RAND tells the US to keep every superintelligence option open

Share
RAND tells the US to keep every superintelligence option open

Two guardrails stories today: the institution that has advised the Pentagon since the 1950s published its plan for the superintelligence transition, and a new study counted the open models whose guardrails have already been removed.

RAND published a 37-page strategy paper arguing the United States should not commit to any single approach to superintelligence, and should spend now to keep all of them available. The paper, from RAND's Center for the Geopolitics of Artificial General Intelligence, sorts the entire debate into seven archetypal strategies across three families — coexistence (dominance, co-development, preparedness), denial (moratorium, deterrence, continuity of society), and acceleration — and argues current evidence cannot resolve five pivotal uncertainties: how close the danger actually is, whether humans and AI systems can reach a stable equilibrium, whether restraint is enforceable, whether any single actor can build a decisive strategic lead, and whether rival programs can be suppressed at all.

The uncomfortable part is what the paper puts in the taxonomy. "Continuity of Society" is described as the strategy for when every preventive approach has failed and coexistence is judged impossible: the US "creates geographically distributed, biologically self-sustaining settlements hardened against AI-enabled threats." A defense think tank listing hardened survival settlements as a live option — beside a verifiable global halt and a co-development consortium that includes China — is the signal, not the recommendation. The paper's own framing is blunt about why: if danger is close, strategies that buy time and build defenses should be favored; if it is not, the case for accelerating strengthens, and nothing in the current evidence settles which world we are in.

What RAND actually recommends is Freedom of Action, and it is deliberately unfalsifiable. It authorizes spending now, names no target, and cannot be scored against an outcome, because the outcome it guards against is the one that did not happen. The four ingredients it does specify — a human-AI ecosystem with safety investment, an AI-security architecture with visibility into compute, national security institutions rebuilt for the AI era, and capacity for citizens, firms and governments to respond — arrive as line items rather than decisions. In practice, US policy already resembles RAND's acceleration archetype, which the authors describe as relying on markets and rapid iteration to produce safety as a byproduct. We covered the legislative version of this argument when Sanders and Casar moved to ban superintelligence and the think-tank version in our deep dive on the CNAS case for treating compute as a military target.


A 10a Labs study found 3,471 original "uncensored" open-weight models on Hugging Face, each repackaged an average of 2.4 times into 8,164 redistributions — and classified a quarter of the 1,643 GitHub applications built on them as explicitly malicious. The report traces the whole supply chain from abliteration and safety-removing fine-tuning through quantization to deployment, and the finding that matters is structural: three actors account for 52% of compressed redistributions, so availability no longer depends on the original producer. Enforcement against one upstream repository removes a node in a mirrored graph, not the model.

Two numbers explain the acceleration. The Heretic abliteration tool took monthly production from roughly 89 original models to about 338 and expanded the producer base from around 640 actors to more than 1,055, with a lower one-shot abandonment rate than any fine-tuning method. And downstream adoption tracks deployability rather than supply: GitHub application creation rose from about 30 per month in mid-2024 to 140–188 by late 2025, aligning with Ollama's maturation rather than with Hugging Face upload volume. Chinese-origin base models are now 38% of identified uncensored repositories, and one producer, huihui-ai, accounts for 192 originals that others have repackaged roughly 1,800 times. We covered the commercial end of this pipeline when Abliteration.ai started selling uncensored models as a hosted API.

What to watch: whether anyone acts on the report's implicit policy ask — the redistribution tier sits across Hugging Face, Ollama and separate accounts, which is exactly the structure no single provider can police.

If the persistence layer is redistribution, what would a real crackdown even target — the models, the quantizers, or the registries? Tell us in the comments.

Sources: RAND — A U.S. Strategy to Secure Geopolitical Advantage on an Uncertain Path to Superintelligence · Import AI 473 · Tencent News (兰德) · Uncensored Open-weight Models: Redistribution as the Persistence Layer (arXiv) · Unite.AI