The 0.002% Problem: Anthropic's R&D Automation Index and the 26% Nobody Can Audit

0xPomp β€’ β€’ Trading

One in forty-seven thousand.

That's the ratio Anthropic handed the world this month, tucked eleven pages deep into a document about how much of its own research and development its own model now runs. Out of roughly every 47,000 decisions a Claude agent made inside the company's research pipeline, exactly one got stopped by a safety monitor. Everything else cleared.

I didn't need the rest of the deck. That ratio told me more about the state of frontier AI governance than the headline number it was packaged with.

Here's the headline anyway. By August 2026, Claude was "leading" β€” Anthropic's word, not mine β€” twenty-six percent of the company's R&D tasks, under human supervision. In February of the same year, that figure sat below one percent. Six months. From a rounding error to more than a quarter of the work. Ninety percent of research and engineering at the firm now involves model collaboration at some level. And the top rung of the autonomy ladder β€” the one where the model runs the whole thing and nobody sits in the chair β€” is still empty. Zero. Not one task.

That gap is the story. Twenty-six percent up. One hundred percent not.

Chaos isn't a model running loose in a lab. Chaos is a company telling the world it's slowing down while its own dashboard shows it flooring the accelerator.

Five days before this document landed, Dario Amodei published an essay arguing for deliberately slowing frontier AI development. Sam Altman boosted it. Elon Musk boosted it. Demis Hassabis boosted it. Five days later, Anthropic shipped an index showing its own model automating a quarter of its own research.

Same week. Same company. Two directions.

I've been covering this industry since 2017, back when I was twenty-six years old and treating ICO whitepapers as optional reading because the Telegram group was moving faster than the PDF. I learned something in that cycle that has held up through every boom since: when a company's marketing and its engineering point in opposite directions, the engineering is telling the truth. Marketing lies on purpose. Code lies by accident.

So let me be precise about what this document is. It is not a technical paper. There's no novel architecture in it, no scaling law revision, no benchmark crown. It's a governance disclosure β€” an attempt to define a vocabulary for how autonomous AI research has become, published at the exact moment the industry needs that vocabulary to exist.

And it's unaudited. Self-reported. Generated by the entity being measured, using a prototype index that entity helped shape, in a document that entity chose to publish.

That matters. I'll show you why. But the numbers are startling enough that they deserve to be taken seriously before they get taken apart.

CONTEXT: The Ladder, the Lab, and the Lawsuit

Let me set the table, because if you're coming to this from the crypto side β€” and most of my readers are β€” the vocabulary is new even though the stakes will feel familiar.

Anthropic is the lab behind Claude. Founded in 2021 by a group of OpenAI defectors who left over direction and safety disagreements, it has spent four years building a brand around one claim: we take this seriously. That brand isn't decoration. It's the moat. It's why enterprise procurement teams sign, why regulators take meetings, why the company can charge enterprise rates that make the public API pricing page look like a rounding error.

The document is the R&D Automation Index. The framework behind it comes from Epoch AI, an independent research outfit that proposed a six-level scale for measuring how much AI research is performed by AI. AL0 through AL5.

At AL0, no AI involvement at all. At AL1, AI assists β€” autocomplete, search, summarization, the tools every developer already uses. Somewhere in the middle bands, the model starts carrying real weight. At AL5, the system runs the entire research process end to end, with no human in the loop at any stage.

That's the ladder. Anthropic is now reporting where it sits on it, publicly, with the implication that the numbers will be comparable quarter to quarter.

The company also disclosed that roughly 30,000 agents are engaged in research and engineering work at any given moment. It disclosed that six percent of its AI R&D compute goes to safety-related uses, and twelve percent of its AI-driven AI R&D compute goes to safety. It disclosed a Bay Area wet lab where Claude directs robotic experiment equipment. Physical science. Pipettes and plates, not code and text.

And it disclosed all of this in the same month Reuters reported the company is weighing an early release of a new model to counter GPT-6 Astra, ahead of a potential IPO.

Now the contrast that makes the whole picture legible.

On September 15, 2026, OpenAI ruled out a 2026 IPO, citing its safety obligations. Read that sentence twice. OpenAI β€” the company with the most aggressive commercial posture in the industry, the one that turned a research lab into a consumer product company in eighteen months β€” publicly traded growth for safety cover. Meanwhile Anthropic, the company whose entire identity is safety, is reportedly accelerating toward both a model launch and a listing.

I'm not claiming Anthropic is lying. I'm noting that identical behavior reads differently depending on which logo is on the building.

There's a third element, and it's the one that should worry anyone holding AI-adjacent assets. A class action antitrust suit has been filed alleging that Anthropic, OpenAI, SpaceXAI, and Google used safety as a pretext to form a cartel that restricts output. The filing doesn't say they talked. It says they agreed to hold back β€” and that the holding back was the point.

A fourth: Anthropic has proposed a FINRA-style safety regulator for AI. Industry-designed oversight, industry-adjacent governance, modeled on a structure the securities industry built for itself.

If you've been in crypto for more than one cycle, you already know that pattern. You've seen it in exchange self-regulatory organizations. You've seen it in foundation councils with impressive names and three signers. You've seen it in decentralization roadmaps that never quite arrive. The industry writes the rulebook, volunteers to be governed by it, then discovers the rulebook happens to describe the industry's existing structure.

I should note what the market did with all this, because I sit close to that book.

Agent-adjacent tokens β€” the ones pitching decentralized autonomous research, agent payment rails, verifiable inference β€” didn't move on the substance. They moved on the headline. The 26% number got screenshotted, stripped of its footnotes, and reposted as proof that autonomous agents have arrived, which is exactly the misreading the document's own zero line refutes.

That's the thing about a disclosure like this. It arrives in a market that will read the loudest number and ignore the most careful one. If you're holding anything in the agent infrastructure basket, the number you should have written down is not 26. It's zero. It's 0.002%. It's six.

I've watched this exact pattern. In 2021 I stood in rooms in Miami where people priced JPEGs off celebrity tweets, and the fundamentals of the collection β€” the artist, the contract, the unlock schedule β€” were treated as fine print. The fine print was the asset. Everything else was the marketing.

Same document. Same trap.

One framing note before the deep dive. Everything above is dated to a moment I cannot independently confirm. The events sit past my knowledge horizon. The data is Anthropic's, the index is a prototype, and no third party has audited any of it. I'm treating this as a disclosed scenario, not a settled fact set. That's not hedging for the sake of hedging. It's the difference between analysis and a press release paraphrase.

What I can do is read structure. Structures don't need an audit to be legible.

CORE: Reading the Dashboard Like an Auditor

The Definition Problem

Start with the word "led."

Twenty-six percent of R&D tasks, Claude led. Under human supervision. What's a task? What's leading? What's supervision?

I've watched this movie in a different theater. In 2017 I covered the ICO wave by tracking Telegram sentiment instead of reading token contracts, and it made me fast. It also made me wrong about things I should have been right about β€” projects with beautiful whitepapers and no code shipped, and projects with no whitepaper and a working testnet that I dismissed as unserious. The lesson wasn't "read the contracts." It was: when a number is doing narrative work, ask what definition it's standing on.

Here's the failure mode, concretely. If a task is narrowly scoped β€” "run this benchmark suite, summarize the results, propose three follow-up experiments" β€” then a model leading that task is genuinely useful and genuinely not the same thing as a model leading a research program. Anthropic's framework doesn't force that distinction. It reports an aggregate.

A task-count metric, an hours metric, and an output-value metric will produce wildly different numbers from the same underlying reality. Anthropic reported one of them and didn't say which.

That doesn't make the number fake. It makes it not yet a measurement. It's a signal that a measurement is being attempted, published early, while it's still cheap to publish.

There's a second definitional hole, and it's bigger. The disclosure says human supervision. It doesn't say how much. Supervision can mean a researcher reviews every output before it ships. It can mean a researcher gets a weekly digest. It can mean a researcher's name is on the project and the model did the rest. All three are supervision. Only one of them is a control.

If you can't measure intervention depth β€” reviews, reworks, rollbacks, discarded proposals β€” you can't measure autonomy. You can only measure the absence of a formal promotion.

That's the honest core of the 26%. The model got promoted. Nobody changed the reporting line.

The Curve Is the Real Disclosure

Forget the level. Look at the slope.

Under one percent in February 2026. Twenty-six percent in August. Six months.

I've seen exactly one curve shaped like that in my career, and it was total value locked in DeFi Summer 2020, and it ended the way those curves end. Not because the underlying thing was fake. Uniswap was real. Compound was real. The yields were real for a while. It ended because a curve that steep is always borrowing from the future.

So the interesting question isn't whether 26% is impressive. It's what happens between 26 and 50.

Because the work that's left after you've automated the easy quarter of a research pipeline isn't four times harder. It's categorically harder. The first quarter is retrieval, drafting, summarization, test generation, boilerplate, ablation bookkeeping. It's the part of research that looks like research but is actually clerical work wearing a lab coat.

The last quarter is judgment. Knowing which experiment not to run. Noticing that an anomaly is signal when every prior says noise. Deciding that a direction is dead and killing it before it eats six months. That's the thing that makes a researcher a researcher, and it's the thing that doesn't decompose into tasks small enough for a current model to "lead."

Anthropic's own framework puts zero at AL5. That's the most honest number in the document. The least honest move available would be letting a 26% headline do the work a zero should be doing.

I'll add one more slope observation. Ninety percent of R&D work involves Claude collaboration at some level. If that number is real, then the honest framing isn't "we automated 26% of research." It's "we changed the nature of 90% of research jobs and fully automated a quarter." Those are the same sentence with very different implications for the people doing the work.

What Thirty Thousand Agents Actually Costs

Thirty thousand agents, running research and engineering work at any given moment.

That number deserves its own paragraph because it's the one with a power bill attached. Thirty thousand concurrent reasoning agents is not a feature. It's a compute commitment. It's a permanent inference load sitting on top of training runs that already consume gigawatts. It's the kind of number that shows up in a cloud provider's quarterly earnings call under "AI demand" before it shows up in a research paper.

It also tells you something about architecture. Agents at that scale need orchestration, memory, tool access, state management, and per-agent monitoring. The monitoring line is where the 0.002% lives. Thirty thousand agents making decisions continuously, and one in 47,000 gets blocked.

Do the arithmetic on the denominator. Thirty thousand agents is a lot of decisions per hour. If the block rate is genuinely one in 47,000 across all of them, you're not running a tight guardrail. You're running a filter with a wide mesh on a stream that never stops.

And the mesh width is a choice. Every safety threshold is a tradeoff between catching bad decisions and slowing good ones. Anthropic picked a threshold. We don't know what it picked it against, because there's no published red-team baseline, no severity distribution, no false-negative estimate.

The 0.002% Block Rate

This is the number I'd put in front of a regulator first.

One blocked decision per 47,000. Chart it and it isn't a control system. It's a smoke detector that triggers once every four years.

Let me give the counterargument its due. A low block rate isn't automatically bad. If agents are well-aligned and tasks well-scoped, most decisions should be fine, and a high block rate would mean you built a paranoid system that wastes compute and annoys researchers. There's a version of this where 0.002% is a flex β€” proof the alignment work succeeded upstream.

But that version requires three things you don't get to see.

What's the denominator? What counts as a decision? Every token classification, or only consequential actions?

What's the severity distribution? Were those 47,000 trivial file edits, or did some of them touch experiment design?

And what's the false-negative rate? How many decisions should have been blocked and sailed through because the monitor didn't recognize them?

A block rate without a miss rate isn't a safety metric. It's a coverage metric. It proves the monitor is running. It doesn't prove the monitor is right.

Here's where my DeFi scars are useful. When an oracle reports a price, the question is never "did it report." It's "how long ago did it report, and what happened in the gap?" Latency is what kills you. A safety monitor that flags after the fact is an oracle with a delay, and a delayed oracle is worse than no oracle, because it hands you confidence you didn't earn.

Every major DeFi exploit I've covered followed the same shape: the monitoring existed, it worked, and it worked too late.

So the structural read on 0.002% isn't "the monitor is too lenient." It's that the monitor is downstream. It watches decisions, which means the decisions already happened, which means the interesting material β€” what the agent considered and rejected, what alternatives it weighed, whether it understood the stakes β€” is invisible in the metric.

You can't audit a decision by looking at its outcome. You audit it by looking at the reasoning that produced it, and that reasoning is exactly what a block-rate statistic throws away.

Compute Allocation Is the Only Number That Can't Be Spun

Six percent.

Of all the AI R&D compute Anthropic spends, six percent goes to safety-related uses. Twelve percent of the AI-driven AI R&D compute goes to safety.

Sit with that for a second.

The company whose entire market identity is "we are the careful ones" allocates roughly one-sixteenth of its research compute to the thing it says is the reason it exists. The safety overhead roughly doubles when the research itself is AI-driven, which makes mechanical sense β€” closed loops need more monitoring β€” but it doubles from six to twelve, not from six to sixty.

I'm not saying six percent is too low. I don't have a baseline. Nobody has a baseline, because nobody has ever published one. That's the actual news here.

Anthropic just handed the industry the first number in a category that has never had a number. The number is small. And the smallness is now the reference point.

The next lab that wants to look serious will report something comparable. The one after that will report slightly less and call it efficiency gains. Within two years, "we allocate six percent to safety" will be the floor everyone points at, and someone will argue that four is fine because monitoring got cheaper.

This is how standards get set. Not by argument. By first publication. Whoever publishes first defines the axis. Everyone else competes on the slope of a graph they didn't choose.

I watched it happen in crypto three times. Block times. Then TPS claims. Then auditor counts and reserve attestations. In each case the first mover set the vocabulary, and the vocabulary constrained everything that followed.

The Wet Lab Nobody Is Watching

And then there's the part that made me put my coffee down.

Claude directs robotic experiment equipment in a Bay Area wet lab. Physical science. Not code. Not text. Pipettes, plates, samples, temperature curves β€” the kind of work that has a biosafety regime, a regulator, and a paper trail with initials on it.

The disclosure treats this as an engineering milestone. It reads like "we extended automation into the physical layer," which is genuinely hard and genuinely impressive.

But nobody in this document says the word biosafety. Nobody says which experiments. Nobody says what happens when a language model schedules a physical reaction it mischaracterized in a plan it generated two steps earlier and no human read. Nobody says whether the robotic equipment has a hard interlock Claude cannot override, or whether the model's judgment is the interlock.

This is the most consequential sentence in the entire disclosure, and it's written in the passive voice as though it were an infrastructure footnote.

I've written about DeFi protocols that automated liquidation without a circuit breaker, and I watched one of them cascade in 2022 in a way that took eleven hours and several hundred million dollars to fully unwind. The lesson wasn't that automation is bad. It was that automation moves the failure mode. It goes from "a person made a mistake" to "a person made a mistake and the system executed it ten thousand times before anyone noticed."

Wet labs are that, with biology. The failure mode doesn't have a rollback.

The Recursive Loop

Here's the thing that sits under all of it, and it's the thing the disclosure is quietly proudest of.

AI is accelerating AI research. That's the loop. The model writes experiments, the experiments improve the model, the improved model writes better experiments.

This is the actual product. Not the model β€” the rate. Every lab in the world is trying to close this loop, because closing it means your next model arrives faster than your competitor's, and the compounding is brutal. Twelve percent of AI-driven AI R&D compute going to safety means eighty-eight percent is going somewhere else, and where it's going is the loop.

I have a specific discomfort with this that isn't about doom. It's about the flywheel. When a model participates in its own development, it accumulates a data advantage nobody outside the lab can replicate β€” not because the data is secret, but because it's generated internally at a rate no external dataset can match. That's a moat built out of recursion.

I've watched an analogous dynamic in crypto exchange markets. The venue that sees the most order flow learns the most about price discovery, which lets it price better, which attracts more order flow. Perfect flywheel, and it ends with one or two venues owning the market. Not because they cheated. Because the flywheel is the business.

The Evaluation Tax

One more piece of the industry picture, and it's the part that hits small players hardest.

Every frontier model release now triggers what I've started calling the evaluation tax. If you build anything on top of these models β€” a product, a protocol, an agent framework β€” a new release means benchmark re-runs, migration tests, safety reviews, procurement renegotiation, and a quiet period where your users ask whether your thing still works.

Add that to a release cadence measured in weeks, and the tax compounds. It's a fixed cost that scales with the number of releases, not the size of your business. Which means it's a rounding error for a lab and a body blow for a startup.

The same-week release cadence this disclosure sits inside is itself a competitive weapon. It doesn't just advance the frontier. It raises the cost of standing still, and the players who can't afford to stand still are the ones who disappear.

I've said for two years that the real difference between OP Stack and ZK Stack was never technical β€” it was who could convince more projects to deploy chains first. Same dynamic one layer down. The lab that sets the release tempo sets the cost structure, and the cost structure decides who's still standing.

Who Gets Displaced

Now the part of the document that gets the least attention and deserves the most.

Ninety percent of R&D work involves model collaboration at some level. That's not an automation statistic. It's a job-description statistic. It says that nine in ten people in that building now do work defined partly by what a model can do, and their value is increasingly the delta between the model's output and their own.

Here's who goes first. Junior research roles where the work is literature review, baseline implementation, and ablation running. QA and test engineering, which is already mostly generation. Lab technicians whose job is executing protocols someone else designed. Data labeling and cleaning pipelines, which are the most automatable thing in the entire stack.

Here's who gets more valuable. Senior researchers who can tell a promising direction from a plausible one. Safety and evaluation staff, whose headcount grows because the surface area grows. Auditors, if any exist. And the small number of people who can read a model's output and say "no" with enough conviction to make it stick.

The compression isn't at the top. It's at the bottom, where the entry-level rungs used to be. And entry-level rungs are how the senior researchers of 2035 get trained.

Every lab automating its junior work is quietly deleting its own future hiring pool, and nobody's dashboard tracks that.

The Open Source Squeeze

One more structural effect, and it's invisible in the index.

If the loop closes inside a lab β€” model writes research, research improves model β€” then the returns to that loop accrue to whoever has the most compute and the cleanest internal data. That's a closed system, and closed systems get better faster than open ones because they don't have to coordinate.

Open ecosystems have exactly one advantage in that race: they can absorb more contributors. But contributors need to be able to use the models, and the models are increasingly the thing that does the work. If the frontier model is the research tool, then open access to the frontier model is the precondition for open research. And open access has been the thing labs are slowest to provide at the frontier.

I've watched this exact dynamic in crypto. The projects that won were rarely the most decentralized. They were the ones that let the most people build on top of them without asking permission. Distribution beat purity every time.

If AI research automation concentrates inside four labs, the research layer becomes a permissioned system. And permissioned systems don't lose because they're worse. They lose because they're smaller.

WHAT ACTUAL ATTESTATION WOULD LOOK LIKE

Let me get concrete, because "you should attest to it" is the kind of advice that sounds smart and means nothing.

Here's what a real audit trail for a claim like "Claude led 26% of our R&D tasks" would require.

A fixed task taxonomy, published before the measurement period. You don't get to bucket tasks after the fact. The categories get defined, hashed, and committed.

Per-task logs with a signed record of the agent's inputs, tool calls, outputs, and β€” critically β€” the human intervention events. Review. Rewrite. Reject. Rollback. Every one of those is a data point, and every one gets committed to an append-only structure with a timestamp.

A commitment scheme. Each period's logs roll up into a Merkle root that gets published. The full logs stay private. The root is public. Any auditor with access can prove that the number they computed matches the number that was published, without the company being able to edit the record afterward.

An independent scorer. Not an evaluator invited by the company β€” an auditor with authority granted by someone else, working from published methodology, producing a public finding that includes their disagreements.

And hardware-rooted measurement of compute allocation. Six percent of R&D compute to safety is a claim about resource usage. Resource usage is measurable. Trusted execution attestation or signed scheduler logs can verify it without revealing what the safety work actually was.

None of that is exotic. Every piece exists. It's been shipped in other contexts. The reason it doesn't exist here is not technical difficulty. It's that the entity being measured is the entity doing the measuring, and that arrangement is comfortable for exactly one party.

CONTRARIAN: The Index Isn't a Safety Tool. It's a Prospectus.

Here's what I think most coverage is missing.

Everyone reading this document is arguing about whether 26% is impressive or alarming. That's the wrong argument. The right argument is about what the index is for.

Look at the chronology. A safety essay from the CEO. A landmark governance disclosure five days later. A reported accelerated model launch. A reported IPO window. A proposed industry-run safety regulator. An antitrust suit alleging the safety claims are coordination.

That's not a safety program. That's a regulatory positioning campaign with a technical appendix.

The R&D Automation Index is not primarily a transparency tool. It's a due-diligence artifact. It exists so that when Anthropic walks into a pre-IPO roadshow, or a Senate hearing, or a European regulator's office, the company can point at a dashboard and say: we measure this, we publish this, we can be governed.

That's worth an enormous amount of money. Not because it proves safety. Because it proves governability, and governability is the thing capital markets and regulators actually price. A lab that can be measured is a lab that can be regulated at low cost. A lab that can be regulated at low cost is a lab regulators prefer to keep alive.

I'll be fair to Anthropic, because the cynical read isn't the whole read. There's a real possibility the company believes the only way to slow things down is to make progress legible β€” that publishing a number nobody else wants to publish is a costly signal, and costly signals are how you prove you mean it. That's a defensible strategy. It might even be correct.

But costly signals and cheap ones look identical from outside the building. And nobody's outside the building, because nobody has been offered a seat that wasn't positioned by the host.

Now the crypto-native reading, which is where this stops being an AI story and starts being a market structure story.

We have the exact tool this disclosure is missing, and we've had it for a decade.

Anthropic says 26%. Anthropic says 0.002%. Anthropic says six percent of compute to safety. Every one of those is a number generated by the reporting entity, formatted by the reporting entity, published by the reporting entity.

There's no Merkle root. No signed attestation. No hardware-rooted measurement. No third party with read access granted by something other than the entity being measured.

Crypto solved the "trust me" problem badly and incompletely, but it solved it in principle. Verifiable computation. Trusted execution attestation. On-chain commitments with timestamps. Agent logs committed as trees so any auditor can prove what was and wasn't inside them.

That's not a thought experiment. That infrastructure exists. It's the same stack we use to prove reserve balances, to verify batch proofs, to attest inference runs inside enclaves. It's unglamorous and it works.

If AI R&D automation is going to be governed β€” and after this disclosure, the pressure to govern it doesn't reverse β€” then the governance layer needs an attestation layer underneath it. Otherwise every number is a press release with a decimal point and a chart.

Nobody is building that yet at scale. The first team to ship credible AI R&D attestation β€” signed agent logs, third-party verifiable autonomy scoring, hardware-rooted safety-compute accounting β€” will own a category the size of the audit industry, and it will look nothing like a compliance startup and everything like a crypto infrastructure company.

The Cartel Suit Is the Sleeper

Everyone's treating the antitrust filing as background noise. It isn't. It's the first legal test of whether safety coordination among frontier labs is a public good or a restraint of trade, and it goes directly at the thing these companies spent four years building: the ability to present coordinated restraint as principled caution.

If a court takes the cartel claims seriously, the safety premium unwinds. Not the safety technology β€” the safety brand. Every joint statement becomes discoverable. Every shared framework becomes evidence. Every industry safety body becomes a venue where competitors had the opportunity and the motive to coordinate.

I've watched this convert in crypto. Self-regulatory organizations that read as maturity became, in litigation, proof of coordination. Listing committees. Standards bodies. Foundation councils with overlapping boards. All of it flipped from legitimacy to liability the moment someone with subpoena power read the meeting notes.

If I'm Anthropic, the R&D Automation Index is the hedge. Because when a plaintiff's lawyer asks "what did you coordinate on," the answer becomes: nothing that mattered β€” look, we published our own autonomy numbers, we're competing on capability, we're racing.

Transparency becomes the defense. Which is a fascinating reason to build it, and a fragile one.

Because you cannot publish an unaudited dashboard and call it transparency forever. Eventually someone with authority says: excellent, we'll audit it ourselves. And then you find out whether the number survives contact with an unfriendly reader.

That's the moment I'm waiting for, and it's the moment this whole narrative either holds or breaks.

TAKEAWAY: Watch the Auditors, Not the Audited

So what do I actually do with this?

For the crypto reader, four things to track. None of them is the 26%.

Watch the safety compute share, not the autonomy share. Six percent and twelve percent are the numbers with an audit trail. Autonomy percentages can be redefined on a slide. Compute allocation shows up in procurement contracts and power bills. If safety's share of R&D compute moves from six to fifteen, something real changed. If it drifts from six to four, the autonomy number stops mattering, because the monitoring that makes it safe isn't being funded.

Watch whether AL5 stays at zero. Every quarter, check the bottom rung. The day a lab reports a single fully autonomous research task is the day the AL scale stops being a framework and becomes an event. Nothing here suggests that's close. But the slope from February to August suggests the question is being asked inside the building.

Watch the auditors, not the audited. The disclosure mentions third-party evaluators. It doesn't say who, what access they get, or whether their findings will be published. If access is granted by the entity being measured, the independence is theater. In crypto we spent years learning that a "trusted" third party with access granted by the counterparty isn't a third party. It's an employee with a different letterhead.

Watch the wet lab disclosure. If biosafety language starts showing up in future versions β€” regulator, protocol, interlock, incident reporting β€” that's a company that got told to. If it stays in the passive voice, nobody has told them yet.

And one trade-level thought for people who hold this stuff.

The 0.002% Problem: Anthropic's R&D Automation Index and the 26% Nobody Can Audit

If the attestation layer gets built β€” and there's a real chance the next eighteen months forces it, between the cartel suit, the IPO, and regulators who've now seen a number they'll want to verify β€” the winners are not the labs. The labs will be the customers. The winners are the infrastructure that makes verification cheap: attestation protocols, agent-log standards, audit tooling that sits between a private pipeline and a public claim.

That's a boring-sounding category with a very unboring total addressable market, because every lab, every enterprise deploying agents, and eventually every regulated entity running autonomous systems on a material workflow will need it. And it will be built the way the L2 wars got settled: not by having better technology, but by convincing more of the market to adopt your standard first.

And the broader thing, the thing I keep circling back to.

What this industry does, over and over, is sprint toward, one block at a time, a place it can't quite describe, and then describe it anyway. The ICOs described a bankless future that turned out to be a token sale. The DeFi protocols described decentralized governance that turned out to be three multisigs and a Snapshot page. The NFT projects described community that turned out to be a Discord and a floor price.

Every time, the technology was real and the description was aspirational, and the gap between them is where all the money was made and lost.

Now the most safety-conscious AI lab in the world has described AI doing a quarter of its own research, with a monitoring layer that catches one decision in 47,000, using a compute allocation that points six parts at safety and ninety-four parts somewhere else β€” and a wet lab where the model schedules physical experiments and the document doesn't use the word biosafety once.

Maybe that's a snapshot of a company doing an honest job in a category that has no standards yet.

Or maybe it's the description of the future, written five years early, by the people who'll be audited on whether they got it right.

The future isn't fully autonomous yet. It's at twenty-six percent, unaudited, on a promise that's five days old and already carrying an IPO inside it.

The auditors are the whole story now. Whoever gets to read the logs gets to write the history. And right now, the only people reading the logs work for the company that wrote them.