AI Hiring Rebounds as Safety Rules Target Dangerous Open Models
John Coogan and Jordi Hays argue that renewed hiring at large companies complicates the claim that AI will simply eliminate jobs: employers may use it to cut freelance work and avoid some backfills, but also to expand output and hire people who can work with the systems. They apply a similar distinction to the open-weight AI debate, presenting Anthropic’s case for restricting models with demonstrated cyber or biological danger while noting Mark Zuckerberg’s argument for broad access. The unresolved issue, they say, is whether regulators can define dangerous capability, distillation and enforceable infrastructure controls without creating a broad barrier to smaller AI developers.

AI may expand work while concentrating the gains
John Coogan treated renewed hiring at large companies as a challenge to the simple story that AI is about to erase broad categories of work. After roughly a year of cautious hiring and layoffs often attributed to AI, companies across technology, transportation, defense, and other industries were again saying they needed people to work alongside AI systems. Coogan pointed to CSX, Alphabet, ServiceNow, Snap-on, and Booz Allen Hamilton as companies signaling expansion, particularly in roles where employees can use AI to become more productive.
His explanation was a version of Jevons paradox. If AI makes work cheaper or faster, organizations may choose to do more of it: pursue activities that previously were too expensive, add new services, or increase the scope of what a relatively small team can attempt. AI does not have to be a drop-in substitute for a coworker in order to change the amount of output a company can produce.
Jordi Hays argued that the earlier layoff narrative often disguised more conventional problems. “AI” gave management teams a forward-looking explanation for cuts that might otherwise be attributed to overhiring, weaker-than-expected business performance, or a need to reset. In Hays’s view, more executives should simply say so.
Coogan added that a company can be reshaping rather than shrinking its workforce. A business with 10,000 or 20,000 employees may decide that its overall headcount is appropriate while replacing some workers with people better suited to its current needs—more salespeople, developers, or employees with newer skills. Hays noted that someone at the bottom of one company’s performance ranking could be among the strongest workers at another.
The more consequential change may be in the work around a core team. Hays said TBPN’s own AI use resembles a replacement for one-off, nonexpert freelance tasks more than for senior accountable roles. A funny song, a quick website, or another small creative project that might once have gone to an online freelancer can now be generated or prototyped with a tool. That creates capacity for work the organization would not previously have undertaken.
But, as Coogan put it, AI “fills the cracks.” The core work still requires a person responsible for it, using AI rather than being wholly displaced by it.
The core stuff is still like you want a person that's responsible and then you want them using AI.
That distinction matters especially for junior hiring. Coogan cited Sarah Franklin, the CEO of HR platform Lattice, saying that companies which initially assumed AI agents could replace entry-level workers are recognizing that human employees remain essential. Coding agents do not mean a company stops hiring engineers; Lattice was seeing renewed hiring among customers, including for junior roles. Robert Half CEO M. Keith Waddell similarly said AI’s employment effect had been more benign than feared and that hiring demand was improving.
There is a real opposing view. Investor Bryce Roberts shared a message saying, “We honestly aren’t hiring a ton right now…AI backfilling most roles.” Coogan read “backfilling” as a decision not to replace someone who leaves: ask the remaining team to absorb more work with AI rather than hire another employee.
Hays did not dispute that some companies are doing this. But he argued it is not the normal posture of a business that is growing quickly. When a company is “ripping,” he said, it generally cannot hire strong people fast enough; a company that is withholding hiring may instead have a business that is not expanding. Coogan also cited Cloudflare CEO Matthew Prince’s opposing prescription: hire new graduates and put them into legacy teams to help those teams adopt AI.
That leaves a practical question: whether employers use AI primarily to reduce payroll through eliminated freelance work and unfilled roles, or to expand what an AI-enabled workforce can do.
Open weights are not the issue in the abstract; dangerous capability is
John Coogan summarized Dario Amodei’s position as three premises followed by three policy proposals. First, Anthropic has never advocated a blanket ban on open-weight models. Second, the United States must prevail over authoritarian governments in the AI race. Third, sufficiently powerful models could be misused for cyber or biological attacks.
Anthropic’s statement distinguished between open-weight models without dangerous capabilities—which it called a public good for businesses, developers, and researchers—and systems whose capabilities could enable severe harm. The question, in that formulation, is not whether weights are open in the abstract. It is what a model can do, and what becomes possible once its weights circulate beyond the developer’s control.
The distinction puts Anthropic at odds with the accusation that it wants a general prohibition on open models. Coogan noted that definitions still matter: a rule can be described as something other than a blanket ban while becoming restrictive depending on how regulators define an open-weight model, a foreign model, a distilled model, or prohibited distribution.
Jordi Hays introduced Mark Zuckerberg’s Wall Street Journal essay, “The AI Future Is for Everyone,” as an effort to make the affirmative case for broad access. Zuckerberg wrote that centralized power stifles human potential; Coogan highlighted his further claim that the history of open-source software, particularly in cybersecurity, suggests that giving people broad access to powerful systems can improve safety and security over time.
Coogan also argued that Meta, despite its scale, does not possess a complete monopoly over attention or information distribution. TikTok, Snapchat, LinkedIn, Twitch, YouTube, Netflix, podcasts, SMS, and iMessage all compete for people’s time and reach.
Zuckerberg’s broad-access case is presented as a principle: decentralizing powerful tools can support human potential and, in some settings, security. Anthropic accepts the value of open weights that are not dangerous, while arguing that the calculus changes when a system can materially assist cyber or biological attacks. The unresolved issue is the capability threshold at which broad access creates that material risk.
Anthropic’s proposals leave the implementation questions open
Amodei’s proposals are more concrete than a blanket restriction on open models, but they leave the hardest questions to definitions, proof, and enforcement.
| Proposal | Anthropic’s stated concern or objective | Implementation question raised |
|---|---|---|
| Restrict powerful chips and chipmaking equipment to China | Keep powerful AI capabilities from authoritarian governments | How much commercial cost follows from reduced access to the Chinese market? |
| Crack down on industrial-scale distillation | Deter the extraction of model capabilities that Anthropic says its systems face | What evidence distinguishes direct distillation from ordinary use of synthetic data? |
| Require safety testing for sufficiently capable models | Evaluate dangerous capabilities in both open and closed models | Who sets the capability threshold, and can smaller labs avoid an incumbent-favoring queue? |
The first proposed action was continued restrictions on sales of powerful chips and chipmaking equipment to China. John Coogan said chip controls could be defended even by people who do not share Anthropic’s most severe safety concerns: advanced compute is an engine of economic competition, and slowing a rival’s capacity to build it may preserve an advantage for the United States. He also suggested that strong domestic demand could limit the commercial damage to American chip companies.
Jordi Hays supplied the counterargument. China is the world’s second-largest computing market, and losing access to it is a serious cost. Coogan replied that U.S. firms may be on course to lose much of that market anyway because China has spent decades developing an indigenous chip supply. His argument was that controls could maintain an existing technological gap, not that their economic costs would disappear.
The second proposal was a crackdown on industrial-scale distillation: using frontier models to generate training material for a competing model. Coogan broadly agreed that labs should be able to enforce their terms of service and protect their intellectual property. But the operational problem is provenance. A model may incorporate outputs from several systems, synthetic data, fine-tuning, modified reinforcement-learning environments, and other sources.
An unnamed participant gave an example of a model trained partly on synthetic data created with Kimi K2.5. That model benefited from a Chinese open-source system, but neither the participant nor Coogan treated it as an obvious instance of industrial-scale distillation. It was downstream of that ecosystem, not necessarily a direct extraction attack.
That leaves a policy question with three parts: what proves distillation, what conduct triggers intervention, and what remedy follows. Coogan floated possible forms of evidence—suspicious API usage, a detailed report from the affected lab, or model behavior that matches relevant evaluations—but emphasized that no binary test can cleanly determine provenance. A direct lawsuit against a foreign lab may also be difficult.
What can the government do that the lab can't?
Anthropic’s third proposal was mandatory safety testing for all sufficiently capable models, whether open or closed. Coogan noted that Demis Hassabis of Google DeepMind had outlined a similar position. The attraction is clear: regulate demonstrated dangerous capability rather than a model’s licensing model.
The risk, Coogan argued, is a review system that rewards incumbency. A small company with a safe, independently developed model could sit in a queue while trillion-dollar companies deploy lawyers, lobbyists, and Washington offices to move faster. He compared the possible bottleneck to biotech, FDA approvals, and nuclear regulation: systems meant to manage serious risks can also slow innovation and protect established players.
A downloadable model is not necessarily deployable at scale
The policy dispute sits alongside an AI buildout in which training and economically meaningful serving can require costly chips, power, data centers, and cloud capacity. As Coogan and Hays framed it, that does not resolve the question of whether weights should be open. It does distinguish a model that can be downloaded from one that can be trained, served, or continuously improved at frontier scale.
John Coogan cautioned against reading every large compute agreement as a circular financing arrangement. Safe Superintelligence had said it would scale its research, but Coogan said that did not establish that it was about to release a public model or agent. Recursive Superintelligence’s reported $410 million, multi-year compute deal with Amazon appeared, by contrast, comparatively straightforward: the company was buying a large amount of compute, even if AWS and Recursive also planned to co-develop infrastructure for companies of that type.
Nvidia’s reported Texas commitment made the concentration of infrastructure more visible. Nvidia was identified as the tenant for a Hut 8 data center that would use Nvidia chips, with leases reported to be worth up to $50 billion. Coogan said Nvidia would lease the entire one-gigawatt facility, expected to house hundreds of thousands of Nvidia GPUs.
Coogan described Nvidia’s balance sheet as helping backstop demand for AI computing. The eventual users of that compute, or the ownership arrangements around it, could change over time. Still, the arrangement illustrates the hosts’ broader point that AI competition involves more than model builders: chip suppliers, cloud providers, data-center developers, and labs are connected through the same deployment and financing system.
That structure may matter if governments try to limit the use of a genuinely dangerous model. Coogan and Hays presented infrastructure providers as a possible enforcement lever, contingent on the compute the model requires. A model that can run usefully on a few GPUs outside conventional hosting would offer fewer centralized points of intervention. One that needs racks of equipment, substantial power, and a relationship with a neo-cloud or major data center may be easier to identify and pressure.
Hays posed the underlying question: how much compute does a model need before it becomes dangerous? A sufficiently advanced system might be usable on GPUs “in the back shed,” he said. Or it might require large clusters and extensive power, making its operators dependent on infrastructure providers that are subject to ordinary business registration and government contact.
The hardest case Coogan described is a foreign lab that distills frontier models, acquires smuggled chips, removes cyber and biological safeguards, and releases the resulting weights through a torrent or hosting platform. In that scenario, the hosts did not suggest the weights could simply be recalled. They instead speculated about measures such as pressuring hosts not to distribute them, restricting their use in U.S. data centers, or directing cloud providers not to provide capacity.
Coogan compared identifiable infrastructure providers to businesses that cannot knowingly facilitate illegal activity, intellectual-property infringement, or organized criminal operations. But he stressed that the response should depend on demonstrated danger. A model that makes unwanted intellectual-property imitations, in his framing, is not equivalent to one capable of systematically stealing money from banks. The unresolved problem is how regulators would make that judgment early enough to matter without turning safety review into a broad barrier to release.



