COBUS KOK

Tracker · companion to Brakes Without a Moat · Draft 1

Brake or Moat?

The AI rules and proposals on the table now, graded with one test, each with a reason and a date

Every AI rule on the table is being called safety by one side and capture by the other, and that charge settles nothing because it can be made of any rule. In Brakes Without a Moat I proposed a test that reads what a rule does rather than who asked for it, and this page runs it on the rules and proposals people are arguing about now. Each row says what the rule stops, gives a verdict with one reason, and carries the date I graded it.

The rules, graded

Where the essay already graded a rule, I use its verdict word for word and mark it (essay). Too early to tell means the text, or the lack of one, doesn't let me decide yet. Nothing here is aimed at concentration so far; the nearest candidate is the EU's move to put Amazon's and Microsoft's clouds under its rules for gatekeepers, which I'll grade when the decision is final.

RuleWhoWhat it stopsVerdictGraded
Pacing, step one: embedded evaluatorsAnthropic; OpenAI pledged the sameModels shipping on the lab's word aloneBrake (essay). One of its three checks is met: Accenture is named. The access is promised, not yet shown, and no result is published yet.23 Sep 2026
Pacing, step two: a common paceDario Amodei; Sam Altman and Elon Musk agreedThe speed of the frontier, by agreement among the leading labsUndecided (essay). A cartel in form until it says where its line sits and who checks it.23 Sep 2026
Pacing, step three, and the US–China incident lineAmodei; the US Treasury's proposal to China on 20 SepAI help with bioweapons first; each government warned of the other's serious incidentsRight direction (essay). The only part that does not depend on the lead. The incident line is a first piece, if Beijing accepts it.23 Sep 2026
Antitrust safe harbour for labs (S. 5105)Senators Schiff and Banks; stalled with the defence billNothing itself: it lets labs agree to delay or limit AIToo early to tell. It names a checker the labs don't pay, the Justice Department, but no line, so the verdict belongs to whatever the labs agree.23 Sep 2026
A standards body on the FINRA modelDemis Hassabis of Google DeepMind; OpenAI, Anthropic and Google in talksFrontier releases that fail its tests, voluntary at firstToo early to tell. It would bind only frontier models, which the test allows, but the labs it checks would pay for it.23 Sep 2026
A federal liability shield for labsSought by labs, as reported; the Treasury Secretary said noNothing a model could do: it moves the cost of harmToo early to tell. There is no text, and a shield is neither brake nor moat until you know what it buys and who qualifies.23 Sep 2026
Ban Artificial Superintelligence ActSenator Sanders and Representative Casar, introduced 23 SepTraining and new releases at 10^25 operations and up, and foreign models without approval, until a new department writes its rulesBrake (essay: one that stops at the border). It stops a capability, spares the small and has a public checker, but it fails the fourth question: it stops qualifying runs at home and none abroad, and keeps foreign models out with a wall.23 Sep 2026
Senate frontier AI draftSenators Thune, Cruz and Klobuchar; no text yetReleases the government judges unsafe, as reportedToo early to tell. As reported, the labs test themselves and the Commerce Secretary approves, so it turns on who checks.23 Sep 2026
FRONTIER Act (H.R. 9925)Representatives Obernolte, Trahan and four others, introduced 23 JulFrontier releases without a report; unaudited practice at the biggest labsBrake. A compute line for everyone, the heavy duties only for firms spending $1 billion or more on AI, and publishing weights counts as release.23 Sep 2026
California SB 53California; in force since 1 Jan 2026Frontier releases without a published framework and report; unreported incidentsBrake (essay: passes question 2, weak on question 3). A startup training a small model faces nothing; the labs report to the state, and no outside audit checks them.23 Sep 2026
New York's RAISE Act, as amendedNew York; its office opened 21 Sep, duties from Jan 2027The same as SB 53, with incidents reported within 72 hoursBrake. SB 53's two lines, and a state office funded by the largest developers but not run by them.23 Sep 2026
EU AI Act: models with systemic riskThe EU; the AI Office has been able to enforce it since 2 Aug 2026Models above 10^25 operations without evaluation, adversarial testing and incident reportsBrake. A compute line the Commission must keep current, a checker the labs don't pay, and open weights bound the same as closed ones.23 Sep 2026
Entity-based regulationDean Ball and Ketan Ramakrishnan, July 2025Unsafe practice at firms spending over $1 billion a year on AI researchBrake (essay). A rule on entities is a brake when they are defined by what they spend, and this one is.23 Sep 2026
US export controls on AI chipsThe US Commerce DepartmentChinese buyers getting the best American chipsA wall (essay). It stops a country rather than a capability or a company, and this year's rules have chased the routes around it.23 Sep 2026
Bans on open-weight modelsDiscussed in Washington since July; nothing writtenAnyone downloading and running the weightsA trade (essay). It buys some protection from misuse and pays for it in concentration. I'd refuse it, but it should be argued as a trade.23 Sep 2026

Notes and sources

Pacing, step one. On 12 September Dario Amodei proposed outside evaluators inside the lab, with desks, badges and access close to its own risk team's, free to publish key findings; the lab may redact security, legal and commercial material, but not findings because they are unfavourable. Sam Altman pledged the same for OpenAI that day. On 18 September Anthropic named its first evaluator, Accenture, and said it will pay for the work directly for now, with pooled or government money as the aim. That meets one of the essay's three checks, a named evaluator. The access is a plan so far: the evaluators will have access comparable to an employee's, and Anthropic says there are as yet no standards for what they should see or how they should report. A result published before a model ships is still to come. A lab paying its evaluators makes them independent the way auditors are, which is better than nothing and worse than it sounds. OpenAI has not named its evaluators yet. Sources: Amodei; Anthropic, 18 Sep; TechCrunch, 12 Sep.

Pacing, step two. The leading labs would agree common safety standards and limits on the rate of unchecked progress, and the government would grant "a narrow waiver" so they can talk without breaking competition law. An agreement among the largest competitors to slow down together is a cartel in form. If its limits bind only frontier runs, a startup training a small model faces nothing, which the test allows; if signing becomes the price of deploying at all, it is a licence. Standards checked by evaluators the labs pay are a closed loop. Since the essay was written, the waiver's likeliest vehicle has stalled, Senators Hawley and Cruz have said no to any antitrust exemption for AI (see the safe harbour), and on 18 September four subscribers sued four labs under the Sherman Act, arguing that an agreement to slow down restricts output. The proposal still names neither a line nor a checker. Sources: Amodei; Bloomberg Law on Buist v. Anthropic.

Pacing, step three, and the incident line. Amodei's third step is coordination with China, starting with a ban on AI help for biological weapons and moving, if trust allows, to testing before release and a limit on the speed of self-improvement. On 20 September, after talks with China's vice premier, the US Treasury Secretary said the two sides had discussed a formal AI dialogue and the US had proposed a way for the two governments to warn each other of AI incidents serious enough to touch national security. China's account confirmed talks on AI but not the warning mechanism, and as proposed it covers incidents, not capability. It becomes the first disclosure brake between rivals if Beijing accepts it and it grows to cover capability jumps. Sources: Amodei; Euronews, 21 Sep.

Antitrust safe harbour. The Collaboration on Adversarial Threats and Security Risks Act, introduced on 23 July, would exempt two things from antitrust law: sharing information about AI security risks, and agreements "delaying or otherwise limiting" the release, training or testing of AI, after written notice to the Justice Department's antitrust chief naming the risk. The sharing exemption excludes price-fixing, market allocation and boycotts, firms claiming either exemption must prove good faith and a security purpose, and the Attorney General can sue to stop abuse. A version was lined up for the Senate's defence bill in a package of amendments, and that bill has been stalled since the summer. On 15 September Senators Hawley and Cruz came out against any antitrust exemption for AI. It is the waiver step two needs. The checker is public and unpaid by the labs, but there is no line: any group of firms qualifies for any delay tied to a named risk, so it can carry a brake or a cartel. Sources: bill text; Semafor, 16 Sep; Hawley, 15 Sep.

A standards body on the FINRA model. On 14 July Demis Hassabis proposed an industry-funded, government-backed body, modelled on the self-regulator for American brokers, that would test frontier models for dangerous cyber, biological and deception capabilities up to 30 days before release: voluntary at first, then required for any frontier model sold in the US once the tests prove themselves. On 15 September OpenAI said it had been talking with Anthropic and Google about working together on safety ever since that proposal. The line is right if it stays at frontier models. The checker is the problem: standards written by the companies they bind, checked by staff those companies pay, are a closed loop unless a public supervisor holds the power over it that the SEC holds over FINRA. Hassabis calls it federally overseen but does not say by whom or with what powers. Sources: Hassabis, 14 Jul; CNBC, 15 Sep.

A federal liability shield. Labs have asked Washington to limit what they owe when their models cause harm, according to reports. On 15 September the Treasury Secretary told a House committee that "the best way to guarantee safety is that the creators are liable for what they build and generate", and on 21 September he said the government would not be a liability shield. No federal text exists. The nearest is Illinois SB 3444, which would have spared developers of models above 10^26 operations from liability for catastrophes, a hundred people killed or badly hurt or a billion dollars of damage, if they had published safety reports and had not acted intentionally or recklessly; it stalled in May. A shield stops nothing a model could do. It can be the price of a brake, paid with the public's right to sue, and it becomes a moat if only those who sign the incumbents' standards qualify. Sources: FedScoop, 15 Sep; Fortune, 22 Sep; Illinois SB 3444.

Ban Artificial Superintelligence Act. It would ban superintelligence outright and put every model trained with 10^25 operations or more under a mandatory pause, with no further training and no new releases until a new Department of Artificial Intelligence is staffed and has written its rules. Building or distributing such a model would need the department's charter, and deploying, releasing, importing or transferring one its approval, under section 9(d). Its list of banned capabilities, such as resisting shutdown or breaking into systems, is written the way a brake is. On the test: it stops a capability, so it is a brake. A startup training below the line faces no pause, only the capability bans that bind everyone, so it passes the second question. The checker is public and the labs don't pay it, which is the part worth keeping. It fails the fourth question. Section 15 tells the government to seek international agreements, but the pause doesn't wait for them: it would stop qualifying runs at home and none abroad, and keep foreign models out with an import wall. That assumes the frontier can be kept at home, while open-weight models trail it by months and arrive as downloads, so the frontier would move to whoever didn't sign. As I read section 8, which bars only unreleased models, models already released stay on sale while nobody can release a new one; sections 9(d) and 12(b), which require approval to deploy and a charter to distribute, may reach them too, and the text doesn't settle it. Its line is reset each year to hold the capability of a 10^25 run constant, so it falls as training gets more efficient and covers more of the industry. Sources: press release; bill text.

Senate frontier AI draft. Senators Thune, Cruz and Klobuchar have been negotiating a bill since the summer that would put a duty of care on developers of the most advanced models. As reported, the companies would test their own models and the Commerce Secretary would approve release; Senator Cantwell wants the national laboratories to do the testing. The draft would reportedly also preempt state safety laws, and on 16 September a coalition of safety groups wrote to reject it. No text is public. If the labs grade themselves and the government reads the grades, it is the closed loop the test warns about; if the national laboratories test, the checker is public and the labs don't pay it. Sources: Nextgov; Washington Post, 16 Sep.

FRONTIER Act. Anyone who trains a model above 10^26 operations must publish a transparency report at or before release, and the bill counts making a model available for copying or modification as release, so open weights are covered. The heavier duties, a published safety framework, a yearly third-party audit and registration, fall only on developers with more than $50 million in revenue that have spent at least $1 billion on AI over three years, close to the entity trigger Ball and Ramakrishnan proposed. The very largest must also keep a licensed verification organisation, which reports to the government and the lab at the same time. The line can only be raised. The labs pay their auditors but may not tie the fee to the result, which is better than most proposals and still short of a checker the labs don't pay. The Commerce Secretary could suspend a model that presents an imminent catastrophic risk. The introduced text also preempts state rules on frontier risk transparency, audits and incident reporting, the ground SB 53 and RAISE cover. Sources: bill text; Obernolte and Trahan, 23 Jul.

California SB 53. A frontier model is one trained with more than 10^26 operations. Every developer of one publishes a transparency report at release and reports critical safety incidents to the state within 15 days; developers with more than $500 million in revenue also publish a safety framework and send the state summaries of their catastrophic-risk assessments. On the test it stops something a model could do, a frontier model shipping in silence, so it is a brake. It passes the second question: a startup training a small model faces nothing, and a report is a sliver of the cost of a run that size. It is weak on the third: the labs report to the state, no outside audit is required, so they report on themselves, and the Attorney General enforces with fines of up to $1 million a violation. Source: the act.

New York's RAISE Act. Signed in December 2025 and rewritten in March 2026 to match SB 53: the same 10^26 line for frontier models and the same $500 million revenue line for the heaviest duties, with incidents reported within 72 hours. On 21 September the governor appointed the official who will put the law into effect at a new state office, said developers will register from November and must comply from January 2027, and floated "kill switches" if they prove feasible, which is too early to grade. The difference from California is who pays the checker: the largest developers fund the office through assessments, but the state runs it, which is close to the levy the essay suggests for evaluators. Universities doing academic research are exempt. Sources: Governor Hochul, 21 Sep; Morrison Foerster on the amendment; Bloomberg, 21 Sep.

EU AI Act, models with systemic risk. A general-purpose model trained with more than 10^25 operations is presumed to carry systemic risk, and its provider must evaluate it, test it adversarially, assess and reduce the risks, report serious incidents and secure it. These duties have applied since August 2025, and the Commission's AI Office has been able to enforce them since 2 August 2026. The omnibus that took effect on 27 July 2026 delayed the high-risk rules and left these duties as they were. The open-source exemption does not apply at this tier, so released weights are bound the same as closed ones. The checker is a public office the labs don't pay, and the Commission must adjust the line as the technology changes. Two cautions. Lighter duties, documentation, a copyright policy and a summary of the training data, start at about 10^23 operations for any general-purpose model, so a startup training a small model is not quite free of obligations, though those duties serve transparency and copyright rather than safety. And I found no public estimate of what compliance costs at the 10^25 line; if it turns out to be a large fixed sum, this becomes a brake and a moat. Sources: the AI Act; Commission guidelines; Regulation (EU) 2026/1744.

Entity-based regulation. Dean Ball and Ketan Ramakrishnan proposed regulating the companies at the frontier rather than their models, the way banks are regulated, with an example trigger of more than $1 billion a year in AI research spending. That exempts the small the way a revenue floor does. A rule on entities is a brake when the entities are defined by what they spend or train, and a moat when they are defined by who got there first; this one is defined by spend. On its own, a spending trigger can miss a small lab with a frontier-scale run, which is what a compute line is for, and the FRONTIER Act now uses both. Source: Carnegie Endowment, July 2025.

US export controls on AI chips. The essay calls them a wall, and walls get routed around. This year's record fits. In January the Commerce Department moved sales of H200-class chips to China from a presumption of denial to case-by-case review. At the end of May it said licences are needed to ship to Chinese-headquartered companies wherever they are. By late August it was drafting a rule on remote access, after reports that Chinese firms were renting restricted chips in data centres in Southeast Asia. On the test, a wall stops a country, not a capability or a company, and it does nothing about open-weight models once they are released. What the essay would build instead is a window: compute visibility, so a government can say how many frontier-scale runs happened last quarter and where. Sources: Federal Register, 15 Jan; Al Jazeera, 1 Jun; Tech Times, 29 Aug.

Bans on open-weight models. In July the administration was reported to be weighing a ban on Chinese open-weight models, after the White House accused a Chinese lab of distilling an American model, and Hugging Face, Meta, Microsoft, Mistral, Nvidia and others wrote against broad restrictions. Nothing is written down. The essay's verdict covers bans in general: a ban buys some protection against misuse, because the person who downloads the weights is the one no rule can see, and pays for it in concentration, by leaving the frontier to the few who can train it. I rank concentration first, so I would refuse the trade. A ban aimed only at one country's models is a different rule, and too early to grade. Sources: TechCrunch, 24 Jul; Lawfare.

A rival test

On 16 September ComplianceHub published a "capture test" for the oversight proposals moving through Congress and the states: licensing, incident reporting, kill switches and a stand-down. It asks who a rule binds, whose costs it raises, and whether the lab asking for it is the lab that benefits, and its core question is whether a rule changes who can build or only what builders must disclose. We agree that licensing is the moat. We disagree in three places. It counts who is asking; I don't, because that charge can be made of any rule, and the text is what binds. It treats a compute or capability threshold as the part of a regime that shields incumbents; I think the threshold is a brake's best tool, as long as the line moves with the frontier and the cost scales with the run, and the licence attached to it is the moat. And it rates incident reporting that binds every developer as the rule least open to capture, while my test first asks whether a startup training a small model is left alone. The reporting duties in SB 53, RAISE and the FRONTIER Act leave it alone; a rule that binds everyone does not. Source: ComplianceHub, 16 Sep.

How to disagree

Tell me the row, and the fact I got wrong or the answer the text gives that I missed: the line, the cost at the threshold, the checker and who pays them. Reply to me on X at @cobuskok. If you're right, I'll regrade the row and change its date. One disclosure: I write with Claude, which Anthropic makes, and three rows grade Anthropic's own proposal, so weigh those with that in mind.

Last updated 23 September 2026.