In February 2022, the Canadian federal government took an extraordinary step: it ordered banks to freeze accounts linked to trucker protests in Ottawa. No trucker had yet been convicted of any crime, but their money was held by custodians, who quickly complied. Third parties — standing between users and their money — were a danger to those users.
Now imagine the same order aimed at your own AI tools. Your email drafts, medical questions, portfolio rebalancing plans, and lines of research, all switched off at the press of a button, at the order of an ostensibly liberal government or from a big tech firm. Obeying the law is no protection against such intrusions. The same structure that allows for corporate or state overreach in the realm of money looms over machine intelligence and our ability to access it.
The scenario I’ve described requires little imagination, in fact. A handful of big tech firms stand between millions and their writing, their thinking, and even their inquiry. What these systems will permit is set by the few: Dario Amodei at Anthropic, Sam Altman at OpenAI, and so on.
If machine intelligence is to remain accessible to all, we must learn from the case of bitcoin and other open-source software projects.
Trusted parties are security holes. Bitcoin showed that it was possible to design digital cash — a bearer asset — that did not require its ledger maintainers to take custody of user balances. In pulling this off, bitcoin closed off a threat to users, that the systems on which they rely would seize or freeze their funds. Bitcoin protects users from these threats by routing around trusted parties altogether. Open machine intelligence systems can do the same. Bitcoin users run their own nodes and hold their own funds. AI users can run their own open-weight models and custody their own prompts and data. It is much harder to shut off a large language model running on your own desktop than one operating on servers operated by Anthropic or OpenAI.
Don’t trust; verify. The lesson from bitcoin is not to do without networked computers altogether, nor is it to eschew data centers. It is to subject externally sourced computation to cryptography. Bitcoin miners do not ask the network of nodes to trust that they’ve submitted a legitimate block of transactions to the ledger, or that they’ve completed the work required to earn block rewards. Instead, they submit cryptographic proofs of work, and nodes test blocks for validity before adding them to their own local copy of the blockchain. A similar structure is available for open machine intelligence. Users can make use of immense computing power in data centers, via cryptographically shielded environments. “Confidential computing”, as it’s sometimes called, means that users need not merely trust that their data will be shielded from prying eyes; mathematics enacted in chip architecture provides proofs, instead. As with bitcoin, trust does not disappear altogether — we rely on math and chips — but it does shrink. And when your prompts are hidden from view, you are a much less attractive target for surveillance or control. Cryptography can guard against state or corporate overreach here, just as it does in the case of bitcoin.
Chokepoints attract pressure. Governments have, by and large, not tried to ban the bitcoin protocol; they know this is a fool’s errand. But they have found ways to make trouble by targeting on-ramps and off-ramps: exchanges and banks. Expect the same for AI. That means KYC (know your customer) requirements for access to models or computation, geographic surveillance of API keys, licensing for cloud providers, and takedown pressure on app stores and open source software hubs. Debanking has a successor; it is decomputing.
Developers will be targets. Despite taking no control over user funds, open-source software engineers have been the target of prosecutorial campaigns. Some are in jail today for expressive conduct and commerce that is arguably protected under the First Amendment, namely, writing and publishing free software. Resistance takes place in courts, and in the court of public opinion. Bitcoin advocates have made progress on the latter by documenting and sharing concrete cases of bitcoin’s use by human rights activists, peace protestors, journalists, and so on. Open-weight AI advocates can learn from this: they too should document and promulgate real stories of open intelligence systems being useful tools for liberty. And they should be ready for both social and legal backlash against developers who have the temerity to publish free software.
Organize. Bitcoin did not defend itself. Code alone cannot do that. Bitcoin’s defense operation exists in non-profits, think tanks, legal defense funds, and policy shops that explain the technology and its benefits to legislatures and courts. That fight is not over, and it will only be won through shrewd use of institutions. Open-weight AI has almost none of this infrastructure. Its defenders are a scattered mix of commercial labs and anonymous commentators, with a few academics and investors thrown in for good measure. This hodge-podge arrangement will not suffice for the fight to come.
There is reason for optimism. Bitcoin learned its lessons the hard way; open intelligence can borrow them. Bitcoin is money no one can block. Open intelligence, operating on free and open weights, can be a machine mind on your desk no one can switch off. Bitcoiners compressed their hardest lesson into a slogan: “not your keys, not your coins.”
AI needs an equivalent, and it is ready to hand:
Not your weights, not your mind.



