Practice Lab

Protectionism in a Safety Costume

EssayAugust 20, 2026 · David J.S. Madgett · 15 min read

A year ago in this section I made a prediction: that the economic value of a language model as such would approach zero, and that the durable value would migrate down the stack to compute and, beneath it, power. The gap between the best open-weight models and the closed state of the art was then measured at roughly three months and compressing.

I want to extend that prediction to the place people still think is safe, and then follow it to the policy fight it explains.

Claim one: even the frontier has no durable value. Not the trailing tier — the leading edge itself. Being three months ahead is worth real money for exactly three months, and then it is worth nothing, and the vendor has to buy the next three months with capital expenditure that grows each cycle. That is not an asset. That is a treadmill with a subscription attached.

Claim two: the effort to restrict open-weight models is protectionism. When every technical moat melts on contact with the market, the only moat left is one the government builds for you. The safety framing on these proposals deserves to be taken seriously exactly once, evaluated against the evidence — which the government’s own study already did — and then the remainder, the part the evidence does not support, should be called what it is.

I write this as a paying customer of a frontier lab. This firm’s entire operation runs on a closed frontier model, by choice, today. That is not a contradiction; it is the point. I pay for the frontier because it is currently the best tool, and I hold the frontier vendor’s pricing power in check — every month, at renewal — precisely because the open alternative exists. Take away the alternative and you have not made me safer. You have made me captive.

The frontier is a release schedule, not an asset

Start with the measurement, which has not changed direction. Epoch AI’s running comparison puts the best open-weight models about three months behind the closed state of the art on their composite capability index — the narrowest gap in the history of the comparison, with their caveats cutting in both directions. Whatever the true number is inside that band, it is denominated in months.

Now ask the question that matters commercially: what is a three-month lead worth?

For a handful of tasks at the true edge — the hardest research problems, the most complex agentic work — it is worth a premium, briefly. But the overwhelming majority of economically valuable work, and virtually all legal work, sits comfortably below the edge. Drafting, summarizing, extraction, first-pass review, correspondence: these saturated some time ago. A model that is three months behind the frontier does them indistinguishably. Which means the frontier premium is collapsing onto an ever-thinner sliver of tasks, even as the cost of staying at the frontier — the training runs, the data centers, the power contracts — compounds.

And the lead itself leaks by being used. A frontier model’s capability transfers into smaller models trained on its outputs; every API call is a lesson. The industry spent early 2025 arguing about whether a Chinese lab’s near-frontier open release had been distilled from American closed models — a dispute I do not need to resolve to make the structural point, which is that the leading product cannot be monetized without being exposed, and cannot be exposed without teaching. The frontier lab’s crown jewel depreciates fastest exactly when it is most popular.

So follow the money to its honest conclusion. The frontier tier is a release schedule — a promise to keep being first, purchased with escalating capex, generating margins that erode on a three-month fuse. The durable assets in this industry are the ones I identified a year ago: compute, power, and distribution. A model, frontier or not, is inventory. Inventory with a sell-by date.

If you run a frontier lab, you know this better than anyone. Which brings us to the policy fight.

What you do when every moat melts

A business whose technical lead decays in months has four options. It can out-execute forever, which is exhausting and margin-free at equilibrium. It can integrate downward into compute and power, which the biggest players are visibly doing. It can build distribution and switching costs, which is what every “platform” and “ecosystem” announcement is. Or it can reach for the one moat that does not melt: law.

A regulatory moat is the best moat there is. It does not depreciate. Competitors cannot distill it. And it arrives dressed, always, in the language of protecting the public — because no one has ever lobbied for a barrier to entry by calling it a barrier to entry.

So look at what is actually on the table in 2026, and ask of each piece: does this scale with risk, or does it scale with being a competitor?

The evidence baseline was set two years ago, and it is worth insisting on because it was the product of exactly the process skeptics should want. The federal government’s own study — NTIA’s July 2024 report on dual-use foundation models with widely available weights, commissioned under the 2023 executive order — looked for the case that open weights were dangerous enough to restrict and reported that the evidence was not there: monitor for marginal risks, it said, but do not restrict the availability of open model weights. That is what an honest safety process looks like. It asks for evidence, and when the evidence is insufficient, it declines to prohibit.

What has happened since is that the models got better, the evidence of catastrophe stubbornly failed to materialize on schedule, and the restriction proposals got bigger. California’s SB 1047 — vetoed in September 2024 — would have imposed liability and shutdown obligations that open developers, who by definition cannot recall a released model, could not satisfy; the veto message itself noted the bill regulated by developer size rather than by demonstrated risk. This year’s sprawling House framework requires “large frontier developers,” defined by revenue, to retain licensed independent verification organizations to audit their risk frameworks — a compliance architecture that a two-hundred-person lab can staff and a graduate student releasing weights cannot, which is to say, a fixed cost that functions as a market-share floor for whoever is already big. And Washington spent the summer openly weighing bans on foreign open-weight models — restrictions their own analysts concede are unenforceable against files that have already been downloaded a hundred million times — while the enforcement mechanism quietly generalizes into infrastructure for restricting any open model.

Notice the recurring shape. Thresholds keyed to revenue and compute rather than to demonstrated capability for harm. Compliance regimes priced in millions per year. Liability for downstream uses that only a closed, API-gated model can even theoretically control — which makes “closed” the only safe legal posture, which makes the incumbents’ architecture the legally mandated one. None of this maps onto the actual risk models safety researchers publish. All of it maps onto the competitive interests of firms whose product depreciates in ninety days.

And notice who declined to join the fiction. In July, twenty-five companies — Nvidia, Microsoft, Meta, IBM, Mozilla, the Linux Foundation, Hugging Face among them — published an open letter against “premature restrictions” on open models that would “stifle competition or drive innovation overseas,” two days after nearly two hundred startups told the White House the same thing. Days later, a frontier lab with the strongest safety reputation in the industry — the one whose model this firm runs on — published its own position stating it has never advocated a ban on open-weight models, that open models without dangerous capabilities are “a public good,” and that the real levers are chip export controls, action against industrial-scale distillation, and capability testing applied to open and closed models alike. When even the most safety-forward frontier lab will not endorse the ban, the ban has no safety constituency left. What remains of the restriction agenda, after you subtract the measures the safety community actually endorses, is the protectionism.

That subtraction is the honest test, so let me state it as a rule: take any proposed restriction, remove every provision that applies equally to closed models, and look at what is left. Capability testing for everything sufficiently powerful? Applies to both; that is safety policy, and I support it. Export controls on chips? Neutral as between open and closed; national-security policy, arguable on its merits. Liability structures only a gated API can satisfy, verification regimes priced for incumbents, thresholds drawn around revenue? Those apply asymmetrically to openness as such — and openness as such is not a risk category. It is a distribution model. Regulating a distribution model is how you protect distributors.

Lawyers have seen this costume before

Our profession should be the fastest in the world to recognize this move, because we invented a version of it.

Every unauthorized-practice-of-law rule is defended as consumer protection, and some of it genuinely is. But the profession has also, for a century, used that costume to keep out competitors whose actual offense was being cheaper: form preparers, publishers of self-help materials, software. The honest test there is the same subtraction — take the UPL enforcement action, remove the part that addresses demonstrated consumer harm, and look at what is left. Often what is left is a guild protecting its rates from people who were serving clients the guild had priced out entirely.

I practice in Minnesota, where thousands of people walk into court every year with no lawyer at all, not because they chose that but because the market the profession built cannot serve them at a price they can pay. The technology this essay is about is the first thing I have seen in my career that credibly changes that arithmetic — and it changes it fastest at the bottom, through the cheap and open tier, the models a legal-aid office can run on its own hardware, the assistants a solo can wire to free public law without a subscription. That is the tier the restriction agenda would freeze. Not the frontier — the incumbents will always be able to comply with their own moat. The tier that gets frozen is the one that was about to make competent help cheap.

So when the profession is asked to weigh in on AI policy — and it will be — the question to carry into the room is the one we should have been asking about our own rules all along: does this restriction scale with demonstrated harm, or does it scale with being a threat to somebody’s margins?

What would prove me wrong

Predictions are worthless without falsifiers, so, as before, the conditions under which I would concede each claim.

On the frontier’s value: if, three years from now, frontier labs sustain high margins on model access itself — not on compute, not on enterprise integration and distribution, not on regulatory position, but on the model qua model — while open alternatives remain months behind, then the depreciation argument failed and I will say so. The evidence to watch is pricing power at renewal time: whether the premium for “best” holds once “second-best, self-hosted, free” is good enough for ninety-five percent of tasks.

On protectionism: if restriction advocates converge on measures that pass the subtraction test — capability-based, evidence-gated, symmetric between open and closed — then the safety framing was sincere and I will retire the costume metaphor. The NTIA evidence standard and the targeted-measures position show what that convergence looks like. If instead the proposals keep gravitating toward revenue thresholds, incumbent-priced compliance, and liability only closed architectures can bear, the costume is the policy.

I hold a stake in this and have disclosed it: my firm’s costs fall as the open tier rises, and my clients’ access to justice improves with it. The incumbents hold the opposite stake, and their filings should be read the way we read any interested party’s filings. That is not cynicism. That is just what lawyers do with testimony from a witness who profits from being believed.

The model will be free. The frontier will be a release schedule. The only question Congress actually controls is whether the free tier arrives for everyone — including the legal-aid office and the solo and the client who could never afford either of us — or whether it is held at the border while the people who could not afford the closed tier wait for permission to be helped. Every article in this section is published free for the same reason this one is: the constraint on justice was never the technology. It was the price. Do not let anyone put the price back and call it safety.


Sources

Speculative commentary on technology policy and the business of law — the opinions, predictions, and stated falsifiers are the author’s. Not legal advice, not investment advice, and not a comment on any pending legislation’s constitutionality. The author’s economic interest is disclosed in the text: this firm benefits from a competitive, partly open model market. No client information appears in this article. Questions about anything here: Send us a message or 612-470-6529.

words
2,417
sections
5
sources
8
distinctive_terms
frontier · safety · moat · models · ntia
Pass it onLinkedInX

Get new articles as they land

One email when something new is published here. No course, no upsell — the Practice Lab stays free either way.

Used only to send Practice Lab posts. Unsubscribe from any email. Subscribing does not create an attorney–client relationship.

The only thing we ask

If something here saves you time, spend some of it on people who could not otherwise afford you.

Everything in the Practice Lab is free. No signup, no subscription, no donations — just take a case you would otherwise have to turn down on economics. More from the Practice Lab →

Keep Reading

31% vocabulary overlap

The Model Will Be Free. The Electricity Won't.

A prediction, with the mechanism and the failure conditions: open weights drive the economic value of the model itself to nearly zero, and the durable value migrates to whoever owns compute — and beneath that, power. What a law firm should do differently if that is right.

Essay · 15 min read

15% vocabulary overlap

The Gap Between Intended and Proven: Ethics Is an Engineering Property

The paperclip maximizer is the famous frame and the wrong one to lead with — it has drawn serious, published, recent criticism, and it postpones the problem to a superintelligence that does not exist. The unsolved problem is here now: we can prove narrow properties of small networks and nothing broad about large ones, and the gap between what a vendor intended and what anyone can prove is precisely where a negligence claim gets built.

Essay · 17 min read

12% vocabulary overlap

Run It Yourself, Then Let the Client Choose

The practical stack for running Qwen on firm hardware — models, runtimes, quantization, what fits in how much memory — and the client-facing tier election it makes possible. If the client picks the tier, the routing has to enforce it.

Tool · 16 min read

← All Practice Lab articles