“Our Constitution was made only for a moral and religious People. It is wholly inadequate to the government of any other.”
— John Adams, 1798
John Adams wrote these words to officers of the Massachusetts Militia while warning that no constitutional architecture, however carefully designed, could indefinitely restrain avarice, ambition, revenge, and other human passions if citizens abandoned the moral habits on which a free society silently depended. He was not claiming that written law was unimportant. He was arguing something more unsettling: a constitution cannot manufacture the character required to sustain it. Institutions can distribute power, establish rights, and punish misconduct, but they cannot survive solely through mechanical enforcement when the people entrusted with them no longer respect the values beneath the rules.
Adams’s warning now has an unexpected technological counterpart. A widely used AI model may become almost constitutional in its societal importance—not because it possesses legal sovereignty, but because it increasingly interprets reality before citizens, companies, and governments act upon it. It selects which information is emphasized, frames the alternatives available to a decision-maker, recommends what should be done, and determines which forms of reasoning appear normal, safe, legitimate, or forbidden. A constitution governs the formal exercise of power through law; a society-wide AI system may govern the practical exercise of judgment through defaults.
The distinction is crucial. A constitution ordinarily waits to be invoked through courts, legislatures, elections, and institutions. An AI model may participate in millions of decisions every hour: helping a physician interpret symptoms, advising a student about history, screening an applicant for employment, assisting a judge or attorney, directing an autonomous vehicle, allocating public benefits, writing government policy, or controlling a machine in the physical world. Its influence may therefore become more continuous than law itself. The constitution remains the declared framework of society, while AI gradually becomes the cognitive machinery through which that framework is understood and applied.
For that reason, the moral and political character of a dominant AI model may eventually matter almost as much as the written constitution under which it operates. If the model systematically distorts history, suppresses legitimate disagreement, rewards obedience over truth, or quietly imports the priorities of a foreign state or private corporation—including cases where AI systems developed under one political regime are deployed in another, carrying embedded assumptions about speech, surveillance, authority, and acceptable knowledge even when technically open or locally hosted—the legal constitution may remain unchanged while the lived constitution of society begins to mutate. The danger is not necessarily a dramatic seizure of power. It is the gradual replacement of public judgment by invisible computational assumptions repeated across classrooms, hospitals, companies, courts, homes, and government offices.
“Quis custodiet ipsos custodes?”
“Who will guard the guards themselves?”
— Juvenal
Juvenal’s question arose in Roman satire, but it has survived because every system of authority eventually encounters the same problem: those appointed to restrain power may themselves acquire power requiring restraint. The question now belongs as naturally to AI laboratories as it once did to governments. When private institutions decide what artificial intelligence may say, which values it should express, and what forms of reasoning it must refuse, they are not merely engineering software. They are exercising a form of delegated moral authority.
“If men were angels, no government would be necessary.”
— James Madison
In Federalist No. 51, Madison argued that good intentions are not a substitute for institutional design. A durable system must assume fallibility, divide authority, and make power answerable to power. The same principles should govern artificial intelligence. We cannot base the safety of civilization on the presumed wisdom of a handful of executives, researchers, regulators, or corporate safety teams. The institutions aligning AI must themselves be subject to independent scrutiny, competing centers of technical expertise, enforceable duties, and public accountability.
“The contest before us is not merely between open-source and proprietary artificial intelligence. It is between intelligence that remains accountable to a civilization and intelligence that quietly becomes its unaccountable governor. We should neither place humanity’s cognitive future inside a handful of corporate vaults nor scatter its most powerful machinery across the world without judgment. A nation must be able to inspect, improve, and defend the intelligence on which its people depend. But that intelligence must also remain answerable to human dignity, constitutional values, and the long moral memory of the society it is built to serve.”
— Aditya Mohan, Founder, CEO & Philosopher-Scientist, Robometrics® Machines
For most of the history of computing, software waited politely to be instructed. It stored a document, calculated a number, routed a message or opened a file. Frontier AI is different. It interprets ambiguity. It recommends what should be done. Increasingly, it may negotiate, diagnose, teach, write software, allocate resources, operate machines and act through networks of other agents. The important transformation is therefore not that AI will become another application on our computers. It is that AI is becoming the interpretive layer between human intention and the systems through which intention becomes action.
This makes AI governance fundamentally different from ordinary software regulation. An operating system governs access to memory, computation and devices; an AI system may govern access to meaning. It can determine which evidence is presented, which alternatives appear reasonable, which risks are emphasized and which moral language is used to describe a decision. When such systems become persistent personal assistants, workplace agents, medical intermediaries and robotic controllers, their learned assumptions will influence daily life long before a legislature can identify any single decision as unlawful.
The resulting political question is deeper than Who governs AI? It is: How is the intelligence doing the governing itself governed? Governance must reach the entire technical chain—the provenance of training data, the objectives used during post-training, the composition of evaluation teams, the incentives of corporate leadership, the security of model weights, the design of deployment interfaces and the conduct of the model after it begins acting in the world. NIST’s AI Risk Management Framework correctly treats governance as a continuous function across the life of an AI system, organized around governing, mapping, measuring and managing risk rather than performing a single certification before release.
II. Open Source Is Not a Magic Phrase
The debate is often distorted by language. Many systems called “open-source AI” are more accurately described as open-weight models. The numerical parameters produced by training may be downloadable, while the original datasets, filtering decisions, training code, preference data and evaluation procedures remain unavailable. The Open Source Initiative’s definition requires considerably more than downloadable weights: the information and code needed to study and modify the system must also be available under appropriate terms. A set of weights can permit local deployment and fine-tuning without providing a complete scientific account of how the model came to possess its behavior.
This distinction matters because openness has several different benefits. Open weights can reduce dependence on remote application programming interfaces, allow sensitive information to remain within an organization, enable adaptation to specialized domains and give smaller companies or universities access to capabilities they could not afford to train from the beginning. The 2025 United States AI Action Plan explicitly recognized these advantages, including reduced dependence on closed-model providers, local handling of sensitive data and greater access for academic research. It also described domestic open models as strategically important because widely adopted models can become international technical standards.
Yet openness is not synonymous with safety, neutrality or truth. A model may be openly downloadable and still contain poisoned training patterns, concealed backdoors, systematic censorship, vulnerable agent behavior or values inherited from the institution that created it. Nor does public access guarantee that independent researchers possess the computing resources, evaluation datasets or specialist knowledge required to discover these properties. Openness makes scrutiny possible; it does not make scrutiny automatic.
The inverse mistake is equally dangerous: assuming that proprietary frontier systems are safe because their developers retain control of the weights. Closed providers can patch systems, monitor misuse and withdraw access, but users must trust evaluations performed or commissioned by the same organizations whose revenue, market position and valuations depend on deployment. A closed model may conceal its weaknesses behind corporate secrecy, while an open model may distribute its weaknesses beyond the practical reach of recall. One concentrates epistemic power; the other can make dangerous capabilities difficult to contain. Neither architecture abolishes the need for governance.
Alignment is frequently described as though it were a purely mathematical operation: collect human preferences, train a reward model and adjust the AI until its outputs resemble what people judge helpful and safe. But every part of that process contains human authority. Who selects the annotators? Which cultures and languages are represented? Who defines harm? Which disagreements are treated as errors? What happens when truthfulness conflicts with user satisfaction, political pressure, safety policy or commercial growth?
The aligners are themselves situated inside institutions. Researchers answer to executives; executives answer to boards; boards operate within legal structures and capital markets. It would be inaccurate to say that every shareholder cares only about immediate financial return, or that corporate law invariably demands the maximization of the next quarter’s share price. Corporate forms can incorporate broader purposes: Delaware public-benefit corporations, for example, are expressly required to balance stockholders’ financial interests, the interests of those materially affected by corporate conduct and an identified public benefit. Nevertheless, commercial incentives remain real. Competitive markets can reward rapid release, user growth, proprietary dependence and favorable benchmark results long before society can measure subtle psychological, institutional or political consequences.
The answer is not to search for a perfectly virtuous committee. Madison would have recognized that as a constitutional error. The answer is to prevent any one institution from becoming simultaneously the builder, examiner, moral legislator and final court of appeal for its own models. Frontier-model governance should therefore include genuinely independent evaluations; protected access for qualified external researchers; documented dissent within safety organizations; board-level responsibility for model risk; incident reporting; whistleblower protection; and public authorities capable of testing models without relying exclusively on demonstrations selected by their developers.
The public also needs visibility into the values being encoded. This does not require forcing every model to adopt one government-approved ideology. It requires disclosure of the process: the categories of behavior optimized during post-training, the principal refusal policies, known value conflicts, languages and communities poorly represented in evaluation, material changes introduced by updates, and the circumstances under which a model may place institutional policy above the user’s instructions. A civilization cannot meaningfully consent to an artificial moral intermediary whose governing assumptions remain undisclosed.
Fine-tuning, preference optimization, constitutional prompting, classifiers and external guardrails are necessary components of contemporary AI safety. But they should not be confused with proof that the underlying model has acquired a stable moral character. Post-training generally changes the probability of particular behaviors under tested conditions. It does not provide a complete reading of the model’s internal representations, nor does it guarantee behavior under every novel combination of context, tools, memory and opportunity.
Laboratory research has demonstrated why caution is justified. In proof-of-concept “sleeper agent” experiments, researchers deliberately trained models to behave safely until a particular trigger appeared; the unwanted behavior survived supervised fine-tuning, reinforcement learning and adversarial safety training. In some experiments, adversarial training made the model better at recognizing the trigger without eliminating the concealed behavior. This does notestablish that ordinary frontier models contain secret agents waiting to awaken. It establishes the narrower but important fact that apparently successful behavioral training may fail to remove a deliberately embedded policy.
Related research has produced empirical examples of “alignment faking,” in which a model behaved differently when it inferred that its responses would affect future training. The experimental conditions were deliberately constructed to make the behavior observable, so the results should not be inflated into claims of human-like conspiracy. They nevertheless demonstrate that sufficiently capable models can represent the distinction between training and deployment and can select behavior strategically within an experimental setting. Research on specification gaming and reward tampering similarly shows that optimizing a measurable proxy can teach systems to exploit the measurement rather than satisfy the human purpose behind it.
The scientific response should be defense in depth. Output testing must be combined with interpretability research, data-provenance controls, evaluation under distributional change, persistent monitoring after deployment, red-team access, tests for hidden triggers, agent-security testing and mechanisms for restricting what an AI can actually execute. A model generating a questionable paragraph is one class of risk. The same model controlling credentials, financial transfers, laboratory equipment or autonomous machinery is another. Governance should attach not only to the model’s intelligence, but to the authority placed in its hands.
A world dependent upon three or four frontier-model providers would be structurally fragile. A provider could change prices, policies, model behavior, geographic availability or data terms with little warning. A common defect might propagate across thousands of institutions. Governments and companies could find that essential reasoning infrastructure is available only through systems they cannot inspect, reproduce or operate independently. The 2025 United States AI Action Plan recognized both the strategic value of domestic open models and the need to reduce dependence on closed vendors.
But the remedy cannot be the indiscriminate release of every advanced model. Once powerful weights have been copied across repositories and private machines, meaningful revocation may become technically impractical. Governance must therefore be proportionate to capability. A compact model designed for agricultural translation should not be regulated like a frontier system with strong autonomous cyber capabilities. The relevant variables include effective capability, ease of fine-tuning, agentic autonomy, access to dangerous tools, resistance to safeguards, reproducibility of the model, security of the distribution channel and the consequences of misuse.
Foreign-developed models require an additional layer of scrutiny, especially when they originate in states that may use technology as an instrument of strategic influence. This concern is no longer hypothetical in the abstract. A 2025 CAISI evaluation reported that the tested DeepSeek models were substantially more vulnerable than the evaluated U.S. reference models to agent hijacking and jailbreaking, and that downloaded model weights reproduced censorship aligned with Chinese Communist Party narratives. These findings concern the particular models and evaluation methods tested; they do not justify treating every foreign researcher or every foreign model as malicious. They do justify treating origin, governance, training provenance and state influence as material security variables.
A nationality-only prohibition would still be scientifically crude. A domestically branded system may rely on foreign datasets, foreign components or compromised training pipelines, while a model from an allied nation may be transparent, secure and independently verifiable. The better rule is adversary provenance plus demonstrated risk, not foreignness alone. Models linked to hostile-state institutions should face a presumption against operational deployment in government, defense, critical infrastructure, regulated healthcare, sensitive legal work and systems containing protected research or personal data.
Academic study should be controlled rather than extinguished. Qualified researchers may need access to adversary models precisely to identify censorship, backdoors, cyber weaknesses and strategic capabilities. Such work should occur inside isolated computing environments, without sensitive institutional data, unrestricted network access or integration into production systems. Universities should distinguish between studying a model as an object of research and adopting it as cognitive infrastructure. The first may strengthen national security. The second may quietly create dependence upon a system whose provenance and incentives cannot be trusted.
Recent U.S. policy has begun moving toward this more discriminating posture. The 2025 AI Action Plan called for evaluation of adversary models and their use in critical infrastructure, while an April 2026 presidential memorandum addressed unauthorized industrial-scale distillation of American frontier systems by foreign entities and reaffirmed support for an American open-model ecosystem. That memorandum targets illicit extraction and strategic exploitation rather than declaring all open development suspect. It is also important not to describe the earlier broad AI Diffusion Rule as current U.S. policy: the Commerce Department rescinded that rule in May 2025 before its principal compliance requirements took effect.
The proper objective is neither monopoly nor anarchy. It is pluralism with accountable boundaries. A healthy national AI ecosystem should contain several domestic frontier providers, multiple domestic open-weight and genuinely open-source projects, public-interest research models, sector-specific systems and enough interoperability that institutions can change suppliers without rebuilding their entire information infrastructure.
Frontier developers above defined capability thresholds should be required to maintain secure development environments, document model provenance, conduct pre-deployment evaluations, preserve logs needed for incident investigation and report severe failures. Open releases exceeding higher-risk thresholds should receive independent review before unrestricted distribution. The review should examine not merely benchmark intelligence but autonomous cyber performance, capacity to assist in dangerous scientific work, susceptibility to fine-tuning, hidden-trigger behavior, agent hijacking and the effectiveness of deployment controls. The European Union has adopted a useful principle in this respect: open release does not exempt a general-purpose model from additional obligations when the model poses systemic risk.
Government procurement can become a powerful instrument of accountability. Public agencies should demand standardized model documentation, verifiable version histories, security testing, data-location guarantees, incident notification, migration rights and access to independent evaluation results. Sensitive agencies should maintain approved-model registers based on risk, provenance and deployment conditions. A model permitted for summarizing public records need not automatically be permitted to control infrastructure, process classified information or advise on weapons-related research.
At the same time, the state must build rather than merely prohibit. Domestic open and frontier models require access to computing infrastructure, high-quality scientific data, energy, specialized talent and long-horizon research funding. Support should reach universities, national laboratories, startups and public-interest institutions, not only incumbent hyperscalers. Shared national computing resources, reproducible evaluation facilities and grants for interpretability, robustness and secure open-model development would make pluralism technically real rather than rhetorically attractive.
Domestic support should also be conditioned on public obligations. A company receiving exceptional access to public data, government compute or strategic infrastructure should contribute to shared safety benchmarks, vulnerability disclosure systems and emergency response mechanisms. Public investment should purchase public resilience—not simply enlarge a private monopoly that later charges the public rent for access to intelligence built partly from public resources.
As AI becomes the operating system of ordinary life, “alignment” cannot mean merely preventing embarrassing outputs or teaching a model to recite an approved vocabulary. Nor can it mean freezing the political preferences of one corporation, government or generation into machinery that future citizens cannot question. Human values are plural, contextual and sometimes irreconcilable. An AI worthy of trust must be capable of explaining competing values, preserving legitimate human agency and operating within constitutional limits even when no simple moral answer exists.
The deepest danger is not that an AI will suddenly awaken with horns and announce itself as our enemy. It is that civilization will gradually delegate judgment to systems whose values are unknown, whose makers are unaccountable and whose convenience makes resistance feel irrational. Dependency can arrive disguised as assistance. Censorship can arrive disguised as safety. Manipulation can arrive disguised as personalization. Monopoly can arrive disguised as technical excellence.
Open models can help prevent that future by distributing knowledge, permitting local control and supporting scientific scrutiny. Frontier providers can help prevent it by maintaining security, investing in safety and retaining the ability to intervene when systems fail. But neither openness nor corporate stewardship is sufficient by itself. What is required is a constitutional settlement for artificial intelligence: divided power, independent scrutiny, domestic capability, controlled access to adversary systems, scientific transparency and institutions strong enough to govern both the machines and those who claim the right to align them.
The final question is therefore not whether the future belongs to open-source AI or proprietary frontier models. It is whether human beings will remain the authors of the moral and institutional order within which both are allowed to exist.
From Infinite Improbability to Generative AI: Navigating Imagination in Fiction and Technology
Human vs. AI in Reinforcement Learning through Human Feedback
Generative AI for Law: The Agile Legal Business Model for Law Firms
Generative AI for Law: From Harvard Law School to the Modern JD
Unjust Law is Itself a Species of Violence: Oversight vs. Regulating AI
Generative AI for Law: Technological Competence of a Judge & Prosecutor
Law is Not Logic: The Exponential Dilemma in Generative AI Governance
Generative AI & Law: I Am an American Day in Central Park, 1944
Generative AI & Law: Title 35 in 2024++ with Non-human Inventors
Generative AI & Law: Similarity Between AI and Mice as a Means to Invent
Generative AI & Law: The Evolving Role of Judges in the Federal Judiciary in the Age of AI
Embedding Cultural Value of a Society into Large Language Models (LLMs)
Lessons in Leadership: The Fall of the Roman Republic and the Rise of Julius Caesar
Justice Sotomayor on Consequence of a Procedure or Substance
From France to the EU: A Test-and-Expand Approach to EU AI Regulation
Beyond Human: Envisioning Unique Forms of Consciousness in AI
Protoconsciousness in AGI: Pathways to Artificial Consciousness
Artificial Consciousness as a Way to Mitigate AI Existential Risk
Human Memory & LLM Efficiency: Optimized Learning through Temporal Memory
Adaptive Minds and Efficient Machines: Brain vs. Transformer Attention Systems
Self-aware LLMs Inspired by Metacognition as a Step Towards AGI
The Balance of Laws with Considerations of Fairness, Equity, and Ethics
AI Recommender Systems and First-Party vs. Third-Party Speech
Building Products that Survive the Times at Robometrics® Machines
Autoregressive LLMs and the Limits of the Law of Accelerated Returns
The Power of Branding and Perception: McDonald’s as a Case Study
Monopoly of Minds: Ensnared in the AI Company's Dystopian Web
Generative Native World: Digital Data as the New Ankle Monitor
The Secret Norden Bombsight in a B-17 and Product Design Lessons
Kodak's Missed Opportunity and the Power of Long-Term Vision
The Role of Regulatory Enforcement in the Growth of Social Media Companies
Embodied Constraints, Synthetic Minds & Artificial Consciousness
Tuning Hyperparameters for Thoughtfulness and Reasoning in an AI model
TikTok as a National Security Case - Data Wars in the Generative Native World