The gap between what citizens have and what governments and corporations have. Track compute infrastructure spending, classified AI programs, model capability gaps, and regulatory timing. If citizens have GLM-5.2, the government has something significantly more advanced.
The asymmetry between citizen AI and government or corporate AI is not an accident. It is a policy outcome. Every restriction on citizen access to AI models, every compliance requirement that prices out small operators, every certification that excludes local deployments — these widen the gap. The gap is the goal. The mechanisms documented in the other four tracks all serve this one: ensuring that the most powerful AI is available only to those who already have the most power.
The asymmetry is not only a government-versus-citizen problem. It is already playing out at the consumer level. Governments restrict access through regulation. Corporations restrict it through subscriptions. Both roads lead to the same place — you depend on them for AI instead of owning it yourself. Subscription AI creates dependency. Local AI creates capability. The same dynamic, at personal scale, happening right now.
ChatGPT. Google Gemini. Microsoft Copilot. Claude. Meta AI. Perplexity. Grok. Mistral. DeepSeek. Amazon Q.
What do these have in common? They hand you instant answers and keep you coming back for more. You don't learn. You don't build. You consume. And the more you consume, the more dependent you become.
That's not intelligence — that's a subscription to dependence.
We're living in the “Answer Era.” Doesn't matter the question — there's an instant answer for it. Doesn't even have to be correct. Just instant. And somehow, technology designed to make people 10x smarter has made many 10x dumber.
Ollama. Hugging Face. LM Studio.
What do these have in common? You run them locally. You control them. You actually learn how the models work, what they do, and how to fix them when they break.
No black box. No dependency. No monthly bill for someone else's answers.
One group makes you a consumer. The other makes you a builder.
This is the asymmetry before it reaches the policy level. The dependency is already being built. The mechanisms documented in the other four tracks — coalitions, compliance, infrastructure framing, threat narratives — are about locking in a world where the consumer side of this divide is the only side most people ever see.
Track public and classified compute spending by the US government and major corporations. The CHIPS Act, DOE supercomputing budgets, DOD AI initiatives, and intelligence community compute contracts all indicate the scale of government AI infrastructure.
The asymmetry is not just about models — it is about compute. A citizen running a 70B parameter model on consumer hardware is competing against government clusters running trillion-parameter models on dedicated infrastructure.
Data collection in progress.
Document what is publicly known about classified AI programs: Project Maven, NRO AI initiatives, CIA venture investments in AI, DOD AI task forces. The public record is incomplete by definition, but the budget lines and contract awards are traceable.
The pattern to watch: capabilities that are publicly denied but privately developed. The gap between what officials say AI "cannot do yet" and what classified programs are already doing.
Track the capability gap between the best publicly available models and the best enterprise or government models. The gap is not always visible — companies like OpenAI and Anthropic have confirmed they withhold their most capable models from public release "for safety reasons."
The framing is always "safety." The effect is always capability restriction. The question is whether the withheld capabilities are dangerous, or simply powerful — and whether the same capabilities are available to government and enterprise customers through private APIs.
Watch for a pattern: a significant AI capability breakthrough becomes publicly available, followed shortly by regulatory proposals to restrict consumer access to similar capabilities. The timing matters. If restrictions consistently follow citizen access to powerful AI — but not government or corporate access — the regulatory intent is asymmetry preservation, not safety.
This is the hardest pattern to document because it requires tracking regulatory proposals against capability releases in real time. But it is the most damning if established.
The asymmetry is maintained through four interlocking mechanisms — each documented in the other tracks.
1. Coalition gatekeeping (Track 01): Industry alliances like OSAA define what "secure" AI means. The definition assumes enterprise infrastructure. Citizens and small operators are not at the table.
2. Compliance pricing (Track 02): Voluntary frameworks like SAFE become de facto requirements. Compliance costs are fixed — they do not scale down for small operators. A 30-day public disclosure process costs the same whether you are NVIDIA or a one-person shop.
3. Infrastructure framing (Track 03): Cloud AI is "safe." Local AI is "risk." The framing makes local-first deployments non-compliant by definition, even when they are technically more secure.
4. Threat narrative (Track 04): Incidents are amplified to justify restrictions on citizen AI access. The restrictions do not apply to government or enterprise AI — only to the public. "Safety" means keeping AI out of citizen hands, not out of government hands.
Both OpenAI and Anthropic have publicly confirmed they withhold their most capable models from public release, citing safety concerns. The same companies provide advanced model access to government agencies and enterprise customers through private contracts and APIs.
The framing is "safety." The effect is a two-tier system: government and enterprise get the most capable AI, citizens get a restricted version. The asymmetry is built into the product offering.
Anthropic is actively lobbying for mandatory third-party testing for frontier AI models, with government authority to block deployment. This would create a regulatory barrier that only well-resourced companies can cross. Small developers and open-weight model providers would need to fund third-party testing or face deployment blocks.
The asymmetry: Anthropic can afford the testing. A local-first operator cannot. The "safety" framing benefits the companies with the resources to comply.
Executive Order 14409 expressly rejects mandatory model licensing or preclearance. This is currently favorable to citizen AI access. But the EO establishes a voluntary clearinghouse — the infrastructure for future mandatory requirements. The rejection of mandates is the current state, not the end state.
Watch for amendments, follow-on executive orders, or legislation that transitions the voluntary framework to mandatory. The path from voluntary to mandatory is the compliance trap (Track 02) applied at the regulatory level.
On August 23, 2026, a contributor outside this investigation filed SAFE RFC Issue #22. The issue identifies a population the RFC does not address: a single-person operator holding the signing key with no SOC. The Reporting Compact and Evidence Preservation both read as written for an organization with a security team. The contributor proposes a portable, verifiable attestation the agent carries, so an individual operator can produce evidence at the point of interaction instead of through a submission process built for organizational members.
This is the most direct external confirmation of the asymmetry this investigation has been tracking. The gap is not theoretical. It is visible to people who found it independently, from a different angle, in a different context. They reached the same conclusion: the framework assumes an organization. A person running Ollama on a server in their office is not an organization.
The contributor discloses: I maintain an open-source operator-side enforcement and custody layer for AI agents. This is the vendor pattern documented across this investigation — a contributor identifies a gap, proposes a requirement that fills it, and happens to have a product that meets the requirement. The requirement becomes standard. The vendor product becomes the reference implementation. Small operators get a new obligation and a new vendor relationship. Large organizations get another checkbox.
When someone outside your investigation reaches the same conclusion from a different direction, that is not confirmation bias. That is independent verification. Issue #22 confirms what Track 05 has been saying: the framework is built for organizations with security teams. A single-person operator holding the signing key with no SOC is not at the table, not in the scope, and not in the plan. The gap is the policy.
On August 31, 2026, The Hacker News published a contributed analysis of Anthropic's new Claude Code Compliance API (endpoints live since August 11). The article documents a boundary that is the asymmetry in product form: "If you run Claude Code on a model that isn't Anthropic's, you get no Compliance API coverage at all... Sessions running on Bedrock, Foundry, or Google Cloud won't be covered."
An enterprise running Claude Code against Anthropic's models gets session transcripts, tool-use logs, MCP command visibility — a full governance surface. A solo developer running the identical tool against an open-weight model on their own hardware gets nothing. Not degraded coverage. Zero. The same actions, on the same endpoint, produce evidence for one class of user and no evidence for the other.
Under the frameworks now being specified — SAFE's Evidence Preservation, the chain-of-custody profiles in PRs #27/#28 — the ability to produce evidence is becoming the definition of legitimacy. An operator who cannot produce session evidence because their tooling doesn't generate it isn't just less visible. They are less compliant, by construction, through no choice of their own except the choice to run models they control.
The asymmetry is no longer only a standards problem. It is shipping as a product boundary: observable inside the vendor's cloud, invisible outside it, with compliance defined as the ability to be observed.