Decelerate by using Capitalism Itself

16 min read
by Joseph Perla
#ai#privacy#safety#trustedrouter#attestation

If you want AI to slow down, stop asking anyone to slow down. Charge them for the data.

Everyone in the safety world says capabilities are outpacing alignment. It has been repeated so many times that it functions as a throat-clearing noise rather than a claim. Here is the version with a mechanism in it: the speed of capability gain is set by a competitive process that has no line item for whether anybody understands what is being built. Not a small line item. There is no line in any lab's financial model called interpretability debt. A firm that slows down to close that gap loses share to a firm that doesn't, and the firm that doesn't gets the capital, the compute, the talent, and the next training run. This isn't villainy. It's what every market does when the externality is unpriced, and this externality is unpriceable, because the party who would sue you is a future that may or may not exist.

So be precise about the dangerous variable. Capability isn't doom. Rate is doom. A world that gets to transformative AI in 2045 with twenty years of accumulated interpretability, formal methods, hardened infrastructure and institutional practice is a different world from one that gets there in 2029 with a pile of evals and some vibes. Same destination, wildly different survival odds. The thing we want is not stop. It's slow. And slow is the one intervention our toolkit is worst at delivering.

Look at what we've tried. A voluntary pause requires unanimity among parties who have every reason to defect and no way to detect each other defecting; whoever pauses gets replaced by whoever didn't, and the 2023 letter is now a cultural artifact instead of a policy. Regulation is slow, bounded by jurisdiction, captured with impressive speed, and double-edged, because compliance is a fixed cost and fixed costs favor incumbents — a regime that demands a $50M safety apparatus is a regime where only frontier labs can operate. You have thinned the race without slowing it. Compute governance is the most serious proposal in the family, but it routes through export control, which routes through geopolitics, which routes through a rival state that has correctly worked out that this technology is strategically decisive. Asking a Chinese lab to slow down over p(doom) is asking a nation to accept permanent subordination on the basis of an argument it doesn't accept. And moral suasion is the ugly one: it works best on the labs that already take safety seriously, which means its net effect is to move the frontier toward labs where it has no purchase at all. Suasion disarms the careful.

Every one of those levers asks people to want something other than what they want. That's why they lose. Markets beat arguments.

Meanwhile look at the flywheel they're up against. Take Anthropic, not because it's the worst actor but because it's the hardest case — it publishes its scaling policy and funds a real interpretability team, so if the structural argument holds there it holds everywhere. The disclosed run-rate sequence goes roughly $9B at the end of 2025, $14B in February 2026, $19B in March, $30B in April, $47B alongside the Series H in mid-May, with third-party trackers putting late-summer ARR in the high $60s and The Information doing the arithmetic on $100B annualized inside the calendar year. They filed confidentially for an IPO on June 1 at a reported $965B. Argue about run-rate versus trailing revenue if you like; the gap between them is the entire point of an exponential. Revenue funds compute, compute funds capability, capability funds revenue, and the loop runs as fast as capital markets will allow. Capital markets are enthusiastic.

Now the part that should bother you more than the revenue curve. The labs are being paid to receive their scarcest input.

In every extractive industry that has ever existed, the firm pays for the raw material. Oil companies pay for leases, smelters pay for ore, pharma pays trial participants. The AI industry invented something better: its customers pay it for the privilege of supplying the material that trains its successor. And the material is not marginal. Public text is running out, which is the stated premise of published frontier research, not a guess. What's left in quantity is private: internal code, internal documents, expert corrections, tool traces, failed attempts, and the record of which answer a domain expert finally accepted. That last category is expert preference data at scale, generated for free, in a transaction where the expert is the one paying. Every enterprise API call is a revenue event and an acquisition event at the same time. Nobody designed this. It's the best flywheel in the history of capital formation.

The contractual promise around it is real, and I don't think the big labs are lying. But notice the promise is about rows. Read Generative Data Refinement: Just Ask for Better Data (Jiang et al., Google DeepMind) as an economic document instead of a technical one. It opens by naming the problem: training sets are growing faster than new text appears on the web, with exhaustion projected inside a decade, while far more text sits in user-generated content that labs have avoided because it carries PII, copyright and toxicity risk. The method is to condition a generative model on each real example, rewrite the parts that make it unusable, and keep the parts that make it valuable — and the authors are explicit that conditioning on real samples is what preserves the diversity that ungrounded synthesis lacks. They validate it across tens of thousands of sentences, a hundred-plus PII categories, over a million lines of code from hundreds of repositories, and a detoxification run where the model still learns the facts after the toxic wording is gone.

Now reread we do not train on your data and ask which data. The row you sent can be deleted. A derivative conditioned on that row can live forever, and the training job that eats the derivative is, truthfully, training on synthetic data. Zero data retention has the same shape available to it: raw bytes arrive, a transformation runs, the derivative gets written somewhere else, the raw bytes are deleted, and every sentence in the policy remains true. A contract can close this, but it has to name derivatives, de-identified content, model improvement, product improvement, research and partner disclosure. Three letters don't tell you whether yours does.

I know people who run this kind of pipeline. I can't source that, and you should discount unsourceable claims from strangers on the internet as a matter of policy. You also don't need it. Strip my private information out entirely and the argument survives, because the argument was never they are doing it. It's that the technique is published, validated and cheap; the economic pressure to use it grows as public text runs dry; and the data holder has no way to check whether it's being used on their traffic. Where those three hold, the incentive wins eventually, at some lab, in some quarter, under some pressure, and you learn about it after it's priced in. Closed source, an unpublished binary, a plaintext prompt and a privacy page describing a company's current intentions toward itself give your computer nothing to check. The verification gap is the finding. My private information only means the clock started earlier than you'd otherwise assume.

Which brings me to the move. Aikido doesn't block force, it redirects it along the attacker's own line of motion. Leave the wanting exactly where it is and change the price of an input.

The flywheel rests on a hidden assumption: that the marginal cost of frontier-relevant private data is about zero, because it arrives attached to revenue. That's an artifact of an architecture where prompts show up in plaintext on a server the sender can't inspect. Change the architecture and the assumption dies. If enterprise traffic moves through infrastructure where the privacy property is architectural — the operator's control plane never sees prompt or output bodies, the code that touches plaintext is published, and the running image can be attested so a different binary produces a different measurement — then the lab stops receiving the data as a free byproduct of the sale. It has to buy it, separately, at a negotiated price, from a counterparty who now knows what they're holding.

The specific vendor doesn't matter and shouldn't; a privacy monoculture is a differently-shaped single point of failure. The properties matter: hidden by default, checkable by the client, and no business model on the other side that depends on it not being checkable. This is not a boycott. Nobody stops buying inference and nobody coordinates with anybody. The enterprise protects trade secrets, customer PII and its regulatory posture, which it wanted anyway — the CISO has been asking since 2023. The infrastructure provider captures a market that barely exists yet. The lab gets a real cost line for a real input and prices its training runs accordingly. The cost of the next capability jump goes up and nobody agreed to slow down. It also survives the China objection better than anything else on the list, because data markets need no treaty and no enforcement agency. A firm in Frankfurt, Singapore or Shenzhen that decides its proprietary corpus is an asset rather than an emission is acting on identical self-interest whichever lab is asking. Data nationalism is one of the few things every major power already agrees on.

Is this tractable or merely elegant? Before 2022, shipping your unredacted corporate documents in plaintext to a third party for processing under terms you couldn't verify was a compliance incident. Not a debate — an incident, and someone lost a job over it. AI got a norm exemption, granted in the rush because the capability was too useful to wait for the security review, and it has never been formally revisited. That exemption is the whole foundation of the free-data flywheel. Revoking it needs no new law and no new argument. It needs enterprises to apply to AI vendors the standard they already apply to every other processor of sensitive data, and it needs "we promise" to stop counting as a control once "you can verify" is technically available. The security function is the best-funded, most politically empowered department in most large organizations, and it's already motivated. It never has to hear the word existential. Deceleration arrives as a procurement checklist.

This already happened once, at scale, run by a company with no stated interest in AI risk. Cloudflare sits in front of roughly a fifth of web traffic. On 1 July 2026, under the label Content Independence Day, it split crawler identity into search, agent and training, on the reasoning that these are different uses and should have different controls. Then it set a deadline: from 15 September 2026, mixed-use crawlers that blur search and training are blocked by default on any page carrying ads, for new customers, new sites of existing customers, and every free-tier account. Alongside it, Pay Per Crawl — billing crawlers per fetch over HTTP 402 — is being extended to pay publishers when their content actually surfaces in an answer. The ratios are the interesting part. By Cloudflare's own numbers, Anthropic's crawler was fetching on the order of 38,000 pages for every referral visit it sent back, and OpenAI's ratio was around 1,091. By June 2026 training crawlers were 50.6% of AI bot traffic on the network while search bots, the ones that historically paid in clicks, were down to 10.7%, and more than half of all AI crawl traffic was re-fetching pages that hadn't changed. Nothing in that sequence involved existential risk, coordination between publishers, legislation, or a request that any lab slow down. An infrastructure provider changed a default on behalf of its customers' commercial interests, and the price of a training input went from zero to negotiable across a fifth of the web.

Two caveats, because the differences are where the lesson lives. The coverage overstated it: the "100% block, no exceptions" headlines were inflated, and the new defaults land on newly onboarding zones and free-tier accounts rather than automatically on every existing site. Norm flips are partial and slow even when the infrastructure provider is fully committed. The second one matters more: raising a price by policy creates an arbitrage, and the arbitrage is already visible. As blocks tightened on user-agent-identified crawlers, demand moved to residential proxy networks that make automated traffic look human. A robots.txt directive is a request. A 402 is a request with a price tag. Neither one is a constraint. You can proxy around a block; you can't proxy around an enclave. If the plaintext never leaves your perimeter in a form the counterparty can read, there's no gray market in reading it, because the property is enforced by the architecture rather than by the other side's willingness to respect a header. The public-web fight shows the economics work and the norm can flip. The enterprise fight is where the same logic has teeth.

Say this buys eighteen months. Eighteen months of what? Mechanistic interpretability first, a field in a period of steep returns and bottlenecked on serial research time in a way money only partly relieves. Then security hardening against weight exfiltration, which is in worse shape than public discussion implies. Evaluation science that measures something besides benchmark saturation. And the slow construction of institutions that can decide anything on a timescale shorter than a legislative session. None of it is exciting and all of it scales with calendar time, which is the whole argument for buying calendar time.

There's a better reason to want this than the months, though. The same primitive that makes data expensive also breaks the auditing standoff. Third-party safety auditing has been stuck for years on a real impasse: labs can't hand model weights to outside auditors, and auditors can't certify what they can't run against, and both refusals are reasonable. Confidential compute dissolves it. Pour Demain, a Brussels AI policy shop, reports building exactly this — a verifiable clean room where gray-box interpretability evaluations ran against a 744-billion-parameter model inside hardware enclaves. The auditor brings the evaluation, the lab brings the weights, both sides get cryptographic proof of which code ran, and the weights never leave the enclave. The hardware is the trust. So the infrastructure buildout this essay wants is the same buildout that external auditing, secure weight custody and verifiable eval reporting all need, and the enterprise privacy market is the thing that will pay to build it at scale, because "our data doesn't leak" is a budget line and "we could audit frontier models" is not. Buy the deceleration, get the audit infrastructure. That's a better deal than any pause was going to offer.

Where does this most likely fail? The objection that decides it is that frontier gains may no longer be data-bound. If the dominant driver has moved to RL against verifiable rewards — math, code, tool use, anywhere correctness is machine-checkable and signal can be manufactured without limit — then taxing private text raises cost at a margin that isn't binding, and you slow personalization and product polish without touching the thing you care about. I take that seriously. My guess is that grounded real-world traces still matter a lot for the messy long-horizon agentic capabilities that most risk arguments actually run through, and that the diversity property is exactly what synthetic pipelines can't manufacture, which is why the DeepMind paper exists at all. But "my guess" is load-bearing there and I'd update hard on good evidence.

Three more failure modes worth naming. The coordination problem may come back rather than get solved, because one enterprise withholding is worth nothing and the mechanism only bites at scale; I claim it's a better coordination problem — incentive-compatible, no unanimity, degrades gracefully, recruits people who don't share the motive — and better is not solved. It may still tax the scrupulous, since the labs likeliest to respect an encryption boundary are the ones already trying to honor a privacy promise, and encryption at least binds regardless of intent, but the routing decision stays voluntary and voluntary decisions select. And encryption costs safety: content no provider can see is content no provider can screen, which means you've hardened the channel a determined bad actor most wants hardened. Anyone who tells you that resolves trivially in privacy's favor is selling something. The partial answer is that attested compute lets policy enforcement run inside the enclave, where the plaintext is, without the operator keeping it — and that's a design problem someone has to actually solve. Follow the incentives here too: every vendor in this category, mine included, profits from the belief that labs are extracting your data. That doesn't make the paper or the verification gap less real. It means evaluate architecture, not marketing. An unverifiable privacy claim from a privacy vendor is worth exactly what an unverifiable privacy claim from a lab is worth.

If you control enterprise AI spend, you're holding a lever almost nobody in this argument holds. Search your ZDR terms for the word derivative; if it isn't there, you didn't buy what you think you bought. Ask what your computer can check rather than what the policy says, because "show me the attestation" is a normal procurement question in every other security domain. Price your corpus and license it as the strategic asset it is instead of letting it leave as a byproduct of a transaction you're already paying for. And say all of this out loud in negotiations, because a hundred CISOs asking the same question moves a roadmap faster than any open letter ever has.

None of it requires you to believe anything about p(doom). Make the data cost money and the race gets slower on its own.

More on this

Enjoyed this essay?

Follow me for more insights on technology, startups, and the future.