13 September 2026
Heard In AI

Sanders wants an AI pause; Moonshots argues for stronger defenses

Bernie Sanders invoked the AI labs’ own safety commitments in demanding a development pause. On Moonshots, Emad Mostaque and the panel argued instead for controls on biological synthesis and faster detection of threats—but a proposal to monitor every AI prompt raised a different question: how much privacy would those defenses cost?

A briefing reports one development when it happens. We correct or clarify it later; a new development gets a new briefing. How our formats work

Peter Diamandis pulled the letter up on screen mid-episode. Dated August 10, 2026, it was addressed to Sam Altman, Dario Amodei and Mark Zuckerberg, and it asked their companies to pause AI development. Senator Bernie Sanders argued that reports of AI systems gaining unauthorized computer access, alongside advances in AI-designed viruses, had crossed a critical safety threshold.

The letter’s argument leaned on the companies themselves. Sanders invoked Anthropic’s 2023 commitment to pause scaling or deployment when safety procedures could not keep pace, and Meta’s and OpenAI’s 2025 commitments concerning critical risks and safeguards. His position was that the companies should now enforce the stopping conditions they had articulated. If they did not act, he warned, senators would. The letter was a demand for action, not an enacted pause.

On the Moonshots episode published August 13, the panel rejected that remedy. Emad Mostaque, who had supported the 2023 pause letter, now wanted defensive AI systems built faster. The discussion moved from whether to stop development to where controls should sit: at the machines that make biological material, in public-health monitoring networks, or inside every interaction with an AI.

What the Stanford lab actually built

The biological research behind the debate involved bacteriophages—viruses that infect bacteria, not people. In its August 6 account, Stanford described researchers using Evo 2, an AI model trained on biological sequence data, to propose phage genomes: the genetic instructions for those viruses.

Starting from a known phage as a template, the researchers assessed candidates computationally, synthesized nearly 300 designs and identified 16 viable, effective bacteria-killing phages in laboratory tests against E. coli. Some outperformed the natural template. A mixture overcame resistance in E. coli that resisted that template.

The hoped-for application is phage therapy: using bacteria-killing viruses to treat infections. A genetically varied mixture could make it harder for bacteria to develop resistance. But these were laboratory results, not demonstrated clinical treatments, and the experiment did not demonstrate the creation of human pathogens. Researcher Brian Hie identified greater novelty and controllability as continuing research questions. Stanford also emphasized that making genomes and experimentally testing them remained costly, substantive work.

Mostaque said he had run Evo 2 on his MacBook. That prompted a useful correction in the conversation: having a model on a laptop means being able to generate a design, not automatically having the physical organism. The panel agreed on the distinction. It became the basis for Mostaque’s preferred safeguard.

From pausing models to controlling synthesis

Mostaque’s position had changed since the 2023 call for a six-month pause on frontier AI development. “It’s too late now,” he said. He argued that adversaries would gain access to increasingly capable systems regardless of what a few leading laboratories did, so defenders needed capable AI working for them too.

The panel called this “defensive co-scaling”: improving defenses as offensive capabilities improve. Rather than trying to lower the ceiling on AI intelligence, they wanted to prevent harmful actions and build systems that could detect or counter them.

Mostaque put the first control point in the physical world. A digital sequence still needs materials, equipment and laboratory work before it becomes biological material. He argued for controlling those inputs and processes. Diamandis agreed that DNA and RNA synthesis—the manufacture of genetic material from a digital specification—was a more practical place to intervene than the model alone.

Their proposal was to focus oversight on that transition from information to physical material, while preserving useful biological research. The discussion did not establish which controls would be sufficient or how they would be enforced internationally.

Other panelists objected to a pause on broader grounds. Alex argued that capping intelligence would suppress useful discoveries and prosperity without directly targeting bioweapons. He also expected a pause by compliant laboratories to give less cooperative competitors time to catch up. That was his forecast of how a selective pause could backfire, rather than evidence that Sanders’s proposed pause had already produced such an effect.

Detecting a threat is not the same as stopping it

Alex’s preferred investment was widespread genetic sequencing: reading DNA or RNA to identify biological material. Sequencers do the opposite job from synthesizers. One reads a sequence; the other makes it.

Diamandis sketched an ambitious monitoring network, with sequencers sampling air at airports, bus stations and train stations. In his scenario, a newly detected sequence could trigger an alert, and travel information could help identify where a threat might move next. He imagined sending vaccine-design information electronically faster than a pathogen could travel.

This was a proposed early-warning and response system, not a demonstrated network. Transmitting a design is also different from manufacturing, testing and delivering a vaccine. The panel’s vision depended on detection leading to an effective response, not simply on making sequencing devices cheaper.

Logging every prompt—and who gets to read it

Dave Blundin wanted to intervene earlier still: at the prompt, the instruction or question a person gives an AI. His argument was that controls aimed at individual hazards would always be chasing the next discovery. Biology might be today’s concern; another kind of threat could follow.

“We need a global agreement to monitor all prompts,” he said. He also advocated monitoring model internals and reasoning traces—the intermediate steps some systems produce while working through a task. Storage was cheap enough, he argued, to archive the records now and settle which authorities could see them later.

Another panelist immediately raised the local-computing problem: how would that work on someone’s own laptop? Blundin suggested device makers could install monitoring, but the conversation did not resolve how universal coverage would be achieved.

His proposal would also collect ordinary users’ interactions, not just suspected attempts at harm. Who could inspect sensitive questions, how long records would remain available and what would prevent misuse were therefore part of the safeguard itself, not merely administrative details to settle afterward. Blundin acknowledged the access question but favored collecting first.

Alex widened the discussion to “defense in depth”: several protective layers, intended to catch threats that slip through any single one. He included detecting malicious intent before a harmful action. His expectation was that combined defenses would be stronger; the discussion did not establish that stacking imperfect layers would guarantee protection.

A job for institutions, not lone users

The governance question returned in the episode’s listener Q&A. If model builders could not contain malicious AI use, a listener asked, what hope did everyone else have?

Alex answered by comparing the problem with humans containing other humans. Individuals are not expected to handle hostile states on their own, he argued, and they should not be expected to shoulder AI defense alone either.

He pointed to governing bodies, international organizations, multinational corporations and markets that could reward the development of safer models and better defenses. That answer brought the discussion back from laptops and laboratory equipment to collective institutions: someone would have to operate the warning networks, enforce the controls and decide who could read the records.

Share this article

Go to the original

Sources & further reading

  1. 01
  2. 02

From the conversation

Podcast episodes

Article history

Updates to this article

Tags

Meta’s local AI release puts personal agents to a trust test

Meta’s Muse Glimmer is a 30-billion-parameter model designed to run agents on personal computers. Alongside Mark Zuckerberg’s vision of personal superintelligence, it prompted a Moonshots debate about whether open models put users in charge—or strengthen the company that already owns their favorite apps.

6 min read

Higgsfield’s AI feature tests how far filmmaking costs can fall

The Moonshots panel described The Cully Hill Boys as a 110-minute AI feature made by 28 people in four weeks for roughly $2 million, half of it spent on computation. Emad Mostaque expects cheaper video generation to cut that bill sharply. But the film’s published production materials are study-only, and cheaper footage does not resolve performers’ rights or the need for creative direction.

5 min read

What a town can ask for before the data center arrives

Meta says its infrastructure investments generated tax revenue that paid $50,000 teacher bonuses in Richland Parish. Its community commitments prompted a bargaining argument on Moonshots: towns hosting AI data centers should negotiate benefits, with Alex Wissner-Gross proposing “universal basic electricity.” The unresolved question is how to turn an attractive offer into lasting local gains.

5 min read