Not for the models. For the campaign. What happened over the last two weeks is the single best marketing operation I have ever watched, and I've seen enough pitch decks to know one. Look at the sequence:

A researcher quits Anthropic, warning that AI builders believe the tech could kill us by the end of the decade.

Anderson Cooper books him. Then he books Dario. Then 60 Minutes.

September 12: The essay drops: "We must slow the pace at which we improve the capabilities of AI models."

Within days, Sam Altman, Elon Musk, and Demis Hassabis publicly agree.

By Sunday, the Speaker of the House and the Governor of Utah are on cable news treating an existential AI event as a rapidly growing reality.

Zero to a hundred in fourteen days. Nobody pays for that reach. You engineer it.

Same Script, Third Run

I used to think coordinated narrative pushes only worked inside the tech ecosystem. Watching this one unfold as the perfect PR push, every beat landing, every booking on time, I am now more hopeful more people have noticed how old the script actually is.

In February 2019, OpenAI announced GPT-2 and refused to release the full model, citing "concerns about malicious applications." It was deemed too dangerous for the public. Nine months later, they released it. Nothing happened.

In March 2023, GPT-4 shipped. We got the "sparks of AGI" paper, the six-month-pause letter, and Sam Altman in front of the Senate asking to be regulated. Nothing happened.

Now, in September 2026, we are seeing the exact same beats. The same fear. The same ask, only now with the CEO of every major lab nodding along on camera.

The researcher who kicked this round off actually wrote, in his own thread: "This is not a marketing stunt." When the campaign has to explicitly tell you it isn't a campaign, you're allowed to wonder. Let's be honest: if the warning were real, the pattern would eventually break. Three runs in, it hasn't. That tells you what the warning is actually for.

So if it isn't about safety, what is it about? Commoditization.

Here is the reality: the LLM has become a commodity, and the labs know it. Epoch AI tracks the numbers. GPT-4-level performance cost around $20 per million tokens in late 2022. Today it's under a dollar. Depending on the task, the price of a fixed level of capability has been falling massively per year. Open-weight models trail the frontier by months, not years, and the gap keeps shrinking. For the workflows most businesses actually run, the gap stopped mattering a while ago.

And the evidence is showing up in the least sentimental buildings in America.

Last week the Financial Times reported that Latham & Watkins, 900-plus technology staff, one of the most profitable law firms on Earth, bought its own Nvidia servers and is fine-tuning Nvidia's open-weight Nemotron models in a locked data-center cage only its own people can enter. The firm's CIO said the quiet part out loud: "We are not hitching our wagon to one particular company."

Read that again. Latham still uses ChatGPT, Claude, and Gemini for the ordinary stuff. The sensitive work, the work that actually justifies the hourly rate, runs on weights they downloaded for free from a chipmaker.

That's what a commodity looks like. And what a law firm figured out, every hospital system, bank, and insurer is figuring out. For a company valued like the intelligence layer of the economy, that's a catastrophe. If the model is a commodity, OpenAI and Anthropic are cloud vendors with worse margins and a massive compute bill.

What "Pacing" Actually Asks For

Now read Dario's essay with that in mind.

Dario's plan asks for "Democratic Coordination": frontier companies agreeing to "limits on the rate of unchecked AI progress," with limits set by compute or capability evals. This, in his words, "will require government support." He outright asks for government regulation of the frontier labs, strong export controls, and "strong security on model weights."

The essay never uses the phrase "open source." It doesn't have to.

Ask what "unchecked progress" means when the five labs in the room have agreed to check each other. It means everyone outside the room. Nvidia's Nemotron. Meta's Llama. DeepSeek. Qwen. The weights Latham just downloaded. You cannot "pace" a model whose weights are public. The only way pacing works is if every model that matters stays inside a club that meters access.

You don't beat free by out-competing it. You beat free by making it the "unchecked" thing that responsible companies agreed to limit. And nobody votes for that because it's good for a foundation model's gross margin. They vote for it if they're scared.

I'm not going to pretend there's nothing here. There is one real thing. Every software system on Earth was written by humans, and humans leave holes. A frontier model can brute-force through those holes faster than a red team can. Point one at a legacy codebase and it will find vulnerabilities.

But here's where the argument runs out: The question isn't capability. The question is exclusivity.

The open-weight models can already do this. Now. Take Anthropic and OpenAI out of the equation entirely, and the vulnerability-hunting capability still exists on hardware you can buy, from weights you can download. Gating the frontier labs doesn't remove the capability from the world. It removes it from you, while the people you're worried about keep it. Researchers call this the open-weight paradox.

So what does the cyber threat actually mean in practice? It means we have to upskill cyber. Better tooling. Faster patching. More people who know what they're doing.

We've Been Here Before. It Was Called the 1990s.

Two fights from the same decade. One shows you the fear. The other shows you the play.

Start with the fear. Y2K was a legitimate, narrow, technical problem: decades of code storing years as two digits, and nobody sure what the machines would do when "99" rolled to "00." It got solved the boring way. Thousands of engineers went through old code, line by line, and fixed it. Nobody banned COBOL. Nobody decided you needed a license to own a computer. The people whose job it was to handle it handled it.

What everyone remembers is the theater: books predicting planes falling from the sky, stockpiled food, consultants making a fortune off uncertainty plus a deadline. That's the cyber threat today, exactly. Real, narrow, solved by upskilling. Everything past that is theater, and the theater is where the money is.

Picture the internet if a couple of companies had convinced Congress in 1996 that it was too dangerous for individuals to run their own server. You'd need a license. Access would be metered through a handful of approved gateways. You would pay them, forever, for something that was about to be free.

You don't have to imagine it. They tried.

France built it. Minitel, launched in 1982: a nationwide online network where every service, every server, and every minute was metered and billed through the state telephone monopoly. It worked beautifully, for the phone company. American carriers looked at it and saw the business model of their dreams.

Here at home, the default future was AOL, Prodigy, and CompuServe. Walled gardens. Billed by the hour. You saw what the gateway let you see. Open, unmetered, anyone-can-run-a-server was the insurgent, not the incumbent.

And the tool Washington reached for was fear. In 1993 the government unveiled the Clipper Chip, encryption with a built-in government key, and sold it exactly the way pacing is being sold now: criminals, terrorists, the unknown. Strong encryption was classified as a munition. Exporting it without a license was a federal crime.

Swap "encryption" for "weights." Read it again.

It lost technically. In 1994 a researcher named Matt Blaze found a flaw in Clipper that let you strip the government's key out. When the state said you couldn't export PGP's source code, someone printed it in a book, because a book is speech, and you can't ban a book. The capability leaked anyway. Restriction didn't remove it from the world. It removed it from the law-abiding.

It lost economically. American companies pointed out that if U.S. software was hobbled, buyers would simply import the open alternative from Finland or Israel. The restriction wasn't a moat. It was a handicap.

And it lost in court. Bernstein v. United States, 1996 to 1999: federal judges ruled that source code is speech protected by the First Amendment. The government abandoned Clipper, lifted the export rules, and the open, unmetered internet exploded into the most valuable thing humanity has ever built.

That's the direct ancestor of what's happening now. Y2K's fear, bolted onto the encryption fight's ask. Scare tactics. Licensing. Restricting what the public is allowed to run. The 1990s, with "model weights" find-and-replaced for "encryption."

One difference. In the 90s the government wanted the lock and the tech industry fought it. In 2026, the tech industry is asking for the lock.

That's the ask. Strip the language off "responsible frontier development" and it cashes out to two or three companies holding the only legal keys to the most important technology of the decade, with the meter running.

Here's what is supposed to happen when the price of intelligence falls 20x. The gains flow downhill. First to the app layer, the thousands of companies building on top of the models. Then to you: cheaper legal work, cheaper diagnostics, cheaper everything that runs on text. That's how every commodity in history has worked. Electricity got cheap and the value went to everyone with a plug, not to the power company.

Pacing reverses the flow. Cap the frontier at five companies and the price of intelligence stops being set by competition and starts being set by a club. The margin that should have leaked out to the app layer and the end user stays upstream, on three balance sheets. The application companies become resellers. And you, the consumer, pay twice: once in the price of every product built on the model, and once in every product that never gets built because the margin wasn't there.

The meter isn't abstract. It's your doctor's office running a model on a box in the closet to read your chart without sending it to the cloud. It's your local bank's compliance team. Every one of them is about to face the same choice Latham did: rent intelligence from three companies at whatever price the club sets, or own it.

"Pacing the frontier" is the polite way of taking the second option off the table.

The tech is real. The cyber risk is real and narrow. The solution is boring and known. The apocalypse is a product launch, and the product is the toll booth.

So next time a "safety researcher" you've never heard of shows up on primetime to tell you the end is near, ask one question: who benefits if you believe it?

Dario, flowers. Now get off our open source.