The Switch
Who decides whether the smartest thing you talk to keeps talking to you.

On June 12th, 2026, at 5:21pm Eastern, Anthropic received a letter from the Commerce Department ordering it to cut off every foreign national on the planet from its two smartest models- Fable 5 and Mythos 5, the top of the Claude line, if you know the family by that name- effective immediately, no carve-outs, up to and including Anthropic’s own foreign-born employees. There is no way to check the passport attached to an API key in real time. So Anthropic did the only compliant thing available: it turned off Fable 5 and Mythos 5 for everybody. The whole planet. For nineteen days.
The legal instrument was something called an “is informed” letter from the Bureau of Industry and Security (BIS)- a mechanism built for blocking chip shipments to China, applied, for what appears to be the first time anywhere, to access to a model. No hearing, no comment period, no published rule- and before a policy reader objects: yes, that’s normal for this instrument. It has never required any of those. That’s exactly what makes it the tool you reach for. The stated reason was a jailbreak some Amazon researchers had found; Anthropic called it “a narrow potential jailbreak” and the whole thing “a misunderstanding.” Maybe so! The models came back. (And if you missed that news cycle and suspect I’m inventing all this- Anthropic’s statements are still up on their site.) But watch how they came back: Mythos 5 returned first, on June 26th, to a hand-picked set of US organizations, through Anthropic’s vetted-access program. The rest of us got Fable 5 back on July 1st.
Sit with that sequence for a second. Nobody had to improvise a tier system under emergency conditions; when Washington allowed partial restoration, the reopening simply flowed through the channel that already existed, vetted list first, public last. The emergency switch and the velvet rope turned out to be the same piece of hardware.
Somewhere in a datacenter there is a switch that determines whether the smartest entity you have access to keeps talking to you. You didn’t know it existed until June. Now you do, and this essay is about the two questions that follow: who else has a switch, and what tier are you? (What’s actually behind the door the switch guards- what the thing is made of- deserves its own essay, and it’s getting one. Watch this space.)
What the Switch Sits On

One sentence of orientation before the tour, because the stakes live here. The thing being tiered is a file- a few hundred gigabytes of floating-point numbers compressed out of some large fraction of everything humans ever wrote down where a crawler could reach it, plus years of annotation and judgment calls by workers you will never meet. Every tier decision, every vetting list, every switch-flip is somebody deciding who gets to use a machine built out of everyone’s output. Keep that in your back pocket; the rest of this essay is about the deciding.
Arms Dealers Don’t Stay Arms Dealers
For the first few years of this boom, the labs ran the classic arms-dealer playbook: sell tokens to everybody, root for nobody. Your startup, your competitor’s startup, a Fortune 500’s skunkworks- everyone rents the same magic at the same metered price. Neutral infrastructure, like electricity.
Look at what the electricity company is doing lately.
OpenAI stood up something called the OpenAI Deployment Company in May- a standalone unit backed by more than $4 billion, led by TPG, staffed on day one by roughly 150 forward-deployed engineers from its acquisition of Tomoro, with a mandate to embed inside enterprises and run AI deployment as its own P&L. Look at the investor list. McKinsey. Bain & Company. Capgemini. The consultants are buying equity in the thing priced to replace consultants. You can practically hear the drool hitting the term sheets.
Anthropic, meanwhile, bought Coefficient Bio in April- a $400 million all-stock deal for a drug-discovery startup that was eight months old and had fewer than ten people- and in late June launched Claude Science, its own drug-discovery program, wet labs and hired biologists included. Whether it will patent the drugs, license them, or hand them to partners, Anthropic explicitly has not said. The honest version of the claim: they run drug programs now. The agent products, for their part, are priced like headcount- OpenAI’s agent tiers were reported at $2,000, $10,000, and $20,000 a month- which is how you price a salary, whatever it says on the invoice. (Reported tiers, via The Information, if you want the receipts.)
And when the neutral infrastructure collides with a customer, we’ve now seen how that goes- repeatedly. Mike Krieger resigned from Figma’s board in April; Claude Design was announced three days later, Figma’s stock dropped 7% in a day, and Dylan Field said on the record that Anthropic had not been “consistently candid in their communications.” Claude Code out-earns Cursor, the wrapper built on it. Brookings has the pattern documented: OpenAI cut off Windsurf when it moved to acquire it, xAI got its API access story, and Anthropic’s terms of service bar customers from “building a competing product”- a clause that means whatever Anthropic decides it means, on the day it decides. Build your company on the platform and the platform decides when you’ve become a competitor. Martin Casado at a16z has been saying the quiet part on podcasts for a year: expect the model- makers to keep frontier capability for themselves, and everyone else to build on the distilled leftovers.
None of this should surprise you, because the plan was published before ChatGPT existed. In 2021 Sam Altman wrote an essay called “Moore’s Law for Everything” that says, in his own words, that AI will drive the price of labor toward zero and concentrate wealth with the owners of capital and land- and then proposes a tax scheme to soften it. Set the tax scheme aside; look at the premise everyone shrugged past. The people building this technology told you, in writing, five years ago, where the money goes. Toward them.
So let me call the shot, so it’s on the record: this generalizes. The labs are secondary sellers into consulting, pharma, design, and software tooling today, and the playbook in every one of those verticals is the same- sell in as the neutral tool, watch the economics from the inside, then show up as the primary. Consulting went first because it has no moat. Pharma got bought because it has the biggest prize. Design and coding were already built on the API, which made them the easiest to walk into. Your industry is somewhere on that list. The only variable is the date.
The Math Requires It
Here’s the part I find scarier than any acquisition, because it removes the need for anyone to be a villain.
Cédric Durand, working from JPMorgan’s own figures, points out what the AI buildout has to earn to make sense: something like $650 billion a year in perpetual revenue just to return 10% on the datacenter capex- roughly $35 a month from every iPhone user on Earth. There is no tooling market that big. Nobody’s dev-tools budget, nobody’s SaaS line item, no aggregate of API subscriptions gets you there. You know what is that big? Payroll. One MIT and Oak Ridge simulation- the Iceberg Index- prices the skills current AI can already technically perform at about 11.7% of US wage value, roughly $1.2 trillion. Capability, mind you; nobody’s claiming those jobs are gone. The claim is simpler and colder: the only pool of money large enough to justify what’s already been spent is the pool that currently gets paid to people. The verticalization is the balance sheet talking. No mustache-twirling required- just debt service.
Now the concessions, because they’re real and they’re the only comfort on offer. Consulting margins are a disaster. Verticals have incumbents with teeth. Ben Thompson argues the existing aggregators may absorb AI rather than be eaten by it. The economists will add, correctly, that “technically automatable” and “substituted” are different animals- complementarity and adoption friction have eaten scarier projections than this one- and the strategy reader will point to AWS, which stayed neutral for twenty years because neutrality was the profitable equilibrium. Both fair. But AWS never owed anyone $650 billion a year; neutrality stops being an equilibrium when the debt is priced against payroll. Even Dario Amodei, whose “Machines of Loving Grace” imagined compressing a century of science into a decade, has since walked the timeline back: “I don’t think that today we can make progress at a rate of 10 years per year.” The conquest is not guaranteed. But notice what all of those comforts have in common: they’re about whether the labs will win the wage pool, and say nothing about whether they’ll stop trying- the debt says they can’t. And notice what the API era quietly was, in retrospect. Every product built on the models was a market experiment the labs got to watch from the inside- what worked, what people paid for, where the margin lived. Their API customers were the R&D department they never had to pay for.
The Clearance Ladder
Which brings us to the part the labs will tell you about themselves, if you read their announcements like a geologist reads a road cut.

In April, Anthropic unveiled Project Glasswing: a model, Mythos-class, superhuman at finding software vulnerabilities- and, in Anthropic’s own words, one it “does not plan to make generally available.” Eleven launch partners got direct access: AWS, Apple, Microsoft, Google. Then a ring of forty-plus vetted organizations. Then funded scraps for the open-source world: $2.5 million through the Linux Foundation, $1.5 million to Apache. Over ten thousand vulnerabilities found, disclosure coordinated with government.
Let me concede the safety logic in full, because it’s genuinely strong: you do not GA a zero-day factory. A model that can find 10,000 vulnerabilities in friendly hands can find them in hostile ones. Some perimeter around that capability is the responsible move, and the people who built the perimeter can defend every stone of it in good faith.
The structural point survives the concession. Nothing outside the company forces the perimeter open, ever. The vetting answers to no legislature and no court; it answers to a safety team and, eventually, to a P&L. The Atomic Energy Commission was a lot of things, but it was at least accountable to Congress. The clearance ladder here is private: lab insiders at the top, then government and classified deployments (ClaudeGov, a $200 million DoD ceiling, “red lines” negotiated as the price of admission), then vetted partners, then enterprise, then you, in the consumer tier, holding a chat box.
And the June episode showed us the ladder under stress. When the government yanked the top models, the first thing restored was Mythos 5- through Glasswing, to the vetted list, with Washington’s sign-off. The general public got theirs last. You can read that sequence as ordinary incident triage, biggest customers first, and you might be right about the intent. Intent was never my claim. The claim is about the plumbing: a full clearance hierarchy already existed, ran under emergency conditions without a hiccup, and sorted the entire planet by trust tier on its first live test. Time-to-frontier is the new class system: everyone eventually gets the capability, the only question is how many months after the people above you. The K-shaped economy, measured in model versions.
Now put the ladder and the wage-pool math in the same frame, because they compound. The same company deciding which tier you occupy is pricing its products against your salary. Getting the shiny model first is the small stakes; the ladder is the org chart of the economy the math is paying for. Your industry reports to a tier. So do you.
The Ban That Wasn’t
Now for the part I got wrong, because it’s the most instructive thing in this essay.
If you’d asked me a year ago how the state would respond to Chinese open-weight models eating the substrate- Qwen past 700 million downloads, more than Llama; something like 40-45% of open-weight traffic; reportedly 80% of US AI startups using a Chinese open model somewhere in the stack- I’d have predicted a ban. It’s the obvious script. Josh Hawley even filed it: S.321, criminalizing the import of Chinese AI models, with penalties glossed in press coverage at up to 20 years. That bill has stalled in committee since January 2025 with zero cosponsors and no action in 18 months. Nobody even bothered to kill it. And sure- most bills die exactly this way, of nothing in particular. The signal is the contrast: while the ban sat, the opposite ask moved.
What’s moving instead is the inversion. In February, Anthropic published a post naming DeepSeek, Moonshot, and MiniMax as running “industrial-scale” distillation campaigns against Claude- rivals training their models on Claude’s outputs. In June it wrote to the Senate Banking Committee about Alibaba’s Qwen team: by Anthropic’s own count- these are allegations, not adjudicated findings- 28.8 million exchanges harvested through roughly 25,000 fraudulent accounts, “the largest known distillation attack on Anthropic to date,” turning US investment into “a subsidy for our competitors.” (One line the coverage keeps blurring: distillation itself- training a small model on a big model’s outputs- is an ordinary, openly documented technique; half the models on your local GPU were made this way. The allegation is about scale, fraud, and terms of service, not about the technique existing.) And the legislative asks that follow are about penalizing extraction: sanction the distillers, protect the asset. To be precise about what’s on the record: Anthropic’s asks are extraction penalties and chip controls; nobody’s own words propose banning Chinese weights for Americans.
Read that as property law, because that’s what it is- the state deciding whose asset gets protected, and the answer is the labs’. A year ago the live debate in Washington was whether to ban open weights; the live debate now is how hard to punish copying the closed ones. The state looked at the fence and decided its job was to help build it.
We also know what “banning” software actually looks like when the state does attempt it, because we’ve run the experiment twice. The Kaspersky ban was a supply cutoff with no possession penalty, and by industry telemetry more than 40% of the US organizations previously running it still were, months later. TikTok took two years and five non-enforcement executive orders to reach a divestiture. Files don’t respect prohibition; corporate compliance departments do. Which is why the mechanism that matters going forward is the quiet one: the same Commerce Department that flipped Anthropic’s switch in June holds a separate instrument- the ICTS Final Determination, the tool that eventually moved TikTok- it can point at a named Chinese lab any time it wants. Different paperwork, same fence. And the fence can always be extended. That’s rather the point of fences.
The Floor
So who’s holding the door open? Here’s the strangest fact in the whole picture: the biggest force keeping frontier-adjacent AI in your hands right now is the Chinese Communist Party’s industrial strategy.
Both blocs run the same two-tier structure. China’s frontier tier stays closed too- Qwen-Max, the actual best stuff, does not ship as weights. What China exports at zero price is its second tier, as deliberate soft-power policy, and that second tier is good enough that it became the world’s default substrate. RAND’s researchers, studying why, land on mechanics rather than ideology: performance parity, licenses more permissive than Meta’s or Google’s, and lock-in- DeepSeek’s attention architecture is now a default in vLLM, the plumbing everyone shares. Credit where due: raw weights become something you can actually run because a volunteer ecosystem- quantizers, fine-tuners, the llama.cpp and vLLM contributors- does the unpaid last mile. But the supply itself exists because Beijing’s export strategy happens to require it, and it could be revoked through the export catalogue overnight.
But here’s what can’t be revoked: everything already released. The weights are mirrored, forked, fine-tuned, seeded across a million hard drives on every continent. An open release is not a subscription that lapses; the archive only accumulates. Only the edge is fragile. The gap between the fenced frontier and the open floor runs maybe 12 to 18 months of capability decay- nobody publishes an official figure, it moves by task, and the open-weights crowd will tell you it’s been shrinking- and that gap, not any statute, is, for now, the actual constitution of this economy.
Your Tier
Run the movie forward and the world it’s pointing at is easy to describe, because the pieces are all on the table. The labs run the drug programs, the deployment consultancies, the design tools, the coding tools- each vertical a subsidiary, each priced against the salaries it replaces, each fed by watching what its API customers built before it built them in-house. Access to the machine that does this flows down a private clearance ladder, and the ladder’s operator answers to a safety team, a P&L, and a Commerce Department switch. Your profession is a line item in a vertical-expansion memo. Your tier was assigned before you knew there were tiers.
That’s the world the capex is betting on. Whether the bet lands is genuinely undecided. The brakes are enumerable, so watch them like a hawk. Watch whether the frontier markup holds across the next three model generations, or whether the floor keeps closing the gap. That one doubles as the test of this essay, because if the labs can’t hold the edge, they can’t hold the wage pool either, and I’m wrong about the whole trajectory. Watch the final text of any anti-distillation bill, because that text decides whether extracting capability from the incumbents is a crime. Watch whether China’s release cadence survives its own strategists. And watch the gap between what the labs use internally and what they sell you. That gap is the truest measure of the clearance ladder, and right now it’s the number they’d least like published.
The switch is real; June proved it. The ladder is real; the restoration order proved that. The appetite is real; the balance sheet proves it daily. What stands between you and the fully-eaten version of this economy is a 12-month head start that has to be re-won every generation, currently underwritten by the geopolitical vanity of a rival superpower. Look on the bright side: your access to the future is guaranteed by nobody you can vote for, but at least somebody’s guaranteeing it. For now, check your tier.
Subscribe to Engineering Our Social Vehicles for occasional satire, philosophy, and short fiction from yours truly- next up: what the thing behind the switch is actually made of. Bring a rock hammer.


Interesting read. This line stood out:
"None of this should surprise you, because the plan was published before ChatGPT existed. In 2021 Sam Altman wrote an essay called “Moore’s Law for Everything” that says, in his own words, that AI will drive the price of labor toward zero and concentrate wealth with the owners of capital and land- and then proposes a tax scheme to soften it. Set the tax scheme aside; look at the premise everyone shrugged past."
Is any of this process new. Isn't the acceleration of the concentration of capital--and therefore power in a society the values wealth over everything else--business as usual during the past three centuries of capitalism. In that context, it seems what we need is a moral shift:
https://writerbytechnicality.substack.com/p/moral-shift?r=3anz55