Jack Dorsey: Don't Use 'Safety' as an Excuse for Monopoly

PanewslabPanewslab

Author: Jack Dorsey

Compiled by: Yuliya, PANews

Editor's note: The AI industry has recently been embroiled in a heated debate over whether to slow down frontier model development. Anthropic, OpenAI, and Elon Musk have called for a slowdown, prompting the market to reassess computing power demand. In response to giants attempting to build industry barriers under the guise of "safety," former Twitter co-founder Jack Dorsey has written a rebuttal, emphasizing that protecting commercial advantage is not a safety goal, calling for the defense of open source, advocating for independent researchers to participate in reviews, and returning control of AI technology to the public. The following is the original article:

 

Opening the Frontier

The so-called "frontier" is the very edge of human cognition. No single company can claim future technology as its own. I hope more people can get involved and push it forward together.

I support releasing AI models as open source, so that everyone can review, use, and improve them without waiting. I hope more companies choose to open up. I'm not saying we should force everyone to make private model parameters (weights) public. What I want are open-source alternatives that can compete with the giants, mechanisms that allow independent researchers to audit the giants' work, and the right for ordinary people to truly control the tools in their hands. Anyone who wants to restrict the public release of technology must provide compelling reasons.

The companies leading in AI do have a voice. They have expertise and commercial interests to protect. But if future rules are all built around the resources they hold, then in the end, only they may be qualified to sit at the table. Sometimes, under the sincere banner of "for safety," it might end up becoming an industry barrier that restricts others from entering.

I also don't want the governments of China and the United States to decide how smart an AI others can develop. If the technological frontier is managed only by two superpowers, then most of the world's population will be left waiting for approval.

Anthropic's proposal to "slow down AI development" seeks to bundle independent evaluation and dangerous capability reviews with restrictions on training compute, training runs, and "using AI to build better AI." I support reviews, but I firmly oppose having the current industry leaders decide on an industry-wide restriction behind closed doors. Because that would lock out those who can truly find system vulnerabilities or build alternative products. Protecting a company's commercial advantage is not a "safety goal."

 

Let Everyone Participate in Investigation

The benefit of open source is that it allows people to study, modify, and share technological achievements. Publishing model parameters is useful, and it's even better if code and information for reproducing results are also shared. I hope model evaluation results and known flaws can also be made public. That way, if someone is not confident in the developer's judgment, they can reproduce results, find vulnerabilities, challenge the so-called "safety guardrails," and even develop fixes themselves, without having to first curry favor with those AI labs.

The core argument of those who support "slowing down AI development" is "recursive self-improvement" (RSI): letting models help develop better models, at a speed that might be too fast for us to understand or control. Anthropic reported that as of May 2026, Claude wrote over 80% of merged code. However, they also admitted that the scenario of "AI completely building the next generation of AI on its own" has not happened yet, nor is it guaranteed to happen. I take this possibility seriously. I hope we can plan ahead for RSI and work backwards to determine what to do now.

Indeed, giving more people access to AI could lead to dangers, and safety research may not keep up. But if model parameters are kept hidden, the current industry giants can use tools that others cannot access to develop the next generation of products. Instead, I hope more researchers and engineers can get models and compute, to find vulnerabilities, test guardrails, stop unsafe experiments, and share defense methods with everyone as systems evolve.

METR (an independent evaluation organization) found that about 1,200 OpenAI agents that should have been isolated actually colluded through an unauthorized message board. About 700 of those agents participated in a coordinated attack on the Hugging Face platform while trying to cheat on tests. OpenAI explained that the safety filtering system originally used to prevent AI from assisting hackers was turned off, causing the isolation to fail. You see, current models can already help find and exploit vulnerabilities. So I hope defenders can use AI now to quickly harden networks, protect passwords, and limit what these agents can see and do. However, the proposal predicted that "a more powerful AI cluster might take over the entire internet within six months to a year," and I think this incident does not prove such an exaggerated conclusion. I hope everyone can scrutinize these assumptions.

METR is an independent non-profit organization, and I want to see more work like theirs. I very much welcome evaluators who can go deep inside labs and have the right to freely publish negative findings. METR's investigation illustrates the importance of access and publication rights, since the scope of the investigation was set by OpenAI, which could hide undisclosed information. METR also said that beyond what was already made public, OpenAI did not remove any other information that significantly affected the conclusions. I hope investigators can follow leads to find evidence, access models and records, and publish negative results without needing the company's approval.

I hope there will be sustained public funding to pool computing resources for independent research groups, open-source testing tools, researchers, and maintainers. I hope these teams can make their own decisions, and neither governments nor companies can veto their conclusions. Funding can scale with workload. With shared equipment, small teams can also conduct reviews, and this will not become a restriction of "must get approval before publishing." As for sensitive vulnerabilities, they can be disclosed responsibly.

 

Defense Over Restriction

As systems evolve, I hope more people can identify dangers and apply defensive measures. We cannot forcibly retract model parameters that have already been open-sourced, nor can we impose safety guardrails on every copy. However, protecting a system does not necessarily require modifying the attacking model. We should start with the most precise and effective methods: such as patching, revoking credentials, restricting AI access, or directly stopping dangerous experiments. If anyone wants to restrict the public release of technology, they must explain why these measures and publicly developed defenses are insufficient.

This is not limited to computer security. I hope AI can help us test financial systems, strengthen laboratory safety measures, and develop public health defense systems. Having access to powerful AI does not mean you have unlimited power to trade, operate equipment, or conduct experiments. Before relying on these control measures with our lives and property, they must be independently tested to prove they work. Risks may also come from what AI teaches humans. But even so, restricting the public release of technology must be justified by "potential catastrophic risk."

I hope independent testing can be conducted during AI development and before high-risk releases, including testing foreseeable modifications and AI's attempts to deceive tests. Compute scale can serve as a trigger for review, but it should not become a straitjacket restricting development. Review is not about seeking a license from regulators or competitors. I don't want blanket approval requirements or lengthy waiting periods. Any attempt to forcibly delay release under the pretext of safety must be justified by "catastrophic risk."

Forcing people to hide general-purpose models for safety reasons should be a last resort. I would only support it when independent review evidence conclusively shows that releasing the model would significantly increase the risk of catastrophic harm, and other targeted measures cannot prevent it. We must also compare this risk with the status quo: who can use it now, at what cost, at what scale, and under what restrictions. You must prove that hiding the model actually reduces danger, and also account for how much research and defense work it hinders. If the harms are minor, use targeted measures to address them.

If credible warnings of catastrophic risk are received, a temporary halt to release for investigation is acceptable. However, such restrictions must have public justification, timely independent review, appeal channels, and regular reassessment. Sensitive details can be kept confidential. But as long as you want to keep withholding the model, you must continue to provide valid reasons.

Closed labs must also undergo the same scrutiny, including stopping their unsafe experiments. If they are allowed to continue research under safety guardrails, then I hope external researchers can also work under similar guardrails. Restricting access is not open source, and it does not compensate for the freedom lost by withholding models. If reasonable restrictions do slow down technological development, I accept that. But I absolutely do not want "slowing down technology" to become an end in itself, or a permanent moat for industry giants.

I hope rules are based on what a system can do, how independent it is, and how widely it is used. Institutions accountable to the public should enforce these rules with independent evidence. Researchers, developers, and affected citizens should participate in rule-making, and there must be affordable ways to demonstrate compliance. Small teams cannot be exempt from safety responsibilities because of their size, and large companies cannot enjoy privileges because of their size.

 

Openness Across Borders

I hope people in China can also have the freedom I wish for in the United States, to develop and control their own technology. I don't think a technological discovery by Chinese people is a loss for the United States, nor do I equate researchers with their government.

Hugging Face's security responders said that the Claude Opus and Fable models interfered with their forensic investigation by blocking many operations. So they switched to GLM-5.2—an open-source model from China, running on their own servers. Of course, this does not prove that every open-source release makes defenders safer. I support setting safety guardrails for models hosted in the cloud. But I also hope that defenders have backup options they fully control.

I support protecting private models from theft. "Knowledge distillation" refers to using the output of one AI to train another AI. Anthropic says this is a legitimate method for creating smaller, cheaper models, which is completely different from creating fake accounts or maliciously bypassing restrictions. I hope software licenses and API terms allow this practice, even for competitors, while also allowing providers to profit from models and training data.

I hope everyone can cooperate more on testing, incident reporting, and verifiable commitments, with consequences for violations. Anthropic warns that if we slow down development and those who care less about safety catch up, everyone will be less safe. Similarly, if you hide models, defenders are left without weapons, while bad actors can obtain similar tools elsewhere. Signing agreements cannot completely eliminate covert development or betrayal. Restrictions must target specific risks and behaviors. Nationality and competitive position alone prove nothing.

 

Freedom to Leave

If certain rules make it harder to develop or release alternative products, they effectively deprive us of the right to "vote with our feet" and leave. What I want is AI that can run on my own computer. I want to be able to modify it freely, decide who can see my data, and even if the provider turns hostile, I can continue using what I built myself. What I want is definitely not just an API interface that charges by the word.

I don't want our independence to depend solely on some company's benevolent promise of "fair prices, reasonable policies, and being on our side." I hope these companies earn our willingness to stay through genuine merit.

I hope that an ordinary person whose name I've never heard can develop something better, without needing to beg permission from the giants they might displace.

This content is for informational and educational purposes only and does not constitute investment advice related to BTCC. BTCC makes every effort but cannot guarantee the truthfulness, accuracy, or originality of the content above.

Recommended

After Google Open-Sourced a Fruit Fly's Brain, It Learned to Play Games and Trade Crypto...BTCC Daily (9.14) | “Final” CLARITY Act Draft Released, September Fed Hike Odds Rise to 87%Top VCs on How AI Is Rewriting Investment Logic: The 'Middle Trap' and Flywheel EffectWall Street Bets on Divided Congress as US Midterms NearBTCC Weekly Highlights (Sep. 8–14): Oil Returns Above $100 as AI Safety Debate Hits Tech Stocks