The Real Question

I think that Fareed Zakaria’s Washington Post column identifies a real problem but presents a solution that is far too complex and, indeed, misses the nature of the regulatory problem:

The central AI problem is not consciousness; it is agency. A system need not feel anger, ambition or fear to cause harm. It needs only a goal, enough intelligence to pursue it and enough access to the world to act. AI’s are not “going rogue”; they are trying to succeed any which way they can.

This is a systemic problem that we cannot leave to the good graces of private companies. When thinking about regulations, we should focus centrally on how much autonomy we give these systems. A chatbot that answers a question poses one set of risks. An agent that can browse the internet, execute code, obtain credentials, move money or operate critical infrastructure poses another. The principle I would propose is simple: Autonomy should expand only as our ability to monitor and control it expands.

I think the solution is simultaneously simpler and older than Mr. Zakaria imagines: strict liability that attaches both jointly and severally to the model developer, API developer, the application developer, and the corporate deployer. If that strategy were used, insurance would become an important part of AI governance.

If an AI system causes legally recognizable harm, the injured party need not establish negligence, recklessness, intent, or a defect in the model. The plaintiff must establish the harm, causation, and a legally defined connection between that harm and the entity that supplied or deployed the AI service. An insurer asked to cover an autonomous AI service would want to know about sandboxing, permissions, audit trails, model evaluations, financial authority, network access, kill switches, and incident history. A poorly controlled autonomous agent would become expensive or impossible to insure.

When liability attaches both jointly and severally the plaintiff need not identify the source of harm specifically. Only that harm was done and AI was part of the chain that produced it.

Joint and several liability is important here. The injured party should not bear the burden of determining which participant in an opaque technological supply chain was ultimately responsible for the behavior that caused the harm. Let the parties that designed, supplied, integrated, and deployed the system allocate that responsibility among themselves through contracts, indemnification, contribution, and insurance.

Zakaria’s safeguards would not disappear under strict liability. They would become the things an AI developer or deployer must demonstrate in order to obtain affordable insurance.

1 comment

Okay, I’ll Bite

I was rather disappointed by the Washington Post op-ed written by Lewis Libby and Jason Fields. They described their objectives well enough:

Coercion, not ideological fervor, buoys the Islamic republic. To sustain an unpopular regime, the core believers recruit thousands of trigger-pullers who brutalize civilians. They also pay regional proxies, in cash and in weapons, to intimidate foes and to spread an image of a hegemonic Iran. The domestic opposition calls them “mercenaries.” They don’t come cheap. Oil — and crucially, the promise of future oil revenue — greases the empire.

and

The regime’s supporters are likewise reassured by steps that Washington hasn’t taken. The U.S. military hasn’t destroyed Iran’s major oil production and export facilities, as the Allies did to Germany and Japan in World War II. U.S. sailors have escorted tanker traffic through the Strait of Hormuz, but that effort has been nowhere near the scale of the operation President Ronald Reagan ordered in the 1980s. Ground troops haven’t seized the coastline or the regime’s enriched uranium stockpiles, much as the United States was willing to do in Kuwait and Iraq in the 1990s and early 2000s. America hasn’t bearded Iran’s patrons, China and Russia, either.

The shortcomings of the piece were that the authors didn’t describe how we could accomplish those goals without violating the laws of war. Which Iranian oil production and export facilities would constitute lawful military objectives under the laws of war, and on what basis? How do they suggest we “beard” China and Russia? Should we bomb them? Target their political leadership?

All of that points to the difficulties in breaking a regime’s internal coercive apparatus while maintaining the international commitments into which we’ve chosen to enter using air and naval power alone.

1 comment

The Real Bolsheviks Were Like That, Too

I found Gary Rosen’s Washington Post op-ed contrasting the Democratic Socialists of America with the historical Bolsheviks sadly amusing. Here’s a snippet:

The Democratic Party is not in the grip of a “Bolshevik revolution,” as House Majority Leader Steve Scalise (R-Louisiana) claimed from the stage of the GOP’s midterm convention last week in Dallas. Nor is it true, as President Donald Trump declared, that “it’s going to be a communist country” if the Democrats win in November. House Speaker Mike Johnson (R-Louisiana) was a bit closer to the mark when he said, “Next year the communists will be in Congress.”

What’s fair to say is that a handful of this fall’s Democratic candidates, many of whom will no doubt win seats in Congress, are proud members of the Democratic Socialists of America, which revels in Marxist rhetoric and whose ranks include a not-insignificant minority of self-identified communists. This ideological insurgency is a gift in a big red bow for Republicans, who need to overcome Trump’s abysmal approval ratings, and a political nightmare for floundering Democrats. The fact of the DSA’s radicalism cannot be disputed.

The real question is how seriously to take it. I tend to think not very.

Clearly, he has not spent enough time with Lenin’s April Theses. In April 1917 the Bolsheviks were a minority, their program seemed wildly unrealistic to many contemporaries, and Lenin himself prescribed patient persuasion rather than an immediate seizure of power. Six months later they took power.

That does not make the DSA the Bolsheviks, nor is the United States of 2026 remotely comparable to Russia in 1917. But it does expose the weakness in Rosen’s argument. He is comparing today’s DSA with the Bolsheviks as they appeared after they had seized power. The relevant comparison would be with the Bolsheviks when they were still a relatively small radical movement that many contemporaries regarded as doctrinaire, unrealistic, and unlikely to govern.

The lesson of the Bolsheviks isn’t that every collection of starry-eyed radicals eventually becomes a dictatorship. Obviously it doesn’t. It is that being starry-eyed, naive, numerically small, or even faintly ridiculous is not evidence that a radical political movement should be taken unseriously. Political circumstances change.

And Russia was hardly the only country in the twentieth century in which a radical movement changed character rapidly as it acquired political power.

As additional counter-evidence, I would submit that bona fide Democratic analysts Ruy Teixeira and John Halpin take the possibility of an ideological capture of the Democratic Party considerably more seriously than Rosen does. Their concern is not that the DSA is about to storm the Capitol and establish a dictatorship of the proletariat. It is that a relatively small but highly motivated ideological faction can exert influence over a much larger political party out of proportion to its numbers. Cf. Ruy’s most recent post.

That strikes me as the question Rosen should be addressing.

6 comments

It’s Internet Traffic

A commenter to a post recently complained that LLM AI had induced a sharp increase in data center construction. The chart above puts the increase in data centers into historical context. The expansion of data-center capacity clearly predates the widespread adoption of LLMs. LLM AI may have accelerated that expansion, but it did not initiate it. It does illustrate increases, particularly since 2010, in utilization of the Internet. The iPhone was introduced in 2007.

In other words the demand for new data centers is a continuation of a process that has been going on for some time.

13 comments

What’s Goin’ On?

ChatGPT first became publicly available in November 2022.

Claude.ai launched in July 2023.

According to the United States International Trade Commission as of January 2021 there were about 8,000 data centers worldwide. The United States has around a third of the data centers. The U. S. government has nearly 1,000.

Data are being created very rapidly, much of that is online, and data centers are needed to store it. According to the MMCG, a real estate investment/data research firm, the number of data centers under construction in the U. S. as of June 2026 was roughly 162.

By and large data centers aren’t used specifically for LLM AI; they’re used for data more generally. Modern data centers are used for cloud computing, storage, websites, streaming, enterprise applications, databases, content delivery, AI training and inference, and much else. Worldwide data creation and replication went from 2 zettabytes in 2010 to 64.2 zettabytes in 2020 (a zettabyte is a billion gigabytes).

I can understand NIMBY impulses; there have been concerns about data center construction locally for decades. I cannot understand outright opposition to the construction of data centers and the tone and just plain hysteria of the complaints. Why not five years ago? Why not ten?

None of this is to say that there are no legitimate objections to particular data centers. They consume electricity, require infrastructure, may consume substantial amounts of water, and can impose real costs on the communities in which they are located. Those are reasonable subjects for zoning, regulation, and negotiation.

But they aren’t new.

Neither is the growth in demand for data centers. Long before ChatGPT appeared, Americans were streaming video, moving corporate computing into the cloud, storing photographs and video online, shopping online, operating enormous databases, and generating ever-increasing quantities of data. Data-center capacity was expanding to accommodate those uses.

What is new is the intensity of the opposition.

That raises an obvious question. If the objection is actually to data centers, why didn’t we see comparable opposition five or ten years ago?

One possible answer is simply scale. Today’s projects can be much larger and much more demanding of the electrical grid than their predecessors. That undoubtedly explains some of the increased concern.

But I don’t think it explains all of it. Something else changed at almost exactly the same time: data centers acquired a new public identity. They became “AI data centers.”

And that suggests that at least some of what is being expressed as opposition to data centers isn’t really opposition to data centers at all. It is opposition to AI, Big Tech, and the economic and social changes with which they have become associated.

There is, of course, a simple way to reduce the need for additional data centers: reduce our use of the services that require them.

Stop streaming video. Stop storing photographs and documents in the cloud. Stop using social media. Stop shopping online. Stop using cloud-based business applications. Stop using smart doorbells, smart thermostats, connected automobiles, smartphones, tablets, and PCs connected to the Internet. And, yes, stop using LLM AI.

I don’t expect that to happen.

What we call “the cloud” has a physical existence. It consists of data centers, fiber-optic cables, electrical generating capacity, transmission lines, substations, cooling systems, and all of the other infrastructure required to deliver the online services we increasingly demand.

We cannot simultaneously demand ever more online services and reasonably expect the physical infrastructure supporting those services to stop growing.

That does not mean that every proposed data center should be built wherever its developer wants to put it. Questions about location, water, electricity, noise, taxation, and who pays for necessary infrastructure are perfectly legitimate.

But those are arguments about how and where data centers should be built. They are not arguments that we don’t need them.

6 comments

A Modest Proposal for Regulating Artificial Intelligence

I ran across an interesting post by Kevin Bass about Anthropic, AI safety, and the network of organizations involved in evaluating the risks posed by AI.

I don’t endorse everything in the post. In particular I don’t think it is necessary to assume corruption, conspiracy, or even bad faith to recognize the problem he identifies.

The problem is incentives.

Anthropic has been among the loudest voices warning that advanced AI may pose extraordinary risks. It has also advocated government regulation of frontier models, including independent evaluations intended to determine whether those models pose unacceptable risks.

Let’s assume they’re right.

Indeed, let’s go considerably farther than that. Let’s give Anthropic the keys.

If Anthropic really has the expertise to determine what constitutes a dangerous AI model, put it in charge of developing the standards. Give it an important role in evaluating models. Give its recommendations substantial regulatory force.

There should be one condition.

Anthropic can’t profit from it.

I don’t mean that figuratively. Congress has considerable power to establish the conditions under which governmental authority may be exercised. We already have conflict-of-interest laws, disclosure requirements, divestiture requirements, procurement rules, and restrictions intended to prevent people from using governmental authority for their own financial benefit.

Use them.

Construct whatever legal mechanism is necessary so that Anthropic, its principals, and those exercising the delegated authority cannot become richer because of the regulatory regime they devise. That might require divestiture. It might require some sort of regulated return. It might require a special corporate structure. Those are details for lawyers to work out.

The principle is simple enough: you can have the keys or you can have the money. You can’t have both.

There is a reason for doing that which has nothing to do with whether anyone at Anthropic is honest.

Regulation creates barriers to entry. The more elaborate the testing requirements, the more expensive compliance becomes. A company already spending billions of dollars developing frontier models is in a much better position to comply with a regulatory regime requiring billions of dollars than a prospective competitor is.

Consequently a company can advocate regulations for perfectly sincere reasons and still benefit enormously from them. The regulations may protect the public. They may also protect the incumbent.

Both things can be true at the same time.

That is why I don’t think accusations of corruption are particularly useful here. We don’t need to know what is in anybody’s heart. We can remove the conflict instead.

There is another advantage to this approach. It would provide a pretty good test of revealed preference.

If the people at Anthropic actually believe that frontier AI presents risks to human civilization sufficiently grave to justify extraordinary governmental intervention, asking them to surrender the opportunity to make extraordinary private profits from that intervention doesn’t seem unreasonable.

The greater the danger, the stronger the argument becomes.

Conversely, if the response is that giving up those profits would be intolerable, perhaps the situation is not quite as extraordinary as we have been told.

I don’t expect anything like this to happen. The major AI companies would oppose it. The investors would oppose it. Quite possibly the AI safety organizations would oppose it. There would be endless arguments that government could not afford to lose access to the expertise concentrated in the companies actually developing frontier AI.

My proposal doesn’t lose that expertise.

Use it.

Give Anthropic the keys.

Just don’t let them own the tollbooth.

3 comments

One Neat Package

A high-ranking Chinese official explains why China may cooperate in trying to control the pace of development of LLM AI and why such plans won’t succeed in one neat package. Carol Yang reports at the South China Morning Post:

China’s top intelligence official has warned of rising national security risks posed by artificial intelligence (AI), calling for robust risk prevention frameworks and stronger global governance of the emerging technology.

The call from Chen Yixin, China’s state security minister, comes as Beijing seeks to play a leading role in global AI governance while criticising US restrictions. At the Brics summit in India over the weekend, Chinese President Xi Jinping proposed an AI-powered initiative to drive new industrialisation and deepen supply chain cooperation in the emerging economies bloc.

Chen underscored Beijing’s view of the technology as a key geopolitical battleground. AI has become “a new arena for strategic rivalry among major powers”, he wrote for China Cyberspace, a journal run by internet watchdog body the Cyberspace Administration of China.

The aspects of the matter are:

  1. China has reasons to fear uncontrolled AI because of regime security.
  2. China also has enormous incentives to exploit AI for strategic advantage.
  3. The United States faces analogous strategic incentives.
  4. The technology and expertise are already too widely distributed for an agreement between two governments to control development reliably.

Consequently, even if the U. S. and China reach an agreement to slow the pace of development there are quite literally millions of people in the U. S. and China with the knowledge, training, abilities, and resources to keep right on developing it and reasons to do so.

Feel lucky, punk?

0 comments

Define “Terrorism”

Inspired by last week’s remembrances of the attacks on 9/11, I set out to research the prevalence of terrorist attacks in the United States since then. What I learned astonished me. What surprised me was not how common or rare such attacks have been but how controversial the definition of terrorism itself remains.

There is no internationally accepted definition of terrorism. Or, rather, there are lots of definitions—there is no single accepted one.

I would define terrorism as violence or the threat of violence intended to coerce public action by frightening or intimidating a population for a political or ideological objective. That definition has several components: violence or its threat; intimidation extending beyond the immediate victims; an attempt to coerce action; a political or ideological objective; and some question of who or what may legitimately be targeted. Somehow one or more of those components has eluded agreement whenever the international community has tried to define terrorism.

One distinction seems particularly important. Political violence is not necessarily terrorism. Political assassination is not necessarily terrorism. Anti-government violence is not necessarily terrorism. Terrorism is distinguished not merely by the motive of the perpetrator but by the use of violence to intimidate a broader population in order to coerce political action.

I can’t help but wonder whether the reason a definition has eluded us is that a rigorous definition would constrain the parties doing the defining. A definition broad enough to encompass everything one side wants to condemn may also encompass actions by itself or its allies that it considers legitimate.

2 comments

Quit While You’re Behind

The moment that many of us have been dreading has arrived. Chicago Mayor Brandon Johnson has announced that he will seek re-election. ABC 7 Chicago reports:

CHICAGO (WLS) — Chicago Mayor Brandon Johnson said he will run for reelection.

The mayor has been hinting at is announcement with plans for a “special announcement” on Sunday.

Johnson posted a two-minute video ending with people chanting “four more years” on X.

He later posted: “I’m here because I’m the only candidate who’s fighting for working families. If you’re ready for a safer and more affordable Chicago, then now is our time!”

Johnson is entering an already crowded race. At least 11 candidates have already announced their intentions to run.

To place that in perspective consider the approval ratings of previous incumbent Chicago mayors when they decided to run for re-election:

Mayor Approval rating
Richard M. Daley 41%
Rahm Emanuel 42%
Lori Lightfoot 22%

Some recent polls have shown Johnson’s approval rating in single digits. If the CTU decides to support his candidacy again of which I have little doubt, at least he’ll have that going for him.

2 comments

The Biggest Dilemma

I just finished hearing the CEO of Anthropic say the following on one of today’s “talking heads” programs:

The biggest dilemma is how we get China to agree to join the agreement on regulating the pace of AI development.

but I think he’s wrong. The dilemma that’s bigger than that is how we prevent a country we support that’s engaged in an existential conflict against a larger foe from developing their own LLM AI that breaks all the rules when it means their survival as a country.

That’s also the problem with Megan McArdle’s more modest and seemingly more doable agreement which she describes in her most recent Washington Post column:

Sure, I can imagine China and the United States coming to a rapid-fire agreement for an AI pause. But then, I can also imagine getting a MacArthur “genius grant,” which seems about as likely.

So back to my question about the murderbots. Could we at least not build the literal, physical murderbots, such as fully autonomous drones that can operate without humans in the kill chain? Controlling their development would be a very hard problem, as all arms control is. But it seems more manageable than completely stopping AI advancement.

Consider her proposal in the context of Ukraine. Should we actively discourage even prevent Ukraine from developing their own “murderbots” if they make the difference between their victory or defeat against the Russians?

The bigger dilemma may be how you construct an AI arms-control regime that remains rational to obey when one of its members believes violating the rules is necessary for national survival.

There’s an even more elementary problem. Suppose Anthropic, OpenAI, xAI, and Google agree on rules limiting what their LLM AIs may do. What prevents a well-financed startup from developing an LLM AI that ignores those rules?

If the prohibited capabilities are useful, that company’s product may be more competitive precisely because it breaks the rules. The agreement would then have accomplished something rather peculiar: it would have imposed competitive disadvantages on the companies that agreed to it while creating an opportunity for companies that did not.

Preventing that requires something considerably more ambitious than an agreement among AI companies—or even an agreement between the United States and China. It requires preventing *anyone capable of developing the technology* from defecting when there is an economic or strategic advantage in doing so.

Now consider Ukraine. If we cannot be confident that a startup will refrain from breaking the rules for money, why should we expect a country to refrain from breaking them when its leaders believe national survival is at stake?

0 comments