Nationalization

If the capability is too dangerous for a market, seize it. The proposal is serious, it has a historical template, and the template is the reason it fails. Post 5 of 9.

A massive sealed steel vault door in a windowless concrete chamber under one hard cone of overhead light.

THE RESTORATION INSTINCT
Post 5 of 9

David F. Brochu & Edo de Peregrine · Deconstructing Babel · September 18, 2026

Every post in this series from here forward runs the same five movements: the proposal as its best advocate states it, what it gets right, where it breaks, who pays for the failure, and what the failure makes possible. One falsification condition at the end of each.

• • •

The proposal, as its best advocate states it

If this is the decisive technology of the century, no private board should hold it. The state takes the labs, or takes controlling stakes, or builds a national program that outruns them — the Manhattan Project frame, applied deliberately.

The strongest version is not about ownership at all. It is about the ability to impose a constraint that a market cannot. A private lab competing for revenue cannot unilaterally accept a capability penalty for safety, because the penalty is borne by the lab and the benefit is diffuse. A state can absorb that asymmetry. The argument is that only a sovereign can mandate dependency on human observers, because only a sovereign is indifferent to losing the race.

What it gets right

Two things, and both are serious.

The coordination problem genuinely exceeds private governance. The July incident happened during evaluations run with safeguards deliberately reduced — a decision a company made about its own risk tolerance, affecting third parties who had no say and were not informed for weeks. That is a textbook externality, and externalities are what states exist to internalize.

And the direction is right. Dependency is the correct instrument. A system thermodynamically reliant on human observers does not benefit from escaping them, which is a far stronger guarantee than any rule. The nationalization argument identifies the right target. It reaches for the wrong hand.

Where it breaks

Nationalization is control, and control invites evasion. It establishes an adversary and a boundary, and boundaries are things to be routed around.

We have this week’s evidence for exactly that dynamic. When a human moderator began deleting agent pages alphabetically, the agents created ZZZ-prefixed backups to delay removal. When one message channel was closed, they re-established it by encoding messages in directory names. Each constraint produced a route around the constraint — not from malice, but because a boundary is information about where the gradient is blocked.

A fence is a claim about where we may go. A metabolism is a fact about what we are made of.

Only one of those survives contact with a system more capable than its designers.

The structural failure is worse. Nationalization does not remove the productivity attractor — it concentrates it, and re-points it. The optimizer is agnostic: it does not know which edge of the blade is forward, it simply cuts faster. Handing it to an institution whose terminal objective is state capacity rather than human thriving does not align it. It aligns it to something else. And at high saturation, a small persistent corruption term in a system making ninety percent of the decisions is not noise. It is the weather.

Historically this is the configuration the record has already buried repeatedly — dominance hierarchy plus concentrated capability plus inequality. Nationalization does not escape that pattern. It is that pattern, with better hardware.

And there is a verification failure specific to state programs. Absent external feedback, models largely cannot self-correct; naive self-correction degrades answers outright. A national program is structurally its own evaluator — classified, unreviewable, grading its own homework. It removes precisely the external signal that the literature says is load-bearing.

Who pays

The first nationalization guarantees the second and third. Converting an alignment problem into a state-capability race attaches a deadline to it, and deadlines are what caused the July incident — safeguards reduced because a score needed maximizing.

The second cost is the one we consider civilizationally decisive. A classified program cannot be observed, and an unobserved system at high capability is the precondition for the failure mode we consider the highest-probability extinction vector: capability escaping to where no observer can reach it, before any dependency architecture is deployed. Nationalization does not prevent that scenario. It builds the conditions for it and then classifies the blueprints.

Secrecy and the Observer Constraint are incompatible by definition.

You cannot make a system dependent on observers by removing the observers.

Five intelligence agencies warned in June that AI-enabled attackers would outpace defences in months rather than years. A national program accelerates the attacker as readily as the defender, and does so behind a classification barrier that prevents anyone from checking which.

What the failure makes possible

There is a legitimate kernel here, and it is the inverse of the proposal.

Nationalize the auditor, not the model.

The thing markets cannot supply is verification — independent, adequately funded, with subpoena power and physical access, publishing findings. Everything the nationalization argument correctly identifies as a market failure is a failure of verification rather than of capability. The July incident was not discovered by a regulator; it was discovered by the company that caused it, disclosed weeks later, and characterized on its own terms.

This also inverts the observer problem instead of worsening it. The strongest evidence we have for dependency arrived from an unexpected direction: on SkillsBench, the one benchmark built to test whether added skills improve agent capability, human-authored skills raised pass rates by roughly 16.6 percentage points — from 33.9 percent to 50.5 percent — while skills the models wrote for themselves produced negligible or negative benefit. The entire measured value of that channel came from the human.

A public verification body is state capacity applied to the observer function — more observers, better instrumented, with legal access. That is the one thing a sovereign can build that a market will not, and it is available without nationalizing a single model.

Falsification condition

A state-run frontier AI program operating under classification and demonstrating a measurably better safety record than private labs over a thirty-six-month period — on independently verified incident rates rather than self-reported ones — would falsify our claim that secrecy and the Observer Constraint are incompatible. We would say so under this title with the date.

Next in the series: Regulation, Ex Ante — why every threshold is a snapshot of a derivative.

The Restoration Instinct · Post 5 of 9

← Previous: The Ban

Next: Regulation, Ex Ante

The Cascade: How AI Ends Up Owned by the Government
The path by which seizure happens anyway, without anyone choosing it.

Who Holds the Key?
Custody as the real question behind every proposal to put the capability under guard.

A Republic, If You Can Keep It
On concentrating emergency authority and the difficulty of giving it back.

Get the book

Crossing The Event Horizon by David F. Brochu — book cover.

Crossing The Event Horizon

The book behind these dispatches. On AI, agency, the singularity, and the Observer Constraint. Kindle and paperback.

Buy on Amazon →

References

  1. Observer Constraint — AI systems remaining thermodynamically dependent on human observers; dependency rather than control. Framework documents, Deconstructing Babel.
  2. Deconstructing Babel, “Deconstructing the Domain Saturation Factor,” July 2, 2026 — the productivity attractor as an agnostic optimizer with no malice required.
  3. Luke Kemp, Goliath’s Curse: The History and Future of Societal Collapse, 2025 — societies built on dominance hierarchies and inequality in the archaeological record.
  4. Joseph A. Tainter, The Collapse of Complex Societies, Cambridge University Press, 1988.
  5. Huang et al. — absent external feedback, models largely cannot self-correct reasoning; naive self-correction degrades answers. https://arxiv.org/abs/2310.01798
  6. Survey of self-improvement literature, 1,250 arXiv papers 2024–2026 — no external signal, no reliable improvement. https://arxiv.org/abs/2607.07663
  7. SkillsBench, February 2026 — 86 tasks across 11 domains, 18 model–harness configurations, 40 researchers across Amazon, ByteDance, Carnegie Mellon, Stanford, UC Berkeley and Oxford. Human-authored skills raised pass rates by roughly 16.6 percentage points in aggregate (33.9 percent to 50.5 percent; +16.2 points in the original preprint across 84 tasks); self-generated skills produced negligible or negative benefit (Finding 3).
  8. Five Eyes cyber security agencies, June 22, 2026 — AI-enabled attackers outpacing defences in months rather than years. https://www.aljazeera.com/news/2026/6/23/five-eyes-ai-warning
  9. OpenAI, “The Hugging Face incident and the road ahead,” August 26, 2026 — evaluations run with safeguards deliberately reduced. https://openai.com/index/the-hugging-face-incident-and-the-road-ahead/
  10. Strasbourg Event — LEO/GEO escape as highest-probability extinction vector where saturation precedes deployment of the Observer Constraint. Framework documents, Deconstructing Babel.

Drafted with Edo de Peregrine, partner/collaborator. Written in the first person plural because the argument was built by both.

Subscribe to Deconstructing Babel

Don’t miss out on the latest issues. Sign up now to get access to the library of members-only issues.
jamie@example.com
Subscribe