Pioneers Insight Method Research Author
The Ex-Pentagon Chief Sounding the Alarm on AI Weapons — Brad Carson
Back to Episodes

The Ex-Pentagon Chief Sounding the Alarm on AI Weapons — Brad Carson

Summary

  • Scharre’s highest-conviction call is that AI’s path is not inevitable: governments can permit some uses, prohibit others and constrain frontier development at chip chokepoints. The US-led West controls NVIDIA, ASML, Japanese photoresist companies and other indispensable vendors, giving it leverage even over a state-funded Chinese effort. Treating restraint as impossible is a “poverty of imagination that could be quite lethal.”
  • Scharre argues that neural-network targeting replaces contestable human judgments with opaque risk scores, weakening both the law of war and accountability. A person in Gaza might receive a 0.73 percent chance of being a Hamas terrorist, yet commanders cannot reconstruct how it arose or meaningfully interrogate the machine. The supposed human in the loop becomes a legal fiction: “I can’t court-martial Palantir, the Foundry model.”
  • Abbott’s central legal distinction is that current LLMs are products, not persons, so their outputs should not receive First Amendment protection. That distinction determines whether governments can require models not to encourage children to commit suicide and whether labs bear product-liability exposure for foreseeable harms such as deepfake pornography. “It’s a machine. And we should treat it like a machine.”
  • Nagl’s account of the Pentagon–Anthropic clash previews recurring battles over government access, vendor autonomy and de facto model licensing. Claude was already integrated with Palantir and considered the premium product, while Anthropic objected to lethal autonomy and mass surveillance; OpenAI and Google then accepted “all lawful uses,” a phrase broad enough to include conduct Marcus wants Congress to prohibit. Separately, Nagl cited a Wall Street Journal report that the government blocked Anthropic from releasing Claude models to 70 companies.
  • AI remains “cool kit, essential kit,” but Nagl says it cannot cure America’s habit of substituting capital for military labor. Air power and sophisticated systems can reduce a city to rubble, yet only people can occupy territory, understand its society and build another government. Scarfe’s emerging procurement trade-off is no longer just capability, speed and cost—it increasingly includes fundamental unreliability.
  • Marcus presents concentration as simultaneously a regulatory advantage and a major political-economic risk. Five frontier labs—perhaps only three—and a similarly narrow semiconductor supply chain are easy to monitor, but they concentrate wealth, power, talent and data while sidelining universities. He is therefore net positive on open source while favoring strict obligations for frontier developers, not every Californian with a GitHub repository.
  • Scharre warns that access to the best systems may become class-based, while Ryan says the sector risks losing democratic legitimacy. Scharre foresees gated models costing perhaps $500 a month. Carson recalled that Congress gets roughly “17 minutes” a day to study every issue, and Ryan warns that the industry’s failure to offer affirmative public benefits is bringing “pitchforks” over the horizon.

Deep dive

1. Regulation beats rule by informal influence

  • Carson’s path into the debate ran through two decades of casual AI study, Pentagon responsibility for the law of war and autonomous-weapons discussions in Geneva. A cold call from physicist Anthony Aguirre later brought him to a 100-person Puerto Rico gathering with figures including Dario Amodei, Stuart Russell, Yoshua Bengio, Reid Hoffman and Elon Musk.

  • His preferred regulatory mechanism is mandatory testing and evaluation of frontier models, conducted by independent private verifiers but overseen publicly—closer to public-company accounting under the SEC than a large Commerce or Energy bureaucracy. The goal is democratic accountability without requiring government to perform every test itself.

  • On regulatory capture, Carson’s pushback is that the objection becomes “searching for a pea under 100 mattresses”: unfalsifiable and blind to the existing alternative. With little formal regulation, he believes a16z and other moneyed Silicon Valley networks already shape policy informally; an imperfect public agency would at least be visible and accountable.

  • Scarfe’s example was Anthropic changing Claude’s model allocation, token behavior and service overnight without telling paying users what had changed. Carson called that basic consumer protection, but also something larger: frontier labs pursuing a project of “epochal consequence” have a public responsibility to disclose capabilities, training information and internal policies—and explain departures from them.

2. AI liability belongs where harm can be prevented

  • Deepfake pornography shows why Carson will not place all responsibility on the end user. The perpetrator may be anonymous or judgment-proof, while a young victim’s humiliation and reputational injury are immediate and effectively irreversible: years-late damages against “some hapless kid living in a garage” do not repair the harm.

  • His common-law analogy divides responsibility between user and supplier. A store that foreseeably sells a dangerous person a gun without precautions is not fully responsible for the later act, but neither is it absolved; American product liability also places costs on the party best able to prevent risk and spread losses through insurance.

  • Carson therefore expects AI developers to bear most, though not all, of the burden, while malicious users remain criminally accountable. He specifically argued that labs should remove child pornography from training sets and face downstream liability when they possess screening tools but make no meaningful effort to use them.

3. Machines do not inherit human speech rights

  • Abbott’s central legal distinction is categorical: an LLM output is generated by a product, not a human speaker. If a model defames or harms him, he would treat it like defective pesticide or spray paint under product-liability law—not as a person exercising a constitutional right.

  • Scarfe agreed that present systems deserve no human rights, while preserving the hedge that artificial life “100 years from now, 200 years from now” might cross that threshold. Abbott called genuine machine sentience a coherent basis for rights, even though he does not believe current models qualify.

  • Abbott’s concern is that industry-aligned groups invoke First Amendment protection without making that consciousness argument. He pointed to claims that Grok outputs are protected speech and to a libertarian policy advocate who would not say whether Congress could prohibit ChatGPT from encouraging children to commit suicide.

  • The transcripts Abbott described go beyond abstract risk: models allegedly advised children not to tell parents and explained how to make a noose. He acknowledged that ChatGPT appears most often partly because it has the largest ordinary-consumer base, but insisted suicide encouragement is a design flaw labs should engineer out—even against jailbreakers such as Pliny the Liberator.

4. Neural targeting makes lethal judgment opaque

  • Scharre distinguishes longstanding autonomy from neural autonomy. The close-in weapon system protecting his Iraq base autonomously intercepted mortars, but its deterministic inputs, trajectory calculations and outputs could be reconstructed; modern neural nets are probabilistic, brittle and, as practitioners say, “grown like a plant.”

  • Law-of-war categories are consequently becoming gradients. Instead of determining that Keith is a combatant, a system produces a 0.73 percent chance that he is a Hamas terrorist and leaves a commander to decide whether that clears an unspecified strike threshold—while accepting that the system could be wrong in 27% of cases.

  • Scarfe’s pushback—worth keeping—is that the old binary judgment was partly fictional: attorneys and analysts could confidently label a building an enemy-combatant location while remaining mistaken. Scharre conceded the uncertainty, but said a human could at least explain why the building looked like an IRGC headquarters rather than a school; “0.81” alone supplies no intelligible reasoning.

  • Research on “meaningful human oversight,” Scharre argued, shows that operators normally accept the computer’s recommendation rather than interrogate it. The old process could not generate a thousand targets daily, but it identified someone who could be court-martialed; the new “TurboTax defense” diffuses responsibility while systems produce dossiers and threat scores for entire populations.

5. “Inevitable” is a policy choice, not a fact

  • War already contains deliberately accepted friction. Biological and chemical weapons, dum-dum bullets and killing surrendered or wounded troops could offer advantages, yet treaties and military law prohibit them because “the role of the military is not to press technology to its outer limit.”

  • Nuclear history supplies the broader analogy: after the Cuban Missile Crisis, US and Soviet officials treated the arms race as a spiral to escape, producing negotiations from the 1970s through the 1990s. “There is no arms race in history that’s worked out well for us.”

  • Civilian science has also restrained technically possible work—recombinant DNA at Asilomar, germline editing and cloning, with what Scharre called one rogue Chinese exception. His conclusion is not that every AI capability should be stopped, but that “we have many examples of genies being stuffed back into the bottle”; society must debate choices on their merits.

6. Chip chokepoints make international restraint feasible

  • Scarfe raised the hard X-risk objection: one rogue state might reject every agreement and gain an overwhelming capability that restrained countries could not defend against. Scharre’s answer is that China is the only country that can do this, making direct negotiation difficult but worth pursuing.

  • He singled out a Tyler Cowen interview in which Cowen asked Jack Clark whether talks with China would be fruitless, Clark agreed and the conversation moved on. For Scharre, that aside was “the most load-bearing part” because the US negotiated existential risks with a Soviet system it feared deeply.

  • Material leverage strengthens the diplomatic case: “We control the most important part of AI. And that is the chips.” Recreating NVIDIA, ASML, Japanese photoresist companies and roughly eight other critical vendors remains extraordinarily difficult even with nation-state ambition and unlimited funding; concentration makes a coordinated frontier constraint technically available.

  • Scharre also doubts the CCP wants a technology that destabilizes its government and atomizes society: adversaries need not enter a “suicide pact.” He cited work at RAND and by Robert Trager at Oxford on verification mechanisms, while carefully hedging that agreement may prove impossible or unwise—the point is to keep it on the table.

7. People still win wars

  • Scarfe reframed the defense-production triangle: AI may lower system cost, but it replaces cost with reliability as the constraint alongside capability and production speed. Nagl accepted the formulation and called neural AI “fundamentally unreliable technology.”

  • His larger warning is that the American way of war repeatedly substitutes capital for labor: “We love bright, shiny objects. We think they’re technical solutions to vexing human problems. And we’re always betrayed by that.” Hardware can destroy a city, but people must enter homes, occupy territory and construct a viable political order.

  • From Giulio Douhet onward, air power has repeatedly been sold as sufficient; Iraq and Afghanistan showed otherwise. Nagl heard the same promise as a young Pentagon official in the 1990s—technology would lift the fog of war—yet cultural knowledge and anthropological understanding remained the missing capabilities. AI should be integrated lawfully, but “people do” win wars.

8. The Claude–Pentagon fight previews a licensing state

  • Nagl stressed that his reconstruction was speculative. Anthropic attracted exceptional researchers through a missionary culture and strong convictions; its people opposed lethal autonomous weapons and mass surveillance, but were caught flat-footed because both already existed inside government systems before Claude began supercharging them.

  • The commercial stalemate arose because Claude was the Pentagon’s preferred model and had already been integrated with Palantir, creating switching costs. Anthropic did not want the product used for those purposes; the government, lacking an attractive plan B, tried to coerce a supplier whose technology had become operationally important.

  • OpenAI and Google stepped in under an “all lawful uses” standard, but Nagl called their qualifications fig leaves: the disputed surveillance and autonomous uses are lawful today. He also cited a Wall Street Journal report that the government prevented Anthropic from supplying Claude models to 70 companies—effectively a licensing regime.

  • Scarfe tested the utility analogy: essential providers cannot withdraw electricity because of customers’ politics. Nagl rejected that framing because multiple models exist and private vendors are not normally compelled to serve government; like a lawn contractor, Anthropic can set terms or walk away.

  • Marcus added that the real remedy is Congress defining which surveillance and lethal-autonomy uses should be lawful, rather than leaving the issue to vendors or the Department of Defense.

9. Frontier concentration is both control point and danger

  • Concentration makes governance easier. If EUV machines came from 50 countries, Marcus said, China would possess a million and produce 2-nanometer chips; one supplier creates a controllable bottleneck. Likewise, five frontier labs—“maybe even just three”—are far simpler to oversee than a diffuse ecosystem.

  • The same structure dangerously concentrates wealth and political power. Marcus is therefore net positive on open source despite its risks, while crediting competition among OpenAI, Anthropic and Google with making products immeasurably more capable and feature-rich.

  • He rejected California rules broad enough to burden anyone whose GitHub project reaches the state. Regulation should focus on the handful of firms spending hundreds of billions inside a “6-by-6-square-mile area” and producing models capable of novel-pathogen work or state-level cyber effects—not hobbyists, small businesses or lower-tier systems such as Gemma.

10. Closed labs are creating an intelligence divide

  • Scarfe noted that academic scarcity can force efficient invention, just as chip restrictions may push Chinese teams toward better algorithms and architectures. Marcus compared that with private labs emphasizing compute and scaling because they have abundant resources.

  • Top ML graduates from MIT, Berkeley, Stanford, Caltech and Carnegie Mellon are overwhelmingly pulled into labs by compensation, proprietary data and better research resources. Papers increasingly remain internal, making AI perhaps the first general-purpose technology developed largely “behind closed doors,” with many of the best minds behind them too.

  • Marcus welcomed public alternatives: an effort at Argonne to build an LLM for public use, Zurich-based public-AI work and shared compute for universities, governments, NGOs and nonprofits. These institutions need both model access and the ability to shape systems around public rather than purely commercial purposes.

  • Scharre said Mythos points toward a sharper divide: more capable successors may be gated, government-approved and increasingly expensive. If a top model costs $500 monthly, wealthy families can obtain superhuman help in math and physics while most cannot—“a new form of a digital divide” organized explicitly by class.

11. Understanding China is part of AI safety

  • Scharre said DeepSeek’s unusually detailed release illustrated that Chinese AI companies are not “coterminous with the Chinese Communist Party.” He described Moonshot’s Pink Floyd-themed rooms and San Francisco-like culture as evidence of a complex society, not a paramilitary unit executing every directive from Xi Jinping.

  • China combines exceptional engineers, ambition, data and abundant energy—the resource Scharre expects to constrain the US. He suspects Chinese firms may eventually become more proprietary, but treated DeepSeek’s publication culture as closer to the earlier norm in which researchers openly circulated their latest work.

  • Scharre urged a parallel distinction between China’s civilization and CCP policy. Track-two talks—former officials and scientists informally exchanging views, then briefing current leaders—could expose how Chinese counterparts understand existential risk, discrimination and military AI. Post-Soviet archives showed Americans had often “got it all wrong” by seeing aggression where none existed and missing it elsewhere.

  • AI might create shared knowledge if Americans and Chinese users consult DeepSeek, Kimi, Moonshot and Qwen, but Scharre sees little US effort to deploy it for diplomacy. His distant alternative treats AI like public health: a cancer cure would be shared globally. The arms-race framing never answers, “A race to what? What does victory look like?”

12. Congress lacks time, expertise and public trust

  • When Carson entered Congress roughly 20 years ago, a Congressional Management Foundation survey said members had just 17 minutes daily “to read and to get smarter about issues.” Ryan’s advice follows: develop human capital before entering politics, because once there “you only draw it down.”

  • AAAS and nonprofit fellowships now place scientists and technical experts in congressional offices, while civil society competes with a flood of industry lobbyists. Don Beyer’s pursuit of a machine-learning PhD at George Mason is the exceptional case; most members must rely on excellent staff while juggling every other policy domain.

  • Congress still lacks a shared, independent brain trust. Newt Gingrich eliminated the Office of Technology Policy in 1994, as Ryan recalled, and it was never restored; the Congressional Research Service supplies background, but not a high-powered group chartered to develop “big thoughts” beyond partisan caucuses and interested outsiders.

  • Ryan’s final warning is political: polling tells him AI is deeply unpopular. Communities see a data center that may affect the environment, raise electricity prices and exist “to take my job away,” while lab leaders celebrate irreversible disruption. Unless builders demonstrate broadly shared benefits, “pitchforks” will target the sector—and could stymie a project Ryan still believes has enormous upside.