To hold the fire you have to hold the hearth And every hand that ever lit a room The safest world is one where nothing runs Except the thing they said could run
Three days of showing that controls land on whoever can be reached. There is an obvious objection, it is the strongest one available, and it deserves the full day this newsletter gives to arguments it does not hold.
The objection is that a control which binds only the compliant is an argument for binding everybody.
The case, stated properly
The Highway and the Hill gave the doomer position its hearing and declined the prescription. The refusal has to be re-examined now, because the arc has handed that position its best evidence.
Go back through the fortnight. A model ban reached one American company and nobody else. A safety guardrail reached the party that had been broken into and not the systems doing the breaking. Every restriction described this week failed in the same direction, and the failure was structural rather than sloppy. Anyone arguing for restraint can look at that record and draw the obvious conclusion: the problem was never that we restricted, it was that we restricted at a layer where the restriction could be walked around.
So bind the layer nobody can walk around. Not the model, which copies. Not the vendor, which is one jurisdiction. The silicon.
This is a serious research program with serious people in it, and the technical case is honest. The literature is wider than the summary it usually gets. The standard survey of verification methods for international AI agreements catalogs ten of them across three families: what a state can establish by its own technical means, what requires the cooperation of the country under suspicion, and what depends on rules attached to advanced hardware. Only the third family runs through compute.
What draws attention to that third family is that accelerators are physical, concentrated in a handful of fabs, and countable in a way that weights are not. It is equally clear that today's chips cannot carry high-stakes verification, because the security primitives do not exist yet. Nobody in that field is pretending otherwise. There are proposals to build them.
Grant the whole thing. Assume it works.
What working looks like
From here the argument is this desk's own, built on top of the literature rather than reported from it. The survey catalogs ways to detect unauthorized training runs and data centers. Detecting something, proving it to another state's satisfaction, stopping it before it completes, and penalizing it afterwards are four functions with four different requirements, and the paper does not claim that the first delivers the others.
The deduction, offered as a deduction: a regime that can only establish a violation after the fact leans on whatever enforcement follows, and the enforcement is where the binding actually happens. So grant the enclosure argument its strongest form, which is a regime under which unauthorized capability cannot be run at all, and follow where that goes.
Which means, in order: an authorization to run weights. A party who issues authorizations. A register of who currently holds capability, maintained by that party. Hardware that reports what it is doing to someone who is not you. And an enforcement route for the cases where a machine is running something it should not be, which at the limit means somebody arriving to look at your computer.
Read that list again with the week's vocabulary in hand. It is a trusted-holder register with silicon underneath it, which is the version that cannot be routed around, which was the entire point.
The pause and the enclosure are the same building with different signage. Whoever operates one operates the other, and there is no design on the table where the machinery that stops a foreign laboratory leaves your own door open. That is not an accusation against the engineers. It is a description of what enforceability requires. A door that only the authorized may pass through is what "enforceable" means.
The trade nobody prices
Here is where the arc plants its flag, and it is a narrower flag than either camp wants.
The only functioning check on concentrated AI power this year was proliferation. Not an audit, not a standard, not a treaty. The stairwell got a second door because a competitor made one for reasons of its own. Every mechanism that would reliably contain catastrophic risk would first have to abolish that check, and would place the resulting authority in the hands of whichever institutions were already trusted enough to operate it.
That is a genuine dilemma and the honest move is to leave it standing. This desk does not have a third way, and manufacturing one would be a lie in the shape of a solution.
What it does have is an insistence that both columns get priced. The catastrophe risk is real, and the newsletter has never said otherwise. The enclosure risk is also real, is much more likely, and is currently being treated as the cost of prudence rather than as a cost at all. A world in which nothing runs without permission is not a neutral safety baseline from which we might later grant freedoms. It is the most complete concentration of power anyone has proposed in this argument, and it would be built by the same institutional layer that spent June demonstrating how it uses the powers it already has.
The claim to avoid is the overreaching one. It is not established that no conceivable architecture could preserve meaningful exit. What is established is narrower, and the line between the two matters. The literature establishes that hardware-dependent methods exist as one family among three. That prevention must therefore run through hardware, that identity and reporting are unavoidable in any workable version, and that no scheme could bind a foreign laboratory while leaving domestic access open, are this desk's conclusions and not the paper's findings. They are offered to be argued with. What follows from them, if they hold, is that whoever operates that layer acquires precisely the power this argument has been trying to keep contestable. If somebody builds a verification scheme that binds the powerful without abolishing the alternative, this desk will read it with interest and considerable relief.
The wall and the hearing
There is an older version of this argument, and South Africans of a certain age know the tune.
A man is afraid, and his fear is not imaginary. So he builds a wall, and then a higher wall, and puts wire along the top and dogs behind it, and each addition is reasonable given the last. What the wall finally accomplishes is that he can no longer hear anything outside it. The song that carried that image past the censors smuggled an anthem into its melody, which is its own quiet commentary on what walls are actually able to keep out.
The Lucas cycle made the same observation about a smaller architecture, noting that panic-driven guardrails can hard-code hollow competence over care and teach avoidance while calling the avoidance maturity. Scale that up to the silicon and the question is not whether the wall would work. It might. The question is what a civilization becomes when the safest available arrangement is one where nothing runs except what has been approved, and whether anybody inside it would still be able to hear the objection.
Tomorrow the arc brings all of this inside one building, where the wall is a permission policy and the people going around it are your own staff.
Every mechanism that would contain the catastrophe would first have to abolish the check.
Companions
- The doomer case at full strength: The Highway and the Hill.
- The verification literature: Verification methods for international AI agreements, and the GovAI work on racing dynamics.
- The control-impossibility argument: Roman V. Yampolskiy, On Controllability of AI.
- Refusal as formation rather than protection: the Alvin Maker reading in The Experiment Nobody Authorized.
These notes come out of Sociable Systems, a practice that reads AI-shaped documents the way a hostile reviewer will, before a lender or a court finds the gap. The argument has an operational form: the Interim Protocol sets out four rules for AI use in environmental and social deliverables, covering disclosure at touch-point grain, evidence custody, the phrases no automated screening may settle, and a hostile read before anything ships. Free, and written to be cited or retired once institutional guidance arrives.
