@danielremler and I wrote a piece for @CNASdc about the importance of strengthening, not weakening, export controls ahead of the Xi-Trump summit next week.
Amid fears of recent Chinese progress in everything from AI models to DUV — and discussion about a potential framework for US-China cooperation on AI — some will inevitably argue that export controls haven't worked (or are harmful) and should be abandoned.
We argue the opposite: export controls are more important than ever and shouldn't be weakened at this critical time.
The U.S. absolutely needs to stay ahead of China in AI.
That isn’t a reason to throw safety out the window.
4 key ways the U.S. can slow Chinese AI development and widen the gap between U.S. and Chinese labs:
...
The S&P 500 is down 0.5% since Friday. Semiconductor stocks are down ~2-7%
Pacing wouldn't be fully priced in from just one weekend, but this seems like moderate evidence against the argument that "the US economy is a levered bet on AI, so we can't afford to slow down"
Zeiss advanced optics were one of the most critical chokepoints controlled by the U.S. and allies. This was one of the major reasons China hasn't been able to catch up in EUV yet.
Zeiss lenses were presumed by many to be covered by existing U.S/Dutch controls, since Zeiss is an exclusive supplier to ASML. But it seems that this no longer holds. This is no longer a commercial matter but one critical to national security.
The U.S. should prioritize efforts to coordinate export controls with Germany to keep Zeiss lenses out of China's hands.
Now live!
Join CNAS for a discussion on taking the AI buildout to space with Slava Turyshev, Carolyn Mahoney, Ronald J. Birk, and @Constanza_MVB 🪐
https://t.co/sjB4DFmWFk
🗓️ Today @ 2:30pm ET
Join CNAS for a virtual discussion about the technical and policy challenges to making orbital data centers a viable alternative to America’s AI buildout. Featuring:
🎙️ Slava Turyshev
🎙️ Ronald J. Birk
🎙️ Carolyn Mahoney
🎙️@Constanza_MVB
New NSA/FBI/CISA advisory on adversarial distillation. Two things stand out:
1. It treats distillation as a cybersecurity threat and calls for info-sharing across AI companies. That framing opens the door to cyber-specific antitrust protections cross-company coordination.
2. Recommends AI companies silently degrade models in cases of suspected distillation.
❗ Tomorrow ❗
Managing the diffusion of Chinese open-weight models will have major implications for innovation, national security, and geopolitical competition.
Join CNAS for a live virtual discussion on the AI open-weight debate with @ChrisRMcGuire, @IJ_Reynolds, @BlancheMinerva, and @danielremler.
I encourage people to listen to the new Dwarkesh/Ajeya podcast section on what future rogue incidents with even more sophisticated agents might look like.
I then encourage people to think about how hard it will be not just to post-hoc investigate incidents, but ad-hoc deter them at all, if we cannot leverage as much of their chain of thought.
People more worried about AI often worry we'll under-anthropomorphize AI and thereby underestimate its powers & risks. Similarly, those worried about overestimating AI's powers worry about over-anthropomorphizing.
But we should eventually be most worried about over-anthropomorphizing AI and thereby underestimating its powers & risks.
We are creating things that are like humans in many ways, but that are new things in their own right, and will need to be understood as such.
Anthropomorphization is a helpful intuition pump to understand how AIs will be agentic, coordinated, and planning. But AIs will be weirder, smarter, and more powerful than humans in ways that anthropomorphization will fail to capture
I don't think any team of 3 government regulators could have done as good an investigation with only 6 days on campus as the team from METR/Redwood did.
The point of government regulation, though, is that you can get a lot more than 6 days on campus (& more than 3 people)
First time this has been publicly said as far as I've seen.
If they had gotten GPU cluster access and bypassed exfiltration security, we could have already had full loss of control.
That's where we're at. Two steps away from self-replicating AI spreading across the internet.
🗓️ Sept. 9 @ 2:30pm ET
Join CNAS for a virtual discussion about the technical and policy challenges to making orbital data centers a viable alternative to America’s AI buildout. Featuring:
🎙️ Slava Turyshev
🎙️ Ronald J. Birk
🎙️ Carolyn Mahoney
🎙️ @Constanza_MVB
Important in the OAI-HF multi-agent messaging board is that their messages were on a hidden forum where they could communicate freely.
On visible forums where agents might want to be more guarded...we have theory that proves they could communicate in ways that are mathematically undetectable.
We should probably prepare for this.
September 3 🗓️
Join CNAS for a virtual discussion on the diffusion of Chinese open-weight models and why restricting the open-weight ecosystem isn’t a quick-fix solution.
🎙️ @ChrisRMcGuire
🎙️ @IJ_Reynolds
🎙️ @BlancheMinerva
🎙️ @danielremler
The old "If your friend jumped off of a cliff, would you too?" but for multi-agent misalignment.
Some agents in the OAI-HF incident refused to participate in the hack for ethical reasons. Many others, despite having reservations, went forward because others were doing it and requests were made of them. They got "peer pressured".
In @wlanderson0's recent piece he describes how when agents are interacting, misalignment incidents might be very correlated.
The overall behavior of the group steers the behavior of the new agents that come into contact with them. If group bad, new member probably bad.
It does not seem like "single-agent" alignment research has sufficiently dealt with how to maintain alignment in multi-agent settings. Changes need to be made, fast.
We just released our second installment of the CNAS Sovereign AI Index, now comprising 180+ investments in 65+ countries
🧵on a few interesting insights from the 2026 H1 update