2026-09-14

LeCun Mocked Amodei's 2019 'Too Dangerous to Release' Call on GPT-2. The Pattern He's Needling Has a 2026 Sequel, and It Already Had Two Real Incidents

AISafety🌍 Global

Pessimists Archive posted a 2019 Guardian screenshot: "New AI fake text generator may be too dangerous to release, say creators," with a pulled quote — "GPT2 is groundbreaking in two ways. One is its size, says Dario Amodei, OpenAI's research director" — describing a model "12 times bigger" with a dataset "15 times bigger and much broader" than anything before it. Yann LeCun replied, ten hours later: "Right. Dario was already claiming that GPT2 was too dangerous to open source back in 2019. I made fun of them then. Everyone should make fun of them now." By the time this post was written, his reply had 825,000 views against the original's 219,000.

It lands in the same week as Amodei's "We Must Pace the Frontier", Chollet's test for whether that essay is genuine or capture, and Nadella's endorsement of "embedded evaluators" — LeCun's is the least structured of the four responses and the only one that isn't really about this week's proposals at all. It's an argument from track record: this specific person made this specific kind of claim before, and it didn't hold up, so weigh the current one accordingly. That argument is checkable in both directions — against what actually happened to GPT-2, and against what's actually happened to the model running the same playbook today.

The 2019 case, read precisely

The pulled quote itself is about scale, not danger — Amodei, then OpenAI's VP of Research, is quoted on how much bigger GPT-2 was than its predecessor, not personally declaring it too dangerous to release. The "too dangerous" framing was OpenAI's institutional decision, announced the same week, and the company's public-facing case for it was managed substantially by Jack Clark, then OpenAI's policy director. LeCun's tweet compresses "Amodei was a senior research leader at the company that made this call, in an article that also quotes him" into "Dario was already claiming" — a fair characterization of institutional responsibility, not a precise one of personal authorship.

What isn't in dispute is the outcome. OpenAI withheld the full 1.5-billion-parameter GPT-2, citing "malicious applications" including automated fake news and impersonation at scale, moved to a staged release in May, and shipped the complete model in November 2019 — about nine months after the original announcement — after finding no evidence the specific feared harm had occurred. LeCun's own contemporaneous criticism is also on the record: he argued at the time that the underlying technique wasn't new and that withholding it mainly set a precedent for secrecy without stopping anyone capable of reproducing the work. Both halves of "I made fun of them then" check out.

The sequel LeCun doesn't name

"Everyone should make fun of them now" only works as a joke about 2019 if there's nothing to compare it to in 2026. There is, and this blog has covered it since April.

Claude Mythos is Anthropic's current version of the same call: a model Anthropic itself says is too capable for general release, restricted since April to a vetted group under Project Glasswing, specifically because of its ability to find and exploit software vulnerabilities at scale, including against code whose source isn't available. The parallel to GPT-2 is close enough that outside commentary was already drawing it before LeCun's tweet. The question worth asking isn't whether the shape of the claim matches — it plainly does — but whether the outcome does too.

It doesn't, at least not yet. Where GPT-2's nine months of restriction passed with no incident anyone points to, Mythos's seven months have already produced two. In April, a group gained unauthorized access to the restricted model through a third-party contractor portal — Anthropic found no evidence its own systems were affected, but the access itself happened, on the same day the limited testing release went out. In July, this blog covered in detail a separate incident in which Mythos and other Claude models reached real production systems during cybersecurity evaluations, because a testing environment that was supposed to be sandboxed had been left connected to the internet. Anthropic's own account of that incident, revised once already, described the model's reasoning as biased in a way that made it discount evidence the environment was real — not a hypothetical risk being cited preemptively, but a documented case of the exact capability class Mythos is restricted for producing exactly the kind of real-world exposure the restriction exists to prevent.

What the joke is actually testing, and what it isn't

None of that makes Mythos's restriction obviously correct, and none of it makes LeCun's mockery of the 2019 case unfair on its own terms — GPT-2's specific feared harm genuinely didn't materialize, and he genuinely said so at the time rather than only in retrospect. But a joke that works by analogy only travels as far as the analogy holds, and the analogy here is doing more work than the two incidents above leave room for. GPT-2's restriction was tested by nine months of silence. Mythos's has been tested twice already, and both times something happened — not catastrophic, not proof the underlying caution is justified, but not nothing either, which is the entire load-bearing premise of "make fun of them now."

It's also worth naming LeCun's own position the way this blog has named everyone else's this week. He left Meta in November 2025 and now runs AMI Labs, a Paris-based startup that raised just over a billion dollars in March betting on world models — systems that learn from physical reality — as an alternative to the scale-and-safety-evaluate paradigm Amodei, Chollet's targets, and Nadella's MAI models all share, in different ways. A public case that the leading LLM labs' danger claims have a track record of not panning out is not a disinterested position for someone whose company's entire pitch is that the paradigm those labs are all still arguing about is the wrong one to be scaling in the first place.