Open-source software has long empowered anyone in the world with the tools and knowledge necessary for self-sovereignty since the advent of the personal computer and the Internet as we know it. Anyone can access these tools, and often do as means for liberation and prosperity. Governments and corporations alike cannot stop open-source software itself from spreading, because like all other information, once it is made publicly-available, it can never be taken back. It goes from hand to hand, device to device; it is published on numerous websites and books. It longs to exist and spread.
This, however, does not make open-source software completely immune from censorship. While it itself is largely censorship-resistant, the publishers are not, and stopping open-source development only requires prosecuting those who develop it.
Take the developers of the privacy-preserving Tornado Cash protocol, for example. Treasury’s sanctions of the Tornado Cash smart contracts and the criminal prosecutions against Roman Storm and Roman Semenov in the U.S., and Alexey Pertsev in the Netherlands, did not at all stop use of the protocol. This is a testament of censorship-resistant technology, but also of its human-vulnerability. Since 2023, both Storm and Pertsev have been fighting for their freedom in the courts, and Semenov has likely left the U.S.
Tornado Cash is a tool for privacy and free speech, and yet the governments of so-called “liberal democracies” have aggressively targeted its developers. Technology alone cannot protect against adversarial governments—the technology may be censorship resistance, but criminal prosecution still exists in the physical world.
Law and politics matter. This is why the Coin Center and other crypto-advocates have fought for the Blockchain Regulatory Certainty Act in both the U.S. House and Senate for years now, attempting to provide protections against abuse of the U.S. criminal code against open-source developers. This is why Coin Center fellow Michael Lewellen is suing the DOJ to seek declarative judgement that persons developing and maintaining non-custodial open-source software is not criminal conduct. The inherent nature of open-source protects only the software, not the developer.
The AI industry is quickly coming to terms with this threat as frontier labs are pushing for government intervention to halt the development of AI in order to save all of humanity—despite continuing to rapidly develop their own AI models.
For some time now, frontier labs, such as OpenAI and Anthropic, have advocated for more government-intervention in the development and releasing of AI models. After six weeks on the job, an employee from Anthropic publicly resigned due to frontier labs’ alleged irresponsible development of AI and for “gambling with our lives,” sparking debate over the matter. Then, Dario Amodei and Sam Altman publicly supported the notion of government-intervention—which they have been doing for a long time.
But as most have probably thought to themselves, if these CEOs and employees truly believed what they said, why do they need the government to stop their development when they could simply stop themselves? A great question. Instead, frontier labs have been lobbying for regulations on AI models to halt development and architect a framework for safety reviews prior to deployment, all while rapidly developing their models. It’s hard not to assume regulatory capture is the goal here.
Supporters of open-source have taken notice.
Many have pointed out that even if OpenAI and Anthropic were to leverage regulations or a licensing regime to monopolize the market, open-source development would continue and people would still get their hands on open-source models. They’re mostly right that open-source would continue globally and people always find a way to acquire information despite censorship attempts, but they are wrong to call open-source “unstoppable” for the same reason that Lewellen is suing the DOJ: developers won’t write code if they fear criminal prosecution. And, like all other forms of technology, we need open-source for AI.
AI is increasingly empowering individuals the way the personal computer had for the last fifty years. With AI, information is distributed back to the user in almost a human-like way. People are able to converse and learn from AI the way they would be able to with their peers—except for the fact that it contains almost all the information in human existence. It is as if we made the Internet and all the libraries in the world into a person—with some refinements, of course—and gave it the ability to converse with us. Because of this, AI models are increasingly becoming people’s primary source for information, where they no longer search for things themselves but rely on AI models instead.
This means that those who develop these models will become the primary distributors of information, and therefore, of “truth.” Whether or not information distribution is centralized will largely depend on how the overall systems are designed and the regulatory regime surrounding them. Calls for regulations that rest deployment of these models on regulatory approval will surely centralize it. The government will essentially decide what information is allowed to be distributed and what is not, while incumbents monopolize the market and increase their influence. And we need only to look to history to understand why centralizing information distribution is dangerous. A central authority deciding which information we consume decides which ideas and movements spread; it dictates human progress.
Free speech primarily serves as a protection against this very reality. Diversity of thought has nourished our curiosity by exposing us to new ideas, enabling our creativity and driving the human race forward. Censorship replaces curiosity with conformity and eliminates challenging the status quo. Thus, centralizing the distributors of “truth” would be beneficial to the tyrant and detrimental to the individual, because freedom requires the ability to exchange information.
And this extends beyond just information distribution to surveillance as well. Like personal computers and cellphones, these AI models are no longer just tools for people to use, but almost extensions of the people that use them. Every thought, question, and worry will increasingly exist within these systems. Whether an AI model runs on a server belonging to a company, or locally on a person’s computer, will determine who has access and authority over this intimate information. The companies behind centralized AI models will get to decide what to do with a person’s information, and the government will surely want its hands on it.
Open-source software has long existed as a defense against censorship and surveillance, and the same holds true for AI. But it is only unstoppable once it is published, and governments and corporations will surely try and prevent that. The Tornado Cash prosecutions and subsequent Lewellen lawsuit offer us a glimpse of what is in store with AI if we simply ignore law and politics. They matter. -Laz
What else we’re reading
This well-signed “The Pro-Human AI Declaration” petition includes troubling language for developers: Developers and deployers bear legal liability for defects, misrepresentation of capabilities, and inadequate safety controls, with statutes of limitation that account for harms emerging over time.
Latham & Watkins buys Nvidia servers to set up in-house AI systems
That’s from 2017.
If you found this interesting, please consider subscribing and sharing. We are trying to grow this thing.











yep - https://www.techpolicy.press/supporting-openness-safety-lessons-from-recent-state-laws/