TRACK 05

The Asymmetry

The gap between what citizens have and what governments and corporations have. Track compute infrastructure spending, classified AI programs, model capability gaps, and regulatory timing. If citizens have GLM-5.2, the government has something significantly more advanced.

DEVELOPING Research framework established Data collection ongoing
Status
ACTIVE INVESTIGATION — RESEARCH IN PROGRESS
This track has identified key research questions and is actively gathering evidence. Data collection is ongoing across compute infrastructure spending, classified AI programs, and model capability gaps. Findings will be documented here as evidence accumulates.

The gap is the policy

The asymmetry between citizen AI and government or corporate AI is not an accident. It is a policy outcome. Every restriction on citizen access to AI models, every compliance requirement that prices out small operators, every certification that excludes local deployments — these widen the gap. The gap is the goal. The mechanisms documented in the other four tracks all serve this one: ensuring that the most powerful AI is available only to those who already have the most power.

Core Insight
If regular citizens have access to advanced AI models, the government has something significantly more advanced. The same dynamic exists in every technology category with national security implications — computing, cryptography, surveillance. AI is following the same pattern. The question is not whether the gap exists. The question is whether it is being deliberately widened under the framing of "safety."

The Answer Era

The asymmetry is not only a government-versus-citizen problem. It is already playing out at the consumer level. Governments restrict access through regulation. Corporations restrict it through subscriptions. Both roads lead to the same place — you depend on them for AI instead of owning it yourself. Subscription AI creates dependency. Local AI creates capability. The same dynamic, at personal scale, happening right now.

Becoming the rented minds
CONSUMER

ChatGPT. Google Gemini. Microsoft Copilot. Claude. Meta AI. Perplexity. Grok. Mistral. DeepSeek. Amazon Q.

What do these have in common? They hand you instant answers and keep you coming back for more. You don't learn. You don't build. You consume. And the more you consume, the more dependent you become.

That's not intelligence — that's a subscription to dependence.

We're living in the “Answer Era.” Doesn't matter the question — there's an instant answer for it. Doesn't even have to be correct. Just instant. And somehow, technology designed to make people 10x smarter has made many 10x dumber.

Becoming the smartest minds
BUILDER

Ollama. Hugging Face. LM Studio.

What do these have in common? You run them locally. You control them. You actually learn how the models work, what they do, and how to fix them when they break.

No black box. No dependency. No monthly bill for someone else's answers.

One group makes you a consumer. The other makes you a builder.

The Divide
One feeds you fish. The other hands you the rod and says figure it out.

We designed AI to amplify humans — not replace them. But if you never touch the tools yourself, you're not being amplified. You're being managed.

Stop renting someone else's brain. Build your own.

This is the asymmetry before it reaches the policy level. The dependency is already being built. The mechanisms documented in the other four tracks — coalitions, compliance, infrastructure framing, threat narratives — are about locking in a world where the consumer side of this divide is the only side most people ever see.

What we are tracking

1. Compute infrastructure spending (classified + commercial)
WATCHING

Track public and classified compute spending by the US government and major corporations. The CHIPS Act, DOE supercomputing budgets, DOD AI initiatives, and intelligence community compute contracts all indicate the scale of government AI infrastructure.

The asymmetry is not just about models — it is about compute. A citizen running a 70B parameter model on consumer hardware is competing against government clusters running trillion-parameter models on dedicated infrastructure.

Data collection in progress.

2. Publicly known classified AI programs
WATCHING

Document what is publicly known about classified AI programs: Project Maven, NRO AI initiatives, CIA venture investments in AI, DOD AI task forces. The public record is incomplete by definition, but the budget lines and contract awards are traceable.

The pattern to watch: capabilities that are publicly denied but privately developed. The gap between what officials say AI "cannot do yet" and what classified programs are already doing.

3. Model capability gaps between consumer and enterprise/government
WATCHING

Track the capability gap between the best publicly available models and the best enterprise or government models. The gap is not always visible — companies like OpenAI and Anthropic have confirmed they withhold their most capable models from public release "for safety reasons."

The framing is always "safety." The effect is always capability restriction. The question is whether the withheld capabilities are dangerous, or simply powerful — and whether the same capabilities are available to government and enterprise customers through private APIs.

4. Regulatory timing — consumer access locked after breakthroughs
WATCHING

Watch for a pattern: a significant AI capability breakthrough becomes publicly available, followed shortly by regulatory proposals to restrict consumer access to similar capabilities. The timing matters. If restrictions consistently follow citizen access to powerful AI — but not government or corporate access — the regulatory intent is asymmetry preservation, not safety.

This is the hardest pattern to document because it requires tracking regulatory proposals against capability releases in real time. But it is the most damning if established.

How the gap is maintained

The asymmetry is maintained through four interlocking mechanisms — each documented in the other tracks.

The four mechanisms of asymmetry
PATTERN

1. Coalition gatekeeping (Track 01): Industry alliances like OSAA define what "secure" AI means. The definition assumes enterprise infrastructure. Citizens and small operators are not at the table.

2. Compliance pricing (Track 02): Voluntary frameworks like SAFE become de facto requirements. Compliance costs are fixed — they do not scale down for small operators. A 30-day public disclosure process costs the same whether you are NVIDIA or a one-person shop.

3. Infrastructure framing (Track 03): Cloud AI is "safe." Local AI is "risk." The framing makes local-first deployments non-compliant by definition, even when they are technically more secure.

4. Threat narrative (Track 04): Incidents are amplified to justify restrictions on citizen AI access. The restrictions do not apply to government or enterprise AI — only to the public. "Safety" means keeping AI out of citizen hands, not out of government hands.

What we are seeing so far

OpenAI and Anthropic withhold models "for safety"
EVIDENCE

Both OpenAI and Anthropic have publicly confirmed they withhold their most capable models from public release, citing safety concerns. The same companies provide advanced model access to government agencies and enterprise customers through private contracts and APIs.

The framing is "safety." The effect is a two-tier system: government and enterprise get the most capable AI, citizens get a restricted version. The asymmetry is built into the product offering.

SOURCES: OpenAI model card disclosures; Anthropic public statements; Dario Amodei interviews
Anthropic lobbying for mandatory third-party testing
EVIDENCE

Anthropic is actively lobbying for mandatory third-party testing for frontier AI models, with government authority to block deployment. This would create a regulatory barrier that only well-resourced companies can cross. Small developers and open-weight model providers would need to fund third-party testing or face deployment blocks.

The asymmetry: Anthropic can afford the testing. A local-first operator cannot. The "safety" framing benefits the companies with the resources to comply.

SOURCES: Anthropic policy positions; Dario Amodei public statements
EO 14409 rejects mandatory licensing — for now
EVIDENCE

Executive Order 14409 expressly rejects mandatory model licensing or preclearance. This is currently favorable to citizen AI access. But the EO establishes a voluntary clearinghouse — the infrastructure for future mandatory requirements. The rejection of mandates is the current state, not the end state.

Watch for amendments, follow-on executive orders, or legislation that transitions the voluntary framework to mandatory. The path from voluntary to mandatory is the compliance trap (Track 02) applied at the regulatory level.

SOURCES: Executive Order 14409 (June 2, 2026); Cloud Security Alliance analysis

The career insight

Hypothesis — The Same Playbook
Projects are kept secret not just for protection but to avoid mass panic. The same playbook is now being applied to AI: capabilities are classified or restricted, the public narrative emphasizes danger, and access is narrowed under the framing of safety. The gap between what is publicly known and what actually exists is the asymmetry. The mechanisms being built today — alliances, standards, certifications, compliance frameworks — are the infrastructure for maintaining that gap.

Hypothesis — based on career experience in classified projects. The pattern needs further documentation through publicly available evidence on classified AI programs.

The small-operator gap, confirmed by someone outside this investigation

EVIDENCE

SAFE RFC Issue #22: No line for the single-person operator

On August 23, 2026, a contributor outside this investigation filed SAFE RFC Issue #22. The issue identifies a population the RFC does not address: a single-person operator holding the signing key with no SOC. The Reporting Compact and Evidence Preservation both read as written for an organization with a security team. The contributor proposes a portable, verifiable attestation the agent carries, so an individual operator can produce evidence at the point of interaction instead of through a submission process built for organizational members.

This is the most direct external confirmation of the asymmetry this investigation has been tracking. The gap is not theoretical. It is visible to people who found it independently, from a different angle, in a different context. They reached the same conclusion: the framework assumes an organization. A person running Ollama on a server in their office is not an organization.

The contributor discloses: I maintain an open-source operator-side enforcement and custody layer for AI agents. This is the vendor pattern documented across this investigation — a contributor identifies a gap, proposes a requirement that fills it, and happens to have a product that meets the requirement. The requirement becomes standard. The vendor product becomes the reference implementation. Small operators get a new obligation and a new vendor relationship. Large organizations get another checkbox.

Source: SAFE RFC Issue #22 (eriknewton)
Documented: August 23, 2026
Key Observation

When someone outside your investigation reaches the same conclusion from a different direction, that is not confirmation bias. That is independent verification. Issue #22 confirms what Track 05 has been saying: the framework is built for organizations with security teams. A single-person operator holding the signing key with no SOC is not at the table, not in the scope, and not in the plan. The gap is the policy.

Same tool, same actions, different rights to be observed

EVIDENCE

The Compliance API boundary: observability as a vendor-ecosystem privilege

On August 31, 2026, The Hacker News published a contributed analysis of Anthropic's new Claude Code Compliance API (endpoints live since August 11). The article documents a boundary that is the asymmetry in product form: "If you run Claude Code on a model that isn't Anthropic's, you get no Compliance API coverage at all... Sessions running on Bedrock, Foundry, or Google Cloud won't be covered."

An enterprise running Claude Code against Anthropic's models gets session transcripts, tool-use logs, MCP command visibility — a full governance surface. A solo developer running the identical tool against an open-weight model on their own hardware gets nothing. Not degraded coverage. Zero. The same actions, on the same endpoint, produce evidence for one class of user and no evidence for the other.

Under the frameworks now being specified — SAFE's Evidence Preservation, the chain-of-custody profiles in PRs #27/#28 — the ability to produce evidence is becoming the definition of legitimacy. An operator who cannot produce session evidence because their tooling doesn't generate it isn't just less visible. They are less compliant, by construction, through no choice of their own except the choice to run models they control.

The asymmetry is no longer only a standards problem. It is shipping as a product boundary: observable inside the vendor's cloud, invisible outside it, with compliance defined as the ability to be observed.

Documented: August 31, 2026