Debates about technological risk usually offer two positions. One side sees increasingly powerful technology and concludes that we should accelerate: progress has made humanity richer, healthier, and more capable, and attempts to stop it will sacrifice enormous benefits while probably failing anyway. The other sees the same power and concludes that we should slow down, because some technologies create risks large enough to overwhelm those benefits. Both contain something true. Neither yields a policy, because technological development is not a single process moving at a single speed.
In The Missing Faction, I argued that estimates of AI risk do not determine what we should do about AI. A ten percent probability of catastrophe is not a policy. To get from a probability estimate to an intervention, we also need to know what the intervention changes, what it costs, what risks it creates, whether others will comply, and what happens if it fails. Someone can take catastrophic AI risk seriously without concluding that technological development should stop. I called that position Decimism: catastrophe is unlikely, but plausible enough that ignoring it would be reckless.
Vitalik Buterin has been developing a framework that begins where that argument leaves off. He introduced it in My techno-optimism, a reply to Marc Andreessen’s manifesto, and revised it a year later in d/acc: one year later. He calls it d/acc: decentralized and democratic differential defensive acceleration. Its central proposal is to accelerate technologies that make people and institutions harder to attack while preferring forms of defense that do not require concentrating enough power to control everyone else.
Technology Is Not a Scalar
Much of the argument over technological progress treats acceleration as though it were a throttle. Push it forward and technology advances faster. Pull it back and technology advances more slowly. But technology consists of thousands of interacting capabilities developing at different rates, and those capabilities alter risk in very different ways. Cryptography can outpace malware or fall behind it. Pandemic detection can outpace pathogen synthesis, and formal verification can outpace the growth of software complexity, or the reverse.
Once this is made explicit, indiscriminate acceleration and indiscriminate deceleration become strange policy categories. They collapse a high-dimensional problem onto a single axis. The “differential” in d/acc rejects that collapse by asking which capabilities should advance relative to which others.
AI makes the distinction especially important. Increasing the general capability of an autonomous agent and increasing our ability to inspect that agent are both technological progress, and they need not advance at the same rate. Neither do autonomous offensive cyber systems and automated vulnerability detection, or persuasive synthetic media and cryptographic authentication. The policy question for AI is what should accelerate relative to what.
Safety Without a Leviathan
A common response to dangerous technology is to control whoever possesses it. If sufficiently advanced AI could cause catastrophic harm, then perhaps access to advanced computation must be monitored, frontier models licensed, research restricted, chips tracked, networks surveilled, and enforcement coordinated internationally. There is an obvious attraction to this approach: if dangerous capabilities can be kept away from dangerous actors, some danger is reduced.
But the mechanism introduces another variable into the risk calculation: the institution powerful enough to impose the controls. An organization capable of reliably preventing billions of people from developing or using a prohibited technology requires substantial powers of observation and enforcement. Those powers can be captured, abused, expanded beyond their original mandate, or simply used incompetently. A system intended to reduce distributed technological risk can therefore replace some of it with concentrated institutional risk.
Buterin makes this concern central. His complaint about most plans to save the world is that they hand a small group extreme and opaque power and hope it is used wisely, and his restatement asks for safety that works without assuming “the good guys (or good AIs) are in charge.” The preferred technologies reduce vulnerability directly and so reduce how much coercive governance is required.
Computer security is a useful, if imperfect, model. It gets most of its safety from architecture rather than from keeping attack techniques secret: memory protection, privilege separation, sandboxing, rapid patching. Law and institutions still matter, but technical architecture reduces how much safety depends on identifying and controlling every possible attacker.
The principle generalizes. Better air filtration makes a respiratory pathogen less dangerous regardless of who released it, and cryptography protects messages without requiring a trustworthy censor. Distributed infrastructure reduces what sabotage can accomplish by removing single points of failure.
That yields a default rule for technological risk. Before constructing an authority powerful enough to stop an attacker, ask whether the environment can be changed so that the attack is harder to execute, easier to detect, or less damaging when it succeeds.
What Counts as Defense?
The hardest problem for d/acc is that “defensive technology” is not a natural category. A wall is defensive when it stops an invading army, but with general-purpose information technology the distinction blurs. An AI system capable of finding security vulnerabilities can find them for defenders or attackers. A model capable of analyzing pathogens can help design vaccines or biological weapons. Better automated reasoning can verify software or discover ways around its protections.
Buterin concedes that classification will be imperfect and compares it to freedom, where ambiguity at the edges is a reason to learn the concept’s nuances rather than abandon it. For general-purpose information technology the ambiguity sits at the center. The risk is that d/acc becomes a labeling exercise, since every developer can describe what they are building as defensive. If the distinction depends on intentions rather than causal effects, differential defensive acceleration has not told us what to accelerate.
The answer has to operate below the level of broad technological categories, at mechanisms that change a system’s structure in predictably defensive ways. They come in three kinds, which address different failure modes and should not be treated as interchangeable. Hardening makes successful attack more difficult: cryptography, authentication, secure hardware, and formal verification of specified properties. Containment reduces the consequences of failure: least privilege limits the authority available to a compromised component, sandboxing bounds arbitrary behavior, compartmentalization limits propagation, and redundancy removes dependence on any single part. Power dispersion reduces the leverage available to any one actor, through decentralization, local control, and distributed infrastructure.
None of these is intelligence-proof. A capable adversary may attack the specification, the hardware, the operator, or the supply chain. Formal verification cannot rescue a bad specification, and a sandbox is only as good as the boundary enforcing it. What these mechanisms do is convert unconstrained failure into narrower failure modes, raise the cost of successful attack, and reduce the blast radius when something goes wrong.
Nor does any of this establish that conventional containment will hold against a system with overwhelming strategic or technological superiority. A superintelligent system may find vulnerabilities that human designers missed, manipulate its operators, or open paths around constraints that looked robust at lower capability. Before that point, capability boundaries can still reduce risk, limit intermediate failures, constrain resource acquisition, and perhaps keep some systems from reaching the capability at which the boundaries stop being reliable.
Much alignment discussion concerns what an advanced system will want, believe, or decide. Security engineering has never relied entirely on correctly predicting the motivations of software. It assumes components can fail and tries to limit what failure can accomplish, which is why containment has to be designed to survive alignment failure. An AI system that can access every credential, modify every process, copy itself freely, communicate without restriction, and acquire resources autonomously presents a different risk from an equally capable system operating with explicit privileges, independently enforced boundaries, restricted channels, and limited authority. The intelligence may be the same, but the path from local failure to wider damage is not. Buterin’s own preference for AI as tools over highly autonomous agents, and his interest in architectures that split an AI’s planning, execution, and perception into separately overseen components, is containment applied to cognition.
Not every technology marketed as defensive belongs on the d/acc side of the ledger. If a frontier reasoning model improves formal verification but simultaneously creates a larger increase in offensive cyber capability, calling the application “defensive” does not settle the matter. The unit of analysis is the whole intervention, including the capabilities needed to build and deploy it.
When Defense Loses
d/acc is most attractive when technology can materially shift the offense-defense balance. It is much less useful when the underlying domain strongly favors offense and defensive improvements cannot keep pace.
Some cybersecurity environments exhibit this problem. An attacker may need to find only one exploitable path while a defender must secure many. Biological threats can create a similar asymmetry if dangerous capabilities diffuse faster than detection, containment, treatment, or infrastructure can respond. In such domains, more decentralized defense may not be enough if offensive capability crosses a threshold beyond which a single successful attack can cause irreversible harm.
Buterin took this as the most compelling objection to his original post: on short AI timelines, accelerating the good is insufficient, and the bad has to be slowed. His 2025 answer offers two instruments. The first is liability, placed as close to end use as possible, with a variant that holds the owners of any equipment an AI hijacks liable for what it does with it, giving everyone an incentive to secure the world’s infrastructure. The second, if something more muscular proves necessary, is a global soft pause: the capability to cut worldwide available compute by 90 to 99 percent for one or two years at a critical moment, enforced by trusted chips in industrial-scale hardware that keep running only with weekly signatures from several international bodies.
So d/acc, in its author’s hands, already concedes that some danger has to be met with restriction rather than more defense. If a particular offensive capability is cheap, scalable, difficult to detect, and capable of causing irreversible damage before defensive systems can respond, narrowly restricting it may reduce total risk more than relying on resilience after diffusion.
A narrowly defined prohibition can still require broad enforcement powers if the prohibited activity is hard to observe. The institutional cost of a restriction depends on what must be monitored to enforce it as well as on what is forbidden. A capability that passes through a few visible bottlenecks can be constrained with limited authority. One that can be developed privately and diffusely may require surveillance extending far beyond the activity being regulated.
Buterin’s pause is designed around this variable. It targets industrial hardware because that is where the bottleneck is visible, stops short of consumer machines to avoid putting kill switches in laptops, and makes authorization all-or-nothing so that no government can quietly exempt its own military. Its residual cost is visible too. A requirement that every signing body sign gives each of them a veto over the world’s industrial compute. That is a narrow power, halting without directing, but it is a real one, and it goes in the ledger.
A restriction that reduces one technological danger by creating pervasive monitoring and discretionary intervention may still be justified, but its institutional costs are part of the calculation, not incidental to it. The tradeoff between technological risk and concentrated authority cannot always be engineered away, only minimized.
The framework therefore turns on an empirical question: can the offense-defense balance be moved in a given domain? Where hardening, containment, or distributed resilience reliably raise the cost of attack or reduce its consequences, accelerate them. Where offense keeps a large structural advantage, add restrictions on the most dangerous offensive capabilities.
Decentralization Has Failure Modes Too
Decentralization can increase proliferation, multiply inconsistent security practices, widen the attack surface, and make dangerous capabilities harder to contain. Buterin knows this. He rejects decentralized acceleration without the defensive component, since an offense-favoring world stays exposed to catastrophe or to someone installing himself as protector, and his experience keeping Ethereum’s client software diverse makes him doubt that a balance among many AIs would be stable. A centralized system can sometimes enforce standards or respond to emergencies faster than a distributed one.
The two architectures fail differently. Centralization reduces coordination costs and raises the consequences of capture, error, abuse, or institutional collapse. Decentralization removes single points of failure and increases variance, duplication, and the diffusion of dangerous capability.
The d/acc case is strongest where defensive properties survive distribution. Cryptography, local authentication, compartmentalized infrastructure, and capability-based security can often provide protection without requiring one institution to exercise broad discretionary authority over everyone else. In those cases, decentralization reduces the dependence of safety on the continued competence and benevolence of a central controller.
Axionic ethics treats concentrated authority over others as a cost that requires justification. On that accounting, a safety mechanism is worse when it works only by giving an institution enough power to impose large-scale constraints on people who have not consented to them. d/acc’s attraction is that it reduces danger by changing technological affordances instead of relying on discretionary control.
Centralized intervention is sometimes justified. Some threshold risks are easier to stop at a bottleneck than to contain after proliferation. But centralized power belongs inside the risk model. The regulator, coordination body, laboratory consortium, or surveillance system is another actor with failure modes, incentives, and attack surfaces, and a safety analysis that treats such institutions as neutral instruments has left out a term.
The Epistemic Problem
Even if we agree that interventions should be judged by their net effects on offense, defense, resilience, and institutional power, those effects are difficult to know in advance.
Technologies are developed under uncertainty, and their creators have obvious incentives to emphasize intended benefits while discounting externalities. A system built for vulnerability discovery may strengthen cybersecurity or automate exploitation. A biological platform built for rapid vaccine design may also lower barriers to dangerous experimentation. A monitoring system introduced for narrowly defined safety purposes may later become infrastructure for much broader control.
Judging by net effect therefore cannot be bookkeeping over quantities already known. Claims that a technology is defense-favoring need adversarial analysis, independent evaluation, and explicit examination of how the capability alters incentives and opportunities outside its intended use.
Uncertainty also makes reversibility important. An intervention whose effects can be observed, contained, and rolled back is easier to justify than one that irreversibly diffuses a dangerous capability. Staged deployment, restricted trials, and compartmentalized access preserve the ability to change course when assumptions turn out to be wrong. Where the expected benefits are large and the downside is poorly understood, preserving optionality is itself a defensive property.
The Cost of Standing Still
Restraint has no zero-risk baseline, a case I made in The Safe Path to Extinction. Slowing one technology delays its benefits along with its dangers, and broad restrictions postpone better diagnostics, cleaner energy, stronger infrastructure, and improved defenses against existing threats.
The more distinctive problem is strategic, and Buterin states it directly: in a world that is not totalitarian, standing still is unstable, because whoever finds deniable ways to keep advancing gets ahead. When the prohibited capabilities offer large economic or military advantages, the actors that continue developing them gain leverage over those that abstain. Maintaining a sufficiently broad prohibition may eventually require extensive monitoring and enforcement, which can recreate the concentration-of-power problem the prohibition was meant to solve.
Some dangerous capabilities may still be constrainable at acceptable cost, and some bottlenecks are visible enough that regulation can meaningfully reduce risk. Nuclear nonproliferation, which Buterin also cites, shows that dangerous technologies can sometimes be restricted for long periods.
But “slower” cannot be treated as synonymous with “safer.” The comparison is always between concrete interventions and their counterfactuals. A civilization that suppresses useful defensive technologies while offensive capabilities continue to diffuse may become less safe. A civilization that prevents technological risk only by constructing an extremely powerful surveillance regime may exchange one class of danger for another.
Postscript
d/acc does not provide an algorithm for deciding which technologies deserve acceleration, and AI makes the problem especially hard because intelligence is unusually dual-use. It provides a better structure for asking the question, and it answers the policy question The Missing Faction left open for Decimism without collapsing it back onto a single axis.
A technology qualifies as defensively useful only when its expected defensive gain exceeds the offensive capability it introduces, the institutional power required to deploy it, and the new failure modes it creates. Those estimates are uncertain, and they should be challenged adversarially and revised as evidence arrives. Where uncertainty is large, reversible and containable deployments deserve preference over irreversible diffusion.
Favor interventions that reduce blast radius, increase verifiability, strengthen local control, eliminate single points of failure, raise the cost of attack, or reduce the amount of discretionary authority required for safety. Scrutinize interventions whose protective effects are overwhelmed by larger gains in offensive capability, whose consequences cannot easily be reversed, or whose success depends on concentrating broad power in institutions that themselves become dangerous failure points.


