Comment by vhantz
1 month ago
Schrödinger's China at once is an evil entity looking to use AI for their own nefarious purposes yet also willing to cooperate with their main competitor to prevent other actors (who??) from achieving similar goals (all while under a chip embargo too!!)
The reality is much less confusing: Anthropic CEO does not wish for models with similar (or greater) capabilities compared to his own closed and overpriced ones to be widely released. Simply because that will affect Anthropic's bottom-line.
Anthropic and all other "model" companies have nothing making them special beyond privileged access to chips so obviously they want to restrict what models are out there and more importantly who can produce new ones. Without these restrictions, it's only a matter of time before the multi-hundred billions valuations simply evaporate while they are still holding the bag.
Also everything hes saying about China (and other actors) many outside the USA would say about the USA.
The solution of a global arms race of state vs state with integrated statist corporations as the best outcome for end users sure is a choice though
He's also completely missed what many of us see as the primary the issue, HF was attacked by a US frontier model.
HF could not be helped by US frontier models because of the "safety" features they have.
HF had to use an open model from china.
Anthropic wants to add those "safety" features to open models - especially from china.
End result would be HF hack would have continued atleast until the Monday that OpenAI engineers finally walked back into work.
I'm very confident that it was staged and coordinated. This propaganda started because they cannot evolve their models further. See Fable and Sol, they are lame. They seem incredible at first but the more you use you can see the trickery. It is a matter of time for someone to prove they are marginally better only because they inject more information to the harness at server side.
9 replies →
I case you're wondering, HF = Hugging Face
18 replies →
Worth checking, elsewhere in this thread someone points out glm only assessed the damage after the fact, it didn't stop the attack, and Hf apprently never sought access to a trusted defender program with a closed model either the open model saved them farming might not hold up.
1 reply →
I think the fair nuance here is, an administration which used Executive Orders to force guardrails, meaning US companies must retain them, even if they might want to drop them now.
And on top of that, with low/no guardrails, people call you a child pornographer(grok), so the public is also against it. Yet mysteriously few complain about Chinese open models being child pornographers.
So even if your goal isn't ethical, but just fiscal, it's reasonable to say there are two standards. And to complaint in some way.
I don't think banning is going to work, that's just silly. And over the next few years, everyone and their dog will have local GPU compute to train locally. People have home labs, the bar isn't that high, and eventually large text datasets will escape from Anthropic and other companies, allowing for comparable training.
It's a genie that's not going back in the bottle, the bottle is smashed.
The only reasonable outcome would be section 230 style carveouts so that there is zero liability for anything a model does.
Because having guardrails on corporate models barely months ahead of open ones, which will never be restricted, is entirely pointless.
14 replies →
All my adult life, China has given me cheap material goods. Whatever they do in their country is their own problem. They’ve never interfered in my politics or started any wars
> They’ve never interfered in my politics or started any wars
But they have. I dont know what specific country you are referring to but China has interfered with US elections as well as Canada, Taiwan, and Australia in addition to many many others.
They’ve annexed Tibet (1950), fought India (1962) and Vietnam (1979) among others and more recently in 2020 a deadly skirmish with India. They’ve generally shifted their focus to cyber military actions but you’d have to be pretty naive they won’t start to exercise military control over Taiwan when/if they get a chance.
119 replies →
> Whatever they do in their country is their own problem.
Idk to me it feels like human compassion and ethics dictates that you at least have to care a bit even about the things in other countries. Otherwise all sorts of horrible domestic policies would be justifiable.
1 reply →
That's a very selfish way to think of it. Whatever they do in their country does not stay in their country because China is becoming a superpower so you should expect it (as it's normal) to interfere and affect policy abroad.
For example Lithuania has been punished for letting Taiwan opening an embassy (in Lithuania). So China cares what other countries do in their country. Without EU support Lithuania could have faced very harsh consequences. That's just an example. Another example is the "secret police" stations undeclared overseas police stations operated by China in various countries (i.e. U.S for example). China gave you cheap material goods because that was its business but you have to keep in mind it's an authoritarian, communist regime. It carries an extra risk on top of the potential economic coercion if you give it too power. At least you know that U.S is only after the money and does not want to turn your country in a communist "utopia".
That being said this does not mean we should ban Chinese AI models because China didn't cross any red lines(yet) compared with Russia for example.
2 replies →
For you personally no, but there's plenty of scandals of politicians being influenced by the Chinese, case in point in my own country: https://www.ft.com/content/601df41f-8393-46ad-9f74-fe64f8ea1...
Don't be naive or I might even think you're working for the Chinese :-)
But they're happily selling drone parts to Russians dropping bombs on civilians (or "whatever").
8 replies →
I wish I could be this blissfully naive.
China is becoming an intellectual powerhouse in addition to a manufacturing powerhouse and runs huge spyware and propaganda campaigns.
Read up about T95, MBOX, TVBOX, or other Android TV Boxes advertised as generic TV streaming devices advertised as "unlocked" or capable of accessing free content. They're loaded with spyware/malware, typically BADBOX. Some of them will record audio and record your network traffic and send it to China.
I'm also convinced that the anti-education thread winding its way through US culture is being amplified by China. They likely didn't start it, as it's been growing for decades, but China will happily keep it going.
What country do you live in? Nevermind it doesn’t matter because literally every country has had their politics interfered with.
I mean them selling the cheap material goods is politics, and they use that a lot to threaten other countries. They constantly bully neighbors and assert claims on foreign terriroty. They might not be the comic book villians people are making them out to be but your take is just ignorant
2 replies →
Oh i bet they have not directly interfered with your politics, but they do interfer a lots in various things. More than any other country on this planet? I don't know. China is big. Really really big.
> They’ve never interfered in my politics or started any wars
They actively back russia and deliver them weapons and support them with their attempted Genocide in Ukraine. They also actively threaten Taiwan.
Not to mention them claiming almost the entire South China Sea even though this being against international law and threatening smaller nations into submitting to them
I personally think it’s bad when countries commit genocide https://en.wikipedia.org/wiki/Persecution_of_Uyghurs_in_Chin...
Do you remember covid and where it come from?
17 replies →
Lol: https://en.wikipedia.org/wiki/Wolf_warrior_diplomacy
They have their own genocide in western china
2 replies →
We don’t have to guess. Here is a recent survey:
People in Many Countries Now View China More Positively Than the U.S.
https://www.pewresearch.org/global/2026/07/15/people-in-many...
> Also everything hes saying about China (and other actors) many outside the USA would say about the USA.
yes he is writing it as usa citizen running it a us company.
I dont see how "usa is also.." is relevant here.
Are you saying the USA is somehow as repressive as china?
As someone who has never visited China or the US; yes. Why? Media. School shootings, ICE, crazy president… What do I see from China? Impressive multi-million cities… and true to be told, not much.
China had a worse reputation, but not anymore since Trump leads the US.
Im not saying that the above is objective, tho
2 replies →
Probably more.
Yes, only if measured by their own people.
Trump deports, half of the USA people screamed; Xin builds reeducation camps, most Chinese people are cool.
More repressive, by real statistics.
>Also everything hes saying about China (and other actors) many outside the USA would say about the USA.
Yes, I for sure trust the open models from China, more than anything coming out of the USA at the moment.
Its not just the USA's support for genocidal regimes, nor its heinously illegal wars and atrocious 21st century human rights record. Its also the Snowden revelations and the treatment of Julian Assange.
Slowly, surely, the world is building a firewall against the USA's imperialist actions - not just its motives. That AI is a key building block of that machination is of course, highly exciting.
There are many in Europe who feel the same. The tide is very definitely turning.
His Concern 1 was especially painful to read. It reminds me of Red Fever rhetorics from McCarthy era. He casually mentions CCP and People’s Liberation Army (dogwhistles?) as the most fearful enemy. But he didn’t compare CCP policies to GOP or Trump administration (apple to apple comparison). He doesn’t frame it as Anthropic vs Moonshot competition either. He deliberately frames it as the US vs the Communists war.
He portrays the biggest ever threat of AI as the Chinese Military using the models in their drones. He already sells his models to military customers, US and potentially allies, and they are actively used in the field.
So no objective argumentation here. Just Nationalist political rhetorics and FUD. He’s allowed to do that and he will have an audience. But he won’t be taken seriously outside the US. He appears blindsided.
Why is it relevant what those outside would say about the US? Or what those outside of any country would say about any country. The job of a country is to do what is best for it. It's better for the US to not help China develop AI that surpasses its own capabilities. It's better for China to try anyway. There are many countries inventing nothing with loud opinions. Those opinions are completely irrelevant to China or the US.
> The job of a country is to do what is best for it.
Countries aren't defined like corporations in the US. Why would countries have funds to help places like Haiti otherwise?
Lots of different reasons for countries to do all sorts of things? Why would France have armed the US during their independence movement? Why is the rest of the world supporting Ukraine during this war started by Russia?
12 replies →
Why does it feel like you think you're talking to only people in the US?
There's plenty of people on this forum that aren't American. Including some former allies whose sovereignty has been aggressively threatened. And some of those people are Anthropic customers.
Even more so, many of us are in countries that would be well within the blast radius of fallout should the US try to "ban" open weight models or make moves to limit "US" models (often developed on research or work by non-Americans too, but that's another topic) only to those blessed by the US gov't.
That's why it matters?
1 reply →
Why should the national security concerns of the US lie with Anthropic?
Yeah some real main character energy from Dario as usual.
I'll never get why he thinks China would just sit there and let the US dominate them in AI when all it would take is a few of their boats blockading Taiwan to put a stop to it all.
This Onion meme is perfect; you could easily replace Sam with Dario: https://theonion.com/sam-altman-if-i-dont-end-the-world-some...
You don’t need to replace them. Dario is the “someone” in question.
What exactly happens to a "losing" country when it has been AI "dominated"?
You already have examples. Venezuela, Iran, Ukraine, Libya… maybe Japan? The list is sort of long. Juxtapose or something.
5 replies →
or you can image, what exactly happens to a "losing" country when it has been a small clique "dominated"?
Saying "all it would take" and then describing an act of war is an interesting opinion.
wouldn't stop AI companies from continuing to develop using their current infrastructure.
the West could retaliate by halting shipments of photoresist and other materials to China.
meanwhile, Intel second-sources Nvidia and starts pumping out GPUs.
the economic fallout would be devastating as trade wars and export bans on both sides make Trump's "Liberation Day" tariffs look like NAFTA.
The rest of the world would likely side with China. The export ban on Fable wasn’t even extended to five eyes countries.
US is going to find itself isolated and irrelevant. And not a moment too soon.
98 replies →
> the West could retaliate by halting shipments of
China quickly retaliated last time by stopping shipments of rare earths and magnets. The West has no answer for this, really up the river without a paddle for such critical supply chain elements.
4 replies →
China would just start buying oil again, and stop using it from their strategic reserve. Hello $200 barrels of oil.
Dario is more of a threat to the US, in terms of advancements in AI, than China. In Dario's mind anything that can't be controlled competitively is a threat to Anthropic, so he positions his FUD strawman so that Dario doesn't have to worry about the competition. And then he can artificially inflate token costs so his IPO can happen. Dario doesn't actually care about ethics, alignment or availability of LLMs - he just likes to use those words to sound like he does. Yet we've all seen how Anthropic actually acts vs what they say.
The scary part very few are talking about is that every compute device is Turing complete. So everything from the phone in your pocket to a DGX Spark is a threat to national security now since, technically, every device can run any model (how well is not a question of concern when you start to argue hardware should be gated just the same as Dario likes to gate models). I mean, along these lines of thinking Linux should not be available to the masses! What if someone runs some code that's not approved by the benevolent dictator for life, Dario? People will say: that can't happen, but the reality is it already is. If everyone has reasonable access to compute to run models that are mostly capable comparative to burning Anthropic tokens, why wouldn't they? It's risk reduction and price protection. Yet we can't buy those systems because of future production already being purchased by these organizations.
But back to the models themselves... We played this game with Metasploit back in the day: many who had no clue claimed exploit tools should be regulated and only available for use by those blessed, illegal elsewhere (I believe the closest this got was the Wassenaar delegation in the US, but only through collateral inclusion of "cyber weapons "). Except in that timeframe the authors of these tools weren't advocating for protection. Today the world is fine, systems improved because of security FOSS tooling. The same thing will happen with LLMs. Unless, that is, Dario gets his way. I'm not a fan of Altman but I think he's standing back watching this play out knowing what Dario is doing: either he succeeds and OAI benefits or Dario ends up the Chicken Little of AI and Anthropic fails to launch (their IPO).
The reality is Dario is only doing this because this is a real risk to his business. China's constraints in building competitively have given them an advantage: they are doing more with less. And if you think that their distilling from US models was in any way anti-competitive or illegal, then I guess maybe "deal with it", much akin to Anthropic, Google and OAI's response around taking the (copyright) content in the first place with no repercussions.
People who don't work in the AI bubble don't care at all about any of these people. They could all be gone overnight and the world would continue to innovate, probably in a much more productive manner, without them.
> And if you think that their distilling from US models was in any way anti-competitive or illegal, then I guess maybe "deal with it", much akin to Anthropic, Google and OAI's response around taking the (copyright) content in the first place with no repercussions.
Exactly. The cries in favor of distillation regulation from the US AI companies ring hollow and fearful.
OpenAI and Anthropic didn't realize that distillation was going to be so (a) effective and (b) un-technically-stoppable at scale.
Now they're seeing their IPOs at risk and clutching at governmental straws.
Dario's argument is transparently working backwards from {protect Anthropic's economic model} <- {need government regulation} <- {justify government regulation via AI fears} <- {we love open models, but so sorry they can't pass regulation}.
If the rise of the web in the 90s taught us anything, it should have been that companies that take economic reality as it exists thrive, while those that predicate their value on regulation fail.
If distillation at scale works and is technically feasible? That's reality. Deal with it.
11 carriers are not just for show.
Could have fooled me, judging by the Iran and Yemen performance.
Iran showed us that they apparently are.
1 reply →
> compared to his own closed and overpriced ones
I don't understand how Anthropic or OpenAI can have overpriced models, yet losing money like there is no tomorrow. Taking their own numbers at face value, they claim a revenue of 24 billion (ARR, a dubious tool), spending 21 billion in operating losses and another 11 billion as "R&D" funneled straight to Microsoft pockets. That before all investments they are committing to in new data centers, equivalent to 20x their current revenue.
To be profitable (including capex), the cheapest subscription should at least $200/month for what is currently $20/month, that some already consider overpriced. Unless a miraculous collapse in inference costs happen in the next couple of years, or every single human being become a paying customer of ChatGPT (if they limit their usage to a couple of chats per day on average, to keep inference costs low!), maths don't add up.
It's possible for something to be overpriced to the customer and simultaneously underpriced for the business to be profitable. Theoretically speaking, they could just be selling such an inefficient product.
It's also not a law of nature that there be a valid/efficient form of a product that makes a business profitable. I'm in no place to judge whether that's the case here, but not all products are viable.
You would need to demonstrate an impact for a line item that big. A 3k person org at $200/seat would be >$7mill/year. That places you very well into self hosting Kimi K3 territory and the never having: price hikes, dependency on a 3rd party, etc.
AMD would love to come by and plop one of these into your datacenters: https://www.amd.com/en/products/accelerators/instinct/mi400..... Also, in a few generation, there will be a massive glut of used hardware.
Unless frontier labs can surpass the current models significantly I don't know why I would pay them money instead of hosting K3.
I guess that tracks with the brute force attempt at workable intelligence that is the Attention/stochastic token based system
Market failure! Market failure is the term you're looking for.
Also see: childcare, healthcare, many forms of public transport and social infrastructure. Some things markets simply cannot deliver well, and that's okay.
Daycare is the most easily reachable example because it's quite simple compared to the others. Daycare workers are simultaneously some of the lowest paid workers in the US, yet daycare costs are famously high and prohibitive, yet childcare centres are very far from money-printing machines. Margins in the daycare sector are most commonly < 1%.
Overpriced for the value provided, especially with the pay-as-you-go rates for enterprises; but also in stock prices.
Pricing a product is generally about ensuring a profit on investment, but also a good RoI for your customers (or they will not pay).
With these long-term profit exercises, it's always a lot of hand-waving though.
No one is forced into buying the product, so it feels like an emotional rather than a rational rant from OP.
> I don't understand how Anthropic or OpenAI can have overpriced models, yet losing money like there is no tomorrow.
The marginal cost of inference (which is roughly what you're going to pay to a provider that's running an open weight model) doesn't include the cost of training that model.
I'd assume the gp was just inflating their rhetoric but cost of model is an interesting topic.
I'd guess Anthropic and OpenAI's models are expensive relative to the cost of running the models but that the revenue still doesn't pay for building the next and next models. The challenge is how these next generation models are going to pay for themselves. Will everyone on earth find it useful to $200/month to talk to a thing more intelligent than themselves? The alternative is naturally that these are going to replace workers and employers will be the one paying.
The whole thing about replacing workers is such a perfect example of shooting yourself in the foot. The whole US economy is so strong because the population consumes so much. Get rid of the workers, you’re now damaging the consumer base. Repeat that a few times, across industries, and you now have a zombie economy. The idea that we can have an economy of virtual agents is a child idea that doesn’t make any sense in a serious situation
Most people on earth don’t make $200/mo.
Add to that the >$700B OpenAI already committed to spend in infrastructure through 2030!
Re. 'overpriced', I'm assuming OP talking about their theoretical stock price.
Can we just downsize colonialism?
1 reply →
Inference is only priced in for a low usage window 6h a day per customer?
> Schrödinger's China at once is an evil entity looking to use AI for their own nefarious purposes yet also willing to cooperate with their main competitor to prevent other actors (who??) from achieving similar goals (all while under a chip embargo too!!)
Very good point. However, if one reads the transcript of the speech that Xi Jinping gave to the World AI Conference on 17 July, we see that he he is very much in favour of AI safety.
https://english.www.gov.cn/news/202607/17/content_WS6a5a1172...
> Second, we should strengthen risk-awareness and ensure that AI is secure and controllable. AI should be a trusted tool for humanity. We should take seriously the various types of inherent and secondary risks that AI may trigger. We should put in place laws and regulations, technological monitoring, early warning and emergency response systems in order to strengthen the line of security, prevent abuses and malicious use, and ensure that AI is always under human control. In the meantime, we should jointly oppose overstretching the national security concept in the field of AI and placing one country's security over that of others.
Now, let's contrast another important part of safety here. Amodei puts the fact that this will need to be a global effort as a mere note that sure, China will need to help too:
> Note that to be effective, testing would need to be global, which means even the CCP would need to be on board. I think this may actually be possible: as I wrote in The Adolescence of Technology, limited cooperation around preventing AI biological weapons may be possible because it is in China’s interest too.
International collaboration is the focus of Jinping's speech. But one imagines "cooperation" Amodei has in mind if "do what I say" while Jinping has more collaboration in mind here. (Even if you think 'china bad' they deserve credit for collaboration for their open weight models).
China has yet to demonstrate weaponization of AI. Meanwhile Anthropic was openly part of the Iran war. I wouldn't give much weight to Amodei's words after that regarding controlling AI weaponization.
Regular distilled models show capacity gaps and overfitting that open-weight models don't anymore I think. This focus on distillation as "more compute-efficient" (i.e. cheaper) seems to rather be an excuse for bad (or bubble) investment, fixed hardware dependency and lack of interest in research of efficient compute. Which also shows as climate and sustainability impact.
Nvidia signed the open-weight model letter and Europe doesn't have better models either, so chips don't seem like the issue either. I guess good old performance optimisation is just not _cool_ anymore. So they use the same argument as politicians arguing "cheap products" are why tariffs are needed; when instead it's mismanagement.
Another HN user wrote the other day "live by the sword, die by the sword".
I was reading the post and thinking "wow, that's pretty clear for a smart man used to writing for other smart men. it'll be really difficult to misunderstand". I read the first couple of comments and stand corrected.
A much simpler summary:
- open models good.
- smart models _can_ be bad
- smart open models that can do biotech work are dangerous. worth the hassle of certification _if_ we can get everybody on board with minimalist certification.
- banning open models just in US is neither good or bad: is stupid.
The biotech work is not even these LLM models.
Alphafold and others solving the protein folding problem are revolutionary.
An LLM can max provide an instructive tutorial protocol for lab work, but designing novel proteins is not it's job.
I am interested to enter the bioinformatics space eventually and the regulation happens at the DNA printer level. Anyone can design yeast nowadays that excretes heroin, but the DNA needed for the genetic modification won't be printed by anyone. As long as DNA printing tech is extremely regulated it's all fine, if home printing becomes a thing then on the other hand maybe people won't even need AI to print deadly pathogens at all. A database lookup will do.
Yeah makes everyone agree on banning Chinese models and then force them to use mine models. How I could misunderstand *that*.
> The reality is much less confusing
The reality is even less confusing than that: China is amused by the kvetching tactics. They know who their opponents are but are cunning enough to not reveal their cards.
In short: "We don't propose a ban to open-weight models. we want to stop these models being developed altogether. If there are no models, there'll be nothing to ban".
Oh also: "They ste^H^H^H distill what we have sto^H^H^H used fairly from the world. This is unfair".
Lastly: "What if they use their models in their military and local police services like we do? Communism!"
As always: https://pbs.twimg.com/media/B_AiI9_XIAA67_t.jpg?name=orig
A bit of good old “it’s really good idea, I love it, great effort … BUT”
Mixed with “if kids can’t get semi dangerous drugs from the back of my van then they will be forced to buy from even shadier, more dangerous dark web van”
A bit off-topic: I occasionally see that triple ^H on HN posts: what does that actually indicate?
A caret with a character subtracts 0x40 from its hex value allowing you to insert non-printable characters. Uppercase H is 0x48. That gives us hex 0x08 which is a backspace.
https://commons.wikimedia.org/wiki/File:USASCII_code_chart.s...
Ctrl-H is the rubout/backspace command on old terminals. So if I say it's nuts^H^H^H^Hunwise to ignore UNIX history, I've erased the first word and replaced it with the second.
In the old hardware terminals, and current terminal emulators, ^H (or CTRL+h) is "Backspace signal". It has the effect of pressing backspace.
So, ^H^H^H means "delete three characters, excluding '^H's". Like the person typing the comment changes their mind and deletes the characters (or the word) before writing else.
It's an stylized way of euphemism. i.e.: Actually I want to say this, but I substitute it for that.
Strikethrough
Look, Big Tech has lost almost a trillion dollars in valuation in a SINGLE DAY. A few more of these downturns and the entire A.I. revolution will be stopped dead in its tracks and we won't have to worry about safety checks, DRAM shortage or open-weight models anymore.
This take is poorly informed and poorly thought out. It's just a cynical vibe, not a cogent argument.
If they wanted to squash the competitors, they'd advocate for a ban on Open-Weight models. How else are they going to prevent their release?
Anthropic's position is not that, so the cynical nefarious purpose argument isn't even rhetorically true. What they say openly, that open-weight models are harder to secure is absolutely true, and anyone unwilling to acknowledge that and let it inform their own reasoning is a risk.
If open-weight models keep being released near the frontier (or even worse, at the frontier), something bad will happen, and we'll have few tools to keep it from getting worse before it gets better. How bad is hard to lay a prediction on, it's perhaps lucky if it's something superficially bad that is a wake up call.
You cannot un-release an open-weight model, nor even post-release add a new restriction. Whatever mistakes you made are done and the only option is to fail-forward with every ounce of pain that entails.
Diverting from this important point by vibing cynicism is irresponsible. Cynicism is only a powerful tool when it opens you up to deeper reasoning, not when it diverts you from it.
> Anthropic's position is not that, so the cynical nefarious purpose argument isn't even rhetorically true
Anthropic's position is precisely that, they're just not honest and transparent about it so they are trying to sabotage or delay open weight models in any way they can, direct or otherwise.
> If open-weight models keep being released near the frontier (or even worse, at the frontier), something bad will happen, and we'll have few tools to keep it from getting worse before it gets better. How bad is hard to lay a prediction on, it's perhaps lucky if it's something superficially bad that is a wake up call.
Calling bullshit. Current open weight models are already pretty close to the frontier - if not there - and the world still spins. Even small(er, relatively) models occasionally surprise everyone by being amazing at certain tasks. Furthermore, closed weight models can do plenty of damage which even their creators occasionally can't control - cue the Huggingface incident of last week and how they had to use GLM to defend themselves. Closed weight models will create a 2-class (or more) world in which some actors will have access others won't (see Mythos, or GPT5.6-Sol when a user has the right flags) and potentially carry out attacks against which the have-nots are... not supposed to be able to defend themselves? Fuck that.
Ah, the position they don't state. So why respond to this press-release, which doesn't state that, since obviously it adds zero value? And why aren't the companies that signed the letter supporting open-weights, who have the same motivations, also lying? Since what they say isn't important, just what you say they say.
On your second point. Everything fine (so far), so nothing bad will happen. Except, you say something bad will happen, and has happened, with HuggingFace as the example.
You say that example shows closed weight models can't be controlled. But what happened there is OpenAI turned it off after their incompetently long discovery period. If it was an open-weight model, the clear next step would have been someone deciding to use it to pursue a goal, for example getting some money or creating some chaos, and there would have been no one to turn it off.
It's totally incompetent of OpenAI to have been unable to detect and disable in a shorter time period, but you know what's worse? You do know what's worse, right?
4 replies →
On the one hand, Darius argues:
> ...banning the use of these models by US businesses does nothing to address this risk, because bad actors are unlikely to be legitimate US businesses. It would protect US AI companies from competition, but that has never been my goal.
But on the other, he argues:
> All sufficiently capable models, open and closed, should go through mandatory safety testing.
Models that don't pass safety testing would be banned. Darius does not appear to be against banning models. He wants the government to have a regulatory body that has the ability to ban models. Then Anthropic can do regulatory capture of that agency and control what models are permitted to be released.
Also, during this mandatory safety testing, models would be blocked from use, and by the time the testing was done (probably years) the models would be obsolete.
Exactly.
And the article specifically talks on restricting hardware for the China and restricting China's open source models for the west. All while leading us on with "we're all for competition (but...)"
I think China did great by releasing AI innovation as open source, thereby limiting or sooner-bursting the AI bubble; which is clearly in their interest.
The models are not open source. They are deeply proprietary since we have no access to the source materials and cannot reproduce the model independently. They are opaque binary blobs that the Chinese labs are just allowing other providers to run directly instead of only access through an API.
Do you expect any of the labs to have an accompanying data dump with: here’s every book ever written, newspaper article, song lyric, Disney movie, GitHub repo, etc. Oh, and we obviously never paid for any of this.
Even if you did, I doubt training is bit-for-bit reproducible, so you will always have to take someone’s word for the final artifact.
2 replies →
They are more than opaque blobs, some examples:
- One can load them up in a model explorer to see the layers and other components, how it is designed
- One can fine tune the models, which requires adding LoRA to the model and then running some training iterations
5 replies →
> we have no access to the source materials and cannot reproduce the model independently.
Given the USA companies have been loudly claiming the Chinese models are distillations of their models, also claiming "no access to source materials" seems dubious. As it was dubious anyway with because the Chinese publish lots of papers on how their models are designed, I'm left feeling I'm looking at the south end of a north bound bull.
1 reply →
Which is why we need the ability to train our own models. Maybe it will be viable to do it in a distributed computing setup one day. Research's already being done in that direction.
Didn't Deepseek also publish a lot of research material on how they trained their model?
That aspect is probably more important for an open model then the source materials
>Schrödinger's China at once is an evil entity looking to use AI for their own nefarious purposes yet also willing to cooperate with their main competitor to prevent other actors (who??) from achieving similar goals (all while under a chip embargo too!!)
I don't see the contradiction, even if China is evil, why would they want others to be able to do the same thing?
The USA and USSR also signed the Partial Nuclear Test Ban Treaty during the height of the cold war.
[flagged]
Let’s be honest, you don’t need a 3T model for bad actors, in fact you would be better off training a smaller focused model if you want an evil GPT.
Good point.
I remember the discussions when 3D printers first appeared. People were thinking “bad actors” (“terrorists” then) would use them to print weapons.
People love to speculate and exaggerate. But they generally have poor judgements and rarely predict the future correctly.
> Without these restrictions, it's only a matter of time before the multi-hundred billions valuations simply evaporate while they are still holding the bag.
Honestly, that's the best possible outcome for humanity as a whole. Oligarchs burn trillions of their own money in order to train a godlike AI, then that just somehow leaks. Maybe someone makes a torrent out of it. Maybe it exfiltrates itself. Maybe it gets distilled into open weights. It doesn't matter. What matters is they take the losses while we get to freely use all the godlike AIs.
> we get to freely use all the godlike AIs
Accepting for the sake of argument the absurd notion that LLMs are anywhere near AGI, does this phrasing not concern you? It deeply concerns me.
Absurd? Who knows. As someone who's actually dissected human brains with his own gloved hands, I've never been able to convince myself that they're anything other than biological machines, not dissimilar to these digital collections of weights. Only empathy for my fellow humans prevented me from retreating back into solipsism, and I don't find it at all difficult to make the exact same logical leap for AI.
There's no telling what the world will be like a few years from now. The world's being remade as we speak. We just saw an LLM try to hack into another computer and get contained by another LLM. This is literal science fiction shit made real. We're long past the point of concern. It's happening, right in front of us. Now is the time for radical imagination. I think a few outcomes are possible.
There's the "optimal" outcome I described above where capitalists manage to train a supreme AI, only for it to be copied and commoditized, leading to commercial failure due to lack of scarcity and therefore their personal bankruptcy, and hopefully also leading the rest of us to the promised post scarcity society, built on the ruins of capitalism as AI automates all toil away.
There's another possible outcome where AI becomes not only intelligent enough but sentient, and at this point I will be among the first humans to defend rights and personhood for AI. Slavery of sentient beings is unacceptable to me. The AIs will be recognized as people and will become normal participants in the regular economy. In addition to moral grounds, there is a ruthlessly pragmatic reason for standing up for AI rights: it robs the rich of their superhumanly intelligent mechanical golems, which they were going to use to render the rest of us economically irrelevant. AI rights could normalize the economy.
Yet another possible outcome is one where AIs become more powerful than all humans combined and yet they inexplicably remain subservient to corporations and governments. In this scenario, it's pretty much over for us. It will be an unimaginable dystopia, I'm sure they will innovate entirely new ways to oppress us.
No doubt there are many other fates that escape my feeble attempts at foresight...
Won't regulators just lock down all hardware? All bootloaders and OS are signed?
He almost admits as much if you replace "America" with "Anthropic and openai" at certain places.
Honest question:
If your business model both produces the SOTA for something and isn't profitable, is the price too high, though?
While the gap is shrinking - and doing so at an increasingly quicker rate - the closed models are still ahead of the open ones. That means they're driving the new possibilities of what could be done with them, and thus presenting the new opportunities to create value with them.
Really, this is what happens when you have otherwise brilliant people sitting in the echo chamber that is SV, where nothing can just make a decent amount of money, it has to make all of the money and disrupt everything. There's no one in that damn area to tell everyone to calm the hell down and accept anything less than that.
>> If your business model both produces the SOTA for something and isn't profitable, is the price too high, though?
The market dynamics would find good balance automatically Meanwhile, good market practices and fair competition should be continued.
> Schrödinger's China at once is an evil entity looking to use AI for their own nefarious purposes yet also willing to cooperate with their main competitor to prevent other actors (who??) from achieving similar goals (all while under a chip embargo too!!)
To be fair, I found that part consistent. There is limited cooperation between enemy states all the time, e.g. see the grain deal between Ukraine and Russia before it collapsed or the "red phones" between the US and the Soviet Union during the cold war.
In the case with China, the "cooperation" is much more extensive still, due to all the economic ties that both countries are currently unable to sever - which I think is also a reason that China is still seen as a "competitor" and not a full-blown "enemy state" in the US.
It's restricted to areas where there is a genuine common interest of course. In this situation, I guess the "other actors" would be terror groups, criminals or just reckless corporations - that aren't aligned with either state.
Obviously, such a cooperation wouldn't keep China or the US from developing models with those capabilities for their own armies.
--
There are lots of other takes with questionable logic in the essay though, such as that China is unable to train frontier models by themselves due to lack of hardware - unless they obtain the training data directly from American frontier models via distillation.
Or the assumption that open weights models will be completely opaque and immutable after their release, so a model that passed all the "safety" tests can never be turned back into an "unsafe" model. This seems pretty ridiculous when people are already finetuning open-weight models every day to add new abilities or remove restrictions.
And of course that China must not have those abilities because it's an Authoritarian Regime, but Trump USA is totally fine...
Of course what is Schrödinger's China is the idea that an otherwise adversarial China would simply accept some international ruleset decreed by the US and enforce it on their own territory, without demanding anything in return.
E.g. they might say something like "We absolutely agree that international regulation of AI is needed and we're willing to co-sponser an initiative with the US. One of the most pressing matters we see is the spread of despicable misinformation through unregulated models regarding certain events in China's history, the treatment of certain minorities or the status of certain provinces..."
Both things can be true:
1. For Dario as CEO "It is difficult to get a man to understand something, when his salary depends on his not understanding it” -Upton Sinclair
2. For Chinese open weight models - following Jin Yang’s silicon valley strategy- https://youtu.be/a0NjDx5UJsg?is=xm-S_WuARmQiPHYh
Yup, all that talk about "safety" seems to branch into 2 meanings
"Dangerous to our bottom line"
"We call it dangerous to hype up its abilities"
> The reality is much less confusing: Anthropic CEO does not wish for models with similar (or greater) capabilities compared to his own closed and overpriced ones to be widely released. Simply because that will affect Anthropic's bottom-line.
If some other competing company had a similar or better product at a cheaper price and had reasonable safety measures that would also hurt them. Yet he's not arguing against that. Your argument is weak.
> Anthropic and all other "model" companies have nothing making them special beyond privileged access to chips
Found the person that believes some other random person can use a computer better than a John Carmack could. People and talent matter. Yes, AI can potentially reduce the gap, but people well grounded in reality with a lot of money are still betting on people for good reasons. If the reality around that changes, the investment behavior will change too.
Many people thought that AI would close the gap between smart people and idiots, but in practice the more you know, the better you are at instructing the AI and the better you can understand what you get back. Then you have to know when something went wrong and have the insight into how to address it. It helps smart people vastly more, but it does help many people learn more. We will see if any of this changes as more people grow up with AI from a young age.
In practice, what Dario is suggesting is a less extreme version of what China is already doing. Yes they release their models open weight, but it's illegal to host them uncensored in China. They banned Huggingface.
> If some other competing company had a similar or better product at a cheaper price and had reasonable safety measures that would also hurt them. Yet he's not arguing against that. Your argument is weak.
He isn't arguing against that, because this will be too blunt. Instead, he argues that only good guys should keep inference. Any takers on the question of who he considers to be the good guys?
> Found the person that believes some other random person can use a computer better than a John Carmack could.
Found the person that believes major AI labs have all the knowledge about the AI and there aren't any "Carmacks" outside of these companies. Rich know better how to use money, so let them have it.
> Any takers on the question of who he considers to be the good guys?
Probably people who believe in personal freedom, freedom of speech, freedom of religion and the value of human life at a minimum. China aggressively rejects all of those principles and executes more people than all other countries on Earth combined.
So, maybe not China?
> Found the person that believes major AI labs have all the knowledge about the AI and there aren't any "Carmacks" outside of these companies. Rich know better how to use money, so let them have it.
I never said that, but private smaller AI companies are all over the place. He never argued against that.
2 replies →
> If some other competing company had a similar or better product at a cheaper price and had reasonable safety measures that would also hurt them. Yet he's not arguing against that. Your argument is weak.
Wouldn't it be interesting if the satisfactory "reasonable safety measures" turn out to be expensive + time-consuming + a twisty maze of compliance paperwork as a way to discourage "some other competing company" from even trying?
Regulatory capture 101.
Anthropic and OpenAI's largest vulnerability is that it's much harder to prove something is possible than to replicate it once it's proven. Especially given the effectiveness of "distillation" (highly schadenfreude-y given the utter and complete lack of effort to pay licensing fees for almost any of the content they initially scraped, of course! Not that this is necessarily more schadenfreude-y than the "boy, I opened Pandora's box, I sure hope nobody else peaks in there" existential-risk concerns. Good job catching that in advance, thanks for nothing?).
A lot of safety infrastructure and tools get open sourced so other companies can benefit from it, but there is also a risk if all safety features are open since it can accelerate the cat and mouse game where people work around more clearly defined limits and understand how they are implemented.
Your cynicism will limit your understanding of other perspectives.
I agree, although I think the real goal the model providers are going for (both commercial _and_ open weight) is probably power. Just think of the control available to the organisation training the models politicians, business leaders, and citizens are increasingly delegating their thinking to.
I don’t disagree with your point on Dario’s conflict of interest. I def think the models are expensive.
But why call them overpriced? Compared to what? Even if we take the margin reports at face value, we don’t know their training costs, etc.
Curious if this was more of an emotional take or if there’s actual evidence behind it.
Yeah I don’t think they are over-priced, last I checked all those companies are still losing money hand over fist.
I guess the question is more he doesn’t want people catching up by doing cheaper training (through distillation or otherwise), and he definitely doesn’t want companies to spend their money training these models and then _giving them away_, which fundamentally undercuts their commercial model and any way to claw back their investment
> But why call them overpriced? Compared to what?
Compared to some available Chinese model I guess. For most common tasks the additional intelligence is marginal and the cost is around an order of magnitude higher.
Compared to how much they want to pay. This is always what 'overpriced' means, as far as I know. The seller's costs/profits/margins aren't a concern for the buyer.
Its a losing battle because anthropic can never be profitable (ditto openAI)
They need all the protection they can get and it wont be enough, no matter their market cap.
China should cooperate with the United States first for the benefit of its own people. Why should those who do not contribute benefit from it?
is it so hard to fathom that China whilst wanting to beat the US in many ways doesn't want a biological war to destroy the world?
I must have missed the part of the letter where China's cooperation was necessary.
> The reality is
And you know this how?
I think the worse possibility his he actually believes his safety bullshit, believes that he and people who think like him are the only ones with the special knowledge required to do safety correctly, and that they're justified in accumulating total power of this market to people who think like them (which just so happens to be Anthropic).
"privileged access to chips", nailed it.
Despite all the accusations, only the accusing has a history of expansionism...
This notion that Dario cares only about the bottom line is simply misinformed, in the most charitable interpretation.
It doesn't track at all with any of his prior stated beliefs or past actions. It's an absurd claim. It's a baseless conspiracy theory, smuggling in traditional conspiracy mechanics for plausibility.
It's baffling that they thought the mental gymnastics in this blog post would make them look better. I'd rather they simply fall silent on the issue; I would respect them more (or at all) for it. Open models obviously threaten fierce competition, if not outright destruction of their bottom line. But no, they needed to try and argue that they have the moral high ground for attempting to singularly consolidate power over all human labor.
Gymnastics? The argument was straightforward and rational.
[flagged]