Except in this case, it&#8217;s NVIDIA renting chips on a loan to OpenAI rather than a car company renting a car on a loan.</p><p><strong>Also the accusations of circular financing apply primarily to OpenAI&#8217;s situation, which is a minority of the broader investment wave.</strong> Microsoft, Meta, Google, and Amazon have immense pre-existing cash flows to pay for their infrastructure buildout without taking on debt. NVIDIA is only doing this for their customers who don&#8217;t have the immediate cash to buy the chips. And NVIDIA also has significant revenue of their own to be able to absorb big hits from bets that don&#8217;t pan out.</p><p>The bigger issue instead is what happens if AI doesn&#8217;t pan out. This, rather than vendor financing, is what would drive a stock market correction or even a recession. NVIDIA&#8217;s $5T market cap assumes sustained AI infrastructure spending. Microsoft&#8217;s $4T market cap includes a large premium for AI-driven productivity gains. If OpenAI&#8217;s revenue trajectory flattens and infrastructure spending is cut because AI-driven productivity doesn&#8217;t pan out, this will cause all these expectations repriced downward. <strong>So the real question is whether AI capabilities will be there on the timelines needed to generate revenue.</strong></p><p></p><h3>The fundamentals of the technology are different</h3><p>Companies like Google and Facebook have already demonstrated that a product that is modestly useful to billions of people can be sufficient to generate hundreds of billions of dollars in annual revenue. OpenAI has a similar level of user base with over one billion free users, and it seems plausible these users could be monetized in some way. This is the basic <em><a href="https://www.theinformation.com/articles/openai-readies-facebook-era">Facebookization of AI</a></em><a href="https://www.theinformation.com/articles/openai-readies-facebook-era"> that seems underway already</a>. AI is not like blockchain, crypto, NFTs, or the metaverse &#8212; there is already real value being delivered.</p><p>But this revenue and other investment can just be a prelude to the true bull case of AI &#8212; AGI that automates the entire economy. If AGI were made, the winner theoretically gets not just some billions in annual revenue, but the entire economy! And along the way to automating the entire economy, maybe AI automate smaller parts of the economy that still deliver economic returns? </p><p>Imagine if the way British Railway Mania worked was not just that additional tracks could produce additional economic value, but that some amount of track (actual amount unknown) would somehow allow the rail company to monetize a cure for cancer, successfully compete with basically every other company in the economy, and potentially even take over the entire world?</p><p>As weird as it sounds, an AI eventually automating the entire economy seems actually plausible, if current trends keep continuing and current lines keep going up. For one example, METR tracks how well AI is doing on software engineering tasks, an economically valuable activity. METR finds that<a href="https://metr.org/blog/2025-03-19-measuring-ai-ability-to-complete-long-tasks/"> models have dramatically increased in their capability</a>, from only being able to do rudimentary toy problems a year ago to being able to stand-in for a non-trivial amount of work that actual software engineers actually do:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!-70S!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdfbeb90f-268f-4dcb-b03c-554d275a0905_2408x910.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!-70S!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdfbeb90f-268f-4dcb-b03c-554d275a0905_2408x910.png 424w, https://substackcdn.com/image/fetch/$s_!-70S!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdfbeb90f-268f-4dcb-b03c-554d275a0905_2408x910.png 848w, https://substackcdn.com/image/fetch/$s_!-70S!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdfbeb90f-268f-4dcb-b03c-554d275a0905_2408x910.png 1272w, https://substackcdn.com/image/fetch/$s_!-70S!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdfbeb90f-268f-4dcb-b03c-554d275a0905_2408x910.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!-70S!,w_2400,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdfbeb90f-268f-4dcb-b03c-554d275a0905_2408x910.png" width="1200" height="453.2967032967033" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/dfbeb90f-268f-4dcb-b03c-554d275a0905_2408x910.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:false,&quot;imageSize&quot;:&quot;large&quot;,&quot;height&quot;:550,&quot;width&quot;:1456,&quot;resizeWidth&quot;:1200,&quot;bytes&quot;:248771,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://peterwildeford.substack.com/i/176958256?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdfbeb90f-268f-4dcb-b03c-554d275a0905_2408x910.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:&quot;center&quot;,&quot;offset&quot;:false}" class="sizing-large" alt="" srcset="https://substackcdn.com/image/fetch/$s_!-70S!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdfbeb90f-268f-4dcb-b03c-554d275a0905_2408x910.png 424w, https://substackcdn.com/image/fetch/$s_!-70S!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdfbeb90f-268f-4dcb-b03c-554d275a0905_2408x910.png 848w, https://substackcdn.com/image/fetch/$s_!-70S!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdfbeb90f-268f-4dcb-b03c-554d275a0905_2408x910.png 1272w, https://substackcdn.com/image/fetch/$s_!-70S!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdfbeb90f-268f-4dcb-b03c-554d275a0905_2408x910.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">(Source: <a href="https://metr.org/blog/2025-03-19-measuring-ai-ability-to-complete-long-tasks/">METR</a>)</figcaption></figure></div><p>And Anthropic&#8217;s Claude Code is <a href="https://www.anthropic.com/news/anthropic-raises-series-f-at-usd183b-post-money-valuation">already generating over $500M</a> by assisting in the development of software code. Trends for other tasks outside of software and math <a href="https://metr.org/blog/2025-07-14-how-does-time-horizon-vary-across-domains/">are not that fundamentally different</a>, suggesting eventually AI will be able to assist with &#8212; and eventually automate &#8212; a bunch of other tasks as well. </p><p></p><h3>So what will happen?</h3><p>Unfortunately, forecasting is not the same as having a magic crystal ball and being a strong forecaster doesn&#8217;t give me magical insight into what the market will do. So honestly, I don&#8217;t know if AI is a bubble or not. Admittedly, OpenAI, NVIDIA, AMD, and other companies are engaging in a lot of weird financial arrangements. But there&#8217;s nothing wrong with these per se. I personally take the bubble possibility seriously.</p><p>But we need to think more clearly. And a lot of people want AI to fail and are just doing ideological pattern-matching to crypto/NFTs and declaring AI a pump-and-dump grift without evidence, and that&#8217;s not good analysis.</p><p><strong>The key question is whether AI capabilities improve fast enough to generate economic returns before the debt comes due.</strong> OpenAI has demonstrated explosive revenue growth already and AI capabilities keep improving on clear trajectories. The underlying bet &#8212; that AI will be economically valuable &#8212; still looks fairly solid.</p><p>My assessment is that there&#8217;s roughly a 30% chance of a significant AI-driven market correction with at least a &gt;20% drawdown in AI-heavy stocks, sometime within the next three years. This may or may not lead to a broader recession, that&#8217;s unfortunately beyond my ability to forecast.</p><p>The modal path (~55% probability) is OpenAI restructures deals and raises dilutive funding rounds, but capabilities keep improving and justify continued investment. Some commitments get renegotiated downward, or OpenAI IPOs at $300B instead of $500B. This reprices AI expectations but doesn&#8217;t crash the market.</p><p>So why are industry leaders calling AI a bubble while spending hundreds of billions on infrastructure? Because they&#8217;re not actually contradicting themselves. They&#8217;re acknowledging legitimate timing risk while betting the technology fundamentals are sound and that the upside is worth the risk.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://blog.peterwildeford.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Want more analysis of AI and the AI economy? Subscribe!</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-1" href="#footnote-anchor-1" class="footnote-number" contenteditable="false" target="_self">1</a><div class="footnote-content"><p>Annualized revenue is a metric that is just the revenue of your most recent month multiplied by 12 to be a full year. It&#8217;s essentially a forward-looking view of how much money you&#8217;d make over the next year if all your months look like the month you just had.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-2" href="#footnote-anchor-2" class="footnote-number" contenteditable="false" target="_self">2</a><div class="footnote-content"><p>Though of course comparing private companies to public companies is an unfair comparison. Private company valuations are based on illiquid preferred shares with liquidation preferences, while public market capitalizations reflect liquid common stock. The $500B likely overstates what OpenAI would be worth as a public company by 20-40%, which would place it lower in the rankings.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-3" href="#footnote-anchor-3" class="footnote-number" contenteditable="false" target="_self">3</a><div class="footnote-content"><p>This includes <a href="https://www.cnbc.com/2025/03/10/openai-to-pay-coreweave-11point9-billion-over-five-years-for-ai-tech.html">an initial $11.9B cloud deal over 5 years with CoreWeave</a> followed up with two separate expansions together adding another $10.5B to the tab</p><p></p></div></div>]]></content:encoded></item><item><title><![CDATA[OpenAI, NVIDIA, and Oracle: Breaking Down $100B Bets on AGI]]></title><description><![CDATA[How vendor financing turns the S&P 500 into a giant AGI bet]]></description><link>https://blog.peterwildeford.com/p/openai-nvidia-and-oracle-breaking</link><guid isPermaLink="false">https://blog.peterwildeford.com/p/openai-nvidia-and-oracle-breaking</guid><dc:creator><![CDATA[Peter Wildeford]]></dc:creator><pubDate>Thu, 25 Sep 2025 19:55:15 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!LPIg!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe88ef79-4d14-49d4-8e6f-dd939160f056_630x498.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!LPIg!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe88ef79-4d14-49d4-8e6f-dd939160f056_630x498.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!LPIg!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe88ef79-4d14-49d4-8e6f-dd939160f056_630x498.png 424w, https://substackcdn.com/image/fetch/$s_!LPIg!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe88ef79-4d14-49d4-8e6f-dd939160f056_630x498.png 848w, https://substackcdn.com/image/fetch/$s_!LPIg!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe88ef79-4d14-49d4-8e6f-dd939160f056_630x498.png 1272w, https://substackcdn.com/image/fetch/$s_!LPIg!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe88ef79-4d14-49d4-8e6f-dd939160f056_630x498.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!LPIg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe88ef79-4d14-49d4-8e6f-dd939160f056_630x498.png" width="566" height="447.4095238095238" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/fe88ef79-4d14-49d4-8e6f-dd939160f056_630x498.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:498,&quot;width&quot;:630,&quot;resizeWidth&quot;:566,&quot;bytes&quot;:491285,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://peterwildeford.substack.com/i/174301735?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe88ef79-4d14-49d4-8e6f-dd939160f056_630x498.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!LPIg!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe88ef79-4d14-49d4-8e6f-dd939160f056_630x498.png 424w, https://substackcdn.com/image/fetch/$s_!LPIg!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe88ef79-4d14-49d4-8e6f-dd939160f056_630x498.png 848w, https://substackcdn.com/image/fetch/$s_!LPIg!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe88ef79-4d14-49d4-8e6f-dd939160f056_630x498.png 1272w, https://substackcdn.com/image/fetch/$s_!LPIg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe88ef79-4d14-49d4-8e6f-dd939160f056_630x498.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><em>About the author: Peter Wildeford is a top forecaster, ranked top 1% every year since 2022.</em></p><p>In 1941, the US<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-1" href="#footnote-1" target="_self">1</a> embarked on the Manhattan Project &#8212; a massive scientific and infrastructure project that produced a working nuclear bomb in less than four years. They spent ~$2B in the process. With inflation, this would be about $37B in today&#8217;s money. It was one of the most expensive scientific projects of all time.</p><p>Today, there is another project at an even bigger scale, except it is happening in the private sector and it&#8217;s for building AGI.</p><p>And it&#8217;s an even larger gamble &#8212; <strong>a $400+ billion web of circular financing deals between OpenAI, NVIDIA, and Oracle that makes everyone&#8217;s valuations contingent on AGI arriving on schedule.</strong> This financial engineering has transformed 25% of the S&amp;P 500 into a leveraged bet that AI scaling will continue unabated through 2030. The math only works if AGI arrives before the money runs out. <strong>The crazy thing is that this all might just actually work.</strong></p><p><strong>Two weeks ago, <a href="https://www.cio.com/article/4056139/what-oracles-300b-openai-deal-means-for-enterprise-cloud-strategy.html">Oracle signed a $300 billion, five-year computing power deal with OpenAI</a>.</strong> The contract was the largest cloud deal ever signed. The resulting bump in Oracle stock briefly made Oracle CEO Larry Ellison the world&#8217;s richest man. The agreement <a href="https://www.pymnts.com/artificial-intelligence-2/2025/oracle-and-openai-strike-300-billion-cloud-agreement-for-ai-infrastructure/">requires 4.5 gigawatts of electricity</a> with <a href="https://www.datacenterdynamics.com/en/news/openai-signs-300bn-cloud-deal-with-oracle-report/">the contract starting in 2027</a>, roughly equal to what 4 million homes consume. This would mean OpenAI paying $60B per year starting in 2028, or almost two Manhattan Projects annually.</p><p>But Oracle quickly got outgunned by another deal. On Monday, <strong><a href="https://openai.com/index/openai-nvidia-systems-partnership/">NVIDIA announced a letter of intent to invest up to $100B in OpenAI</a>. </strong>NVIDIA invests cash in exchange for non-voting shares and OpenAI has committed to using that cash to buy NVIDIA&#8217;s chips. So far, Nvidia has committed the first $10B. We don&#8217;t yet know how the remaining $90B will be spread across years or how many years the investment will be over &#8230;or if it will even actually happen. What we do know is that this is a massive commitment for computing power.</p><p>What does this mean for the future of AI? Let&#8217;s dig in.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://blog.peterwildeford.com/p/openai-nvidia-and-oracle-breaking?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://blog.peterwildeford.com/p/openai-nvidia-and-oracle-breaking?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p></p><h2><strong>The Infinite Money Glitch</strong></h2><p><strong>The structure of this financing warrants closer inspection, as it contains significant risks.</strong></p><p>This is because there is another key deal that gives the OpenAI-Oracle deal and the OpenAI-NVIDIA deal more context &#8212; a third deal announced back in May where <a href="https://www.networkworld.com/article/3995015/oracle-to-spend-40b-on-nvidia-chips-for-openai-data-center-in-texas.html">Oracle promises to spend $40B purchasing NVIDIA&#8217;s GB200 GPUs</a> for an OpenAI data center in Abilene TX as part of the Stargate project. This is a 15-year lease agreement where Oracle purchases the chips and then leases the computing power to OpenAI.</p><p>This leads to what Semianalysis&#8217;s Dylan Patel calls <strong><a href="https://x.com/dylan522p/status/1970346183827783756">the &#8220;Infinite Money Glitch&#8221;</a>:</strong></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!y1-I!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4030317c-fc38-4696-9991-bee888a75ac3_1004x632.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!y1-I!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4030317c-fc38-4696-9991-bee888a75ac3_1004x632.jpeg 424w, https://substackcdn.com/image/fetch/$s_!y1-I!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4030317c-fc38-4696-9991-bee888a75ac3_1004x632.jpeg 848w, https://substackcdn.com/image/fetch/$s_!y1-I!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4030317c-fc38-4696-9991-bee888a75ac3_1004x632.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!y1-I!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4030317c-fc38-4696-9991-bee888a75ac3_1004x632.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!y1-I!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4030317c-fc38-4696-9991-bee888a75ac3_1004x632.jpeg" width="1004" height="632" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4030317c-fc38-4696-9991-bee888a75ac3_1004x632.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:632,&quot;width&quot;:1004,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Image&quot;,&quot;title&quot;:&quot;Image&quot;,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Image" title="Image" srcset="https://substackcdn.com/image/fetch/$s_!y1-I!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4030317c-fc38-4696-9991-bee888a75ac3_1004x632.jpeg 424w, https://substackcdn.com/image/fetch/$s_!y1-I!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4030317c-fc38-4696-9991-bee888a75ac3_1004x632.jpeg 848w, https://substackcdn.com/image/fetch/$s_!y1-I!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4030317c-fc38-4696-9991-bee888a75ac3_1004x632.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!y1-I!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4030317c-fc38-4696-9991-bee888a75ac3_1004x632.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Source: <a href="https://x.com/dylan522p/status/1970346183827783756">Dylan Patel</a></figcaption></figure></div><p>Here&#8217;s how it works:</p><ol><li><p>NVIDIA invests capital in OpenAI, which OpenAI then uses to purchase NVIDIA hardware directly and purchase Oracle cloud compute.</p></li><li><p>Oracle also uses the revenue from the cloud compute deals to purchase NVIDIA hardware.</p></li><li><p>NVIDIA books all of this as additional revenue, despite the revenue being spurred on in significant part by its original investment.</p></li><li><p>This new revenue helps support NVIDIA&#8217;s valuation, which in turn makes its stock more valuable as currency for future investments.</p></li><li><p>The additional increase in stock price allows NVIDIA to afford to invest even more in the next revenue round-trip.</p></li><li><p>The same happens for Oracle and OpenAI too.</p></li></ol><p>Critically, the same money moves around in just one circle, but all of a sudden everyone&#8217;s valuations go up. It&#8217;s a virtuous cycle &#8212; as long as the music keeps playing.</p><p>NVIDIA has already executed smaller versions of this playbook with <a href="https://www.reuters.com/technology/nvidia-backed-coreweave-valued-19-billion-new-funding-round-2024-05-17/">CoreWeave</a>, <a href="https://techcrunch.com/2024/08/21/crusoe-energy-raises-500m-to-expand-ai-cloud-infrastructure/">Crusoe</a>, <a href="https://www.teslarati.com/elon-musk-xai-gets-investment-nvidia-new-funding-round">xAI</a>, and <a href="https://www.datacenterdynamics.com/en/news/nvidia-signs-15bn-deal-to-lease-its-gpus-back-from-lambda-report/">Lambda Labs</a>, but this is next level. $100 billion represents roughly 3% of NVIDIA&#8217;s current market cap, and much bigger than all of the CoreWeave, Crusoe, xAI, and Lambda Lab deals combined.</p><p>Here&#8217;s <a href="https://x.com/kakashiii111/status/1970343371450519875">a more detailed diagram</a>, courtesy of Kakashii. This diagram also shows Coreweave and the increasingly irrelevant Microsoft, showing the confusing web of financials where everyone is circularly funding everyone else:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!B_Ni!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F476162e9-a8a5-4842-97f1-66f871b7fbf5_1360x1530.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!B_Ni!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F476162e9-a8a5-4842-97f1-66f871b7fbf5_1360x1530.png 424w, https://substackcdn.com/image/fetch/$s_!B_Ni!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F476162e9-a8a5-4842-97f1-66f871b7fbf5_1360x1530.png 848w, https://substackcdn.com/image/fetch/$s_!B_Ni!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F476162e9-a8a5-4842-97f1-66f871b7fbf5_1360x1530.png 1272w, https://substackcdn.com/image/fetch/$s_!B_Ni!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F476162e9-a8a5-4842-97f1-66f871b7fbf5_1360x1530.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!B_Ni!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F476162e9-a8a5-4842-97f1-66f871b7fbf5_1360x1530.png" width="1360" height="1530" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/476162e9-a8a5-4842-97f1-66f871b7fbf5_1360x1530.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1530,&quot;width&quot;:1360,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Image&quot;,&quot;title&quot;:&quot;Image&quot;,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Image" title="Image" srcset="https://substackcdn.com/image/fetch/$s_!B_Ni!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F476162e9-a8a5-4842-97f1-66f871b7fbf5_1360x1530.png 424w, https://substackcdn.com/image/fetch/$s_!B_Ni!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F476162e9-a8a5-4842-97f1-66f871b7fbf5_1360x1530.png 848w, https://substackcdn.com/image/fetch/$s_!B_Ni!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F476162e9-a8a5-4842-97f1-66f871b7fbf5_1360x1530.png 1272w, https://substackcdn.com/image/fetch/$s_!B_Ni!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F476162e9-a8a5-4842-97f1-66f871b7fbf5_1360x1530.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Source: <a href="https://x.com/kakashiii111/status/1970343371450519875">Kakashii</a></figcaption></figure></div><p>And across all of this is SoftBank, which <a href="https://www.datacenterdynamics.com/en/news/softbank-buys-additional-shares-in-oracle-and-tsmc-increases-investment-in-nvidia-to-3bn/">increased its stake in Nvidia to $3B and bought $170M worth of Oracle shares</a> in early 2025. SoftBank has also invested over $10B in OpenAI across different investments, with up to $30B total committed. <strong>A leveraged investor at the core of the infinite money loop provides an even deeper point of vulnerability.</strong></p><p></p><h2><strong>Vendor financing, or something more?</strong></h2><p>Of course, the <em>&#8220;Infinite Money Glitch&#8221;</em> is a bit pejorative and hyperbolic. We should acknowledge that financial arrangements of this form are not actually uncommon&#8230; and do not actually yield infinite money. It&#8217;s an arrangement more commonly called <em>vendor financing</em> and it happens all the time. For example, no one complains of an infinite money glitch when a car dealership offers you a loan to buy their car, even though the car dealership ends up being both the seller and the source of capital.</p><p>Companies do vendor financing frequently to move inventory that might otherwise sit unsold, lock in customers (they&#8217;re literally indebted to you), potentially earn interest income on top of product margins, book revenue earlier (though accounting rules vary on this), and gain competitive advantage over vendors who only take cash. The buyer also benefits from this arrangement by preserving cash for other needs and/or getting products they couldn&#8217;t otherwise afford.</p><p>But there&#8217;s a key risk here for the seller-lender &#8212; if your customer can&#8217;t pay you back, you&#8217;re screwed twice, as you&#8217;ve lost both the product AND the money. This dynamic led to <a href="https://en.wikipedia.org/wiki/Telecoms_crash">the collapse of numerous telecom equipment companies in 2001</a>, who provided vendor financing to startups that subsequently went bankrupt. This is important for Nvidia&#8217;s version of vendor financing which is at an extreme and unprecedented scale &#8212; NVIDIA putting up $100B is extraordinarily aggressive.</p><p>Additionally, when NVIDIA has 80-90% market share in AI training chips and nearly every major AI company needs their product, this isn&#8217;t normal vendor-customer dynamics. It&#8217;s more like a sovereign lending to its colonies - you need the currency (GPUs) to participate in the economy at all.</p><p>Thus the &#8220;infinite money trick&#8221; pejorative here is capturing something real &#8212; most vendor financing deals are a tiny fraction of the vendor&#8217;s valuation, and this is very different, with unprecedented scale and market dynamics. If AI compute demand slows or NVIDIA competitors catch up, this whole structure unwinds for NVIDIA in a very bad way. It&#8217;s vendor financing on steroids, enabled by a unique market position for NVIDIA that may not last forever.</p><p></p><h2><strong>Understanding the scale of the ambition</strong></h2><p>In speaking about the NVIDIA deal, OpenAI CEO Sam Altman said something that I hope is obvious to readers of this blog:</p><blockquote><p>Everything starts with compute. Compute infrastructure will be the basis for the economy of the future.</p></blockquote><p>In short, <a href="https://peterwildeford.substack.com/p/compute-is-a-strategic-resource">compute is a strategic resource</a>, and OpenAI wants to have as much of it as possible.</p><p>How will OpenAI pull this off? Altman&#8217;s latest essay <a href="https://blog.samaltman.com/abundant-intelligence">&#8220;Abundant Intelligence&#8221;</a> spells out the plan:</p><blockquote><p>Our vision is simple: we want to create a factory that can produce a gigawatt of new AI infrastructure every week. The execution of this will be extremely difficult; it will take us years to get to this milestone and it will require innovation at every level of the stack, from chips to power to building to robotics. But we have been hard at work on this and believe it is possible. In our opinion, it will be the coolest and most important infrastructure project ever.</p></blockquote><p><strong>To clarify, the scale here is enormous.</strong> &#8220;GW&#8221; refers to &#8220;gigawatt&#8221;, a measure of power. Each individual watt is enough power to run an old-school nightlight. A gigawatt is one <em>billion</em> watts &#8212; enough total power to supply roughly 750,000 homes. Altman wants to produce that <em>each week</em>.</p><p> Today, the largest AI data center is likely 0.3-0.5GW (xAI&#8217;s Colossus).<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-2" href="#footnote-2" target="_self">2</a> There are projects to build 1GW data centers &#8212; <a href="https://semianalysis.com/2025/09/16/xais-colossus-2-first-gigawatt-datacenter/">currently these projects take about two years to produce start to finish</a>. Altman proposes soon somehow speeding up this process 100x.</p><p>Across all of xAI, Meta, OpenAI, Google/DeepMind, Microsoft, and Amazon/AWS, there likely is 15-20GW total being used for AI.<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-3" href="#footnote-3" target="_self">3</a> If not used for data centers, 20GW would be enough to power both New York City and London at the same time. Altman is talking about adding all of that every few months.</p><p>The entire United States currently has ~1300GW of total installed electrical generating capacity as of 2024.<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-4" href="#footnote-4" target="_self">4</a> The US added <a href="https://www.canarymedia.com/articles/clean-energy/chart-96-percent-of-new-us-power-capacity-was-carbon-free-in-2024">56GW of new capacity in 2024</a>. Altman wants to add an equivalent amount annually, just for OpenAI&#8217;s data centers and AI.</p><p>This is a lot, to put it mildly. <strong>Achieving Altman&#8217;s vision would require nothing less than a complete reimagining of how data centers are built.</strong> This would fundamentally restructure global industrial capacity around AI infrastructure, likely requiring breakthrough technologies in modular construction, energy generation, and manufacturing automation that simply don&#8217;t exist today.</p><p>How will Altman pull this off? We will find out soon:</p><blockquote><p>Over the next couple of months, we&#8217;ll be talking about some of our plans and the partners we are working with to make this a reality.</p></blockquote><p>And besides Nvidia, how will OpenAI afford this? Altman isn&#8217;t yet saying.</p><blockquote><p>Later this year, we&#8217;ll talk about how we are financing it; given how increasing compute is the literal key to increasing revenue, we have some interesting new ideas.</p></blockquote><p></p><h2><strong>Can this dream be achieved?</strong></h2><p>Here&#8217;s how I think the AI buildout will go down.</p><p>Currently the world doesn&#8217;t have any operational 1GW+ data centers. However, it is very likely we will see fully operational 1GW data centers before <strong>mid-2026</strong>. This likely will be a part of 45-60GW of total compute across Meta, Microsoft, Amazon/AWS/Anthropic, OpenAI/Oracle, Google/DeepMind, and xAI.</p><p>My median expectation is these largest ~1GW data center facilities will hold ~400,000-500,000 Nvidia Blackwell chips and be used to train ~4e27 FLOP model sometime before the end of 2027.<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-5" href="#footnote-5" target="_self">5</a> Such a model would be 10x larger than the largest model today and 100x larger than GPT-4. Each individual 1GW facility would cost ~$40B to manufacture, with ~$350B total industry spend across 2026.<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-6" href="#footnote-6" target="_self">6</a></p><p>By the end of <strong>2027</strong>, I expect<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-7" href="#footnote-7" target="_self">7</a> a fully operational ~2GW facility with total AI compute across all companies reaching ~90GW. These 2GW facilities would cost ~$95-100B each to build and total industry annual spend would reach ~$500-600B.</p><p>By the end of <strong>2028</strong>, I expect the largest single facility to be ~3GW facility, holding a ~1M chip Nvidia Blackwell/Rubin mix costing $150-165B to build, capable of a ~1e28 FLOP training run.<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-8" href="#footnote-8" target="_self">8</a>  A 1e28 FLOP training run represents a computational effort thousands of times greater than what was used to create GPT-4, allowing the AI to process and learn from vastly more information. Total AI data centers would reach 130GW combined, with ~$900B-1000B spent by the AI industry over 2028.</p><p>By 2029, it starts getting very fuzzy to predict and my forecasting powers break down. How AI continues to scale, whether we&#8217;ve encountered data-related or other algorithmic bottlenecks, what AI capabilities have already emerged, and how economically valuable those AI capabilities are will be key to whether the economics favor continued scaling. Needless to say, building $150B+ individual data center campuses and spending ~$1000B on AI infrastructure would get very difficult to sustain financially, let alone continue to increase dramatically year-over-year.</p><p>I&#8217;m also unsure about how well all the physical supply chains across compute and other forms of manufacturing will continue to support this level of scale or whether we can continue to get the actual energy buildout needed. You can only build physical infrastructure so fast. Whether we are still limited to training frontier AI systems in single data center campuses versus being capable of distributed training across geographically distributed data centers will matter a lot. The unit economics of training versus inference in allocation of compute will matter a lot. Additionally, <a href="https://www.metaculus.com/questions/11480/chinese-invasion-of-taiwan/">wars</a> or <a href="https://pauseai.info/">major regulation</a> could significantly alter the picture. Substantial and rapid AI scaling beyond 1e28 FLOP requires many many different things to all go right. Thus, it&#8217;s plausible we could see a plateau of sorts around ~1e28 FLOP, or 1000x larger than GPT-4.</p><p>However, on an optimistic path where bottlenecks are resolved and AI is immensely economically valuable and generating sufficient financial returns to finance further AI scaling, <strong>2029</strong> might involve ~4GW facilities each costing $210-240B, with total compute reaching 180GW and total spending reaching ~$1200B-1400B annually. We could then see a ~1e29 FLOP model<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-9" href="#footnote-9" target="_self">9</a> trained by the end of <strong>2030</strong>, which would be 10,000x larger than GPT-4. If things keep going on the optimistic path, we also might finally be adding 1GW/week of AI infrastructure in 2030, but <em>across all US AI companies</em>, not <em>just</em> OpenAI.</p><p>This may sound fanciful. And keep in mind that even the not-so-optimistic scenario is still a very aggressive timeline involving very aggressive build-outs. This necessarily already prices in very aggressive investments from OpenAI and others that make the $100B NVIDIA investment look small. Many more headlines about $100B+ investments will need to occur regularly to keep this money-infrastructure train on track.</p><p>What does that get us? <strong>Some say that AI scaling is dead, but the rumors of scaling&#8217;s death have been greatly exaggerated.</strong> As I mentioned <a href="https://peterwildeford.substack.com/p/gpt-5-a-small-step-for-intelligence">in my review of GPT-5</a>:</p><blockquote><p>GPT-5 should only be disappointing if you had unrealistic expectations &#8212; GPT-5 is very on-trend and exactly what we&#8217;d predict if we&#8217;re still heading to fast AI progress over the next decade.</p></blockquote><p><strong>While much is still uncertain, the financing and requisite infrastructure build-out suggests progress towards AGI is very much still on schedule</strong>, <strong>probably sometime in the early-to-mid 2030s.</strong> Get ready for the next five years, and we will truly see what some scaled AI models can do!</p><p></p><h2><strong>OpenAI is not the only hyperscaler</strong></h2><p>Another thing people might read into the announcement is that these investments suggest OpenAI is running away with it and is potentially on track to be the leader in frontier AI development. However, while <strong>OpenAI</strong> is being the loudest and most openly ambitious, they aren&#8217;t the only ones out there. In fact, all of <strong>xAI</strong> (Colossus 2), <strong>Meta</strong> (Prometheus), <strong>Amazon</strong> (Project Rainier), and <strong>Google</strong> (no catchy name unfortunately) are poised to have 1GW data centers by the end of the year, and all companies likely have what it takes to keep on going.</p><p>Hopefully the ability for <strong>OpenAI</strong> and <strong>Google</strong> to remain on the frontier in infrastructure buildout is obvious. For <strong>xAI</strong>, Elon Musk clearly still has the skills to raise the relevant capital and build infrastructure incredibly quickly. However, xAI&#8217;s financial footing also appears questionable, trying to justify a valuation much higher than Anthropic while most of their revenue appears to be inter-company transfers from Twitter. xAI has also recently started bleeding talent and it&#8217;s unclear how this will affect the company long-term.</p><p><strong>Meta</strong> has had an impressive talent pivot, buying up superstar AI engineers, but their infrastructure pivot has been equally dramatic. They scrapped their entire data center playbook and are now building GPU clusters in &#8220;tents&#8221; &#8212; prefabricated structures prioritizing speed over redundancy. It&#8217;s not yet clear if Meta will be able to build frontier AI models that compete with OpenAI, Anthropic, Google, and xAI, but I wouldn&#8217;t count them out yet.</p><p>I&#8217;m most concerned about <strong>Anthropic</strong>. They&#8217;re making a big bet on <strong>Amazon</strong>, but it&#8217;s not clear if Amazon is in turn going to give them the capital needed to compete with the other players. Amazon also is betting a large amount themselves on their Trainium chips, eschewing NVIDIA chips, which are less proven. So far Anthropic has done a good job staying on the AI frontier, but it&#8217;s not clear if they can continue to do so year over year as the scale keeps getting bigger. But Amazon has a lot of capital available, so don&#8217;t count Amazon and Anthropic out just yet.</p><p>Lastly, we should mention the <strong>Chinese AI companies</strong>. Many Chinese companies, such as DeepSeek, Alibaba (Qwen), Zhipu AI (GLM), and MoonshotAI (Kimi) have an explicit focus these days on building AGI. But they&#8217;re just not currently on track to spend on the level of America. <a href="https://www.investopedia.com/alibaba-plans-to-invest-usd52b-in-ai-cloud-over-next-three-years-11684981">Alibaba&#8217;s $52B USD infrastructure plan </a>sounds impressive until you realize it&#8217;s over multiple years and includes all cloud/AI spending, not just frontier AI training, and Alibaba&#8217;s cash generation is much lower than American companies. Additionally, the other Chinese AI companies are much smaller startups without deep access to capital. Lastly, US-led export controls bite hard here, preventing the build up of necessary chips, high-bandwidth networking, liquid cooling infrastructure, and fault-tolerant training systems even if the capital was there.</p><p></p><h2><strong>The economy is increasingly a leveraged bet on AGI</strong></h2><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!oas5!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa5e42b25-0674-49ee-9c9f-c02e23be9509_500x505.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!oas5!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa5e42b25-0674-49ee-9c9f-c02e23be9509_500x505.jpeg 424w, https://substackcdn.com/image/fetch/$s_!oas5!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa5e42b25-0674-49ee-9c9f-c02e23be9509_500x505.jpeg 848w, https://substackcdn.com/image/fetch/$s_!oas5!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa5e42b25-0674-49ee-9c9f-c02e23be9509_500x505.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!oas5!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa5e42b25-0674-49ee-9c9f-c02e23be9509_500x505.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!oas5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa5e42b25-0674-49ee-9c9f-c02e23be9509_500x505.jpeg" width="430" height="434.3" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a5e42b25-0674-49ee-9c9f-c02e23be9509_500x505.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:505,&quot;width&quot;:500,&quot;resizeWidth&quot;:430,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Sam Altman: \&quot;AI will most likely lead to the end of the world, but in the  meantime there will be great companies created with serious machine  learning.\&quot; : r/ArtistHate&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Sam Altman: &quot;AI will most likely lead to the end of the world, but in the  meantime there will be great companies created with serious machine  learning.&quot; : r/ArtistHate" title="Sam Altman: &quot;AI will most likely lead to the end of the world, but in the  meantime there will be great companies created with serious machine  learning.&quot; : r/ArtistHate" srcset="https://substackcdn.com/image/fetch/$s_!oas5!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa5e42b25-0674-49ee-9c9f-c02e23be9509_500x505.jpeg 424w, https://substackcdn.com/image/fetch/$s_!oas5!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa5e42b25-0674-49ee-9c9f-c02e23be9509_500x505.jpeg 848w, https://substackcdn.com/image/fetch/$s_!oas5!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa5e42b25-0674-49ee-9c9f-c02e23be9509_500x505.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!oas5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa5e42b25-0674-49ee-9c9f-c02e23be9509_500x505.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The reason we should be somewhat concerned &#8212; or at least <em>curious</em> &#8212; about this infinite money glitch is twofold. Firstly, AGI might lead to the serious destruction of everything we value and love, <a href="https://peterwildeford.substack.com/p/if-we-build-ai-superintelligence">if not the extinction of the entire human race</a>. Secondly, and much more mundane by comparison, because NVIDIA currently represents <a href="https://www.slickcharts.com/sp500">approximately 7% of the S&amp;P 500&#8217;s total market capitalization</a>. Add in Microsoft, Google, Meta, Amazon, and other companies whose valuations assume continued AI progress, and you&#8217;re looking at perhaps 25-30% of total market value predicated on AI transformation happening roughly on schedule.</p><p>In other words, AGI happening soon may mean the end of humanity, but at least the S&amp;P 500 will remain strong. On the other hand, if the AI scaling hypothesis hits unexpected walls, the unwinding could be a second &#8216;dot com bust&#8217; or worse.<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-10" href="#footnote-10" target="_self">10</a> When everyone is both buyer and seller in circular deals, you&#8217;ve created massive correlation risk. If OpenAI can&#8217;t pay Oracle, Oracle can&#8217;t pay NVIDIA, NVIDIA&#8217;s stock crashes, and suddenly 25% of the S&amp;P 500 is in freefall.</p><p>As Elon Musk <a href="https://x.com/elonmusk/status/1970514040880566675">notes</a>, the &#8220;big question is whether the infinite money glitch lasts until the infinite money AI genie arrives&#8221;.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://blog.peterwildeford.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Want more analysis of the future of AGI? Subscribe!</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-1" href="#footnote-anchor-1" class="footnote-number" contenteditable="false" target="_self">1</a><div class="footnote-content"><p>With help from the UK and Canada.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-2" href="#footnote-anchor-2" class="footnote-number" contenteditable="false" target="_self">2</a><div class="footnote-content"><p>xAI&#8217;s Colossus <a href="https://semianalysis.com/2025/09/16/xais-colossus-2-first-gigawatt-datacenter/">is reported to be at least 300MW</a>. I am guessing it is larger at this point due to further construction since last reporting, but I don&#8217;t know for sure.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-3" href="#footnote-anchor-3" class="footnote-number" contenteditable="false" target="_self">3</a><div class="footnote-content"><p>I am uncertain about this and just estimating based on what is publicly available information. This is an estimate, not a definitive fact.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-4" href="#footnote-anchor-4" class="footnote-number" contenteditable="false" target="_self">4</a><div class="footnote-content"><p>Note this is <em>capacity</em> (maximum potential output). Actual generation was <a href="https://en.wikipedia.org/wiki/Electricity_sector_of_the_United_States">4,178 TWh in 2023</a> - capacity factor varies wildly by source (nuclear runs at ~90%, solar at ~25%).</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-5" href="#footnote-anchor-5" class="footnote-number" contenteditable="false" target="_self">5</a><div class="footnote-content"><p>Note that GB300 improves FP4 to 1.5e16 FLOP/s per package (1.5x over GB200), suggesting the 4e27 FLOP projection could utilize early FP4 capabilities if NVFP4 techniques mature by then.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-6" href="#footnote-anchor-6" class="footnote-number" contenteditable="false" target="_self">6</a><div class="footnote-content"><p>Microsoft is at <a href="https://www.networkworld.com/article/3632209/microsoft-will-invest-80b-in-ai-data-centers-in-fiscal-2025.html">$80B for FY2025</a> and <a href="https://stratechery.com/2025/google-earnings-google-flips-the-switch-on-cloud-search-notes/">increasing to $120B/yr</a>. Google (Alphabet) is at <a href="https://finance.yahoo.com/news/big-tech-set-to-invest-325-billion-this-year-as-hefty-ai-bills-come-under-scrutiny-182329236.html">$75B for 2025</a> and <a href="https://stratechery.com/2025/google-earnings-google-flips-the-switch-on-cloud-search-notes/">increasing to $85B</a>, with the majority going toward &#8220;technical infrastructure, primarily for servers, followed by data centers and networking&#8221;. Amazon is at <a href="https://www.nextplatform.com/2025/02/07/amazon-will-spend-nearly-a-year-of-aws-revenue-on-ai-investments/">~$105B in 2025</a>, with CEO Andy Jassy saying the &#8220;vast majority&#8221; is for AI infrastructure in AWS. Meta announced <a href="https://qz.com/meta-microsoft-alphabet-amazon-spend-billions-ai-capex-1851767670">$60-65B for 2025</a>.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-7" href="#footnote-anchor-7" class="footnote-number" contenteditable="false" target="_self">7</a><div class="footnote-content"><p>Again, median expectation (that is 50% likely to be higher, 50% likely to be lower).</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-8" href="#footnote-anchor-8" class="footnote-number" contenteditable="false" target="_self">8</a><div class="footnote-content"><p>The ~1e28 FLOP projection assumes early Rubin deployment mixed with Blackwell infrastructure. Pure Rubin NVL144 CPX systems achieve significantly higher efficiency: 5,000 racks at 2 GW could theoretically deliver ~8e28 FLOP in 4 months at FP4 precision with 30% utilization. The 1e28 estimate reflects a conservative (a) mixed-generation deployment rather than full next-gen capacity, (b) uncertainty about achieving FP4 training parity despite promising initial NVFP4 results, and (c) uncertainty about training duration.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-9" href="#footnote-anchor-9" class="footnote-number" contenteditable="false" target="_self">9</a><div class="footnote-content"><p>Full-year training on pure Rubin systems with FP4 could potentially achieve ~1e29 FLOP.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-10" href="#footnote-anchor-10" class="footnote-number" contenteditable="false" target="_self">10</a><div class="footnote-content"><p>Though much less worse than extinction.</p></div></div>]]></content:encoded></item></channel></rss>