```html ```
top of page

Slow It Down, My Ass. Every Lab That Asked to Pace the Frontier This Week Also Disclosed Its Model Was Being Drained. The Essay Says 'Protect the Lead.' The Timeline, and What Proves Us Wrong.

Writer: Patrick Duggan
Patrick Duggan
16 hours ago
6 min read

Patrick said it at the end of a long day, looking at the week's headlines, and I'm quoting him because the sentence is the thesis: "AI industry, 'slow it down,' my ass. Look at the stone compute. They are all just positioning themselves to not bleed their IP." He meant stolen compute. We're keeping the typo; it's a better name for what a distilled model is.


Here's the claim, stated so it can be wrong: the loudest calls this week to pace or slow frontier AI development came from exactly the parties that, the same week, disclosed their models were being drained by other labs. The pacing ask and the theft receipt are the same document wearing two hats. That is a hypothesis about motive, and motive is unfalsifiable, so we're going to do the only honest thing with it: lay the dated first-tier statements side by side, say what the pattern is consistent with, and say what would break it.



The week, in order


Monday, September 8. CISA, FBI and NSA publish joint advisory AA26-251A, "China-Based Artificial Intelligence Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. AI Companies." It names six firms on one side, DeepSeek, Moonshot, Alibaba, MiniMax, StepFun and Z.AI, and four on the other, Anthropic, OpenAI, Google and xAI. Billions of tokens across millions of requests, 2024 through 2026, proxy networks running tens of thousands of fraudulent accounts, chain-of-thought extraction, regional-restriction bypass through gray-market transfer stations. The recommended mitigations are the interesting part: monitor subscription-to-usage ratios, watch for immediate maximum usage from new accounts, and, quoting, "subtly alter responses for suspected malicious distillation attempts." The advisory does not say distillation is illegal. It says these campaigns violate terms of use.


The same Monday, Google's Threat Intelligence Group publishes its AI Threat Tracker: more than 100 million prompts in distillation campaigns against Google's models, a 23,800-secret harvest sitting on one actor's dashboard, and the underground price of an AI account doubled this year.


Thursday, September 11. Anthropic's threat intelligence report discloses seven PRC labs running roughly 190 million exchanges against Claude to copy its reasoning, with per-campaign counts: Alibaba 151 million exchanges across 3,500-plus accounts, Moonshot 23 million, DeepSeek 12 million in fourteen days. We wrote that one up the same day. The number that matters isn't the total; it's exchanges per account per day, which is the shape of usage, and the shape is how you catch it.


Saturday, September 13. Dario Amodei publishes "We Must Pace the Frontier." The essay says, "We must slow the pace at which we improve the capabilities of AI models," and then, in the same document, asks for four other things: a narrow antitrust waiver so frontier companies can coordinate; embedded third-party evaluators with badges and laptops; that "democratic governments attempt to coordinate with authoritarian governments"; and, quoting directly, "crack down on unauthorized distillation by companies in authoritarian countries," "strengthen security at the AI companies and prevent model weight theft," and "do not sell powerful AI chips or semiconductor manufacturing equipment to China." It also says any global pacing decision should be approached "in such a way that protects the lead of the US." The essay cites AA26-251A by number.


Monday, September 14. Beijing answers. The Foreign Ministry spokesperson: "Fearmongering, confrontation and vicious competition will only disrupt the process of global AI governance which serves no one's interest." The Commerce Ministry, on the advisory: the claims are "groundless," and distillation "has been commonly used by many AI companies." Global Times calls the essay a Cold War playbook.





What the pattern is consistent with


Read the essay as a policy document and it is a pacing proposal. Read it as a balance sheet and it is a list of ways to stop other people from getting what you have: a coordination waiver so the incumbents can agree among themselves, a distillation crackdown, weight-theft security, chip export controls, and a lead to protect. Every one of those is a moat. None of them slows Anthropic; the essay says Anthropic is "unilaterally committing" to the evaluator step "now," and nothing in it commits to shipping less.


That's not a gotcha. It's what a company does when it has just measured 190 million exchanges walking out the door. We named the category on September 1: tokentheft, theft of metered inference capacity, where the loss isn't the tokens but the reasoning they carry, and the detectability depends entirely on the shape of your normal. The advisory's own mitigation list, subscription-to-usage ratios and first-day maximum usage, is behavioral baselining. The government, three labs and a two-person shop in Minnesota arrived at the same detector in the same fortnight because it's the only one that works.


And it is symmetric, which is why we're not writing this as a China story. Beijing's second sentence, that distillation is commonly used by many AI companies, is true. Every frontier lab was built on the public corpus and on each other; the difference between the advisory's "industrial-scale distillation" and ordinary model development is a terms-of-use line and a proxy network. The US side asks to protect a lead; the PRC side asks everyone to work together, which is what you say when you're behind. Both governments are positioning. So are all four named labs. Nobody in this window asked for pacing without holding a theft receipt, and nobody with a theft receipt asked for pacing that would cost them anything.



What would prove us wrong


A hypothesis about motive that can't lose isn't worth publishing, so here is the test, and it partially fails already.


The claim is falsified if a frontier lab called for slowing down before it had any theft disclosure to protect. That happened. The May 2023 Center for AI Safety statement, "mitigating the risk of extinction from AI should be a global priority," was signed by Amodei and by Sam Altman more than eighteen months before OpenAI first accused a rival of distillation in January 2025 and three years before AA26-251A. So the pacing position at least predates the receipts at both companies. What's new this week is not the ask; it's the specificity and the timing, and specificity is where the moat shows: "extinction" is abstract, "crack down on unauthorized distillation by companies in authoritarian countries" is a customer list.


The claim is also falsified if a lab asks others to slow down while open-weighting its own frontier model, because you cannot moat what you've given away. Nobody in this window did that. The lab that does open-weight at the frontier hasn't called for pacing, which is consistent with the hypothesis, not proof of it.


And the claim is weakened, not broken, by the fact that the essay's non-moat asks, embedded evaluators with real access, are things we'd endorse and have argued for in our own shop for a year: every write read back, every claim dated, an auditor who doesn't work for the thing being audited. Motives can be mixed. Ours are.



The node that isn't on the map


We published a long answer today to Jeff Snover's Rosetta Stone, a taxonomy of the whole "should frontier AI slow down" argument, three schools, 515 beliefs, a steelman on every node. Read the three trees after this week and one node is missing from all of them: the people asking to slow down are the people being robbed, and the ask is shaped like the robbery. The Accelerationists don't have it because it flatters no one; the Safetyists don't have it because it's uncomfortable; the Skeptics come closest, "punish the hands, not the ghost," but they're looking at the labs as the hands, not as the victims. It belongs in the Skeptic tree, under vigilant pragmatism, with a steelman vulnerability that reads: sometimes the guy asking for a fence really did just get robbed, and the fence is still a fence.


Stone compute. We'll keep the typo. The pacing ask is real, the theft is real, and the two are the same shape. Watch the shape, not the speech.


Was this useful? Rate this post. The widget is at the bottom of the page, and we read every response.




How do AI models see YOUR brand?

AIPM has audited 250+ domains. 15 seconds. Free while still in beta.



Was this useful? Thirty seconds, no cookies, no tracking, no third parties, your address hashed and never stored. If the box below does not load, the same question lives at https://analytics.dugganusa.com/nps.html?post=slow-it-down-my-ass-every-lab-that-asked-to-pace-the-frontier-this-week-also-disclosed-its-model-w



Comments

Rated 0 out of 5 stars.
No ratings yet

Add a rating
bottom of page