What Dario Wanted
A frontier model was switched off by government order. The lab most identified with safety appears to have wanted it.
Begin with something you would not expect in the sweet land of liberty, least of all in the summer it turned two hundred and fifty. In June, the United States government reached into a private company and switched off the two most capable AI models in the world. Not with a court order and a hearing, but with an export-control directive that took effect the moment it was issued. The company had released them three days earlier; they were available worldwide one afternoon and dark the next, for everyone, because the rule applied to foreign nationals and no one can verify in real time who is on the other end of a login. Eighteen days after that, the government approved turning them back on, under new conditions it helped write.
The first two pieces in this series were about money: the bill arriving on my account as the subsidy ends, and the larger bill arriving on the country as American intelligence prices itself out of a world that has found somewhere cheaper to shop. Both of them ended by pointing at this, the thing money does not explain. A government now sits in the room where these models are switched on and off. And there is good reason to think at least one of the people who builds them was not sorry to see the state take a seat.
That is the question this last piece is about. Not who holds the switch, though that matters. Why anyone constructing the future would want the state’s hand on it, what he gets for it, and whether any of us should trust the arrangement.
The Man Who Asked for the Rules
The company is Anthropic, the maker of Claude, and its chief executive is Dario Amodei. Of the people running frontier AI labs, he is the one who has argued longest and loudest that this technology is dangerous enough to require the government’s hand. This past month he published an essay, “Policy on the AI Exponential,” calling in plain terms for mandatory third-party testing of frontier models and for the government to hold the power to block a deployment it judges unsafe. Not voluntary commitments. Binding rules, with the state as the gate.
You can read that as conscience, and it deserves to be read that way first. The case for it is not weak. Anthropic’s own security program, run on its most powerful model, has turned up more than ten thousand high- or critical-severity vulnerabilities in real software. The jailbreak that triggered the June shutdown was not imaginary: a researcher got the model to produce working demonstration code for exploiting a flaw. And Anthropic says the honest thing itself, that it is “probably impossible to make any AI model fully robust (that is, impervious) to jailbreaks.” If you believe the capability is real and the danger is real, then wanting a referee is not cowardice. It is the reasonable position of someone who can see what he is building.
David Sacks, the White House AI advisor, reads it the other way, and he does not soften it. “Anthropic is running a sophisticated regulatory capture strategy based on fear-mongering,” he wrote, and then added the part that stings: “About eight months ago, I warned” of exactly this, “now look how many people are saying it.” In his telling, the safety argument is not a conviction. It is a business plan wearing the costume of a conscience.
This is the fault line running down the middle of the industry, and the June episode dragged it into the open. On one side, the accelerationists, Sacks and Musk and Marc Andreessen, who want the models open, the regulation light, and the technology exported as an instrument of American power. On the other, the safetyists, with Amodei as their most articulate voice, who want testing, gates, and a government able to say no. The two camps agree on almost nothing except that the stakes are enormous. And the thing worth noticing is which camp gets richer if it wins.
The Moat That Looks Like a Fence
Here is what a rule does that a press release cannot. A rule sets a price of admission, and it sets the same price for everyone, which is exactly why it is not the same burden for everyone.
Imagine the regime Amodei is asking for, and in large part now getting. Before you release a frontier model, you submit it to a government-supervised testing process. You maintain a monitoring team. You build the classifiers, document the safeguards, and coordinate disclosure through an approved channel. A company the size of Anthropic can absorb all of that. It has the lawyers, the compliance staff, the government relationships, the safety researchers already on payroll. A startup with eleven people cannot. An open-source collective releasing free model weights to the world has no way to comply at all, because compliance assumes a single company with a door the government can knock on.
So the review regime that reads as a fence around danger works, in practice, as a moat around incumbents. It does not stop the frontier. It raises the drawbridge behind the labs already across it. And the tell, the detail that should make anyone pause, is that the regulated companies are helping write the regulations. The jailbreak-severity framework now being drafted after the June shutdown, the one that will define how bad a flaw has to be before a model gets pulled, is being authored by Anthropic together with Amazon, Microsoft, and Google. The entity being governed is co-authoring the terms of its own governance. That is not a conspiracy theory. It is in the announcement.
The shape of this was drawn well before the June shutdown, and one of the investors it targeted was told the plan to his face. Marc Andreessen has described a set of meetings with Biden-administration officials in the spring of 2024, and his account is first-person and specific: “I was in the meeting.” What he says he heard was not a hint. “They actually said flat out to us: don’t do AI startups. Don’t fund AI startups. It’s not something that we’re going to allow to happen.” AI, the officials told him, “is going to be a game of two or three big companies working closely with the government,” companies the state would “wrap in a government cocoon,” protect from competition, and control. When Andreessen objected that the knowledge could not be contained, that the mathematics under AI is taught in every university on earth, the answer unsettled him more than the plan. During the Cold War, they told him, the government had classified whole branches of physics out of the research community, taken them dark, and it was prepared to do the same to the math beneath AI.
Andreessen is not a neutral narrator either. He runs one of the largest AI venture funds and has his own reasons to cast the last administration as the enemy of the startups he champions. But his account does not stand alone. Sacks, surveying the same terrain from the White House, describes the same machine. Anthropic, he argues, treats “competition between AI companies as a dangerous race condition” and therefore wants to “create a cartel, and that is their view of AI safety.” And he offers the personnel proof. The federal AI Safety Institute stood up under the last administration was, in his telling, “something that Anthropic basically set up,” and when that administration ended its AI officials went to work at the company: the AI lead at the National Security Council, the head of the Safety Institute, the man who held Sacks’s own job before him. Two rivals, describing from opposite sides a single design, to narrow the frontier to a few blessed companies operating hand in hand with the state.
The switch is real, and it is already being thrown on more than one company. The government is now approving access to OpenAI’s most advanced model, GPT-5.6, on a case-by-case basis, individually clearing users during the preview. Sam Altman, agreeing to it, made a point of saying it is “not our preferred long-term model.” Aaron Levie, who runs Box, called the arrangement what it is, “de facto AI regulation,” and named the trap inside it: gate the American frontier tightly enough and the open Chinese models simply close the distance while our best work sits behind a federal approval queue. The gap is already measured in points on a benchmark, not years.
The most interesting witness against the fence is a man who builds them. Mustafa Suleyman co-founded DeepMind and now runs Microsoft’s AI division, and in his book The Coming Wave he describes the endgame of concentrated AI power without any of the industry’s usual reassurance. The companies that pull ahead, he writes, become power centers “without parallel,” and then comes the line that belongs on the wall of this whole debate: “How these entities are governed, how they will rub against, capture, and reengineer the state, is an open question. That they will challenge it seems certain.” Capture and reengineer the state. That is not an activist’s slur. It is a description offered by one of the people doing the building. In The Age of AI, Henry Kissinger and his co-authors saw the flip side of the same coin: once a technology becomes nationally indispensable, the power to withhold it becomes leverage, and that leverage does not stay in private hands. The June shutdown was the leverage, demonstrated.
The Honest Complication
If the story ended there it would be clean, and it would be a lie by tidiness. The clean version is that Amodei wanted a moat and dressed it as safety. The honest version is stranger and more to his credit, and leaving it out would be exactly the kind of dishonesty this series is supposed to resist.
Earlier this year, before any of the June drama, the Pentagon wanted to use Anthropic’s models. Anthropic asked for guarantees: that its systems would not be used for autonomous weapons, or for mass domestic surveillance. The Defense Department would not give them. So Anthropic walked away from the contract and the money attached to it. The administration responded by banning federal agencies from using Anthropic at all. OpenAI stepped into the gap and took the Pentagon work Anthropic had refused. Palantir sat underneath both as the software layer. The company now accused of running a regulatory-capture play is the same company that, months earlier, gave up a government payday rather than compromise a line it had drawn.
Both things are true at once, and the maturity of the argument depends on holding them together. Anthropic pushed for a regulatory regime that happens to protect its position, and Anthropic sacrificed real revenue on a matter of principle when the principle cost it. What Dario wanted, as far as anyone outside the room can tell, is a world in which powerful AI is governed by rules, tested before release, and gated against the worst uses, even when the gate costs him. Whether that is the conviction of a man who has genuinely seen something frightening, or the strategy of an incumbent who has noticed that his convictions are good for business, is a question I cannot answer, and neither can Sacks, because the honest answer is that it is almost certainly both. The uncomfortable part is not that Amodei is a hypocrite. It is that his sincerity and his self-interest point the same direction, and there is no instrument that separates them.
We should sit in that discomfort rather than resolve it, because we are in the same position ourselves. We want these tools to be safe and we want them to be open and free, and almost none of us has said out loud which of the two we would give up if forced. This is the honest version of Pushing Their Book, the discipline of reading a man’s incentives before you trust his warnings. Amodei is pushing his book. He may also be right. Both.
You Can’t Fence Intelligence
Grant the safety case its full weight, and a hard practical problem remains, one the gate does not solve and may make worse.
The only way to keep a dangerous model out of the wrong hands is to restrict who can get it. That is the whole mechanism: nationality checks, approval queues, access denied to some and granted to others. Set aside for a moment whether that is wise and notice what it is. It is the opposite of the thing America has always claimed to sell. We told the world our technology came with our values attached, openness among them, and the enforcement mechanism we have arrived at is a permission slip. A country that built its standing on the free flow of tools and ideas is now, in the name of safety, metering access to the most important tool of the age by citizenship and clearance.
Andreessen came away from those Biden-administration meetings calling them the most alarming he had ever sat in, and his reason cuts deeper than the specific plan. If the century really is a contest between the United States and China, he argues, then the test of any move is simple. Does it make you more like your rival, or more like yourself? A frontier narrowed to two or three national champions with the government’s hand inside them is not an American answer to China. It is the Chinese model, the political officer down the hall who can overrule the chief executive at will, imported and renamed. You do not beat that system by building your own version of it. A world where the American lab answers to a state minder is not a safer America; it is a worse China, and it throws away the exact advantage this series has kept pointing at, the openness that made the American stack worth building on to begin with.
And here is the part that should end the argument on its own merits: it does not work. The premise of the fence is that if we lock down American frontier models, the dangerous capability stays contained. It does not, because the capability is not only American. China is shipping open-weight models, free to download, at or near the frontier, every month. The second piece of this series was partly about that. You cannot un-ship an open model. It is already on hard drives all over the world. The officials who floated classifying the mathematics of AI, the way the Cold War classified whole branches of physics, had at least grasped the true size of the task. To contain the capability you would have to contain the knowledge, and the knowledge is loose. It is taught in every graduate program on earth, published in the open, downloaded a hundred thousand times a week. Gate GPT-5.6 behind a federal approval process and a bad actor does not give up. He downloads a Chinese model that has the same class of vulnerability and no queue at all. The jailbreak that shut down Fable, Anthropic itself noted, works on nearly every comparable model in existence. Fencing ours removes exactly none of the threat and forfeits the openness in the process.
Even Alex Karp, the Palantir chief executive who profits from every version of this and says so, put the strategic absurdity cleanly. It is “a loser,” he said, “to restrict something from the government because you don’t agree with how the government fights war and then open it up to the world, including our adversaries.” Take him as the interested party he is. He is still right that you cannot hold a capability back from your own side and expect it to stay away from the other. The answer to a world full of powerful models is not a taller fence around ours. It is to release and to harden, to build the defenses that assume the dangerous capability is already loose, because it is. You do not secure a field by pretending you can wall it. You secure it by learning to defend it.
Who Is Fit to Hold It
There is a coda to Andreessen’s story that everyone repeats for the laugh and should keep for the rest. Rogan asked him the obvious question: after a meeting where the government tells you it intends to seize the defining technology of the age, what do you do? The answer got its laugh. “You go endorse Donald Trump.” But the joke has a second half the room did not stay for. He fled one administration’s plan to control AI and threw in with the one that, half a year into power, reached into a company and switched two models off. The hand on the switch changed parties. The switch did not go away. That is the thing to see plainly, because it is the whole point. The reach for the kill switch is not a Republican impulse or a Democratic one. It is what power does when a technology this consequential comes within its grasp, and it will be waiting there no matter who you elected to keep it away.
So the switch exists, and someone is going to hold it. The question the whole series has been circling is the one Who Holds the Switch raised in June, before there was a concrete event to hang it on: whether anyone in this story is fit to.
Look honestly at the candidates and the trouble is that every one of them is compromised in the same motion that qualifies them. The labs know the technology better than anyone, and they answer to their shareholders and to the safety brand that sells their product. The government can claim to speak for the public, and it answers to its own appetite for power. Its readiness to fuse itself to this technology, to reach for the sword and the switch in the same grip, is the thread Who Bears the Sword has been following since the Iran strikes. Suleyman, again, names it without flinching: nation-states will “use the tools of the coming wave to tighten their grip,” entrenching their dominance the way every power does when a new instrument falls into its hands. There is no neutral party in the room. There is a company with a book to push and a state with a grip to tighten, negotiating the terms of a switch over the tools a civilization is about to think with.
And there is one more thing to weigh about the man most eager to hold it, because it goes deeper than incentives. Duncan Umphrey, a writer and philosopher at Palladium, put the vision plainly in a June interview, and it is worth quoting because it is not hostile, only clear. “What Dario, and ... a lot of these AGI maximalists, are trying to do is build a world in which human beings, we’re flourishing, but we’re no longer center stage. There’s something ... more perfect than human beings,” he said. He called it what it is, “a theological vision,” an “eschatology of AI” rising to fill the space where traditional religion is receding. That is the conviction underneath the safety argument, and Machines of Loving Grace? took the measure of it in Amodei’s own manifesto months ago. Not merely that these machines are dangerous, but that they are the more perfect thing, and that the human is on the way to the edge of the frame.
Set that beside the oldest claim my tradition makes about what a human being is. Genesis opens with it: “So God created man in His own image; in the image of God He created him” (Genesis 1:27, NKJV). The Psalmist turns it into wonder: “What is man that You are mindful of him... For You have made him a little lower than the angels, and You have crowned him with glory and honor” (Psalm 8:4-5, NKJV). Crowned. Not central because he is the most capable thing in the room, which he is about to stop being, but crowned by something outside himself, with a dignity that does not rise or fall with his output.
The Vatican, of all institutions, saw the collision coming and answered it directly this year. In Magnifica Humanitas, Leo XIV writes that human dignity “does not depend on a person’s abilities, wealth or position in life,” and then names the exact ideology the age is building: the “particularly insidious” one “that suggests that every person must earn or justify his or her own worth, to the point of attributing greater value to those who are more efficient or effective.” Under that logic, he warns, “persons end up being reduced to a means of achieving results, a resource to be used and exploited.” That is the eschatology of AI stated as a moral error. A world organized around the more perfect thing is a world in which the human being is graded on capability, and the human being is going to lose that grade. The point of the imago Dei is that the grade was never the thing. A vision that decenters the human is not one to trust with the switch over the human’s tools, however sincere its concern for our safety. The concern and the decentering come from the same man.
The King You Chose
Israel once asked for exactly this, and the story is almost too on the nose.
The people came to Samuel and asked him to give them a king “to judge us like all the nations” (1 Samuel 8:5, NKJV). They wanted order. They wanted a strong hand at the top to keep them safe and settle their disputes, the way the nations around them had. It was not an unreasonable request. It was a request for good governance, for someone to hold the switch. And God’s answer to Samuel was not that the request was wrong to feel, but that it was dangerous to grant, and He told Samuel to warn them exactly what the switch-holder does once he has the switch.
“He will take your sons,” Samuel told them, and “He will take a tenth of your sheep. And you will be his servants” (1 Samuel 8:11, 17, NKJV). The warning is a list of takings, because that is what concentrated power does; it takes, and the taking is not a malfunction of the arrangement but the nature of it. Then the line that should hang over this entire debate: “And you will cry out in that day because of your king whom you have chosen for yourselves, and the Lord will not hear you in that day” (1 Samuel 8:18, NKJV). The king whom you have chosen. Not a tyrant who seized the throne. One you asked for, because you were afraid, and wanted to be safe.
This is where the three pieces land together. The first said count the cost before you build. The second said do not withhold what you should scatter. This one says the last thing, the hardest: be careful what king you crown to hold the switch, because the crowning is the one move you do not get to undo. We are frightened, reasonably, by what we have made, and out of that fear we are reaching for a sovereign to hold the dangerous thing for us. Some of the people who built it are reaching right alongside us, for reasons that are part conscience and part interest and impossible to separate. And the warning is not that safety does not matter. It is that the one who ends up holding the switch, whether a company or a state or the strange fusion of the two now forming, will not be a neutral guardian. He will take. He was chosen. And he does not give the switch back.
What Dario wanted, in the end, may be what we all want when we are afraid, which is for someone competent and serious to take the dangerous thing off our hands. The oldest wisdom I know says to look very hard at who that someone is before you hand it over, because the day you cry out about the choice is the day it is already made.
Sources
The June shutdown and conditional redeployment of Fable 5 and Mythos 5 (June 9 release; June 12 export-control directive suspending both models globally; June 30 controls lifted; return with new classifiers, 50% weekly usage caps, credits-only after July 7, and expanded early government access before broad release): Anthropic, “Redeploying Fable 5”, and Anthropic’s announcements that controls were lifted and on the redeployment terms and Glasswing framework. Anthropic’s own facts (dates, availability) are reliable; its framing (that the severity was low and the safeguards extraordinary) is self-interested and should be read as such.
Dario Amodei’s call for mandatory third-party testing and government power to block deployments: “Policy on the AI Exponential” (announcement thread).
David Sacks’s “regulatory capture strategy based on fear-mongering” response: via X. Sacks’s fuller account of the “cartel” / “race condition” thesis and the Biden-era personnel pipeline into Anthropic (the AI Safety Institute “Anthropic basically set up”; officials moving to the company) is from the All-In podcast, “World’s First Trillionaire, Anthropic Fable Banned, The New Oligarchs, Iran Peace Deal” (June 19, 2026): YouTube. Sacks is the White House AI advisor and a committed rival of Anthropic; read his account as such.
Marc Andreessen’s first-person account of the spring-2024 meetings with Biden-administration officials (”don’t do AI startups... a game of two or three big companies working closely with the government... wrap them in a government cocoon,” and the offer to classify the mathematics of AI as the Cold War classified physics): Andreessen interview on Honestly with Bari Weiss, The Free Press. He recounts the same meetings (”the most alarming meetings I’ve ever been in”) and the “become more like your rival or more like yourself” framing, along with the CCP political-officer contrast, on The Joe Rogan Experience (~2:45:40). Andreessen runs a major AI venture fund (a16z) and is an interested party; his account corroborates Sacks’s from the opposite side of the same administration change.
Project Glasswing’s 10,000+ high/critical-severity vulnerabilities found using Anthropic’s most capable model: Anthropic, via X.
Federal case-by-case gating of OpenAI’s GPT-5.6, Altman’s “not our preferred long-term model,” and the “de facto AI regulation” framing plus the open-weight catch-up dynamic (GLM 5.2 at 68.8 vs. Fable 5’s 76.5 on the Artificial Analysis Coding Index): ActionModelAI, via X; Aaron Levie, via X; benchmark gap, via X.
The February 2026 Anthropic–Department of Defense dispute (Anthropic refused Pentagon terms over autonomous-weapons and mass-surveillance use and walked from the contract; the administration banned federal use of Anthropic; OpenAI stepped in; Palantir was the application layer): NBC News; Fortune; Wikipedia, “Anthropic–United States Department of Defense dispute”.
Alex Karp on withholding models from the government and opening them to adversaries, on CNBC (July 1, 2026): interview clip, via X. Karp is an interested party; Palantir sells the application layer, and the interview aired alongside its Nvidia deal.
Duncan Umphrey, writer and philosopher at Palladium, describing Anthropic’s AGI vision as a competing theological eschatology (human beings “no longer center stage... an eschatology of AI”), in a June 2026 interview with MTS: via X. He develops the argument in “The Rival Theologies of Artificial Intelligence” (Palladium, June 2026).
Mustafa Suleyman with Michael Bhaskar, The Coming Wave: Technology, Power, and the Twenty-First Century’s Greatest Dilemma (New York: Crown, 2023): on AI firms as power centers “without parallel” that will “rub against, capture, and reengineer the state,” and on nation-states using the wave to “tighten their grip.”
Henry Kissinger, Eric Schmidt, and Daniel Huttenlocher, The Age of AI and Our Human Future (Little, Brown, 2021): on nationally indispensable network platforms and the leverage of their withdrawal.
Leo XIV, Magnifica Humanitas (2026): human dignity “does not depend on a person’s abilities, wealth or position in life,” and the warning against the ideology that grades persons by efficiency and reduces them to “a means of achieving results.”
Scripture quotations are from the New King James Version: Genesis 1:27; Psalm 8:4-5; 1 Samuel 8:5, 11, 17, 18.
This article was developed using AI writing tools I built to work with my voice, research, and editorial framework. The ideas, arguments, and theological positions are mine. The pipeline that helps me draft, evaluate, and refine them is something I created as part of my work at Nomion AI. I believe in building with AI and being honest about it. If you want to know more about that process, ask me.


While history has seen societies wrestle with new technologies and the impact they will have, the disruption caused by AI is on a portended level beyond the pale. I can think of only one other technology that can compare - the development of nuclear power and "the Bomb." That transformed politics on a global scale and became the defining factor of world affairs since WWII.
AI appears to me to be a similar challenge. It is a technology with the potential to radically alter geopolitics AND the daily lives of billions of people.
So, the issue of "Who holds the switch?" or "Who wears the crown?" is indeed crucial.
That phrase “eschatology of AI” is interesting.
When I stopped by the office of Cross Connection Church earlier this morning to thank you, Miles, for writing this series of articles, I called it in my own mind "The Metaphysics of A.I.". Your phrase is probably better.