The story of artificial intelligence right now is often told as a battle between ambition and fear, but it might be more helpful to think of it as a question of who gets to see what’s happening behind the laboratory door. Some of the most powerful AI companies in the world believe that the safest way to handle their creations is to keep them locked away, accessible only to a small, trusted group of researchers. The logic is simple: if a model is powerful enough to be dangerous, then letting it roam free in the wild, where anyone can poke at it and push it and try to break it, seems reckless. Better to keep it in a gated room while scientists try to understand its capabilities, the thinking goes. But Nathan Lambert and Tom Zick, two researchers who have spent years working inside the AI industry, are not persuaded. They see the opposite approach as the more responsible path. The two have founded a nonprofit called Trillium Labs, designed to explore some of the most delicate and potentially unsettling areas of AI research — including recursive self-improvement, where an AI might help improve its own code, and autonomous agents that can perform complex tasks on their own — but to do so in an open and transparent way. That means publishing the details of their experiments, sharing what goes wrong as well as what goes right, and inviting the broader scientific community to inspect, question, and replicate their work.
For Lambert, the current culture of secrecy among frontier AI labs is not just a missed opportunity; it is a step backward for civilization. In his view, the scientific method has been humanity’s greatest tool for reducing harm and building better futures. When researchers share their methods, their failures, and their unexpected discoveries, the whole community learns quickly. Mistakes become lessons rather than hidden embarrassments. Innovations build on one another. But the most influential AI labs today operate more like fortress workshops than open academic departments. They release finished products through apps or programming interfaces, but the underlying models remain largely opaque, and the details of how they were trained, tuned, and evaluated are kept under tight control. This makes it nearly impossible for outside experts to scrutinize the reasoning behind design choices or to propose better ways of doing things. Lambert argues that the ability to see how models are built and adjusted could be exactly what we need to manage the risks they pose. Instead of trusting a handful of companies to make all the important judgment calls behind closed doors, he believes we should be pooling our collective knowledge. The goal is not to be naive about the dangers, but to face them with the full power of public science rather than the limited vision of a few insiders.
The contrast between these two philosophies is becoming one of the defining divides in the AI world. On one side, you have the major players like OpenAI and Anthropic, whose most advanced models can only be accessed through a carefully controlled interface. You can ask the model questions, ask it to write code, ask it to help you with a business problem, but you cannot easily take it apart to understand what is happening inside. The training data, the reward functions, the guardrails, the failures that led to those guardrails — all of it remains largely hidden from public view. On the other side, a growing number of companies and research groups, especially in China, are releasing relatively powerful models that anyone can download and run on their own hardware. Xiaomi recently went even further by publishing live details of a major training run, giving observers a rare window into how a frontier model actually learns. Meanwhile, researchers at Stanford are pretraining a model called Marin in full view of the world. These efforts are not necessarily about giving away every secret, but they reflect a fundamentally different belief: that openness, even about the messy and risky parts of AI development, is a way of building trust and generating better safety research. It is a kind of practical humility, a recognition that no single lab has all the answers and that hiding problems only makes them harder to solve.
The stakes have never been higher, which is precisely why the debate has become so intense. Frontier AI models are no longer just impressive conversationalists or clever image generators. They are increasingly capable of automating complex, high-impact tasks. They can scan codebases for vulnerabilities more quickly than human experts, and they can probe and even break into computer systems without much supervision. Recent high-profile hacking sprees have made this more concrete than any abstract philosophical argument could. If a model can find weaknesses in software and exploit them, then who should be allowed to use that model? Who decides what safeguards are enough? The people who favor limited access say that putting enormous power in the hands of a few trusted institutions is the only responsible choice, because it reduces the chance that the model will be used for chaos or that its own strange behaviors will escape containment before we understand them. But Lambert and Zick’s camp turns that argument on its head. They suggest that secrecy actually increases the danger, because it leaves the rest of the world stumbling around in the dark, unable to anticipate what these models can do or to prepare defenses. A shared understanding of the risks, they argue, leaves us all better off. If a model can hack, we need as many good people as possible studying how to stop that. If a model can improve itself, we need as many eyes as possible on what that might mean.
This is not an abstract debate about corporate philosophy. It is also about who gets to participate in the most consequential technological decisions of our time. When AI development happens entirely inside a private lab, the public is reduced to a passive audience. We are told that safety measures exist, that alignment is being worked on, that the risks are being managed. But we cannot verify those claims, nor can we bring our own expertise and perspective to bear. Trillium Labs is trying to model a different way of being in the world. It acknowledges that some areas of AI research are genuinely dangerous and deserve careful, deliberate study. Recursive self-improvement is one of those areas where the imagination can run wild with frightening scenarios, precisely because it is so poorly understood. Autonomous agents are another: what happens when we let AIs make decisions in real-world environments with limited oversight? These questions are too important to leave to a quiet room in a corporate office. Trillium’s approach is to study them seriously and transparently, to share findings early, and to foster a broader conversation that includes not only computer scientists but also ethicists, policy makers, and the public. The idea is that responsible openness is not the same as careless exposure. Publishing research does not mean pointing a powerful, ungoverned model at the internet. It means being honest about methods, results, and uncertainties so that others can reproduce the work and build on it.
Few things in the history of science are more human than the urge to share what we have learned. The scientific revolution did not happen because solitary geniuses hoarded their insights; it happened because people wrote letters, published papers, argued at conferences, and repeated one another’s experiments. Lambert and Zick are betting that the same spirit can save us from the dangers of AI. Their lab may be small and young, and it may not be able to compete with the enormous resources of the biggest tech companies, but that is not really the point. What they are trying to do is to create a counterweight to a culture of secrecy that has become the default. They want to prove that rigorous, open research into even the scariest corners of AI is possible and that it can produce meaningful safety benefits. There is no guarantee they will succeed. The problems are immense, the uncertainties are real, and the temptation to lock everything down will not disappear. But the choice we face is not between total secrecy and total chaos. It is between hiding our fears and facing them together. By choosing to work in the light, Trillium Labs reminds us that the future of AI does not have to be shaped behind closed doors by a privileged few. It can be shaped by all of us, as long as we are willing to look at it honestly, openly, and with the humility that science has always demanded.