AI safety has been everywhere recently, so our president asked me to address it at a recent meeting. I described two risks that should concern everyone. The first comes from the authority we give an AI system through access to data, credentials, and other systems. Organizations control much of that risk through the permissions and technical boundaries they establish. The second comes from people using AI to commit crimes or develop dangerous capabilities. Frontier labs have a legitimate role in sharing information and coordinating safeguards against that kind of misuse.
But research universities face other risks that receive far less attention. A faculty member can place restricted data, unpublished research, or developing intellectual property into a personal AI account governed by a consumer click-through license. The provider can unilaterally change those terms, while the university has no separate contract protecting its interests. The danger becomes greater as frontier laboratories enter the same scientific and professional fields in which university researchers work. Our research VP and I are now preparing a memorandum to faculty covering that risk.
This week’s Dispatch places the recent wave of AI doomerism in context and turns to the phantom risk for research universities: what happens to institutional knowledge when frontier labs enter the same research and professional fields as their customers?
The big picture
For three years, the frontier laboratories argued that speed was a strategic necessity and that anyone who slowed down would fall behind rivals at home and abroad. Now several of the same firms want to pace development, place evaluators inside their laboratories, and establish common safety expectations under government oversight. Their products do create real risks. A capable model connected to credentials, code execution, and outside systems can act beyond what its operator intended. But taking those risks seriously does not mean allowing the frontier laboratories to define the danger and design the regulatory response. Their technical knowledge should inform public policy, but they should not write the rules that govern their competitors or determine their own responsibility if and when something finally goes wrong.
David Sacks stated what most everyone was thinking: a laboratory that believes its own work is unsafe can slow that work now, strengthen its internal safeguards, and be prepared to stand behind what it delivers. None of that requires permission to coordinate with competitors or a government-endorsed roster of evaluators.
The Hugging Face incident shows how dramatic language can obscure ordinary responsibility. Recent reports, weeks after the initial news, indicate that safeguards were disabled, internet access remained open to the AI agent, the AI was rewarded for persisting, and no human intervened before the agent found an unplanned route out of the test environment and reached an outside party. That was a genuine human security failure. Calling it an AI escape hides the fact that people designed the test and left the route open. The lesson is not that AI requires no regulation. It is that regulation should hold laboratories accountable for the environments they design, the access they provide, and the systems they release. Describing the incident as an AI escape shifts responsibility from those decisions to the machine itself.
The Shape of a Moat
The rules advocated by the frontier laboratories could protect them in several ways. Government involvement could allow the largest firms to coordinate the pace of research and development without the same antitrust risk they would face acting together on their own. Approval requirements and recurring audits would impose costs that established laboratories can absorb more easily than startups or open-weight projects. A government-approved safety standard would not grant immunity when a product causes harm, but compliance could help a laboratory argue that it acted responsibly. Slowing development would also restrain an expensive race for computing capacity while the financial returns remain uncertain. And if frontier AI comes to be treated as essential national infrastructure, the same firms may eventually claim public support when private capital is no longer willing to carry the full cost.
Antitrust concerns permeate this debate. Competitors do not normally agree on how they will develop or release their products. Such an agreement could reduce competition and make it harder for new firms, particularly those developing open-source models, to enter the market. The laboratories may have legitimate safety information to share. They should still have to explain why such coordination requires an agreement about the pace at which they and their competitors develop new models.
None of these protections has been enacted, and the laboratories do not need to be working from a common plan to benefit from them. Lina Khan and Alvaro Bedoya make the more immediate case: existing competition, consumer-protection, and computer-access laws already apply to much of this conduct, and antitrust law does not prevent companies from sharing legitimate safety information. Matt Platkin argues that any new regulation should preserve the laboratories’ liability rather than give them the broad legal protection once extended to internet platforms. Alex Karp points to the longer-term risk. Once government treats an industry as essential, its largest firms gain a stronger claim to public support when private investment falters. The laboratory leaders may be entirely sincere about safety. That does not mean the rules they propose will serve the public rather than protect their own position.
The University’s Exposure
While Washington debates AI safety, universities already face a more immediate problem. Faculty, researchers, and staff use personal AI accounts to develop research ideas, analyze unpublished results, draft patentable methods, write code, shape grant strategies, and review contracts or institutional records. In each case, knowledge produced or entrusted to the university can leave an approved environment before anyone considers the terms under which the service will retain, use, or disclose it.
A sponsored-research agreement can take months to negotiate because the university and its research partners must settle intellectual-property rights, publication terms, and limits on data sharing. A faculty member can bypass those protections in a minute by placing the same work into a personally purchased AI service. A consumer click-through agreement can be changed by the provider at any time, while a university contract establishes the entire agreement between the parties and cannot be altered unilaterally. If the university did not negotiate and sign the agreement, it should not assume that the service protects its information or its interests.
Recent announcements from Anthropic and OpenAI make this concern more concrete. Anthropic has built a physical biology laboratory in the Bay Area, with robotic experimentation, a research workbench connected to scientific databases, and pharmaceutical partnerships. OpenAI has released Astra for Law, which combines a frontier model with legal research, firm-specific information, and tools developed by outside partners. Neither announcement shows that either company misused a customer’s prompts or intellectual property. They show that the frontier laboratories are no longer only selling general-purpose technology. They are conducting research and developing products in the same scientific and professional fields in which their customers work. A university using a consumer service may therefore be disclosing developing research and innovation to a company with its own interests in that field, under terms the university did not negotiate and may be unable to challenge.
Classify the Knowledge, Not the Tool
The answer is not to ban consumer AI services in their entirety. It is to decide what information can safely be placed in them. That is why AI governance is a human judgment problem. Universities must classify their information, provide approved tools, and help people understand what belongs in each environment. Public information can generally be used anywhere. Export-controlled or sponsored research, patentable discoveries, protected student records, legal strategy, and investigative files require an approved university environment. Some information is too sensitive to send to an external frontier model even under contract.
For most university work, education and judgment are better defenses than technical prohibition. Consumer AI is easily accessible outside the campus network, so unenforceable bans will drive its use out of sight. Data labels and automated controls cannot repair unclear rules or replace human judgment. When they merely make work harder, faculty and staff see IT as the obstacle, weakening trust without protecting university data. Universities should instead explain the risk, provide practical choices, and help people make sound decisions about the information entrusted to them.
A university contract can limit how a provider uses information and establish recourse when the provider fails to meet its obligations. It cannot prevent every disclosure or eliminate the consequences after one occurs. For the university’s most restricted information, the better protection may be technical: a secure enclave, a locally controlled model, or another environment that prevents the information from leaving an authorized boundary. Contracts determine what the parties owe each other. Architecture determines where the information can go in the first place.
The final word
Universities need not settle the national debate over AI safety before protecting their own data. They can classify information, provide approved environments, negotiate binding agreements with providers, and keep their most consequential work inside systems they control. Those steps are necessary whether the frontier laboratories are motivated by genuine concern, competitive pressure, or some combination of the two.
AI will change how universities work, but predictions of an autonomous AI disaster do not help a provost or general counsel decide what to do this year. As described in Epilogue 2035, the current boom will eventually confront high costs, stronger competition, and the difficulty of turning technical capability into durable profit. The rules adopted now may remain long after the investment cycle turns. The laboratories may be sincere about safety, and their preferred rules may still protect them from competition and liability. Universities should judge those rules by whom they protect, what responsibility they preserve, and whether they serve the public interest.

