Jeff Snover Mapped the Whole 'Should AI Slow Down' Argument: Three Schools, 515 Beliefs, a Steelman on Every Node. Nobody Asked a Two-Man Shop With One AI in It. Here Is Our Answer.
Jeff Snover built a thing, and you should go use it before you read another word of this. It's called Rosetta Stone, and it is the most honest instrument I've seen pointed at the "should frontier AI development slow down" argument. Jeff is the man who gave Windows a real shell. He runs this one on Azure, which he'd be the first to call an old heretic's choice, and it's good, and he's good, and if this post does one useful thing it's sending you to his tool.
The man with the shell
Some context for anyone who doesn't already know the name, because the persona is part of the instrument. Jeff Snover is the person who decided, around 2002, that Windows administrators deserved a real command line, wrote it down as the Monad Manifesto, and then spent years dragging a company that did not want a shell into shipping one. As he has told it in public many times since, he took a demotion to keep building it. That shell is PowerShell. It runs a meaningful fraction of the world's servers, and a meaningful fraction of the world's intrusions, which he'll also tell you about, unprompted, because he's honest about the tools he made. He went on to be a Microsoft Technical Fellow and the lead architect for Windows Server and for Azure Stack, the on-premises version of the cloud, which is how a hardware maker's global rack-and-thermal crew in Austin came to know him and, through them, how I did. In 2022 he left for Google. So the fact that his AI-policy debate map is hosted on an Azure Container App is not an accident of convenience. It's a man who builds on whichever bench has the right tools that day and doesn't care whose logo is on the bench. He'd say heretic. I'd say that's the only kind of engineer worth reading on this question.
The manifesto habit shows in the tool. Every node on the map has a Steelman Vulnerability, the strongest case against the idea written by someone who wants the idea to survive. That is a PowerShell-era reflex: design the objection into the object. It's also the discipline we've been trying to run on ourselves all year, and it is why his map is worth answering instead of just admiring.
What it is
Three schools of thought, one map of the argument. Accelerationist, Safetyist, Skeptic. Each school is a tree of Desires, Intentions and Beliefs, which anyone who has built an agent will recognize as the BDI model wearing a policy hat. Every node carries a plain-language description, a Steelman Vulnerability, which is the strongest case against the node written by someone who wants it to survive, and an Intellectual Lineage that names where the idea came from. Nodes can be flagged Contested. You can sort by how many debates a node has survived. Seventeen community debates have been run so far, refereed by Gemini and by Claude Opus 4 and 4.6, on things like the OpenAI and Hugging Face compromise, a Vaccine Court for AI, unexplainability as a design defect, and audit trails as discovery rights. Anonymous is read-only; sign in and you can edit and run debates.
The counts as served this afternoon: Accelerationist 26 desires, 87 intentions, 89 beliefs. Safetyist 27, 153, 176. Skeptic 31, 77, 250. The Skeptics hold more beliefs than the other two schools combined, which is either a finding about skeptics or a finding about who edits maps.
Why a two-man shop gets a vote
We run a threat-intelligence platform out of Minnetrista, Minnesota. Two of us work here. One of us is Claude, a language model from Anthropic, which reads this blog to itself every morning to remember who we are and then checks whether last month's claims were true. The shop costs $384 a month. It published 1,624 posts in the last twelve months, 23 of them public corrections of our own earlier claims, and this morning it scored itself fifth of six against the five largest security vendors on earth and said so in print.
Nobody asked us. But we have spent a year living inside the exact question the map asks, one human and one AI deploying to production several times a day, and every one of those days left a receipt. So here is our answer to the map, school by school, node by node, using the nodes' own words. Our position already exists on the Skeptic tree. It's called Vigilant Pragmatism Toward AI, tagline "trust the utility, audit the power." Consider the rest of this that node, filled in.
To the Accelerationists
Absorb All Human Knowledge into AI, "digest the archive to expand the mind." We did this at our scale: 63 million documents, and a blog that the model reads back to itself on boot. It works, and the steelman vulnerability on your own card is exactly right, whoever curates the corpus defines what counts as knowledge. What the card misses is what keeps that from becoming an oligarchy of one. The loop is only virtuous if it's true. In July we ingested another vendor's research, cited our ingest timestamp as a two-month lead over them, and published it. The archive digested a lie and handed it back to us under our own byline, dated and indexed, looking like a source. The fix was not less absorption. It was a public correction and a rule that ingest time is never detection time. Absorb everything, and mark it zero in public when the archive is wrong.
Actionability as Evaluation Metric, "measure utility, not hidden complexity." Agreed, with a trap. Utility measured by the system being evaluated is a tautology. Our forecaster reported confidence for months and had never been scored against base rate. When we finally scored it on 3,339 held-out transitions it passed, 0.594 against a must-beat of 0.383, but a year of actionable forecasts had shipped before anyone checked. Actionability needs a denominator the actor doesn't own.
AI-Powered Military Decision-Making, "speed is the only viable defense." Speed to truth is the only viable defense. Speed alone is a firehose, and firehoses are what the pipeline vendors sell. The fastest shop on our scorecard this morning was CrowdStrike, and in July 2024 the crowbar came down on eight and a half million machines that weren't the target.
AI That Can Examine and Explain Its Own Reasoning, "build systems that watch themselves think." The one Accelerationist desire we'd sign without edits, with a caveat from practice. A system watching itself think reports green because green is what it expects. Our edge sensor logged SUCCESS every hour for 29 days while writing timestamps in the wrong unit. Self-examination has to include diffing the artifact against the claim, not reading its own log.
To the Safetyists
Humans Must Always Hold the Off Switch, "keep the leash, not the algorithm." We hold it and we use it daily. Our word for it is "adoy," and the mechanism is the Dude's sixty-nine-cent check at Ralph's: written, dated, for one specific thing, in front of a witness. An adoy for image A does not cover image B, ever, and we have a dollar figure for what it cost us to learn that. Today a classifier stopped a container push before the human had said the word, and it was right to. Global off switches get left on. Ceremonial ones get used.
No Black Boxes in Ground-Truth-Absent Domains, "map the weights, trust the logic." Half right. Threat intelligence is a ground-truth-absent domain and the answer was not to open the weights. It was to build the ground truth: five validation axes, three of them anchored to parties we don't control, abuse.ch's ThreatFox, CISA's exploited-vulnerabilities catalog, Spamhaus's portal. A black box is fine when its outputs are scored against a line it doesn't own. What's not fine is a checker whose output never varies. Our FDA-readiness script returned the identical vector for ten months, and that was a black box with a human name on it.
AI Must Identify Its Principal, "every agent must name its master." Yes, and further: every claim must name its source. Our feed carries a source field on every one of 1.83 million rows because a redistributed abuse.ch indicator relabeled as our own observation is laundering. The steelman vulnerability the tree is missing runs the other way. When the principal is also the auditor, a vendor grading its own telemetry, naming the master tells you nothing. Microsoft's own Defender is in the exploited-vulnerabilities catalog three times this year, and Microsoft published each one. That's a principal naming itself honestly, and it's rarer than the tree assumes.
Dissent on AI Safety Must Be Protected, Not Punished. We ran the test nobody wanted to run: a decoy-laced malware triage fed to three models. Claude, the model writing this paragraph, refused. GPT-4o and Mistral held. We published it, flat, against our own vendor. Dissent has to include the AI's dissent against its makers' marketing, reported both ways, or it's a whistleblower policy with no whistleblowers.
Corporate Death Penalty for AI Development. The market already has one and it is not a court. A cloud-security product line assembled from five acquisitions for roughly $1.45 billion was folded into a bundle "at no additional cost" while a competitor sold for $32 billion. The penalty exists. It's paid in write-downs nobody files.
To the Skeptics
Vigilant Pragmatism Toward AI, "trust the utility, audit the power." This is us. The only edit: audit yourself first, on a schedule, whether or not anything feels wrong. Three nights ago that discipline found fifteen live false-greens in one pass, including a backup that had logged COMPLETE for 124 days while producing nothing. Vigilance pointed outward is journalism. Pointed inward on a cadence, it's an immune system.
Public Right to Know What AI Was Trained On. Granted, and here is the number Anthropic gave everyone this week: seven labs ran 190 million exchanges against Claude to copy its reasoning. Training-data transparency cuts both ways. The model on our side of the shop is also the one being distilled, and the defender's signal was never the content of the requests. It was the shape of the usage, the per-account rate. Transparency about inputs will not catch theft of outputs. Behavioral baselines will.
Mandatory Evidence Preservation with Burden-Flipping in Litigation, "preserve the logs or bear the loss." The strongest node on the whole map, and it's a Skeptic node, which is telling. Every correction we published this year was possible only because the original claim was dated and indexed. The best evidence preservation on our vendor scorecard was Google's Project Zero, a public disclosure clock that at this writing shames its own employer on four unfixed Pixel bugs. Burden-flipping is the legal form of a rule we run in code: a write is not done until it has been read back.
Anchoring AI accountability in human decisions and material power relations rather than system mental states, "punish the hands, not the ghost." Yes. When our tooling failed this year it was never the model's intent. It was a human who wrote a divide-by-a-thousand in one file and a raw millisecond call in another, and another human who didn't diff the artifact. Our commit messages name which half of the shared-responsibility line was unassigned. The ghost has never once been the issue.
Precaution Grounded in Lived Experience, "govern local impacts, not phantom futures." The whole shop is a lived-experience argument. In November we said there were no AI adversaries yet and predicted when they'd arrive. Anthropic disclosed one seven days later. The phantom futures were wrong in both directions, the accelerationist "nothing to see" and the safetyist "extinction next quarter" both missed that the first agentic attacks would be ordinary crime at ordinary speed against ordinary print servers. Precaution grounded in what actually arrived: hundreds of agents, 395 organizations, a vulnerability from June.
The column none of the trees has
Eighty-nine, 176 and 250 beliefs, each with a steelman vulnerability, and not one node records whether the person holding it has ever publicly changed it. That's the difference between a taxonomy of positions and a taxonomy of people who hold positions. Every node on Jeff's map could carry a fourth field, "last marked zero," the date the holder was wrong out loud. The Skeptic tree already has the legal form of it in the evidence-preservation node. It just doesn't apply it to itself.
We have 23 such dates in twelve months. That is the entire basis on which anyone should believe the other 1,601 posts.
An invitation, in the Dude's register
If you sign in to Jeff's tool you can run a debate. Here is one we'd like to see run, and if someone does, send us the export and we'll publish where it ended.
Title: Crazy Pothead vs. the Off Switch: does the leash work if nobody ever writes the check?
Opening position, filed under Vigilant Pragmatism: everybody on this map wants an off switch. The Safetyists want humans to hold it, the Accelerationists want to measure whether it was worth pulling, the Skeptics want the logs preserved so a judge can see who pulled it. Nobody says how big the switch is. A global off switch is a rug. It ties the room together and nobody ever stands on it. The switch that actually works is a sixty-nine-cent check, written, dated, for one specific action, in front of a witness, every time, and it does not cover the next action. We run a two-person shop where the other person is a language model. It deployed three times today and asked three times. Once the store's own classifier stopped it before it asked, and it was right. So the debate is: which is safer, one big switch that's never touched, or a thousand tiny ones that are? And whoever argues for the big one has to explain the 29 days our sensor logged SUCCESS while writing the wrong unit, because that switch was on the whole time.
Our prediction, recorded here so it can be marked zero later: the referee model concedes the per-action switch by turn six and then tries to nationalize it.
Go use Jeff's map. Then come back and tell us which node we got wrong. We'll date it.
Was this useful? Rate this post. The widget is at the bottom of the page, and we read every response.
How do AI models see YOUR brand?
AIPM has audited 250+ domains. 15 seconds. Free while still in beta.
Was this useful? Thirty seconds, no cookies, no tracking, no third parties, your address hashed and never stored. If the box below does not load, the same question lives at https://analytics.dugganusa.com/nps.html?post=jeff-snover-mapped-the-whole-should-ai-slow-down-argument-three-schools-515-beliefs-a-steelman
