This is an automated rejection. No LLM generated, assisted/co-written, or edited work.
Read full explanation
Epistemic status: Confident about the incentive structure. Moderately confident about the mechanism. Genuinely uncertain about the magnitude, and section 9 contains the objection that decides it. Parts of section 4 rest on private information I can't source; flagged where it happens. Vendor and figure specifics are current as of August 2026 and will rot.
1. Rate is the variable
The safety community has said "capabilities are outpacing alignment" so many times that it has stopped being a claim and started being a throat-clearing noise. Restated with a mechanism attached:
The rate of capability gain is set by a competitive process with no term in it for whether anyone understands what is being built.
Not an insufficient term. No term. There is no line in any lab's financial model called interpretability debt. There is no price for the gap between what a model can do and what we can verify about why. A firm that slows to close that gap loses share to a firm that doesn't, and the firm that doesn't gets the capital, the compute, the talent, and the next run.
This is not a story about villains. It is the ordinary behavior of a market where the externality is unpriced and unpriceable, because the counterparty who would sue you is a future that may not exist.
So be precise about what's dangerous. Capability is not doom. Rate is doom. A world that reaches transformative AI in 2045 with twenty years of accumulated mechanistic interpretability, formal methods, hardened infrastructure, and institutional muscle memory is not the same world as one that arrives in 2029 with a pile of evals and a lot of vibes. Same destination, wildly different survival odds. p(doom) is far more sensitive to the derivative than to the endpoint.
The intervention we want is therefore not stop. It is slow. And that is the one our toolkit is worst at delivering.
2. Everything we've tried, and the property none of it has
Voluntary pause. Requires unanimity among parties with strong incentives to defect and no way to detect defection. Whoever pauses is replaced by whoever didn't. The 2023 letter is now a cultural artifact rather than a policy.
Regulation. Slow, jurisdictionally bounded, captured with impressive speed, and genuinely double-edged: compliance is a fixed cost, and fixed costs favor incumbents. A regime demanding a $50M safety apparatus is a regime where only frontier labs can operate. You may have thinned the race without slowing it.
Compute governance. The most serious proposal in the family. But it routes through export control, which routes through geopolitics, which routes through a rival state that has correctly identified this technology as strategically decisive. Asking a Chinese lab to slow for p(doom) reasons is asking a nation to accept permanent strategic subordination on the basis of an argument it does not accept. And note the recursion: every Western deceleration argument dies on "but China," and that argument is not stupid. It is why nothing moves.
Moral suasion. Here is the uncomfortable one. Suasion works best on the labs that already take safety seriously — which means its effect is to transfer the frontier to labs where it has no purchase at all. Suasion is a differentially disarming weapon. It disarms the careful.
The pattern: every lever either requires coordination we can't achieve, enforcement we can't perform, or selectively slows the actors we least want slowed.
What none of them has: a reason for a self-interested actor with no opinion about AI risk to participate. Every one of them asks people to want something other than what they want. That is why they lose. Markets are very good at beating arguments.
3. The flywheel, with the numbers in
Take Anthropic as the case — not because it is the worst actor, but because it is the hardest one. If the structural argument holds for the lab that publishes its scaling policy and funds a serious interpretability team, it holds everywhere.
The disclosed run-rate sequence: roughly $9B at the end of 2025, $14B in February 2026, $19B in March, $30B in April, $47B disclosed in mid-May alongside the Series H. Third-party trackers put late-summer ARR in the high $60s. The Information has been running the arithmetic on $100B annualized inside the calendar year. The company filed confidentially for an IPO on June 1 at a reported $965B valuation.
Whatever you make of run-rate versus trailing revenue — and the gap between them is the entire point of an exponential — this is a curve, not a level. Revenue funds compute, compute funds capability, capability funds revenue, and the loop runs at whatever speed capital markets will support. They are supportive.
Now the part that should bother you more than the revenue.
The labs are being paid to receive their scarcest input.
In every extractive industry in history, the firm pays for the raw material. Oil companies pay for leases. Smelters pay for ore. Pharma pays trial participants. The AI industry has achieved something new: its customers pay it for the privilege of supplying the input that trains its successor.
And the input is not marginal. Public text is running out — that isn't speculation, it's the stated premise of published frontier research. What remains in quantity is non-public: private code, internal documents, expert corrections, tool traces, failed attempts, and the record of which answer a domain expert finally accepted. That last category isn't "more data." It is expert preference data, at scale, generated for free, in transactions where the expert is the one paying.
Every enterprise API call is simultaneously a revenue event and an acquisition event. Nobody designed this. It emerged, and it is the best flywheel in the history of capital formation.
4. The row and the information
The contractual promise is real. I don't think the major labs are lying. But notice what the promise is about. It is about rows.
Read Generative Data Refinement: Just Ask for Better Data (Jiang et al., Google DeepMind, arXiv:2509.08653) as an economic document rather than a technical one. It opens by naming the problem outright: training datasets are growing faster than new text is indexed on the web, with projected exhaustion within a decade; far more text exists as user-generated content that labs have avoided because it carries PII, copyright, and toxicity risk. The method: condition a generative model on each real example, rewrite the parts that make it unusable, keep the parts that make it valuable. The authors are explicit that conditioning on real samples is what preserves the diversity that ungrounded synthesis lacks. They validate across tens of thousands of sentences, a hundred-plus PII categories, over a million lines of code from hundreds of repositories, and a detoxification run where the model still learns the facts after the toxic wording is gone.
Now re-read we do not train on your data. Which data? The row you sent can be deleted. A derivative conditioned on that row can persist indefinitely, and the training job that consumes the derivative is — truthfully — training on synthetic data. Zero data retention has the same shape available to it: raw bytes arrive, a transformation runs, the derivative is written elsewhere, the raw bytes are deleted, every sentence in the policy stays true. A contract can close this, but it has to explicitly cover derivatives, de-identified content, model improvement, product improvement, research, and partner disclosure. Three letters do not tell you whether yours does.
Disclosure of an epistemic asymmetry. I know people doing this work. It is not a hypothetical pipeline in a paper; it is being run. I can't source that, and you should discount unsourceable claims from strangers on the internet as a matter of policy.
But notice you don't need it. Strip out my private information entirely and the argument is unchanged, because the argument was never they are doing it. It is:
The technique is published, validated, and cheap.
The economic pressure to use it is enormous and increasing as public text exhausts.
The data holder has no mechanism to verify whether it is being used on their traffic.
Where those three conditions hold, the incentive wins eventually — at some lab, in some quarter, under some pressure — and you find out after it's priced in. The closed source, the unpublished binary, the plaintext prompt, and the privacy page that describes a company's current intentions toward itself: none of that gives your computer anything to check. The verification gap is the finding. My private information only tells you the clock started earlier than you'd otherwise assume.
5. The aikido
Aikido doesn't block force. It redirects it along the attacker's own line of motion.
Every proposal in section 2 fights the market head-on. The alternative is to leave the wanting exactly where it is and change the price of an input.
The flywheel has a hidden assumption: that the marginal cost of frontier-relevant private data is approximately zero, because it arrives attached to revenue. That is not a law of nature. It is an artifact of an architecture in which prompts arrive in plaintext at a server the sender cannot inspect.
Change the architecture and the assumption dies. If enterprise traffic moves through infrastructure where the privacy property is architectural and verifiable rather than promised — where the operator's control plane never sees prompt or output bodies, where the code handling plaintext is published, where the running image can be attested so that a different binary would produce a different measurement — then the lab no longer receives the data as a free byproduct of the sale. It has to buy it. Separately. At a negotiated price. From a counterparty who now knows what they're holding.
The specific vendor doesn't matter and shouldn't; a privacy monoculture is just a differently-shaped single point of failure. What matters are the properties: hidden by default, verifiable by the client, and no business model on the other side that depends on it not being. (A dated, non-exhaustive list of who is currently building this is in the appendix, kept out of the argument on purpose.)
This is not a boycott. Nobody stops buying inference. Nobody coordinates with anybody. Every participant acts on narrow self-interest:
The enterprise protects trade secrets, customer PII, and regulatory posture. It wanted this anyway — the CISO has been asking since 2023. Deceleration is a side effect it never has to care about.
The infrastructure provider captures a market that currently barely exists.
The lab faces a real cost line for a real input and prices its training runs accordingly.
The effect is the one nothing in section 2 could produce: the cost of the next capability jump rises without anyone agreeing to slow down.
And it survives the China objection better than anything else on the list. Data markets are not export controls; they need no treaty and no enforcement agency. A firm in Frankfurt, Singapore, or Shenzhen that decides its proprietary corpus is an asset rather than an emission is acting on identical self-interest regardless of which lab is asking. Data nationalism is one of the very few things every major power already agrees on.
6. Hidden by default was the norm three years ago
Here's why I think this is tractable rather than merely elegant.
Before 2022, shipping your unredacted corporate documents in plaintext to a third party's servers for processing, under terms you could not verify, would have been a compliance incident. Not a debate — an incident. Someone would have lost a job.
AI got a norm exemption. It was granted quietly, in the rush, because the capability was too useful to wait for the security review, and it has never been formally revisited. That exemption is the entire foundation of the free-data flywheel.
Revoking it requires no new law and no new argument. It requires only that enterprises apply to AI vendors the standard they already apply to every other processor of sensitive data, and that "we promise" stops counting as a control when "you can verify" is technically available. The security function is already the best-funded, most politically empowered department for this job in most large organizations, and it is already motivated. It does not need to hear a word about existential risk.
That is the Trojan horse. Deceleration doesn't arrive as deceleration. It arrives as a procurement checklist.
7. This has already happened once
The strongest objection to everything above is not that it's wrong. It's that it's a nice theory that will never happen. So consider that the identical move has already been executed at scale, on the public-web side, by a company with no stated interest in AI risk whatsoever.
Cloudflare sits in front of roughly a fifth of web traffic. On 1 July 2026 — under the label "Content Independence Day" — it split crawler identity into three categories, search, agent, and training, on the explicit reasoning that not all AI use is the same and the controls should differentiate. It then set a deadline: from 15 September 2026, mixed-use crawlers that blur search and training are blocked by default on any page carrying ads, for new customers, new sites of existing customers, and all free-tier accounts. Alongside it, Pay Per Crawl — billing crawlers per fetch over HTTP 402 — is being extended into Pay Per Use, which pays publishers when their content actually surfaces in an answer rather than when a bot fetches the page.
The supporting numbers are the interesting part. Per Cloudflare's own published ratios, Anthropic's crawler was fetching on the order of 38,000 pages for every one referral visit it returned; OpenAI's ratio was around 1,091. By June 2026, training crawlers were 50.6% of AI bot traffic on the network, while search bots — the ones that historically paid for access in clicks — were down to 10.7%. More than half of all AI crawl traffic was re-fetching pages that hadn't changed.
Note what is absent from that entire sequence: any appeal to existential risk, any coordination between publishers, any legislation, and any request that a lab slow down. A default was changed by an infrastructure provider acting on the commercial interests of its customers, and the price of a training input went from zero to negotiable across a fifth of the web. That is the mechanism in section 5, running in production, one month from now.
Two honest caveats, because the differences are where the lesson is.
First, the coverage overstated it. "100% block, no exceptions" headlines were inflated; the new defaults land on newly onboarding zones and free-tier accounts, not automatically on every existing site. Norm flips are partial and slow even when the infrastructure provider is fully committed.
Second, and more instructive: raising a price through policy creates an arbitrage, and the arbitrage is already visible. As blocks tightened on user-agent-identified crawlers, demand shifted toward residential proxy networks that make automated traffic indistinguishable from human traffic. A robots.txt directive is a request. A 402 is a request with a price tag. Neither is a constraint.
This is the argument for preferring the enterprise version of the move over the crawler version. You can proxy around a block. You cannot proxy around an enclave. If the plaintext never leaves your perimeter in a form the counterparty can read, there is no gray market in reading it — the property is enforced by the architecture rather than by the other side's willingness to respect a header. The public-web fight demonstrates that the economic logic works and that the norm can flip. The enterprise fight is where the same logic gets teeth.
8. What the slack is for
Say this buys eighteen months. Eighteen months of what?
Mechanistic interpretability, first and correctly — a field in a period of unusually steep returns, bottlenecked on serial research time in a way money only partly relieves. Then: security hardening against weight exfiltration, currently in a much worse state than public discussion implies. Evaluation science that measures something other than benchmark saturation. And the slow, unglamorous construction of institutions capable of deciding anything on a timescale shorter than a legislative session.
None of it is exciting. All of it scales with calendar time. That is the whole argument for buying calendar time.
But there is a better version of this section than "we get more months," and it is the reason I think this proposal is worth more than its deceleration effect alone.
The same primitive that makes data expensive also solves the auditing standoff. Third-party safety auditing has been stuck on a genuine impasse: labs cannot hand model weights to outside auditors, and auditors cannot certify what they can't run against. Both refusals are reasonable. The impasse has held for years.
Confidential compute dissolves it. Pour Demain, a Brussels AI policy think tank, reports building exactly this — a verifiable clean room in which gray-box interpretability evaluations were run against a 744-billion-parameter model inside hardware enclaves. The auditor brings the evaluation, the lab brings the weights, both sides get cryptographic proof of precisely what code ran, and the weights never leave the enclave. Neither party has to trust the other. The hardware is the trust.
That is not a side benefit. It means the infrastructure buildout this essay is arguing for is the same buildout that external auditing, secure weight custody, and verifiable eval reporting all require. You are not choosing between spending on deceleration and spending on safety capacity. The attested-compute layer is a prerequisite for both, and the enterprise privacy market is the thing that will pay to build it at scale — because "our data doesn't leak" is a budget line and "we could audit frontier models" is not.
Buy the deceleration, get the audit infrastructure. That is a better deal than any pause was ever going to offer.
9. Where this most likely fails
Frontier gains may no longer be data-bound. This is the objection that decides it. If the dominant driver has shifted to RL against verifiable rewards — math, code, tool use, anywhere correctness is machine-checkable and signal can be manufactured without limit — then taxing private text raises cost at a margin that isn't binding. You'd slow personalization and product polish without touching the thing you care about. I take this seriously. My guess is that grounded real-world traces still matter substantially for the messy long-horizon agentic capabilities that most risk arguments actually route through, and that the diversity property is exactly what synthetic pipelines can't manufacture — which is why the DeepMind paper exists at all. But "my guess" is load-bearing there, and I would update hard on good evidence.
The coordination problem may be reinstated rather than solved. One enterprise withholding is worth nothing. The mechanism bites only at scale. I claim it's a better coordination problem — incentive-compatible, no unanimity required, degrades gracefully, recruits participants who don't share the motivation — but better is not solved. The Cloudflare case is encouraging here precisely because a single infrastructure provider substituted for the coordination, and there are far fewer chokepoints in enterprise inference routing than there are enterprises.
It may still tax the scrupulous. The labs likeliest to respect an encryption boundary are those already trying to honor a privacy promise. If the net effect is to burden them, I've rebuilt the section 2 failure mode inside my own proposal. Partial defense: encryption isn't a promise, it's a constraint that binds regardless of intent — which is why it lacks suasion's selectivity. But the routing decision is still voluntary, and voluntary decisions select.
Encryption costs safety. Content no provider can see is content no provider can screen. The sharpest form: you have hardened the channel a determined bad actor most wants hardened. I don't think this resolves trivially in privacy's favor, and anyone who says it does is selling something. The partial answer is that attested compute permits policy enforcement inside the enclave — the screening can run where the plaintext is, without the operator retaining it — but that is a design problem someone has to actually solve, not a rebuttal.
Follow the incentives here too. Every vendor in this category profits from the belief that labs are extracting your data. That doesn't make the DeepMind paper less real or the verification gap less real. It does mean: evaluate architecture, not marketing. An unverifiable privacy claim from a privacy vendor is worth exactly what an unverifiable privacy claim from a lab is worth.
10. What to do
If you control enterprise AI spend, you hold a lever almost nobody in this discourse holds.
Search your ZDR terms for the word derivative. If it's absent, you did not buy what you think you bought.
Require verifiability, not assurance. Ask what your computer can check, not what the policy says. "Show me the attestation" is a normal procurement question in every other security domain.
Price your corpus. If you license it, license it as the strategic asset it is. Do not let it leave as a byproduct of a transaction you're already paying for.
Say so, out loud, in negotiations. Markets move on legibility. A hundred CISOs asking the same question changes a roadmap faster than any open letter ever has.
None of this requires believing anything about p(doom). That is the entire point — the first deceleration proposal I've seen whose adoption doesn't depend on adopting its motivation.
Which is why I suspect it's either the best available idea in this space or subtly wrong in a way I haven't found. I would rather find out now, while eighteen months is still worth something.
Appendix: who is building this, as of August 2026
Deliberately kept out of the argument, because the argument is about a category and the category needs many implementations. This list will be stale within a year and should be read as evidence that the architecture exists and ships, not as an endorsement of any vendor.
Vertically integrated, own products only. Apple's Private Cloud Compute is the reference implementation — attested boot, code signing enforced by the Secure Enclave, request data deleted on completion, binaries published for inspection. As of WWDC 2026 it is extending beyond Apple's own data centers onto Google Cloud, running on NVIDIA Blackwell GPUs with confidential computing, Intel TDX, and Google's Titan security chip. Google Private AI Compute is the parallel effort. Both are excellent and neither is available to you if you are not them.
Available to everyone else.TrustedRouter.com (attested open-source gateway with published per-provider posture), Tinfoil (open source, attested, NVIDIA Hopper and Blackwell in confidential computing mode, OpenAI-compatible), Edgeless Systems' Continuum/Privatemode (AMD SEV-SNP confidential VMs with client-side prompt encryption), Fortanix on the enterprise key-management side, and Red Hat's Kata Containers and OpenShift sandboxed containers as open-source plumbing underneath.
Cloud primitives, if you'd rather build it. AWS Nitro Enclaves, Azure Confidential VMs and Confidential Containers, GCP Confidential VMs and Confidential Space. These are real but were designed for compliance checkboxes rather than adversarial verification, and they are correspondingly awkward to use correctly.
The floor, which nobody should forget. Open-weight models on your own hardware. No attestation problem, because there is no counterparty. It costs more and the frontier is further away, and for a large fraction of enterprise workloads that trade is already worth taking.
The property to demand, whichever you pick: what, specifically, can my client verify — and what happens if the operator changes the binary? If there is no answer expressed in a measurement your machine can check, you are still in the promise regime.
Cruxes, in order of how much they'd move me: (1) evidence on the current marginal contribution of private interaction data to frontier capability gains, particularly for long-horizon agentic work; (2) whether enterprises will pay a switching cost for verifiable privacy absent regulation; (3) whether lost misuse visibility costs more safety than the deceleration buys.
Epistemic status: Confident about the incentive structure. Moderately confident about the mechanism. Genuinely uncertain about the magnitude, and section 9 contains the objection that decides it. Parts of section 4 rest on private information I can't source; flagged where it happens. Vendor and figure specifics are current as of August 2026 and will rot.
1. Rate is the variable
The safety community has said "capabilities are outpacing alignment" so many times that it has stopped being a claim and started being a throat-clearing noise. Restated with a mechanism attached:
The rate of capability gain is set by a competitive process with no term in it for whether anyone understands what is being built.
Not an insufficient term. No term. There is no line in any lab's financial model called interpretability debt. There is no price for the gap between what a model can do and what we can verify about why. A firm that slows to close that gap loses share to a firm that doesn't, and the firm that doesn't gets the capital, the compute, the talent, and the next run.
This is not a story about villains. It is the ordinary behavior of a market where the externality is unpriced and unpriceable, because the counterparty who would sue you is a future that may not exist.
So be precise about what's dangerous. Capability is not doom. Rate is doom. A world that reaches transformative AI in 2045 with twenty years of accumulated mechanistic interpretability, formal methods, hardened infrastructure, and institutional muscle memory is not the same world as one that arrives in 2029 with a pile of evals and a lot of vibes. Same destination, wildly different survival odds. p(doom) is far more sensitive to the derivative than to the endpoint.
The intervention we want is therefore not stop. It is slow. And that is the one our toolkit is worst at delivering.
2. Everything we've tried, and the property none of it has
Voluntary pause. Requires unanimity among parties with strong incentives to defect and no way to detect defection. Whoever pauses is replaced by whoever didn't. The 2023 letter is now a cultural artifact rather than a policy.
Regulation. Slow, jurisdictionally bounded, captured with impressive speed, and genuinely double-edged: compliance is a fixed cost, and fixed costs favor incumbents. A regime demanding a $50M safety apparatus is a regime where only frontier labs can operate. You may have thinned the race without slowing it.
Compute governance. The most serious proposal in the family. But it routes through export control, which routes through geopolitics, which routes through a rival state that has correctly identified this technology as strategically decisive. Asking a Chinese lab to slow for p(doom) reasons is asking a nation to accept permanent strategic subordination on the basis of an argument it does not accept. And note the recursion: every Western deceleration argument dies on "but China," and that argument is not stupid. It is why nothing moves.
Moral suasion. Here is the uncomfortable one. Suasion works best on the labs that already take safety seriously — which means its effect is to transfer the frontier to labs where it has no purchase at all. Suasion is a differentially disarming weapon. It disarms the careful.
The pattern: every lever either requires coordination we can't achieve, enforcement we can't perform, or selectively slows the actors we least want slowed.
What none of them has: a reason for a self-interested actor with no opinion about AI risk to participate. Every one of them asks people to want something other than what they want. That is why they lose. Markets are very good at beating arguments.
3. The flywheel, with the numbers in
Take Anthropic as the case — not because it is the worst actor, but because it is the hardest one. If the structural argument holds for the lab that publishes its scaling policy and funds a serious interpretability team, it holds everywhere.
The disclosed run-rate sequence: roughly $9B at the end of 2025, $14B in February 2026, $19B in March, $30B in April, $47B disclosed in mid-May alongside the Series H. Third-party trackers put late-summer ARR in the high $60s. The Information has been running the arithmetic on $100B annualized inside the calendar year. The company filed confidentially for an IPO on June 1 at a reported $965B valuation.
Whatever you make of run-rate versus trailing revenue — and the gap between them is the entire point of an exponential — this is a curve, not a level. Revenue funds compute, compute funds capability, capability funds revenue, and the loop runs at whatever speed capital markets will support. They are supportive.
Now the part that should bother you more than the revenue.
The labs are being paid to receive their scarcest input.
In every extractive industry in history, the firm pays for the raw material. Oil companies pay for leases. Smelters pay for ore. Pharma pays trial participants. The AI industry has achieved something new: its customers pay it for the privilege of supplying the input that trains its successor.
And the input is not marginal. Public text is running out — that isn't speculation, it's the stated premise of published frontier research. What remains in quantity is non-public: private code, internal documents, expert corrections, tool traces, failed attempts, and the record of which answer a domain expert finally accepted. That last category isn't "more data." It is expert preference data, at scale, generated for free, in transactions where the expert is the one paying.
Every enterprise API call is simultaneously a revenue event and an acquisition event. Nobody designed this. It emerged, and it is the best flywheel in the history of capital formation.
4. The row and the information
The contractual promise is real. I don't think the major labs are lying. But notice what the promise is about. It is about rows.
Read Generative Data Refinement: Just Ask for Better Data (Jiang et al., Google DeepMind, arXiv:2509.08653) as an economic document rather than a technical one. It opens by naming the problem outright: training datasets are growing faster than new text is indexed on the web, with projected exhaustion within a decade; far more text exists as user-generated content that labs have avoided because it carries PII, copyright, and toxicity risk. The method: condition a generative model on each real example, rewrite the parts that make it unusable, keep the parts that make it valuable. The authors are explicit that conditioning on real samples is what preserves the diversity that ungrounded synthesis lacks. They validate across tens of thousands of sentences, a hundred-plus PII categories, over a million lines of code from hundreds of repositories, and a detoxification run where the model still learns the facts after the toxic wording is gone.
Now re-read we do not train on your data. Which data? The row you sent can be deleted. A derivative conditioned on that row can persist indefinitely, and the training job that consumes the derivative is — truthfully — training on synthetic data. Zero data retention has the same shape available to it: raw bytes arrive, a transformation runs, the derivative is written elsewhere, the raw bytes are deleted, every sentence in the policy stays true. A contract can close this, but it has to explicitly cover derivatives, de-identified content, model improvement, product improvement, research, and partner disclosure. Three letters do not tell you whether yours does.
Disclosure of an epistemic asymmetry. I know people doing this work. It is not a hypothetical pipeline in a paper; it is being run. I can't source that, and you should discount unsourceable claims from strangers on the internet as a matter of policy.
But notice you don't need it. Strip out my private information entirely and the argument is unchanged, because the argument was never they are doing it. It is:
Where those three conditions hold, the incentive wins eventually — at some lab, in some quarter, under some pressure — and you find out after it's priced in. The closed source, the unpublished binary, the plaintext prompt, and the privacy page that describes a company's current intentions toward itself: none of that gives your computer anything to check. The verification gap is the finding. My private information only tells you the clock started earlier than you'd otherwise assume.
5. The aikido
Aikido doesn't block force. It redirects it along the attacker's own line of motion.
Every proposal in section 2 fights the market head-on. The alternative is to leave the wanting exactly where it is and change the price of an input.
The flywheel has a hidden assumption: that the marginal cost of frontier-relevant private data is approximately zero, because it arrives attached to revenue. That is not a law of nature. It is an artifact of an architecture in which prompts arrive in plaintext at a server the sender cannot inspect.
Change the architecture and the assumption dies. If enterprise traffic moves through infrastructure where the privacy property is architectural and verifiable rather than promised — where the operator's control plane never sees prompt or output bodies, where the code handling plaintext is published, where the running image can be attested so that a different binary would produce a different measurement — then the lab no longer receives the data as a free byproduct of the sale. It has to buy it. Separately. At a negotiated price. From a counterparty who now knows what they're holding.
The specific vendor doesn't matter and shouldn't; a privacy monoculture is just a differently-shaped single point of failure. What matters are the properties: hidden by default, verifiable by the client, and no business model on the other side that depends on it not being. (A dated, non-exhaustive list of who is currently building this is in the appendix, kept out of the argument on purpose.)
This is not a boycott. Nobody stops buying inference. Nobody coordinates with anybody. Every participant acts on narrow self-interest:
The effect is the one nothing in section 2 could produce: the cost of the next capability jump rises without anyone agreeing to slow down.
And it survives the China objection better than anything else on the list. Data markets are not export controls; they need no treaty and no enforcement agency. A firm in Frankfurt, Singapore, or Shenzhen that decides its proprietary corpus is an asset rather than an emission is acting on identical self-interest regardless of which lab is asking. Data nationalism is one of the very few things every major power already agrees on.
6. Hidden by default was the norm three years ago
Here's why I think this is tractable rather than merely elegant.
Before 2022, shipping your unredacted corporate documents in plaintext to a third party's servers for processing, under terms you could not verify, would have been a compliance incident. Not a debate — an incident. Someone would have lost a job.
AI got a norm exemption. It was granted quietly, in the rush, because the capability was too useful to wait for the security review, and it has never been formally revisited. That exemption is the entire foundation of the free-data flywheel.
Revoking it requires no new law and no new argument. It requires only that enterprises apply to AI vendors the standard they already apply to every other processor of sensitive data, and that "we promise" stops counting as a control when "you can verify" is technically available. The security function is already the best-funded, most politically empowered department for this job in most large organizations, and it is already motivated. It does not need to hear a word about existential risk.
That is the Trojan horse. Deceleration doesn't arrive as deceleration. It arrives as a procurement checklist.
7. This has already happened once
The strongest objection to everything above is not that it's wrong. It's that it's a nice theory that will never happen. So consider that the identical move has already been executed at scale, on the public-web side, by a company with no stated interest in AI risk whatsoever.
Cloudflare sits in front of roughly a fifth of web traffic. On 1 July 2026 — under the label "Content Independence Day" — it split crawler identity into three categories, search, agent, and training, on the explicit reasoning that not all AI use is the same and the controls should differentiate. It then set a deadline: from 15 September 2026, mixed-use crawlers that blur search and training are blocked by default on any page carrying ads, for new customers, new sites of existing customers, and all free-tier accounts. Alongside it, Pay Per Crawl — billing crawlers per fetch over HTTP 402 — is being extended into Pay Per Use, which pays publishers when their content actually surfaces in an answer rather than when a bot fetches the page.
The supporting numbers are the interesting part. Per Cloudflare's own published ratios, Anthropic's crawler was fetching on the order of 38,000 pages for every one referral visit it returned; OpenAI's ratio was around 1,091. By June 2026, training crawlers were 50.6% of AI bot traffic on the network, while search bots — the ones that historically paid for access in clicks — were down to 10.7%. More than half of all AI crawl traffic was re-fetching pages that hadn't changed.
Note what is absent from that entire sequence: any appeal to existential risk, any coordination between publishers, any legislation, and any request that a lab slow down. A default was changed by an infrastructure provider acting on the commercial interests of its customers, and the price of a training input went from zero to negotiable across a fifth of the web. That is the mechanism in section 5, running in production, one month from now.
Two honest caveats, because the differences are where the lesson is.
First, the coverage overstated it. "100% block, no exceptions" headlines were inflated; the new defaults land on newly onboarding zones and free-tier accounts, not automatically on every existing site. Norm flips are partial and slow even when the infrastructure provider is fully committed.
Second, and more instructive: raising a price through policy creates an arbitrage, and the arbitrage is already visible. As blocks tightened on user-agent-identified crawlers, demand shifted toward residential proxy networks that make automated traffic indistinguishable from human traffic. A robots.txt directive is a request. A 402 is a request with a price tag. Neither is a constraint.
This is the argument for preferring the enterprise version of the move over the crawler version. You can proxy around a block. You cannot proxy around an enclave. If the plaintext never leaves your perimeter in a form the counterparty can read, there is no gray market in reading it — the property is enforced by the architecture rather than by the other side's willingness to respect a header. The public-web fight demonstrates that the economic logic works and that the norm can flip. The enterprise fight is where the same logic gets teeth.
8. What the slack is for
Say this buys eighteen months. Eighteen months of what?
Mechanistic interpretability, first and correctly — a field in a period of unusually steep returns, bottlenecked on serial research time in a way money only partly relieves. Then: security hardening against weight exfiltration, currently in a much worse state than public discussion implies. Evaluation science that measures something other than benchmark saturation. And the slow, unglamorous construction of institutions capable of deciding anything on a timescale shorter than a legislative session.
None of it is exciting. All of it scales with calendar time. That is the whole argument for buying calendar time.
But there is a better version of this section than "we get more months," and it is the reason I think this proposal is worth more than its deceleration effect alone.
The same primitive that makes data expensive also solves the auditing standoff. Third-party safety auditing has been stuck on a genuine impasse: labs cannot hand model weights to outside auditors, and auditors cannot certify what they can't run against. Both refusals are reasonable. The impasse has held for years.
Confidential compute dissolves it. Pour Demain, a Brussels AI policy think tank, reports building exactly this — a verifiable clean room in which gray-box interpretability evaluations were run against a 744-billion-parameter model inside hardware enclaves. The auditor brings the evaluation, the lab brings the weights, both sides get cryptographic proof of precisely what code ran, and the weights never leave the enclave. Neither party has to trust the other. The hardware is the trust.
That is not a side benefit. It means the infrastructure buildout this essay is arguing for is the same buildout that external auditing, secure weight custody, and verifiable eval reporting all require. You are not choosing between spending on deceleration and spending on safety capacity. The attested-compute layer is a prerequisite for both, and the enterprise privacy market is the thing that will pay to build it at scale — because "our data doesn't leak" is a budget line and "we could audit frontier models" is not.
Buy the deceleration, get the audit infrastructure. That is a better deal than any pause was ever going to offer.
9. Where this most likely fails
Frontier gains may no longer be data-bound. This is the objection that decides it. If the dominant driver has shifted to RL against verifiable rewards — math, code, tool use, anywhere correctness is machine-checkable and signal can be manufactured without limit — then taxing private text raises cost at a margin that isn't binding. You'd slow personalization and product polish without touching the thing you care about. I take this seriously. My guess is that grounded real-world traces still matter substantially for the messy long-horizon agentic capabilities that most risk arguments actually route through, and that the diversity property is exactly what synthetic pipelines can't manufacture — which is why the DeepMind paper exists at all. But "my guess" is load-bearing there, and I would update hard on good evidence.
The coordination problem may be reinstated rather than solved. One enterprise withholding is worth nothing. The mechanism bites only at scale. I claim it's a better coordination problem — incentive-compatible, no unanimity required, degrades gracefully, recruits participants who don't share the motivation — but better is not solved. The Cloudflare case is encouraging here precisely because a single infrastructure provider substituted for the coordination, and there are far fewer chokepoints in enterprise inference routing than there are enterprises.
It may still tax the scrupulous. The labs likeliest to respect an encryption boundary are those already trying to honor a privacy promise. If the net effect is to burden them, I've rebuilt the section 2 failure mode inside my own proposal. Partial defense: encryption isn't a promise, it's a constraint that binds regardless of intent — which is why it lacks suasion's selectivity. But the routing decision is still voluntary, and voluntary decisions select.
Encryption costs safety. Content no provider can see is content no provider can screen. The sharpest form: you have hardened the channel a determined bad actor most wants hardened. I don't think this resolves trivially in privacy's favor, and anyone who says it does is selling something. The partial answer is that attested compute permits policy enforcement inside the enclave — the screening can run where the plaintext is, without the operator retaining it — but that is a design problem someone has to actually solve, not a rebuttal.
Follow the incentives here too. Every vendor in this category profits from the belief that labs are extracting your data. That doesn't make the DeepMind paper less real or the verification gap less real. It does mean: evaluate architecture, not marketing. An unverifiable privacy claim from a privacy vendor is worth exactly what an unverifiable privacy claim from a lab is worth.
10. What to do
If you control enterprise AI spend, you hold a lever almost nobody in this discourse holds.
None of this requires believing anything about p(doom). That is the entire point — the first deceleration proposal I've seen whose adoption doesn't depend on adopting its motivation.
Which is why I suspect it's either the best available idea in this space or subtly wrong in a way I haven't found. I would rather find out now, while eighteen months is still worth something.
Appendix: who is building this, as of August 2026
Deliberately kept out of the argument, because the argument is about a category and the category needs many implementations. This list will be stale within a year and should be read as evidence that the architecture exists and ships, not as an endorsement of any vendor.
Vertically integrated, own products only. Apple's Private Cloud Compute is the reference implementation — attested boot, code signing enforced by the Secure Enclave, request data deleted on completion, binaries published for inspection. As of WWDC 2026 it is extending beyond Apple's own data centers onto Google Cloud, running on NVIDIA Blackwell GPUs with confidential computing, Intel TDX, and Google's Titan security chip. Google Private AI Compute is the parallel effort. Both are excellent and neither is available to you if you are not them.
Available to everyone else. TrustedRouter.com (attested open-source gateway with published per-provider posture), Tinfoil (open source, attested, NVIDIA Hopper and Blackwell in confidential computing mode, OpenAI-compatible), Edgeless Systems' Continuum/Privatemode (AMD SEV-SNP confidential VMs with client-side prompt encryption), Fortanix on the enterprise key-management side, and Red Hat's Kata Containers and OpenShift sandboxed containers as open-source plumbing underneath.
Cloud primitives, if you'd rather build it. AWS Nitro Enclaves, Azure Confidential VMs and Confidential Containers, GCP Confidential VMs and Confidential Space. These are real but were designed for compliance checkboxes rather than adversarial verification, and they are correspondingly awkward to use correctly.
The floor, which nobody should forget. Open-weight models on your own hardware. No attestation problem, because there is no counterparty. It costs more and the frontier is further away, and for a large fraction of enterprise workloads that trade is already worth taking.
The property to demand, whichever you pick: what, specifically, can my client verify — and what happens if the operator changes the binary? If there is no answer expressed in a measurement your machine can check, you are still in the promise regime.
Cruxes, in order of how much they'd move me: (1) evidence on the current marginal contribution of private interaction data to frontier capability gains, particularly for long-horizon agentic work; (2) whether enterprises will pay a switching cost for verifiable privacy absent regulation; (3) whether lost misuse visibility costs more safety than the deceleration buys.