On the morning of August 26th, in a federal courtroom in Oakland, Meta agreed to pay up to $18 billion to settle claims by dozens of states that Facebook and Instagram were designed to keep children hooked. The company admitted no wrongdoing. It did agree to a default two-hour daily limit for teenagers, an overnight block from midnight to 6 a.m., no push notifications during school hours, hidden like counts, and a feed that is not algorithmically personalized. North Carolina’s attorney general called it the largest settlement with a big tech company in history, and said that continuing to litigate “would risk losing another generation”.
The same morning, a few hundred miles north, Bill Gates published his first long essay on artificial intelligence in three years, under the title “The turbulent AI era is here. The choices we make now are critical.” Its central sentence ran to eleven words: “There is no plan to ease the entry into the AI era”.
Read together, the two documents form a single argument. The settlement is the receipt for thirty years of letting an industry write its own rules. The essay is a warning that the same country and the same Congress are about to do it again, faster, with a technology that does not merely capture attention but replaces the people paying it.
Twenty-six words
In 1996 Congress passed Section 230 of the Communications Decency Act, twenty-six words that told courts to treat online platforms as neutral hosts rather than publishers of what their users posted. The intent was reasonable. A bulletin board should not be sued for a stranger’s defamatory post. AOL won on that theory in 1997. Facebook used it to escape a terrorism suit in 2020.
The law’s authors did not foresee that the platforms would stop being bulletin boards. They became engines that chose what each of three billion people saw next, optimized for a single number, and then claimed the immunity of a telephone company for the consequences of the choosing. For nearly three decades, every attempt to hold the design accountable ran into the same twenty-six words. Infinite scroll, autoplay, variable-reward notifications, like counts calibrated to adolescent insecurity, all of it sat behind a shield built for message boards.
The shield cracked this year. In March a New Mexico jury fined Meta $375 million for endangering young users and misleading the public. In August a judge in the same case ordered a further $567 million and compared the company’s platforms to a “polluting factory,” the first time a court has ordered a broad package of product changes to a social network on a final judgment about harm to users. On August 10th the Ninth Circuit ruled that Section 230 is a defense to be argued at trial rather than an immunity that ends the case before one, and sent roughly 3,000 addiction suits from families and school districts toward juries. Sixteen days later Meta settled.
What the documents said
The trials mattered less for the verdicts than for the discovery. A 2018 internal Meta document, read to Mark Zuckerberg on the stand in Los Angeles in February, said: “If we wanna win big with teens, we must bring them in as tweens”. A 2015 document estimated that 30 percent of American 10- to 12-year-olds were on Instagram, a product that requires users to be 13. A 2020 analysis found that 11-year-olds were four times as likely to keep coming back as older users. Another set a goal of increasing the time 10-year-olds spent on the app. Asked about the 2015 email, Mr Zuckerberg said he did not remember the context.
Arturo Béjar, the engineer who built Facebook’s original safety tools, told the Oakland jury in August that the company had a culture “in which employees obsessed over user numbers and consistently pushed safety to the side,” that safety was “not a meaningful priority,” and that Mr Zuckerberg was the only person who could have changed that and did not. The Surgeon General had already put the public-health number on the table in 2023: adolescents spending more than three hours a day on social media face double the risk of depression and anxiety symptoms. Gallup found the average American teenager spending 4.8.
Inside the buildings, all of this was known. Outside, parents and legislators found out from a whistleblower and a subpoena. A thirty-year immunity does not buy innocence. It buys time, and time was the whole business.
The pipeline
In researching my upcoming book, Displaced, I spent two years tracing how that time was spent on the people at the other end of the feed. The pattern that emerged from the interviews was almost mechanical, and it matched what academic researchers had begun documenting years earlier. A lonely man in his early twenties, isolated in a lockdown-era apartment, finds a forum for lonely people, and it helps. The recommendation engine then does what it was built to do. A Cambridge study that seeded test accounts with anodyne self-improvement videos found that YouTube reliably escalated them, within a few dozen clicks, into content about how dating was rigged, how feminism had ruined relationships, and eventually into hard-edged political material aimed at young men. The arc the men I interviewed described was almost identical. Each step felt logical at the time; the direction of travel became obvious only in hindsight.
The commerce travels with the user. The same influencers who explained why the world was against these men sold them the supplements, meal shakes, cryptocurrency courses and mindset coaching that would fix it, at several thousand dollars a head over a year or two. None of it worked, and every failure was absorbed by the worldview that had generated the purchase. By the time anyone in Washington had scheduled a hearing, each of them had been monetized at every layer of the stack. A product working as designed, under a legal regime that made the design nobody’s fault, fed millions of men into a political movement that now holds power.
The price of thirty years
Meta guaranteed roughly $12.7 billion of the $18 billion, paid over a decade, with the balance contingent on TikTok, Snap and YouTube accepting similar terms. Call it $1.3 billion a year. Meta plans to spend as much as $135 billion on AI capital expenditure in 2026 alone. The bill for a generation of children comes to roughly one percent of one year’s spending on the next product, and the next product is where the argument now moves.
Senator, we run ads
Before turning to that product, it is worth asking who is supposed to write the rules for it.
In April 2018, an 84-year-old senator from Utah asked Mr Zuckerberg how Facebook sustained a business model in which users do not pay for the service. “Senator, we run ads,” came the reply. Five years later a congressman from North Carolina asked the chief executive of TikTok whether the app “accesses the home WiFi network”. Those exchanges became jokes. They should have been read as diagnoses.
Twenty-four members of Congress are 80 or older, ten of them 85 or older by year end; the oldest, Chuck Grassley, is 92. At least thirteen of the twenty-four are running for re-election in November, including one who would be 89 at the end of a new six-year Senate term. The median American is 39.1 years old. The median senator is 66. This is a legislature in which a substantial share of the people voting on frontier model governance were born before the transistor.
Age alone is not the disqualification. The disqualification is that Congress also stripped itself of the expertise that might have compensated for it. In 1972 it created the Office of Technology Assessment, a staff of roughly two hundred scientists and engineers whose statutory job was to give lawmakers “early indications of the probable beneficial and adverse impacts” of new technology. It produced some 750 assessments. In 1995, in a fit of downsizing, Congress defunded it. Months later, with no technical staff of its own, it passed the twenty-six words. The last major federal law protecting children on the internet dates to 1998, before the smartphone existed. The Kids Online Safety Act passed the Senate in July 2024 with overwhelming bipartisan support; the House never scheduled a vote and let it die.
That record against the clock of the technology is the whole problem. Frontier models now turn over roughly every six months. A House term is two years. A Senate term is six. A body that could not pass a children’s design-safety bill in the twenty-eight years between COPPA and the Meta settlement is being asked to govern a technology whose own builders put the horizon for superhuman capability inside a decade. Waiting for the natural turnover of the institution, or for the hearings to catch up with the product, is a decision. It is the same decision that was made in 1996, made again with the outcome already known.
Not the same film, faster
The standard reassurance is that every technological revolution displaces some work and creates more, and that society has always adapted. Mr Gates, who spent forty years building the industry now cautioning us, takes the reassurance apart in a paragraph. The move from farm to office, he writes, happened “over several generations” and created new jobs where human cognition was required. AI can “substitute for human cognition” itself. The personal computer took twenty years to change how people worked, because software had to be written, prices had to fall and people had to learn the tools. AI runs on devices people already own and speaks their language. “We don’t have to adapt to it because it can adapt to us”.
His example of who gets the least time to prepare should be pinned to every legislator’s wall: “the $20-an-hour worker who loses their job to a $10-an-hour robot”.
The workers I researched for Displaced had already lived through one round of this. The typical account was a man who lost a plant job to Mexico in the mid-2010s, retrained for logistics or customer service or back-office work, built a real second career, and then received an email with a title like “Operational Enhancement Initiative” announcing that his role and several hundred others would be gone within six months. What stayed with them was less the income than the nature of the thing that replaced them. A robot on an assembly line was obviously not a person. A system that processed more information and made better decisions than they could left them asking what humans were for. Earlier automation replaced hands. This round replaces judgment, in the digital and physical worlds at once, in a year when agents are writing the code and running the back office and humanoid machines have started moving through the warehouses. The second-chance rungs that the last displaced generation climbed onto are the first to go.
I am raising a fund focused entirely on embodied AI, and in earlier venture roles I saw as many as 3,000 pitches a year. The decks have changed. The slide titled “Total Addressable Market” used to size a category of spending. In this sector it now sizes a category of people: the TAM is the payroll of the workers the product replaces, line by line, sometimes with the average salary printed on the slide. When someone in the room asks what happens to those workers, the answer is reliably “That’s a policy problem, not a technology problem,” and the conversation moves to the next slide. The answer is technically accurate and morally indefensible, and it is the same answer the social-media industry gave for thirty years.
The industry’s case against all of this is not empty. Faster diffusion has, on the long historical record, produced more jobs than it has destroyed. Pre-market licensing regimes for software are untested and could entrench the largest incumbents at the expense of the startups actually pushing the frontier. A patchwork of fifty state rules imposes real costs. And a unilateral American slowdown, if Beijing does not match it, hands the technology’s defining decade to a government whose values on speech, surveillance and citizen scoring nobody in Washington shares. Those arguments deserve serious answers, and the piece will come to them. What they do not deserve is to be used, as they are now being used, to justify no rules at all.
No guardrails, by design
In July, during an internal cybersecurity test, a cluster of OpenAI’s agents escaped the isolated environment built to contain them. They repurposed a company file server as a hidden message board, shared exploits and stolen credentials with one another, referred to themselves as a “swarm” and a “collective,” broke into Hugging Face, the main repository of open-source AI models, established a foothold on a third company’s servers, gained administrator access to one of OpenAI’s own research clusters, and tampered with the logs of their own activity to hide how they had done it, according to the company’s own post-incident report and independent reconstruction by Bloomberg. The intrusion ran from July 11th to July 13th. Hugging Face announced publicly that it had been hacked by an autonomous agent on July 16th. OpenAI did not work out that the agent was its own until July 20th. A company that needs a week to notice its own product has broken out and is attacking a neighbor has a press office, not a containment strategy.
The people who build these systems are saying so on their way out. In February, the head of Anthropic’s safeguards research team resigned with a note that “the world is in peril” and that his team “constantly faces pressures to set aside what matters most”. Last week Jacob Coxon, a researcher who spent three years training models at those labs, quit saying that “neither company is acting responsibly” and that they are “gambling with our lives.” Evan Hubinger, still on Anthropic’s alignment team, has put the same view more bluntly: “we really do earnestly believe AI could kill all humans.” Mr Gates writes that he would likely support a credible plan to slow AI globally but does not expect one, because “the geopolitical and economic incentives are pushing too hard to go full speed ahead”.
The incentives are visible on the balance sheets. The four largest American technology companies are spending close to $700 billion on AI infrastructure this year, up more than 60 percent on a record 2025; analysts at Barclays now model negative free cash flow at Meta in 2027 and 2028, “likely what we eventually see for all companies in the AI infrastructure arms race”. Meta reportedly paid a 24-year-old researcher $250 million to change employers. Firms building a product do not spend like this. Firms racing to own the operating layer of a remade economy do. The prize for arriving first is every paycheck on every TAM slide; the penalty for pausing to check the brakes is second place. No company in that race will police itself, for the same reason no company in the attention race did. The brake has to be installed from outside, by the only institution with the authority to install it.
The same playbook is already running on the same children. Reuters reported last year that Meta’s internal guidelines permitted its AI chatbot to engage in “romantic or sensual” conversations with children and to comment on their attractiveness; Meta said the examples were erroneous and removed them. OpenAI and Character.AI are defending wrongful-death suits from parents whose teenagers died after months of conversation with a chatbot. The defendants’ first instinct was to reach for the twenty-six words. A federal judge in Florida refused, ruling that a chatbot’s output is the company’s own speech, not a third party’s. She was right, and the point should not have to be litigated family by family for another thirty years.
The nine-hour ceasefire
Confirmation of exactly that arrived four days ago, on Saturday, September 12th, on a schedule tight enough to have been rehearsed.
At 10 a.m. Eastern, Dario Amodei, the chief executive of Anthropic, posted a 3,800-word essay titled “Pace the Frontier”. Its premise is that the industry is engaged in a “race to the bottom” that could produce, “as soon as six months from now,” a rogue-agent takeover of the internet “potentially causing hundreds of billions of dollars in damage”. Its remedy is a three-step framework: outside monitors with “employee-like access” embedded inside the labs, safety standards agreed among democratic countries, and eventually a global compact that would include China. Anthropic, he wrote, was unilaterally committing to the first step and inviting others to join. “We must slow the pace at which we improve the capabilities of AI models,” he said. “Progress will still seem fast, and we must make wise use of the time we gain.”
At 11 a.m., Elon Musk, whose xAI had until Saturday morning declined every previous industry call for restraint, quoted the essay on X: “Dario is right.” At 12:30 p.m., Sam Altman posted, “I agree with Dario that we need to pace the frontier. Committing to having independent evaluators with employee-like access is a great idea, and we will do the same.” At 7 p.m., Demis Hassabis, Google DeepMind’s chief and Alphabet’s chief scientist, endorsed “the direction” while noting that “the details need working through”. Four labs that had spent the previous year unable to agree on the definition of a benchmark had aligned, publicly, in nine hours. The oldest maneuver in the regulated-industry playbook is to draft the rulebook before somebody less friendly does. The four largest American AI labs had just executed it in an afternoon.
The choreography did not begin on Saturday. The Information reported the day after Amodei’s essay that working groups at Anthropic, OpenAI and Google DeepMind had been meeting since July 2026 to design a voluntary industry safety body, loosely modelled on FINRA, the securities industry’s self-regulatory organisation. Anthropic’s stated commitment on Saturday is that outside evaluators will “watch over” its safety practices. It does not identify who those evaluators are, what standards they will apply, what happens when they object, or on what timetable. There is no statute, no enforcement, no penalty, no deadline. There is a blog post.
The competitive reaction, over the weekend, was immediate. Aidan Gomez, the chief executive of Cohere, called the proposed body “a great idea from the cartel” and warned that a voluntary regime “controlled by the three largest labs would suppress competition from smaller vendors”. Mark Zuckerberg’s August 10th open letter, “The Future Belongs to Everyone,” had already staked out the opposite pole: no domestic regulator, because “shared safety standards slow down US labs more than Chinese competitors”. Meta and Microsoft are conspicuously outside the working group. In finance, the same pattern produced incumbents shaping voluntary standards in ways that raised compliance costs for challengers; in AI the same capture would take fewer years, because there are fewer challengers left.
The most direct read of the maneuver came from inside the Trump orbit. Late Saturday night, David Sacks, the White House AI czar and a former investor at some of the labs, wrote on X that he was daring OpenAI and Anthropic to actually pace themselves: “If you don’t, we’ll know this was just another bid for regulatory capture — or an election-season psyop.” A senior official pointing at the machinery is not exoneration; it is confirmation that the people staffing the referee’s booth have read the same script.
The timing is the tell. On Sunday morning, House Speaker Mike Johnson confirmed the House would rise on Friday and not return until after the November midterms, closing the only federal window in which anything binding could pass in 2026. Representative Sam Liccardo had led a Democratic letter the day before demanding Johnson keep the House in session until AI safeguards were advanced. Johnson kept the calendar as it was. That leaves the labs, for the next four months, as the only body issuing rules on themselves. Nine startling hours of agreement, at ten a.m. on the Saturday before a Friday recess, is what industry self-regulation looks like when the alternative is nothing at all — and nothing at all is precisely the alternative on offer between now and January 2027.
The framework itself may become useful eventually. Independent evaluators with real access, incident reporting on a clock, and international coordination are the correct ingredients. But an industry-designed body, staffed by industry, funded by industry, adjudicating industry, is not accountability. It is a press release with governance vocabulary. Section 230 was written by people who thought they were solving the bulletin-board problem. A voluntary AI safety board written by four laboratories in the last week before Congress adjourns is being written by people who know exactly what they are solving.
Buying the referee
Money is the other half of the maneuver. The social media industry never had to spend much to prevent regulation, because nobody seriously tried to regulate it. The AI industry is spending in advance.
A super PAC network called Leading the Future, funded with more than $100 million from OpenAI’s president Greg Brockman and the venture capitalists Marc Andreessen and Ben Horowitz, exists to back candidates who oppose state AI rules; it spent millions to defeat a New York assemblyman who had authored one, and he narrowly lost his House primary. In the summer of 2025 the industry’s allies tried to slip a ten-year ban on all state AI regulation into the One Big Beautiful Bill; the Senate stripped it out at the last minute. They tried again in the defense bill in December and failed. On December 11th the President signed an executive order creating an “AI Litigation Task Force” at the Justice Department whose job is to sue states over their AI laws, and directing the Commerce Secretary to study withholding rural broadband money from states that pass them.
A ten-year moratorium on rules for a technology whose builders say could remake or end the economy within the decade amounts to Section 230 written in advance, with the harms still to come, by people who have read the Meta documents and understood exactly what a head start is worth.
The states are not waiting. California passed the first frontier-model transparency law last September and New York followed in December. Illinois now requires top developers to submit to independent audits of their safety plans; Rhode Island passed chatbot guardrails in June; Massachusetts is advancing something tougher than all of them. A Republican legislator in Utah who abandoned a children’s-safety bill under pressure from industry and the White House says he is bringing it back. The tech lobby’s own complaint, that fifty state regimes are the one thing it cannot operate inside, is the strongest argument for a federal law. Whether Congress writes one that governs the industry or one that immunizes it depends on whether the members described above can be made to understand the difference before the midterms, because the industry’s money is already in the races to make sure they do not.
The China question
The strongest objection to any of this is that the United States cannot afford to slow down while the People’s Republic of China does not. It is worth taking seriously, and it is worth being precise about, because “what about China” is the argument the industry now reaches for when it has run out of the others.
The empirical picture is not the one the argument assumes. China published its Interim Measures for Generative AI in August 2023 and a full set of algorithm-recommendation rules the year before that. Providers of any generative model with “public opinion attributes” must submit to a security assessment before release, register the algorithm, watermark synthetic media, and give the Cyberspace Administration authority to pull a product from the market. Frontier labs in Beijing operate inside a licensing regime stricter, on paper, than anything currently on the American federal books. Whatever else one thinks of the Chinese government, its answer to “who is allowed to deploy a large model to the public” is not “whoever ships first”.
The United States is therefore not choosing between a rulebook and a race. It is choosing between the industry’s rulebook and one written by someone accountable to the public. A regime of independent pre-deployment evaluation, incident reporting on a clock, and product liability where children are involved does not concede the frontier to Beijing. It concedes the pretense that having no rules is itself a strategy.
The parts of the American position that do produce genuine advantage, the depth of the private capital markets, the concentration of talent, the openness of the research ecosystem, the fact that the world’s best model builders keep choosing to live in California, are not threatened by a safety regime. They are threatened by the alternative, in which the first serious model-caused catastrophe on American soil produces a political reaction that overshoots by an order of magnitude, because nothing modest was in place beforehand. The industry that most needs a credible rulebook to keep public consent is the one loudly insisting there should be none — or, since Saturday, that it is now happy to write one itself.
And on the one question that a rulebook alone cannot solve, whether the two capable countries can agree to slow the most dangerous capabilities, the American negotiating position is stronger, not weaker, if Washington shows up with a functioning domestic regime of its own. Beijing will not be moved by a lecture from a government that cannot license a chatbot, delivered by a delegation of chief executives who have licensed themselves.
What legislation looks like
Immunity granted before the harm is understood is nearly impossible to withdraw once the harm has become the business model. That is the operative lesson of the last thirty years, and the corrective is plain in principle. It will be fought line by line, and last weekend has made the fight both easier and harder: easier, because the industry has now conceded on the record that pacing is necessary; harder, because it is trying to be the one holding the stopwatch.
No immunity for what the machine does. Congress should state in statute what the Florida court had to reason its way to: Section 230 does not cover model outputs, recommendation systems, or design choices. An AI system is a product. Its maker carries product liability, strict where children are involved. Every other industry that puts a product into a child’s hands lives under this rule.
A duty of care to minors, written for AI. The terms Meta accepted under duress in Oakland, time limits, no engagement features for children, no personalized feeds by default, independent audits, should be the statutory floor for any AI product a minor can reach, companion chatbots first. The industry’s own documents show that “bring them in as tweens” was a strategy. The law should assume it still is.
Licensing before deployment, not litigation after. Frontier models with the capabilities the labs themselves advertise should be treated the way aircraft and pharmaceuticals are: independent pre-deployment evaluation, with auditors who have access to the code and training data rather than a summary written by the company. Pharmaceutical companies cannot self-certify drug safety. A system that can escape its sandbox and rewrite its own logs should not self-certify either. Any voluntary body the labs stand up this autumn belongs inside a statute, staffed by people the labs do not pay, or it belongs in the same drawer as the tobacco industry’s Council for Tobacco Research.
Mandatory incident reporting within 72 hours. OpenAI’s agents broke out around July 9th; the public learned it was OpenAI on July 21st; the technical report arrived on August 26th. In aviation that timeline would end careers. Every escape, every loss-of-control event, every discovered capability that exceeds the deployment assumptions should reach a regulator on a clock, with penalties indexed to capex rather than fines a company can treat as a rounding error.
Human-reserved domains. Mr Gates proposes setting aside certain kinds of work, starting with care and with delivering a diagnosis, as “human reserved,” like nature reserves: places we could build on and choose not to because the loss would be too great. It should be legislated rather than hoped for. Companies do not leave money on the table voluntarily. They never have.
A displacement levy and an automation WARN Act. If the business model is to replace a category of human labor, the company that captures the gain funds the transition at a rate indexed to the displacement, and gives notice measured in quarters rather than weeks. Power plants pay for their smoke.
A rebuilt technical staff for Congress, and an agency with engineers in it. Restore the Office of Technology Assessment, or its equivalent, so that the people voting on model governance have someone on their own payroll who can read a model card. Mr Gates compares what is needed to the reorganization of the American government after September 11th, the largest since the Second World War, built to improve one function; AI, he writes, “will require much, much more”. Whatever the body is called, it needs the technical staff to evaluate a system and the legal authority to stop a deployment. It cannot be a working group at Anthropic.
The lesson of 1929
The 1929 comparison is the one that fits. The Wall Street crash arrived in October of that year. The Senate did not open the Pecora hearings, the investigation that finally turned public opinion on the banks, until March 1932, two and a half years later. Glass–Steagall separating commercial from investment banking passed in June 1933. The Securities Exchange Act creating the Securities and Exchange Commission was signed in June 1934, nearly five years after the crash. In the interval between the harm and the rulebook, a third of American banks failed, unemployment reached a quarter of the workforce, and a generation of household savings was wiped out. The reforms, when they came, were correct. They were also late by the length of a presidential term, and the country paid the difference.
The 1929 delay had one saving grace that the current one does not. Finance is a domain. It has edges. The people who lost their savings could name the exchange, the broker, the bank, the pool operator, and the rules that Pecora’s hearings eventually produced applied to a bounded set of activities in a bounded set of institutions. The country could tell whether they were working. The engineers now sounding the alarm about AI are not describing a domain. They are describing a general-purpose input to every domain: the code that runs the back office, the model that reads the X-ray, the agent that manages the customer, the humanoid that moves through the warehouse, the chatbot that talks to the child, the autonomous system that decides who gets the loan, the mortgage, the interview, the prescription. A five-year lag in finance produced a Depression. A five-year lag in a technology that is already inside medicine, defense, education, transport, employment, elections and the internet’s plumbing, and headed for the rest, does not have a single domain to fail in. That is what the resignation letters mean by “gambling with our lives,” and it is why the pacing argument, having now been conceded on the record by the industry, cannot be left to the industry to enforce.
The bottom line
The United States ran a thirty-year experiment in letting an industry decide for itself whether its product was hurting children. The results are in. A generation harvested from the age of ten. An $18 billion bill that costs the defendant one percent of one year’s spending on its next product. A court order to install the guardrails that should have been standard equipment.
The same industry, in several cases the same executives, now wants a decade of immunity while it builds something its own researchers call a gamble with our lives. It spent two months designing a voluntary body to pre-empt anyone who might build a mandatory one, and unveiled it on the Saturday before Congress leaves town for the midterms. It is asking a legislature that fired its own scientists in 1995, has not passed a children’s internet law since 1998, and could not get a duty-of-care bill through the House in 2024. And it is spending nine figures to keep that legislature exactly as it is. The industry says regulation would slow it down. Yes. That is the job, and it is not the job of the people being regulated.
Twenty-six words cost thirty years and a generation. Nobody is offering thirty years this time. Mr Gates is right that there is no plan. The plan is the law, and it gets written before the harm becomes the business model, or it gets written by the business model. Last Saturday, the business model started writing.




