Lock up the weights
Model-weight security standard. Protect unreleased frontier weights against theft by well-resourced attackers.
What it does
Labs must protect unreleased models from theft by skilled attackers, including foreign spies, with strict access controls and monitoring.
Applies to: Frontier developers holding unreleased model weights.
- Implement security controls for unreleased model weights at a defined level (RAND's SL3, roughly: resistant to well-resourced non-state and moderately resourced state actors).
- Describe the controls in the published framework (SB 53 requires this).
Where things stand
Anthropic's ASL-3 standard and OpenAI's security commitments already target this level. SB 53 requires large developers to describe their weight-security practices. The mandate sets a floor under current practice.
Why it gains ~1 day
Stronger protection costs under a day of U.S. progress. It makes a stolen U.S. model less likely, which on balance slightly widens the lead.
Biggest unknown: The probability that frontier weights get stolen in a given year, which nobody outside the labs and intelligence agencies can estimate.
Why it lowers p(doom) by ~0.15%
Stops hackers and foreign spies from stealing the most powerful models.
Whoever steals a model's weights can strip out its safeguards. Strong security keeps dangerous models out of the wrong hands.
The strongest case that it costs more
A higher price would argue that security standards, once regulated, ratchet toward the paranoid: access controls that slow every engineer, air-gapped clusters and clearance requirements. That is the next item on the menu. At the SL3 level, the honest steelman is that the China-side benefit is speculative; it may be zero if theft was never the channel.
The debate
For
- RAND defined five security levels for protecting model weights, up to nation-state attackers, 2024.
- Anthropic activated ASL-3 protections focused on securing model weights, 2025.
- Institute for Progress proposed a national sprint to reach the highest security level, 2025.
- California SB 53 requires frameworks to cover security of unreleased model weights, 2025.
Sources
Rough starting points, not precise forecasts. Lead costs assume China doesn't depend on U.S. models, the case least favorable to safety laws, and count 3 years. On the menu you can change every assumption and put in your own numbers. Last priced 2026-09-26.