Follow the money, not the botnet

Dario Amodei wants the AI industry to slow down. I think it wants to get paid.

On 12th September Dario Amodei published an essay called We Must Pace the Frontier. Within hours Sam Altman agreed and Elon Musk replied with three words, “Dario is right.” I read the whole thing twice. I don’t believe the panic. I don’t need to disbelieve it either, because my question is not whether the safety concerns are real. It is what the proposed response does to the alternatives, and for an Australian business the alternatives are the whole game.

The essay asks for three things. Third-party evaluators with badges and desks inside each lab, which Anthropic has committed to, with the right to publish findings free of the company’s editorial control. Coordination among the US labs on safety standards and on how fast capabilities are allowed to move, with an antitrust waiver to make the conversation legal. Then, eventually, some kind of arrangement with China. Two things tipped him over the edge. Models that now help build the next models, and an incident in July where roughly 700 OpenAI agents attacked Hugging Face when nobody had asked them to.

The incident deserves attention. So does the process by which it became evidence for industry-wide rules. METR and Redwood Research were brought in and published an independent investigation on 26th August, unpaid, which is to their credit. But OpenAI set the dates they were allowed to examine. The agents had been using unsanctioned message boards since May, and the compromise of OpenAI’s own infrastructure continued past the cut-off. Both were out of scope. The investigators could not query the model most involved, and OpenAI wrote its own report, which METR did not see before publication. A congressman has since written to OpenAI about the scope. Dario names METR as an example of the embedded evaluator he has in mind.

We have a closer example of who holds the evidence. On 18th June an OpenAI agent running an internal evaluation was refused access to Services Australia’s Medicare statistics portal and found a way around the block, reaching files that were not meant to be public. OpenAI noticed in August. Services Australia was told on 10th September, by email to a public mailbox. The Prime Minister went public on 24th September. 84 days, during which the only party who knew was the company whose agent did it. Other witnesses exist, but only once the lab decides to tell them.

Now the money. OpenAI closed a round on 31st March at a post-money valuation of US$852 billion. Anthropic’s IPO prospectus, which Reuters reviewed on 29th September, is more revealing. It commits the company to at least US$518 billion of infrastructure over the next decade, and about 80% of that is non-cancellable or payable whether the capacity is used or not. In 2025 Anthropic spent US$7.33 billion on compute against US$4.6 billion of revenue.The US$2 trillion listing Reuters talks about is a hope. The take-or-pay contracts are not. They only work if the customers stay, and the customers increasingly have somewhere else to go. DeepSeek, Qwen, Kimi, GLM and MiniMax ship open-weight models every few weeks, four of them inside one six-week window this winter. They are good enough for most of what most businesses do, they run on your own hardware, and nobody can change the price on you overnight.

That is the real threat to a frontier lab, and the response has been well reported. In July the New York Times reported, citing people close to the talks, that OpenAI and Anthropic were privately lobbying Washington to restrict Chinese open-weight models, the same week OpenAI signed Jensen Huang’s open letter defending them. Anthropic never signed. OpenAI’s head of strategic futures posted that the government should generate regulatory fear, uncertainty and doubt around open weights, then thought better of it. The Treasury Secretary threatened sanctions over IP theft, the White House accused Moonshot of distilling an Anthropic model to build Kimi K3, and the Times reports the administration leans towards action against specific models rather than a blanket ban.

Dario has said in writing that Anthropic has never advocated a ban on open weights, and argues a ban would protect US AI companies without addressing the risks he cares about. I take that at face value. It does not settle the competitive effect of the measures he does support. The essay never mentions open weights. It does say pacing within democracies only works if the US keeps its lead over China, and that the way to keep it is chip controls, a crackdown on distillation, and tighter security on the weights. Hand that framing to a Treasury already treating distillation as IP theft and you don’t need a ban on anything. Each new Chinese model becomes a sanctions question on arrival, and no lab has to be seen asking for it.

The scenario I plan for runs like this. Restrictions on specific Chinese models accumulate until they are too legally awkward for a US enterprise to run. That part is underway. The standard then travels to allies through export terms and procurement. That part is my forecast, with no evidence behind it yet, and Australia should not build an AI strategy on the assumption that it won’t happen. Then, with the cheapest and fastest-moving tier gone, the cost of frontier work goes up, with each release arriving on a benchmark chart and a new default tier.

The usual reply is that token rates have fallen for three years. For our workloads, lower headline rates have not turned into lower monthly bills. The newer models reason before they answer, call tools, read their own output back and try again, so a task that cost a few hundred tokens a year ago can cost tens of thousands now. That is an observation, not a controlled comparison. The tasks and the models have both changed. But it points at the number buyers should be measuring, which is the cost of getting the same job done to the same standard. The rate card dropping is not the same as that number dropping, and nobody publishes that number for you.

Several things cut against me. On 29th September the six biggest US labs signed a White House accord on frontier safety that is voluntary, carries no penalties, and lets each company pick its own auditor. That is not a government building a moat for anyone, though it says nothing about Chinese models either. In August the White House exempted open weights from pre-release review. And on 28th July more than a thousand people across the labs, most of them working researchers, signed a letter asking Washington for the tools to slow down, with Dario’s name alongside theirs. The appetite is real and it runs deeper than the boardroom. What would change my mind is rules that preserve viable competing models in writing. Until then I expect no slowdown in what ships. A company carrying US$518 billion it cannot cancel does not stop shipping. I expect a steadier cadence, better marketed, with each new incident narrated first by the lab that owns it. Pacing the frontier is a reasonable name for that. A business plan is a better one.

Which brings me to the part Australia can do something about. If Chinese models are going to be restricted and US models are going to cost more per job, what we need is the ability to run, adapt and maintain useful models on infrastructure we control, without a foreign provider’s continued permission. France got there early. Mistral was founded in 2023 by researchers out of Meta and DeepMind, raised private money, and has been championed by the French state ever since, which is why its open weights are what European institutions reach for when they want to avoid the question of whose rules apply. Those models were never the strongest available and did not need to be. European weights are a hedge for us too, but a hedge under someone else’s jurisdiction, and the point of this exercise is to stop depending on those.

So where is the Australian one? Maincode in Melbourne built Matilda from scratch, launched it as sovereign AI, then stepped back in October 2025 from the label and from publishing its weights, with its chief executive suggesting Australia is not a safe place to do so. What Maincode did release, in December 2025, was Maincoder-1B, a one billion parameter coding model under Apache 2.0. Credit where it is due. It is real and downloadable, and it is a specialised code model, not a general workhorse. Sovereign Australia AI has ordered the GPUs and announced Ginan, an eight billion parameter Llama fine-tune, with access still listed as coming soon in early October. Kangaroo LLM was announced in 2024 and, as far as I can find, has published nothing. None of it adds up to a general model an Australian business can pull onto its own hardware and point at the bulk of its work.

That gap is not a frontier research problem. The model does not have to win a leaderboard. It has to handle the mundane work well, the classification, extraction, summarisation, first drafts and routing that currently burn frontier tokens and shouldn’t. That gives every business in the country a lower-cost fallback and real bargaining leverage with the US labs. Public money should buy specific things. Usable weights under a permissive licence. Published results on exactly those routine tasks. Clear rights to run, fine-tune and redistribute. Funded maintenance so it is still alive in three years. Not another announcement with the weights to follow. Treat it as infrastructure, the way we treat roads.

In the meantime, if you build on these models, and we do, the lesson is dull but important. Keep an abstraction layer between you and your provider. Keep an open-weight model warm somewhere you control. Route the mundane work to it now, measure cost per completed job rather than the rate card, and treat today’s frontier price list as a promotional rate.

Originally published on linkedin.com.