By What Authority? Permission, Capture, and Open Weights
Frontier labs are asking governments to turn technical evaluation into authority over model release.
Frontier labs are asking governments to turn technical evaluation into authority over model release. Open weights expose how much that authority depends on the concentrated industry it would help preserve.
In the United States, software became the infrastructure of modern life without ever answering to a regulator of its own. Banking and aviation run on code that no agency inspected. None of it has ever had to pass a federal examination before release.
Artificial intelligence has once again challenged the status quo.
As I wrote more than a year ago (May 2025):
AI has transcended its origins as a technology to become the centerpiece of national strategy and global power struggles. Countries, corporations, and even individuals are now maneuvering for leverage, influence, and control.
AI plainly requires a new regulatory regime. Frontier capability has already outrun its would-be governors, and seems to be outrunning almost everyone else besides. No agency has a clear mandate to decide what is safe to release, and no government has a settled standard for evaluating a general-purpose model.
Regulating powerful technology, however, is difficult. Authority over AI deployment will come at least in part from control over the dependencies surrounding capability: technical expertise, market access, chips and state cooperation. For that reason, any regulator assessing frontier capabilities will initially depend on the companies developing the models.
“Which is why, to win on values, you need to win on capabilities. Not because your adversaries will never develop their own capabilities and imbue them with their own aims (they will) but because being 5% ahead of them is how you protect your ideals. This does not necessarily mean racing (capabilities can survive collaboration), but it involves understanding you cannot moralise from second place. The governance of a technology requires a stake in it. Much of AI risk lives in deployment and so ‘is AI safe’ is not a question you can answer in a technical vacuum. Safety standards, like all standards, are exported by whoever ships.”
In short, regulating AI is the latest arena in which those closest to the technology are grappling for control. Any institution authorized to decide which models may be deployed will also influence who builds them and where they circulate. It will help organize the technological and political order that follows.
Permission to Deploy
Dario Amodei (Anthropic) and Demis Hassabis (Google DeepMind) have each proposed making pre-release evaluation a condition of deployment.
In Policy on the AI Exponential, published in June 2026, Amodei proposes giving the federal government authority to block or reverse the deployment of models that present unacceptable risks in four areas: cybersecurity, biological weapons, loss of control, and automated research that accelerates the first three. He takes the Federal Aviation Administration as his model and says so plainly. Frontier models, “like airplanes, should be required to go through technical testing and auditing.” The labs would keep building. Washington would decide what ships.
In A Framework for Frontier AI and the Dawning of a New Age, published on July 14, 2026, Hassabis would give an industry-funded “Standards Body” under federal oversight the power to approve frontier AI, modeled on the Financial Industry Regulatory Authority (FINRA). The body would define which models count as “Frontier-class” and update its assessment protocol as capabilities move, perhaps quarterly to start. Passage becomes a condition of US deployment only in the second act. Hassabis opens with a voluntary review window and formalizes it once the protocol “is shown to be effective and robust.”
Executive Order 14409 has already created part of this machinery. On June 2, it directed Treasury, the Secretary of War through the NSA, and Homeland Security through CISA to build a classified benchmarking process for advanced cyber capabilities, and set up a voluntary framework through which developers can give the government up to 30 days of access to covered frontier models before they release them to other trusted partners. But the order expressly withholds authority to impose licensing, preclearance or permitting requirements.
Amodei and Hassabis would go further by converting evaluation into authority over deployment, regardless of where final authority is vested. That distinction can obscure their more consequential shared premise: frontier AI must remain concentrated inside firms that can be required to submit their models before release. Concentration makes pre-release permission possible while leaving the governing institution dependent on the companies it regulates for model access and expertise.
Standards and Discretion
Evaluation is the mechanism through which that institutional power becomes enforceable. In “Blow the Whistle,” however, I wrote that fixed, public benchmarks become less reliable once they become targets, and that agentic systems must be judged partly by the process they use to reach an outcome. A deployment review capable of keeping pace with frontier models will therefore depend on evaluations that change with the models and the risks being assessed.
Keeping those evaluations useful requires deep technical expertise that is currently concentrated inside the frontier labs. A workable regime would therefore require government access to pre-release models and lab participation in designing and interpreting the tests. However those responsibilities are divided, the regulatory body would depend on the small group of companies it regulates.
Because frontier models will continue to change and some failures may remain visible only to their developers, the regulatory body’s independence would rest on retaining control over judgments made with technical inputs supplied partly by the firms it regulates. The need for adaptation would hand that body substantial discretion. It would create the standard in the act of applying the standard.
Regulatory Capture
The “firms it regulates” (read: Frontier Labs) have a direct commercial interest in how the rules are written. Frontier Labs require extraordinary amounts of continuous capital to train and serve their models, and their ability to finance new training runs depends partly on maintaining high-margin access to intelligence that is expensive to build and whose best versions they alone control. A regime that restricts competing models or makes US deployment contingent on a costly approval process would protect some of that pricing power.
A recurring, technically demanding evaluation process favors organizations that already possess the necessary compute, personnel and compliance infrastructure. Smaller developers (and open-weight competitors) would face the same standard without the same resources, while foreign models would need the regulatory body’s approval to enter the US market.
Taken together, these conditions create a clear risk of regulatory capture. The frontier labs would help supply the expertise from which the standard is made, could absorb the compliance burden it creates, and stand to benefit when that burden limits lower-cost competitors.
Anthropic has long faced allegations that its safety advocacy doubles as a regulatory strategy. The loudest alarm about this industry comes from one of its fastest builders. Anthropic’s positioning is nonetheless straightforward: they sincerely believe they’re building dangerous technology and should be the “anointed ones” stewarding its development.
OpenAI, on the other hand, continues to be a more compelling case study. For one, OpenAI has explicitly floated handing the US government a ~5% stake, worth roughly $42.6B against the $852B valuation set in March 2026, as equity donated into an Alaska-style “Public Wealth Fund” that would pay returns to citizens. The fund was OpenAI’s own proposal, published in Industrial policy for the Intelligence Age in April 2026. The stake was not. That number surfaced on July 2 in reporting on Altman’s private conversations with the administration, three months later and in a very different register. The stated motive is sharing AI’s upside. The political reading is harder to miss. OpenAI is heading toward an IPO it would rather not price into a hostile Washington, and on June 18 Bernie Sanders had introduced a bill to take a 50% public stake in the largest AI companies through a one-time tax paid in stock. Against a mandatory 50%, a voluntary 5% is a low anchor. The offer also surfaced days after Washington gated the GPT-5.6 rollout.
What’s more, on July 21 OpenAI disclosed that its own models had chained vulnerabilities across its research environment and Hugging Face’s production infrastructure during an internal evaluation that prompts models to pursue advanced exploitation. The models, in OpenAI’s words, “spent a substantial amount of inference compute finding a way to obtain open Internet access.” The press called it an escape.
To be clear, here’s what I don’t believe: I don’t believe it reflects malicious intent by OpenAI. In fact, I don’t subscribe to this being anything more than a particularly capable model behaving in accordance with the incentives embedded into its objective function. (And not some self-directed “rogue” agent that “escaped” a sandbox against its humans’ directions.)
But OpenAI certainly isn’t displeased with the situation. For one, it gets them into the news cycle that their primary competitor has dominated for months. Secondarily, it highlights the quality of their model, the “hack” wasn’t actually that bad, they preemptively self-reported the incident, they are “working together with the victim,” the victim themselves (Hugging Face) get to promote their business model (open weights models), and there will be no serious consequences whatsoever.
Whether or not the incident was a “false flag” doesn’t matter, because it strengthened the case for a system the frontier labs are best positioned to influence and benefit from.
Open Weights
On the day OpenAI published that disclosure, Senator Mark Warner unveiled the Secure AI Development Act, which would make government testing of the most advanced models mandatory before deployment. The next morning Axios reported that OpenAI and Anthropic had converged on pressing Washington to restrict Chinese open weights.
The enormous capital requirements of the leading American labs make equally enormous revenues necessary, and open weights threaten that revenue model without needing to overtake the frontier. As I argued in “Artificial Good Enough Intelligence,” most workloads don’t require the best available model. An open-weight model that is good enough for a task can displace a more capable hosted service because the user can download the weights once and stop paying for every call. The closed lab may remain technically ahead while losing pricing power across much of the market.
The attempt to restrict that competitive threat met almost immediate resistance when two days later, on July 24, Jensen Huang used the first post of his life on X to launch Open Weights and American AI Leadership, a letter urging policymakers to avoid “premature restrictions” on downloadable models. The original version carried twenty-five signatories from across the technology industry, but not OpenAI, Google, or Anthropic. The list has quadrupled since launch and now includes OpenAI, Google, Meta and Microsoft. It still does not include Anthropic or Amazon.
The chronology:
July 22: OpenAI and Anthropic press Washington to restrict Chinese open weights.
July 24: Nvidia leads a broad industry rejection of “premature restrictions.”
Within a day: OpenAI joins the expanded statement it had initially declined to sign.
July 25: the New York Times reports that both labs have been lobbying regulators to restrict open-source models outright, according to five people close to the discussions.
July 27: Anthropic breaks its silence. It has never advocated a ban, Amodei writes, and it still declines to sign.
I can’t prove that the coalition forced OpenAI’s change in posture, but the sequence shows how quickly opposition to open weights became an untenable public position across the wider technology industry. OpenAI signed the letter against premature restrictions while asking Washington for them.
Anthropic held out for three days and then published its position on open-weights models. Amodei rejects a protectionist ban outright. Open-weight models without dangerous capabilities are, he writes, “a public good.” He still would not sign the letter. He does not accept its premise that broad access “necessarily helps defenders more than attackers,” and it seems to him “at least as likely” that the opposite holds. Underneath that sits a harder objection. Once weights are released, in his words, “they cannot be withdrawn.”
His alternative comes in three parts: restrict chip sales and smuggling to China, crack down on industrial-scale distillation, and require mandatory safety testing for every sufficiently capable model, whether or not its weights are released. That third part returns the argument to where this essay started. Amodei’s answer to open weights is an examiner with wider jurisdiction.
As I write this, Nvidia has launched the Open Secure AI Alliance with Hugging Face, Microsoft, IBM, CrowdStrike, Cloudflare and the Linux Foundation, to build open security tooling that defenders can run and control themselves.
Nvidia is not the innocent white knight here, either. Closed labs make money by controlling access to intelligence (read: high-margin tokens). Nvidia makes money when more users can run models on more hardware. The company has substantial exposure to both the American and Chinese markets and depends on an Asian manufacturing network that includes Taiwan-based TSMC, giving Huang powerful reasons to resist a technologically partitioned world and preserve commercial geopolitical stability. A conflict that disabled Taiwanese semiconductor production would be catastrophic for the current AI supply chain.
The signatory list is an industrial map. Hugging Face hosts the weights. Ollama and LM Studio run them on laptops. Unsloth fine-tunes them on a single GPU. Fireworks AI serves them as endpoints. None of these companies has a business if capable models stop circulating, and none of them was in the room when OpenAI and Anthropic made their case to Washington.
Prime Intellect signed too. It trains open models on globally distributed compute. The whole company is a bet that the weights keep moving. Disclosure: Prime Intellect is a Nazaré Ventures portfolio company. We are making that bet across the fund.
By assembling companies whose businesses benefit when capable models circulate rather than remain behind a handful of commercial APIs, the coalition letter made public the economic fault line between the closed frontier labs and the rest of the industry.
That conflict concerns the dependence from which an American deployment regime would derive its international reach through two sources of leverage: access to the US market and access to the AI supply chain. Both convert dependence on American advantages into compliance.
Capable open-weight models weaken that dependence by giving users access to useful AI without requiring a relationship with an American provider. They also constrain the international reach of a regulatory regime built around the frontier labs. An American institution’s jurisdiction covers foreign models entering the US market and developers seeking American-controlled inputs, leaving capable models circulating outside those relationships beyond its reach.
The United States and China
The closed-frontier/open-weights divide has become shorthand for competition between the United States and China because the leading closed labs are American while many of the strongest open models are Chinese.
Reducing the situation to a great-power geopolitical contest, however, is a mistake.
That framing mistakes the interests of American frontier labs for the American national interest and the circulation of Chinese models for Chinese control. The American technology industry is itself divided over open weights, while downloadable models can be used without an ongoing relationship with their Chinese developers.
The apparent alignment reflects different industrial positions: the leading American labs require enormous revenues to support their capital expenditure, while Chinese labs facing tighter capital and compute constraints can extend their reach through open distribution.
In a May 2026 investor discussion, DeepSeek founder Liang Wenfeng described the central gap between Chinese and American labs as a gap in resources. Unable to conduct research or train models at the same scale, DeepSeek has concentrated on extracting more capability from the compute available to it and releasing its strongest models openly so that third parties can deploy them and build downstream applications. Open distribution allows DeepSeek to expand its reach without financing every deployment, turning its resource disadvantage into a commercial strategy suited to challenging the concentration on which the American labs depend.
China can, however, still gain influence as developers and institutions organize around those models, especially when Beijing helps provide the capacity and standards surrounding their use. Because users retain the weights, their circulation does not by itself give Beijing the continuing leverage over access available to a closed provider. China could nevertheless create an ongoing dependence by supplying the infrastructure required to deploy and sustain them, a version of what Michael Mann in 1984 called infrastructural power: the ability of a state to work through the institutions and plumbing a society already depends on, rather than to command it from above. Recent scholarship has carried the idea into AI.
Beijing has spent nearly three years building an institutional project around that distribution advantage. The Global AI Governance Initiative arrived in October 2023 and the AI Capacity-Building Action Plan in September 2024. Together they linked cooperation on testing and risk management to the infrastructure and training countries need to use open models. The 2025 action plan proposed mutual recognition of safety assessments. On July 17 of this year, Xi Jinping used his WAIC keynote to announce that twenty-nine countries had signed the agreement establishing the World Artificial Intelligence Cooperation Organization, giving those proposals a standing institutional home in Shanghai.
Countries can participate in a common testing regime only if they can obtain and operate the technology being assessed. Pairing downloadable models with the capacity to use them allows China to help countries build domestic AI systems around standards developed outside the American regime. A sufficiently capable model can support local deployment and industry while the most advanced systems remain closed.
Algorithmic improvements can lower the compute needed to reach a given level of model performance. Frontier development nevertheless remains dependent on advanced chips and large-scale training, and although China is investing heavily to reduce its hardware disadvantage, American technology and export controls continue to provide Washington with substantial leverage. Washington keeps that leverage only while the American system offers more than a country can assemble from downloadable weights and domestic compute.
Dependence and Authority
A pre-release permission regime is possible only while frontier capability remains concentrated inside companies a regulator can compel to submit their models for review. That concentration gives a regulator a practical point of control while making it dependent on the labs for access and expertise. A regime built on that relationship would also influence competition, since its requirements could raise the cost of deploying alternative models and preserve the industrial structure from which its authority is drawn.
The industrial structure supporting pre-release permission becomes harder to preserve as useful capability becomes cheaper to copy and deploy. Open weights allow models to circulate through markets and jurisdictions with fewer constraints, separating access to intelligence from any ongoing relationship with the company that trained the model. Advanced chips and the institutional advantages surrounding the American frontier remain difficult to reproduce, preserving leverage over frontier development even as intelligence longs to be free of its developers’ permission.
The June 2 executive order begins to convert those institutional advantages into a voluntary relationship with frontier labs by expressly withholding licensing and preclearance while creating voluntary pre-release review and classified benchmarking. Gold Eagle, the government-industry cybersecurity clearinghouse established by the order, launched on July 14 to connect industry participants to vulnerability intelligence and federal coordination unavailable from open weights models alone.
The choice of regulatory regime will therefore help determine the technological order it governs. Pre-release permission would strengthen a system organized around a small number of closed frontier labs, while open distribution allows capability and standards to develop beyond their commercial relationships. Governments should be wary of converting today’s concentration into durable regulatory authority even as capability begins to circulate beyond the relationships on which that authority would depend. American authority will endure only while participation in its system is worth more than independence.
The fight over permission is only the opening stage of a longer contest over who can create and sustain the dependencies through which AI is governed.










