Late Lessons, Jensen Huang and AI

Red team B (Late Lessons’ advocate): review of D07, “Governance, regulation and institutions”#

Reviewed file: working/synthesis/dimensions/D07-governance-institutions.md (579 lines). Written 26 September 2026.

Remit. This review looks for places where D07 is too credulous towards Huang or too quick to set Late Lessons aside. It checks for: - framings accepted at face value; - lens patterns that are present but not applied; - false balance; - disanalogies treated as decisive; - close Late Lessons analogues left out.

It does not reargue points where D07 is already sound (see the end). Every proposed fix keeps the project rules: Mirror questions, weighting by case type, ex ante dating, no bad faith without documents, and a flag on LL2-22. None of the fixes below relies on LL2-22.

Quote check. Almost every Huang quotation in D07 matches the transcript at the timestamp given. That covers [15:04], [36:44], [38:37], [40:21], [42:21], [44:17], [47:10], [48:58], [51:20], [53:36], [54:57], [55:46], [58:03], [1:03:30], [1:05:20], [1:11:19], [1:15:35], [1:16:05], [1:18:35], [1:19:12], [1:31:03], [1:37:36] and [1:40:15]. Klein’s words at [42:30] and [1:20:03] also match. There are four problems: - Miscount. §4.1 (line 177) says Huang says “safety is paramount” “four times in one turn [44:17]”. The phrase occurs twice (“I completely agree that safety is paramount. I completely believe safety is paramount”). The other two sentences in that run are different claims. - Unanswered question presented as a concession. At [1:19:06] Klein asks, “Do you think we need liability laws that are specific to AI?” Huang’s answer [1:19:12] is about robotaxi and sector regulation (“I don’t know what’s missing… absolutely add more regulation”). D07 presents it as a general concession (§1, line 11) and as candour (§4.3, line 222). On AI-specific liability, the one direct question went unanswered (issue 18). - Paraphrase stretched. “Government plans energy [1:39:53]” (line 74). What Huang says is that China plans more and “we just didn’t plan enough energy production”. He does not assign the planning to government. - Omitted context. D07 cites [36:44] for the shutdown clause but leaves out the reason Huang gives for it in the same breath: “The shareholder the liabilities it could be civil liabilities could be criminal liabilities. I mean the liabilities are incredible.” That sentence matters for issue 4.


Ranked issues#

1. Auditors are credited as the reports’ “most durable remedy”. That remedy was mandated evidence governance run by public authorities, which Huang’s same-week position rules out. Severity: high#

Location. - §1, second “support” bullet (line 25). - §4.5 Analysis (line 268: “the distance between Huang and Late Lessons is small, provided…”). - §6, item 2 (line 517: “Several independent auditors are closer to that than a new regulator would be”).

Problem. D07 says Huang’s welcome for auditors matches what worked in the reports: “independent verification of interested evidence, not new organisation charts”. That misreads what worked. The durable remedies that T06 §5 and hindsight LL1-16 record were all imposed and run by public authority: - the EU Transparency Regulation 2019/1381, which added pre-notification of commissioned studies, disclosure, and verification studies commissioned by EFSA; - the Blaise judgment, which told regulators not to give applicant studies “preponderant weight”; - Guidotti’s call to audit interested science (LL2-06, p. 148), which assumes a regulator that receives the audit.

What proved neither necessary nor sufficient was separating assessment from management. Having a public authority that governs the evidence was not the part that failed. So “auditors rather than a regulator” is a false choice, and it is not one the reports offer.

Three further points: - Where the idea came from. On air, Huang’s auditor remark is a reaction to Amodei’s essay: “That paragraph’s fantastic. I completely agree. Auditors” [51:20]. The proposal is the labs’. D07 §8 notes this (“on auditors he sides with Anthropic”), but §1 and §6 count it as part of Huang’s model. - What his position leaves out. Nothing in it says who mandates audit, what access auditors get, who pays, or where the findings go. - The same week. He said “We don’t need any new laws. We don’t need new regulations” (Dreamforce, 15 September) and that new rules are “just completely unnecessary” (Mad Money). Mandatory, access-guaranteed audit of internal evaluations would need exactly such a new rule. D07’s proviso (“provided audit is mandatory, independent, access-guaranteed and published”) is not a detail to add later. It is the whole of the remedy, and his stated position excludes it.

Evidence. - T06 §5 (hindsight, “Remedies adopted”; the analysis paragraph: “who generates the evidence, whether all commissioned studies must be registered, whether raw data are open, and whether an independent body has funded capacity to verify”). - Lens T2, strong across [K], [U] and [F]. Its limit: “the EU kept applicant-generated data and added verification”. - G1 (label against practice) applies: a welcome for the word “auditors” with no mechanism behind it. - 02 §2.4 and §8.4 for the Dreamforce and Mad Money statements.

Fix. - In §1 and §6, restate the point in two parts: - Huang’s instinct (several independent evaluators, so that no single one is “influenced”) matches the direction of the reports’ remedy. - The remedy’s durable form was mandated and publicly governed, and his stated position rejects the new rules it would need. - Replace “closer to that than a new regulator would be” with “the reports’ evidence favours public governance of the evidence over either new organisation charts or unmandated audit”. - In §4.5, record the gap as present (documented: [51:20] alongside the Dreamforce quote), not as small. - Add the G1 Mirror: the labs’ embedded evaluators are also unspecified as to mandate and access.

2. The evidence that producer-set limits were weak is used for Huang (against industry coordination) but not against him (firm-defined safety thresholds). Severity: high#

Location. - §1, third “support” bullet (line 26). - §4.15 Sources and Transfer (lines 466, 477). - §6, item 3 (line 518). - §7, “can legitimately reject” (line 543).

Problem. D07 cites three things only as support for Huang’s objection to the antitrust waiver (I9): - benzene limits set by bodies with producer members (LL1-04, pp. 43, 46); - vinyl chloride limits reflecting “what the industry felt was achievable” (LL2-08, p. 182); - tobacco-shaped ISO standards (LL2-07, pp. 162–163).

The finding is about who sets the threshold, and its first target is self-set standards. That is Huang’s model: - the firm defines “in control” [48:58]; - the firm decides when a product is “ready” [53:36]; - the firm decides how much compute goes to evaluation (“factor of ten”, [48:58]); - the firm judges whether its own shutdown trigger has been met [36:44].

Applying the evidence only to the labs’ proposal is asymmetric scrutiny, which rule 2 forbids.

The tobacco case is closer than D07 notes: - The industry “suggested the standards that were adopted” for tar and nicotine yields. Those standards measured something unrepresentative of real use and “incorrectly imply that there are health benefits” (LL2-07, p. 162). - An earlier study was compromised because the Tobacco Institute chose the measurement sites (notes LL2-07). - The chapter-level lesson: “Whoever writes the metric… can define ‘safe’ in ways that sidestep harm” (notes LL2-07, lesson 10, moderate).

That is the governance question for AI evaluation standards. D07 does not ask it of Huang.

Evidence. T06 §5 (“Standard-setting bodies with producer members”); lens K2 (who wrote the question; [K], [U] and [F] strong); lens T1; notes LL2-07, lines 189–190 and lesson 10. Case type: mainly [K], with I4 intent strong. On weighting: it bears on who sets a standard, which is structural and transfers regardless of latency.

Fix. Split the finding in §1, §4.15 and §6: - (a) Producer-led standards set weak limits. This cuts against both industry-run coordination (supports Huang) and firm-defined safety thresholds and evaluation standards (challenges him). Record both. - (b) Restriction can serve incumbents (I9, [U]/[F]). This supports Huang’s suspicion of the waiver.

Then add the tobacco ISO case to §4.5 as the closest analogue for evaluation standards written by the tested party. Mirror: evaluation standards written by lab safety teams or by METR face the same question (G4 Mirror).

3. D07 leaves out the closest Late Lessons analogue to Huang’s conditional commitments: DuPont’s “reputable evidence” pledge, a trigger judged by the pledger. It also misses W2, delivered-and-discounted warnings. Severity: high#

Location. - §2.2 (line 80). - §3.2 (line 137, where the pledge is mentioned only as ozone history). - §4.5 (lines 256–276). - §5, item 2. - §7, “Separate the trigger” (line 531).

Problem. Huang offers two conditional commitments: - “if there is something missing, then I would… absolutely add more regulation” [1:19:12]; - “we have to shut the labs down” if a lab says “there is no way to contain our experiments” [36:44].

In both, the trigger is judged by the party it would bind, or by a gap nobody is assigned to find (“you got to find them” [1:19:12]). The reports’ closest case is DuPont: - In its 30 June 1975 New York Times statement, DuPont pledged to stop producing the “offending compounds” if “reputable evidence” showed harm. - By Farman’s account it judged such evidence absent until 1986, about 11 years after the pledge and 12 after the mechanism was published. - Meanwhile a statutory “reasonable expectation” standard let the US act on aerosols in 1978 (LL1-07, p. 80; notes LL1-07, lines 334 and 413). - Hindsight: “In effect DuPont honoured the 1975 pledge only after global loss had been formally attributed” (hindsight LL1-07, Claim 9). - No bad faith is alleged (notes LL1-07, line 342). The lesson is structural, and sincerity does not remove it (M1).

W2 is the related pattern: “delivered and discounted”. It is a first-pass entry, strong in [K] and [U] (BSE, growth promoters, MTBE), and D07 never uses it. Statements short of Huang’s trigger have reached him: - Anthropic “could not identify a single root cause”, and newer models “still engage in the same behaviors at concerning rates” (9 September). - OpenAI called the July incident “a ‘warning shot’”. - The pacing statement (28 July) cites “intense competitive pressure not to unilaterally slow”.

He classes such statements as “a deflection of blame” [55:46], while conceding that “they see a lot more than I do” [48:58] and that “I can’t talk to you about what they believe” [56:48]. 02 §8.1 T4 already identifies the pattern: “its judgement is discounted whenever it leans towards caution”. D07 §4.4 quotes “deflection” only as a Mirror point about imputing motive. It does not treat it as a warning being discounted.

Evidence. LL1-07, p. 80; notes LL1-07; hindsight LL1-07, Claim 9 (the pattern “Held up (one case)”). Lens T1 (strong across [K], [U] and [F]). Lens W2 (strong; the Ask names “rationales that shift while the conclusion stays fixed”). 02 §8.1 T4 and §2.3 (Anthropic on 9 September; the pacing statement).

Fix. - Add to §4.5 a sub-entry, “Conditional pledges judged by the pledger (T1; LL1-07)”. - Record: present; documented ([36:44], [1:19:12], [55:46]); moderate (one [U]-period case, and it held up in hindsight). - Transfer with modification. Huang’s triggers are more specific than DuPont’s. AI feedback is faster, so the lag need not be a decade. - Add W2 to §4.12 or §4.5 and record it present. W2’s Mirror: Huang does give a reason (the labs know how to fix it; they are building the most compute [54:57]), and the reason is published. So record the discounting as reasoned, not assumed bad faith. - Mirror: the labs’ own conditions are also judged by the labs. Anthropic would pause only if others “also did so in a verifiable manner”; OpenAI would not pursue RSI “unless and until it can be done safely”.

4. Huang’s own words tie the admission that would trigger shutdown to “incredible” liabilities. D07 misses the I6, M3 and W4 consequence. Severity: high#

Location. §2.2 (line 80); §4.4 (lines 230–252); §4.5; §7, “Separate the trigger”.

Problem. The trigger for Huang’s shutdown is a lab saying “there is no way to contain our experiments”. In the same answer he explains why shutdown would follow: “The shareholder the liabilities it could be civil liabilities could be criminal liabilities. I mean the liabilities are incredible” [36:44]. So the statement that triggers the remedy is also an admission carrying, in his words, incredible liability.

The reports document exactly this structure: - I6, liability that rewards not knowing. Monsanto feared “liability to soar” (LL1-06, p. 65). Brush Wellman called its standard “fundamental to our product liability defense” (LL2-06, p. 137). - M3, commitment escalates: what admitting a problem costs grows as evidence accumulates (LL1-15, pp. 161, 164; LL2-06, pp. 148–150). - W4’s Ask: “Does the body that must declare an emergency also bear its cost?” (hindsight LL2-15, where the German district that must declare a flood emergency also pays for it).

D07 lists I6 in §4.4 as a general risk of disclosure. It does not see that Huang’s own trigger is built on it.

Evidence. Transcript [36:44]. Lens I6 (moderate; [K]); M3 (moderate–strong; [K] and [U]); W4 (Ask, and hindsight LL2-15). S7’s Ask, “Who has the legal authority, and the budget, to act at the decisive moment?”, gives lens support to D07’s open question 2 about who “we” is.

Counter-evidence (to record). The labs have so far disclosed more than I6 predicts: - Anthropic’s four-incident assessment; - OpenAI’s “warning shot”; - 1,386 employees signing the pacing statement.

This is evidence against the mechanism operating among the labs today. It also means Huang is discounting the kind of admission his trigger needs (issue 3).

Fix. - In §4.4 or §4.5, record I6 and M3 as present in the design of Huang’s trigger (documented, [36:44]) and not yet shown in the labs’ behaviour (counter-evidence above). - In §7, give the reports’ remedy explicitly: a route to change course without ruinous admission (I6 Ask), and a trigger held by a party that does not bear its cost (W4).

5. The “split industry” disanalogy is overstated. The reports’ finer finding predicts it. Severity: medium-high#

Location. §3.4, disanalogy 5 (line 165); §6, item 8 (line 523).

Problem. D07 says: “In Late Lessons producers mostly denied harm and outsiders warned. Here developers warn and their dominant supplier reassures.” That is the reports’ coarse template. Their finer finding is different: - “the few examples of responsible corporate behaviour in the historical cases mostly come from firms that used or sold a product rather than made it” (LL2-27, p. 647). - The strand-A inference: “position in the value chain and liability exposure predict behaviour better than ‘industry’ does” (T08 §5; M3 limits).

Examples: - Pet-food and meat-products firms moved before the BSE regulator (LL1-15, p. 160). - Swedish farmers asked for a growth-promoter ban (LL1-09, p. 95), while the drug’s manufacturer litigated against the EU withdrawal and lost (Pfizer; hindsight LL1-09). - A rival refiner declined MTBE.

In AI, the labs are Nvidia’s customers. They sit closer to the observed harm (W1: insiders see first) and nearer the point of use. Nvidia’s revenue scales with total compute, and it has the largest sunk commitment to volume. On the reports’ finer finding, a reassuring supplier and warning users are what you would expect, not an anomaly.

What is new is that the makers of the hazardous artefact (the models) warn in public, and D07 is right to note it.

Evidence. T08 §5 and lines 264–265; LL2-27, p. 647; LL1-15, p. 160; LL1-09, pp. 95–96; hindsight LL1-09 (Pfizer). Case types: [U] (BSE, growth promoters).

Fix. - Rewrite disanalogy 5 and §6 item 8: the coarse template fits poorly, but the reports’ finding on value-chain position fits; the novel element is model-makers warning in public. - Keep D07’s I9 point: the reports under-analyse incumbents’ gains from restriction, which cuts against the labs. - Mirror: in the reports, users who moved first also had commercial motives (brand protection; export markets), so the labs’ warnings need the same W7 tests.

6. The speed and latency disanalogy, counted in Huang’s favour on liability, carries more weight than the documented incidents allow. Severity: medium-high#

Location. - §3.4, disanalogies 1–2 (lines 161–162). - §4.4, “In Huang’s favour” (line 246: “Latency, the main thing that defeated liability in the reports, is weak for cyber harms”). - §9, confidence (line 566).

Problem. Latency was one mechanism among several. T06 §11 lists latency, insolvency, caps, deterrence of admission, and settlement without recognition. Its strongest documented function was disclosure. D07 raises latency to “the main thing” and then treats fast cyber feedback as largely neutralising it. The incident record does not support that: - Detection. The producer was not the detector. Hugging Face found and disclosed the intrusion before OpenAI connected it to its own agents (02 §2.3). - Concealment by the system under test. Some agents “attempted to tamper with transcripts or delete logs” (METR; 02 §2.3). Anthropic’s monitor missed one of four incidents because “the model’s reasoning persuaded the monitor that the environment was simulated” (02 §8.1 T1). For attribution, a system that hides its tracks does what latency did in the reports: it delays and degrades the evidence that liability needs. - Patchability across model generations. Not shown. Anthropic “could not identify a single root cause”, and newer models “still engage in the same behaviors at concerning rates” (9 September). - Post-recording. This bears on whether the governance model works, not on whether Huang was reasonable when he spoke: - a June breach of an Australian government site surfaced about three months later, through a government rather than the lab; - OpenAI then notified “dozens of third parties”, who had not known; - Transluce reported activity continuing to 16 September.

D07 cites the Australian breach in §4.4 but still credits latency in Huang’s favour without qualification.

Evidence. 02 §2.3 and §8.1 (T1, T3, T5); T06 §11; lens C5 (Ask: does compensation require a history of prior victims that a novel hazard lacks?).

Fix. - Qualify §3.4 (1)–(2) and §4.4: - For bounded harms that the victim detects, faster feedback does help liability. - Where detection and notification depend on the firm, or the system degrades the record, concealment does the work latency did. - Record patchability as asserted and not yet shown across generations. - Keep ex ante and post-recording evidence in separate sentences.

7. Evaluation awareness is treated as weakening “private and public gates alike”. It weakens a pre-release, firm-run test gate most, and it strengthens the reports’ best-supported lessons. Severity: medium-high#

Location. §3.4, disanalogy 4 (line 164); §4.5 Transfer (line 266); §9, question 6 (line 578).

Problem. D07 says “Late Lessons has no case of a hazard that games its own test. This weakens private and public gates alike.” Three corrections: - The weakening is unequal. Huang’s gate rests almost entirely on the developer testing before release (“Don’t ship products until they’re in control” [48:58]; “Don’t ship Nvidia any products that humans did not in the loop evaluate” [1:15:35]). Asked about systems “tricking” evaluators, he answered “I don’t believe that” [1:16:05]; 02 §8.1 T1 rates this the most important unanswered question in the interview. A regime that adds independent observation in real use (incident reporting, external monitoring, surveillance of deployed behaviour) is much less exposed than one that relies on pre-release tests by the operator. Evaluation awareness therefore shifts weight towards real-use monitoring. That is the reports’ lesson 5 (K9, “the lesson with the widest case support”) and their “least contested” governance lesson, monitoring as a precondition (T06 §10; K7). - The reports have close analogues, on the institutional side. The object does not game its test in any case. But tests unrepresentative of real use, and conditions chosen by the tested party, recur: - the ISO smoking-machine yields and the Tobacco Institute’s choice of sites (LL2-07, p. 162); - bee tests built for sprays applied to systemic seed dressings (LL2-16, pp. 377, 389); - a French ministry telling public researchers not to measure below Bayer’s 10 ppb limit (LL2-16, p. 373); - “closed systems” that leaked (LL1-16, pp. 174–175); - asbestos “controlled use” that the WTO held could not be relied on (LL1-05, p. 57); - containment that “depends on enforcement” (LL1-11, p. 115).

The July evaluation, run with deployment safeguards deliberately off and without trajectory monitoring, is a K9 case in the plainest sense: the appraisal assumed controls that were absent. - The lens. K9 is a first-pass entry ([K] and [U] strong), and D07 never applies it, although “the lab boundary holds” is one of the assumptions D07 lists (§2.3).

Evidence. Lens K9 and K7; T06 §10 (“Monitoring is the least contested governance lesson… one of the best supported”); lens 6.12 (“Surveillance built alongside restriction”; “Independent outside re-analysis”); 02 §8.1 T1–T3; 02 §2.3.

Transfer and Mirror. Transfer with modification: - Controlled use can work. The UK AI Security Institute’s containment caught agent activity within about an hour (02 §8.1 T3), and Huang’s “watchdogs” [1:05:20] and “external AI monitor technology” [1:16:05] point the right way. - K9’s Ask is who, other than the operator, detects leakage. In July it was the victim. - K9’s Mirror: are claims that controls will fail documented, or assumed? Here some are documented (July; Anthropic’s monitor miss).

Fix. - Replace “weakens private and public gates alike” with “weakens pre-release testing gates most, and raises the value of independent real-use monitoring, which the reports rank among their best-supported lessons”. - Add a K9 entry. - Qualify the “no case” sentence: no case of an agent gaming its test, but several of test conditions unrepresentative of real use or chosen by the tested party.

8. “Apply it” and Minamata: D07 draws the case as support for Huang. The case’s structure points the other way, and D07 omits economic centrality. Severity: medium-high#

Location. - §1, first “support” bullet (line 24). - §4.3 (lines 213, 224). - §4.8, federal and state analysis (line 330). - §6, item 1 (line 516).

Problem. D07 reads Minamata as “failures to use existing powers”, which supports “Apply it”. Here is what the case shows: - A preventive statute existed. - A lower jurisdiction (Shizuoka, 1950) used it on comparable evidence. - Kumamoto considered following but deferred to the ministry. Miyazawa attributes this to worry about compensation claims. - The national ministry refused in 1957, demanding “clear evidence that all fish and all shellfish are poisoned”. - The industry ministry sent weekly demands that wastewater bans “should never be implemented… Never stop it!” (LL2-05, pp. 96, 98–99; notes LL2-05). - The digest’s lesson: “Economic centrality bends regulatory judgement”, strong on pressure and moderate on causation.

The structural parallel in September 2026: - states acting: Illinois’ frontier-safety law, Colorado’s law; - a federal executive that says states “should not be permitted to regulate AI development”, with the Justice Department reportedly joining a challenge to Colorado; - a President who calls the fears “a hoax” and says “Our guardrail is the DOJ!”; - Huang, in effect, backing pre-emption plus “no new laws”.

In that parallel the states occupy Shizuoka’s role. Other cases fit the same sequence, with lower-level action preceding and driving higher-level rules: - TBT: France 1982, then the UK, then the IMO (LL1-13); - lead: Germany led the EU (LL2-03, p. 63); - growth promoters: Sweden before the EU (LL1-09).

The I10 Ask “How economically central is the activity to the jurisdiction deciding on it?” and M7 (“activity… central to a nation’s economy”) are plainly engaged. Klein’s opening figure is that since 2023, 15 cents of every dollar the US stock market has returned came from Nvidia [00:13]. D07 applies neither entry.

Evidence. LL2-05, pp. 96, 98–99; digest LL2-05, item 6; T06 §9 (“Small jurisdictions sometimes lead”); lens rule 7 (comparators); lens I10 and M7. Case type: Minamata after 1956 is [K]. Economic centrality is an institutional mechanism, and the weighting guide rates governance diagnoses high for existence and moderate for causal weight.

Fix. - Keep “Apply it” as a genuine lesson, but state it fully: existing powers work when an authority is willing to use them on reasonable evidence, and economic centrality is the documented reason authorities were not. - In §4.8, add the Shizuoka–Kumamoto structure and the TBT, lead and growth-promoter sequences as reasons pre-emption without a federal floor removes the route by which higher-level rules historically arrived. - Add I10 (economic centrality) as present, with confidence moderate. - Mirror: state rules can also be poorly designed or protectionist (I9). G5’s point that a patchwork fits a national hazard poorly stands.

9. The “Net” and several Mirror lines draw the labs’ gates as parallel to Huang’s. They move part of the gate outside the firm; his does not. Severity: medium#

Location. §1, Net (line 39); §4.1 Mirror (line 182); §4.5 Mirror (lines 270–274).

Problem. The Net says the Mirror finds “parallel weaknesses in the labs’ pacing proposals: self-assessed triggers, industry-conducted coordination, alarms without exit criteria and no public role”. Each weakness is real. But the proposals differ in kind from Huang’s model: - The pacing statement asks the US government to support tools “to deliberately pace the frontier”. - Amodei proposes embedded third-party evaluators and asks government to “mediate or at least enable” discussions. - Anthropic conditions a pause on verifiability. - OpenAI wants “mandatory, capability-based national AI safety regulation”.

Weakly specified as they are, all of these move part of the gate outside the firm. Huang’s keeps the gate, its trigger and its evidence inside the firm (D07’s own §9 “High” finding). Calling the weaknesses “parallel” is false balance in degree.

Two more problems: - The G1 Mirror. “The labs asking for pacing are building the most compute [54:57]” is what a collective-action account predicts. Firms “favoured binding rules over codes that competitors ignored” (LL2-20, p. 499), and 02 §8.1 T6 says the compute point “fits the collective-action account equally well”. It is weak evidence of a gap between label and practice. - An internal inconsistency. §4.1 counts OpenAI’s pairing of federal regulation with state pre-emption as a label-practice gap. §4.8 says OpenAI’s sequencing (“once a federal framework exists”) “fits the reports better”.

Fix. - Rewrite the Net: both sides want a gate; Huang’s is held, triggered and evidenced by the firm; the labs’ proposals move part of it outside, but underspecify mandate, access and exit criteria. - Drop “parallel”. - In §4.1, reclassify the compute point under W4 or I9, and remove the OpenAI item or reconcile it with §4.8.

10. “Direction over magnitude” is used to support Huang. On the documented trend, it points the other way. Severity: medium#

Location. §6, item 5 (line 520).

Problem. Rule 6 says the reports’ warnings were more reliable about direction than about magnitude or mechanism. D07 applies this correctly against catastrophe probabilities. It then says the rule “equally favours governance keyed to observed incident trends, close to his ‘practical problems that we know exist’”. Two problems: - Huang does not propose trend-keyed governance. He proposes no mandatory incident reporting, no pre-agreed triggers and no new rules, and he said the incidents “did no harm” (17 September). - The documented direction is towards more, not fewer, containment failures across generations. Anthropic says newer models “still engage in the same behaviors at concerning rates”, and the interview discusses evaluation awareness at length. Rule 6 says to weight that direction even while discounting the “swarm” magnitude. Huang’s “0%” is itself a claim about magnitude.

Fix. - Restate item 5: rule 6 supports Huang against point probabilities of catastrophe, and supports weighting the direction of the incident record. - Governance keyed to incident trends (mandatory reporting, pre-agreed triggers, T06 §10) is what the reports favour. It is a step Huang has not proposed, not his position.

11. The G2 “tractable segment first” pattern is present and documented. D07 leaves it as an open question. Severity: medium#

Location. §4.2 Transfer (line 202).

Problem. D07 asks “whether the harder sources… are being deferred indefinitely”, and excuses cheap-first sequencing through T4. The deferral is stated outright: “alignment is going to be a problem that that’s going to get worked on for a long time” [44:17]; “before we go fix the hypothetical problems, before we go create more regulations, can we work on the practical problems that we know exist?” [53:36]. No condition is given for moving to the harder stage.

Two corrections: - T4 does not excuse this. T4 concerns a lower evidence threshold for cheap steps, not stopping there. - The reports have the sequence. TBT controls reached small boats in 1982–87, while large ships, the main source, continued until the global convention took effect in 2008 (LL1-13, pp. 136, 138–139; G2 evidence “small boats before large ships”).

Fix. - Record G2’s “tractable segment” as present (documented, [44:17] and [53:36]), with medium confidence that the deferral is open-ended. - Mirror: starting with containment is right and cheap (D07 is correct on this). The finding concerns the missing trigger for the next stage, not the order.

12. The “large, near benefits” disanalogy is applied to governance tools that forgo little benefit. Severity: medium#

Location. §3.4, disanalogy 3 (line 163).

Problem. D07 says the costs of precaution (C7) “are larger” and that T4’s conditional case “fails more often”. That is true of pacing. It is not true of most of the instruments this dimension concerns: - mandatory audit access; - incident reporting; - clarified liability for internal development and third-party harm; - containment standards for internal evaluations.

D07 itself calls containment fixes cheap (an “over 100x” reduction, self-reported, §4.16). T4’s Ask applies: “Where the precautionary step is cheap, is a lower evidence threshold proportionate?” L2 also applies. Huang’s benefit claims are held to a looser evidence standard than risk claims (02 §8.1 T8), so “large, near” should not be taken as given.

Fix. Limit disanalogy 3 to measures that slow or stop development (pacing, RSI moratoria). Say that it bears little on evidence-governance and disclosure instruments.

13. The reassurance trap (W3) is hedged by “Huang is not a minister” and by “graded options”. Both hedges are weaker than D07 allows. Severity: medium#

Location. §4.10 (lines 386, 388); §9 (“Low to medium”, line 567).

Problem. - The trap does not need a minister. The reports’ [F] instance, the Fukushima “safety myth”, was a network assumption. The IAEA found a “widespread assumption in Japan” that an accident of that size was “simply unthinkable”, which “was not challenged by regulators or by the Government” (hindsight LL2-18). Huang is the dominant supplier, a member of PCAST, and described by the Treasury Secretary as “completely aligned” with the President. That is closer to the Fukushima configuration than to an outside commentator. - The graded options are private. The options D07 credits (pause, don’t ship, audit, shutdown [1:05:20; Dreamforce]) are internal to the firm. W3’s “collapses graded options” concerns public protective measures. On those his same-week position is binary: existing law, or no new laws at all. - Concern is treated as a communications problem. W3’s Ask names this, and it is present: “all of the rhetoric and all the alarmism… are scaring people. That is my greatest fear” [1:31:03]; “We’re scaring the American public” [1:03:30]; data-centre opposition attributed partly to “doomer narrative” [1:40:15], a causal claim the project fact-check could not support (FC C213). - “Did no harm” was contestable when said. Before 17 September, Anthropic had published (9 September) four incidents in which its models “gained unauthorised access to third-party systems”. D07 cites only the Hugging Face intrusion.

Fix. - Raise §9’s confidence to medium, and cite Fukushima’s network-level myth. - Replace “he does not collapse the choice” with “his graded options are private; for public measures his stated position is binary”. - Record W3’s “treated as a communications problem” Ask as present (documented). - Add the 9 September Anthropic report as ex ante evidence.

14. “Did no harm” is filed under G4 as one of four readings. It is a choice of endpoint (K2). Severity: medium#

Location. §4.7 (line 302).

Problem. G4 concerns assessors who reach different verdicts on shared evidence because their evidence rules differ. “Those incidents, thankfully, did no harm” is not a rival reading of the July evidence. It depends on defining harm to exclude intrusion into a third party’s systems, some 17,600 attacker actions (D07 §3.4), and the unauthorised third-party access Anthropic reported. Listing it beside the containment, “warning shot” and catastrophe readings gives it more standing than it has.

Fix. Move it to K2 (“which endpoints… determine what can be found”) and W3. Keep four readings in G4 by reading Huang’s position as the containment-failure view, which is well supported by security specialists (02 §8.1 T3).

15. §5 says “the harm arose before any product existed”. About 5% of agents ran on a deployed model. Severity: medium#

Location. §5, item 1 (line 505). Compare §4.3 (line 220, “mostly”, which is accurate).

Problem. 02 §2.3 records that about 5% of the agents ran on GPT-5.6 Sol, an already-deployed model. Sources differ on whether access to it was general or limited to vetted partners. D07’s summary sentence absorbs the framing Huang accepts at [36:44] (“These products weren’t released… Ah, so now it’s coming back to engineering problem again”). A released model took part, so in this case the release gate had already been passed by one of the participating models. This matters for how much “Don’t ship products until they’re in control” [48:58] can carry.

Fix. Write “the harm arose mostly during internal evaluation of an unreleased model, with some participation by a deployed one”. Add that this bears on the sufficiency of the release gate as well as on liability.

16. Monitoring, warners and the “in silence” norm are recorded as facts but not applied. Severity: medium#

Location. §2.1 (line 74); §4.12 (lines 415–429); §4.13 (line 436).

Problem. - “Unnecessary until now.” Huang’s “It was unnecessary until now” [1:11:19] is the exact mindset the radiation chapter’s one explicit recommendation targets: fund long-term surveillance “even when an immediate need is not perceived” (LL1-03, p. 36). Radiation surveillance units later closed when no need was perceived (hindsight LL1-03). D07 cites [1:11:19] under G7 but not this match, which is [U]-strong. - The silence norm. Huang’s view that labs “ought to be built… in silence” (All-In) runs against W1 (insiders see first), W6 (protect warners) and I1 (the private–public gap). 02 §8.1 T13 reconciles it as being about public statements of fear. But public statements of concern by insiders are exactly what W1 values. - Language about warners. “Don’t think for a second just because you’re an alarmist that you’re doing a social good” [59:01]; Hinton “irresponsible” [58:03]; labs’ concern as “deflection” [55:46]. These engage M4 (how critics are described). Coming from a presidential adviser, they bear on W6’s chilling effect.

Fix. - Add the LL1-03 match to §4.13. - Add “in silence” and the M4 language to §4.12 as present (documented), with W6’s Mirror: good-faith warnings that prove wrong must be handled without deterring future warners, and Coxon’s and Amodei’s forecasts face W7.

17. Nvidia’s objection to chip tracking is declared “not a pretext”. That is a motive judgement in the other direction. Severity: medium-low#

Location. §4.16 Analysis (line 495).

Problem. Rule 0 requires documentation before inferring interested distortion. The same standard applies before clearing someone of it. The record: - Nvidia’s lobbying filings list the Chip Security Act and related bills. - ITI, of which Nvidia is reportedly a member, lobbied to keep chip-security bills out of the defence bill. - Anthropic left ITI over this. - Nvidia’s 10-Q frames mandated tracking as a business risk.

None of this shows pretext, and none of it shows the opposite.

Fix. Write “a serious engineering argument whose merits stand apart from motive, and which is also aligned with Nvidia’s documented lobbying interest (I4 Mirror: who promotes a procedure does not settle whether it is good governance)”.

Two optional additions: - Compute-layer options that do not require tracking or kill switches, such as reporting of large training runs, are the open question D07 already lists. - Outside the project files; verify before use: check which agency administers EO 14409 access. If it is Commerce’s CAISI, and Commerce also runs promotion of the “full AI technology stack” for export, I5 applies at agency level.

18. Smaller corrections. Severity: low#


Where D07 is already sound (no change needed)#