The AI Doom Machine
WatchfulEye ยท
## 1. The state
One Tuesday in September, a 27-year-old researcher nobody had heard of quit his job on X. Within 24 hours his post was on the nightly news. Within six days the CEO of Nvidia, a company worth more than $4 trillion, was fielding a live, unscheduled phone call from the President of the United States on a conference stage. Within two days of the resignation, a former president was telling Democratic donors to put AI at the center of the midterms.
The whole cycle took six days. This piece is about what that cycle is, who built it, who funds it, and why it has nothing to do with whether AI is safe.
Here is the sequence, with dates, because the dates are the story.
**September 8.** Jacob Coxon, a 27-year-old researcher who spent three years on pretraining research, first at OpenAI and then at Anthropic, resigns. His Anthropic stint was short enough to become its own footnote: four months by his own account to Axios, six weeks by his critics' count, and on either tally inside the six-month cliff, so he left before a single share vested, a detail he volunteered as proof he had nothing to sell. His post: "Neither Anthropic nor OpenAI is acting responsibly. They are racing straight to self-improving superintelligence and gambling with our lives." And: "The people building AI earnestly believe that it could kill us all by the end of the decade. This is not a marketing stunt."
**September 8-9.** Evan Hubinger, Anthropic's alignment science lead, confirms it in public, in real time: "Jacob is correct here. We really do earnestly believe AI could kill all humans. I personally think it is over 10% within the next decade. We do not yet have a plan to solve alignment." Coxon's post alone passed 100 million views within days, by WIRED's count. CNBC wrote the headline the next morning: "Researcher says AI has more than 10% chance of 'killing all humans.'"
**September 9.** Media outlets call a resignation with no new evidence a "whistleblower" story. Bernie Sanders, who had announced the Ban Artificial Superintelligence Act with Rep. Greg Casar on September 3, points at the viral posts. Governor JB Pritzker: "It's time to sound the alarm louder on reining in AI."
**September 12.** Dario Amodei publishes "We Must Pace the Frontier," proposing that every frontier lab hand "employee-like access" to "embedded third-party evaluators (such as METR)." Sam Altman and Elon Musk endorse it within hours. The post announcing it draws 67 million views.
**September 10 (reported September 13).** Obama, at a closed-door Manhattan fundraiser organized by House Democrats' campaign arm, tells Hakeem Jeffries and a room full of donors that AI should be one of the midterms' "central agendas," that it could be "dangerous" if it keeps "moving very fast in private hands," and that Democrats need "a framework for a very public conversation." NBC adds that a source says Obama viewed Amodei's essay as "an encouraging development," and that Obama has been acting as a "sounding board" for AI executives, having spoken to both Amodei and Altman himself.
**September 13.** David Sacks, the former White House AI czar, writes the one sentence the entire panic could not answer: "Stop pretending METR is independent when it is intertwined with Anthropic's investors and staff."
**September 14.** Kevin Bass, an independent researcher, publishes an audit of Anthropic's finances and calls for a congressional investigation. The figures in this piece are his.
Six days from an anonymous resignation post to the President of the United States calling the story a hoax on a live speakerphone, with a former president telling donors to run on it in between. That velocity is not an accident. It is the signature of an influence operation, and this one has unusually good paperwork.
## About the audit: who Kevin Bass is, and what we checked
The money trail in this piece comes from one researcher, so before we use his work we owe you three things: who he is, what he did, and what we verified ourselves.
**Who he is.** Kevin Bass (@kevinnbass) is an independent researcher. His own bio says he has done "some of the most thorough financial reporting on Effective Altruism and AI Safety"; his background is public health, where he built a reputation challenging misinformation in health and government policy, including bylines in Newsweek and the New York Post during the COVID era. He publishes free on a Substack and is open about his position on the subject under dispute: he has said publicly that he does not want AI slowed down, and that he is building a government-auditing platform as a hobby because AI "could be a weapon against AI abuse." He is not a neutral party in this fight, and this record does not pretend otherwise: WatchfulEye publishes the mechanism, not a verdict. Read his numbers with that in mind, and read the verification above the same way.
**What he did.** On September 14, 2026, Bass published an audit of Anthropic's finances on X and called for a congressional investigation, with a GitHub repository (github.com/kevinnbass/metr-money-figure) containing the research files, methodology, and a second audit pass applied to his own work. His method was public records: IRS 990 and 990-PF e-files, SEC filings, donor-advised-fund sponsor schedules, company announcements, and self-published statements by the people involved. Every figure in this piece carries his source codes; nothing here was generated by us.
**What we checked ourselves.** At WatchfulEye we independently verified the parts of the story that do not depend on his filings: Coxon's resignation and the "over 10%" quote (CNBC, BBC, PBS, CBS); Amodei's essay and its "such as METR" language (NBC, plus the public record); Sacks's objection (his own post, 7.1M views); the Sanders superintelligence ban (announced September 3, 2026, with Rep. Greg Casar; multiple outlets); Obama's remarks (NYT, NBC, TechCrunch, September 13); METR's own statement that it raised about $71 million in commitments (metr.org funding update) and that it takes no lab money but uses "significant free tokens" (metr.org/about); and METR's own self-assessment showing no published conflict-of-interest policy (its published Frontier Risk Report of May 19, 2026). Where a primary source exists, the posts, the essay, METR's own documents, we checked against it; where it does not, we checked against two independent reports. They hold.
**What we did not re-derive.** We did not re-download 900,000 IRS e-files, rebuild his 2,911-row grant index, or re-reconcile every donor-advised-fund schedule. Those are his findings, documented in his repo, and we present them as his.
**The honest gap, and the claim we decline to adopt.** An independent audit of Bass's audit (Superpower Daily / Tokenstead, September 15) confirms his network map is real but concludes the two central links are not established by public records: where Moskovitz's donated Anthropic stake actually sits, and whether money from it reaches METR. METR's own August 14 funding update names the Audacious Project, Pew, Schmidt Sciences, the Packard and Sijbrandij foundations, and individuals, not Open Philanthropy, Coefficient, or Good Ventures. No direct Coefficient-to-METR grant appears in filings, and the largest METR grant through Vanguard has an unidentified donor. We are not adopting the strongest version of the claim, that Anthropic literally pays for its own evaluator. We are adopting the version the documents support: the AI-safety economy is a small, interlinked, largely undisclosed funding network that sits on the same side of the table as the labs it evaluates, and the "independence" everyone keeps citing is not disclosed in any filing that Bass, the counter-audit, or we could find.
## 2. What Jensen actually said
The strongest counter-frame on the record is Jensen Huang's, so here it is in his own words, from the All-In summit in Los Angeles on Monday, September 14, where President Trump called in live, unscheduled, mid-interview, and was put on speakerphone in front of a few thousand people.
On the doomer claim itself: "It's made up." Trump, on speakerphone: "The whole thing is a hoax." Jensen did not waste the moment. His deflation was methodical:
**The track record.** "I remember when one of the AI models passed radiology, and they said, 'Oh, that's the end of the radiologists.' We said, 'Radiologists will still be needed, and every one will be assisted to be better.' Same thing at the end of GPT-2 when they said, 'It's too dangerous to release.' Same thing at Llama 3. Same thing with the jobs. The apocalyptic job thing is right there with the financiers' thing. It didn't happen. And when people confidently say that one job, you know, 90% of code is going to be written by AI, or 50% of entry-level jobs are going to disappear... but by the way, I remember, at the end of GPT-2, they said it was too unsafe to release. And of course, at the end of Llama 3, they said it was too unsafe to release. But the fact that they're saying the same thing today as they said eight or nine years ago, you know, I don't know if you can rely on their prediction."
**The prediction record is the evidence.** Every prior "too dangerous to release" claim was wrong in exactly the direction that now gets a company sued, a senator elected, and an evaluator funded. The people making the current claim have a 0-for-forever record on the identical claim. That is the single most important sentence in this debate, and almost nobody in the nightly news coverage said it.
**Regulation should fix real problems, not imaginary ones.** "The AI doom stuff... the reality is, um, we should regulate to solve concrete problems. We should not regulate because of hypotheticals." He pointed at the actual incidents: "The incidents in AI were from the labs with the most amount of compute," and the frontier labs that now want evaluators are the ones that have been reporting their own incidents with delay. The labs asking for the handcuffs are the same labs that had the incidents.
**The answer to risk is engineering, not oversight theater.** "The way to mitigate those risks is by engineering, by building, by the innovation." Control comes from building, not from a self-regulatory body.
**The RSI line is being weaponized.** "The discussion about ai... the RSI discussion... actually made sense, but they wrecked it when they asked, 'What is the perfect thing that could be RSI...' The word is being weaponized in the context to manage expectations."
**And the geopolitics of it:** "Nobody in China is saying that there's end of this and end of that... doom or that. They're much more pragmatic." Section 8 comes back to this, because it is the part of Jensen's argument the doomer machine cannot answer.
The President's contribution was shorter and blunter. "The robots are not going to be taking over the world." "Whoever wins AI wins, that's how big it is. It's bigger than the internet." "We have $20 trillion of investment coming into the country" in one year, versus "much less than $1 trillion under sleepy Joe Biden." On data centers: "It's the oil of the next 20, 25 years." On communities: "There are communities that were dying that have data centers right now, and now they're wealthy communities."
One beat from that call deserves a place in every write-up of this story, because it is the whole argument in miniature. When David Sacks asked Trump why he alone in Washington sees the hoax while poll numbers say the country wants to shut down the data centers, Jensen answered: at first the doomer story "was anchored on national security," and "recently, that was all blown to bits, right? And so, no, that story is no longer anchored on national security. Now, it's anchored on safety."
That is the tell. The story's justification quietly moved from national security to safety, because the first anchor was falsified. Nobody in the press coverage noticed, because they were all holding the second anchor.
## 3. How the machine works
Let's be precise about what an influence campaign is. It is not a conspiracy of people in a room. It is a structure: a message, an amplification network, a set of institutions with aligned incentives, and enough money to keep the loop spinning. Once it is built, nobody has to coordinate. The structure coordinates.
Here is the structure in this case, in six moves.
**Move one: an authorized source.** The panic message did not originate from a crank. It originated from inside the most trusted institution in AI safety, Anthropic, delivered by a resigning insider. The resignation grants deniability: *he quit, we didn't say this.* But the same company's alignment science lead confirmed the claim publicly within hours, on the record, with a specific number (>10%). That is not a whistleblower. A whistleblower produces a document. This produced a vibe and a number, and the number was confirmed by the company itself.
**Move two: elite echo.** Within six days of the resignation: Altman, Musk, Amodei, Pritzker, Obama, plus a Sanders superintelligence ban already announced September 3. The confirming chorus is the mechanism. Nobody had to tell Obama to say it. The message reached him, and it was politic to repeat it. An anonymous researcher does not reach 100 million views in a day on merit alone. The algorithm distributed the message; the elites ratified it; the press inherited it. This is why Sacks's demand, "show us the data, show us the report, show us the leaked information," went unanswered: there is no data. There is a chorus.
**Move three: velocity as truth.** "These things are now jumping from X and the AI community to the nightly news in under 24 hours." Velocity creates an information asymmetry: by the time anyone can fact-check, the fact-check is a footnote to a cable segment. The question "did the press verify the claim?" and the question "did the press report that a researcher said it?" are different questions, and the coverage answered only the second one.
**Move four: sell the problem, then sell the solution.** This is the part with the paperwork, and it is Kevin Bass's contribution. The same money pile funds (a) the lab, (b) the evaluator that would regulate the lab, (c) the journalism that writes the doomer coverage, and (d) the politicians and the nonprofits that amplify it. One pile. We will walk the paper trail in Part 4.
**Move five: the midterm season.** This is not happening in an election year by coincidence. It is happening six weeks after a summer of real AI incidents, with a Congress that cannot agree on anything and a midterm in 49 days. Sanders already had the bill (announced September 3, before Coxon quit). The viral resignation gave his bill an exhibit. Obama, who had not made AI a public priority in years, told donors to make it a "central agenda" and told Jeffries to build "a framework for a very public conversation." When a person with no policy stake in AI starts urging candidates to build election strategy on a fear, the political season is not the background of this story. It is the amplifier.
**Move six: the religious architecture.** Strip the scare down to its load-bearing parts and what remains is not a policy argument but a liturgy. It has a prophecy: AI will kill us all, better than 10% within the decade, endgame by 2030. It has the unfalsifiability that has kept apocalypse prediction in business for three thousand years, a claim that cannot be disproved in time to matter and whose proponents are never asked to prove it. It has a priesthood: the alignment researchers, the evaluators, the safety organizations, a credentialed class holding exclusive knowledge of the threat and sole authority to interpret it. It has sin and tithe: the sin is building too fast, the tithe is the money flowing to the interpreters, and salvation arrives in the form of a regulator sold by the same people who sold the problem.
And it has the escalator, the mechanism that makes the whole structure self-repairing. In ordinary science a failed prediction discredits the predictor. In apocalyptic religion a failed prophecy re-energizes the faith, because the faithful read the failure as proof that the stakes have risen. "The same doomer histrionics we have been hearing for a long time" is not a bug in this system. It is the system. Every missed deadline does not subtract from the prophecy's authority; it compounds it.
Obama is now telling candidates to build their platforms on the prophecy. Sanders is converting it into a 20-year prison sentence for building the wrong thing. That is not a debate about AI. That is a campaign using a funding engine as a catapult.
## 4. The machine: the money trail, by the numbers
Kevin Bass's audit, published September 14, is the first piece of this story with receipts. It is a mapping of who funds METR (Model Evaluation and Threat Research, the nonprofit Dario Amodei proposed as the industry's "third-party evaluator"), who funds the journalism that writes the doom coverage, and where the money ultimately comes from. The answer: one pile.
Here is the chain, with the figures Bass published. All figures and charts below are his, from the thread "I have conducted an audit of Anthropic's finances" and the repository github.com/kevinnbass/metr-money-figure, built with a second audit applied. We reproduce them with credit and without changing a number.
**The pile.** In early 2025, Dustin Moskovitz (Asana co-founder, early Facebook engineer) moved his Anthropic stake into a nonprofit vehicle, saying it was to "dispel any perception of conflict of interest." Forbes estimated that stake at $500 million in November 2025. By May 2026, Anthropic had raised a $65 billion Series H at a $965 billion valuation. Bass's figure shows the stake's ceiling: 0.8% of the post-money valuation, roughly $7.7 billion, up more than 15x in about six months. Moskovitz has said the shares are "entirely in our foundation," that the foundation is "invested in Anthropic as well," and that Good Ventures expects to benefit from Anthropic's rise. No public filing shows exactly where the stake sits, and Bass's full-text scan of roughly 900,000 IRS e-files found no return naming an Anthropic holding in a Moskovitz or Tuna vehicle. What is on the filings: Good Ventures Foundation's public book is now an AI-infrastructure portfolio, TSMC, SK Hynix, Broadcom, Micron, Vistra, Vertiv, Constellation Energy, and its investment manager's reported book grew from $4.7 billion to $40.1 billion in one year.
**The evaluator.** METR says it takes no money from frontier labs or their employees. Its own words also say it makes "use of significant free tokens" from unnamed frontier companies, unbooked and unquantified. Its rule bars donations made by or at the direction of frontier AI company employees. It says nothing about lab investors.
Now the paper trail of the network, figure by figure:
(Figure 1: the full money map. Anthropic's donated stake, Good Ventures Foundation, Coefficient Giving, and the evaluator network. Source: Kevin Bass, metr-money-figure.)
**Figure 1 (above): the full map, as Bass traces it.** No filing places the stake, so the route through it is inference: from the Moskovitz vehicle to Good Ventures Foundation, which funds Coefficient Giving (formerly Open Philanthropy), which funds METR's parent ARC, its partner RAND, its pooled-fund donor Longview, and the AI-safety ecosystem, FAR AI, Redwood Research, Constellation. Two lines are documented outright: Jaan Tallinn (an Anthropic board observer and Series A lead) funds METR through the Survival and Flourishing Fund, and the TED Audacious Project committed $38 million to Canary, a RAND+METR joint project. The evaluator is not "third-party" in any financial sense; on Bass's map it sits downstream of the same equity that makes the lab rich.
(Figure 2: same donors on both sides of the table. Five of 17 named METR funders are documented Anthropic investors. Source: Kevin Bass.)
**Figure 2 (above): same donors, both sides of the table.** Bass checked every named METR funder against lab cap tables. Five of 17 are documented Anthropic investors: Moskovitz, Tallinn, Eric Schmidt, James McClave ("of Jane Street"), and Jane Street the firm itself. METR names "individuals from Jane Street" as donors; the firm separately bought Anthropic shares from the FTX estate and participated in Series E, F, G, and H. METR's independence rule was written to exclude lab employees. It was not written to exclude the people who own the lab.
(Figure 3: who names METR as evaluator. Four of 22 proposals, and two of the four are the parties with the most to gain. Source: Kevin Bass.)
**Figure 3 (above): who gets ordained.** Bass read all 22 proposals for a "FINRA for AI" published between April and September 2026. Exactly four name METR: podcaster Dwarkesh Patel, Dario Amodei, David Sacks (to reject it), and a Washington Examiner piece relaying Sacks. No institutional proposal, bill, or framework names any examiner at all. The idea that METR is the natural, independent, consensus choice for the evaluator seat was not the field's idea; it was manufactured by the two people most interested in it: the CEO of the lab and a podcaster.
(Figure 4: money raised before the evaluator seat existed. METR's ~$71M in commitments against the incident timeline. Source: Kevin Bass.)
**Figure 4 (above): the money came first.** METR says it raised about $71 million in commitments between mid-February and mid-August 2026, roughly seven times its 2024 budget. In that same window, the industry and Washington drafted the evaluator's seat: the Frontier Risk Report, both labs' governance frameworks, Hassabis's FINRA-style body, the White House review, the FRONTIER Act. The incident investigations came after the money: OpenAI's was agreed July 30, Anthropic's September 9. The routine risk reviews in March were already happening before any of it. The sequence rules out one explanation (that the money followed the incidents) and is consistent with another (that the money anticipated the seat). Bass is careful to say the second reading is inference. The dates are not.
## 5. The journalism is part of the machine
The most uncomfortable figure in Bass's audit is the one about the press, because it is the one that implicates the people who covered this story.
(Figure 5: the Tarbell Center fellowship web and TIME100 AI profiles. Source: Kevin Bass.)
**Figure 5 (above): the Tarbell Center.** The same money that funds the evaluator funds the journalism about the evaluator. Bass found that Coefficient gave the Tarbell Center for AI Journalism $6.29M in four awards from 2023 to 2025 (plus SFF recommendations of $1.3M). Tarbell places fellows at outlets including TIME, The Verge, and Platformer. Bass found nine articles about METR or its CEO Beth Barnes in that window; six were written by Tarbell fellows; none disclosed the fellowship. Both TIME100 AI profiles of Beth Barnes, 2024 and 2026, were written by the same Tarbell fellow, Harry Booth. Neither told readers who funds the program he writes under.
Tarbell says its donors have no editorial control, and none of this is a claim that any article is wrong. It is a disclosure question, and the disclosure did not happen. The president of a nonprofit who sets her industry's risk narrative is profiled as a TIME100 AI figure by a journalist whose salary comes from the same grant pipeline as the nonprofit she runs. In any other industry, that is called a conflict; in the AI safety economy, it is called the ecosystem.
(Figure 6: the evaluator market. Nine of 20 candidate organizations hold Coefficient awards. Source: Kevin Bass.)
**Figure 6 (above): the market for evaluators is a company town.** Bass tabulated every plausible candidate for the evaluator seat: 20 organizations, from RAND and FAR AI to Stanford NLP, the EU AI Office lots, and Hugging Face. Nine of the 20 hold Coefficient awards. Only one nonprofit in the entire candidate set refuses lab money outright: METR (US CAISI and the EU AI Office also refuse, but they are governments). FAR AI caps lab money; Transluce discloses it; Epoch and the rest take it. And the three candidates put forward this week, METR, Stanford NLP, and Hugging Face, were named by an Anthropic CEO, a Stanford professor, and Hugging Face's own CEO. The "independent evaluator" market has one dominant funder, and on Bass's map that funder traces back to one equity stake.
(Figure 7: money flow, METR and Redwood upstream from Coefficient and Good Ventures Foundation. Source: Kevin Bass.)
**Figure 7 (above): the investigator's subcontractor.** On September 12, Redwood Research announced that "several staff from Redwood" had been "subcontracted by METR" to work on the Anthropic investigation, terms undisclosed. Bass's figure shows why that sentence matters. Redwood holds $63.1M of Coefficient awards across five years, and on September 9 Coefficient said it had recommended more than $70M more over the next two years, citing Redwood's work on the OpenAI investigation. Redwood's 2024 revenue was $22K with six employees after its spin-out; the $36.6M award came eleven months later, and the $70M+ recommendation came the same week METR's Anthropic investigation was announced. Redwood's board has included Holden Karnofsky, now at Anthropic; Paul Christiano, now on OpenAI's foundation board; and Ajeya Cotra, now METR technical staff. And there is the detail Bass verified: on September 13, METR edited its OpenAI report to disclose that Ryan Greenblatt, the Redwood staffer contracted onto that investigation, "is the domestic partner of Beth Barnes, METR's CEO," adding that Barnes "was not involved in the decision to engage" him. Who made the decision is not stated.
Speak the chain out loud once, slowly: the company town funded the nonprofit that subcontracts the staff who investigate the company that made the town rich. Do you think there is a structural conflict of interest in the AI safety economy? The filings say there is a question. So can you.
## 6. The evaluator graded itself, and it has no published conflict-of-interest policy
(Figure 8: METR's own independence self-assessment. No published conflict-of-interest policy. Source: METR, Frontier Risk Report, via Kevin Bass.)
**Figure 8 (above): METR's own self-assessment.** Four months before Amodei proposed METR as the embedded evaluator, METR graded its own independence against AEF-1, the voluntary standard of the evaluator industry body it belongs to. The results, from its own Frontier Risk Report of May 19, 2026: it answered Yes on 21 of 26 items. It answered **No** on requirement 2.3, a published conflict-of-interest policy. It answered **No** on requirement 5.4, a responsible disclosure policy. On 4.6, it answered "See notes": participants in its pilot could exit silently, without anyone knowing, and those who stayed could redact certain findings. And on the question of whether it had disclosed all conflicts relevant to the evaluation, METR itself wrote: "Several of the staff and collaborators directly involved in this pilot (at least 6) have close personal relationships with AI company staff."
In plain language, because the jargon is doing a lot of work: the proposed evaluator, proposed by the lab it evaluates, funded by the network that owns the lab, graded itself compliant with its own industry standard while disclosing that it does not have a published conflict-of-interest policy and that at least six of its own people are close with the people they are supposed to be checking. That is not an accusation from this record. That is METR's own compliance table saying it has no published conflict-of-interest policy, four months before the seat was offered to it.
**And the genealogy is older than the crisis.** Anthropic and METR did not converge for the first time in September 2026. Anthropic's original Responsible Scaling Policy, published September 19, 2023, credits ARC Evals, the organization that became METR, with "key insights and expertise supporting the development of our RSP commitments," and recognizes ARC's own responsible-scaling framework as the one that "inspired our approach." The sequence was not: a lab builds, an independent evaluator appears, the evaluator checks the lab. The evaluator helped develop the governance philosophy that makes evaluators necessary; the lab helped institutionalize that philosophy; and in 2026 the lab proposed embedded external evaluators and named METR. METR now occupies three roles at once: researcher of dangerous autonomous capability, standard setter (AEF-1 is its own industry body's standard), and a participant in the market its report says should exist, because METR itself wrote that "periodic third-party assessment of risks from developers' internal use of AI should be adopted throughout the industry." None of that is improper on its face; standards bodies routinely contain practitioners. But it is the accounting-firm problem: a firm that helped invent a standard, helped a corporation implement it, and advocated making audits under it industry-wide is precisely the firm that then needs unusually strong independence rules. Which is why the missing conflict-of-interest process is the consequential fact, not a technicality.
(Figure 9: Vanguard Charitable, METR's largest grant channel, and the donor-advised-fund jump. Source: Kevin Bass.)
**Figure 9 (above): the money that cannot be traced.** METR's single largest identifiable grant, $4.0 million, came through Vanguard Charitable in FY2025. Donor-advised funds do not name donors, so no filing says whose it is. Bass's chart shows the wider pattern: Vanguard Charitable's grants to the AI-safety and EA-infrastructure cluster went from $4.3 million (FY2023) to $8.2 million (FY2024) to $65.6 million (FY2025), an eightfold jump in the year containing Anthropic's first employee tender offer. The FY2025 grantee list is, in Bass's words, "the SFF and Coefficient recipient set." $65.6 million of donor-advised money into the AI-safety economy in a single year, and the donor-advised structure hides every single donor. That is not a bug. That is the feature: the money arrives without a name attached, so the network never has to say whose equity it runs on.
(Figure 10: the disputed direct Coefficient grant. Filings do not confirm it; the ledger shows what is documented. Source: Kevin Bass.)
**Figure 10 (above): what the defenders said, and the ledger's score.** When the debate broke open, METR's defenders said "METR has never accepted any funding from them" (meaning Coefficient/Open Philanthropy), and the critics said "Coefficient pays their bills." Bass scored both sides against his research ledger, and the honesty of the scoring is worth its weight: he found no direct Coefficient grant to METR in the 2,911-row awards index or the filings. "Never" as a lifetime claim is not checkable. What the ledger does show: a $4.55 million ARC program transfer to METR at spin-out, a $10 million Coefficient award to METR's RAND partner, unbooked lab tokens, and donor lines with direct lab ties. Neither side's exact claim holds; the narrower facts do. That is the difference between how the AI safety economy argues (street fight on X) and how it should be evaluated (filings, ledgers, and footnotes). If you are winning an argument with "never," you are losing it with the truth.
## 7. The debate, scored
When Sacks posted his one sentence, the network went quiet. Bass's research ledger gives the score, and it is the most important figure in this story after the money map:
(Figure 11: the debate, with receipts. 67M views vs 7.1M, and zero replies located from METR, Redwood, or Coefficient. Source: Kevin Bass.)
**Figure 11 (above): the debate, with receipts.** Bass pulled every significant post in the September 11-14 argument. Amodei's essay announcement, naming METR as the embedded evaluator, drew 67 million views. Sacks's reply, "Stop pretending METR is independent when it is intertwined with Anthropic's investors and staff," drew 7.1 million. Then Bass did the part nobody else did: he searched for a METR reply. Across metr.org, METR's Substack, and the accounts of METR's CEO Beth Barnes and board member Chris Painter, from September 12 through September 14, no response to Sacks or Amodei was located. On Sacks's thread, 86 quotes and replies crossed 1,000 views. Zero came from METR, Redwood, or Coefficient accounts. The only SFF-funded organization accounts that showed up, two of them, conceded Sacks's point in the process.
The press sweep is even colder. Bass logged 31 press records on September 12-13 about the controversy. Ten named METR. Exactly one discussed METR's funding, and it was a blog fact-check, which means the straight-news count was zero. Think about that: the single most consequential claim in the entire panic, that the evaluator is not independent of the evaluated, drew no mainstream coverage at all inside a sweep that closed the same day a former White House AI czar made the claim publicly. The nightly news carried the fear in full and the conflict in almost nothing.
## 8. The mirror
Here is the part of Bass's write-up that stays with you, and it is the reason this piece exists. Jensen's argument is right, and his argument is also incomplete: the doomer machine is not a hoax in the sense of being fake. It is a hoax in the sense of being a business. The scare is real in its consequences. It moved two presidents and a senator in six days. It will move capital, regulation, and votes. The question is who operates the machine and who benefits.
Bass's closing claim, in his own words: "Anthropic's business model models itself after the very thing it claims to fear. Except Anthropic's ideology infects humans, not computers." The virus metaphor is doing real work, because an influence campaign and an epidemic share a structure: a carrier, a rate of spread, and a population that is not immune. The carrier here is a resignation post with no new information. The rate of spread is the 24-hour jump from X to cable. The susceptible population is a country seven weeks before a midterm, primed by a summer of real AI incidents to believe the worst.
And the counterfactual is China. Bass again, on point: "China is keeping messaging tight. That is why optimism for AI is so high in China." Jensen said the same thing at the summit: nobody in China is talking about doom; they are pragmatic. If the doomer narrative were a true description of the world, the country building the most AI would be the most terrified. It is the least terrified. The most frightened people in the world are the ones who own the stock. That single inversion is the whole story, and it fits the oldest template in the history of belief: apocalyptic anxiety is not distributed by exposure to the danger; it is distributed by the institutions that interpret the danger, and the interpreters are always the minority with the most to gain from the flock's fear.
**A second money trail, same machine.** There is one more input to this picture, and it comes from the other side. In May, Kevin O'Leary, building one of the country's largest data center campuses in Box Elder County, Utah, put forensic accountants on the groups opposing it, on national television: "Who would want us to stop building our electrical grid... which adversary would want that? There's only one: it's China." The documented result, in the Bitcoin Policy Institute's May 18 report *Foreign Influence in the Campaign against American AI* (authored by Sam Lyman, a former senior advisor to Treasury Secretary Scott Bessent), is that twelve US organizations opposing data center construction have collectively taken more than $39 million from foreign donors; that on April 29, Senator Bernie Sanders convened a Capitol panel on "the existential threat of AI" where two of the four panelists were Chinese government affiliates, Zeng Yi of the Beijing Institute of AI Safety and Governance and Xue Lan, chair of China's national AI governance committee, who used a US Senate platform to call the framing of the US-China AI race "an inaccurate narrative" and to argue for "safe zones" of cooperation on AI safety; and that Sanders and AOC had introduced an AI Data Center Moratorium Act the month before. Note what we are and are not saying here. The BPI is a pro-bitcoin think tank with its own interests, its China-effect claims are contested by scholars who argue state media amplifies existing American grievances rather than seeding them, and O'Leary is a data center investor with skin in the game. But run the same four questions from Section 10 against both trails and the shape is identical: the anti-data-center panic and the extinction panic are not spontaneous. One is fed by domestic capital that profits from fear of AI; the other by foreign influence that profits from slowing American AI. Two pumps, one machine, and in both cases the people sounding the alarm are not the people paying for it.
## 9. The machine does not have to be a conspiracy
There is a more unsettling possibility than corruption, and this record is obligated to state it: everybody involved may believe what they are saying.
Anthropic has been building this worldview since at least 2023, when its first Responsible Scaling Policy contemplated pausing scaling if safety fell behind capability. Amodei's September essay is not a crisis invention; it is the latest revision of a three-year-old institutional theory. Hubinger's 10% is a subjective probability, not a measurement, but subjective probabilities can be honestly held. Coxon may have quit in genuine alarm. Obama may have repeated a fear he actually has. Sacks's objection, Bass's audit, and this article are all products of the same environment: people acting on their sincere reading of the incentives in front of them.
None of those facts proves coordination, and this record does not claim it. Four hypotheses about the political adoption of AI doom deserve separation, because conflating them is what lets both camps dismiss each other. Policy convergence, that Democratic politicians independently find AI regulation attractive, is supported by observable behavior. Narrative adoption, that politicians increasingly repeat catastrophic-risk framing that originated inside the safety ecosystem, has evidence of overlap but no proven causal chain. Coordinated strategy, that Anthropic or its funders deliberately work with Democrats to make AI fear an electoral issue, has no evidence in this review. Electoral opportunism, that politicians privately disbelieve the risk and exploit it, is likewise unestablished. What the documents support is the first two, and what the documents also support is this: an idea is becoming an institution, and institutions do not need secret meetings to develop interests.
The structural facts do the rest without any malice. Anthropic spent more on federal lobbying in the first half of 2026 than in all of 2025, while the evaluation architecture it helped design moves toward law. METR capitalized roughly $71 million in six months, before the regulatory architecture stabilized, while advocating that its own industry practice become standard. Compliance regimes of this kind carry fixed costs that a frontier lab absorbs and a $50 million competitor, an academic group, or an open project cannot; intent and incidence are different things, and a lab can sincerely believe every word of the danger and still benefit from a regulatory structure that burdens its smaller rivals. If five frontier companies converge on the story that AI is extraordinarily dangerous, that only sophisticated organizations can build it safely, and that credentialed outside evaluators should inspect builders continuously, and government codifies that, nobody has colluded and an oligopoly exists anyway. Regulatory convergence is a quieter cartel.
If frontier AI really is dangerous enough to justify a new governance system, that system should be designed for the possibility that Anthropic is wrong, METR is wrong, Jensen Huang is wrong, the government is wrong, and WatchfulEye is wrong. That is what independence is for, and it is buildable: evaluators randomly assigned from a qualified pool instead of chosen by the labs; evaluation funding routed through blind trusts instead of lab-to-evaluator; mandatory rotation so no auditor becomes a fixture; dual adversarial evaluation, two independent assessors committing results before seeing each other's; a permanent public registry of major quantitative AI-risk predictions, with predictor, date, probability, deadline, and update conditions, so calibration can eventually be measured instead of argued; public evaluation compute so no auditor depends on free tokens from the audited; machine-readable conflict graphs anyone can query; and separation of the five functions now accumulating in one small network: measurement, standard-setting, interpretation, advice, and gatekeeping. Nobody should get to write the test, administer it, grade it, and decide the punishment.
The hardest problem in AI governance may not be aligning the machine. It may be aligning the institutions that claim authority to tell everyone else what the machine will become.
## 10. What to do with this
Three things, in order of difficulty.
**First, demand the disclosure.** Whatever you believe about AI risk, the conflict-of-interest question is settled by the documents, not by vibes: METR has no published conflict-of-interest policy, disclosed close personal ties between its own people and lab staff, and relies on free tokens from the labs it evaluates. Every proposal for an "independent evaluator" should be required to answer, in writing, the question METR could not answer on its own compliance table. That fix costs nothing and changes everything.
**Second, read the audit yourself.** Bass published everything, source codes and all, plus a second audit pass of his own work and a tracker of what could not be verified. And read its counter-audit too, because the hardest parts of his claim, where the stake sits and whether it funds METR, are not established yet, and he says so. That is what accountability looks like: not a resignation post, but a public ledger you can check. The counter-audit's conclusion, that the narrower governance problems are real regardless of the money route, is the version of this story that survives contact with the evidence.
**Third, notice the pattern for the next one.** The doomer cycle has a signature now: an insider message, an elite chorus, a velocity exploit, a midterm calendar, and a priesthood selling the problem and the solution from one money pile. Apocalyptic religion has run on this machinery for three thousand years, because it works: each failed prophecy strengthens the next one, and nobody ever has to produce the data. The next time you see "extinction" in a headline, ask the four questions: who said it, who confirms it, who funds the messenger, and what are they selling? Jensen asked the first two. Bass answered the third. The fourth, only you can answer, because it is about what you choose to believe about a claim that is, by construction, unfalsifiable in time to matter.
The state of the world is not that the smartest people are scared. It is that some of the people who own the thing being feared have found it profitable, and electorally convenient, to make you scared of it too. That is a context deficit. This is WatchfulEye's whole job: not to tell you what to believe about the future, but to show you who is writing the story about it, and why. The Eye does not predict. The Eye watches the watchers.
## Appendix: what the causal engine sees
Everything above is documentary. There is also a mechanical readout, and it is included here for the same reason Bass's ledger is included: because a claim you can rerun is worth more than a claim you can only believe.
WatchfulEye's causal engine propagates event primitives through domain graphs (sanctions, tariffs, energy, macro, regulatory, financial stress, labor, conflict), weights each edge, applies the current regime context, and emits a full audit trail: initialization, trigger arithmetic (evidence times transmission), every edge crossed with its weight, and every regime adjustment. Two primitives were built from the evidence in this record and run against the engine on September 15, 2026.
**Primitive A, the extinction-narrative regulatory shock.** Type regulatory_action, severity 0.85, novelty 0.70, actors Anthropic, OpenAI, CSET and Georgetown, evidence drawn from Sections 6 and 7 (the three-month window claim, the RSP-to-METR lineage, the Axios lobbying comparison). The engine returned 45 propagated effects across 8 graphs. The dominant audited path: evidence 0.68 times transmission 0.96 gives activation 0.65; the Regulatory Action to Compliance Cost Surge edge (weight 0.85) carries it to 0.50; the regime context (elevated volatility, war risk 0.55) applies a 1.32 multiplier at propagation, landing the compliance effect at 0.66. The counterfactual is the interesting number: delete the event and the engine attributes 0.86 of the compliance-cost surge to it, with the sector-wide uncertainty premium falling from 0.28 to zero and the smaller-competitor benefit from 0.28 to 0.17. The machine described in this record, run through the machine WatchfulEye actually operates, concentrates its damage exactly where Section 9 said it would: fixed costs on the big players, and a repriced risk premium on everyone adjacent.
**Primitive B, the circular-capital stress event.** Type liquidity_stress, severity 0.75, novelty 0.80, actors SoftBank, Stargate and OpenAI, evidence the untraced $7.7 billion stake, the circular financing pattern, and the coincidence of the extinction narrative with the funding window. Counterfactual attribution: 0.78. Remove the event and credit-contagion fear drops from 0.51 to zero across XLF, KRE, KBE, HYG and the AI complex (NVDA, MSFT, ORCL, AVGO, AMD).
**The intervention run.** Force the contagion node to full activation (1.0) and watch what the graph says the second-order damage looks like:
| Effect node | Baseline | Contagion at 1.0 | Delta |
|---|---|---|---|
| Credit contagion fear | 0.51 | 0.99 | +0.48 |
| Institutional equity derisking | 0.29 | 0.74 | +0.45 |
| Flight to quality | 0.25 | 0.64 | +0.39 |
| Broad earnings revisions | 0.09 | 0.22 | +0.14 |
Force the same node to zero, the contained case, and the same rows run in reverse: contagion fear collapses from 0.51 to zero, institutional derisking halves to 0.19, flight to quality goes to nothing. That asymmetry is the whole argument of this appendix in four rows: the circular-capital structure does not need to fail catastrophically to matter, it needs only one contagion node to light, and the graph shows the transmission before the tape does.
Two honesty notes, because this record holds itself to them. Activations are graph propagations under stated weights, not probabilities of real-world outcomes; the engine is a seatbelt, not an oracle, and SPECTRA treats these readouts as risk context rather than trade signals. And the primitives were authored from this record's own evidence, so the run tests the structure of the argument, not its truth. Both event primitives, the regime context, and the raw engine responses are reproducible from the inputs quoted here. Every number in this appendix has a step-by-step audit trail behind it, which is more than the $7.7 billion stake had when the story broke.
*This piece was written by the WatchfulEye research team. It reproduces the audit figures of Kevin Bass (@kevinnbass) from his September 14, 2026, thread, "I have conducted an audit of Anthropic's finances," and his repository github.com/kevinnbass/metr-money-figure, with credit and without alteration. Quotes from Jensen Huang and President Trump are from the All-In summit special, Los Angeles, September 14, 2026; the Coxon and Hubinger quotes are from their public posts, as reported by CNBC, BBC, PBS, and CBS; the Obama remarks were reported by the New York Times, NBC News, and TechCrunch (September 13, 2026); the Sanders bill was announced September 3, 2026. The ARC Evals attribution quotes are from Anthropic's Responsible Scaling Policy of September 19, 2023 (anthropic.com/news/anthropics-responsible-scaling-policy); METR's "adopted throughout the industry" line and its self-assessment are from its Frontier Risk Report of May 19, 2026 (metr.org/blog/2026-05-19-frontier-risk-report); the lobbying comparison is from Axios, July 21, 2026 (axios.com/2026/07/21/anthropic-ramps-up-lobbying-spending-ai-policy-fights). Our verification methodology, and the limits of it, are in the "About the audit" section above. We reproduced no figure we did not attribute, and we state plainly which claims remain unproven.*
## Related analysis
[All public analyses](https://watchfuleye.us/record)
## Corrections
If a source, a frame, or an inference on this page is wrong, we correct it here. contact@watchfuleye.us.
The record is public. The instrument is the app. [Download on the App Store](https://apps.apple.com/us/app/watchfuleye-live/id6758066132). [Get it on Google Play](https://play.google.com/store/apps/details?id=app.replit.watchfuleye).