"Similar access."
Two words in Sam Altman's reply to Anthropic's September blog, and they carry the full weight of the most consequential governance proposal currently circulating among frontier AI labs. Not equal access. Not identical access. Similar. I've spent enough time sitting inside audit language to know that the hedge is always where the argument actually lives.
In 2017 I spent four months auditing early ERC-20 implementations for three projects raising into the ICO boom out of Cape Town. Two of them carried reentrancy flaws I found by reading transfer functions line by line; both later collapsed. What protected investors from roughly $45,000 in avoidable losses wasn't the word "secure" in their whitepapers. It was the word "approximately," sitting in a code comment above a state update where a developer had "approximately" handled reentrancy. Approximate is where value leaks. Tracing the code back to the conscience behind it means reading the adjectives, not the mission statements.
Now Ray Dalio, Sam Altman, and Elon Musk have briefly converged on the claim that AI model development should slow down. The most technically loaded word in the entire exchange is the one Altman chose to describe how much visibility outsiders would get. That is the thing worth pulling apart.
Context: A Familiar Shape, Wearing New Names
Anthropic's blog asked the industry โ and implicitly its competitors โ to accept two propositions: frontier development is outpacing the industry's capacity to evaluate it, and independent third parties should receive meaningful access to models before deployment. Altman agreed in principle days later, offering independent evaluators "similar access to employees." Musk's contribution was four words endorsing Dalio's framing, which is that AI capability is arriving faster than our institutions can metabolize it.
Strip out the personalities and you are looking at a recurring artifact. March 2023 produced an open letter โ signed by a long list of researchers and executives โ calling for a six-month moratorium on training anything more capable than GPT-4. GPT-4 shipped that same month. The letter generated no mechanism, no committee with authority, no consequence for non-participation. That is what always happens when a standard is drafted by the parties it is meant to constrain. Open source is not a license; it is a promise. A promise with no enforcement layer is a press release with better typography.
I have watched this exact shape before, in a domain where the consequences were measurable. In 2021 I worked with ten indigenous South African digital artists to build a royalty enforcement toolkit, after we found that roughly 60 percent of secondary sales on the major marketplaces paid no automatic creator royalty. The standard we leaned on, EIP-2981, was elegant and structurally incapable of enforcement. It was a signaling standard: it told a marketplace what the creator would prefer to be paid. Marketplaces honored it while honoring it remained cheap. That lesson keeps returning to me, and it generalizes cleanly. A standard that expresses intent without controlling any party that can defect is not a standard. It is a suggestion with a logo attached.
Hold that frame against three CEOs asking one another to slow down.
Core: Four Kinds of Access, One Elastic Phrase
When a lab says an evaluator will get access "similar to employees," it is collapsing at least four very different capabilities into a single phrase, and the distance between them is the distance between a compliance check and an actual audit.
Inference API access means you can query the model. You can build a harness, measure refusal rates, hunt jailbreaks, catch behavioral regressions between versions, run large-scale automated evals. It is genuinely useful and it is the weakest tier, because you are testing the product as shipped, with every safety layer engaged. You cannot see weights, cannot strip the alignment wrapper, cannot fine-tune, cannot elicit latent capability the deployed system has been instructed to keep quiet.
Weight access changes the game. With a checkpoint you can probe activations, run fine-tuning-based elicitation โ the technique that has repeatedly turned safety-tuned models into capable collaborators in ways no API eval ever surfaced โ and test the raw model beneath the wrapper. Most of the red-teaming literature that actually found something depended on this tier.
Training-pipeline access is where you learn whether a capability was suppressed or simply never measured: data mixtures, hyperparameters, RLHF and Constitutional AI processes, internal evals that ran during training and never left the building.
Infrastructure access โ cluster topology, compute budget, run logs โ is where you learn what is coming next. It is also, unsurprisingly, the most commercially sensitive item on the list, and the one nobody hands over.
"Similar to employees" could describe any negotiated slice of these, wrapped in an NDA that keeps the exercise invisible to everyone outside the room. The phrase is deliberately elastic, because elasticity is the asset: it lets each lab claim safety leadership while retaining full discretion over what "similar" ultimately means in a contract nobody else can read. That is not cynicism. It is how every compliance regime behaves before an external authority specifies the artifact being audited.
I have built verification systems, so let me be concrete about what that artifact should be.
In 2025, working with fifteen researchers across four time zones, I helped design and pilot a framework that let users prove the origin of digital content without revealing personal data โ 5,000 users, roughly 2,000 identity fraud attempts blocked. The cryptography was the least interesting part. The decision that mattered was what gets published. We published receipts: signed, timestamped, hash-committed attestations that a check occurred, who ran it, which standard version they applied, and what the outcome was. Anyone could verify the check happened. Nobody could see the private inputs. That pattern is well-trodden in adjacent infrastructure โ Certificate Transparency logs, Sigstore, reproducible builds, on-chain attestations. AI safety evaluations have no published artifact of this kind. None, from any of the three labs.
So here is the design I would push for. Publish an evaluation receipt for every frontier run: evaluator identity, standard version, model version hash, compute environment, and a commitment to the result โ written to an append-only, publicly readable log. Internals stay private. The fact of evaluation becomes verifiable, the timestamp becomes non-repudiable, and "we had it independently evaluated" stops being a sentence no outside party can check.
The obvious objection is that a receipt proves a check happened, not that the check was good. True, and still a strict improvement over a status quo where you cannot confirm the check happened at all, and where the same lab funding the evaluator also decides whether the result is ever mentioned. The second objection is overclaiming on decentralization. Attestations can be decentralized cheaply. Evaluating a frontier model cannot. Nobody has proven inference at that scale in a zk circuit, and the proving-cost curve is not bending fast enough to pretend otherwise. Decentralize the log, not the judgment.
Then there is the supply problem, which the pledge's signatories gloss over. The global population of people who can meaningfully red-team a frontier model, who are not employed by a lab, and who carry no grant, advisory, equity, or co-authorship entanglement with one, is small. I would put it in the low hundreds. The number who can do that work at the capability frontier โ where the model outperforms the evaluator on the task being evaluated โ is smaller still, and the number who can do it without compute they do not own is approximately zero.
That is not a scandal; it is a labor-market consequence. The talent grew up inside the labs because the labs owned the GPUs. But it means the "independent third party" in the pledge is, today, a fiction assembled from overlapping consulting arrangements and shared conference committees. An evaluator who depends on a lab's compute grant to run evaluations, and who hopes for that grant to be renewed next cycle, is not independent in any sense that survives an inconvenient finding.
And then the timing. Evaluation takes weeks to months. Release cadence in a competitive market is quarterly at best, monthly in practice. If a lab can only ship after evaluation completes, evaluation becomes the release gate โ and whoever controls the gate controls the roadmap. Which raises the question nobody in the exchange has answered: who wants to hold the gate, and what would they charge for it?
For the audience I write for, this is where it turns commercially interesting, because crypto has already traded this story โ just not the part of it that matters.
In the current cycle, decentralized AI has become the most dependable narrative rail on exchanges: compute marketplaces, inference networks, agent frameworks, data-labeling protocols, hundreds of tokens whose pitch is that AI's supply chain should be permissionless. Some of that will prove to be durable infrastructure. Most will not, and the tell is familiar. Narrative rails reprice long before capability exists, and then the market convinces itself the capability arrived because the price did. AI compute "fragmentation" gets discussed precisely the way liquidity fragmentation gets discussed in DeFi โ as a problem requiring a new product, usually the one being launched. Fragmentation is sometimes real. It is also very often a story that exists because a story is what raises.
The exchange layer shows how the recycling works. Launchpad allocations that once returned triple-digit multiples for anyone holding a slot have compressed to roughly ten times at best across recent cycles, and the decay continues. When the mechanism monetizing user traffic stops printing, exchanges need a fresh narrative to sell. AI is the best one on the shelf: it is genuinely important, so taking it seriously cannot be dismissed as chasing hype.
Underneath the headline, the urgent thing is already deployed. AI agents are being handed keys โ signers, session keys, ERC-4337 smart accounts, token-bound accounts. An agent that can sign is an agent that can drain a wallet, and the failure mode is not an offensive sentence. It is a contract call. Every line of code is a hand extended in trust, including the line an agent signs with. Not one of the three statements pledged anything about deployment. Every pledge addresses training runs, while the live risk surface in my industry is autonomous software holding spending authority.
Ethically, this is the part that should keep builders awake. The same architecture that lets a creator monetize a pixel without a platform's permission is the architecture that lets an unsupervised model spend your balance. Sovereignty cuts both ways, and no pledge touched it.
Contrarian: The Pledge Is Priced, Not Principled
Everyone treated the three-way convergence as an unusual moment of conscience. Read it as a market position instead. Slowing down is cheap for whoever believes they are behind and expensive for whoever believes they are ahead, which means the value of any slowdown pledge runs inversely to how much the pledger loses by keeping it. xAI is still catching up on capability; a pause shortens its gap, and the statement costs nothing if the pause never materializes. Anthropic has spent two years building safety into its product identity, so leading the call converts a research position into a standards-setting seat. OpenAI cannot afford silence and cannot afford delay, which is exactly the shape of a reply promising "similar" access and nothing further.
The blind spot nobody in the exchange mentioned: mandatory third-party evaluation is a fixed cost, and fixed costs are a moat. The pattern is already visible in European crypto regulation, where stablecoin reserve requirements and CASP licensing costs were written in the language of consumer protection and functioned in practice as consolidation. Small teams simply cannot pay the compliance bill, so the market narrows to firms with legal departments. Apply that template to AI evaluation and you get a regime in which the largest labs are the only entities able to afford being audited, and the auditors were trained by the audited.
The instinct from my own industry โ decentralize the verifier โ is right in spirit and not yet a cure. Decentralized attestation, yes. Decentralized evaluation of frontier capability, not at this scale and not this cycle. Claiming otherwise is how you end up selling a token for a proof nobody can generate.
Takeaway
Watch three signals over the next year. Whether any lab accepts evaluation findings as binding rather than advisory. Whether evaluation receipts are published to an append-only log outsiders can actually query. And whether the first public incident involving an autonomous agent with real spending authority arrives before or after the first serious regulatory hearing on AI deployment.
Education is the only true decentralized currency, and right now the syllabus is being written by the parties under examination. The question for 2026 is not whether AI development slows down. It is whether anyone outside the lab will ever be in a position to know.