Extended Discourse on MAIM: Does Hardening Work?
Clarifying The Positional Incentives Argument
One of the most likely counterarguments to my positional incentives analysis is that even if the incentives point in the direction of U.S. undermining MAIM, the country’s efforts to prevent sabotage will ultimately be futile, because (1) it is extremely difficult to prevent sabotage, and (2) effective security efforts will likely end up slowing development.
However, I believe neither claim withstands scrutiny; here are my counterarguments.
1. The U.S. has strong reasons to harden AI infrastructure regardless of MAIM
Proponents of MAIM will likely argue that increased security investment to prevent sabotage is not likely to be worth the high cost, in both the money investment required and the speed trade-offs such security measures would incur. However, even without superintelligence concerns, preventing China from stealing US AI advances is a strategic priority, and one that should rationally receive investment accordingly. Companies are already incentivized to prevent theft for commercial reasons, and the U.S. government is incentivized to prevent adversaries from stealing AI capabilities that have military applications.
This means the framing is not “should we accept slowdown to reduce sabotage risk?” but instead “what is the additional cost for MAIM-specific hardening1 beyond the baseline security investment we should already be making?” I believe the delta is smaller than MAIM proponents suggest.
Moreover, if the incentive is to race, and the race matters, then hardening actually makes the trade-off worth it— because without it, your opponent can immediately copy whatever you develop through espionage, effectively ‘teleporting’ to your technological level. Without hardening, the U.S. bears all development costs while China gets the benefits nearly for free. In that sense, hardening isn’t a racing slowdown relative to China; instead, it’s preventing China from matching U.S. speed by stealing the country’s technological advances.
2. Strategic ambiguity is achievable and sufficient for deterrence
Additionally, I think the “hardening is futile” argument overstates how much opacity is actually necessary. Achieving complete opacity, or even something marginally close to that, is almost certainly impossible and would involve trade-offs that are not worth making. However, I’d argue that strategic ambiguity is very possible— in that I think the U.S. could reduce China’s confidence in its timelines to a sufficient degree that it would be too risky for China to MAIM.
Consider the difference between China knowing that the U.S. is likely to achieve ASI / DSA in March 2029, vs. China knowing that the U.S. is likely to achieve ASI / DSA sometime between 2028-2031. Without precise timing, China faces substantially greater risk when considering a MAIM strike: they would essentially be risking war over uncertain belief of a breakthrough. This uncertainty deters action even when stakes are high, because the costs of being wrong (triggering escalatory retaliation) remain constant while confidence in the necessity of action drops. Strategic ambiguity only requires sufficient uncertainty to make the risk calculation prohibitive.
Beyond the technical feasibility of hardening, history shows the U.S. consistently chooses defense over voluntary vulnerability.
3. The U.S. only accepts vulnerability when hardening is technologically impossible
I am unaware of any similar historical precedents where the U.S. accepted vulnerability rather than attempting hardening when hardening was technologically feasible. When considering the nuclear arms race, the space race, etc., in cases where the U.S. believes it can achieve decisive strategic advantage through technology, it races aggressively, accepts enormous costs and risks, does not coordinate with rivals, and only accepts limitations when advantage is impossible.
Why did the U.S. accept international coordination with nuclear weapons (to some degree)? I’d argue this is because mutual vulnerability in nuclear deterrence is unavoidable, but this is not the case with AI.
Consider Reagan's Strategic Defense Initiative. Despite knowing it would destabilize MAD, despite Soviet protests, Reagan pursued it aggressively. It ultimately failed not because the U.S. chose restraint, but because the technology didn't work and countermeasures made it economically futile. This reinforces the pattern: the U.S. pursues defense whenever feasible, and only accepts vulnerability when defense is technologically impossible.
The AI parallel is straightforward: hardening AI infrastructure is both technologically and economically feasible. History suggests the U.S. will pursue it, regardless of whether doing so undermines cooperative deterrence frameworks.
One might object: “Modern missile defense technologies have advanced significantly since SDI's failure, yet we're still not pursuing a MAD-breaking defense system—doesn't this contradict your claim that the U.S. always hardens when feasible?”
Not quite. In the world of nuclear, there’s another element that disincentivizes destabilizing projects like SDI: they are destabilizing precisely because mutual vulnerability already exists. A successful U.S. defense would break MAD by allowing America to strike with impunity while remaining protected; other countries may correctly perceived this as preparation for a first strike.
Now consider a counterfactual: If no other country had developed nuclear weaponry yet— if the U.S. was currently the sole nuclear power considering whether to build defenses against a potential future adversary— would it hesitate for an instant? I think not. The U.S. would build the defense precisely to maintain its advantage and prevent other countries from achieving parity.
MAD teaches us that the U.S. sometimes restrains itself when both sides are already vulnerable. It does not teach us that the U.S. will voluntarily forgo defenses when it's ahead. MAIM asks the leader to accept vulnerability before rivals have achieved parity— the opposite scenario from MAD, and one where historical precedent suggests the U.S. will pursue hardening aggressively.
Conclusion
Essentially, MAIM asks for the leading actor to opt into mutual vulnerability by choice. This points to the crux of the issue: deterrence theory says something like, “when vulnerability is unavoidable, equilibria emerge around it.” I do not think vulnerability is unavoidable with AI.
Economically, hardening makes sense regardless of MAIM. Technically, strategic ambiguity is sufficient and achievable. Historically, the U.S. chooses hardening over maintaining stability through mutual vulnerability. With AI, defense is feasible, meaning the U.S. is rationally incentivized to pursue it rather than cooperate with frameworks requiring voluntary vulnerability.
The next post I’ll be doing on MAIM will be about the practical implications of my positional incentives argument; if you have thoughts— feel free to reach out! Also, I’m always open to stress-testing of my arguments— if you spot a hole in my logic or have a different take, I’d love to hear it.
By “hardening,” I mean a range of security measures, including: air-gapping sensitive systems, distributing infrastructure across multiple geographically dispersed facilities, improving cybersecurity and access controls, implementing stricter personnel vetting, maintaining operational security around development timelines, etc. This is not primarily about physical hardening (e.g., underground datacenters), but rather about reducing the probability of successful remote sabotage through layered defensive measures.
Another note I want to make re: hardening is that in Superintelligence Strategy, hardening is framed as difficult, time-consuming, and cost-prohibitive, with the major example being building datacenters underground to increase resilience to kinetic strikes. However, there is a substantially easier way to almost certainly deter kinetic strikes: building datacenters near populated areas, the inverse of what Superintelligence Strategy suggests to maintain mutual vulnerability.


Good article! I'm hoping to write something similar on the practical feasibility of MAIM. Some thoughts:
"This means the framing is not “should we accept slowdown to reduce sabotage risk?” but instead “what is the additional cost for MAIM-specific hardening beyond the baseline security investment we should already be making?” I believe the delta is smaller than MAIM proponents suggest.
Moreover, if the incentive is to race, and the race matters, then hardening actually makes the trade-off worth it— because without it, your opponent can immediately copy whatever you develop through espionage, effectively ‘teleporting’ to your technological level. Without hardening, the U.S. bears all development costs while China gets the benefits nearly for free. In that sense, hardening isn’t a racing slowdown relative to China; instead, it’s preventing China from matching U.S. speed by stealing the country’s technological advances."
This section makes the argument that necessary hardening and MAIM-specific hardening is nearly one and the same, by virtue of the fact that a) the cyberdefenses needed to prevent against model theft are already very comprehensive, and b) that physical defenses won’t need to be implemented, because they could be sidestepped by placing targets close to cities.
I roughly agree with point a). B), on the other hand, presumes that physical destruction (a “hard kill”) is the only alternative to remote sabotage. But there are probably many “soft kill” approaches either country could take before they’d escalate to this extent. One of these options is to use an EMP device to bake the GPUs within the datacenter: these could be delivered through conventional cruise missiles like HiJENKS (which would only need to fly nearby), or have a swarm of drones carrying e-bombs. Likewise, local power could be easily taken out, either by using cyberattacks on the plants providing the electricity (as Russia repeatedly showcased in Ukraine), or by using small graphite bombs to take out the on-site grid connection.
Of course, these options would be less certain than just bombing the building outright, but they’re 1) still plausibly effective enough to permanently disable the compute, and 2) can serve as a limited demonstration of rival capabilities and commitment, increasing the credibility and deterrence effect of possible kinetic strikes.
It’s also worth noting that, throughout the Cold War, the U.S. did in fact avoid placing its ICBMs and missile silos near cities, despite the fact that this would have reduced the credibility of Soviet threats.
“By “hardening,” I mean a range of security measures, including: air-gapping sensitive systems, distributing infrastructure across multiple geographically dispersed facilities, improving cybersecurity and access controls, implementing stricter personnel vetting, maintaining operational security around development timelines, etc. This is not primarily about physical hardening (e.g., underground datacenters), but rather about reducing the probability of successful remote sabotage through layered defensive measures.
Another note I want to make re: hardening is that in Superintelligence Strategy, hardening is framed as difficult, time-consuming, and cost-prohibitive, with the major example being building datacenters underground to increase resilience to kinetic strikes.”
It is not obvious to me that this level of great-power cyberdefense (something like the SL5 standard) could actually be implemented so smoothly (or that it’s possible in the first place—even the NSA gets hacked). In particular, integrating remote clusters with extremely long network interconnects and airgapping research would development fragile and less efficient. These are engineering problems without existing solutions, and in the case of airgapping, would impose ongoing efficiency penalties (since researchers would lose the ability to pull from external datasets, easily train models online, or collaborate across sites synchronously).