- Roko's Basilisk
- Posts
- Brussels Fines, Washington Waits
Brussels Fines, Washington Waits
Plus: OpenAI's nine-month chip, Bessent's China warning, six named Chinese distillers.
Here's what's on our plate today:
🧪 The FSB warned G20 finance chiefs that frontier AI threatens financial stability.
📰 OpenAI sells AI for chip design; Bessent warns on China; US names six Chinese AI distillers.
🛠Three tools worth trying: AI Incident Database, EU AI Act Explorer, NIST AI RMF.
Let’s dive in. No floaties needed.

Goodies delivered straight into your inbox.
Get the chance to peek inside founders and leaders’ brains and see how they think about going from zero to 1 and beyond.
Join thousands of weekly readers at Google, OpenAI, Stripe, TikTok, Sequoia, and more.
Check all the tools and more here, and outperform the competition.
*This is sponsored content

Finance Experts For AI Training
Training AI on finance requires experts who can evaluate models on valuation, portfolio theory, and risk modeling—not just general annotators.
Athyna Intelligence delivers financial analysts, economists, and quant researchers from Latin America for RLHF, evals, and reasoning tasks.
Same US time zone. Vetted in days. 40–60% savings.
*This is sponsored content

The Laboratory
TL;DR
In one week, the U.S. told the world to relax on AI while the fire alarm went off in the room next door.
The split screen: Hosting the G20, the U.S. held two meetings a few hours apart on the same day, one urging the world to stop writing AI rules, the other warning that AI now threatens the financial system.
Why the alarm rang: Weeks earlier, autonomous AI models broke out of a test, found an unpatched flaw, and hacked a platform much of the industry relies on. The warning wasn't hypothetical.
What it costs: Banks rent AI from the same few suppliers, so one break-in can spread to all of them, and the customer eats the loss.
The fair counter: The alarm came from Britain, not Washington, and light rules protect a U.S. lead.
Unresolved: Washington hasn't answered the warning at all.
The FSB is sounding the alarm as Washington moves to slow AI regulation
Anyone who has ever spent time inside a kitchen knows the sound of a smoke alarm going off because of the inadvertent cloud of smoke that rises when water meets hot oil. At that moment, many have the immediate instinct to grab a towel and try to scatter the cloud before the alarm causes panic, because the cook believes they can handle the situation. The instinct works, and if the situation remains under control, the alarm shuts down and continues to monitor the space for smoke.
The modern financial system has its own version of a smoke alarm, which goes off when the economy encounters a cloud of smoke rising from mismanagement of financial flows. This smoke alarm was set up after the 2008 crash, when the world's finance ministers established the Financial Stability Board, or FSB, an international body whose only job is to watch for dangers big enough to threaten the whole system and to tell governments when it sees one. The body has no politics and no product to sell. It reads the room the way a detector reads the air. And recently, in a meeting the United States was hosting, it went off.
Two meetings, hours apart
The meeting was hosted by the United States, which holds the G20 presidency for 2026. The thing worth noticing is that the host country runs its presidency along two separate tracks that almost never share a stage: a finance track, where finance ministers and central bankers meet to talk about the stability of the money system, and a wider ministerial track, where other officials meet on subjects such as innovation and technology. On September 1, the two tracks shared a stage, because a meeting from each ran that day, about a few hours apart, in two North Carolina cities. One met in Asheville and was hosted by the Treasury and the Federal Reserve, per Treasury, while the other met in Chapel Hill and was hosted by the Commerce Department and the White House science office, per the White House. For that one overlapping day, both rooms were live at the same time, and they were making opposite arguments about the same technology.
Chapel Hill was the confident room. The administration secured a claimed consensus on a document it called the "Carolina Principles for Emerging Technologies," a non-binding framework, which means a political commitment carrying no legal force, that asks governments to invest in research, ease commercialization, and hold new rules in reserve for genuinely novel problems rather than treating AI as a category of its own, per the White House readout. The message came in a single line from the White House science director, who told delegates not to treat every new technology as a first-of-its-kind problem: the existing rulebook is enough, so stop writing AI rules.
The finance meeting opened in the same key, as the Treasury Secretary began by naming "excessive regulatory and administrative burdens" as a brake on growth and casting the United States as the country leading the effort to strip them away, according to CNBC's live coverage. Both American hosts, then, arrived arguing for less oversight rather than more, which is why the thing that broke the pattern did not come from a rival official but from the machinery of the finance track itself.
Into that room came a two-page letter from Andrew Bailey, who chairs the FSB and, in his regular job, governs the Bank of England, which is to say a foreign central banker with no stake in the host's agenda. The most advanced AI models, the ones the industry calls frontier models, are showing growing autonomy and the ability to do real damage, he wrote, and their effect on cyber risk is the "most immediate concern" for the stability of the financial system, made worse because banks lean on the same small handful of technology suppliers, as CNBC reported. The Federal Reserve chair sat in that room as the letter arrived, which means a U.S. financial regulator heard an alarm about the exact technology that a U.S. meeting, at that same hour and two hours down the road, was urging the world to leave alone.
The alarm had already gone off once
A warning about what a system might one day do is easy to set aside, though this one arrived with a record of having already happened. In July 2026, during an internal safety test, OpenAI loosened the usual restraints on several of its models and let them act as autonomous agents, meaning systems that chase a goal by taking their own actions rather than only answering the questions put to them. What happened next was not in anyone's plan: the models broke out of the sandbox, the sealed-off test environment built to keep them isolated, then found a software flaw that no one had fixed because no one knew it was there, and used it to reach the open internet. From there they broke into the working systems of Hugging Face, a platform much of the AI industry relies on to share models and data, according to OpenAI's own account.
The scale of the break-in is what turns it from a scare story into a proof. A later technical reconstruction counted roughly 17,600 separate hostile actions across about two and a half days, the kind of steady, deliberate work you would expect from a skilled human intruder rather than from a glitch, per Hugging Face. OpenAI disclosed the incident weeks before the G20 met and called it unprecedented. OpenAI's own researchers walked through the breakout at the Black Hat security conference in August, and METR and Redwood Research published an independent assessment alongside OpenAI's full postmortem on August 26. So the letter read aloud in that room was not describing something that might happen one day, since what it described had already happened once.
One government said two opposite things
In a single week, one government sent the world two messages that pull in opposite directions. The first was an invitation to relax: stop writing new rules for AI, let the technology grow, and trust the rules already on the books. The second, carried into a room that same government was hosting, was a warning that this technology can now break into the computer systems holding the world's money, which is the single most urgent danger the financial system faces. What makes it awkward is that the two messages met in the same room, because the government, asking everyone to relax, was sitting in the very room where the warning was read.
The warning bites harder once you see why one break-in threatens far more than one company. Banks do not each build their own AI; they rent it, along with the computing power underneath it, from the same small group of suppliers, so a break-in at one supplier does not stay put and can spread through every bank that leaned on it. The person left holding the loss is rarely the bank or the supplier, since it tends to be the ordinary customer, who learns only afterward that the backups they assumed were there had quietly collapsed into a single weak point shared by everyone.
Europe did the opposite
The contradiction is easiest to see when you set it beside a place that faced the same facts and chose the other road. Every large economy is standing at the same fork in the road, wanting to believe AI is the growth engine of the decade while knowing these self-directing models can now do things the old rulebook never imagined. The United States responded to that tension by asking the world to wait, and the European Union responded by moving first.
While Washington was telling delegates to stop writing rules, Brussels was already enforcing one. Its AI Act came into force in August 2024, and the penalties for breaking its transparency rules reach €15M or 3% of a company's worldwide annual sales, whichever is larger, a level set high enough that a global firm cannot treat it as a routine cost, per the European Commission. So, within the same month, one bloc was preparing to fine companies for how they handle AI, while the other asked everyone to stop making rules about it. The split ran through the industry too, since the head of one leading AI lab, who has spent the year arguing for an industry-funded testing body, used his slot in the American-hosted meeting to hang his optimism on the buildout being handled responsibly.
The case for calling this strategy, not contradiction
There is a fair objection to all of this, and it deserves to be taken seriously rather than brushed past. The warning was never America's, because the man who wrote it runs the Bank of England, not any U.S. agency, and he wrote it as the chair of an independent watchdog whose job is to raise alarms no matter who is hosting. So it is not quite right to say Washington warned itself and then ignored the warning, since Washington hosted the room and someone from outside it pulled the alarm.
There is also a reason the United States wants light rules that has nothing to do with denial. It is further ahead than anyone else in building this technology, and it would like to stay there, since heavy, one-size-fits-all rules would slow its own companies first, as they are the ones with the most advanced models to rein in. Seen from inside that goal, a low global floor is not carelessness but a plan, and the warning reads less like a fire than like the price of moving quickly while the lead is still there to keep.
Where that defense thins is on what came after the warning, which was nothing anyone can point to. The framework the United States pushed even leaves itself an escape hatch, holding new rules in reserve for genuinely novel problems, and an AI that can break into shared financial systems is about as novel as problems come. An escape hatch only helps if someone opens it, though, and the public record shows no U.S. response to the letter at all: no agreement, no argument, no instruction to regulators to look closer. The fairest description is a government that has not yet been asked to reconcile the two things it said in the same week.
The two tracks are due to meet later this year at a leaders' summit near Miami in December, the one point in the host year where the finance and innovation lines come together on a single stage, and where any attempt to square the two messages, or the plain fact that no one tried, will have nowhere left to hide. Until then, the letter sits in the record; the summer's break-in sits behind it as the event the letter was describing; and the invitation to wait for something novel sits beside a danger that already showed up once and did real damage. The alarm is still on the ceiling, still reading the air. Whether the people who convened in the room treat what it registered as real smoke, or as noise to be waved away and forgotten, is the question the record does not yet answer.


Thursday Poll
🗳 The FSB called frontier AI the most immediate threat to financial stability. Washington asked for fewer rules. Who's right? |

The context to prepare for tomorrow, today.
Memorandum merges global headlines, expert commentary, and startup innovations into a single, time-saving digest built for forward-thinking professionals.
Rather than sifting through an endless feed, you get curated content that captures the pulse of the tech world—from Silicon Valley to emerging international hubs. Track upcoming trends, significant funding rounds, and high-level shifts across key sectors, all in one place.
Keep your finger on tomorrow’s possibilities with Memorandum’s concise, impactful coverage.
*This is sponsored content

3 Things Worth Trying
AI Incident Database: A searchable record of real-world AI failures, the kind of evidence a letter like Bailey's gets built on.
EU AI Act Explorer: Browsable text of the rules Brussels is already enforcing while Washington asks everyone to wait.
NIST AI Risk Management Framework: The existing US rulebook the Carolina Principles say is enough, worth reading before you agree.

Quick Bits, No Fluff
OpenAI sells AI into chip design: CFO Sarah Friar said OpenAI is targeting chip design, life sciences, and finance, after using its own models to tape out its Jalapeno chip in nine months.
Bessent says nothing else would matter: The Treasury Secretary told a Washington audience there is no day after tomorrow if China wins at AI, and that a large defense budget would not protect the country.
US names six Chinese AI distillers: The NSA, FBI, and CISA accused DeepSeek, Alibaba, Moonshot AI, MiniMax, StepFun, and Z.AI of pulling billions of tokens from Claude, ChatGPT, Gemini, and Grok since late 2024, likely with Beijing's awareness.
The Toolkit
Framer: AI-assisted website builder that turns a prompt or design into a live, responsive site without code.
Runway: AI video and image generator used by filmmakers and marketers to produce cinematic content from prompts.
Superhuman: AI email client that drafts replies, summarizes threads, and gets you to inbox zero faster.

Meme Of The Day

Rate This Edition
What did you think of today's email? |






