On 10 August 2026 Mark Zuckerberg published The Future is for Everyone, a letter proposing a philosophy for superintelligence: individual empowerment as the source of prosperity, invention as the technologyâs primary purpose, balance of power as the foundation of safety. The thesis is that distributing superintelligence to everyone is safer than concentrating it, and the line that sums it up is âthere is no such thing as a singular benevolent superintelligenceâ.
On the philosophy I have nothing to add: the opposition between centralised and distributed knowledge I have already treated in epistemic terms, and Hayekâs version holds up better, because it does not require the distributor to be one particular company. Here I look at something else. The document contains not one note, citation or link, and several of its statements concern checkable facts. Three are worth testing against the documents.
The governance announced
The most concrete passage is this: âMeta is implementing a governance structure that gives our independent board of directors the power to approve the safety criteria for releasing models and reviewing whether each model release adheres to the criteriaâ. Zuckerberg adds that the CEOs of all frontier labs currently hold extensive authority over releases, and invites the others to follow Meta.
The document governing those decisions today is the Advanced AI Scaling Framework v2.0, dated 7 April 2026 and still served from ai.meta.com on 11 August. It states that âthe Chief AI Officer or the Director of Alignment and Risk will determine whether to request further testing or information, require additional mitigations or improvements, or approve the model for deploymentâ. The board of directors appears once, in a generic formula: âMetaâs Board of Directors provides oversight of the companyâs product and regulatory complianceâ. No power to approve criteria, no per-release conformity check.
The same documentâs changelog is worth reading in full, because the April revision does two opposite things. It widens the net: for high and critical risk it adopts âsubstantially contribute toâ as the primary standard in place of âuniquely enableâ, so more models fall within it. And it softens the consequences: âCritical threshold changed from âStopâ to âDevelop with Mitigations.â High threshold measure changed from âDo not releaseâ to âDeploy with mitigations.â [âŚ] All thresholds now permit proceeding with sufficient mitigations validated to reduce risk to moderate or lower, with security processes commensurate with the threshold initiatedâ. The same revision adds loss of control as a risk domain and introduces publication requirements. The two stops that were unconditional become conditional: work proceeds provided mitigations are defined, implemented and validated to bring risk down to moderate or lower. That validation is judged by the same executive who approves the release.
Of the new governance structure there is no documentary trace. In the proxy statement filed on 16 April 2026 the phrase âsafety criteriaâ does not appear; a full-text search of Metaâs SEC filings between 1 June and 11 August 2026 returns no occurrence of that phrase or of âindependent board of directorsâ; on 10 August the only filing under Metaâs CIK is a Form 144, an officerâs notice of a share sale, and there is no 8-K. The Meta Research post announcing the model released in those same days points to the framework that assigns the decision to the Chief AI Officer as its evaluation standard.
The same proxy supplies the corporate context, which the letter acknowledges by writing âMeta is a founder-controlled companyâ: as of 1 April 2026 Zuckerberg holds 99.8% of the Class B shares, worth ten votes each, and 60.8% of the voting power. The corresponding economic interest Meta does not publish: two shareholder proposals in the same document put it at 13% and at 14%, and the proxy warns that statements by proponents are their sole responsibility. The document states that under Nasdaq rules Meta is a controlled company, and that having a majority-independent board is a voluntary choice rather than an obligation.
The criterion for reading an announcement of this kind I have written before and will not restate: whoever measures themselves produces no independent evidence, and a gap between a stated commitment and a verifiable property is the difference between a policy and an architecture. The precise formulation here is that the structure is announced in the present progressive and is documented nowhere. It may arrive; as of 11 August it has not.
The cybersecurity episode
It is the one place where the letter rests on a technical incident that can be reconstructed from third-party sources: âEven in recent weeks, we have seen companies handling security incidents like HuggingFace rely on widely available open models to patch vulnerabilitiesâ. It serves to support the claim that widely deployed open source systems have proven more secure.
I wrote about that incident on 23 July. Re-reading the post-mortem and the technical timeline published by Hugging Face, the sentence shifts on three points.
The first is what the open model did. It analysed over seventeen thousand events and reconstructed the obfuscation scheme the intruder had used: that is forensics, not patching. The vulnerabilities were closed by shutting down the evaluation sandbox with the third-party vendorâs help, fixing the dataset config renderer, rotating every credential and rebuilding from scratch the cluster the intruder had pivoted into. âPatching with open modelsâ supports the letterâs thesis; âanalysing logs with an open modelâ supports a narrower one.
The second is which model. The timeline names Nvidiaâs quantised build of GLM-5.2, a model from the Chinese lab Z.ai, run locally. The letter argues that the goal should be for American open source models to be the best in the world.
The third is why that model was used. The analysis requests contained real attack commands and payloads, and the post-mortem says âthese requests were blocked by the providersâ safety guardrailsâ; the timeline names them: âThe models we reached for first, Claude Opus and Fable, refused a large part of that workâ, because âtheir safety guardrails treated reverse-engineering an exploit the same as launching oneâ. The responders rerouted the entire pipeline through the open model. The episode therefore supports a thesis about guardrails rather than about open source as such â that open weights and code make independent verification possible without making the model safer in itself has been understood for some time.
Intermediate checkpoints, as a mechanism
The letterâs operative proposal is that frontier labs share intermediate training checkpoints with the government ârather than waiting until training has completedâ, so that the administration has early access to the most capable models and âan army of capable engineersâ to harden critical infrastructure.
Taken as a mechanism, it adds less than it appears to. Early government access already exists: Executive Order 14409 of 2 June 2026 provides a voluntary framework in which developers may grant access to models up to thirty days before release. And evaluating non-final checkpoints has been documented practice for some time: the UK AI Security Institute published an evaluation on 30 April 2026 conducted on an early checkpoint, and the o1 system card of December 2024 already listed an o1-near-final-checkpoint alongside the release version.
What the proposal changes is the nature of the access. The checkpoints serve the government in defending systems, and Zuckerberg says so in place of a review process: âI think it will be more productive to have a close proactive collaboration between frontier labs and the government rather than a rigid process and review timeline that is followed in all casesâ. The same letter states that âany policy that slows American model releases â even by a month â could add significant risk to American leadershipâ, and thirty days is precisely the window the executive order already provides.
What is missing, then, is the stage that turns an artefact into a control. The proposal sets out what the government receives, not what it is required to do with it, nor who stops a release when verification fails. It is the same structure I wrote about for signatures on software artefacts: an artefact nobody verifies protects as much as one that does not exist. And there is an asymmetry with the letterâs own argument: when intermediate checkpoints are public they make a documented claim reproducible, whereas here they go to a single recipient, in a text whose thesis is that concentrated verification is the problem.
The point of comparison is twenty-seven days old. The framework Demis Hassabis proposed asked for the opposite: an external standards body, review up to thirty days before release, a board with independent experts and open source representatives. The letter prefers a flexible collaboration to a fixed review timetable, and it does not name that framework. The technical reason for the contrast lies in the nature of the releases: a fixed-window pre-release review is designed for closed models distributed through an API, whereas for open-weights releases the line between sharing for review and publishing is thin.
The figures the text does not support
Four quantitative statements hold up poorly, and since the text carries not one reference they have to be checked one by one.
- âCountries like China are bringing online 1GW+ of nuclear capacity every other weekâ means about 26 GW a year. According to the World Nuclear Association Chinaâs entire nuclear fleet amounts to 63,985 MW across 64 reactors, built from 1991 onwards: at the claimed pace it would be rebuilt from nothing in under three years. The 37 reactors under construction total 38.6 GW, less than two years at that pace, and the five-year plan approved in March 2026 targets 110 GW by 2030 from roughly 62 GW at the end of 2025: under ten GW a year of planned capacity.
- âBefore the industrial revolution, 90% of people were farmersâ works as a rough world average and is wrong where it matters. In England and Wales, where the industrial revolution happened, agriculture employed 47% of the male labour force in 1701 and 43% in 1761, according to the Cambridge project on British occupational structure.
- The leap of â100x or more intelligence out of each gigawattâ that the letter attributes to a self-improving system has no source and matches no published estimate. The letter marks it as hypothetical and then uses it as the premise for arguing that such a system, running on a fraction of the worldâs compute, could command more effective compute than everyone else combined.
- âRecent statistics suggest it may be more likely that individualsâ capability growth could match or outpace automationâ: no statistic is cited, and no series measures the comparison proposed. The recent literature is split between those finding no aggregate effect and those measuring effects concentrated on young entrants.
The same category holds the anecdote about a model that supposedly refused to help draft a letter to a schoolâs prospective parents because it judged standardised testing unethical, offered as an example of alignment gone wrong. Meta does not name the model, does not date the episode and publishes no transcript, and it is not documented anywhere else.
The release of 10 August
One fact the letter does produce. âNow that Meta Superintelligence Labs are up and running, we will resume releasing some open source models soonâ: on that same 10 August Meta published Muse Glimmer 30B under the Apache 2.0 licence, some sixteen months after the last open-weights release of the Llama family in April 2025. The Hugging Face repository was created the evening before.
The licence is the change that counts and needs stating precisely. Apache 2.0 is OSI-approved, so on the weights this is a real shift from the Llama Community License, which OSI rejected in blunt terms. The release covers weights and documentation, not training code or data information, so it does not meet OSIâs definition of open source AI â a boundary I have written about elsewhere and that the letter never addresses, despite using âopen sourceâ sixteen times.
What remains
On the substance of the proposal one can stand on either side in good faith, and the thesis that concentrating superintelligence is dangerous is not a weak one. The problem is verifiability, and it is the same one I wrote about ten days ago, on a proof that carries the means of checking it: a claim that arrives with the artefact for checking it is worth more than a stronger claim that arrives alone.
There is finally a question of form that bears on the substance. A document asking to change the governance regime for artificial intelligence, and resting its argument on the claim that distributed verification is safer than concentrated verification, contains not one reference a reader can follow.
- https://www.meta.com/thefutureisforeveryone/
- https://ai.meta.com/static-resource/Meta_Advanced-AI-Scaling-Framework-v2
- https://www.sec.gov/Archives/edgar/data/1326801/000162828026025532/meta-20260416.htm
- https://huggingface.co/blog/security-incident-july-2026
- https://huggingface.co/blog/agent-intrusion-technical-timeline
- https://www.whitehouse.gov/presidential-actions/2026/06/promoting-advanced-artificial-intelligence-innovation-and-security/
- https://opensource.org/blog/metas-llama-license-is-still-not-open-source
- https://huggingface.co/meta-models/Muse-Glimmer-30B
- https://world-nuclear.org/information-library/country-profiles/countries-a-f/china-nuclear-power
- https://www.campop.geog.cam.ac.uk/blog/2024/12/12/agriculture/
- https://digitaleconomy.stanford.edu/wp-content/uploads/2025/08/Canaries_BrynjolfssonChandarChen.pdf
- https://epoch.ai/trends
Cover image: the seal press in the halls of the Congress of Versailles, 1913 â Agence de presse Meurisse, Bibliothèque nationale de France, public domain â https://commons.wikimedia.org/wiki/File:Salles_du_Congr%C3%A8s_de_Versailles,_le_sceau_-_btv1b9021532v.jpg