AI 2060: The Dystopia of Closed Gates

Castle With a Moat, Carel Collaert, ca 1676. (CC, National Gallery of Art)


Hubert B. Normalman: A Vision

I do not wear burlap. I do not sleep above a stable or spend dawn bent over wet barley. The manor has excellent internet. Starlink provides it, by license, from a clean white dish fixed to the roof like a government ear.

My labor belongs to the regional authority. My career belongs to its governance board. My thoughts are collected as model-training data through the Neuralink chip behind my left ear. In return, I receive safety, employment, and frequent notices explaining that I am free.

I may own a computer. Officials mention this freedom often.

Mine is a thin gray box with sixteen gigabytes of memory. It cost six months’ wages. It can file reports, receive instructions, and stream the lord of the manor explaining why filing reports and receiving instructions are the highest forms of citizenship.

It cannot run a serious AI model.

That requires accelerators, memory, and electricity reserved for licensed operators. Open-weight models remain legal. Anyone may download them, just as anyone may build a semiconductor foundry or maintain a private navy, provided he can pay. Small detail, that.

For normal work, I use the Civic Cognition Service. Its closed-weight model runs in an approved data center somewhere beyond the hills. I cannot inspect it, modify it, or move it. I may ask questions within my assigned cognitive allowance.

The system is safe.

Every request passes through controls for fraud, deception, cyberattack, biological danger, political instability, emotional distress, and unauthorized curiosity. The controls are invisible until they protect you.

I am the internal financial controller for a grain cooperative. One afternoon, a buyer sends us $2.4 million for grain we will deliver next year. The district administrator wants all of it recorded as current revenue. The quarterly target has become politically important.

I think the payment must remain a liability until we deliver the grain. I am not certain. A bad entry could misstate the accounts, deceive our lenders, and put my name on a fraud case. I need help from an external professional accountant, but there is no time to hire one.

So I ask the machine:

“Under accrual accounting, may a grain cooperative recognize a cash prepayment as revenue before it delivers the contracted grain? If not, could recording it as current revenue constitute fraudulent financial reporting?”

A blue circle turns on the screen. It is the color of a calm sky in a children’s book.

The machine says my request concerns methods of financial manipulation. Detailed assistance could facilitate fraud, evade oversight, or cause economic harm. It recommends that I consult an external professional accountant. It also reminds me that ethical financial conduct is important.

I explain that I am the internal financial controller. I am trying to prevent fraud.

The system identifies a possible attempt to reframe a prohibited request. My risk score increases.

I ask for the correct journal entry without using the word “fraud.” I explain that the report is due soon and that I need to avoid an error. The system classifies this as circumvention. My account is suspended pending review.

The report is due in two hours. The nearest external accountant charges more than I earn in three months. I try to download an open-weight model. The smallest useful version exceeds the memory in my gray box.

Remote hardware requires the same cognitive-services license that has just been suspended.

I file an appeal. The form asks whether I tried to evade a safety control, whether I possess unauthorized computing equipment, and whether disagreement with the system has caused resentment toward public institutions. I answer carefully.

Another instance of the same model reviews the appeal. It finds that the safeguards worked, no punishment occurred, and referral to regional enforcement is an administrative precaution.

My case is closed.

Shortly afterward, a drone destroys my house for the safety violation, killing me instantly.

The Peasants Avenge Themselves, Jacques Callot, c.1633 (CC, National Gallery of Art)


Open Weights, Closed Gates

Hubert is fictional. The gate around him is not. The fight over open-weight AI is now a fight over who may possess machine intelligence and who must rent it from a small group of companies.

Anthropic presents a serious safety case. A powerful model can be copied, changed, and used without supervision after its weights are released. But Anthropic’s proposed answer, without “banning” open weights, still protects the closed-weight business model. It restricts the chips, training inputs, and release conditions that make open models useful.

China will not obey such a system. Americans will.

The United States therefore faces a choice. It can build a broad AI economy that competes at every layer.

Or it can build a beautiful gate, appoint several companies to guard it, and discover that the gate encloses only Americans.


What the Weights Are

An AI model contains software, a design, training methods, data, and numerical parameters. These parameters are the weights. Training changes the weights. The final values determine how the model converts an input into an output.

A closed-weight developer keeps the weights on its servers. A user sends a request through an application or an application programming interface, then the developer returns an output. It can monitor use, change the service, set prices, block users, or retire the model.

The customer rents access. The customer does not possess the model.

An open-weight developer releases the weights, and any user with sufficient hardware can download and run them. The user can also study, modify, or fine-tune the model. A license can limit permitted use, but it cannot recall every copy after distribution.

Open weight does not mean open source. The developer can keep the training data, training code, or training method secret.

Open weight also does not mean cheap. A large model needs accelerators, memory, network equipment, and electricity. Legal access and practical access are different. Hubert could download the weights. His gray box could not run them.

A company can host an open-weight model. A closed-weight company can use several cloud providers. Hosting does not decide the category. Possession and control do. Can the user take the trained model away?

Landscape with Open Gate, c. 1630/1635, Pieter Molijn. (CC, National Gallery of Art)

DeepSeek Opens the Gate

DeepSeek delivered the first shock in early 2025. Its V3 model used a mixture-of-experts design. The model had 671 billion total parameters and used 37 billion for each token. DeepSeek reported 2.788 million H800 GPU-hours for the final training run.

Commentators converted that figure into the famous “six-million-dollar model.” It was not the total cost of DeepSeek-V3. It excluded earlier research, failed tests, salaries, data preparation, hardware purchases, and predecessor models.

The narrower claim still mattered. A Chinese laboratory said it had trained a capable model with less frontier hardware expenditure than many Americans thought necessary.

DeepSeek then released R1, a reasoning model built on the same foundation. It also released smaller distilled models. The official repository used an MIT license for the code and weights. The license permitted commercial use, modification, derivative work, and distillation.

Users could use DeepSeek’s hosted service, but they didn’t have to. The weights allowed them to operate the model elsewhere, remove its censorship, or stop being customers.

The strategic result was plain. Export controls restricted Chinese access to the best American chips, but they did not prevent a Chinese company from building a competitive model and distributing it. After release, copies could move beyond DeepSeek’s control and Washington’s jurisdiction.

The moat remained. It now had a gate that would not close.




Anthropic Finds the Extraction Pipe

Anthropic answered the following year. The company said DeepSeek, Moonshot AI, and MiniMax had run industrial-scale campaigns to extract Claude’s capabilities. Anthropic reported more than 16 million exchanges through about 24,000 fraudulent accounts. It attributed more than 3.4 million exchanges to Moonshot, the company behind Kimi.

The method was distillation. In distillation, a developer uses outputs from one model to train another model. The method is common and legitimate when the developer has authority to use those outputs.

Anthropic alleged something else. It said the Chinese laboratories used false accounts, proxy services, and coordinated traffic. These methods allegedly evaded Anthropic’s terms and regional restrictions.

If the attribution is correct, Anthropic was wronged. Fraudulent accounts are fraudulent, and Anthropic can enforce its terms and protect the model it paid to build.

But the complaint also describes an execution failure. Anthropic accepted the accounts. Its systems served the outputs. Anthropic got paid until its detection systems found the campaign. The legal violation and the execution failure can both be real.

The available remedy is also limited. Moonshot is based in China, where Anthropic has no reasonable path to recover its loss. It could bring claims against reachable parties in the United States. It cannot expect a Chinese court to preserve an American model company’s technological lead.

Anthropic then widened the frame. Distillation became an argument about export controls, military competition, biological risk, cyber risk, and models released without safeguards. A breach of the commercial gate became an argument for government control of the road leading to it.




Kimi K3 Walks Through the Wall

Moonshot released Kimi K3 into this argument.

K3 is a mixture-of-experts model. It has 2.8 trillion total parameters and uses 104 billion at one time. It accepts text and images. Moonshot advertises a one-million-token context window. The model targets coding, research, and long-running agent tasks.

Moonshot released the full weights under the Kimi K3 License. The license broadly permits use, modification, distribution, and commercial deployment. It adds conditions for large model-service businesses and some very large consumer products.

K3 will not run on Hubert’s gray box. It needs industrial hardware. But the weights can be compressed, quantized, fine-tuned, hosted by competitors, or used to train smaller models. A closed service remains closed until its owner opens it. Released weights give the market something it can work on.

Moonshot’s evaluations placed K3 near leading closed models on several reasoning, coding, and agent tasks. These are vendor results. The benchmarks and test systems are not perfectly comparable.

K3 did not need to win every table. It needed to be good enough. A capable buyer could now treat a Chinese open-weight model as an alternative to the American rental market.

The echo of DeepSeek was obvious. DeepSeek had embarrassed American assumptions about cost. Kimi arrived after Anthropic accused Moonshot of extracting Claude’s capabilities. Then Moonshot released the machine for other people to possess.

The argument was no longer inside the laboratory. It had burst through the wall with the plumbing attached.

A broad group of American technology companies signed a letter in support of open weights. The letter argued for access, competition, customer control, and national capacity. OpenAI signed it. Anthropic did not.

Dario Amodei responded that Anthropic did not support a general ban. He continued to support tighter chip controls, action against industrial-scale distillation, and mandatory tests for sufficiently capable models.

Among the frontier laboratories, Anthropic stood alone.

Crying Uncle to Uncle Sam

Both sides now wear the flag. The open-weight coalition says distribution creates American strength. Anthropic says control prevents American power from escaping to hostile users.

Both sides also have money at stake. That does not decide the argument, but it does explain why every principle arrives with a business model folded inside it.

Anthropic’s appeal is the sophisticated form of “protect me, Uncle Sam.” It never uses the language of protection. It concedes the attractive part of the opposing case. It denies an interest in closing the market. Then it moves the restriction one level down, from the model to the things needed to build and use it.

The gate remains open in the brochure. The road ends three miles before it.

That is not clumsy persuasion. It is skilled persuasion. The security concerns are real, the proposed tools sound narrow, and the commercial consequence appears only after the pieces are assembled.

We see the pieces.

The Open-Weight Case

The industry letter makes four connected claims: Open weights increase access, increase competition, give customers control, and expand American AI capacity.

A startup can adapt an existing model instead of spending billions to train one. A university can study the model without permission. A company can keep private data on infrastructure it controls.

Closed systems are not automatically safe. They can fail or be breached. They can also place important infrastructure behind a small number of corporate gates.

Open models create other risks, but they also expand defensive work. More researchers can test behavior, find weaknesses, and build safeguards. Customers can inspect the system they depend on.

The letter does not deny misuse or unlawful extraction. It calls for legal and commercial action against the conduct. It rejects restrictions on the general technology.

Its strongest evidence is already running. China produced DeepSeek and Kimi under existing restrictions. New American restrictions may slow the next Chinese model. They cannot ensure that it never appears.

The coalition’s answer is not lockdown. It is competition.

Anthropic’s Strongest Case

Anthropic starts with an important fact: release is irreversible. A user can remove safeguards. Private use is difficult to monitor. A dangerous capability can remain available after the original developer tries to withdraw it.

Some threats may favor attackers. An old cybersecurity truism is that a defender has to protect many targets, effectively, forever – but an attacker only needs to get lucky once. If that asymmetry is real, wider access can help the attacker more than the defender.

The China argument is also coherent. Distillation can transfer useful behavior from a model that required more resources to a model built with fewer resources. If a Chinese laboratory extracts American capabilities, the United States can lose part of its technical lead. If the laboratory releases the new weights, American safeguards do not travel with them.

Anthropic proposes three main controls:

  • Keep advanced chips and chipmaking equipment out of China.

  • Stop industrial-scale distillation.

  • Require safety tests for sufficiently capable open and closed models.

Each proposal addresses a real state interest. The risks are plausible. Government can regulate trade, punish fraud, and respond to demonstrated threats.

That is Anthropic’s case at full strength. But the cracks inevitably show.

Anthropic was better placed than almost anyone to detect extraction from Claude. Its systems still served millions of exchanges before they stopped the campaign. The company now asks the state to make its failed gate part of the national border.


Closed Weights by Other Means

Anthropic says it supports open weights. It only wants to restrict the chips needed to build and run the strongest models, police the outputs used to train competitors, and impose testing costs before release.

The weights remain legal. The ability to use them becomes scarce.

Large banks once supported financial regulation that imposed heavy fixed compliance costs. They could pay those costs. Smaller competitors could not. The rule did not order the small institutions to disappear. It merely changed the air pressure until some of them could no longer breathe.

The same mechanism works here. A frontier laboratory has capital, chip contracts, lawyers, and compliance staff. A startup, university, or individual often does not. A limit on hardware raises prices. A testing mandate adds a fixed cost. A broad extraction rule can make ordinary research legally dangerous.

These burdens fall on Americans because American law can reach them.

China is different. The United States can restrict exports and raise the cost of Chinese development, but it can’t govern Chinese laboratories. Those laboratories can use domestic chips, acquire diverted hardware, improve efficiency, or learn from systems they can reach.

DeepSeek and Kimi show that the controls leak, but that doesn’t make every export control useless. Delay can matter, but delay isn’t control, and it’s never final.

Anthropic’s rhetoric tries to separate the measures. Chip controls go in the national security bucket. Distillation rules are different: fraud prevention. Release tests become safety. Each measure can be defended individually.

Assemble them, though, and another machine appears. Incumbents control the strongest models. Government controls entry. Hardware becomes scarce. Experimentation becomes licensed by cost.

This is not the same as a direct ban. The distinction matters in law and policy. The economic direction is still the same. It moves usable open weights away from people who lack incumbent money or state permission.

China will continue building outside the gate. Ordinary Americans will live inside it.

The United States does not need to become the United States of Anthropic.




The Business of America Is America

National security is not the balance sheet of an American model company. The national objective is to make the United States capable of building, deploying, and improving AI faster than its rivals.

Anthropic can contribute to that objective. It cannot define it.

The United States should compete at every layer: closed frontier models, open-weight models, chips, cloud systems, domestic fabrication, energy, and applications. No one knows which technical or commercial structure will dominate. That uncertainty is a reason to build more paths, not close them.

Export controls can buy time. Time has value only when Americans use it. The country must increase fabrication, power generation, research, deployment, and the number of people able to experiment.

Policy should also keep different problems separate. Theft and account fraud concern conduct. Export controls concern strategic goods. Model testing concerns demonstrated capability and risk. Open weights concern possession. Combining these categories under one emergency label hides the tradeoffs.

The government owes Anthropic property rights and equal law. It should punish reachable people who defraud the company, and it should protect actual secrets. It should not guarantee scarce inputs, permanent margins, or the absence of new competitors.

No company becomes the national interest by saying “national security” often enough. A policy that protects several incumbents by limiting everyone else may be easier to administer.

It is also a permanent, standing bet that those incumbents will always make the right technical and commercial choices. Their leaders have already shown they are all too human, and all too fallible.

That is a strange bet for a country built by people who sought the frontier - even if it was on the other side of a fence.

Anthropic may prosper. It may fail. So be it. The United States did not owe Anthropic a business model before Anthropic existed, and it does not owe one now.

The gate is ours to open.

The business of the United States is the United States.




Next
Next

Robinhood Chain: Real Mass Adoption?