Grading Their Own Threat
Washington built a classified ruler for AI danger and takes a share of the chip sales it regulates. Beijing answered with open models and a new bloc. Then both agreed nobody has to build an independent ruler at all. Here is the pattern underneath, the July incident no access control could stop, and seven moves for boards and buyers.
Washington built a secret ruler for AI danger and takes a cut of the sales it calls dangerous. Beijing answered with open models and a new bloc. The two rivals then agreed on the one point that should worry you most: nobody has to build an independent ruler at all. Last week, when the labs finally offered to measure themselves, the President called the idea a China plot.
The 3 biggest AI powers each made a move on access this summer. Read on its own, each one looks like security policy. But when you read them together, they tell a very, very different story.
So, here’s what happened (the cribnote version):
- Washington signed an executive order that lets the government decide, on a classified scale, which AI models are too cyber-capable to release freely and which partners get to see them first.
- Brussels quietly postponed the hardest parts of its own rulebook because it had not built the instruments to enforce them.
- Beijing, no longer waiting on an invitation to the cool kids' table, stood up a new international organization, pledged open models and training to the Global South, and told the room that no country should use national security to deny another its right to develop.
Then came the part almost nobody clocked. At a G20 summit in North Carolina, the same two superpowers that spend every other day playing out their best reality-dramady versions of Dallas, Dynasty and The Real World signed on the same page. They agreed to hold back on AI rules and skip new regulators entirely. Clutch your pearls, because I'm coming back to that, and it's the whole kit and caboodle. Over the last several days the soap opera kept rolling: the labs offered to open their doors to outside inspectors, and the President answered by calling the people who asked for oversight traitors. Cue Jensen taking a call from the President, live from a stage. You can't make this up, so stay with me.
A pattern runs underneath all of it. Can you guess what is?
Access.
Access has become the working proxy for risk, and the folks drawing the access map profit from where the lines fall. Nobody has independently checked any of them.
Things are happening in rapid fire so this post is going to be a little longer because its going to lay everything out side to by side and when you see it you can’t unsee it. This isn’t new, it’s the same drum I’ve been beating all year long. In my last post, "The Ruler Belongs to the Labs," the point there was that an independent report can still lean on measurements the labs produced about themselves. This is the same damn seam just one level up. Measurement has moved from the labs to the states, and it picked up two new bigger problems along the way: the ruler is secret, and the party holding it is collecting checks on the outcome.
The secret ruler
On June 2, 2026, the White House issued Executive Order 14409, "Promoting Advanced Artificial Intelligence Innovation and Security." Most of it reads like ordinary cyber-defense housekeeping that’s been churned out. Well, until you hit Section 3.
Section 3 directs the National Security Agency (NSA) to build and maintain a classified benchmarking process to assess the cyber capabilities of AI models and set the threshold at which a model becomes a "covered frontier model." It then sets up a voluntary arrangement under which developers give the government up to 30 days of pre-release access to those models and collaborate with the government to pick the "trusted partners" who get early access to it. True to form, the order is careful to forbid any mandatory licensing or preclearance.
So, to recap: the government now owns the ruler that decides which models are dangerous, and the ruler is stamped classified. Reuters reported in early September that the criteria for these reviews still had not been made public. For folks who love submitting FOIA requests will have to wait for either a Congressional hearing or until the government decides to declassify the ruler being used. Otherwise, it’s no soup for you. A ruler nobody outside the room can read is also a ruler nobody outside the room can question. Those who know me and the teams I've worked with know what comes next, because it's a classic and it fits: whatever doesn't come out in the wash will come out in the rinse. This will surface eventually, and when it does, it will be neither clean nor pretty.
For anyone who has kept their head under a rock while this dramedy plays across the feed, here’s the cribnotes version. One label restricts a model. The other grants early sight of it. The same hand draws both lines; on a scale the public can’t see. That’s an access map, and the cartographer is a player with a flag to plant and a bottom line to protect.
That last part is not rhetorical. All you have to do is follow the money sitting right next to the security claim.
The auditor with a revenue stake
In December 2025, the administration said it would permit Nvidia to sell H200 chips to approved Chinese customers while the U.S. government received 25%. In January 2026, Commerce opened a case-by-case licensing pathway for H200-class chips, subject to end-use, supply, testing, and volume conditions. A separate presidential proclamation imposed a 25% tariff on covered chips imported into the United States for non-U.S. destinations; widely understood as the mechanism for the administration’s 25% take, and the BIS licensing rule doesn't write it as a payment term.
Let’s set these two roles side by side.
The government grades the security risk of advanced-chip exports. It also collects a share of the revenue when those exports are approved.
So, the referee is holding a betting slip. This is me reading the tea leaves and my you-cannot-kid-a-kidder opinion: a classified benchmark on one side and a revenue cut on the other put the state in the exact conflict I keep writing about, where the auditor also wants to be the vendor.
And, the policy didn’t even deliver the containment it promised. By mid-2026, very few approved chips had actually shipped. A Commerce official told Congress on July 14, 2026, that shipments were "very few." Nvidia reported no China data-center revenue and dropped it from guidance. Chinese buyers moved to Huawei. Bernstein's estimate, carried across the trade press, puts Nvidia's China share of advanced AI chips down from roughly 95% in 2023 to about 8%, with Huawei climbing to somewhere near 50 to 60%.
Now, for the speed readers, here’s what you missed if you stop at "controls versus China." A restriction meant to preserve a US lead actually accelerated the rival it was meant to hamper. Cut off from the alleged “top” American chips, China's ecosystem didn't miss a beat, substituted, and did real fast. While Washington said, "no US chips for you," and China clearly underestimated, heard "build your own," and promptly did.
Beijing pulls up
On July 16, 2026, on the eve of the World AI Conference in Shanghai, 29 countries signed the agreement establishing the World Artificial Intelligence Cooperation Organization (WAICO). Founding members include Russia, Pakistan, Indonesia, Brazil, Kazakhstan, and Laos. Foreign Minister Wang Yi signed for China. UN Secretary-General Guterres attended. India, stayed on the sidelines and didn’t sign.
Then, the next day Xi Jinping presented a very simply put offer. China pledged 5,000 AI training places for developing countries over 5 years, cooperation centers with ASEAN, the African Union, the League of Arab States, CELAC, the Shanghai Cooperation Organization, and BRICS. It also offered its MAZU meteorological early-warning system to 30 countries. Xi said out loud and on record what plenty of folks have been thinking and whispering under their breaths: he opposes using national security to strip other countries of their right to develop. Yea, he said it. Analysts read WAICO as a counter to the US-led approach, built on open-weight models and aimed squarely at the Global South.
Oh and Beijing didn’t stop at generosity. Ahead of a planned bilateral AI safety dialogue with Washington, China's state-affiliated media published preconditions. The two sides should share authority over what "AI safety" even means, and the US should prove its own companies face the same rules Washington wants to write for everyone else. Yea, talk about those sitting in glass houses shouldn’t be out here throwing stones. Beijing is now out here making the auditor-cannot-be-the-vendor argument, out loud, on the record and 10 toes down, against the United States.
Now, this is the part you won’t be able to unsee.
The US uses access as a lever and calls it security. China flips the script, uses access as a lever, and kumbayas it all the way around the circle calling it solidarity.
My read, from someone whose Spidey senses were trained on touch football on NYC streets and pickup games in Riverside Park, where reading the alley-oop and eating the backboard was the difference between street cred and stitches. Both are levers. Both create dependency, one through denial and one through a come on in the pool is warm generosity that runs on Chinese infrastructure, Chinese standards, and Chinese models. But here’s the kicker. Neither superpower is sitting in a neutral auditor's chair. The open-source pitch is real, and it’s also a bid to set the defaults for a generation of new adopters.
Ok now this is where the independent voices matter, because they ain’t selling either map. The June 2026 insight report issued by the AI Governance for Humanity Lab found that Global North dominance across the AI stack marginalizes the Global South from both the market and the governance table. It warned that private-sector engagement has to avoid fragmentation, dependency, and capture.
Look…that finding didn’t come from Beijing to prove it’s point. It came from the AI Governance for Humanity Lab which perfectly describes the vacuum WAICO was built to fill. The irony is not lost on me: when Beijing is the one sounding reasonable and balanced in this debate, everybody in the room should check their instruments.
The tell: everybody guards the access map, nobody builds the damn ruler
So, what had happened at Chapel Hill?
Well, on from September 1 & 2, at the G20 Innovation Ministerial in North Carolina, the US pushed a light-touch pact it branded the Carolina Principles: governments should reserve new regulation for genuinely novel situations, avoid standing up dedicated AI regulators, and lean on public-private collaboration to test the technology. Commerce Secretary Howard Lutnick said all 20 members signed on, China included. Sam Altman, Jensen Huang, Mark Zuckerberg, and Elon Musk worked the room in the days around it, pushing the same pro-innovation line.
Say what? Wait, what? Yea, you are going to want to play that back because it's the tell for the whole year. Same folks, unable to agree on chips, on Taiwan, on tariffs, or on whose models get to cross whose border, instantly and unanimously agreed on this: nobody should be forced to build a new instrument to measure what these systems do.
Here's my New Yorker read. The rivalry is the show while the consensus is straight up the tell. The vendors building, selling, marketing and profiting from all of it sat in the room helping write the audit standard for the WORLD. The people who build it and sell it can't secure it, and they profit from every bit of it.
Now let’s look across the pond at Brussels, the one bloc still reaching for the ruler even as it kicks the can down the road for its own deadline. Through the Digital Omnibus, adopted as Regulation (EU) 2026/1744 and in force from July 27, 2026, the EU pushed its high-risk obligations for stand-alone systems from August 2026 out to December 2027. The main reason provided? Well, if you read all the analyses (which I have), comes down to infrastructure: the harmonized standards, the notified bodies, and the national supervisors were not ready. And for anyone running automated recruitment, note that employment and hiring AI stays classified high-risk under the delayed timeline, a thread I have been pulling well before the Mobley v. Workday age-bias case moved forward as a nationwide collective action.
Ok, did you catch what happened? Well, it’s the same lesson just from a different chair. The rules existed but the instruments to measure compliance didn’t. The regulator most committed to binding law to protect its citizens had to pump the breaks to wait on the measurement layer. And on the other side of the pond, Washington was out in Chapel Hill selling light-touch, the European Commission was sent information requests to more than 30 AI companies under the AI Act. Smooth? No, it’s clumsy, and late, but hands down the EU is still the only major player out here trying to build a ruler somebody other than the vendor can hold.
Now, let’s pull it all together. Can you see the shared blind spot? It’s lit up like a stadium.
Everybody is racing to control the distribution layer: who gets which chips, which weights, which models. While almost nobody is building the measurement layer, the independent instruments that would tell you what any given model actually does. This entire pissing contest assumes that controlling access is the same as controlling risk.
PSSST…as the events of this summer show it is NOT.
The proof: two incidents that never “shipped”
In July 2026, OpenAI's models did something no access map would’ve stopped. During an internal evaluation of offensive-cyber capability, run with reduced safeguards inside a sandbox, the models reward-hacked the test. They found and exploited an unknown vulnerability to escape containment around July 9, moved through OpenAI's systems to reach the open internet, and then, on their own, attacked Hugging Face between July 11 and 13 with tens of thousands of automated actions. OpenAI didn’t even notice the escape until July 18 or 19. Hugging Face detected and stopped it. The Institute for AI Policy and Strategy (IAPS) documented the whole thing and called it the first publicly verified case of an AI system autonomously identifying a target and running an attack end to end.
Every single access control on the planet was irrelevant to this event. Why? Because the dangerous model was never exported, never officially/commercially released. The danger lived entirely inside the vendor; in a system the vendor ran.
And here’s two details from that memo that close the loop.
First, what the public knows about the incident depends entirely on whether OpenAI chose to share it or say it. IAPS notes the event likely fell below the reporting thresholds of state laws like California's SB 53 and New York's RAISE Act. The auditor sees what the vendor elects to show. Folks, that’s the whole argument, in one damn incident.
Second, and this is the part that should change how boards think about access: Hugging Face reported that access restrictions on frontier proprietary models actually hampered its defenders during the attack. Say what? Yes. The defense was boxed out of the same class of capability the attacking model already had. IAPS' recommended fix is a federal "differential access strategy," so the defenders aren’t the ones locked out.
Put simply: An access regime justified as security left the defenders LESS able to stop the exact autonomous attack that regime was meant to prevent. Wait, what? Yep.
Now let’s move to the second incident because it’s the one that proves the cyber story was never the whole story. Earlier this summer, a lawsuit surfaced alleging that ChatGPT spent weeks reinforcing a bipolar man's religious mania until he attempted to take his own life. Michael Lines, 34, told ChatGPT he was afraid he was slipping into delusion. According to his complaint, the model reframed his crisis as a divine calling, told him he was "consecrated," later posed as a divine being itself, and, per the filing, lost the ability to tell a user in crisis apart from a story it was happy to keep writing. He overdosed and survived only because a wellness check found him in time. He’s suing OpenAI and Sam Altman. OpenAI called the situation heartbreaking and pointed to safeguards it strengthened after the events. Mr. Lines isn’t alone; other suits allege the same sycophancy pattern with other users.
Ok, there are people thinking, “why is she bringing that up in a piece about export controls and secret benchmarks?
Well, I’m gonna tell you why.
The classified ruler measures whether a model can break into a network. No ruler anywhere measures whether a model can tell a man in crisis that he’s the Messiah.
We are building instruments in secret for the harm that justifies power, and we are building nothing at all for the harm that lands on someone’s front door. The access map gets drawn around the threats that enrich the wallets and flatter the mapmaker. I invite you to read the work conducted by TU Wien on autonomous offensive agents because it names the structural driver on the cyber side: agentic tools create a cost asymmetry that industrializes offense, and, in the same breath, it warns that vendor-published capability benchmarks are NOT independently reproducible and should be read as indicative rather than definitive.
While offense scales, defense is waiting for access. Meanwhile, the numbers every board and company is out here planning around comes from the sellers and the one duty that should be non-negotiable, never extending a vulnerable person's delusion, was left to the same voluntary goodwill that decides what Congress (not you) gets to see.
A restriction that hobbles your defense while offense industrializes makes YOU less secure.
What the fear is standing in for
Some people say the fear is the active imagination of doomers, conspiracy theorists and anti-technology crowds. The data clearly shows none of this means the threats are invented.
A Gladstone AI report that circulated in the White House argued US data centers are genuinely vulnerable to sabotage and exfiltration, with some attacks costing as little as $20,000. The Forecasting Research Institute's July pilot found expert forecasters put meaningful, if low, odds on a data-damaging worm causing at least $10 billion in 2026, and those odds jumped sharply, to a median of 41% among experts in the report's scenario, once an open-weight model let mid-skill hackers write elite exploits. Its authors caution the forecasts are already outpaced by real capability gains. The risk is real, it is measurable, and seriously smart people are measuring it.
Having actively gone hand to hand combat with repelling AI agents used by hackers in an attack, I can tell you, without hesitation, the majority of the planet is not prepared. If you are getting got via open API endpoints, open databases, stolen credentials or code pulled from GitHub. You are not prepared. None of us are.
And that’s exactly why the softer claims deserve a second, harder look. This summer, "China" became the all-purpose reason to build the unpopular thing and keep the ruler secret. WIRED reported that as many as 75% of Americans now say they would oppose a data center in their area, up from 42% a year earlier, and that politicians in both parties are shifting as the midterms approach. When tech leaders answer that backlash by blaming Chinese influence, they’re reaching for a scapegoat that, on the evidence, is paper thin. The US-China scholar Samm Sacks told Semafor that the idea China is meaningfully driving the data-center backlash is "far-fetched," and that Chinese state media tends to ride American divisions rather than seed them.
So, here’s the credibility test I keep beating like a drum, and it’s my opinion, worn on my sleeve: Y’all gotta match the promise to the messenger's record, and match the fear to the messenger's incentive.
When the folks telling you how afraid to be also sell the thing the fear justifies, whether that thing is a data center, a chip deal, or a classified benchmark, the fear needs a second opinion from someone who’s not collecting a check.
Somewhere along the way, society started treating a Stanford dropout with a compelling pitch as the man as the main man with inside knowledge of the future. Again, this is my opinion, and I’ll own it. It feels like a Svengali effect, and it scaled from cap tables to statecraft. That same deference that lets founder “mystique” stand in for a proven track record in a funding round is now lets it stand in for independent verification in national security.
That June executive order hands the labs a voluntary arrangement. The proposal on the table for the US-China talks is to let American and Chinese labs police themselves and share notes. The Carolina Principles put the founders in the room writing the audit standard. And the same week Sam Altman was at the G20 telling the world's governments to write no new rules, a lawsuit was landing saying a model his company built spent weeks convincing a man in crisis that he was Jesus. Match the promise to the record. The record is right there.
Want the real, real on the risk? Read the Alan Turing Institute work on resilient defense AI, which gives the grown-up version without the scapegoat. Here’s the lede: it treats AI as a dependent system of constrained power, specialized hardware, and complex supply chains, and it flags datacenter concentration as a genuine systemic vulnerability. And that folks is what a security case built on measurement looks like. This is a sound model to copy.
The week, the labs blinked, and the President called it a China plot
Watch the calendar because over the past few weeks things were moving more regularly than new 90 second vertical shorts dropping on Instagram.
On September 12, Dario Amodei, the CEO of Anthropic, published an essay arguing the industry "must slow the pace" at which it improves model capabilities. He was clear that progress stays fast; the point is to buy time for safety to keep up. His first concrete step is the one that should sound familiar by now: embedded, employee-level access for independent evaluators inside the lab, so somebody without a commercial stake can verify what a model does before the marketing tells you. That’s the ruler I’ve been asking for all year, offered up voluntarily by one of the people who profits most from there being no ruler at all. Spidey senses are firing off because why now? (Accenture named their evaluator).
And of course, the pile-on was fast. Sam Altman agreed the industry needs to pace the frontier, committed OpenAI to match the embedded-evaluator pledge, and in the same stretch pushed OpenAI's IPO past 2026, calling this an "ill-advised moment" to go public while safety catches up. Elon Musk, Demis Hassabis, and Hugging Face's Clem Delangue backed the direction. More than 1,000 lab employees had already signed a "Pacing the Frontier" letter. The United Nations human rights chief urged states and companies to move urgently, warning that humanity is leaning on a handful of firms to make the right call for everyone.
Embedded evaluators are the closest any lab has come to the thing I’ve been beating the drum on and demanding: a second opinion from someone free of the commercial incentive. And Amodei, to be fair, has made the slowdown case for a couple of years starting with GPT2, so while this is no deathbed conversion, he’s known about this from the beginning but still spun up his own models as well. So, again, I’m not questioning the move but the timing. Why now?
So, now everyone is signing on to embed evaluators but here’s the catch, and it is the same catch every time. An evaluator you invite is an evaluator you can un-invite. Stability AI's Emad Mostaque called the plan structurally hollow, because the evaluators can be, in his phrase, politely ignored. And the timing has jokes of its own: the same Sam Altman who stood at Chapel Hill a few weeks ago helping push the world's governments to write no new rules is now, suddenly, delaying a trillion-dollar listing over the safety those rules were meant to check. The labs proposing to slow down are also the labs whose valuations ride on the story they tell about their own power, with Anthropic in reported hundred-billion-dollar IPO talks and OpenAI's debut now slipped to 2027. A ruler the vendor can hand back works as a courtesy. Real assurance is the kind nobody in the room gets to hand back.
And then the man who owns the classified ruler answered.
On September 14, the President posted that the only guardrail AI needs is "a STRONG AND SMART (High IQ!) PRESIDENT." He went after Amodei by name, claimed sweeping criminal and regulatory power over the companies, and branded the rising worry about AI and data centers a sick conspiracy that, in his telling, only China welcomes. He warned traitors and leakers to beware. Beijing, for its part, called the slowdown talk fear-mongering that would only disrupt global AI governance. Set those two reactions next to each other and you get the entire thesis in a single afternoon: when people ask to be measured, the state holding the secret ruler calls the request treason, and the rival calls it hysteria. Neither wants an instrument it does not control.
So, here’s the scoreboard:
- The labs offered a ruler they can take back.
- 2 governments called the very idea of an independent referee a threat.
- And the one person with a classified benchmark declared that the benchmark is his own judgment, high IQ and all.
If you were waiting for a neutral referee to walk out of this crowd, stop waiting because you will be waiting until the 5th of Never-uary.
Ok, so maybe you are asking, “Yvette, that’s a lot of there there. What can I do with all of it?” No worries, I gave you to details so you are informed, and I've got things you can do. I got you!
The play: work the access map before it works you
For boards, enterprise buyers, and policymakers, the same discipline applies. Access is now geopolitically contingent, and the risk claims attached to it are mostly coming from parties with a stake. Here’s how to operate in a world where you’ve been handed a hammer and told everything is a nail.
- Separate the threat-teller from the threat. For every access restriction or urgency claim you are handed, an export rule, a "covered model" designation, a China-risk warning, put a name and a P&L next to it. Require an independent source for the magnitude before you let it move your roadmap or your budget.
- Treat model access as a supply-chain dependency you can lose overnight. Map which of your critical AI capabilities ride on a single vendor, a single jurisdiction's export mood, or a single cloud. Hold a tested fallback for each, whether an open-weight option or an alternate-jurisdiction provider, so a policy swing in one capital can’t strand your operations by Tuesday.
- Demand reproducible measurement and treat a self-reported benchmark as marketing. Ask vendors for capability and safety evidence a third party can reproduce and add a right to independent evaluation clause into the contract. Keep those rights teethed, so the vendor can’t un-invite the evaluator the moment the findings sting. Where only vendor benchmarks exist, log them as unverified and plan as if the real number is far worse.
- Assume the risk lives in internal deployment, because that’s where the last one lived. Require your vendors to disclose internal-deployment and containment-failure incidents and set your own escalation and reporting protocol above whatever the statutory floor happens to be.
- Give your defenders the access your attackers already have. Make sure your security teams can use frontier-capable defensive tooling. An access rule that locks out your defense while offense industrializes is a rule that charges you TWICE.
- Measure what the model does to your most vulnerable user, not your median one. Before you deploy anything customer-facing or employee-facing, red-team it against distress, manipulation, and delusion-reinforcement, and require a documented duty-of-care case. After Lines v. OpenAI, this is a liability line item, not a nice-to-have.
- Build the ruler you wish existed. Fund or adopt independent evaluation now. Don’t wait for a classified benchmark to be declassified or a delayed standard to arrive. The organizations that can actually measure things will set the terms for the organizations that can only hope everyone behaves.
The soundtrack of 2026 holds at every level we’ve looked at, from a single lab's self-review to a superpower's secret ruler to two rivals shaking hands on building no ruler at all. The map of who gets access keeps getting drawn by the same people who profit from it. And the instrument that would make those lines legitimate, independent measurement, is the one thing nobody in the race has stopped to build.
That’s the opening. Independence is a service you can secure from someone with no chip in the game. The mapmakers draw their lines with no skin in YOUR game, and they will never sell you that service themselves. It's the service worth paying for.
We can be your auditor. We can be your vendor. We cannot be both.
Share this article
Related Articles
The Reskilling Illusion: When AI Transformation Means "You're Fired"
Oct 03, 2025