PodBrowser
The Defiant

"Bazooka in Every Hand" Do We Really Want Unstoppable AI? w/ Jake Brukhman, Haseeb Qureshi, Jesus Rodriguez

Friday, 19 June 2026 · 4 min read · Listen to the episode ↗

Jake Brukhman, Haseeb Qureshi, and Jesus Rodriguez debate the U.S. government's quiet restriction of Anthropic's Claude Opus 4, in which Andy Jassy reportedly flagged a jailbreak to the White House and triggered a global cutoff affecting millions of users with no public process or appeal.

The episode centers on the U.S. government's restriction of Anthropic's Claude Opus 4, referred to throughout as Fable 5, and what that episode reveals about centralized control over AI. Haseeb Qureshi described the sequence as follows: Anthropic cleared Fable 5 with the national security apparatus before launch, the roughly thirty partners in a government-adjacent program called Project Glasswing were handpicked by the government rather than by Anthropic, and the shutdown was triggered when Andy Jassy went to the White House and reported a jailbreak involving a grandmother dying scenario. Camila Russo framed the outcome bluntly: a private company pressured by a government killed access to a technology for millions of people with no public debate and no way to appeal.

Jake Brukhman argued that centralized AI companies are structurally susceptible to exactly this kind of pressure because of their corporate form, and that the Fable 5 shutdown resulted in a global cutoff with no warning, no alternative, and no appeal. Jesus Rodriguez added a skeptical note, saying the shutdown felt theatrical because the successor model Mythos had already been pre-announced, and because his company LayerLens had benchmarked Fable 5 and found it capable of only very minimal cyber work, making the security justification appear staged. Rodriguez also argued that if the restriction was genuinely an export control issue, every American company should have had access rather than a selectively chosen group.

Haseeb pushed back on the framing that restricting frontier AI is obviously wrong. He argued that models like Claude Opus 4 should be treated under national security controls the same way fighter jets and missiles are, because if AI is taken seriously it is potentially the most powerful weapon ever invented and historically powerful weapons have been the remit of nation states. He pointed to crypto hack data as evidence of accelerating risk: April was the biggest month by number of hack incidents in crypto history up to that point, and then May set another record. His most pointed prediction was that a performant uncensorable frontier model would cause a COVID-level spread of cybersecurity attacks very quickly, particularly targeting software that cannot be patched, and that the damage phase could last years before infrastructure gets rebuilt and hardened.

Jake's response was that even if Anthropic restricts a model, equivalent capability will arrive anyway, either from an Asian lab open sourcing it or from a decentralized training run, and that people who need frontier models to protect their own systems will obtain them regardless. He cited Epoch AI data showing the frontier gap between open and proprietary models is closing, with open models from Chinese labs already within a couple of percentage points on evals compared to frontier proprietary models despite disadvantaged compute and processes.

The debate over decentralized AI as an alternative produced three distinct positions. Jake argued decentralization is the answer to the control problem, pointing to research showing reinforcement learning post-training is approximately ten times cheaper and ten times faster than previous methods, and noting that roughly half of total cost of ownership in data centers is facilities maintenance and coolant, costs absent in a decentralized swarm. His firm is conducting a training run called Pluralist entirely on consumer 4090 GPUs to demonstrate that a serious LLM can be trained on consumer devices. He also argued that when model weights are distributed across a network, revenue flows to token holders, users, and trainers rather than to centralized founders.

Haseeb challenged the decentralized training thesis on two grounds. First, distributed training over the public internet incurs unavoidable costs from compressed gradient updates compared to co-located machines on high-bandwidth interlinks, a point Jake conceded while arguing ongoing research addresses it. Second, and more fundamentally, he argued that one of the biggest constraints to training a large model is data rather than compute. Training a model at the scale of Fable or Mythos requires roughly eight trillion parameters, OpenAI and Anthropic pay large sums to data providers, generate synthetic data at enormous cost, and collect user data from products like Claude Code and Codex. He used Kirkland and Ellis spending five hundred million dollars on a proprietary dataset as his example, arguing that firm is spending that money precisely to keep its data private and internalize the value, not to share it with a decentralized network.

Rodriguez offered the most structurally critical view of decentralized AI, arguing it has failed to match the quality of centralized alternatives for approximately twenty years and that the gap has widened rather than shortened. He pointed to OpenAI's own statement that the model is no longer the product, arguing that decentralized AI projects are too focused on building models rather than the layer around them, and that the real value lies in tools, evaluations, data, and other surrounding components. He identified what he sees as the actual opportunity as modernizing crypto itself with AI, given how far behind crypto is technologically, and building modern finance applications at the intersection of DeFi and AI. Haseeb reinforced this by noting that even on Venice, a privacy-preserving crypto-native AI product, the most-used models are not decentralized-trained models but DeepSeek, GLM5, and other open-weight models from conventional companies.

This summary was generated from the episode transcript and can contain mistakes.