On July 19, an adviser to the administration said the leading closed-model companies had already made their positions clear. It was time, he argued, for the rest of Silicon Valley to do the same.
The next day, reporting explained what had prompted the statement. The administration had spent months considering restrictions on Chinese open-weight models. Officials had discussed adding companies to the Entity List, limiting government purchases, and requiring security guarantees before models could be hosted in the United States. Each proposal had previously stalled inside the administration, but that resistance was beginning to weaken.
Four days later, twenty-five companies published a joint letter arguing that Washington should not treat downloadable model weights as the source of the danger.
The first piece in this series asked where economic value moves once building a powerful model is no longer the hardest part. What happened next makes the question more specific. Governments are now considering rules that could determine which companies are allowed to release their most capable models.
The next source of scarcity may not be the ability to build intelligence. It may be the permission to distribute it.
The rest of this briefing is for readers on the list.
Free, permanently. Enter your email and a link comes back that unlocks every piece on the site, current and future.
Part I: What the speed actually showed
The coalition formed quickly. At first, that looked like proof that the issue had suddenly become important enough to unite twenty-five companies in less than a week.
The public summons changes what that speed tells us.
Twenty-five companies did not independently study the issue, settle their disagreements, approve shared language through their legal departments, and publish a coordinated position within four days. The argument had already been made internally. The companies were not forming a view in public. They were publishing one they had already prepared.
Political pressure brought a private consensus into the open.
That does not make the letter less meaningful. An invitation can only produce a coordinated response that quickly when the underlying interests are already aligned. The companies had reached the same basic conclusion before anyone asked them to sign their names beneath it.
The speed measured readiness, not sudden conviction.
Part II: The real dividing line
Three days after the letter appeared, the most prominent company missing from it explained why.
Anthropic's position was not as simple as the coverage suggested. The company said open-weight models that do not contain dangerous capabilities can be a public good. Anyone able to provide the computing power should be allowed to run them, and Anthropic said it had not asked the government to ban open models as a category.
Its main concern was broader. Anthropic argued that authoritarian governments could build models more powerful than American ones and use them for military advantage or domestic control. Under that view, whether the model is open or closed is not the central issue. A dangerous model could be trained in secret and never released publicly.
Its second concern was that an open-weight release cannot be taken back. Once the weights are available, safety controls can be removed, copies can spread, and the original developer loses control over how the model is used. The coalition acknowledged that risk but placed more weight on competition and American leadership.
The two sides therefore sound further apart than they are. Neither supports banning all open-weight models, and both reject open versus closed as the only useful dividing line.
Their disagreement is over the threshold. At what point does a model become capable enough, and dangerous enough, that its release should be restricted?
That is the variable that matters.
Part III: What staying off the letter cost
The first article was right that the list became less informative as more companies joined it. Once nearly everyone signs, the signatures stop telling us much about who has a distinct position.
What it underestimated was the cost of remaining outside the group.
Anthropic's safety argument was quickly interpreted as a business argument. Critics claimed that the company supported restrictions because tighter rules would protect the economics of its closed models. Anthropic therefore had to begin its response by denying a commercial motive before it could explain its actual position.
That creates a lasting problem. Once a principle is understood as a defense of revenue, every future statement of that principle begins to sound like marketing.
The framing had also been established before the list of companies was public. The July 19 summons presented refusal to join as support for the closed-model incumbents. Later coverage did not create that cost. It simply attached the cost to specific companies.
The broader lesson is that policy debates are often shaped before the public receives the full argument. By the time a company explains what it believes, the market may have already decided why it believes it.
Part IV: Three gates that restrict different things
Anthropic supports three broad measures. They are often discussed as though they are parts of one restriction, but each controls a different point in the system.
The first is export controls on advanced chips. These rules limit access to the physical hardware needed to train and run powerful models. This is a familiar kind of scarcity. Chips must be manufactured, the supply is limited, and the restriction only works while production remains concentrated in countries and companies willing to enforce it.
It is also imperfect. Hardware can be redirected, resold, or smuggled, and domestic manufacturing can eventually reduce the restriction's power.
The second measure targets industrial-scale distillation. Distillation allows a company to train a cheaper model using the outputs of a more expensive model. In practical terms, it can help a competitor reproduce part of a frontier model's capability without paying the full cost of building the original.
Restrictions on distillation are meant to close a hole in the chip controls. Limiting access to hardware matters less if a competitor can copy much of the resulting capability from the model's outputs.
The third measure is mandatory testing before release. This is different from the first two because it does not control the materials used to build a model or the methods used to copy it. It controls whether the finished model is allowed to reach the market.
Hardware is something a company must build or buy. Approval is something a government can create by writing a rule. It does not run out when it is used, and control over it can be given to an institution that owns no chips, data centers, or models.
This is where the bottleneck moves from production to permission. The question is no longer only what a company is capable of building. It becomes what the company is allowed to release.
The word "attempt" still matters. A rule written into law does not automatically become an effective restriction. It may bind American companies while doing little to constrain the foreign governments or private groups policymakers are most concerned about. That is the standing weakness of placing the restriction at the point of release rather than on the underlying technology.
Still, permission is the only proposed source of scarcity that is already moving through the policy process. The earlier article described two technical possibilities: a model whose capabilities could not be copied through its outputs, or a computing requirement so large that only a few companies could meet it.
Neither is currently being proposed.
The scarcity now being considered is legal.
Part V: The benchmark changes jobs
The coalition's letter contained no benchmarks. That was notable because the commercial story of artificial intelligence had been built around numbers. Companies spent years comparing model scores, context windows, costs, and performance, then published a major policy letter without using a single measurement.
The original reading was that benchmarks lose commercial value once too many companies can post similar results. A score stops proving that one company has a lasting advantage when competitors can reach it a few months later.
That remains true, but it is incomplete. The benchmark may not be disappearing. It may be changing jobs.
A rule for "sufficiently capable" models first needs a definition of sufficient capability. That requires a test. A benchmark that no longer proves a durable commercial lead may still become the line that determines whether a model can be released.
Another frontier lab has proposed a similar system. Its leadership argued that the most capable models should face testing regardless of where they were built or whether they are open or closed. The proposed threshold would be based on model performance, with outside auditors keeping the tests private and changing them regularly so companies could not train specifically to pass them.
The policy designs differ, but the central idea is the same. Open versus closed is not the right dividing line. Capability is.
That leaves two difficult questions.
The first is what the test should measure. Regulators could use the amount of computing power spent during training. That is easier to verify, but it measures resources rather than what the finished model can actually do. A smaller or cheaper model could still develop dangerous capabilities and remain below the threshold.
The alternative is to test performance directly. That catches capable models regardless of how they were built, but it creates a different problem. Once companies know the test, they can optimize for it. The benchmark would therefore need to remain private, change frequently, and measure real capability rather than a narrow set of rehearsed tasks.
The second question is who controls the test. An industry-funded standards organization and a government agency with the power to block a release are not interchangeable. They differ in who pays for mistakes, who can be influenced, and who carries responsibility when a safe model is delayed or a dangerous one is approved.
The benchmark is becoming less important as a sales tool and more important as a rule. The test may no longer decide who appears to lead the market. It may decide who is allowed to enter it.
Part VI: Where the economics move
This is where the policy debate becomes an investment question.
The first piece argued that the advantage would move toward companies capable of reorganizing around cheaper intelligence. Approval introduces a second test. Companies may now separate not only by how effectively they use the technology, but by whether they can afford the process required to release it.
Testing, external audits, documentation, security reviews, and delayed launches do not cost every company the same amount. A large frontier lab can treat those requirements as another operating expense. A smaller developer may find that the process makes competing impossible.
A rule intended to control dangerous capability can therefore protect the companies that are already ahead. It does not need to be designed for that purpose. The fixed cost of compliance is enough to widen the gap.
This was one of the central concerns raised by critics of the closed labs. A safety rule can also become a barrier to entry.
There will be new demand for independent testing, model governance, security, documentation, and verification. Once those practices become legal requirements rather than optional standards, companies will have to budget for them.
That market is real, but it may remain small compared with the infrastructure spending created around it.
If different countries adopt different rules, the same model may need to be tested several times. Some markets may also require local hosting, separate security systems, or new data controls. A company may have to build and approve the same capability more than once.
That means more demand for chips, cloud capacity, power, cooling, data centers, security, and the systems needed to prove compliance. Regulation of this kind may not reduce the AI buildout. It may make companies repeat parts of it in every major market.
Below the regulatory threshold, the economics look different. Smaller models remain cheaper, more widely available, and easier to deploy. Competition moves toward operating costs, self-hosting, proprietary data, and applications that turn inexpensive capability into something customers will pay for.
The market could divide into two layers. Below the line are cheap and increasingly interchangeable models. Above it are expensive systems that have been tested and approved.
The weakest position may sit between them. A company whose entire business is selling access to a model would face pressure from cheaper systems below and higher compliance costs above. It would lack the cost advantage of small models and the scale advantage of the largest labs.
This outcome is not automatic. Compliance only becomes a competitive advantage if the gate is difficult enough that some companies cannot pass through it. A rule that everyone can satisfy is paperwork, and paperwork alone does not create scarcity.
Two developments would weaken the argument. The first would be testing rules that do not change which companies can release models or how long a release takes. In that case, the gate was never meaningful.
The second would be a frontier model that opens a large and lasting technical lead. If benchmarks return to the center of the sales pitch because one company has clearly moved beyond the rest, then building the model remains the hard part. Permission would matter, but it would not be the main source of advantage.
The debate is moving toward one conclusion. Open versus closed is not the line that matters most. The harder questions are how capability will be measured, where the threshold will sit, and who will have the authority to enforce it.
The advantage may no longer belong only to the company that builds the best model.
It may also belong to whoever decides whether that model is allowed to ship.
