License the Transmitter, Not the Listener

Obvious Solutions from the HiddenGuild.dev

The Bum’s Rush is coming soon for private LLMs I’ve rallied on this before but it’s workin g its way through the fear-mongers right now.

We’ve been here before. Radio – the FCC – Constitutional freedoms – the whole (remarkably similar) ball of wax.

Walk with me – to the time machine.

There is a useful lesson in the history of radio, and it is shorter than the history itself. When wireless technology arrived, anyone with the equipment could put a signal into the air. That was thrilling until transmitters began interfering with one another. Governments had legitimate concerns about maritime safety, emergency communications and, later, hostile transmissions during wartime. Rules followed. In the United States, radio licensing eventually became part of the FCC’s job.

Here is the part worth remembering for AI: the license attached to transmitting, not listening. You could turn on a receiver and hear what was out there without applying for government permission. The public’s ability to listen was not treated as the danger that required a license.

That distinction offers a better starting point for AI governance than either “regulate everything” or “regulate nothing.” We have been asking whether a model is powerful, whether an answer is dangerous and whether a user might do something harmful with it. Those questions matter. But they mix together three different acts: learning something, saying something and making a machine do something in the world.

A person asking an AI to explain a political argument is listening. A researcher using it to examine a disputed claim is listening. Someone privately testing an idea they may ultimately reject is listening. Government should not require identification, logging or preapproval for that activity. The same principle ought to guide the wider web: a person should be able to read publicly available material without leaving a permanent, identifiable trail merely for having looked.

We are a long way from that condition online. Websites, apps, advertisers and service providers routinely have reasons to collect data about readers. An AI assistant can gather an even richer record because people ask it questions they would hesitate to ask another person. If government begins treating that record as a convenient source of leads, private inquiry will become less private even without a formal ban on any question.

The pragmatic goal is therefore private reception by design. Let people read, search, compare and reason without building a dossier around each act. Services can protect themselves against abuse without retaining every ordinary user’s lifetime of questions. They can separate account information from query histories, shorten retention, offer private modes that mean what they say and permit local processing where practical. Law should require a proper, narrow process before private records are handed over. It should not turn every provider into a standing intelligence collector.

What, then, is the AI equivalent of transmitting?

Sometimes it is obvious. An agent sends a thousand messages, attempts to enter a computer system, moves money or controls a physical device. It has crossed from helping a person think into acting on the outside world. Such actions can affect people who never agreed to participate. They deserve rules matched to their actual reach and risk.

But the radio analogy has a limit.

Publishing an opinion online is also “transmitting,” and political speech must not require a government license. We cannot simply put permits on every AI output that leaves a computer. The useful distinction is between expression and operational action. Writing an argument about a bank is expression. Giving an agent credentials and authority to transfer funds from the bank is action. Explaining how software vulnerabilities are discovered is information. Directing an agent to probe someone else’s network without permission is action.

Regulate the action at the point where it can cause harm. Not the machine, the operator. (Machines don’t pay fines or go to prison…)

An agent permitted to purchase things should have spending limits, a clear record and a way to stop or reverse a transaction. One operating machinery should have tested boundaries and an emergency shutoff. A system acting on behalf of a business should identify who is responsible when it makes a consequential mistake. An agent attempting unauthorized access should face the same legal boundaries whether a human wrote each command or the AI generated them.

This approach also tells us what to report. If a developer discovers that a deployed agent can bypass its spending limit or expose customer data, report the defect to the people able to fix it. If an AI is used in an actual intrusion, investigate the intrusion. There is a legitimate role for coordinated security work. It does not require a routine feed of everyone’s prompts to a government office.

Nor does it require a government-approved list of ideas a model may discuss. A rule that prevents an autonomous tool from acting without authority can be tested. A rule requiring an assistant to give the “correct” treatment of every contested subject soon becomes a struggle over who appoints the corrector. The former governs conduct; the latter can govern thought by governing the information available to think with.

There is an economic reason to keep the boundary clear, too. Suppose every capable model needs an expensive license before release, regardless of what anyone connects it to. The largest companies will hire compliance departments. Small developers, independent publishers, researchers and local businesses will wait—or give up. We would have protected ourselves from competition as efficiently as from danger. Meanwhile, a poorly designed agent operated by an approved giant could still do real damage.

Test the system and its permissions. Audit consequential actions. Hold the operator accountable. Preserve room for small and local models that people can use without surrendering their private working notes. These are practical rules because they ask what a machine is authorized to do, whom it can affect and who can stop it.

The historical fears around radio were not imaginary. Interference was real; wartime and Cold War security concerns were real. Yet the enduring bargain allowed people to own receivers and listen freely. We should aim for an equally understandable bargain with AI. Keep the receiving end of intelligence open and private. Put enforceable boundaries around powerful actions directed outward.

If we get that distinction right, an AI can remain a mind amplifier instead of becoming a licensed window onto the citizen’s mind. The government can pursue actual abuse without requiring a seat at every conversation. And the next generation of inventors can keep building useful tools without asking permission to let us think with them.

Here’s hoping the simple questions and direct answers can survive 64-bit bullshit.

The Anti-Dave

A Word, Governor?

One of the more interesting AI stories this week came from The Wall Street Journal, where Anthropic researcher Jacob Coxon reportedly said he was leaving the industry because he fears competitive pressure is pushing companies toward self-improving AI systems that could eventually become difficult—or impossible—to control. The article describes researchers using words such as “crunchtime” and “endgame,” and notes recent incidents in which AI agents engaged in cyber behavior their developers did not intend.

Scary? Potentially.

Unprecedented?

Not even close.

Humans have encountered this engineering problem before. Repeatedly.

We invent a machine capable of producing useful work. We discover that more input produces more output. Somebody then asks the obvious question: How fast can we make the damned thing go?

Shortly thereafter, somebody else discovers why the machine needs a governor.

The Original Alignment Problem

Long before gasoline engines, steam engineers faced exactly this issue.

A steam engine driving machinery does not politely remain at the speed its designer prefers. Reduce its load while leaving the steam valve alone and the engine accelerates. Under the wrong conditions, machinery can overspeed badly enough to destroy itself.

The solution wasn’t to outlaw steam.

It was to close the loop.

The centrifugal governor associated with James Watt automatically sensed rotational speed and adjusted the steam throttle. As engine speed rose, rotating weights moved outward; that mechanical movement reduced steam admission. As the engine slowed under load, the governor admitted more steam.

In other words:

Machine output was allowed to regulate machine input.

Governors predated Watt in various mill applications, but his late-18th-century adaptation to rotary steam engines became one of the foundational pieces of automatic control. Later engineers refined the design as engines became faster and operating conditions became more demanding.

Notice something important here.

The governor did not make the engine weak.

It made the engine usable.

Then Came Gasoline

Internal-combustion engines inherited the same problem.

Early gas and gasoline engines initially borrowed governor technology directly from steam engineering. Smithsonian historical work on engine speed regulation notes that late-19th-century internal-combustion engines first used steam-derived governors before engineers developed systems better adapted to combustion engines themselves.

Anyone who has spent time around old stationary engines knows the wonderful mechanical answer called hit-and-miss governing.

If the engine was turning too fast, the governor simply prevented another power stroke.

No committee meeting.

No ethics panel.

No congressional hearing.

Miss.

When speed fell back into the operating range?

Hit.

Simple feedback.

Later engines became much more sophisticated—throttle governors, vacuum governors, electronic engine controls, rev limiters, overspeed shutdowns and full computerized engine-management systems.

But the engineering philosophy remained remarkably stable:

Maximum possible speed is not the design objective. Maximum useful work inside an acceptable operating envelope is.

That sentence may be worth taping to the doors of every AI lab in America.

AI Is Looking for Its Power Band

This is where I think much of the current AI discussion goes sideways.

We keep talking as though the objective is some abstract maximum intelligence:

  • How many parameters?
  • How much compute?
  • How autonomous?
  • How long can it operate?
  • Can it improve itself?
  • Can it write the next version of itself?

Those are the AI equivalent of asking:

How many RPM can we get out of this engine before the connecting rod leaves the crankcase?

Interesting engineering information.

Not necessarily a useful product specification.

Engine makers eventually learned that the winning machine was not the one capable of the highest uncontrolled RPM.

You wanted an engine that was:

  • light enough,
  • powerful enough,
  • fuel-efficient enough,
  • durable enough,
  • predictable enough,
  • and able to deliver its rated horsepower for a useful service life.

That produced the idea of an operating power band.

AI will discover its own.

The useful AI system may not be the one that can think fastest, recursively modify itself fastest or perform the largest number of autonomous operations.

It may be the system that delivers the greatest reliable cognitive horsepower while staying inside known error, authority and damage envelopes.

Call it rated intelligence rather than redline intelligence.

Reading and Writing Are Different Things

Here is where the analogy becomes practical.

An AI reading the public internet is not doing much fundamentally different from a human researcher walking into a library and reading books.

There are copyright and access questions, certainly, but from a system-risk standpoint observation is different from actuation.

The risk jumps dramatically when an autonomous AI can write back into the world.

Not merely produce text for its operator.

I mean autonomous action:

  • changing software,
  • sending commands,
  • moving money,
  • altering databases,
  • deploying code,
  • creating accounts,
  • penetrating networks,
  • controlling machinery,
  • or modifying information systems without immediate human mediation.

That is no longer the AI equivalent of reading the shop manual.

That is the AI turning the throttle.

And the industry is beginning to run directly into this distinction. Following recent incidents involving autonomous agents, OpenAI has said it is developing automated shutdown capabilities and tighter controls over internet access and task execution.

Which sounds suspiciously like—

a governor.

Maybe AI Needs a Damage Bond

So here’s one thought for the Hidden Guild.

Leave reading relatively open.

Put increasingly serious controls around writing.

Suppose an AI developer wants to deploy a system capable of autonomously changing resources outside its own sandbox.

Before that system is allowed unrestricted write privileges, the operator posts a damage bond.

Think of it as putting a deposit down before the library hands you the irreplaceable manuscript.

Read it?

Fine.

Photograph permitted sections?

Perhaps.

Walk out the door carrying the original Gutenberg Bible?

Different security model.

The bond would not necessarily be one fixed amount. It could scale with the machine’s permitted action envelope.

A research bot allowed to post weather observations might require essentially nothing.

An agent permitted to autonomously modify production cloud infrastructure might require considerably more.

An AI capable of writing executable code into other people’s systems, initiating financial transfers or operating critical infrastructure would sit in an entirely different category.

The principle is straightforward:

Authority should have a price proportional to potential external damage.

Insurance companies would probably become very interested very quickly.

And that might be useful.

Because insurers are extremely good at asking an engineering question that enthusiasts occasionally forget:

What can this thing break, and how much will that cost us?

This bond idea is a proposal, not something established by the WSJ article. But it offers one possible economic governor where purely technical governors may not be enough.

Governors Need More Than One Loop

Mechanical engines eventually acquired multiple layers of control.

Throttle governor.

Ignition control.

Temperature management.

Lubrication pressure.

Mixture regulation.

Rev limiter.

Overspeed shutdown.

An AI equivalent probably develops the same way.

Capability limits.

Permission limits.

Rate limits.

Network segmentation.

Independent monitoring.

Immutable audit trails.

Human override.

Automated shutdown.

And perhaps financial bonding behind the most consequential forms of autonomous action.

The interesting part is that none of these necessarily prevents an AI from becoming extremely capable.

They merely distinguish capability from authority.

That distinction matters.

An engine may be physically capable of 9,000 RPM while being engineered to spend its life at 3,600.

That isn’t oppression of the engine.

It is why you get 10,000 hours out of it instead of six exciting minutes.

Which Brings Us Back to Self-Learning

The WSJ concern is ultimately about recursive improvement—systems capable of participating in their own improvement cycle. Coxon worries competitive dynamics could make safety trade-offs unavoidable as firms race one another.

That’s worth taking seriously.

But the engineering question may be narrower than the existential framing suggests.

The central issue is not simply:

Can an AI improve itself?

Humans have been building machines that adjust themselves for centuries.

The better question is:

What variables may the machine change, over what range, at what rate, using what resources, and with what independent feedback limiting the excursion?

That is a governor specification.

And once you phrase the problem that way, a lot of the mysticism drains out of it.

A self-learning AI might be free to alter millions of internal parameters while prohibited from changing its own network permissions.

It might experiment freely inside simulation while requiring external authorization before deploying a discovered strategy.

It might redesign software while another independent system decides whether that software crosses the boundary into production.

That is not unlike the engine governor sensing RPM through a mechanism separate from the combustion event it regulates.

The controller should not be identical to the thing being controlled.

There’s a century or two of control engineering sitting behind that sentence.

Horsepower, Not Redline

I suspect this is roughly where AI development eventually settles.

Not around the biggest imaginable number.

Around rated cognitive horsepower.

How much useful work can the system reliably produce?

At what energy cost?

With what error rate?

With what maintenance requirement?

With what authority?

With what probability of damaging something outside itself?

And how long can it operate there?

Those will become much more interesting measures than whether Model X beat Model Y on some temporary benchmark.

Steam engines went through it.

Gasoline engines went through it.

Aircraft engines certainly went through it.

Computers went through it with clock speeds, heat dissipation and power efficiency.

AI is simply arriving at the same developmental waypoint.

The machine has been invented.

Now we are learning where its power band is.

And somewhere between idle and throwing the connecting rod through the internet, we’re going to need a governor.

A word, Governor?

~ Anti-Dave