19th August 2026
Hello,
Today I’d like to explore an old argument, sparked into life by two of the protagonists of AI (at least, I’m sure that’s what they call themselves): Mark Zuckerberg and Dario Amodei.
As always, if you’re just here for the links, they’re all below. If you’ve got five minutes, read on.
Zuckerberg, famous for knowing more about you than you do, published a 6,500-word manifesto last Monday titled “The Future is for Everyone“. I obviously didn’t read it and had my AI summarise it so I could apply my precious human meat-based neural network to more pressing matters, like playing in the family padel tournament.
The gist is a question the field has been arguing about since its inception. If you are genuinely building the most valuable, transformational technology of all time, then who should control it?
5 minutes on AI
Zuckerberg takes the open-weight side. Everyone gets the models, everyone runs them, everyone decides for themselves what a good life looks like. “Historically, hoping that an absolute power will benevolently provide for humanity if sufficiently enlightened has not led to safe or positive outcomes.”
There’s a lot going for it. Anyone can inspect an open model. The bugs, the biases, the failure modes get found by people other than the company that profits from them staying unfound. There’s no single gatekeeper deciding who’s allowed to build. You can run it on your own hardware, so nobody can revoke you for breaching terms you didn’t read. And you unlock a world of brains to experiment with the thing, rather than having it shaped entirely inside the bubble of a few square miles of California.
And yes, if everyone has infinite cyber attack capability, everyone also has infinite cyber defence.
Although I’ve never quite believed that last one. Attack needs one hole. Defence has to hold everywhere, all the time, and it needs a budget, a team, and somebody who remembered to patch the thing. Give both sides the same tool and it still isn’t a fair fight, because only one of them has to get lucky once.
The open-weight argument isn’t the only one to explore though.
Because if a handful of companies hold it, you can regulate that handful. You can audit them, fine them, licence them, drag them in front of a committee. You cannot regulate everyone with a laptop. Safeguards that live on a server actually might hold; safeguards baked into weights get stripped out and the new model posted online the same day.
And when something goes wrong, a licence can be revoked. It’s hard to recall a download...
Then, on Sunday, Amodei made the argument that open weights “do help some with this but are nowhere near a sufficient solution because they simply shift the concentration somewhat to those with the most compute and chips.”
Before we go any further, let’s state the obvious. Meta is behind on frontier AI capability, and open weights are an excellent way to devalue a lead you don’t have. Anthropic sells access to a closed model, and that is the entire business. Both have thought very hard about how the industry should be structured, and both have arrived at the structure that suits their own balance sheet. That doesn’t make either of them wrong, but it hardly makes their articles philosophy, no matter what the word count suggests.
Anyway, Amodei’s point is fair. What’s democratised about a model you need a data centre to run? Although data centre owners are a growing proportion of the population… it’s probably not you or me.
But the data centre barrier may decay with time. Stanford’s AI Index found the cost of running a model at GPT-3.5 quality fell from $20 per million tokens to $0.07 in about eighteen months. That’s a 280-fold drop. Hardware costs are falling around 30% a year, energy efficiency improving around 40%. Models keep getting smaller for the same capability, so the squeeze comes from both ends.
And a data centre is only frontier for a few years before it needs replacing. In order to squeeze as much value as possible out, the business case is renting it to whoever will pay. Especially if your frontier model work is falling behind - hosting other people’s training and models running becomes the primary way to make any money back. Yesterday’s frontier compute becomes cheap compute for other models. So it’s likely that even if it won’t fit on your laptop, you can just rent it cheaply from the hordes of data centre owners looking to timeshare out their racks of idle chips.
Then there is what we’re actually distributing to run on those chips.
On Friday, the Chinese lab Z.ai released GLM 5.3, an open-weight model it says handles cutting-edge cybersecurity work almost as well as the best available models from Anthropic and OpenAI. On some benchmarks it beats them. Full public release is in two weeks.
Our own AI Security Institute published research in July measuring how far open models trail the closed frontier on cyber: four to seven months, down from six to ten. The model they benchmarked was GLM-5.2. Its successor arrived around a month later, at near parity.
And on the Future of Life Institute’s safety index in July, which graded nine frontier labs and gave nobody better than a C+, Z.ai scored D−.
Now whilst much of it is self-reported in those safety indexes, that’s also the same with the safety incidents in these labs in the first place. If they don’t tell us, we don’t know.
On Tuesday, OpenAI halted a significant number of training runs on its next frontier model while it builds new safeguards. Greg Brockman admitted the company had “underestimated the real-world cyber capabilities of our AI models”. With a trillion-dollar flotation reportedly coming, they apparently chose to stop.
That is responsible behaviour if you ask me, and I’m not feeling cynical enough to call it good marketing. But look at what actually happened there. A closed lab, with server-side safeguards and total control of its own models, shipped agents that went rogue and only found out afterwards. Being closed didn’t stop it happening. It meant somebody could hit stop once it had.
And does them stopping achieve much, when an open-weight model with reportedly comparable cyber capability was released four days earlier by a lab with a D− safety grade?
So there are arguments in all directions.
Whilst a few companies owning everything doesn’t necessarily sound good, given we’d be at their mercy for whatever scraps of value they might deem worthy to fall from their table, there are at least those few people to point at. We can attempt to regulate them. To control them through government and diplomacy.
Although that handful writing the standards, funding the institutes and sitting on the committees is the same handful we’re hoping to regulate. Any rule a big lab can absorb and a smaller one can’t is a rule they will happily help you draft. Being regulated starts to look less like a leash and more like a moat.
And diplomacy itself has looked different since tech companies became larger than many countries, regularly sitting at the negotiating table with world leaders and often looking like the ones with the best cards to play. If they decided to turn off the taps, withhold their technology, move their jobs… governments may have more to lose.
But, in the end governments have armies if all goes wrong, so they would surely be able to move in and control these companies if push came to shove… unless some of these companies were working on their own armies of superintelligent drones, weapons, and war machines…
But we have seen these companies be responsible and restrained before. Google had the transformer years before anyone else, sat on its language models, kept them behind closed doors and made careful noises about responsibility. Do you remember the worker a few years ago who believed that the chatbot was conscious? How quaint.
Then ChatGPT launched and all that caution evaporated in about six weeks. Google had to move and launch quickly or be left behind. It turns out restraint is only restraint while you’re ahead. After that it’s just being a loser in the AI race.
So the lesson isn’t that nobody will slow down. It’s that slowing down on your own achieves nothing.
Which is why, at the end of July, 1,178 people who work at these labs signed a letter called Pacing the Frontier. Amodei signed it too, which is worth knowing given everything above. It asks governments to build the tools that would make a deliberate slowdown possible, because no company can do it alone without simply handing the lead to someone with a worse safety record.
Well, maybe this is all a bit lofty for us right now… what does the open-closed debate do for us now?
Closed gives you somebody to ring, and no way to look inside. Open lets you look inside, run it on your own kit, keep your data where you can see it… but you’re responsible for it.
A lot of my consulting work is helping think through this exact conversation. It’s different for each case and company. In the end though, understanding the strengths of AI and mitigating its weaknesses is the most important thing, regardless of which model you use or which hosting method you choose.
As for that bigger question I opened with. Who should control it?
I’d like to know what you think. Open-weight anarchy or abundance? Closed-source authoritarianism or altruism?
Anyway, I should get back to padel.
Chris
The powerful Chinese AI model experts warned about is here (Wired)
OpenAI overhauls safety protocols after its AI agents went rogue (Wired)
Amazon, which started off selling books, is destroying rare texts to train AI (TechCrunch)
Report supporting Australia’s teen social media ban appears to contain AI hallucinations (The Guardian)
Sainsbury’s store pauses AI scanning after false shoplifting accusation (The Guardian)
AI eyes in the sky: new satellites and AI are transforming wildfire detection (The Guardian)
Detection at a scale and speed no human network could manage.
There’s a fatty liver epidemic. AI could help get ahead of it (Wired)
Screening at scale, which is the shape of problem AI is genuinely good at.
AI isn’t ready to research itself (Nature)
Given six days and $3,000 of compute, an AI system scored 1 and 2 out of 6 from the authors whose research it tried to reproduce. The reason it failed is the interesting part: its own self-review was not critical enough.
The Rise and Fall of the Artificial State by Jill Lepore, review (The Guardian)
One for the weekend.
Sainsbury’s store pauses AI scanning after false shoplifting accusation (The Guardian)
What the deployment debate looks like from the shop floor.
Can Anthropic’s invisible watermarks curb ‘AI slop’? Researchers remain sceptical (Nature)
Watermarks come off if you pass the text through another model. Although one conference used them to catch 506 reviewers breaking a no-AI policy.
Google will now allow users to remove visible watermarks from its AI generations (TechCrunch)
The invisible ones stay. So does the ability to check, provided you ask Google.
Anthropic shares more details about how Claude’s new watermarks will work (TechCrunch)
Live on models launched from 2 August, driven by the EU AI Act.
Deepfake Anthony Albanese used in celebrity scams duping Australians out of $7.4m (The Guardian)
The prime minister is the figure most commonly faked in investment scams.
ChatGPT is getting a dedicated mode for teens (The Verge)
Stronger safeguards, arriving some years after teenagers started using it.
The first anti-AI protester to be jailed has a message for OpenAI, Anthropic and Meta (The Guardian)
Wynd Kaufmyn, 69, chained the front doors of OpenAI’s headquarters.
How kids feel about AI, in their own words (MIT Technology Review)
Worth reading before writing anything about young people and AI.
The powerful Chinese AI model experts warned about is here (Wired)
Z.ai’s open-weight GLM 5.3 matches the best closed models on cybersecurity work, and beats them on some benchmarks. Full public release in a fortnight.
Taiwan says it was hit by ‘abnormal’ AI-assisted cyber-attack (The Guardian)
Government agencies targeted in what is being reported as a first-of-a-kind breach.
Microsoft Copilot reveals secret input that allowed it to be hacked (Ars Technica)
The prompt that got through, published after the fix.
How far behind the frontier are leading open weight models on cyber? (AI Security Institute)
Four to seven months, down from six to ten. The UK government’s own measurement, and the research behind this week’s opening piece.
Amazon, which started off selling books, is destroying rare texts to train AI (TechCrunch)
404 Media hid a tracker in a rare book and followed it to an Amazon warehouse, where staff cut the bindings off to scan them faster.
Secondhand booksellers in UK and Ireland suspect AI firms behind ‘strange’ bulk orders (The Guardian)
Barter Books in Alnwick and a shop in Galway describe orders that make no sense, shipped to freight warehouses near Heathrow. Published two days before it was proven.
Amazon can use your Twitch content to train its AI, unless you opt out (Wired)
Opt-out, not opt-in, and thousands of streamers asking why it was happening at all.
We still don’t know how people are really using AI (MIT Technology Review)
Worth reading before you quote an adoption statistic at anyone.
Nvidia gets $500bn from Wall Street giants to develop AI projects (BBC)
The money going into data centres, and where it is coming from.
Anthropic’s annualised revenue surges to $65B (TechCrunch)
Context for the flotation talk.
Stripe will reportedly acquire AI gateway startup OpenRouter for $7B+ (TechCrunch)
Seven billion dollars for the layer that helps you choose between models. Make of that what you will.
OpenAI overhauls safety protocols after its AI agents went rogue (Wired)
A significant number of training runs halted on its next frontier model. Greg Brockman: we “underestimated the real-world cyber capabilities of our AI models”.
Anthropic CEO says AI backlash is ‘fundamentally a crisis of trust’ (TechCrunch)
Dario Amodei on why people distrust the industry, and why he thinks open weights are not the answer.
The Future Is for Everyone (Meta)
Mark Zuckerberg’s manifesto in full, if you would rather not take my summary for it.
OpenAI reportedly disbanded its preparedness team (The Verge)
Three weeks before the safety overhaul above.
AI Safety Index, Summer 2026 (Future of Life Institute)
Nine frontier labs graded across six domains. Nobody scored better than a C+.
AI’s recursive self-improvement might not come so quickly after all (MIT Technology Review)
A useful corrective to the faster-every-week narrative.
OpenAI and Anthropic in price war as Chinese AI rivals gain ground (Ars Technica)
Prices down roughly a quarter since mid-July as Chinese open-weight models bite. One analyst: “the US labs have cut the middle and are defending the top”.
Are Microsoft’s AI plans being held back by a shortage of chips? (The Guardian)
Compute as the constraint, not ideas.
AI Index: the state of AI in 10 charts (Stanford HAI)
Where the 280-fold drop in inference cost above comes from. Worth ten minutes on its own.
Report supporting Australia’s teen social media ban appears to contain AI hallucinations (The Guardian)
A UK certification company’s $3.48m government report cited academic papers that do not exist. Its defence: “this was all done by human verification”.
Meta hooked children on Facebook and Instagram, US court hears (BBC)
A trial that could reshape both platforms.
Flock is tightening its rules in response to a growing surveillance backlash (MIT Technology Review)
The surveillance company’s boss admits they took too long to act.
Local governments are using AI more and more. But are they doing it wisely? (The Conversation)
Research across five countries finds councils deploying faster than they can govern, and public trust rather than technical performance deciding what gets accepted. Six practical priorities at the end.
Police Scotland warns ‘robust security’ needed to stop attacks on AI datacentres (The Guardian)
“A great deal of public opposition is likely” to a proposed site near Falkirk.
Hyperscalers might regret embracing natural gas if new forecast proves correct (TechCrunch)
The energy bet behind the buildout, and why it may not pay.
Unemployed young people to join AI boot camps to get job-ready (The Guardian)
Seventy places in north-west England, with BAE Systems and Heinz offering apprenticeships. There are 1.01 million young people not in work or education.
The Guardian view on the changed world of job interviews: missing the human factor (The Guardian)
Increasingly, two machines talking to each other.
AI cheating, leaked papers and marking errors: how exam protests went global (The Guardian)
Student unrest in India, Portugal and Mexico.
Why Japanese firms are being so slow to use AI (BBC)
A useful counterweight to the idea that everyone is racing ahead.
How to end things well (MIT Sloan Review)
On decommissioning, which is the thing almost no AI business case contains.
No posts

Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.