IV. The Project
IV. 计划
As the race to AGI intensifies, the national security state will get involved. The USG will wake from its slumber, and by 27/28 we’ll get some form of government AGI project. No startup can handle superintelligence. Somewhere in a SCIF, the endgame will be on.
In this piece: Toggle
“We must be curious to learn how such a set of objects—hundreds of power plants, thousands of bombs, tens of thousands of people massed in national establishments—can be traced back to a few people sitting at laboratory benches discussing the peculiar behavior of one type of atom.”
Spencer R. Weart
Many plans for “AI governance” are put forth these days, from licensing frontier AI systems to safety standards to a public cloud with a few hundred million in compute for academics. These seem well-intentioned—but to me, it seems like they are making a category error.
I find it an insane proposition that the US government will let a random SF startup develop superintelligence. Imagine if we had developed atomic bombs by letting Uber just improvise.
Superintelligence—AI systems much smarter than humans—will have vast power, from developing novel weaponry to driving an explosion in economic growth. Superintelligence will be the locus of international competition; a lead of months potentially decisive in military conflict.
It is a delusion of those who have unconsciously internalized our brief respite from history that this will not summon more primordial forces. Like many scientists before us, the great minds of San Francisco hope that they can control the destiny of the demon they are birthing. Right now, they still can; for they are among the few with situational awareness, who understand what they are building. But in the next few years, the world will wake up. So too will the national security state. History will make a triumphant return.
As in many times before—Covid, WWII—it will seem as though the United States is asleep at the wheel—before, all at once, the government shifts into gear in the most extraordinary fashion. There will be a moment—in just a few years, just a couple more “2023-level” leaps in model capabilities and AI discourse—where it will be clear: we are on the cusp of AGI, and superintelligence shortly thereafter. While there’s a lot of flux within the exact mechanics, one way or another, the USG will be at the helm; the leading labs will (“voluntarily”) merge; Congress will appropriate trillions for chips and power; a coalition of democracies formed.
Startups are great for many things—but a startup on its own is simply not equipped for being in charge of the United States’ most important national defense project. We will need government involvement to have even a hope of defending against the all-out espionage threat we will face; the private AI efforts might as well be directly delivering superintelligence to the CCP. We will need the government to ensure even a semblance of a sane chain of command; you can’t have random CEOs (or random nonprofit boards) with the nuclear button. We will need the government to manage the severe safety challenges of superintelligence, to manage the fog of war of the intelligence explosion. We will need the government to deploy superintelligence to defend against whatever extreme threats unfold, to make it through the extraordinarily volatile and destabilized international situation that will follow. We will need the government to mobilize a democratic coalition to win the race with authoritarian powers, and forge (and enforce) a nonproliferation regime for the rest of the world. I wish it weren’t this way—but we will need the government. (Yes, regardless of the Administration.)
In any case, my main claim is not normative, but descriptive. In a few years, The Project will be on.
The path to The Project
A turn-of-events seared into my memory is late February to mid-March of 2020. In those last weeks of February and early days of March, I was in utter despair: it seemed clear that we were on the covid-exponential: a plague was about to sweep the country, the collapse of our hospitals was imminent—and yet almost nobody took it seriously. The Mayor of New York was still dismissing Covid-fears as racism and encouraging people to go to Broadway shows. All I could do was buy masks and short the market.
And yet within just a few weeks, the entire country shut down and Congress had appropriated trillions of dollars (literally >10% of GDP). Seeing where the exponential might go ahead of time was too hard, but when the threat got close enough, existential enough, extraordinary forces were unleashed. The response was late, crude, blunt—but it came, and it was dramatic.
The next few years in AI will feel similar. We’re in the midgame now. 2023 was already a wild shift. AGI went from a fringe topic you’d be hesitant to associate with, to the subject of major Senate hearings and summits of world leaders. Given how early we are still, the level of USG engagement has been impressive to me. A couple more “2023”s, and the Overton window will be blown completely open.
As we race through the OOMs, the leaps will continue. By 2025/2026 or so I expect the next truly shocking step-changes; AI will drive $100B+ annual revenues for big tech companies and outcompete PhDs in raw problem-solving smarts. Much as the Covid stock-market collapse made many take covid seriously, we’ll have $10T companies and the AI mania will be everywhere. If that’s not enough, by 2027/28, we’ll have models trained on the $100B+ cluster; full-fledged AI agents/drop-in remote workers will start to widely automate software engineering and other cognitive jobs. Each year, the acceleration will feel dizzying.
While many don’t yet see the possibility of AGI, eventually a consensus will form. Some, like Szilard, saw the possibility of an atomic bomb much earlier than others. Their alarm was not well-received initially; the possibility of a bomb was dismissed as remote (or at least, it was felt that the conservative and proper thing was to play down the possibility). Szilard’s fervent secrecy appeals were mocked and ignored. But many scientists, initially skeptical, started realizing a bomb was possible as more and more empirical results came in. Once a majority of scientists came to believe we were on the cusp of a bomb, the government, in turn, saw the national security exigency as too great—and the Manhattan Project got underway.
As the OOMs go from theoretical extrapolation to (extraordinary) empirical reality, gradually, a consensus will form, too, among the leading scientists and executives and government officials: we are on the cusp, on the cusp of AGI, on the cusp of an intelligence explosion, on the cusp of superintelligence. And somewhere along here, we’ll get the first genuinely terrifying demonstrations of AI: perhaps the oft-discussed “helping novices make bioweapons,” or autonomously hacking critical systems, or something else entirely. It will become clear: like it or not, this technology will be an utterly decisive military technology. Even if we’re lucky enough to not be in a major war, it seems likely that the CCP will have taken notice and launched a formidable AGI effort. Perhaps the eventual (inevitable) discovery of the CCP’s infiltration of America’s leading AI labs will cause a big stir.
Somewhere around 26/27 or so, the mood in Washington will become somber. People will start to viscerally feel what is happening; they will be scared. From the halls of the Pentagon to the backroom Congressional briefings will ring the obvious question, the question on everybody’s minds: do we need an AGI Manhattan Project? Slowly at first, then all at once, it will become clear: this is happening, things are going to get wild, this is the most important challenge for the national security of the United States since the invention of the atomic bomb. In one form or another, the national security state will get very heavily involved. The Project will be the necessary, indeed the only plausible, response.
Of course, this is an extremely abbreviated account—a lot depends on when and how consensus forms, key warning shots, and so on. DC is infamously dysfunctional. As with Covid, and even the Manhattan Project, the government will be incredibly late and hamfisted. After Einstein’s letter to the President in 1939 (drafted by Szilard), an Advisory Committee on Uranium was formed. But officials were incompetent, and not much happened initially. For example, Fermi only got $6k (about $135k in today’s dollars) to support his research, and even that was not given easily and only received after months of waiting. Szilard believed that the project was delayed for at least a year by the short-sightedness and sluggishness of the authorities. In March 1941, the British government finally concluded a bomb was inevitable. The US committee initially entirely ignored this British report for months—until finally in December 1941, a full-scale atomic bomb effort was launched.
There are many ways this could be operationalized in practice. To be clear, this doesn’t need to look like literal nationalization, with AI lab researchers now employed by the military or whatever (though it might!).1 Rather, I expect a more suave orchestration. The relationship with the DoD might look like the relationship the DoD has with Boeing or Lockheed Martin. Perhaps via defense contracting or similar, a joint venture between the major cloud compute providers, AI labs, and the government is established, making it functionally a project of the national security state. Much like the AI labs “voluntarily” made commitments to the White House in 2023, Western labs might more-or-less “voluntarily” agree to merge in the national effort. And likely Congress will have to be involved, given the trillions of investment involved, and for checks-and-balances.2 How all these details shake out is a story for another day.
But by late 26/27/28 it will be underway. The core AGI research team (a few hundred researchers) will move to a secure location; the trillion-dollar cluster will be built in record-speed; The Project will be on.
**Why The Project is the only way **
I am under no illusions about the government. Governments face all sorts of limitations and poor incentives. I am a big believer in the American private sector, and would almost never advocate for heavy government involvement in technology or industry.
I used to apply this same framework to AGI—until I joined an AI lab. AI labs are very good at some things: they’ve been able to take AI from an academic science project to the commercial big stage, in a way only a startup can. But ultimately, AI labs are still startups. We simply shouldn’t expect startups to be equipped to handle superintelligence.
There are no good options here—but I don’t see another way. When a technology becomes this important for national security, we will need the USG.
Superintelligence will be the United States’ most important national defense project
I’ve discussed the power of superintelligence in previous pieces. Within years, superintelligence would completely shake up the military balance of power.* *By the early 2030s, the entirety of the US arsenal (like it or not, the bedrock of global peace and security) will probably be obsolete. It will not just be a matter of modernization, but a wholesale replacement.
Simply put, it will become clear that the development of AGI will fall in a category more like nukes than the internet. Yes, of course it’ll be dual-use—but nuclear technology was dual-use too. The civilian applications will have their time. But in the fog of the AGI endgame, for better or for worse, national security will be the primary backdrop.
We will need to completely reshape US forces, within a matter of years, in the face of rapid technological change—or risk being completely outmatched by adversaries who do. Perhaps most of all, the initial priority will be to deploy superintelligence for defensive applications, to develop countermeasures to survive untold new threats: adversaries with superhuman hacking capabilities, new classes of stealthy drone swarms that could execute a preemptive strike on our nuclear deterrent, the proliferation of advances in synthetic biology that can be weaponized, turbulent international (and national) power struggles, and rogue superintelligence projects.
Whether nominally private or not, the AGI project will need to be, *will be, *integrally a defense project, and it will require extremely close cooperation with the national security state.
A sane chain of command for superintelligence
The power—and the challenges—of superintelligence will fall into a very different reference class than anything else we’re used to seeing from tech companies. It seems pretty clear: this should not be under the unilateral command of a random CEO. Indeed, in the private-labs-developing-superintelligence world, it’s quite plausible individual CEOs would have the power* to literally coup the US government*.3 Imagine if Elon Musk had final command of the nuclear arsenal.4 (Or if a random nonprofit board could decide to seize control of the nuclear arsenal.)
It is perhaps obvious, but: as a society, we’ve decided democratic governments should control the military;5 superintelligence will be, at least at first, the most powerful military weapon. The radical proposal is not The Project; the radical proposal is taking a bet on private AI CEOs wielding military power and becoming benevolent dictators.
(Indeed, in the private AI lab world, it would likely be even worse than random CEOs with the nuclear button—part of AI labs’ abysmal security is their utter lack of internal controls. That is, random AI lab employees (with zero vetting) could go rogue unnoticed.)
We will need a sane chain of command—along with all the other processes and safeguards that necessarily come with responsibly wielding what will be comparable to a WMD—and it’ll require the government to do so. In some sense, this is simply a Burkean argument: the institutions, constitutions, laws, courts, checks and balances, norms and common dedication to the liberal democratic order (e.g., generals refusing to follow illegal orders), and so on that check the power of the government have withstood the test of hundreds of years. Special AI lab governance structures, meanwhile, collapsed the first time they were tested. The US military could already kill basically every civilian in the United States, or seize power, if it wanted to—and the way we keep government power over nuclear weapons in check is not through lots of private companies with their own nuclear arsenals. There’s only one chain of command and set of institutions that has proven itself up to this task.
Again, perhaps you are a true libertarian and disagree normatively (let Elon Musk and Sam Altman command their own nuclear arsenals!)6 But once it becomes clear that superintelligence is a principal matter of national security, I’m sure this is how the men and women in DC will look at it.
The civilian uses of superintelligence
Of course, that doesn’t mean the civilian applications of superintelligence will be reserved for the government.
- The nuclear chain reaction was first harnessed as a government project—and nuclear weapons permanently reserved for the government—but civilian nuclear energy flourished as private projects (in the 60s and 70s, before environmentalists shut it down).
- Boeing made the B-29 (the most expensive defense R&D project during WWII, more expensive than the Manhattan Project) and the B-47 and B-52 long-range bombers in partnership with the military—before using that technology for the Boeing 707, the commercial plane that ushered in the jet era. And today, while Boeing can only sell stealth fighter jets to the government, it can freely develop and sell civilian jets privately.
- And so it went for radar, satellites, rockets, gene technology, WWII factories, and so on.
The initial development of superintelligence will be dominated by the national security exigency to survive and stabilize an incredibly volatile period. And the military uses of superintelligence will remain reserved for the government, and safety norms will be enforced. But once the initial peril has passed, and the world has stabilized, the natural path is for the companies involved in the national consortium (and others) to privately pursue civilian applications.
Even in worlds with The Project, a private, pluralistic, market-based, flourishing ecosystem of civilian applications of superintelligence will have its day.
Security
I’ve gone on about this at length in a previous piece in the series. On the current course, we may as well give up on having any American AGI effort; China can promptly steal all the algorithmic breakthroughs and the model weights (literally a copy of superintelligence) directly. It’s not even clear we’ll get to “North Korea-proof” security for superintelligence on the current course. In the private-startups-developing-AGI-world, superintelligence would proliferate to dozens of rogue states. It’s simply untenable.
If we’re going to be at all serious about this, we obviously need to lock this stuff down. Most private companies have failed to take this seriously. But in any case, if we are to eventually face the full force of Chinese espionage (e.g., stealing the weights being the MSS’s #1 priority), it’s probably impossible for a private company to get good enough security. It will require extensive cooperation from the US intelligence community at that point to sufficiently secure AGI. This will involve invasive restrictions on AI labs and on the core team of AGI researchers, from extreme vetting to constant monitoring to working from a SCIF to reduced freedom to leave; and it will require infrastructure only the government can provide, ultimately including the physical security of the AGI datacenters themselves.
In some sense, security alone is sufficient to necessitate the government project—both the free world’s preeminence and AI safety are doomed if we can’t lock this stuff down. (In fact, I think it’s fairly likely to be a major factor in the ultimate trigger: once the Chinese infiltration of the AGI labs becomes clear, every Senator and Congressperson and national security official will… have a strong opinion on the matter.)
Safety
Simply put: there are a lot of ways for us to mess this up—from ensuring we can reliably control and trust the billions of superintelligent agents that will soon be in charge of our economy and military (the superalignment problem) to and controlling the risks of misuse of new means of mass destruction.
Some AI labs claim to be committed to safety: acknowledging that what they are building, if gone awry, could cause catastrophe and promising that they will do what is necessary when the time comes. I do not know if we can trust their promise enough to stake the lives of every American on it. More importantly, so far, they have not demonstrated the competence, trustworthiness, or seriousness necessary for what they themselves acknowledge they are building.
At core, they are startups, with all the usual commercial incentives. Competition could push all of them to simply race through the intelligence explosion, and there will at least be some actors that will be willing to throw safety by the wayside. In particular, we may want to “spend some of our lead” to have time to solve safety challenges, but Western labs will need to coordinate to do so. (And of course, private labs will have already had their AGI weights stolen, so their safety precautions won’t even matter; we’ll be at the mercy of the CCP’s and North Korea’s safety precautions.)
One answer is regulation. That may be appropriate in worlds in which AI develops more slowly, but I fear that regulation simply won’t be up to the nature of the challenge of the intelligence explosion. What’s necessary will be less like spending a few years doing careful evaluations and pushing some safety standards through a bureaucracy. It’ll be more like fighting a war.
We’ll face an insane year in which the situation is shifting extremely rapidly every week, in which hard calls based on ambiguous data will be life-or-death, in which the solutions—even the problems themselves—won’t be close to fully clear ahead of time but come down to competence in a “fog of war,” which will involve insane tradeoffs like “some of our alignment measurements are looking ambiguous, we don’t really understand what’s going on anymore, it might be fine but there’s some warning signs that the next generation of superintelligence might go awry, should we delay the next training run by 3 months to get more confidence on safety—but oh no, the latest intelligence reports indicate China stole our weights and is racing ahead on their own intelligence explosion, what should we do?”.
I’m not confident that a government project would be competent in dealing with this—but the “superintelligence developed by startups” alternative seems much closer to “praying for the best” than commonly recognized. We’ll need a chain of command that can bring to the table the seriousness that making these difficult tradeoffs will require.
Stabilizing the international situation
The intelligence explosion and its immediate aftermath will bring forth one of the most volatile and tense situations mankind has ever faced. Our generation is not used to this. But in this initial period, the task at hand will not be to build cool products. It will be to somehow, desperately, make it through this period.
We’ll need the government project to win the race against the authoritarian powers—and to give us the clear lead and breathing room necessary to navigate the perils of this situation. We might as well give up if we can’t prevent the instant theft of superintelligence model weights. We will want to bundle Western efforts: bring together our best scientists, use every GPU we can find, and ensure the trillions of dollars of cluster buildouts happen in the United States. We will need to protect the datacenters against adversary sabotage, or outright attack.
Perhaps, most of all, it will take American leadership to develop—and if necessary, enforce—a nonproliferation regime. We’ll need to subvert Russia, North Korea, Iran, and terrorist groups from using their own superintelligence to develop technology and weaponry that would let them hold the world hostage. We’ll need to use superintelligence to harden the security of our critical infrastructure, military, and government to defend against extreme new hacking capabilities. We’ll need to use superintelligence to stabilize the offense/defense balance of advances in biology or similar. We’ll need to develop tools to safely control superintelligence, and to shut down rogue superintelligences that come out of others’ uncareful projects. AI systems and robots will be moving at 10-100x+ human speed; everything will start happening extremely quickly. We’ll need to be ready to handle whatever other six-sigma upheavals—and concomitant threats—come out of compressing a century’s worth of technological progress into a few years.
At least in this initial period, we will be faced with the most extraordinary national security exigency. Perhaps, nobody is up for this task. But of the options we have, The Project is the only sane one.
The Project is inevitable; whether it’s good is not
Ultimately, my main claim here is descriptive: whether we like it or not, superintelligence won’t look like an SF startup, and in some way will be primarily in the domain of national security. I’ve brought up The Project a lot to my San Francisco friends in the past year. Perhaps what’s surprised me most is how surprised most people are about the idea. They simply haven’t considered the possibility. But once they consider it, most agree that it seems obvious. If we are at all right about what we think we are building, *of course, *by the end this will be (in some form) a government project. If a lab developed literal superintelligence tomorrow, *of course *the Feds would step in.
One important free variable is not if but when. Does the government not realize what’s happening until we’re in the middle of an intelligence explosion—or will it realize a couple years beforehand? If the government project is inevitable, earlier seems better. We’ll dearly need those couple years to do the security crash program, to get the key officials up to speed and prepared, to build a functioning merged lab, and so on. It’ll be far more chaotic if the government only steps in at the very end (and the secrets and weights will have already been stolen).
Another important free variable is the international coalition we can rally: both a tighter alliance of democracies for developing superintelligence, and a broader benefit-sharing offer made to the rest of the world.
- The former might look like the Quebec Agreement: a secret pact between Churchill and Roosevelt to pool their resources to develop nuclear weapons, while not using them against each other or against others without mutual consent. We’ll want to bring in the UK (Deepmind), East Asian allies like Japan and South Korea (chip supply chain), and NATO/other core democratic allies (broader industrial base). A united effort will have more resources, talent, and control the whole supply chain; enable close coordination on safety, national security, and military challenges; and provide helpful checks and balances on wielding the power of superintelligence.
- The latter might look like Atoms for Peace, the IAEA, and the NPT. We should offer to share the peaceful benefits of superintelligence with a broader group of countries (including non-democracies), and commit to not offensively using superintelligence against them. In exchange, they refrain from pursuing their own superintelligence projects, make safety commitments on the deployment of AI systems, and accept restrictions on dual-use applications. The hope is that this offer reduces the incentives for arms races and proliferation, and brings a broad coalition under a US-led umbrella for the post-superintelligence world order.
Perhaps the most important free variable is simply whether the inevitable government project will be competent. How will it be organized? How can we get this done? How will the checks and balances work, and what does a sane chain of command look like? Scarcely any attention has gone into figuring this out.7 Almost all other AI lab and AI governance politicking is a sideshow. This is the ballgame.
The endgame
And so by 27/28, the endgame will be on. By 28/29 the intelligence explosion will be underway; by 2030, we will have summoned superintelligence, in all its power and might.
Oppenheimer and Groves.
Whoever they put in charge of The Project is going to have a hell of a task: to build AGI, and to build it fast; to put the American economy on wartime footing to make hundreds of millions of GPUs; to lock it all down, weed out the spies, and fend off all-out attacks by the CCP; to somehow manage a hundred million AGIs furiously automating AI research, making a decade’s leaps in a year, and soon producing AI systems vastly smarter than the smartest humans; to somehow keep things together enough that this doesn’t go off the rails and produce rogue superintelligence that tries to seize control from its human overseers; to use those superintelligences to develop whatever new technologies will be necessary to stabilize the situation and stay ahead of adversaries, rapidly remaking US forces to integrate those; all while navigating what will likely be the tensest international situation ever seen. They better be good, I’ll say that.
For those of us who get the call to come along for the ride, it’ll be . . . stressful. But it will be our duty to serve the free world—and all of humanity. If we make it through and get to look back on those years, it will be the most important thing we ever did. And while whatever secure facility they find probably won’t have the pleasantries of today’s ridiculously-overcomped-AI-researcher-lifestyle, it won’t be so bad. SF already feels like a peculiar AI-researcher-college-town; probably this won’t be so different. It’ll be the same weirdly-small circle sweating the scaling curves during the day and hanging out over the weekend, kibitzing over AGI and the lab-politics-of-the-day.
Except, well—the stakes will be all too real.
See you in the desert, friends.
Next post in the series: ***V. Parting Thoughts***
Reunion of atomic scientists on the fourth anniversary of the first controlled nuclear fission reaction at UChicago.
Note that while private companies help develop components for nuclear weapons, they are never allowed to possess a completed and assembled nuclear weapon. In comparison, the mainline version of the “AGI government project” I am putting forward here is unprecedentedly privatized, for the WMD reference class.↩
Congress—even the Vice President!—didn’t know about the Manhattan Project. We probably shouldn’t repeat that here; I’d even suggest that key officials for The Project require Senate confirmation.↩
It wouldn’t even require cooperation from AI lab employees at this point, since they’ll have been mostly automated by this point.↩
And as Sam Altman once said, every year we get closer to AGI everybody will gain +10 crazy points.↩
In fact, the government having the biggest guns was an enormous civilizational achievement! Rather than medieval-like fights of all against all, we would sort out disagreements via courts, pluralistic institutions, and so on.↩
Or perhaps you say, just open-source everything. The issue with simply open sourcing everything is that it’s not a happy world of a thousand flowers blooming in the US, but a world in which the CCP has free access to US-developed superintelligence, and can outbuild (and apply less caution/regulation) and take over the world. And the other issue, of course, is the proliferation of super-WMDs to every rogue state and terrorist group in the world. I don’t think it’ll end well. It’s a bit like how having no government at all is more likely to lead to tyranny (or destruction) than freedom.
In any case, people overrate the importance of open-source as we get closer to AGI. Given cluster costs escalating to hundreds of billions, and key algorithmic secrets now being proprietary rather than published as they were a couple years ago, it’ll be 2-3 or so leading players, rather than some happy community of decentralized coders building AGI.
I do think a different variant of open source will continue to play an important role: models that lag a couple years behind being open sourced, helping the benefits of the technology diffuse broadly.↩
To my Progress Studies brethren: you should think about this, this will be the culmination of your intellectual project! You spend all this time studying American government research institutions, their decline over the last half-century, and what it would take to make them effective again. Tell me: how will we make The Project effective?↩
随着 AGI 竞赛白热化,国家安全机器(national security state)将介入其中。USG(美国政府)将从沉睡中醒来,到 27/28 年,我们将看到某种形式的政府 AGI 项目。没有哪家初创公司能驾驭超级智能。在某个 SCIF(敏感情报设施)之中,终局之战即将上演。
本文内容: Toggle
“我们必须充满好奇地去了解:这样一组事物——数以百计的发电厂、数以千计的炸弹、数以万计聚集于国家机构中的人——如何能够追溯到几位坐在实验室长凳旁、讨论某一种原子奇特行为的科学家。”
斯宾塞·R·沃特(Spencer R. Weart)
如今,人们提出了许多“AI 治理”方案,从给前沿 AI 系统发牌照,到制定安全标准,再到为学术界提供拥有数亿美元算力的公共云。这些方案看起来用意良善——但在我看来,它们似乎犯了一个范畴错误。
我认为,美国政府会放任一家随机的旧金山初创公司开发超级智能,这是一个疯狂的设想。想象一下,如果我们当初是让 Uber 临场发挥来研发原子弹。
超级智能——远比人类聪明的 AI 系统——将拥有巨大的力量,从开发新型武器到推动经济爆炸式增长。超级智能将成为国际竞争的焦点;在军事冲突中,领先数月就可能是决定性的。
认为这不会召来更原始的力量,是那些不知不觉地把我们从历史那里得到的短暂喘息内化于心之人的错觉。正如我们之前的许多科学家一样,旧金山的伟大头脑们希望他们能掌控自己正在孕育的那个恶魔的命运。眼下,他们确实还能做到;因为他们是少数具有“情境感知”(situational awareness)、明白自己在建造什么的人。但在未来几年,世界将苏醒。国家安全机器也会随之苏醒。历史将凯旋归来。
就像以往许多次一样——Covid、二战——美国看上去仿佛在方向盘后睡着了——然后,突然间,政府以最非同寻常的方式挂上挡位全速运转。将会有那么一刻——就在几年之内,只需再经历几次“2023 级别”的模型能力和 AI 舆论跃升——届时一切将昭然若揭:我们正站在 AGI 的门槛上,随后不久就是超级智能。尽管具体机制存在许多变数,但无论如何,USG 将执掌航向;领先的实验室将(“自愿地”)合并;国会将拨款数万亿美元用于芯片和电力;一个民主国家联盟将会形成。
初创公司擅长很多事情——但一家初创公司本身并不具备接管美国最重要的国防项目的条件。我们将需要政府介入,才有希望抵御我们将要面对的全面间谍威胁;私营 AI 努力几乎等于直接把超级智能交到 CCP(中国共产党)手中。我们将需要政府来确保哪怕是形式上健全的指挥链;你不能让随便哪个 CEO(或随便哪个非营利组织董事会)握着核按钮。我们将需要政府来管理超级智能严峻的安全挑战,驾驭智能爆炸的战争迷雾。我们将需要政府部署超级智能,以抵御随之而来的任何极端威胁,安然度过紧随其后的、极度动荡不安的国际局势。我们将需要政府动员一个民主联盟来赢得与威权大国的竞赛,并为世界其他国家锻造(并执行)一套防扩散机制。我希望事情不是这样——但我们将需要政府。(是的,无论哪个政府执政。)
无论如何,我的主要论断不是规范性的,而是描述性的。几年之内,The Project(“计划”)就会启动。
通往 The Project 之路
铭刻在我记忆中的一段转折是 2020 年 2 月下旬至 3 月中旬。在 2 月的最后几周和 3 月初的日子里,我陷入彻底的绝望:看起来我们已经站在了新冠指数曲线上——一场瘟疫即将席卷全国,我们的医院即将崩溃——然而几乎没有人把它当回事。纽约市长仍在把对新冠的担忧斥为种族主义,并鼓励人们去看百老汇演出。我所能做的只是买口罩和做空市场。
然而就在短短几周内,整个国家停摆,国会拨款达数万亿美元——毫不夸张地说,超过 GDP 的 10%。提前看清指数曲线将走向何方太过困难,但当威胁足够逼近、足够攸关存亡时,非凡的力量便被释放出来。应对来得迟缓、粗糙、生硬——但它来了,而且声势惊人。
未来几年 AI 领域的感觉会与此相似。我们现在正处于中局。2023 年已经是一次狂野的剧变。AGI 从一个你不太愿意沾边的边缘话题,变成了参议院重大听证会和世界领导人峰会的主角。考虑到我们仍处于如此早期,USG 的介入程度已令我印象深刻。再来几个“2023 年”,奥弗顿之窗(Overton window,即可接受言论的范围)将被彻底炸开。
当我们疾速穿越 OOM(数量级跃升)时,跃升仍将继续。到 2025/2026 年前后,我预期会出现下一轮真正震撼的阶跃式变化;AI 将为大型科技公司带来每年 1000 亿+美元的营收,并在原始解题能力上胜过博士。正如新冠股市崩盘让许多人开始认真对待新冠,我们将看到 10 万亿美元市值的公司,AI 狂热将无处不在。如果这还不够,到 2027/28 年,我们将拥有在 1000 亿+美元集群上训练的模型;成熟的 AI 智能体/即插即用式远程员工将开始大规模自动化软件工程及其他认知类工作。每一年,加速感都会令人目眩。
虽然许多人还看不到 AGI 的可能性,但最终共识会形成。有些人,如西拉德(Szilard),远比其他人更早看到原子弹的可能性。他们的警报最初并不被接受;原子弹的可能性被斥为遥远(或者至少,人们觉得保守而妥当的做法是淡化这种可能性)。西拉德热切呼吁保密,却遭到嘲笑和忽视。但随着越来越多的实证结果涌现,许多起初持怀疑态度的科学家开始意识到原子弹是可能的。一旦大多数科学家相信我们正站在原子弹的门槛上,政府反过来也认定国家安全紧迫性过于重大——于是曼哈顿计划(Manhattan Project)启动了。
随着 OOM 从理论外推变成(非凡的)经验现实,共识也会逐渐在顶尖科学家、高管和政府官员中形成:我们正站在门槛上,站在 AGI 的门槛上,站在智能爆炸的门槛上,站在超级智能的门槛上。在这条路上的某个节点,我们将看到 AI 首批真正骇人的展示:也许是常被讨论的“帮助新手制造生物武器”,或是自主入侵关键系统,或是完全别的东西。到时将变得清清楚楚:不管喜不喜欢,这项技术都将成为一种具有彻底决定性的军事技术。即便我们幸运地没有卷入大战,CCP 也很可能已经注意到并启动了声势浩大的 AGI 计划。也许,最终(必然)会发现 CCP 已渗透美国顶尖 AI 实验室,并引发轩然大波。
大约在 26/27 年前后,华盛顿的气氛将变得凝重。人们将开始从骨子里感到正在发生什么;他们会感到恐惧。从五角大楼的走廊到国会闭门简报会,都会回响着那个显而易见的问题、那个所有人都在想的问题:我们需要一个 AGI 曼哈顿计划吗?起初是缓慢的,然后突然之间,一切将变得清晰:这事正在发生,局面将变得疯狂,这是自原子弹发明以来美国国家安全面临的最重大挑战。国家机器将以这样或那样的形式深度介入。The Project 将是必要且唯一合理的回应。
当然,这是一个极度简化的叙述——很多事情取决于共识在何时、以何种方式形成,关键示警信号等等。DC(华盛顿)的失灵是出了名的。和 Covid 乃至曼哈顿计划一样,政府会迟到得令人难以置信,而且笨手笨脚。在 1939 年(由西拉德起草的)爱因斯坦致总统的信之后,成立了铀顾问委员会。但官员们无能,起初没什么进展。例如,费米(Fermi)只拿到 6000 美元(约合今天的 13.5 万美元)来支持他的研究,即便是这点钱也给得不痛快,他等了好几个月才拿到。西拉德认为,由于当局的短视和迟缓,项目至少被延误了一年。1941 年 3 月,英国政府终于断定原子弹不可避免。美国委员会最初一连数月完全无视这份英国报告——直到 1941 年 12 月,一场全面的原子弹研发才终于启动。
在实践中,这件事有很多种落实方式。需要说明的是,这不必是字面意义上的国有化——AI 实验室研究人员被军方雇佣之类的(虽然也可能如此!)。1 我更期待一种更为圆滑的编排。与国防部(DoD)的关系可能类似于 DoD 与波音(Boeing)或洛克希德·马丁(Lockheed Martin)的关系。或许通过国防承包或类似机制,在主要云算力提供商、AI 实验室与政府之间建立合资企业,使其在功能上成为一个国家安全国家项目。就像 2023 年 AI 实验室“自愿”向白宫作出承诺一样,西方实验室可能会或多或少“自愿”同意并入国家努力之中。鉴于涉及数万亿美元的投资,并且为了制衡,国会很可能会介入。2 这些细节如何落地,是后话。
但到 26/27/28 年底,它就会启动。核心 AGI 研究团队(几百名研究人员)将迁往一处安全地点;耗资万亿美元的集群将以创纪录的速度建成;The Project 将正式启动。
为什么 The Project 是唯一的路
我对政府不抱任何幻想。政府面临各种局限和不良激励。我深信美国私营部门,几乎从不主张政府深度介入技术或产业。
我曾把这个框架同样套用到 AGI 上——直到我加入了一家 AI 实验室。AI 实验室擅长某些事情:它们能够把 AI 从一个学术科学项目带到商业大舞台,这种方式只有初创公司才能做到。但归根结底,AI 实验室仍然是初创公司。我们根本不应该指望初创公司具备驾驭超级智能的能力。
这里没有好的选项——但我也看不到别的路。当一项技术对国家安全变得如此重要时,我们将需要 USG。
超级智能将成为美国最重要的国防项目
我在之前的文章中讨论过超级智能的力量。数年之内,超级智能将彻底撼动军事力量平衡。到 2030 年代初,美国的整个武库(无论你喜不喜欢,它都是全球和平与安全的基石)很可能会过时。这不仅是现代化的问题,而是全面的替换。
简言之,届时将变得清楚:AGI 的发展将归属于一个更像核武器而非互联网的类别。是的,它当然是军民两用的——但核技术当年也是两用的。民用应用会有自己的时代。但在 AGI 终局的迷雾中,无论好坏,国家安全都将是首要背景。
面对快速的技术变革,我们将需要在数年之内彻底重塑美国军队——否则就有被那些这样做了的对手全面超越的风险。也许最重要的是,初始优先事项将是把超级智能部署于防御性应用,开发对策以求在数不胜数的新威胁下生存:拥有超人黑客能力的对手、能够对我们的核威慑发动先发制人打击的新型隐身无人机蜂群、可被武器化的合成生物学进展的扩散、动荡的国际(和国内)权力斗争,以及失控的超级智能项目。
无论名义上是否私有,AGI 项目都将需要成为、也必将会成为一个彻头彻尾的国防项目,并且将需要与国家安全国家机器进行极其密切的合作。
一条健全的超级智能指挥链
超级智能的力量——以及挑战——将落入一个与我们习惯从科技公司看到的任何事物都截然不同的参照类别。事情似乎很清楚:这不应置于某个随便的 CEO 的单方面指挥之下。事实上,在私营实验室开发超级智能的世界里,个别 CEO 极有可能拥有足以真正政变美国政府的权力。3 想象一下,如果埃隆·马斯克(Elon Musk)对核武库拥有最终指挥权。4(或者一个随便的非营利组织董事会可以决定夺取核武库的控制权。)
这一点也许显而易见,但还是要说:作为一个社会,我们已经决定民主政府应当掌控军队;5 而超级智能至少在一开始将是威力最大的军事武器。激进的主张不是 The Project;激进的主张是押注于私营 AI 公司的 CEO 们掌握军事力量并成为仁慈的独裁者。
(事实上,在私营 AI 实验室的世界里,情况很可能比随便哪个 CEO 握着核按钮更糟——AI 实验室糟糕透顶的安全状况,部分原因在于它们完全缺乏内部控制。也就是说,随便一个(未经任何审查的)AI 实验室雇员都可能神不知鬼不觉地走上歧途。)
我们将需要一条健全的指挥链——以及所有那些伴随负责任地行使近似于大规模杀伤性武器(WMD)之权力而来的流程与保障——而这将要求政府来做到。在某种意义上,这不过是一个柏克式(Burkean)论证:那些制约政府权力的制度、宪法、法律、法院、制衡机制、规范与对自由民主秩序的共同忠诚(例如将军拒绝执行非法命令)等等,已经经受住了数百年的考验。与此同时,专门的 AI 实验室治理结构在第一次接受考验时就崩溃了。美国军队如果想要,现在就能杀死美国几乎所有平民,或者夺取政权——而我们约束政府对核武器之权力的方式,并不是靠许多各自拥有核武库的私营公司。已经被证明能胜任这一任务的指挥链和制度只有一套。
再说一次,也许你是一个真正的自由意志主义者,在规范层面不同意(让埃隆·马斯克和山姆·奥特曼(Sam Altman)指挥各自的核武库吧!)6 但一旦事情变得清楚:超级智能是国家安全的首要事务,我确信华盛顿的人们就会这样看待它。
超级智能的民用用途
当然,这并不意味着超级智能的民用应用将被保留给政府。
- 核链式反应最初是作为政府项目被驾驭的——核武器也永久地保留给政府——但民用核能以私营项目的形式蓬勃发展(在 60、70 年代,在环保主义者将其叫停之前)。
- 波音与军方合作制造了 B-29(二战期间最昂贵的国防研发项目,比曼哈顿计划还贵)以及 B-47 和 B-52 远程轰炸机——之后才将这项技术用于波音 707,这款商用客机开启了喷气时代。而今天,虽然波音只能向政府出售隐身战斗机,却可以自由地在市场上研发和销售民用客机。
- 雷达、卫星、火箭、基因技术、二战工厂等等,情况都是如此。
超级智能的初期开发将受国家安全紧急状态的支配——为了在一个极度动荡的时期生存下来并稳住局面。超级智能的军事用途仍将保留给政府,安全规范也将得到执行。但一旦最初的危难过去、世界恢复稳定,自然的道路就是让参与国家联合体的公司(以及其他公司)以私营方式去追求民用应用。
即便在存在 The Project 的世界里,一个私营的、多元的、以市场为基础的、繁荣的超级智能民用应用生态也终将迎来自己的时代。
Security(安全)
我在本系列的前一篇文章中已经就此大谈特谈。按照目前的路线,我们还不如放弃任何美国 AGI 努力;中国可以径直偷走所有的算法突破和模型权重(那字面上就是超级智能的副本)。在目前的路线下,我们能否为超级智能实现“朝鲜级防泄漏”的安全都不清楚。在私营初创公司开发 AGI 的世界里,超级智能将扩散到几十个流氓国家。这根本行不通。
如果我们打算认真对待这件事,显然需要把这些东西锁死。大多数私营公司都没能认真对待。但无论如何,如果我们终究要面对中国间谍活动的全部火力(比如,窃取权重成为国安部(MSS)的头号优先任务),那么一家私营公司很可能不可能获得足够好的安全。届时将需要美国情报界广泛配合,才能充分保障 AGI 的安全。这将涉及对 AI 实验室和 AGI 核心研究团队侵入性的限制,从极端审查、持续监控、在 SCIF 内工作,到限制离境自由;并且需要只有政府才能提供的基础设施,最终包括 AGI 数据中心本身的实体安全。
从某种意义上说,仅 Security 一项就足以让政府项目成为必需——如果我们不能把这些东西锁死,自由世界的卓越地位和 AI 安全都将注定失败。(事实上,我认为它很可能成为最终导火索的一个主要因素:一旦中国对 AGI 实验室的渗透变得明朗,每一位参议员、众议员和国家安全官员都将……对此有强烈的意见。)
Safety(安全,指对齐等安全挑战)
简言之:我们有很多种方式搞砸这一切——从确保我们能可靠地控制和信任即将掌管我们经济与军队的数十亿超级智能体(超级对齐问题),到控制新型大规模杀伤手段被滥用的风险。
一些 AI 实验室声称致力于安全:承认他们正在建造的东西一旦失控可能引发灾难,并承诺在关键时刻会做必要之事。我不知道我们能否足够信任他们的承诺,以至于把每个美国人的生命押在上面。更重要的是,迄今为止,他们并未展现出他们自己所承认正在建造之物所要求的胜任力、可信度或严肃性。
从根本上说,它们是初创公司,带有所有惯常的商业激励。竞争可能推动它们全都干脆在智能爆炸中狂奔,而且至少会有一些行为者愿意把安全抛到一边。尤其是,我们可能想要“花费我们领先优势的一部分”,以赢得时间解决安全挑战,但西方实验室需要协调一致才能做到。(当然,私营实验室的 AGI 权重早已被偷走,所以他们的安全预防措施根本不重要了;我们将听凭 CCP 和朝鲜的安全预防措施的摆布。)
一个答案是监管。在 AI 发展更缓慢的世界里,这也许是合适的,但我担心监管根本无力应对智能爆炸这一挑战的性质。必要的事情将不像花几年时间做细致评估、在官僚体系里推动若干安全标准那样。它会更像打一场战争。
我们将面临疯狂的一年:局势每周都在极其迅速地变化;基于模棱两可数据的艰难抉择将关乎生死;解决方案——甚至问题本身——都无法提前完全看清,只能取决于“战争迷雾”中的应变能力;这将涉及疯狂的取舍,比如“我们的一些对齐测量结果看起来模棱两可,我们不再真正理解正在发生什么,也许没事,但有一些警示信号表明下一代超级智能可能失控,我们是否应该把下一次训练推迟 3 个月以在安全上获得更多把握——但糟糕的是,最新的情报报告显示中国偷走了我们的权重,正在他们自己的智能爆炸上飞速前进,我们该怎么办?”
我并不确信一个政府项目就能胜任应对这一切——但“由初创公司开发超级智能”这一替代方案,似乎比人们通常认识到的更接近“祈祷一切顺利”。我们将需要一条能够拿出做这些艰难取舍所需之严肃性的指挥链。
稳定国际局势
智能爆炸及其直接余波将带来人类有史以来最动荡、最紧张的局面之一。我们这一代人并不习惯于此。但在这一初期阶段,眼前的任务不是打造炫酷的产品,而是拼命想办法熬过这段时期。
我们将需要政府项目来赢得与威权大国的竞赛——并为我们提供驾驭这一局面的险境所需的明确领先和喘息空间。如果我们无法阻止超级智能模型权重被瞬间窃取,那还不如放弃。我们将希望把西方努力捆绑在一起:汇聚我们最优秀的科学家,动用我们能找到的每一块 GPU,并确保数万亿美元的集群建设发生在美国。我们将需要保护数据中心免遭对手破坏,乃至直接攻击。
也许最重要的是,需要美国的领导来制定——并在必要时执行——一套防扩散机制。我们将需要阻止俄罗斯、朝鲜、伊朗和恐怖组织利用它们自己的超级智能开发能让它们挟持世界的技术与武器。我们将需要利用超级智能来加固我们关键基础设施、军队和政府的安全,以抵御极端的新型黑客能力。我们将需要利用超级智能来稳定生物学等领域进展的攻防平衡。我们将需要开发工具来安全地控制超级智能,并关停从别人不经心的项目中冒出来的失控超级智能。AI 系统和机器人将以人类速度的 10-100 倍以上运行;一切都将开始以极快的速度发生。我们将需要准备好应对把整整一个世纪的技术进步压缩进几年而带来的任何其他六西格玛级别的剧变——以及随之而来的威胁。
至少在初期阶段,我们将面对最非同寻常的国家安全紧急状态。也许没有人能胜任这项任务。但在我们拥有的选项中,The Project 是唯一理性的一个。
The Project 是不可避免的;好坏则未必
归根结底,我在此的主要论断是描述性的:无论我们喜不喜欢,超级智能都不会长得像一家旧金山初创公司,而会在某种意义上主要属于国家安全的领域。过去一年里,我向旧金山的朋友们多次提起 The Project。也许最让我惊讶的是,大多数人对这个想法如此惊讶。他们根本没考虑过这种可能性。但一旦他们考虑了,大多数人都会同意这看起来是明摆着的。如果我们对自己正在建造之物的判断有任何正确之处,那么当然,到最后这将(以某种形式)成为一个政府项目。如果明天有一家实验室开发出了货真价实的超级智能,当然,联邦政府会介入。
一个重要的自由变量不是是否,而是何时。政府是要等到我们身陷智能爆炸之中才意识到正在发生什么——还是提前几年就会意识到?如果政府项目不可避免,那么越早似乎越好。我们将极其需要这几年时间去执行安全紧急计划,让关键官员跟上进度并做好准备,建成一个运转正常的合并实验室,等等。如果政府只在最后关头才介入,局面将混乱得多(而且机密和权重早已被偷走)。
另一个重要的自由变量是我们能够集结的国际联盟:既要有一个更紧密的民主国家联盟来开发超级智能,也要向世界其他地区提供更广泛的利益共享安排。
- 前者可能类似于魁北克协定:丘吉尔与罗斯福之间的一份秘密协议,约定汇集双方资源研发核武器,未经双方同意不得将核武器用于对方或第三方。我们将希望把英国(DeepMind)、日本和韩国等东亚盟友(芯片供应链)以及北约/其他核心民主盟友(更广泛的工业基础)拉进来。联合行动将拥有更多资源、人才,并掌控整个供应链;能够在安全、国家安全和军事挑战上实现密切协调;并对行使超级智能之权力提供有益的制衡。
- 后者可能类似于和平利用原子能(Atoms for Peace)、国际原子能机构(IAEA)和《不扩散核武器条约》(NPT)。我们应当提议与更广泛的国家群体(包括非民主国家)共享超级智能的和平红利,并承诺不对它们进攻性使用超级智能。作为交换,它们放弃推进自己的超级智能项目,在 AI 系统部署上作出安全承诺,并接受对两用应用的种种限制。希望这一提议能降低军备竞赛与扩散的激励,并在美国主导的保护伞下为后超级智能时代的世界秩序集结一个广泛的联盟。
也许最重要的自由变量,就是那个不可避免的政府项目是否能够胜任。它将如何组织?我们怎样才能做成这件事?制衡机制将如何运作,一条健全的指挥链该是什么样子?几乎没有人花心思去弄清楚这些。7 几乎所有其他的 AI 实验室和 AI 治理政治博弈都是次要表演。这才是真正的比赛。
终局
就这样,到 27/28 年,终局将上演。到 28/29 年,智能爆炸将全面展开;到 2030 年,我们将召来超级智能,以其全部的力量与威能。
奥本海默(Oppenheimer)和格罗夫斯(Groves)。
无论他们让谁来掌管 The Project,都将面临一项极其艰巨的任务:建造 AGI,而且要建得快;让美国经济转入战时状态以制造数以亿计的 GPU;把所有东西锁死,清除间谍,抵御 CCP 的全方位攻击;设法管理一亿个疯狂地自动化着 AI 研究、一年做出十年跨越、并很快制造出远超最聪明人类之 AI 系统的 AGI;设法稳住局面,使其不至于脱轨、产生出试图从人类监管者手中夺取控制权的失控超级智能;利用这些超级智能开发稳定局势、领先对手所必需的任何新技术,并迅速重塑美国军队以整合这些技术;而这一切都发生在可能是人类史上最紧张的国际局势之中。他们最好足够出色,我得说这话。
对于我们这些接到召唤、受邀同行的人来说,那将是……充满压力。但服务自由世界——以及全人类——将是我们的职责。如果我们能挺过去,回望那些年,那将是我们做过的最重要的事。而且,无论他们找到什么安全设施,大概都没有今天荒唐的高薪 AI 研究员生活方式那样的舒适惬意,但也不会太糟。旧金山已经让人感觉像一座独特的 AI 研究员大学城;大概这也不会有太大不同。还是那个小得古怪的圈子,白天为缩放曲线(scaling curves)捏一把汗,周末聚在一起,聊着 AGI 和当下的实验室政治。
只是,嗯——赌注将无比真实。
朋友们,沙漠见。
本系列下一篇:V. 临别感想
原子科学家们在芝加哥大学首次受控核裂变反应四周年之际重聚。
请注意,虽然私营公司帮助开发核武器的部件,但绝不允许它们拥有组装完成的核武器。相比之下,我在此提出的“AGI 政府项目”的主流版本,就大规模杀伤性武器的参照类别而言,其私营化程度是前所未有的。↩
国会——甚至副总统!——当年都不知道曼哈顿计划。我们大概不该在此重演这一幕;我甚至建议,The Project 的关键官员需要参议院确认任命。↩
到那时甚至不需要 AI 实验室雇员的配合,因为到那时他们大多已经被自动化了。↩
而且正如山姆·奥特曼曾说过的,每一年我们越接近 AGI,每个人都会增加 +10 疯狂点数。↩
事实上,政府拥有最大的枪是一项巨大的文明成就!与中世纪那种所有人对抗所有人的战争不同,我们会通过法院、多元制度等来解决分歧。↩
或者也许你会说,干脆把一切都开源。简单地把一切都开源的问题在于,那不是一个美国国内千花齐放的幸福世界,而是一个 CCP 可以自由获取美国开发的超级智能、能建得更多更快(且应用更少的谨慎/监管)从而接管世界的世界。另一个问题当然是超级大规模杀伤性武器扩散到世界上每一个流氓国家和恐怖组织。我不认为这会有什么好结局。这有点像:完全没有政府,更可能通向暴政(或毁灭)而非自由。
无论如何,随着我们越来越接近 AGI,人们高估了开源的重要性。鉴于集群成本攀升至数千亿美元,而且关键的算法机密如今已归专有、不像几年前那样公开发表,将只有 2-3 个左右的领先玩家在建造 AGI,而不是某个由分散的编码者组成的快乐社区。
我确实认为开源的一个不同变体会继续扮演重要角色:落后几年的模型被开源,帮助这项技术的红利广泛扩散。↩
致我的进步研究(Progress Studies)同道们:你们应该想想这件事,这将是你学术事业的高潮!你们花了这么多时间研究美国政府科研机构、它们过去半个世纪的衰落,以及要怎样才能让它们重新高效运转。告诉我:我们将如何让 The Project 高效运转?↩

