Salvatore Sanfilippo, the software engineer who created the open source database Redis and writes under the handle antirez, published a rebuttal this week to Anthropic chief executive Dario Amodei’s recent essay on AI safety. Sanfilippo’s target is narrower than the headline threats Amodei raised. He argues the real danger sits inside frontier labs, in the hands of executives nobody chose for the job.

Amodei’s essay had focused on the danger of open weight models spreading capability and on China closing the compute gap with the United States. Sanfilippo spends most of his post disputing both points: he argues leaks inside closed labs are a bigger threat than public releases, since a single employee with the wrong intentions can expose a frontier model that was never meant to reach the public at all.

But his sharpest claim sits underneath the technical argument. The existential risk, in his telling, is not code that escapes or a country that races ahead. It’s that a small cluster of executives, spread across labs worldwide, hold power over decisions with civilizational stakes. Sanfilippo writes that these leaders were never selected for that role, that chance produced the arrangement, and that owning GPUs and capital does not qualify anyone to answer for the rest of humanity.

The essay landed the same week Meta chief executive Mark Zuckerberg published a Wall Street Journal op-ed arguing the opposite position on where AI power should sit. The two pieces diverge on almost everything except the shared premise: this decision, whoever ends up making it, matters more than most policy debates happening in public right now.

Sanfilippo’s case is strongest as a legitimacy critique, and it holds up under scrutiny. Nobody ran for office promising to decide whether a model trained on unrestricted biological research ships to the public. No electorate ratified the executives at Anthropic, OpenAI, Google DeepMind, or Meta before they inherited that authority. The role selects for people who raised capital and built infrastructure, not for people with a mandate to weigh civilizational risk on behalf of billions who never voted on the question.

The weakest link is what replaces the current arrangement. “Democratic control of AI” is easier to demand than to specify. Which body actually casts the vote: national governments that disagree on almost everything, a body modeled on nuclear oversight that frontier labs could route around by relocating, or some new institution built from scratch with no history of enforcing anything against companies that hold the compute? Sanfilippo’s own proposal, a joint safety organization recognized by the governments where frontier labs operate, resembles arms control more than democracy, and arms control regimes took decades to build even for weapons that are far easier to define than a model checkpoint.

That gap between the critique and the fix is the real story, not a reason to dismiss the critique. The absence of a workable alternative does not restore legitimacy to the current setup. It just means the fix has to be built, not assumed. Any operator shipping products on top of frontier models should treat the question of who gets to call a model safe as unresolved, and watch whether anything like the joint oversight body Sanfilippo describes gets built before the next capability jump makes the debate moot.

Salvatore Sanfilippo (antirez) published this argument on his blog, antirez.com, on July 28, 2026.