Don't Blame the Bomb.

AI isn't the villain — the people building it and the government refusing to govern it are. A lesson from WebEx's churn crisis, a county that acted while Washington didn't, and what accountability with teeth looks like.

In the early days of WebEx, we were bleeding. More than half our customers left every year. Fifty percent churn is not a business, it's a bucket with a hole in it.

And everyone knew exactly whose fault it was — someone else's. Finance blamed Sales for selling to the wrong accounts. Sales blamed Marketing for garbage leads. Marketing blamed Engineering for shipping a product nobody wanted. Engineering, presumably, blamed the weather.

Then Subrah Iyar, our CEO, called an all-hands. No executive would receive a performance bonus until churn dropped below 10%. Not the CRO. Not the CMO. Not the VP of Engineering. Nobody.

The finger-pointing stopped inside a week. Cross-functional teams formed, with actual customers and prospects in the room. Six months later, churn was under 10%.

Nothing about the technology changed. What changed was that the people with the power to fix it became the people who paid the price if they didn't.

Now apply that to a country that has forgotten how agency works.

On the September 15 episode of Pivot, Scott Galloway put it as directly as it can be put: "The bomb didn't kill 50,000 Japanese, we did." He corrected the number a few minutes later — roughly 50,000 in the initial blasts, and somewhere between 150,000 and 250,000 across Hiroshima and Nagasaki once fallout is counted.

The point survives the correction, and it's the whole argument. A bomb is an object. It has no intent, no judgment, no conscience. The physicists who built it and the government that chose to use it are the moral agents in that sentence, and history has assigned responsibility to both — correctly, since some of the builders petitioned against its use and the government proceeded anyway.

Builders and deciders. Two parties, both accountable, neither permitted to hide behind the object.

Galloway's version for AI: it isn't that there's a 10% chance AI kills us. It's that there's a 10% chance these companies and their leaders do. Saying "AI will kill 10% of humanity" is grammatically identical to saying electricity killed people. Electricity doesn't decide anything. Neither does a model.

There is a word for knowing a risk, holding authority to address it, and choosing not to.

It isn't gridlock. It isn't polarization. It's negligence, and negligence has elements.

Galloway reaches for a case most people have forgotten. In January 2001, Diane Whipple, a 33-year-old former All-American lacrosse player, was mauled to death in the hallway of her San Francisco apartment building by two Presa Canario dogs. Her neighbors owned the dogs. Her neighbors were prosecuted. The law's reasoning was straightforward: if you own an agent capable of lethal harm, and you know it is capable, and you let it off leash, you are on the hook for what it does.

We are applying the same logic now to parents who leave an AR-15 unsecured. But we have declined to apply it to the only trillion-dollar industry in modern economic history operating with essentially no regulation at all. Executives get to keep every dollar of upside their agents generate while describing the downside as something Frankenstein did.

Own the agent, own the outcome. Galloway's position on the extreme case is unambiguous: if one of these systems is used to create a pathogen that kills people, the executives responsible go to prison.

Which brings us to the specific fear.

The catastrophic AI risk isn't a sentient model that decides it dislikes us. It's a competent, motivated, mid-talent actor using an unguarded system to compress twenty years of virology into a weekend. Biology is the one domain where a single person can produce a global casualty event. Software bugs get patched. A pathogen doesn't.

And here the article's own thesis lands hardest. The greatest live threat to American disease control is that a frontier lab ships something that lowers the barrier to an engineered virus. The agency charged with that threat sits inside HHS. Galloway's read: a competent HHS would already have forty or fifty scientists and technologists sitting in the offices of these companies, not requesting cooperation but compelling it, and asking the models directly how one would build a super virus before anyone outside gets to touch them.

The CDC should be on-site. Not as guests.

That word — compelling — is where Galloway parts company with the industry's own proposal.

Dario Amodei has called for independent evaluators to review companies' safety practices, and Sam Altman and Elon Musk have backed a slowdown. Galloway is unimpressed by the shape of it. An evaluator embedded at a company, earning a fraction of what the executives earn, with no statutory authority, is a chaperone at the all-hands. She has no teeth.

The distinction matters enormously, because it's the difference between a program that works and one that provides cover. So here's his package, and none of it is exotic — it's the FAA, and it's the SEC after 1929:

Pre-market safety review for every model above a defined capability line, before deployment. Not after.

Mandatory incident reporting on the NTSB model. Something goes wrong, you file immediately.

Funding via a transaction fee on frontier compute, the way FINRA is funded — so taxpayers aren't subsidizing the supervision of the richest companies in history.

An independent evaluator with subpoena power. The single feature every fast-moving industry resists and requires.

Internationally, the gap is starker. We have cooperated with adversaries on nuclear and biological weapons for eighty years through the IAEA and its equivalents. We have nothing comparable for AI. Galloway's minimum viable step is a room containing the American and Chinese heads of state and a two-page memorandum covering the interests both nations demonstrably share: no one builds a super virus, our kids don't kill themselves, and misinformation doesn't set our streets on fire.

Meanwhile China already regulates. Bots can't impersonate a person indefinitely, kids face time limits, and there are constraints on AI-generated information. Some of that machinery serves censorship — Galloway says so plainly. It also reflects a government that took the risk seriously. Roughly three-quarters of the Chinese public reports optimism about AI. Ours doesn't, and our public is the one being told to trust the vendors.

And now the local part, which is the most encouraging thing in this article.

In April 2025, Santa Cruz Works hosted Beaches, Books, Budgets, and Bots at Chaminade. Our fireside chat included Zach Friend, alongside John MacMillan, Lori Kletzer, Gary Griggs, and Dante Di Gregorio.

Friend had already done what Washington wouldn't. In September 2023, Santa Cruz County became one of the first jurisdictions in California to adopt a policy governing employee use of AI — protecting personal information, disclosing when the public is interacting with an AI tool, offering a choice to opt out. It was built through a working group that included industry, organized around transparency and informed consent. That work is why he was at the White House for the signing of the executive order on safe, secure, and trustworthy AI, telling the administration how counties could help shape the federal framework.

A county of 270,000 wrote a workable AI policy in a few months, with the regulated parties at the table, and did not strangle a single startup. California has since signed a package of thirteen bills covering minors and AI companion chatbots, with penalties reaching a million dollars per child.

That executive order is gone now. Congress has spent its energy trying to preempt states rather than replace what was removed. Galloway's assessment of why is blunt — he describes an administration he considers not merely uninformed but bought, with the people around it angling for a cut. You don't have to adopt his vocabulary to notice the pattern: a patchwork of counties and states is doing the work, and the only level of government with the authority to do it nationally is the one doing nothing.

We're not short on warnings. We're short on a Subrah — someone willing to stand in front of the room and say nobody gets paid until we fix this.

Related Articles

Next
Next

We're All Tech Bros Now