Cut Off

From the Threading the Needle newsletter. Challenges the popular “AI tokens will be abundant, the future belongs to those who use them best” mantra — loudest among the world’s “middle powers” betting on navigating the AI revolution with “good-enough” models. Leicht argues access to frontier AI will soon be limited by economic and security constraints.

The “Mythos moment”

  • In early April, Anthropic announced Mythos, a leading cybersecurity model, and made its vulnerability-patching ability available only to a [select few] mostly US-based companies (its “Glasswing” partners) — leaving startups, systems integrators, and allied capitals off the list.
  • OpenAI followed with a similarly limited release (its “Daybreak” initiative for a gpt-5.5-cyber model), dispelling hopes this was a fluke.
  • The US government is reportedly planning to “do something at some point.” Leicht argues this reveals structural trends, not just current events.

Three compounding constraints

1. Security & distillation

  • Misuse risks: a highly capable model (useful for cyberattacks or bioweapon design) gets rolled out first to defenders to shore up vulnerabilities, then to trusted customers, and only later — once no longer state-of-the-art — to everyone.
  • US government interest: restricted access serves national security. The NSA might want to know which zero-days a model like Mythos can find so it can exploit them first (cf. EternalBlue), rather than ensure equitable global diffusion.
  • Theft, espionage, distillation: the biggest concern. “Fast followers” (e.g. DeepSeek, 6–9 months behind) reportedly rely on distillation requiring broad API access. Distillation is economically untenable for frontier labs (can’t recoup R&D if distilled in six months), so expect crackdowns — stricter KYC, more restrictive default access, geopolitically conditioned access.

2. Compute crunch

  • Unlike software (low marginal cost, so market-size logic favours mass rollout), serving frontier AI is near zero-sum — high marginal compute cost per token.
  • Labs repeatedly hit compute crunches, cut offerings, and struggle to subsidise consumer subscriptions; Anthropic is reportedly shopping ad-hoc datacenter deals (even with rival xAI). This worsens if AI begins to rival human workers’ output.
  • Efficiency curves won’t save you: they make last year’s capabilities cheap, but frontier (“Mythos 2”) capabilities keep getting more expensive month-to-month. If you need “the best” AI (not just good-enough) to compete with rivals and attackers, efficiency gains don’t bail you out.
  • So the marginal cost of a new user (firm or country) is high, sharply diminishing the market-power leverage that buyers usually wield. Competition over who gets tokens will emerge — Leicht foresees a revival of GAIN Act–style logic (Americans as “buyers of first resort” of American-produced intelligence), or razor-thin margins favouring whoever monetises tokens best (not cash-strapped governments or constrained European businesses).

3. US government leverage

  • What begins as genuine security restriction may not stay that way. With a formal role over frontier-token flow, the US could wield access control for political/strategic ends.
  • The Trump administration’s style is to bundle leverage (breaking trade deadlocks with intelligence threats, stalling tech deals over food-safety standards). So frontier access stays “fundamentally contingent” wherever governments’ strategic interests diverge — even if security and economics are handled “right.”

The next equilibrium

  • Unlimited API access becomes the exception. A new model flows first to the US national security apparatus, then to trusted defenders (US firms, maybe a few internationals), then to firms clearing high KYC/security bars. Everyone else — consumers, scrappy startups, nervous governments — may only ever get limited product layers (chatbots, coding agents), never clean API access, until the next generation enters the pipeline.
  • This is a bad future. Economically, the accelerationist critique is right: restricting frontier access throttles innovation and the “Hayekian” process of figuring out how to live and work with AI. But the fault isn’t Anthropic’s alleged push for nationalisation — it’s the underlying market and security dynamics.
  • Geopolitically: countries split into frontier “haves” and “have-nots,” with the haves much wealthier and safer. Historically, unevenly distributed industrial revolutions triggered mass migration, reopened conflicts, and destabilised democracies.

Proposed solutions (framed as accel/safety convergence)

  1. Make the world safer so security-motivated restraint is less necessary — harden against bio pathways, screen protein synthesis, deploy technical fixes for distillation before heavy-handed rules arrive, and improve importers’ own datacenter/cyber security.
  2. Build lots of datacenters to ease the compute crunch — “not complicated, just fairly hard”; every GPU online now makes equitable diffusion later more likely.
  3. Non-US countries build compute in exchange for access — allies offer hyperscalers favourable datacenter terms (subsidised energy) for contractual frontier-access guarantees, with mutual hostage-like incentives to prevent reneging.
  4. Middle powers retain contingency options (leverage, and some domestic build capacity) for edge cases where all else fails — the subject of his next post.

Bottom line: the fix isn’t clever new ideas but executing the long-standing agenda — build infrastructure to host advanced AI at scale, and build a world that can handle it — before the “Andy Warhol era of AI access” (where rich and poor use the same product) ends.