Argument architecture

How this editorial can be challenged

Core question

Who should hold the evidence when an AI claim is too consequential to accept on institutional reputation alone?

Proposed mechanism

Frontier AI concentrates access to models, logs, training data, evaluations, and compute inside a small number of companies and security institutions. That concentration lets the same actor generate a claim, select the supporting record, define the caveats, and control reproduction. Independent custody breaks that loop by preserving evidence before incentives, litigation, competition, or national-security concerns reshape what can be inspected.

Strongest counterargument

Evidence access can expose trade secrets, personal data, security methods, and unpublished research. Forced transparency could help attackers or competitors and destroy scientific priority.

Our response

Independent custody is not the same as public disclosure. Courts already use protective orders, regulators inspect confidential records, and scientific bodies review sensitive work under controlled access. The rule should be tiered: preserve the complete record, give qualified independent reviewers access, publish methods and findings at the safest useful level, and disclose enough for affected parties to challenge a decision without releasing an operational blueprint.

Evidence limits

The NSA advisory does not expose the intelligence underlying its attribution; the two resignation reports rely heavily on public statements and forecasts that cannot be validated today; historical-model experiments remain early and vulnerable to data leakage; and OpenAI's Navier-Stokes result has a formal artifact but still requires independent mathematical scrutiny and resolution of provenance concerns.

What would change our mind

This argument would weaken if consequential claims were repeatedly reproduced without privileged access, or if protected third-party review added no corrective value and caused greater security or privacy harm.

The AI argument has moved from outputs to evidence

The public is being asked to absorb claims of extraordinary scale. U.S. agencies say foreign companies extracted the capabilities of frontier models across millions of requests. Researchers inside a safety-focused laboratory say systems could become uncontrollable and catastrophic. A scientific magazine asks whether AI can rediscover theories without secretly knowing the future. A frontier company says an internal system solved a problem that resisted mathematicians for roughly 90 years.

These claims are not equivalent, but they share an institutional structure. The people with the strongest access to the relevant evidence are often the people making the claim. Outsiders receive an advisory, an interview, a benchmark result, a paper, or a selected log. The dispute then collapses into reputation: trust the institution or reject it. That is an impoverished choice for decisions this consequential.

Security attribution arrives with a closed evidence box

The NSA, FBI, and CISA say six China-based AI companies extracted billions of tokens from variants of Claude, GPT, Gemini, and Grok through industrial-scale distillation. Their advisory names distributed accounts, transfer-station proxies, metadata sanitization, prompt injection, chain-of-thought extraction, and automated quality checks. It gives defenders specific behavioral indicators and three immediate categories of mitigation.

That detail makes the advisory operationally useful, but it does not reveal the intelligence that supports every attribution or the basis for saying the activity occurred with likely government awareness. National security sometimes requires protected sources and methods. The answer cannot be blind publication. It should be a review structure capable of testing classified or proprietary evidence, separating confidence levels, and preserving a record that can later support accountability.

Insider access is valuable evidence, not final proof

The resignation of a pretraining researcher who worked at both OpenAI and Anthropic is evidence about institutional belief and incentive. His warning is specific: employees may understand the stakes yet continue because each laboratory believes a rival will move first. A serving alignment lead then put his own estimate of human extinction above 10% within a decade and said the company does not yet have a clear plan for aligning superintelligence.

Those statements deserve more weight than an anonymous social-media prediction because the speakers have relevant access and place reputations at risk. They still do not establish the probability or timeline of catastrophe. Access can produce insight, but it can also produce selection effects, organizational narratives, and incentives to dramatize capability. The missing institution is one that can examine the evaluations, near misses, forecast assumptions, and internal disagreement behind the warning without forcing whistleblowers to publish secrets or asking the public to accept a percentage on authority.

The Einstein test fails when the future leaks backward

Historical language models offer a brilliant idea: train a model only on information available before a discovery, then ask whether it can reproduce the breakthrough. Nature reports that early attempts showed occasional sparks but mostly failed, and that supposedly time-locked models sometimes answered questions about events after their cutoff. Poorly dated archives, digitization artifacts, and subtle contamination make it difficult to prove that a model did not already know the answer.

This is an evidence-custody problem disguised as a benchmark problem. A result is meaningful only if someone can reconstruct the dataset, cutoff, prompts, interventions, failed candidates, and evaluation rule. Otherwise the demonstration rewards plausible output while hiding whether hindsight entered through training data, researcher hints, or selective reporting. Scientific discovery needs a chain of custody because novelty is a historical claim before it is a performance claim.

A formal proof shows what stronger verification can look like

OpenAI says an internal model, coordinated through roughly 10,000 agents, produced an analytical construction showing finite-time singularity in a forced three-dimensional Navier-Stokes system. The company published a long paper and a Lean formalization, and says the effort used about 130 billion output tokens for the Navier-Stokes work. Formalization does not guarantee that every definition matches the intended mathematical problem, but it creates a far stronger artifact than a press claim alone.

The episode also exposes a second custody issue: provenance. OpenAI says it began after hearing rumors of related work, did not access the outside researchers' specific user data, but cannot completely rule out indirect influence from de-identified product data. Independent scrutiny must therefore examine two questions, not one. Is the proof correct, and can the intellectual path to it be reconstructed fairly enough to allocate credit and protect researchers who use commercial AI tools?

Confidentiality is the strongest objection

A universal transparency demand would be reckless. Publishing anomaly detectors could help distillers evade them. Releasing frontier-model logs could expose personal data or dangerous capabilities. Forcing immediate disclosure of unfinished mathematics could destroy priority and encourage laboratories to avoid external tools. A badly designed audit mandate could become an industrial-espionage channel with a compliance label.

The remedy is layered access, not evidentiary darkness. Preserve the complete record with tamper-evident timestamps. Let accredited reviewers work under confidentiality and conflict rules. Publish methods, uncertainty, and conclusions at a level that supports challenge without revealing operational details. Give courts, regulators, journals, and affected parties different access according to their legitimate role. The point is not that everyone sees everything. It is that no interested institution remains the sole judge of its own evidence.

By next year, trust will become a custody product

The prediction is straightforward: frontier laboratories, regulators, and scientific publishers will begin building protected evidence rooms, escrowed evaluation records, and reproducible provenance systems because ordinary disclosure will no longer satisfy either security or science. The first versions will be uneven. Some will become theater. But the competitive advantage will shift from claiming trustworthiness to demonstrating that a qualified outsider can reconstruct the consequential decision.

That transition will change what counts as a mature AI institution. A polished system card will be less persuasive than preserved test artifacts. An insider percentage will matter less than a forecast ledger with assumptions and updates. A spectacular proof will travel with its formal object, prompt history, data policy, and independent review. Verification will become infrastructure.

Stop asking the public to choose a brand

Here is the challenge for every institution making a consequential AI claim: identify the evidence that would prove you wrong, preserve it before controversy begins, and place enough of it beyond your unilateral control that correction remains possible. If security prevents public release, name the protected reviewer. If privacy limits access, disclose the method and aggregate finding. If a result is scientific, make reproduction and provenance part of the release rather than an afterthought.

The next AI monopoly will not be only compute, data, or distribution. It will be control over the evidence used to define reality. Break that monopoly early. A society that cannot independently reconstruct what its most powerful systems did will not govern them; it will merely decide which institution's confidence sounds most convincing.

  • Preserve consequential model logs, evaluation artifacts, and provenance before release.
  • Create protected access for qualified independent reviewers.
  • Publish confidence levels, failure conditions, and correction procedures.
  • Separate technical verification from commercial reputation and national prestige.
Evidence behind the argument

Read the reporting

Opinion is ours. The factual record is linked below.

NSA — Joint warning on industrial-scale model distillation Euronews — Former frontier researcher warns of catastrophic AI risk CNBC — Alignment warning follows a researcher's resignation Nature — The Einstein test for AI scientific discovery OpenAI — On the Navier-Stokes Millennium Prize Problem