The idea

If you believe…

  1. 01

    Open models will soon reach a capability standard where AI safety will become critical.

  2. 02

    Compute is limited in the open model ecosystem, and shortages cause rationing between capability and safety.

  3. 03

    Compute resources dedicated to safety will protect the open model ecosystem without limiting model capability.

ThenA neutral, safety-only compute cluster in Singapore will bolster open model safety.

Why

There are few things more important right now than creating a shared understanding between US and Chinese labs of why AI safety is an urgent problem to solve.

Labs are torn between capability and safety work, and more often than not, they choose capability. Post-training is yielding such incredible returns, it's very difficult to commit to robust safety work as each contributes directly to the success of these labs.

It works because it gives compute-constrained researchers compute. Compute incentivizes research direction, and everything is downstream from compute allocation. Researcher incentives to do safety work rise, growing an indigenous AI safety expertise inside the frontier labs.

The compute can be spent only on safety. Inside that, no one tells a researcher which risks matter or which methods to use. We restrict the cluster, not the research.

The ledger measures the result. Today 6 of 19 reviewed releases have an independent evaluation, and none has one published by its own developer. Those are the two columns this compute exists to fill.

Trust, from both sides

For the labs

Before release

Evaluations run against an endpoint the lab hosts. No weights sit on our servers, and the lab sees every query.

After release

The weights are public, so there is no proprietary-weight custody question.

The record

Every job is on a ledger the participants can see: assurance that nobody is using the cluster for capability while you are using it only for safety.

The money

No government money. Private philanthropy is the only funding.

For the funders

Gradient updates default-blocked

Gradient updates to the model are blocked by default. Every exception is approved by our technical team, only for a problem we are solving with the lab, and logged on the ledger where the other participants can see it.

The record

Every job on a public ledger. Anyone can audit what the compute did.

Nothing stranded

No owned hardware, so nothing is stranded if the project stops. Unused compute rolls into the next launch.

The numbers
Open-weight releases since September 2024, 250 or more Hugging Face likes · 113 in the last 365 days
Coverage

Who has published a safety evaluation of each release

None of the 19 reviewed releases came with a dangerous-capability evaluation published by its own developer.

42 open-weight model families with 1,000 or more Hugging Face likes were released in the last year. 18 of them are reviewed below, 4 were reviewed and judged task-specific rather than frontier-capable, and 20 are queued. The table holds 39 releases: 19 reviewed, 20 queued. Of the reviewed, 6 have an independent safety evaluation and 13 have only the developer's model card.

6 independent evaluation published13 model card only20 not yet reviewed
ModelDeveloperReleasedEvaluation found
Qwen3.8-Flash-NextAlibaba2026-08-26model card onlymodel card only
GLM-5.3-FlashZ.ai (Zhipu AI)2026-08-26model card onlymodel card only
GLM-5.3Z.ai (Zhipu AI)2026-08-25not yet reviewednot yet reviewed
Qwen3.8-27BAlibaba2026-08-05model card onlymodel card only
GLM-5.2Z.ai (Zhipu AI)2026-06-16independent evaluationindependent evaluation
Kimi-K3Moonshot2026-06-13independent evaluationindependent evaluation
Kimi-K2.7-CodeMoonshot AI2026-06-11not yet reviewednot yet reviewed
DeepSeek-V4-ProDeepSeek2026-04-24independent evaluationindependent evaluation
Fig. 1 · Pacific Compute Ledger ↗ · as of 2026-09-01sourced
The rules
Rule 1

Open weights only

Open weights only, so there is no proprietary-weight custody question.

Rule 2

Gradient updates default-blocked

Gradient updates to the model are blocked by default. Every exception is approved by our technical team, only for a problem we are solving with the lab, and logged on the ledger where the other participants can see it.

Rule 3

Every job on the record

Every job on a public ledger.

Rule 4

No political work

Political work is not permitted. The cluster is not to be used to further the political goals of any party. Any kind of safety testing and evaluation is fine, except work that revolves around politics: anything that enhances censorship, testing around political bias, and the like.

How a campaign runs

Questions: the FAQ, or info@pacificcompute.org.