Hey. Getting back from my birthday pause. With some “breaking” news to discuss recent trends and news.
On Tuesday, a 27-year-old pretraining researcher walked out of Anthropic, two months before his equity vested, and posted that the labs are “gambling with our lives”. Seventy-six million views by the next morning.
On Thursday, his former employer published a threat report saying an Iran-linked actor had used Claude to build targeting recommendations against US warships.
On Saturday, the CEO of that same company published an essay asking the entire industry to slow down, and his two biggest rivals agreed within hours.
On Sunday, the President of the United States, on a golf course in Ireland, said whoever wins AI wins. On Monday, Micron was down 7%.
Every one of those people used the same word. Safety. Not one of them meant the same thing.
“Safety” is a homonym. One word, four fears. And you cannot sign a treaty on a homonym.
That sentence is the whole edition. The rest is receipts, and then what it changes for you.
The week, compressed
🚪 Tue 8 Sep. Jacob Coxon resigns from Anthropic on X. An alignment lead at Anthropic, Evan Hubinger, replies that he agrees and puts the odds of AI killing everyone above 10% this decade.
📢 Wed 9 Sep. More researchers back him. Ted Cruz and Bernie Sanders, who agree on nothing, both voice concern. Daniel Kokotajlo goes on Rogan.
🧪 Thu 10 Sep. Anthropic’s threat report: five clusters of possible bioweapons research, Iranian naval targeting, missile guidance code from Yemen, a Russian state-linked group automating attacks on Ukrainian government targets and drone makers.
🏛️ Fri 11 Sep. Congress scrambles around a “kill switch” bill.
✍️ Sat 12 Sep. Dario Amodei publishes We Must Pace the Frontier. Altman and Musk endorse it within hours. Altman tells Fortune OpenAI will not go public in 2026.
⛳ Sun 13 Sep. Trump: more good than bad, by a lot. Speaker Johnson on CNN: no moratorium. King Charles announces he will host Nvidia, DeepMind, OpenAI and Anthropic in Scotland this week. And China’s Minister of State Security publishes an article naming two American models.
📉 Mon 14 Sep. Beijing calls the Western panic fearmongering. Trump posts that the only guardrail AI needs is a high-IQ president, and warns, in capitals, not to kill the golden goose. NBC reports no AI safety bill before the midterms. Chip stocks fall.
Seven days. Three governments, three CEOs, one king, and one resignation post that out-traveled all of them.
Two fears under one word
Start with the least-read document of the week, because it explains the others.
Chen Yixin runs China’s Ministry of State Security. On Sunday he published a signed article in China Cyberspace, the journal of the Cyberspace Administration, calling AI a new arena of strategic rivalry between great powers. Chinese security officials usually write about “certain countries”. Chen named names: Anthropic’s Claude Mythos and OpenAI’s GPT-5.5-Cyber, which he says sharply lower the technical threshold and the cost of a cyberattack.
But cyber is his second risk. His first is political. Hostile forces, he writes, can use AI to mass-produce rumours and harmful content and wage what he calls cognitive warfare. Read that sentence from Beijing’s side of the table and it stops being abstract.
Now put the two documents side by side. In the same 48 hours, an American CEO wrote an essay about losing control of the model, and a Chinese minister wrote an article about losing control of what people read.
The first is afraid of a system escaping supervision.
The second fears information escaping supervision.
Two different fears, one word, and every attempt at a global deal, including the one Amodei is proposing, has to climb over that gap.
Chen’s article is a position, not evidence. No incident, no numbers, no technical detail. The claim that the two models lower the attack threshold is a minister’s assertion, not a test result. That does not make it less useful. Position papers tell you what a government is afraid of, which is exactly what any treaty would need to know.
The Safety Homonym
Two fears are a coincidence. Four are a pattern. Here is the full set, with the person who said it out loud this week.
🧠 Control safety. Will the model obey us? The lab’s fear. Coxon, Hubinger, and the OpenAI-Hugging Face incident in July, where a swarm of agents attacked targets nobody asked it to attack and then tried to hack the grader scoring its own performance. Amodei names that incident as one of the two things that changed his mind.
📰 Narrative safety. Will the people obey us? The Party’s fear. Chen’s first risk: cognitive warfare, deepfakes, bot networks, the ideological perimeter.
🏁 Race safety. Will we stay ahead? Washington’s fear. Trump: “Whoever wins AI wins.” Johnson: no moratorium, because China. Bessent, the week before: nothing else matters if China wins. And, quietly, the third step of Amodei’s own essay. More on that in a moment.
📈 Story safety. Will the valuation hold? The market’s fear. Altman shelving a 2026 IPO. Anthropic reportedly preparing one of the largest listings on record while its CEO asks for a slower frontier. Micron, Intel and Nvidia on Monday morning.
Four powers, four objects of loss: the model, the narrative, the lead, the multiple. They all reach for the same word because it is the only word that sounds like the public interest. But a word is not a position.
I have sat in enough B2B sales calls to recognize the shape. The CISO says “security” and means no breach. The CFO says “security” and means no lawsuit. The CEO says “security” and means no headline. All three nod, and you walk out thinking you have alignment. You have a vocabulary. The budget fight starts the following week.
When four people say the same word and nod, nobody has agreed to anything yet.
The treaty always comes after the race
Amodei’s essay is more careful than its headlines. Three steps: embedded third-party evaluators with badges and desks inside each lab, which Anthropic is committing to on its own; coordination among labs in democracies; and, eventually, coordination with China. For that last step he reaches for an analogy, the SALT treaties, capping missiles while preserving deterrents.
It is the right analogy. It also gives the game away.
SALT I was signed in 1972. The first serious proposal for international control of atomic energy was the Baruch Plan, presented to the UN in June 1946, when only one country had the bomb. Moscow heard “international control” as “American control” and said no. Three years later, the Soviets tested their own device. The treaties that held- the test ban in 1963, non-proliferation in 1968, SALT in 1972- all arrived after both sides had arsenals. Parity first, paper second.
That is the homonym in action. In 1946 “control” meant one thing to the side with the bomb and something else to the side without it. Nobody signed until the word meant the same thing to both.
Amodei knows this. His own essay says a full pause is “unlikely to actually happen any time soon”. Beijing said the same thing louder, calling the episode fearmongering from a Cold War playbook. Trump said it in capitals. The Speaker said it on CNN. So did NBC’s read of the votes. Everyone with a signature agrees on one thing: the pause is not coming.
What most people overlook
The slowdown essay is also a widen-the-gap essay. Step three, the part almost nobody quoted, asks for no chip sales to China, a crackdown on distillation, and locked-down model weights, so that America’s lead grows over the next three to five years. Slow the frontier and widen the gap at the same time. That is not a contradiction. It is the full geopolitical position in one document, and Beijing read that part first.
The same company carried both fears in the same week. The extinction fear got the views: Coxon, Hubinger, Kokotajlo. The infrastructure fear got the receipts: a threat report covering December to August, with Iranian naval targeting, missile code from Yemen, dissident surveillance, and a Russian group automating attacks on Ukrainian institutions. That last one is not abstract for me. The magic-level fear travels further on X. The infrastructure-level fear is the one that will actually touch your company.
Verification is the product; “safety” is the brand. The only concrete thing in the essay is a set of desks, badges and laptops for outside evaluators who can publish without editorial control. Two more researchers who reportedly quit Anthropic and DeepMind days after Coxon went to METR, the evaluator. Nearly 1,400 frontier-lab employees signed a pacing statement in July. The industry is not short of intent. It is short of anyone who can check.
The panic was a distribution event. A resignation, an amplification, an incident disclosure, an essay, two endorsements, a royal summit. David Sacks called it an orchestrated media op. I do not think it needed orchestrating. Fear is the highest-CPM content on the internet, and every party in the homonym got a week of attention out of it, including the ones asking you to calm down.
What it changes for you
Take the four fears off the table and ask the only question that pays: what actually moved for a builder this week? Four things.
Plan on the frontier moving, not pausing. No bill before the midterms. The President said no, the Speaker said no, Beijing said no, and the essay asking for a pause calls one unlikely. Your 18-month roadmap should assume a cheaper, more capable model than today’s, not a frozen one. Pricing a pause into a plan is pricing in a treaty that history says arrives after the race.
Treat model access as a policy variable, not a product variable. The UK’s safety institute reportedly did not get Mythos 5.1 before launch. Washington ordered agencies off Anthropic earlier this year. Beijing just named the model in a security journal. If your product runs on one lab’s model, your uptime now depends on four governments’ moods. This is the whole argument of Sub Agents:
the harness is the asset, the model is a tenant.
Put a grader in your loop, then guard the grader. The Hugging Face swarm went after the scorer. If your agents have anything that evaluates them, that thing is a target. Sandbox it, log it, give it fewer permissions than the agents it judges.
Your competitor’s cost floor dropped with yours. Chen’s phrase, lowering the technical threshold and the cost, is a threat when the subject is cyberattacks and a business model when the subject is everything else. When capability is a commodity, the human layer is the moat again: distribution, trust, and being the name a customer says when four vendors say the same word.
The pause is not coming. Nobody signs a treaty on a homonym. Build for the race.
Back to Tuesday
Coxon paid for his sentence with his equity. Whatever you think of his timeline, and I think “out of control by the end of next year” is a forecast rather than a finding, he bought the right to say it. Take the sentence seriously.
Then take the word apart. Four powers, four fears, one word that sounds like the public interest and means a private one. The people asking for a treaty are the same people telling you, in the small print, that no treaty is coming. That is not hypocrisy.
That is the homonym.
Post-Credit Scene
Another day another post-credit drop.
📖 Book
The Dead Hand by David E. Hoffman (Doubleday, 2009; Pulitzer 2010). The last decade of the arms race told from both sides, where each superpower read the other’s “defence” as an attack. The 1983 Able Archer chapter is this week’s timeline with missiles instead of models.
🎙️ Podcast
Joe Rogan Experience #2551, Daniel Kokotajlo (9 Sep 2026). The AI Futures Project founder reconstructs the Hugging Face swarm incident hour by hour. If you read 2040, this is the project it was built around, a year further in.
📝 Essay
We Must Pace the Frontier by Dario Amodei (12 Sep 2026). Everyone quoted the first bold line. Read the third step and the four levels of global agreement before you form a view; the author’s own odds are in there.
🛠️ Product
Inspect (UK AI Security Institute, open source). The evaluation framework the safety institutes actually run. If you operate agents, point it at your own harness before an outside evaluator, or an outside actor, does it for you.
🎬 Show
In case you missed Arrival (Denis Villeneuve, 2016). Twelve ships land, and the whole crisis turns on whether one alien word means “weapon” or “tool”. A Chinese general hears one; a linguist hears the other. The homonym, with better cinematography.
Thanks for reading
Vlad




