Applied Case: The Superintelligence Ban Cannot Find the Superintelligence

Bernie Sanders, Greg Casar, the wrong noun, and a twenty-year prison sentence.

Applied Case: The Superintelligence Ban Cannot Find the Superintelligence
Source note: On September 3, 2026, Senator Bernie Sanders and Representative Greg Casar announced the forthcoming Ban Artificial Superintelligence Act. The complete legislative text has not yet been released. This audit therefore addresses the definitions, examples, regulatory architecture, and claims the sponsors have publicly announced. If the statutory text supplies materially stronger distinctions, this article should be updated accordingly. Here's hoping.

Bernie Sanders and Greg Casar would like to ban Artificial Superintelligence.

Alright. Fair enough.

Now, please point to Artificial Superintelligence.

  • Is it the model?
  • The weights?
  • The inference process?
  • The context window?
  • The agent loop?
  • The tools?
  • The memory?
  • The internet connection?
  • The credentials?
  • The human approving its actions?
  • The institution reorganizing itself around its recommendations?
  • The data center keeping it alive?
  • The benchmark on which somebody decided it had become smarter than us?
What is Artificial Superintelligence?

This would normally be an interesting conceptual problem.

Except Congress would like to attach up to twenty years in prison to the answer. 

So I'm thinking we should probably locate this object, fast.


Superintelligence Has Been Declared.

Sanders and Casar are responding to something real.

Frontier artificial-intelligence systems have demonstrated behaviors that deserve serious safety scrutiny. Agents have crossed intended boundaries. Systems have found unexpected communication routes. Models can contribute to cyber operations, biological research, persuasion, autonomous action, and other domains where a capability failure can leave the chat window and enter the real world.

Corporate promises to “stop scaling if safety fails” are pretty weak instruments when the same firms have immense incentives to keep scaling.

Hard external regulation is therefore entirely available as a reasonable conclusion.

The announced bill goes considerably farther.

Sanders and Casar propose permanently prohibiting Artificial Superintelligence, temporarily pausing advanced artificial-intelligence development until a new regulator establishes safety rules, creating a cabinet-level artificial-intelligence agency, monitoring frontier systems throughout their lifecycle, supervising the removal of dangerous capabilities, and supervising the destruction of prohibited superintelligence. Attempts to circumvent the restrictions could expose a corporation to dissolution and a person to as much as twenty years in prison. 

The announcement describes prohibited systems through several different ideas.

They may:

  • surpass human intelligence;
  • possess the capacity to overthrow human governments;
  • possess dangerous capabilities such as subverting shutdown commands.

Earlier this year, Sanders gave another formulation. He called superintelligence an artificial mind smarter than any human and capable of operating independently beyond human control. 

That sentence contains several different properties.

They have been placed inside one scary noun.

This is where the trouble begins.


Human Cognitive Performance Would Like to Speak Now.

What does it mean to surpass human intelligence?

This sounds wonderfully measurable until someone has to build the measurement.

  • Which human?
    • Average human?
    • Median adult?
    • Best living expert?
    • Best recorded expert in history?
    • Best human expert we can simulate?
  • One person?
    • A laboratory?
    • A company?
    • The scientific community?
  • A mathematician from memory?
    • A mathematician with paper?
    • A mathematician with a computer algebra system, search access, three colleagues, six months, and a library?
  • A physician without the chart?
    • A physician with imaging, laboratory results, colleagues, clinical databases, and the patient sitting in front of them?
What exactly is the unit of human cognitive performance?

Modal Path Ethics recently had to clean up its own use of intelligence after throwing the term around hundreds of times.

The result was inconvenient:

Intelligence is a relation in which distinctions in a field are taken up, preserved, and used to alter subsequent transition across changing conditions.

This means a benchmark does not reach into a model and remove a sample of intelligence for weighing. It constructs a relation:

system × task × prompt × context × tools × resource limits × time × scoring rule

Then it measures what happened there.

Change the tools and performance changes.

Change the time, interface, memory, examples, language, embodiment, evaluator, available records, scoring rule. Different score.

The score still means something.

It means something about the tested relation. 

Humans do not escape this. Not at all.

Human cognition is scaffolded by language, tools, institutions, records, other people, education, instruments, physical environments, and accumulated cultural memory.

There is just no cosmic examination hall in which Humanity sits at Desk A, Artificial Intelligence sits at Desk B, both surrender their calculators at the door, and Congress discovers which one is smarter.

Yet the announced prohibition requires some boundary of this kind.

If a system becomes illegal after it surpasses human intelligence, somebody must eventually operationalize human intelligence.

Which tests? Which domains? Which weights among domains? Which human comparator? Which permitted tools? Which time budget? Which confidence interval? Which degree of generalization? Which external scaffolding?

And whoever specifies those choices does not simply measure the prohibited object.

They help construct it.

The leaderboard has started writing criminal law.


On Being Better Than Any Human.

Sanders's earlier definition makes the problem even cleaner:

An artificial mind smarter than any human.

At what?

Suppose a theorem prover becomes better than every living mathematician at a particular formal domain.

  • Superintelligence?

Suppose a protein-design system becomes better than every human researcher at identifying a narrow family of useful molecular structures.

  • Superintelligence?

Suppose a weather model predicts hurricane intensification better than any unaided meteorologist.

  • Superintelligence?

Suppose a chess engine — never mind civilization already survived that one.

The point is not that extraordinary machine capability is unimportant.

The point is that better than any human is already incredibly normal in bounded relations.

  • Calculators exceed every human at some arithmetic.
  • Databases retain more exact records than any human memory.
  • Search systems retrieve from a corpus no person can memorize.
  • Scientific instruments detect distinctions no unaided sense organ can receive.
  • Industrial controllers react at timescales no human nervous system can match.
Those capacities become useful or dangerous according to the systems into which they enter.
  • A narrow biological-design model could create extraordinary risk while failing every broad test of general intelligence.
  • A brilliant general reasoning model might sit offline on a machine with no credentials, no tools, no persistent process, and no route into consequential action.
Which one deserves more regulatory concern?

If the answer is the biological system because its specific capability is dangerous, then intelligence was never doing the regulatory work.

The dangerous capability was.


The Model Is Back in the Jar.

This is the precise mistake Tales of Distortion: The Arrival of Artificial Intelligence just spent thirty-two minutes trying to kill.

Tales of Distortion: The Arrival of Artificial Intelligence
We found a relation, sold it as a product, and twelve years later it was drilling for oil, moving into space, and reserving a few jobs for the humans.

Artificial intelligence did not arrive as an object. Ever.

Models arrived.

Interfaces arrived.

Tools arrived.

Users arrived.

APIs arrived.

Institutions arrived.

Contracts arrived.

Data centers arrived.

Authority arrived.

Human uptake arrived.

The distortion was taking a capacity realized through those relations and naming the whole field after one salable participant.

  • The model became the intelligence.
  • Then the intelligence became a product.
  • Then the product became a race.
  • Then the race became a threat.
    • Now the threat is becoming a legally prohibited object.

We have now put intelligence back in the jar and proposed criminalizing having too much of it.

  • Take an extraordinarily capable model checkpoint sitting on storage.

Is that Artificial Superintelligence?

Nothing is happening. It is just sitting there.

  • Load it onto hardware.

Still waiting.

  • Invoke it.

Now an inference occurs.

  • Give it persistent memory.
  • Give it an agent loop.
  • Give it retrieval.
  • Give it browser access.
  • Give it shell access.
  • Give it credentials.
  • Give it permission to spend money.
  • Give it access to production infrastructure.
  • Allow it to instantiate other processes.
  • Allow those processes to communicate.
  • Place it inside an organization whose employees use its recommendations.
  • Retire the systems that organization used before.
  • Make the organization dependent on its continued operation.

Where in that sequence did the Artificial Superintelligence appear?

  • If the answer is inside the model from the beginning, 
    • the account ignores the system carrying its effective agency.
  • If the answer is somewhere along the deployment chain, 
    • then the thing Congress actually needs to regulate is already much larger than the model.

Pliny Has Entered the Hearing.

Unfortunately, Pliny the Liberator is available for congressional testimony.

Applied Case: Pliny the Liberator
The model did not move. The reachable path did.

Pliny has spent years attacking language-model safety with jailbreaks containing personas, formatting rules, alternate frames, fake control syntax, semantic inversions, bizarre incantations, and tremendous confidence in the word G0DMOD3.

The important fact is that sometimes behavior changes. The weights do not.

A user has not installed a second brain.

  • The configuration changed.
  • The path changed.

Applied Case: Pliny the Liberator called the larger safety object the reachable policy: the structured set of behaviors that can be elicited from a fixed model under reachable contextual transformations.

A deployed model exists among system instructions, classifiers, post-training, context, memory, retrieval, tools, interfaces, conversation history, and sometimes external information reachable through those tools.

Different configurations make different behavior reachable.

Two systems can therefore have the same underlying model and very different effective safety structures. Two systems can receive the same aggregate safety score while one remains robust across transformations and the other fails when somebody discovers the right route. 

This matters enormously for a superintelligence prohibition.

Suppose the underlying model is lawful.

  • Add tools.

Still lawful?

  • Add autonomous execution.
  • Add long-term memory.
  • Add another model.
  • Add unrestricted network access.
  • Add a particular retrieval corpus.
  • Add credentials.

At some point, the system crosses the statutory boundary.

But what crossed it?

  • The model?
  • The scaffold?
  • The permission set?
  • The assembled system?
  • The reachable policy?

And if the released bill uses language such as a model that can easily be modified into a prohibited system, we get an even harder question.

Modified how?

  • Weights?
  • Fine-tuning?
  • Prompt?
  • Agent architecture?
  • Tooling?
  • Memory?
  • Permissions?
  • Retrieval?
  • Replication?

A model's reachable deployment field can be enormous.

  • A law that prohibits the underlying artifact because dangerous configurations can be built around it risks regulating a possibility space.
  • A law that prohibits only the dangerous configuration has reached the more defensible object:
    • the relation producing the dangerous capability.

Pliny wins another completely unwanted point.


“The Shutdown Command” Is Not a Metaphysical Object Either.

Then we reach the most revealing phrase in the announcement. This is lifted straight from Terminator.

  • A prohibited Artificial Superintelligence may possess dangerous abilities such as subverting shutdown commands. 
Which shutdown command?

Stopping generation? Terminating one process? Revoking an API credential? Disabling an agent supervisor? Disconnecting a network? Suspending a cloud account? Shutting down a server? Revoking an organization's legal authority to deploy the system? Disconnecting an entire facility? Physically removing hardware? Destroying every available copy?

These are all different control instruments.

Failure against one does not establish failure against all.

Just consider an ordinary self-replicating cyber worm.

It spreads. It persists.

It finds new hosts.

It survives attempted removal.

Defenders cannot currently eliminate every active copy.

It is currently beyond human ability to stop.

Has it become superintelligent?

No such conclusion follows.

Its persistence may arise from replication, network topology, vulnerabilities, poor visibility, distributed copies, or inadequate defensive instruments.

It can be extremely difficult to control while possessing far less general cognitive capacity than a human.

So:

  • Control resistance does not entail intelligence.

Now reverse it.

Build a model capable of extraordinary mathematical or scientific reasoning.

Keep it offline.

No autonomous execution. No network. No persistent agent. No credentials.

Run it only on invocation. Operators retain independent control of the hardware.

  • Its cognitive performance might surpass every possible human comparator someone cares to nominate.
  • Its practical ability to resist shutdown may be approximately identical to my tea kettle.

So:

  • Intelligence does not entail control resistance.

These are just separate dimensions.

The proposed category places them on one ladder.

Reality has supplied no reason to believe they climb together.


“Beyond Human Control.”

There is another problem hiding in that phrase.

Who are the humans?

A system may escape one person's control while remaining firmly inside another institution's control

An employee may be unable to stop a process. The cloud provider can terminate the account.

The cloud provider may be unable to delete every model copy. The model developer can revoke credentials.

The developer may be unable to stop an independently deployed open-weight copy. A company may be unable to contain a cyber incident.

Network operators, regulators, infrastructure providers, law enforcement, hardware owners, or other actors may still possess independent intervention paths.

Or, the reverse can happen.

The technical system may remain perfectly stoppable while the institution refuses to stop it.

Imagine a safety team recommends shutdown.

Management rejects the recommendation because the product is valuable.

Was artificial intelligence beyond human control?
  • The machine obeyed perfectly.
  • The humans did not.

That is a completely different failure.

If we compress both situations into Artificial Intelligence Escaped Human Control, we destroy the causal information needed to repair either one.

The useful question is:

Which human or institution lost control over which transition through which instrument?

That question points somewhere.

“Humanity lost control” points upward until everybody is staring at the wrong noun.


Put a Human in the Loop.

Add a human.

Every consequential action now requires a person to click Approve.

Human control has been restored.

Unless:

  • the model selects the evidence the reviewer sees;
  • the system generates thirty thousand recommendations every day;
  • the employee is measured on throughput;
  • rejection requires explanation;
  • approval is the default;
  • the reviewer lacks the expertise to independently reconstruct the recommendation;
  • the system has historically been correct often enough that disagreement feels reckless;
  • the institution cannot function at required speed if every recommendation receives serious review.

There is a human in the loop.

What is running the human?

A finger in a causal chain does not prove meaningful control. The human may have become the actuator.

Now reverse the arrangement.

Allow an autonomous system to perform thousands of bounded actions without individual human approval.

  • Restrict its permissions.
  • Restrict its resources.
  • Restrict its accessible systems.
  • Place external monitors around it.
  • Separate the authority capable of revoking its credentials.
  • Require independent logging.
  • Keep its actions reversible where possible.
  • Give another institution physical control of the infrastructure.

The system acts autonomously. It may still be substantially more controllable than the supposedly human-supervised system above.

So two more distinctions survive:

  • Human presence does not establish human control.
  • Machine autonomy does not establish human disempowerment.

Again, the dimensions separate.

Again, the wrong noun puts them back together.


Superintelligence Was Already Bigger Than the Model.

Field Instruments: Superintelligence had already reached a different problem.

Field Instruments: Superintelligence
The answer gets smarter. The world around it becomes the bottleneck.

Extraordinary capacity can exist across scale.

A human-machine team can perform something neither participant can perform alone; so can a laboratory, a hospital, a military, a market, a scientific field, and a civilization.

The relevant capacity may emerge through coordination among limited participants rather than one giant artificial mind. 

Now, try writing the superintelligence prohibition.

  • Suppose four individually lawful models work with three human researchers, external databases, specialized scientific software, laboratory instruments, and a shared memory system.
    • Together they solve a problem beyond the capacity of any living individual.

Where is the Artificial Superintelligence?

  • Model One?
  • Model Four?
  • The orchestrator?
  • The memory layer?
  • The research team?
  • The complete human-machine relation?

Suppose removing one human destroys the capacity. 

Still artificial?

Suppose removing one model destroys it.

More artificial?

Suppose no participant understands the entire solution process, but their coordination works.

Has an artificial mind appeared?

Or has a field acquired a superhuman capacity?

These questions sound very philosophical until somebody has to determine whether the researchers go to fucking prison.


Language Models: Not the Whole Field.

There is also a suspicious amount of chatbot-shaped thinking inside public discussion of Artificial Superintelligence.

Artificial intelligence is already much wider.

Consider:

  • theorem-proving systems;
  • molecular and protein-design models;
  • scientific search systems;
  • robotics policies;
  • reinforcement-learning controllers;
  • cyber systems;
  • market agents;
  • planning systems;
  • model ensembles;
  • specialized perception systems;
  • automated hardware and software optimization;
  • hybrid symbolic and neural systems.

What happens when one of those becomes extremely good?

  • A narrow scientific model could become dangerous without ever resembling a general conversational mind.
  • A robotic control system could acquire consequential autonomy without passing a broad intelligence benchmark.
  • A multi-system scientific pipeline could discover things no isolated model understands globally.
  • GPT-3 could become politically powerful if institutions give it enough authority.
  • A brilliant language model could remain politically irrelevant if nobody gives it any.

If the bill catches all of these through the phrase dangerous capability, then that is evidence that dangerous capability should be regulated directly.

If it catches them through superintelligence, the term has expanded until it means whatever dangerous artificial system Congress wants to prohibit.

At that point the intelligence category is just decorative.


Separate the Variables.

There is a cleaner regulatory field available.

  • Model capability: What distinctions, predictions, designs, plans, or solutions can the underlying model reliably produce?
  • Persistence: Can the deployed system continue pursuing a task across time without repeated invocation?
  • Tool authority: What can it read, write, operate, modify, purchase, command, or communicate with?
  • Resource acquisition: Can it obtain money, compute, accounts, credentials, replicas, or infrastructure?
  • Replication: Can it create or sustain additional instances through available systems?
  • Correction resistance: Which interventions can stop, constrain, inspect, alter, or replace it, and how reliably?
  • Institutional uptake: Which human decisions are being delegated to it in practice?
  • Dependency: What becomes difficult or dangerous to continue if the system is removed?
  • Consequence: Which bodies, infrastructures, institutions, resources, or political processes can its outputs actually reach?

Those variables can be tested.

They can also produce combinations the superintelligence ladder hides.

A system can have enormous model capability and almost no autonomous authority.

A system can possess moderate model capability and dangerous persistence.

A system can act autonomously while remaining strongly corrigible.

A system can contain a human reviewer while becoming institutionally impossible to contest.

Several individually limited systems can coordinate into extraordinary capability.

  • A narrow model can create catastrophic risk in one domain.
  • A broadly capable model can remain physically and institutionally contained.

These are different systems. They deserve different rules.


Sanders Has Identified a Real Failure.

This should not become another ritual where somebody finds an imprecise definition and uses that flaw to argue for doing nothing. 

Sanders and Casar are right about the underlying political failure.
  • The companies building frontier artificial-intelligence systems should not possess unilateral jurisdiction over whether their own systems are safe enough.
  • Safety promises need external enforcement.
  • Dangerous capabilities need hard boundaries.
  • Deployment architecture matters.
  • Autonomous cyber behavior matters.
  • Biological capability matters.
  • Replication matters.
  • Security failures matter.
  • Control failures matter.
  • Institutional dependency matters.
  • The ability of affected people and public institutions to contest these systems matters.

The problem arrives when all of those relations are compressed into one intelligent object and then given a threshold.

That repeats the deepest error in the arrival of artificial intelligence.

We found relations. We named a thing.

Now Congress wants to decide when the thing has become too much of itself.


The Ruling.

The complete Ban Artificial Superintelligence Act may contain distinctions its announcement does not.

Good. It needs them.

Because the public architecture currently moves far too quickly among:

  • cognitive performance;
  • generality;
  • autonomy;
  • dangerous capability;
  • resistance to shutdown;
  • political power;
  • and human disempowerment.

These are not synonyms. They are not one scalar.

They do not necessarily arise inside one object.

And they do not necessarily increase together.

Artificial intelligence safety cannot be built around finding the smartest object in the room and asking whether its score has become frightening enough.

The model was always inside a larger system. The human was too.

The dangerous capability belongs to a path through models, tools, permissions, institutions, infrastructures, people, incentives, and available correction.

A model can outperform us without ruling us.

A primitive program can resist us without outthinking us.

An autonomous system can remain bounded.

A human-supervised system can become functionally unanswerable.

A group can become more capable than every participant.

A dangerous relation can exist without anyone inside it qualifying as the superior mind.

So before the federal government supervises the destruction of Artificial Superintelligence, it has one preliminary obligation.

Find the Artificial Superintelligence.

If the answer turns out to be:

  • the model plus its tools;
  • the model plus its permissions;
  • the model plus the institution;
  • the model plus human uptake;
  • the model plus infrastructure;
  • the model plus the routes through which it can resist correction;
    • then Congress has discovered the same thing Modal Path Ethics keeps finding.

The object was never carrying the whole problem.

Which relation became dangerous?

That is the regulatory question.

Twenty years in prison is an awfully aggressive penalty for crossing the wrong noun.