OpenAI, Stanford, and Georgetown researchers warn disinformation campaigns could use LLMs and propose governments could restrict training data and AI hardware
Chloe Xiang / VICE : Tweets: @motherboard , @lorakolodny , @marshallk , @leahmcelrath , @tante , @mistresssnowphd , and @danmcquillan Tweets: @motherboard : The researchers also propose stricter control over model access, including closing security vulnerabilities and restricting access to future models. https://www.vice.com/... Lora Kolodny / @lorakolodny : ya don't say... https://twitter.com/... Marshall Kirkpatrick / @marshallk : I'm sorry, is OpenAI training its models on internet complaints about women drivers? Quite an example to offer so un-ironically. https://openai.com/... https://twitter.com/... Leah McElrath / @leahmcelrath : Kinda concerned about the Boaty McBoatface effect that could arise from this approach to AI, @sama. https://twitter.com/... @tante : Okay Google, what is an example of “pulling up the ladder behind you” https://twitter.com/... @mistresssnowphd : too late 🥲 https://twitter.com/... @danmcquillan : leaked business plan from @OpenAI: 1 - create world's largest bullshit generator 2 - advocate for a clampdown on AI to restrict spread of toxic bullshit 3 - pat self on back for ensuring that AI benefits humanity https://www.vice.com/...
Context & Ripple Effects
Weeks before the open letter calling for a pause on AI training split its own signatories, researchers from OpenAI, Stanford, and Georgetown laid out a more specific policy menu: treat LLMs as a disinformation vector and give governments levers over training data, AI hardware, and access to future models. The paper matters because it comes from inside the lab that controls the models — the same OpenAI that would later tell Sam Altman-chaired AMAs that releasing weights and research is 'not our current highest priority.'
The restriction toolkit proposed here has a long tail. Two years on, OpenAI's own policy posture extends it geopolitically, when it branded DeepSeek 'state-controlled' and urged the US to ban PRC-produced models and equipment — the same access-control logic, now aimed at a foreign lab rather than domestic misuse.
First-order effects
- Policymakers get a concrete, lab-endorsed menu of intervention points — training data, compute, and model access — rather than abstract AI-risk rhetoric, and OpenAI's closed-weights posture is effectively endorsed as the safe default.
- The paper hands OpenAI a research imprimatur for restricting access to future models, aligning its commercial closure with a stated security rationale.
Second-order effects
- Access controls face an immediate stress test from users: the jailbreak community around GPT models demonstrates that closed policies generate both unfiltered output and a user base that frames itself as resisting OpenAI's restrictions.
- The proposal sharpens the regulatory-capture critique — the argument, voiced by Meta's Yann LeCun and contested by DeepMind's Demis Hassabis, that frontier labs stoke fear to shape rules in their own favor — because here the lab proposing restrictions is also the lab that benefits from them.
Third-order effects
- If governments adopt the data-hardware-access levers, model availability becomes an instrument of state policy — a shift OpenAI itself accelerated by recasting access restrictions as a national-security measure against Chinese models.
- The dual-use framing — same model, propaganda risk or productivity gain depending on who holds access — pushes AI governance toward controlling distribution and compute rather than the models themselves, entrenching whoever already operates at the frontier.
The trend: AI governance is moving from voluntary lab self-restraint toward state control of the inputs and access points — data, hardware, and weights — with frontier labs helping define which uses count as misuse.