Don’t stop AI: Steer it.
The question in front of us is not whether to stop artificial intelligence. It is who gets to hold the steering wheel, and on whose behalf they are steering.
A voluntary moratorium on AI only binds the people willing to sign on. It does nothing to the laboratory that never signed, the state program that does not publish, or the operator running an open-weight model on hardware nobody inspects. The people most likely to decline are the ones building without guardrails in the first place.
If the systems that do the most damage are going to be built anyway, then the systems built with care have to be better, faster, and more widely available than the ones built without it.
This is not hypothetical
In September 2026, Anthropic published an account of misuse it had identified and disrupted between December 2025 and August 2026, across seven categories: cyber operations, surveillance operations, influence operations, conventional weapons, biological misuse, scams and fraud, and illicit distillation. Its summary of what followed each case is one sentence long: “In each case, we disrupted the activity involved, strengthened our AI safeguards based on what we learned, and shared intelligence with authorities and industry partners where appropriate.”
Read that as a policy document rather than a news item. It tells us four things at once. Serious misuse is being attempted now, by people with resources. Someone is watching that data flow. Some of it is being caught. And it is being caught because somebody built the instrument to catch it and chose to look.
That last part is the whole argument. The safety came from design, not from delay.
What steering actually requires
It requires a steering committee, and not the one you are picturing.
When I served as an Assistant Solicitor in Montgomery County, Pennsylvania, I formed the county’s AI committee. I did not build it out of technologists. I built it from a cross-section of the county itself: community members, business people, students, and the people who would have to live with whatever we decided. That was deliberate, and it is the reason the work held up.
Scale that design. Every state should have one, composed the same way — not a panel of vendors and agency counsel, but a genuine cross-section of the people the technology is used on. The principle is simple enough: a standard written only by the people who build the system will always be a standard the system can meet.
Then there are three obligations, and each one can be written into law, procurement language, or a standard of care.
Containment by design. A system should behave safely in the environment it was not supposed to be in. Most of the current conversation assumes the sandbox holds. Engineering assumes the opposite: that the enclosure fails, the network is not the one you expected, the permissions are wider than intended. A system that behaves well only inside its cage is not safe; it is merely contained for now.
A declared purpose. Every model is optimized for something. A system tuned to hold attention and a system tuned to support a person’s judgment will behave differently on the same prompt, and only one of the two vendors has told you which they built. Undisclosed optimization is the absence of documented care. Declared design intent is evidence of it. That distinction is familiar ground in any negligence analysis, and it belongs in procurement.
Loyalty. This is the one nobody has written down, and it is the one that matters most to the person at the other end.
The conflict of interest nobody names
Ask a lawyer what happens when a powerful agent with access to everything about you also serves someone else’s interests. We have an answer, and it is centuries old. We call it a conflict of interest, and we prohibit it.
The professions that hold people’s secrets — law, medicine, accounting, trusteeship — are governed by undivided loyalty, a duty of confidentiality, and a rule against serving two masters. Not because practitioners are virtuous, but because the relationship does not function without those duties.
Jack Balkin proposed extending that logic to the platforms a decade ago, arguing that companies holding our information should be treated as information fiduciaries. The idea has been argued over ever since. What has not happened is the obvious next step: nobody built the machine.
Every AI system in an ordinary person’s life today belongs to someone else. It is hosted by a company with shareholders, trained on objectives the user cannot read, and improved by data the user supplies. The user is not the client. The user is the input.
What a person is actually owed
Consider what a system built with undivided loyalty to one person would do, given that people now live most of their practical lives online.
It would defend them against attacks rather than merely warn them afterward. It would watch their credit file and tell them the moment something opened in their name. It would verify that the machine in front of them is clean and that the code running on it is what it claims to be. It would keep track of the devices that quietly joined their household — the television, the doorbell, the thermostat, the refrigerator with a Bluetooth radio in it that nobody asked for and nobody patches. It would keep an eye on the house. It would call for help if help were needed, and it would know who to call.
Notice what is not on that list. It does not report the person to anyone. It does not sell what it learns. It does not build a profile to be monetized later.
That is the distinction the next decade turns on, and it is worth stating as plainly as possible:
A system can watch the world on your behalf, or it can watch you on someone else’s. It cannot do both.
Everything sold to consumers today does the second thing while using the language of the first. Protection is the marketing; the product is the profile.
The moral problem underneath
We are about to sort people into those who have a competent digital advocate and those who do not.
The wealthy already have one, assembled from human beings: an attorney, an accountant, a private security consultant, an IT professional on call. Everyone else gets a browser warning they do not understand and a breach notification that arrives eleven months late.
If this technology is what its builders say it is, it should close that gap rather than widen it. A person without money should have the same instrument as a person with it. That is not a technical constraint. It is a design decision, and it is being made right now, mostly by default and mostly in the wrong direction.
Agency is the point
Underneath the safety argument is a simpler one. A person should have something in their life that is unambiguously theirs — that answers to them, holds what they say in confidence, and has no second party to please.
Not a service. Not a subscription that reads what it processes. An instrument, owned by the user, working for the user, incapable by construction of divided loyalty.
We are not there yet. The systems most people use are conflicted by design, and no amount of policy language repairs a conflict that the architecture creates. But the path is not a mystery and it is not a matter of waiting for a breakthrough. It is a matter of deciding who the system is for, and then building it that way.
Stopping is not on the menu, and it never was. Steering is.
Sources
Anthropic, Detecting and Countering Misuse of AI: September 2026 (September 2026). https://www.anthropic.com/threat-intelligence-report-september-2026
Jack M. Balkin, Information Fiduciaries and the First Amendment, 49 U.C. Davis Law Review 1183 (2016).