To make advanced AI safe, the most durable tool may turn out to be watching how everyone uses it — the models, the companies, and eventually the rest of us. In June 2026 the US briefly barred foreign access to Anthropic’s most capable model after it surfaced serious dual-use risks, and Europe is still fighting over whether to scan private messages to catch a handful of bad actors. Three honest positions disagree about whether that trade is acceptable, and none of them is the obvious villain. So the question this lesson puts to the room is simple to ask and hard to answer: to make AI safe, must we accept being watched — and who decides?
Contents
The same topic is scaled across three levels below. A universal set of AI-governance and surveillance vocabulary runs through all three; each level scales the reading, the tasks and the register. Pick the one that fits you — or, if you teach, read all three and choose per group.
Read the companion article → B1–B2 version · C1 version
About The BEBB Method — The Agency Loop
Every task in this lesson runs on the BEBB Method — The Agency Loop, a five-step framework for using AI in language learning without letting it replace your own thinking. It is my own configuration of established best practices in human-AI collaboration, built in direct response to Gerlich (2025) on cognitive offloading, and informed by the “AI Sandwich” tradition (Ippolito, 2023) and “AI as Critic” scaffolding (Mollick, 2024).
Agency = your own capacity to decide, think, and act. In this method, you keep your agency at every step — you, not the AI, remain the one deciding what happens to your thinking. The Agency Loop (dt. etwa: Handlungsfähigkeit im Umgang mit KI — du bleibst die Entscheider·in).
The five steps
Think first — form your own view before you touch any tool.
Use AI for facts — let the tool gather information, not opinions.
Draft yourself — write it in your own words, from your own head.
Challenge with AI — ask the tool to attack your position and find its weakest point.
Combine — fold the best of the challenge back into a stronger version that is still yours.
How the levels use the loop
B1 = Tasks 1 + 3 (two cycles): think first, then challenge and finalise with AI.
B2 = Tasks 1 + 3, with Task 2 optional if there is time.
C1 = Tasks 1 + 2 + 3 (the full loop, including the assigned-position debate).
For teachers
This lesson was tested with several groups in Germany over the course of one week, at all three levels — the C1 jigsaw “Safe — or Watched?” and simpler rebuilt B1 and B2 readings, across mixed-industry corporate groups and 1:1 clients. It ran well as a 60-minute session at B1/B2 and a full 90-minute session at C1.
A few things to protect:
Stay neutral — and this week the neutrality bar is hard. There is no tidy moral close waiting at the end. Argue every position’s strongest form and let the room sit in the genuine disagreement; do not resolve it with “but of course we need some rules” or “but of course privacy matters.” One extra wrinkle: you visibly use an AI stack and teach an AI method, so students may assume you lean a particular way. Do not confirm any lean; if asked directly, ask them which position they think you hold and why.
Protect the “what surprised you” moment. The strongest learning in this lesson is a participant discovering that a position they had dismissed has a real case. When someone says “I didn’t expect to find that convincing,” slow down — that is the lesson working.
Mixed-level guidance. A security, legal or compliance participant may already own half the vocabulary; an engineering or HR participant may not. Surface gaps live at Task 1, and lean on the “define any difficult word in eight words or fewer” mechanic in the research prompt.
Micro-research is the engine. The warm-up research task is what brings real figures — the Chat Control error rates, the Fable timeline, the CNIL fine — into the room. Do not skip it to save time; without it the debate becomes opinion-only.
The share-back is load-bearing. At C1 the lesson is a jigsaw: each student reads only one position in depth and meets the other two through their colleagues’ presentations. If the share-back is weak, half the room never really meets those positions. Feed a drifting presenter their position’s strongest anchor and ask them to re-deliver one sentence.
60-minute block (B1 / B2)
Warm-up + micro-research · 11 min
Vocabulary · 6 min
Task 1 — Anchor Your Own Position · 8 min
Reading · 9 min
Comprehension · 7 min
Task 3 — Challenge With AI (B2: Task 2 first if time) · 10 min
Discussion · 9 min
90-minute block (C1)
Warm-up + micro-research · 12 min
Vocabulary · 8 min
Task 1 — Anchor Your Own Position + draw your card · 8 min
Reading (jigsaw) · 8 min
Task 2 — Build and Teach Your Position · 18 min
Comprehension · 6 min
Discussion · 14 min
Task 3 — Challenge and Finalise · 8 min
Homework setup · 2 min
45-minute fallback: keep the warm-up micro-research (shortened to items 1–3 only), the three position summaries only (skip the deep readings), and one focused round of Task 3 (challenge your position with AI, then revise). Drop Task 2 and cut the discussion to two questions. The lesson still completes one full Agency Loop this way — think first, gather facts, draft, challenge, combine — which is the minimum that makes it worth doing.
A note on the three-way distinction: much of the disagreement in this debate is definitional, and it helps to separate three things before the room argues — AI safety (making the model behave), AI governance (rules about who may build or access frontier models), and AI-enabled surveillance (using AI to observe how people use AI, and people generally). The claim the lesson tests is that the first two inevitably pull you into the third. If participants conflate them in the warm-up, that confusion is itself the first teaching moment.
B1 version
Warm-up — micro-research (single prompt)
Before you search, take 30–60 seconds and write down what you already know or believe about AI safety, or about being watched online. Just keywords. This is your starting point — your own thinking comes first. Agency means your own power to decide, think, and act; you keep it at every step, and the AI never decides for you.
Umbrella question: How does your item help answer the big question — to make AI safe, must we accept being watched?
For your item, find:
What is it? (one or two simple sentences)
One key fact, number, or example.
Why does it matter?
Your item list (take one — items 1–3 first; 4–6 if there is time):
The Anthropic AI ban — the US stopped other countries using a powerful AI model for two weeks in June 2026
The 1990s “Crypto Wars” — when a government tried to control secret codes on the internet, and failed
The German census case of 1983 — when the top court said people have a right to control their own data
“Chat Control” — a European plan to scan private messages; how often it makes mistakes
Watching AI use — how a company could check who uses a powerful AI model (harder item)
“Safe city” cameras — how one country sells AI camera systems to about 75 other countries (harder item)
Paste this into your AI tool with your item filled in:
LEVEL: B1
I'm preparing for a Business English lesson about AI safety and surveillance.
The big question is: to make AI safe, must we accept being watched — by
governments and companies?
My research item is: [MY ITEM]
In clear, simple B1-level English (maximum 100 words), give me:
1. What it is — one or two short sentences.
2. One key fact, number, or example.
3. Why it matters to the question "to make AI safe, must we accept being
watched?"
Keep it short enough to say to my group in about two minutes. Define any
difficult word in eight words or fewer.Vocabulary
Match each word or phrase (1–8) to its definition (A–H). Guess first, then check the key.
safety
surveillance
to monitor
dual-use
privacy
proportionate
a trade-off
function creep
A. keeping people safe from harm or danger
B. watching people closely and all the time, often without asking them
C. to watch or check something for a clear reason
D. able to be used for good and for harm
E. your right to keep parts of your life private
F. fair in size compared to the goal; not more than you need
G. when you accept something bad to get something good
H. when a tool made for one job is slowly used for more and more other jobs
Task 1 — Anchor Your Own Position
Prepare alone (2 min). Before you read anything: to make AI safe, how much watching would you personally accept — of companies, and of ordinary users like you? Write 4–6 keywords only. No AI yet — this comes from your own head.
Share (3 min). Tell a partner your answer in about a minute. Use at least two vocabulary words from the list above.
Reading — Safe, or Watched?
(1) AI is very powerful now. The same AI that helps doctors could also help a bad person plan an attack. This is called dual-use — it can be used for good and for harm. So many people ask: how do we keep AI safe?
(2) One idea is simple but hard. To stop bad people using AI, you have to watch how everyone uses it. This means more surveillance — more watching. And this is where people start to disagree.
(3) Some people say: a little watching is the price of safety. In June 2026, the United States stopped other countries from using a very powerful AI model for two weeks, because it was too risky. They say this was good and careful. If free countries do not watch AI, then only the bad governments will — and they will watch in a much worse way. Some watching, with clear rules, is proportionate — fair for the danger.
(4) Other people say: the government is the real danger. In the 1990s, a government tried to control secret codes on the internet. It failed, and the codes spread anyway. These people say big rules only help big companies and hurt small ones. Do not watch everyone. Instead, punish people only after they do something bad.
(5) A third group says: do not build the watching machine at all. In 1983, Germany’s top court said people have a right to control their own data. There is “no such thing as a small piece of data,” the court said. Today, Europe wants to scan private messages to catch criminals. But the numbers are bad: the scans are wrong 13–20% of the time, and they catch almost no one. And function creep is a real danger: a tool made for one job slowly starts doing more and more jobs. Once you build the watching machine, it never stops growing.
(6) All three groups agree on one thing: AI can be dangerous. But they do not agree on the answer. Is being watched the price of being safe? Or is a free country still safe without watching everyone? There is no easy answer — and that is the point.
Comprehension
Answer from the reading. Note the paragraph.
What does “dual-use” mean? (¶1)
What did the United States do in June 2026, and why? (¶3)
What did Germany’s top court say in 1983? (¶5)
How often are the message scans wrong, according to the reading? (¶5)
What is the one thing all three groups agree on? (¶6)
Task 3 — Challenge With AI
Write (alone, 4 min). Answer this question in 3–5 sentences, from your own head, no AI: To make AI safe, would you accept more watching of how people use it? Give one reason.
Challenge (3 min). Paste your answer into an AI tool with this prompt: “In simple English, what is the strongest argument against what I just wrote?”
Revise (3 min). Read the answer. Then rewrite your 3–5 sentences into a stronger version — but keep your own view unless the AI really changes your mind.
Discussion
Do you feel watched online or at work? When?
Would you give up some privacy to be safer? How much?
Is there a machine or app you started using for one thing, and now it does many things?
Do you trust companies more, or governments more, with your data? Why?
When is watching helpful, and when does it go too far?
B2 version
Warm-up — micro-research (single prompt)
Before you search, take 30–60 seconds and write down what you already know or believe about AI safety and surveillance — about being watched by governments or companies. Just keywords. This is your starting point — your own thinking comes first. Agency means your own capacity to decide, think, and act; you keep it at every step, and the AI never decides for you.
Umbrella question: How does your item help answer the debate — to make AI safe, must we accept being watched, and who should decide?
For your item, bring back:
What is it? (one or two precise sentences)
One key fact, figure, or example that shows its scale.
Why does it matter to the debate?
Your item list (take one — items 1–3 first; 4–6 only if there is time):
The Anthropic Fable/Mythos export ban — what happened between 12 June and 1 July 2026
The 1990s Crypto Wars (the Clipper chip) — why an attempt to control encryption failed
The German Volkszählungsurteil (1983) — the census ruling and “informational self-determination”
“Chat Control” — the EU message-scanning proposal and its error-rate and hit-rate numbers
KYC-for-compute — how you could technically “police” access to a powerful AI model (stretch)
China’s “safe city” surveillance exports — sold to roughly 75 countries (stretch)
Paste this into your AI tool with your item filled in:
LEVEL: B2
I'm preparing for a Business English lesson about AI safety and surveillance.
The debate is: to make AI safe, must we accept being watched — by governments
and companies — and who should decide?
My research item is: [MY ITEM]
In clear B2-level English (maximum 150 words), give me:
1. What it is — one or two precise sentences.
2. One key fact, figure, or example that shows its scale or significance.
3. Why it matters to the "safe or watched?" debate.
Keep it tight enough to present to my group in about two minutes. Define any
difficult term in eight words or fewer.Vocabulary
Match each word or phrase (1–10) to its definition (A–J). Guess first, then check the key.
dual-use
surveillance
to monitor
to gatekeep
proportionate
a chilling effect
function creep
informational self-determination
regulatory capture
a trade-off
A. technology that can be used both for benefit and for harm
B. watching people continuously and systematically, usually without their consent
C. to track or check something for a defined, limited purpose
D. to control who is allowed access to something
E. reasonable in scale compared to the aim; not more intrusive than necessary
F. when people stop doing something legal because they fear being watched or punished
G. the gradual expansion of a tool or power beyond its original purpose
H. your right to decide who knows what about you
I. when rules end up serving the established companies that helped write them
J. accepting one thing you want less in order to get another thing you want more
Task 1 — Anchor Your Own Position
Prepare alone (3 min). Before you read any argument: to make AI safe, how much watching would you personally accept — of the companies that build the models, of the users, of you? Write 5–7 keywords only. Use three vocabulary items from the list. Work from your own head first — no AI.
Exchange (5 min). Tell a partner your position in about 90 seconds: what you would accept → what you would refuse → where your line sits. Your partner listens for the three vocabulary items and for where the real tension is.
Reading — Safe, or Watched?
(1) Frontier AI is dual-use: the same model that helps design a vaccine could, in the wrong hands, lower the barrier to a bioweapon or a large cyberattack. That is why the question of AI safety keeps arriving at an uncomfortable place. To catch the rare bad actor inside a tool that everyone uses, you may have to watch how everyone uses it. In June 2026 this stopped being theory: the United States barred foreign access to Anthropic’s most capable model for two weeks after it surfaced serious risks, then restored it once new guardrails were agreed. So — safe, or watched? Three honest positions pull in different directions.
(2) The first position says some watching is the price of safety. If frontier AI is genuinely dangerous, someone must monitor how it is used — and better a democracy than an authoritarian state. Supporters point to nuclear inspection as the model: you do not search every home, you check a small number of observable facilities. Rules that target the frontier — licences for the biggest models, checks on who can access them — could police the danger without reading anyone’s email. On this view, the two-week ban was careful detection working exactly as designed, and a proportionate loss of privacy is a fair price for preventing catastrophe.
(3) The second position says government control is the real danger. Gatekeeping powerful technology has been tried before: in the 1990s Crypto Wars, an attempt to control strong encryption collapsed while the code spread worldwide anyway. Critics warn of regulatory capture — rules written with big companies end up serving big companies, locking out smaller ones behind a government-built wall. And a government that can switch off a critical tool overnight, worldwide, creates a chilling effect on everyone who builds on it. Better to police AI after the fact, through liability and targeted checks, than to watch everyone in advance.
(4) The third position says: do not build the watching machine at all. Germany’s Constitutional Court ruled in 1983 that there is “no such thing as a trivial datum,” establishing a right to informational self-determination. Europe is testing the opposite logic right now with “Chat Control,” a plan to scan private messages: the EU’s own figures show the tools err 13–20% of the time and that only a vanishingly small fraction of scanned content is actually illegal — scan everyone, catch almost no one. And function creep is the historical rule: powers built for terrorism drift to tax, then to protest. In 2024 France fined Amazon €32 million for tracking warehouse workers too closely; the watching always reaches ordinary desks eventually.
(5) Notice what all three share. None of them denies that frontier AI is dangerous. They disagree about the method — whether safety requires watching, whether watching can be kept proportionate, and whether a free society has other ways to stay safe. That is the honest shape of the debate: the risk is real, and state control has real costs, and reasonable people genuinely disagree about which matters more.
Task 2 — Draft Your Argument
Optional — recommended if time permits.
Choose one of the three positions and write 5–7 sentences arguing for it, from your own head, no AI:
Some watching is the price of safety — democracies must monitor frontier AI first.
Government control is the real danger — police AI after the fact, do not watch everyone.
Do not build the watching machine at all — use constitutional limits and liability instead.
Push your case as hard as you honestly can, even if it is not the side you first chose. You will use this draft in Task 3.
Comprehension
Answer from the reading. Note the paragraph.
What does “dual-use” mean, and why does it make AI safety hard? (¶1)
What model does the first position use for how to watch frontier AI, and how does it work? (¶2)
What is “regulatory capture,” and why does the second position fear it? (¶3)
What do the Chat Control numbers show, according to the third position? (¶4)
What is the one thing all three positions agree on? (¶5)
Task 3 — Challenge With AI
Draft (alone, 4 min). Take your Task 2 argument — or, if you skipped Task 2, write 5–7 sentences now on whether making AI safe is worth accepting more surveillance. From your own head, no AI.
Challenge (3 min). Paste it into an AI tool: “In clear, simple English, what is the single strongest argument against my position?”
Revise (3 min). Read the answer, then rewrite your argument into a stronger 5–7 sentences that answers the objection — without giving up your view unless you are genuinely persuaded. Present your revised version to the group.
Discussion
To make AI safe, how much watching would you personally accept — of companies, and of users like you? Where is your line?
The US switched off foreign access to a powerful AI model for two weeks. Responsible caution, or a worrying precedent?
“Scan everyone to catch almost no one” — can numbers like a 13–20% error rate ever justify scanning private messages? What would have to change?
Where does this reach your desk? Your AI use at work is increasingly logged. Where is the line between a sensible audit trail and surveillance?
Do you trust governments or companies more with this kind of power? Why?
Germany has a strong privacy instinct but no frontier AI model of its own. Is that instinct a strength that should set the rules — or a luxury that leaves Europe following others?
C1 version
Warm-up — micro-research (single prompt)
Before you search, take 30–60 seconds and write down 2–3 things you already know or believe about AI safety and surveillance. Just keywords. This is your starting point — your own thinking comes first. Agency = your own capacity to decide, think, and act; you keep it at every step, and the AI never decides for you.
Umbrella question: How does your item bear on the debate — to make AI safe, must we accept being watched, and who decides?
For your item, bring back:
What is it, in one or two precise sentences?
One anchor fact, figure, or example — or, for a concept item, one concrete example.
What trade-off or counter-position does it expose?
Your item list (take one — items 1–3 first; 4–6 if attendance is full or there is time):
The Anthropic Fable/Mythos export ban — precisely what happened between 12 June and 1 July 2026
The 1990s Crypto Wars (the Clipper chip) — why gatekeeping encryption failed, and what it cost
The Volkszählungsurteil (1983) and informationelle Selbstbestimmung — the ruling and its principle
Chat Control (the EU message-scanning proposal) — the error-rate and hit-rate figures in detail
KYC-for-compute — how you would technically “police” access to a frontier model (stretch)
China’s AI-surveillance export model — “safe cities” in roughly 75 countries (stretch)
Paste this into your AI tool with your item filled in:
LEVEL: C1
I'm preparing for a Business English lesson framed as the debate "To make AI
safe, must we accept being watched?" — the tension between AI safety, AI
governance, and AI-enabled surveillance, and who should decide.
My research item is: [MY ITEM]
In clear C1-level English (maximum 200 words), give me a 90-second present-back
I can read aloud to the room:
1. What it is — one or two precise sentences.
2. One anchor fact or statistic — or, for a concept item, one concrete example.
3. One trade-off or counter-position it exposes.
Use the language a senior professional would use in a meeting. Keep it tight
enough to present in about two minutes, and define any technical term in eight
words or fewer.Debrief — the three-way distinction: most disagreement in this debate is definitional. Before you go further, separate AI safety (making the model behave), AI governance (rules about who may build or access frontier models), and AI-enabled surveillance (using AI to observe how people use AI, and people generally). The claim you test today is that the first two inevitably pull you into the third.
Vocabulary
Match each term (1–12) to its definition (A–L). Guess first from the word itself or from what you know about the topic, then check the key.
to gatekeep
to steelman
function creep
dual-use
a chilling effect
regulatory capture
proportionate
to surveil
informational self-determination
an incumbent
the thin end of the wedge
to launder X as Y
A. when people stop doing something legal because they fear being watched or punished
B. reasonable in scale compared to the aim; not more intrusive than necessary (Ger. verhältnismäßig)
C. to present the strongest, fairest version of a position you disagree with (opposite: to strawman)
D. technology that can be used both for benefit and for harm
E. to control who is allowed access to something
F. when rules end up serving the established companies that helped write them
G. the gradual expansion of a tool or power beyond its original purpose
H. a small first step that opens the way to something much larger
I. an established player that already dominates a market
J. to watch people continuously and systematically, usually without their consent
K. to disguise one thing as another, more acceptable thing
L. your right to decide who knows what about you (Ger. informationelle Selbstbestimmung)
Phrases for contested authority (use these in Tasks 2–3 and the discussion):
While conceding that X, one might still argue Y.
It does not follow that… / That is not to say that…
The strongest case for the other side is…
Where I’d push back is… / The place I part ways is…
The control-verb spectrum: to license, to sanction, to greenlight, to claw back, to gatekeep.
The verb family German collapses into überwachen/prüfen: to monitor (track for a defined purpose) / to observe (watch neutrally) / to surveil (watch people systematically, covertly or coercively) / to audit (check formally against rules).
Task 1 — Anchor Your Own Position
Before you see any argument, put your own instinct on paper. You will return to it in Task 3.
Prepare alone (3 min, no AI). Write 2–3 sentences: to make AI safe, how much watching — of companies, of users, of you — would you personally accept? This is your anchor.
Deliver (2 min). Read your sentences to a partner. No debate yet.
Reflect (1 min). Note one word that captures your gut position.
Now draw your position card. Your trainer will hand out cards A, B and C at random. Your card decides which position you will build and teach — regardless of what you just wrote. That gap is deliberate.
Reading (jigsaw)
First read all three summaries below (everyone reads these). Then read in full only the deep reading for the position on your card. You will meet the other two positions properly through your colleagues’ presentations in Task 2.
The three positions — summaries (everyone reads all three)
Position A — Security & Control: “Some watching is the price of safety.”
Frontier AI is dual-use: the same model that designs vaccines can lower the barrier to bioweapons or industrial-scale cyberattacks. Dario Amodei, CEO of Anthropic, has said “AI-enabled authoritarianism terrifies me” — and argues that precisely because AI could become a perfect tyrant’s toolkit, democracies must build monitoring and gatekeeping first, before authoritarian states define the norms. On this view, the 12 June 2026 ban on foreign access to the Fable model was responsible detection working as designed. A limited, law-governed loss of privacy at the frontier is a proportionate price for preventing catastrophe.
Position B — Freedom & Innovation: “Government control is the real danger.”
Gatekeeping dual-use software has been tried: in the 1990s Crypto Wars, Washington’s Clipper chip was dead by 1996 while strong encryption spread worldwide anyway. Marc Andreessen warns that rules written with incumbents serve incumbents — regulatory capture that entrenches a few labs behind a government-built moat. Police AI after the fact, through liability and targeted audits, not pervasive monitoring. The Fable ban shows how arbitrary state control of a critical tool can be — switched off overnight, worldwide.
Position C — Human Dignity & Democratic Limits: “Don’t build the apparatus at all.”
Germany’s Constitutional Court ruled in the 1983 Volkszählungsurteil that there is “no such thing as a trivial datum” (kein belangloses Datum). The EU’s own Chat Control figures show detection tools err 13–20% of the time and only 0.000002735% of scanned content was confirmed illegal — scan everyone, catch almost no one. Digital-rights advocates like Patrick Breyer argue “a little surveillance for safety” is the move behind every historical over-reach; once built, monitoring ratchets (function creep). Make AI safer through constitutional limits, data minimisation, transparency and liability — not by watching everyone.
If you drew Position A — read this in full
Begin with the risk. A frontier model is dual-use in the strict sense: the capability that drafts a vaccine protocol can, in the wrong hands, lower the barrier to a bioweapon or an industrial-scale cyberattack. Dario Amodei, chief executive of Anthropic, is blunt about the political danger too: “AI-enabled authoritarianism terrifies me,” he has said, warning that advanced AI could become a perfect tyrant’s toolkit. Position A draws the uncomfortable conclusion: precisely because the technology is this dangerous, someone must watch how it is used — and better the democracies than the alternative.
The model here is nuclear non-proliferation. The IAEA does not inspect every household; it monitors a small number of observable facilities. Frontier AI, the argument runs, has the same property: it depends on concentrated compute that is detectable, excludable and quantifiable. Know-your-customer rules for compute providers, licences for the largest training runs, and audit access to frontier labs would police the choke point without reading anyone’s email.
On this reading, the Fable episode was the system working. On 12 June 2026 the US barred foreign access to Anthropic’s most capable model after it surfaced serious dual-use vulnerabilities; on 1 July access was restored — initially to roughly one hundred trusted critical-infrastructure organisations — once guardrails were agreed. Detection, pause, controlled restart: responsible caution, not panic.
And the counterfactual is not a surveillance-free world. China already exports its “safe city” surveillance stack to roughly seventy-five countries. If democracies refuse to build proportionate, law-governed oversight of frontier AI, they will not prevent monitoring; they will simply let authoritarian states define what monitoring means. Some watching — targeted at the frontier, bounded by law — is the price of keeping the catastrophic tail risks, and the tyrants, in check.
If you drew Position B — read this in full
Start with a history lesson. In the 1990s, Washington decided strong encryption was too dangerous for ordinary hands. The Clipper chip would give the state a key to every secure conversation. Cryptographers revolted, business balked, and the code spread anyway: by 1996 Clipper was dead, and PGP — free, strong encryption — had travelled the world, at one point exported as a printed book protected as free speech. The Crypto Wars are Position B’s anchor: governments tried to gatekeep dual-use software once before, and they failed — while the attempt did real damage.
The second claim is about who writes the rules. Marc Andreessen puts it plainly: rules written with incumbents serve incumbents. Regulatory capture is not a conspiracy theory; it is the normal outcome when compliance costs only giants can pay become the ticket to operate. Licensing frontier models entrenches a handful of labs behind a government-built moat and kills the open ecosystem that keeps them honest. Guillaume Verdon calls the catastrophe scenarios “near-zero” risks; Sam Altman himself has dismissed some rivals’ warnings as “fear-based marketing.”
What about the Fable ban? Holman Jenkins wrote in the Wall Street Journal: “Anthropic’s Mythos didn’t create security vulnerabilities. It found them. Identifying these risks is a net gain to the world, not a disaster, not a reason to pull the emergency brake on AI.” For Position B, the two-week ban proved the opposite of what regulators intended: a government switched off access to a critical tool arbitrarily, overnight, worldwide — a textbook chilling effect on everyone who builds on AI.
The alternative is not “no rules.” It is ex-post accountability: liability when AI causes harm, targeted warrant-based audits where there is cause, transparency requirements — the way we already police cars, chemicals and code. Punish misuse; do not watch everyone to prevent it.
If you drew Position C — read this in full
Germany has run this experiment before. The Stasi files showed what a state can do with complete information about ordinary lives. And in 1983, when West Germany planned a routine census, the Federal Constitutional Court stopped it and wrote a sentence that still anchors European law: under modern data processing there is “no such thing as a trivial datum” — kein belangloses Datum. From that judgment comes informational self-determination (informationelle Selbstbestimmung): your right to decide who knows what about you.
Position C applies that standard to AI. To catch the rare bad actor inside a general-purpose system, you must observe how everyone uses it. Europe is testing that logic right now in the Chat Control fight over scanning private messages. The Commission’s own figures are the strongest argument against the method: detection tools err 13–20% of the time, roughly half the reports reaching Germany’s BKA are criminally irrelevant, and only 0.000002735% of scanned content was confirmed illegal. Scan everyone; catch almost no one. Patrick Breyer, the German MEP who led the opposition, calls the approach what the Constitutional Court would: disproportionate.
And surveillance does not stay where you built it. Function creep is the historical rule: powers introduced for terrorism drift to tax evasion, then to protest policing. Nor is this abstract for employees. In January 2024, France’s regulator CNIL fined Amazon France Logistique €32 million for tracking warehouse workers’ activity down to the “stow machine gun” speed indicator. The watching always reaches ordinary desks eventually.
None of this denies that frontier AI is dangerous. Position C disputes the method, not the danger: data minimisation, hard constitutional limits, transparency and liability can make AI safer — without building an apparatus that history says will not stay pointed at its original target.
Task 2 — Build and Teach Your Position to the Room
The room has only seen a 100-word summary of your position — your presentation is how they meet it properly.
Prepare alone (4 min). Build a 90-second teach of your position. You must include at least one named voice or data anchor from your deep reading that does not appear in your position’s summary. Use at least two phrases from the “contested authority” box. You are presenting the position’s strongest form — whether or not you believe it.
Deliver (≈12 min). Each student teaches their position to the room (90 seconds), then takes one question. Groups of three (one A, one B, one C) if the room is large.
Reflect (2 min). Complete aloud: “The strongest point I heard from a position that was not mine was…”
Comprehension
Answer from your own deep reading plus what you heard in the share-backs. Questions are framed at position level, not paragraph level.
According to Position A, what did the Fable episode actually demonstrate — and which international institution does A use as its model for policing AI? (Position A)
Which historical case is Position B’s anchor, and what was its outcome? (Position B)
What does Position C mean by “function creep,” and which two concrete anchors does it use to show surveillance reaching ordinary people? (Position C)
Which position(s) could accept KYC-for-compute, and on what condition? (Inference — Positions A and C)
Name one point on which all three positions agree. (Inference — all positions)
Discussion
Choose questions as a group. Use the hedged-challenge and steelmanning phrases — the trainer is listening for them.
Now that you have heard all three: which position do you actually find most defensible — and which was hardest for you to take seriously? What does the second answer tell you about your information environment?
The US barred foreign access to Fable on 12 June and lifted the ban on 1 July after guardrail concessions. Responsible caution, government overreach, or an arbitrary precedent that should worry everyone who builds on AI?
“Scan everyone to catch almost no one”: can the Chat Control numbers (13–20% error; 0.000002735% confirmed) ever pass a proportionality test? Where would the numbers have to sit before you said yes?
Where does this reach your desk? Your AI usage at work is increasingly logged; the CNIL fined Amazon €32m for watching workers too closely. Where is the line between a sensible audit trail and surveillance at your own company?
Germany has no frontier model and depends on US models it cannot fully govern. Is the German privacy instinct a strength that should set the global terms — or a luxury that leaves Europe a rule-taker?
In the 1990s, gatekeeping encryption failed. Is AI fundamentally different — centralised on observable compute — or will control fail the same way? What should policy do if it will?
Task 3 — Challenge and Finalise
Return to your Task 1 anchor and upgrade it under pressure (Agency Loop, Steps 4–5).
Prepare alone (2 min, no AI). Rewrite your Task 1 sentences as a final position of 3–4 sentences, informed by everything you have heard. Use at least one concessive construction.
Challenge (4 min). Paste your position into an AI tool with this prompt, then revise your sentences to address the counter-argument:
Here is my position on whether AI safety requires accepting surveillance:
[PASTE YOUR 3-4 SENTENCES]. What is the strongest argument against my position?Reflect (2 min). What did the AI flag — and what did you keep despite its objection?
(If time is short, Steps 2–3 move to homework — the homework completes the arc either way.)
Homework — Steelman the Position You Did NOT Defend
What to do: choose one of the two positions you were not assigned. Write an email to a friend who honestly holds that position — and make their case as strongly and fairly as you can. Use reporting verbs, at least one concessive construction, and at least one steelmanning phrase. Then complete Agency Loop Steps 4–5: paste your draft into an AI tool, ask “Where is my steelman still weak or unfair — where am I secretly strawmanning?”, and revise once before sending.
Deliverable: 200–300 word email. Time needed: about 20 minutes. When we meet again: send via WhatsApp to Daniel by Tuesday morning. The next session opens with the strongest 2–3 extracts, read anonymously — we discuss what made them land.
Answer keys
B1 vocabulary key
1-A, 2-B, 3-C, 4-D, 5-E, 6-F, 7-G, 8-H
B1 comprehension (model answers)
That AI can be used both for good and for harm. (¶1)
It stopped other countries from using a very powerful AI model for two weeks, because it was too risky. (¶3)
That people have a right to control their own data, and there is “no such thing as a small piece of data.” (¶5)
They are wrong 13–20% of the time. (¶5)
That AI can be dangerous. (¶6)
B2 vocabulary key
1-A, 2-B, 3-C, 4-D, 5-E, 6-F, 7-G, 8-H, 9-I, 10-J
B2 comprehension (model answers)
Dual-use means a technology can be used for both benefit and harm; it makes safety hard because catching the rare bad user of a general tool may mean watching how everyone uses it. (¶1)
Nuclear inspection: you do not search every home, you monitor a small number of observable facilities — and frontier AI similarly depends on concentrated, detectable compute. (¶2)
Regulatory capture is when rules written with big companies end up serving big companies; the second position fears it because licensing would lock out smaller players behind a government-built wall. (¶3)
That the tools err 13–20% of the time and confirm almost no illegal content — scan everyone, catch almost no one. (¶4)
That frontier AI is genuinely dangerous; they disagree only about the method. (¶5)
C1 vocabulary key
1-E · 2-C · 3-G · 4-D · 5-A · 6-F · 7-B · 8-J · 9-L · 10-I · 11-H · 12-K
C1 comprehension (model answers)
That detection-pause-controlled-restart worked as designed (responsible caution, not panic); the IAEA / nuclear non-proliferation model — monitor few observable facilities, not everyone.
The 1990s Crypto Wars: the Clipper chip was dead by 1996 while PGP spread worldwide — gatekeeping dual-use software failed.
Powers built for one purpose drift to others; anchors: Chat Control’s own error/hit-rate figures and the CNIL’s €32m fine of Amazon France Logistique for employee tracking.
A accepts it as its core mechanism; C could accept narrow, law-bounded compute-level oversight only with hard constitutional limits and data minimisation — it rejects observation of users. B rejects ex-ante gatekeeping generally.
All three accept that frontier AI misuse risk is real; the disagreement is about method (also acceptable: all three claim to defend democratic societies).
No model answers are provided for the discussion questions or the TBLT tasks — the point is your own argument.
I write one editorial article and one paired lesson every week, teaching the same topic across corporate groups in Germany before publishing it here. This one came out of a week on AI safety, surveillance and who gets to decide — read the companion article, Who Holds the Power to Watch?, for the fuller argument. If you teach, take this into your own classroom and tell me what happened; if you are learning, pick your level and argue it out.

