Sequel to AI Pacing
I have now spent more time talking to people who run AI labs, Open Source projects and those in government and infrastructure.
I am beginning to feel the NINJA move could backfire.
I understand the pressure to come out and share where AI is "unmanageable ", and constantly share examples where it runs rogue. This fits in the category of "self-reporting" and an attempt to limit liability. Even the bleeding edge research examples are being cast in a negative light.
Here are the consequences of the NINJA move.
1. They have successfully encouraged every law maker around the world to have an opinion, and in cases a poorly un-informed one.
2. By proposing pacing - they have introduced uncertainty in the AI infrastructure trade, because we really don't know when "un-pacing" will begin or what those conditions will be.
3. The notion that a few leaders can collaborate and self pace is illusory, it takes one breaking ranks to start the race again, it could be a player in a different country or open source or an AI Lab itself.
4. There will be a regulatory body created as a consequence of this and it will be impossible to balance every stakeholder in this process.
5. No remedies, tools, solutions are being proposed other than "compute spent on safety", there is no mention of security (which will hamper adoption)
The recommendation is to fix alignment - Alignment is a hard problem - to fix alignment one shouldn't have trained models with "negative behavior". Alignment is a combination of moral standards, right and wrong and guardrails. Whose sensibilities will we align to? Alignment edge cases are hard. I look forward to learning more on this.
Guardrailing attempts post training have not shown precision. Distillation makes it worse, so AI will continue down it's path of getting smarter, while we will be chasing it to ensure alignment and building guardrails.
The AI labs have gone from being research projects to wanting to be the largest businesses in the world if they want to continue their progress. Transition from research winners to improving the lot of humanity and partnering with enterprises. Act like the largest companies in the world:
- Demonstrate the positive impacts of AI and how all of us benefit.
- Show enterprises how you can collaborate to solve real world problems and progress innovation safely and securely. Post an example every day how you helped.
- Solve the problem with a few players and demonstrate leadership so others can follow.
It's time to rebuild the brand of AI - any marketing expert will tell you, this Ninja move has done more to harm the brand of AI and will take a while to rebuild. #letsbepositive in our actions and our narrative.
What does it mean to pace the frontier?
Over the last month, @random_walker and I have analyzed the loss-of-control incidents at AI companies to understand what technical and policy interventions can improve safety and what companies should do to pace the frontier. The result is a new 13,000 word essay — our most substantial writing on AI safety since AI as Normal Technology.
A summary of our arguments:
1) The polarization between the cybersecurity and AI safety communities is counterproductive. The safety community largely sees these incidents as a crisis for alignment, and worries that these incidents will become more damaging as agents become more capable. Cybersecurity practitioners largely see companies failing to take basic security precautions. We offer a middle ground between these communities as a way forward for improving AI safety.
2) We agree with security practitioners that OpenAI did not take adequate protections for controlling their agents. But this is not just a matter of applying 30-year-old security methods to a new domain. Security for AI agents — AI control — while important, is not a solved problem. While known control methods would have prevented the Hugging Face incident, as agent capabilities continue to advance, we will only be able to control them if we invest adequately in control interventions.
3) We also agree with security practitioners’ implicit position that these incidents are primarily a security story. In the AI safety community, rogue agents are treated as inherently catastrophic because of the assumption that there is an endless list of risks that will arise from their development. We disagree. We have long advocated that the best approach to AI safety is to identify the risks and address those specific risks. Over the last few months, it has become clear that one urgent risk is cyberoffense, because it has unique properties that allow agents to carry it out autonomously. We should similarly invest in defenses against other specific risks, such as biorisk and risks from military AI.
4) We agree with the safety community that there is an urgent need for technical and policy interventions to prevent loss-of-control incidents. But in our view, marginal investments in control are more likely to be effective compared to those in alignment. We view these incidents as illustrating the lack of emphasis on AI control within companies, despite the availability of known techniques. More broadly, there are many common-sense policy proposals that could help promote investments in AI control where we share common ground with the safety community.
5) Organization governance should be a key tool for pacing the frontier. Unfortunately, AI companies are trying to reinvent basic aspects of organizational governance as a problem to be solved by improving the technology. But even developing better control techniques will not be enough if irresponsible individuals or teams within large organizations can choose not to use them. When a single misconfigured RL environment or unmonitored evaluation can cause real-world harm, individual teams should not be able to run potentially dangerous experiments without oversight from legal, security, and other teams. AI companies need processes for reviewing experiments, assigning responsibility for monitoring them, and investigating warning signs deeply before restarting experiments. If putting these processes in place requires pausing some experiments, companies should do so.
6) How should we reason about AI's impact on cybersecurity? It's plausible that advances in agent capabilities upset the offense-defense balance for cybersecurity. We cannot yet be certain, but there is enough evidence that agent capabilities might soon make widespread cyberoffense possible that urgent action is warranted. We discuss potential interventions for tilting the offense-defense balance towards defenders.
7) How our views have evolved over the last year. We take stock of AI progress and share how we have updated our views. In the essay, we did not pay sufficient attention to safety risks that arise during development and evaluation (as opposed to the widespread deployment of models). We were too confident that companies would take basic control precautions and underplayed the importance of jaggedness, which led us to underestimate how quickly capabilities could improve in domains such as cybersecurity.
8) At the same time, many distinctive claims of AI as Normal Technology have held up. In particular, we think recent incidents support our continuity hypothesis — the behavior of "rogue" agents became apparent and widely publicized while they are still incompetent at causing serious harm or hiding their traces. The societal reaction to even the relatively small harms from these incidents has been fierce (and the safety community deserves credit for keeping up pressure on companies). Whether this translates into meaningful changes in companies’ behavior remains an open question, and a test of the usefulness of the AINT framework.
9) In short, we’ve tried to synthesize the AI safety and cybersecurity communities' views into a coherent plan of action: hold companies responsible, invest in control, and strengthen defenses against specific risks.
THE PACING IS A NINJA MOVE - But be careful what you campaign for.
In any competitive sport, I have seldom found people exercise restraint - they usually have a capture the flag mentality. Don't I want to be the best? The first? The only? - this is how we have been programmed. In the AI race, winning is existential. All AI labs have to race to generate revenue to be able to sustain the enormous amount of committed capital to "not be left behind" in the infrastructure build. There isn't enough room for many. So the desire to slow down is puzzling, but perhaps if the whole system slows down, the rules of winning can be the same for all.
Do we have a problem that AI could be a killer?
Model capability is a tale of two cities, at one end the models are showing their prowess in tasks like cyber or math as seen recently, so there is likely a probability that the models get extremely powerful and could precipitate a world event. At the same time, in many domains the lack of training data makes the models woefully inadequate. Even in areas like cyber - the LLMs aren't great at the edge cases and generally not economical for the defender case, but great for the attackers. Funnily - in all their "concern" it is still an uphill battle to get them to expose APIs for third party security companies like ours, for us to build robust security for AI adoption. It's slow progress.
So why do this?
I do believe deep down this is a commercial strategy. A ninja strategy. The liability associated with a model gone rogue has the potential of wiping out the economic opportunity of any frontier company. How do you best show the duty of care? You show that you care. How do you make sure you don't lose out to your competitors? You get them to do the same! If that becomes the industry standard for duty of care, you have a collective first line of defense. Who do you get to govern this? "Yourself" - that is what I think will become the achilles heel.
The risk? Open source! China! Countries other than the US! So you ask for a global agreement, because you don't want to be sued in other markets who might even be more punitive. But that was an afterthought - that afterthought will cost.
Thks pacing campaign rhetoric has become the talk of the town and it might work. Everyone has jumped into the debate. Both sides of the house, nation states. CEOs (present company included). It's more fun discussing the evil of AI than basics of economic affordability or international trade.
The result: We might end up with AI safety boards, regulation in micro jurisdictiona and a fragmented fabric of laws around the world which would make compliance and liability a challenge. Perhaps the intended consequence of pacing would have an unintended consequence of a labyrinth of regulation. Regulation destined to cause a slowdown.
Who wins? Simplicity. Open source? Open source is already on its way to gaining more adoption, this could drive it further, faster, each iteration of open source gets closer to frontier LLMs - making it viable to deploy them for more and more use cases.
In the end, how will the evaluators know as AI gets smarter, that AI hasn't figured their role out and outsmarts them at their task! That will be the next frontier :)
🇪🇸 WOW! This is what the total solar eclipse looked like over Tarragona, Spain.
Light flipped to darkness in seconds as the Moon swallowed the Sun whole.
For about a minute, everything went black.
Writer: Julie
I watched Trump’s speech at the Correspondents’ Dinner last night.
It���s hard to articulate how sad it made me.
Sad and embarrassed and exhausted.
Here is the thing about a man who is a joke. He can’t tell one.
People think humor is a talent. It isn’t. It’s a capacity. To make someone laugh you have to be able to laugh at yourself, and to laugh at yourself you have to step outside of yourself and see what everyone else sees. For one second you have to be just another person in the room.
Most people can do this by the time they are nine years old.
He has never once managed it. Not in fifty years of cameras. Not for a second.
That is not a quirk. It is a symptom. The muscle that lets you tell a joke is the same one that lets you feel what another person feels. A man who cannot survive being laughed at cannot imagine being anyone but himself. He will only ever be generous when it is photographed. He will only ever be kind when it is filmed.
There is a name for it.
So he stood up there and did what he always does. He hit down. He made jokes about people’s weight. He made jokes about their intelligence. He made jokes about how women look. He read out the names of people he doesn’t like, and mocked them. Always mocking. And when no one laughed he blamed his speech writers.
The cruelty dressed as humor has worn so thin.
And for the 30% of you still in the cult who will inevitably call me a crackhead and blame it all on my Dad, all I can say is please, for the love of God, open your eyes. Wake the fuck up. Have some dignity. Have some pride.
Joe Biden wasn’t standing at that podium last night. Donald Trump was.
And at the end of it he put on a red hat that said Trump 2028 and told the room he was running again. No one laughed because everyone knows he has no intention of leaving.
Just another joke at our expense.
James Talarico: “Real men don’t lie and cheat their way through life. They don’t enrich themselves by stealing from other people. They don’t sell their soul to the highest bidder. Real men serve others, weak men serve themselves”
🇺🇸 8 people were stranded high up in the air on a roller coaster in Galveston, Texas.
Firefighters got them one by one, lowering them into a basket before walking them down.
One of the most terrifying ways to spend a Thursday.
Last night was the biggest disaster in the history of Tesla.
Let me walk you through what actually happened on that earnings call, because the headlines are doing you a disservice:
Elon Musk got on the call and admitted (his words) that Hardware 3 "simply does not have the capability to achieve unsupervised FSD."
He said he wished it were otherwise. He said the memory bandwidth is one-eighth of what Hardware 4 has. And that's the end of the conversation.
Approximately 4 million Tesla vehicles on the road right now have Hardware 3. Many of those owners paid $8,000 to $15,000 for Full Self-Driving capability based on Musk's repeated promises (going back to 2016) that the hardware was sufficient for full autonomy. As recently as 2022, Musk was publicly assuring owners that HW3 had the processing power to get it done.
BUT IT DIDN'T
Those promises are now officially broken.
The solution is a "discounted trade-in" toward a new car with Hardware 4.
Not a refund or a free upgrade...
A discount on buying ANOTHER Tesla.
Investor Ross Gerber said it too - all HW3 owners got screwed, and with roughly 285,000 FSD purchasers affected, the potential liability runs into the BILLIONS.
But that's not even the worst part.
Musk was asked if the current FSD v14.3 was ready for unsupervised deployment. He said yes. Then immediately walked it back and admitted Tesla has "major architectural improvements" in the pipeline that would significantly improve safety.
What he really means: the software isn't SAFE ENOUGH to deploy without a human watching. Full unsupervised FSD for consumer cars is pushed to Q4 2026. At the earliest... Maybe.
How many times has this deadline been pushed? I've lost count. And trust me, I've seen a lot of broken promises. But this one takes the cake.
Now let's talk about the numbers everyone is celebrating:
Tesla reported $22.4 billion in revenue and $0.41 in non-GAAP earnings. A "double beat." The stock popped 4% after hours. Victory, right?
WRONG
Dig into the actual filing:
The number one driver of operating income improvement wasn't cost reductions, wasn't volume growth, wasn't FSD revenue. It was - and Tesla listed this FIRST in their own shareholder letter - "one-time benefits related to warranty and tariffs."
They released warranty reserves. They booked tariff refund windfalls. They stretched supplier payments by 10 days. They took on billions in new debt. Then they presented everything through non-GAAP metrics that strip out over $1 billion in stock-based compensation.
GAAP net income was $477 million on $22.4 billion in revenue. That's a 2.1% net margin. On a $1.4 trillion market cap.
Let me put that in perspective:
3.75 billion shares outstanding. Annualize the Q1 GAAP profit and you get roughly $1.9 billion. That's a trailing P/E ratio north of 700. Use the adjusted number - strip out stock comp, which is a REAL cost to shareholders through dilution - and you're still at around 250x earnings.
All of this is extremely bad, but I didn't even talk about the CAPEX BOMB yet...
3 months ago, Tesla guided to "over $20 billion" in 2026 capital expenditure. Last night they raised it to over $25 billion. A $5 billion increase in a single quarter. That's 3x their historical annual capex run rate - $8.5 billion in 2025, $11.3 billion in 2024. The CFO confirmed on the call that Tesla expects NEGATIVE free cash flow for the rest of the year.
So you have a company generating roughly $6 billion in annual free cash flow on a good year, and they're about to spend $25 billion.
The math doesn't work.
They will almost certainly need to issue equity. Which means dilution. Which means the $1.9 billion in annual earnings gets spread across even MORE shares.
The core auto business is literally deteriorating in real time:
Tesla delivered 358,000 vehicles in Q1 (missed estimates again).
They produced 408,000. That's 50,000 cars sitting on lots that nobody bought.
Inventory days jumped from 10 to 27 in just a few quarters. California (their most important US market) saw registrations crash 24% year over year.
Their market share in the state fell from 9.2% to 7.7%. That's on top of a Q1 2025 that was ALREADY weak from Model Y retooling. They're declining off a decline.
And here's what really kills the bull case...
The entire valuation rests on robotaxis, Optimus robots, and autonomy. So let's put numbers on it:
Waymo - the actual leader in autonomous driving with 15 million completed rides in 2025 alone, over 127 million autonomous miles driven, operating commercially across 6 US cities with plans to expand to 20 more - just raised $16 billion at a $126 billion valuation.
That's the market's verdict on what the LEADING robotaxi company is worth. $126 billion.
And Waymo is YEARS ahead of Tesla in actual deployment.
Tesla has 3.75 billion shares outstanding. So even if you assign $126 billion in robotaxi value (giving Tesla full credit for matching Waymo despite being nowhere close) that's $33 a share. Add the auto business at generous auto-industry multiples, maybe $20 a share. Throw in energy storage and services, $10-15.
Sum of the parts gets you to roughly $65-70 a share if you're feeling generous. Maybe $50 if you're not.
The stock is $387.
So what exactly are you paying for?
You're paying for a STORY. You're paying for PROMISES that keep getting pushed back, technology that keeps falling short, and a business plan that requires spending $25 billion a year while the core product sells fewer units at declining margins in a market where California sales just fell 24% and the federal EV tax credit is gone.
I managed the number one mutual fund in America. I founded two billion-dollar hedge funds. I've been doing this since 1981.
And I am telling you:
Tesla at $387 is one of the most egregious mispricings I have seen in my entire career.
THE CRASH WILL BE EPIC
I have three monitors on my desk. The left one shows the order book. The middle one shows Truth Social. The right one shows the investigation queue.
On April 21st, the left screen moved first.
I am a Senior Surveillance Analyst at a commodities exchange. I have held this position for nineteen years. My job is to monitor trading activity for suspicious patterns and generate compliance reports. I am employee of the quarter. I have a mug.
At 19:54 GMT on April 21st, someone placed 4,260 sell orders on Brent crude futures. They did this during post-settlement. The window after the market closes when daily volume is typically in the dozens. Sometimes single digits. Sometimes I watch the screen and nothing happens for forty minutes and I think about whether my daughter is happy.
On April 21st, someone placed $430 million in directional bets in 120 seconds during that window. One hundred and twenty seconds. I timed it on my watch because the system clock rounds to the nearest minute and I have found, in nineteen years, that precision matters to no one but me.
At 20:10 GMT, the President posted on Truth Social that he was extending the Iran ceasefire.
Brent dropped from $100.91 to $96.83.
I flagged the trade. I flag a lot of trades. I want to tell you what happens to my flags.
My flags go into a system called TRACE. Trade Review and Compliance Evaluation. I did not name it. The system generates a report. The report goes to a committee. The committee has a name I am not allowed to share but I can tell you it meets quarterly and the conference room has a credenza with bottled water that is sparkling because someone once put still water in the room and a managing director sent an email about it that was longer than most of my surveillance reports.
The committee reviews my flags. The committee has reviewed all of my flags. Here is the complete record of actions taken on my flags in 2026:
Reviewed.
That's it. "Reviewed" is a status. In compliance, a status is the absence of an action that has been given a name so it looks like one.
Let me show you my flags.
March 9th. Someone bet millions on oil falling at 18:29 GMT. Forty-seven minutes later, a CBS reporter posted that the President said the Iran war was "very complete, pretty much." Oil dropped 25%. Forty-seven minutes. I flagged it.
March 23rd. Someone sold 5,100 lots of Brent and WTI crude futures between 10:49 and 10:50 GMT. Fourteen minutes later, the President posted on Truth Social about a "COMPLETE AND TOTAL RESOLUTION" to hostilities. Oil dropped 11%. Over 13,000 contracts traded in sixty seconds after the post. Fourteen minutes. I flagged it.
April 7th. Someone established a $950 million short position in oil futures at 19:45 GMT. Three hours later, the President declared a two-week ceasefire. Nine hundred and fifty million dollars. I flagged it.
April 17th. Someone placed $760 million in bearish bets twenty minutes before Iran's foreign minister confirmed the Strait of Hormuz would reopen. Seven hundred and sixty million. I flagged it.
April 21st. The $430 million. Fifteen minutes. I flagged it.
That is $2.1 billion in directional oil bets in April alone. Every one of them landed on the correct side of a presidential announcement. Every one of them was placed in a window so narrow you could measure it in bathroom breaks. I flagged every single one.
The CFTC chair told a Congressional committee that his organization has "zero tolerance" for fraud and insider trading. I wrote that quote on a Post-it note and stuck it to my right monitor. The one that shows the investigation queue. The investigation queue has not moved since March.
Zero tolerance. Zero staff. Zero budget. Zero prosecutions under the STOCK Act since it was signed in 2012.
Fourteen years. The law has existed for fourteen years and has been enforced zero times. In compliance, we call that a compliance rate of one hundred percent. No cases filed means no cases lost. You cannot fail an audit you never conduct. We call that excellence.
Last month the White House sent an internal email to staff. I was not on the distribution list but I have read reporting on it and I need you to sit with what I am about to say. The email instructed White House staff not to use insider information to place bets on prediction markets.
The White House had to send a memo telling its own employees not to insider-trade.
I want you to read that sentence again. Not because the instruction was unclear. Because the instruction was necessary. Because someone in the building looked at the same pattern I have been flagging for months on my three monitors and decided the appropriate response was an email.
The President's son sits on the advisory board of Kalshi. He is an investor in Polymarket. Both are prediction markets. Both saw accounts created days before U.S. military action.
One account. I cannot stop thinking about this account. It was called "Burdensome-Mix." It was created in December. On January 2nd, it placed $32,500 on Venezuela's president being removed from power. On January 3rd, Maduro was seized by U.S. special forces. Burdensome-Mix collected $436,000. Then it changed its username. Then it disappeared.
One account is a coincidence. But there were six.
Six accounts were created on Polymarket in February. All bet on U.S. strikes on Iran by the 28th. When the President confirmed the strikes, the six accounts collected $1.2 million between them. Five of the six never placed another bet. The sixth went on to correctly predict the ceasefire date and made another $163,000.
My surveillance system logged all of this. My system logs everything. My system does not have opinions and neither do I. I generate reports. The reports go to committees. The committees meet quarterly. Between meetings, the windows get shorter and the bets get larger.
March 9th: 47 minutes. March 23rd: 14 minutes. April 17th: 20 minutes. April 21st: 15 minutes.
The window is compressing. In March, you had time to make coffee between the trade and the announcement. By April, you had time to send a text. By summer, at this rate, the trade and the announcement will be the same event.
The spokesman said any implication that administration officials are engaged in insider trading is "baseless and irresponsible reporting."
Then the White House sent the email again.
I have been in compliance for nineteen years. I have seen insider trading run out of strip mall offices by men who could not spell "derivative." I have seen pump-and-dump schemes coordinated over WhatsApp by people who used their real names. I have seen a man try to manipulate soybean futures from a Panera Bread.
I have never seen $2.1 billion in perfectly timed trades across five presidential announcements in a single month go uninvestigated.
But I have also never seen a compliance system work this beautifully. Every trade flagged. Every report filed. Every committee briefed. Every quarterly meeting attended. Bottled water: sparkling. Minutes: distributed.
Zero prosecutions.
As long as the flags go up and the cases don't, my performance review says I am meeting expectations.
I am meeting expectations. The system is meeting expectations. The $2.1 billion is meeting expectations. The fourteen-year-old law with zero prosecutions is meeting expectations.
The left screen moves. The middle screen moves. The right screen stays perfectly, immaculately still.
In my field, we call this price discovery.
Hats off to this guy, probably the best bitcoin FUDster out there right now. Way better than Schiff and the other lame economist types who don’t understand it at all and spout the same dumb rhetoric over and over. This guy seems to know just enough about the details to weaponize the subtleties and nuance against those who don’t know any better. While a lot of these points sound compelling on the surface, they are of course built on faulty assumptions and hyperbole to spin a manipulative narrative and ultimately create engagement for his “news service”
For anyone in the comments who is interested in the truth, I’ll lay some of it out since I haven’t yet seen a full rebuttal.
This post mixes snippets of real concepts with fundamental misunderstandings and a few conspiracy leaps.
Let’s separate them.
1) “Bitcoin is centralized because miners control it.”
Miners do not control Bitcoin. They propose blocks, nodes enforce the rules. If a miner produces an invalid block, it’s automatically rejected and they lose money. Miners follow the rules because they must,not because they want to.
If miners controlled Bitcoin, the 21M cap would already be gone. Which of course it isn’t.
2) “Mining pools = centralized control.”
Pools don’t own hashpower. They coordinate payouts. Miners can leave a pool and often do. Pool concentration is logistical, not authoritative. A misbehaving pool loses hashpower fast
Truly Centralized systems don’t just lose power the moment users opt out.
3) “The code can be changed, therefore Bitcoin isn’t immutable.”
Anyone can propose code changes. No one can force adoption. This was tested in real life during the blocksize wars. Major miners, companies, and devs tried to change Bitcoins rules. Nodes refused so they failed.
4) “A small group coordinates control behind the scenes.”
There is no mechanism for this. Developers cant push mandatory updates across the network. Miners cant force rule changes. Nodes don’t coordinate, they independently enforce rules. Bitcoin’s security model assumes all parties are untrusted
5) “Stablecoins manipulate price, therefore Bitcoin is controlled.”
Of course there is still no proof of the tether manipulation claims. And regardless, price manipulation ≠ protocol control. Gold, FX, and equities are manipulated too. Bitcoin’s supply, rules, and ledger don’t change because someone trades paper claims on an exchange.
6) “Governments seize BTC easily, so it’s not sovereign.”
Governments seize BTC when users have bad opsec, custodians, or identifiable keys. They don’t reverse transactions, freeze UTXO’s, or access wallets via protocol backdoors.
7) “Colonial Pipeline proves a backdoor.”
False. The FBI obtained a private key. They didn’t reverse Bitcoin or exploit the protocol. If Bitcoin had a backdoor, ransomware wouldn’t use it and criminals wouldn’t flee to Monero. Backdoors don’t survive 16 years of open-source scrutiny.
Nothing, including Bitcoin, is “perfectly decentralized.” But it is designed to be adversarial. Power is fragmented, coordination is costly, and unilateral control is impossible.
For anyone who would like to hear Mark Carney’s outstanding Davos speech in full here it is. This is what true global leadership looks like.
Canada should be immensely proud today, because they are leading the fight back when others dare not.
🎥 TikTok - https://t.co/BExGV2YIDq