Abstract
Governing AI compute can play an important role in the governance of AI. Unlike data, algorithms and trained models — which are easily shareable, non-rivalrous intangible goods — computing hardware is tangible and produced through an extremely concentrated supply chain, making it a uniquely tractable lever for increasing regulatory visibility, steering resource allocation, and enforcing restrictions.
Central thesis
- Compute has been the key enabler of the current AI wave, with general performance improving predictably as more compute is applied.
- Policymakers are already making significant compute decisions: investing in domestic production, imposing export controls, and subsidising access for actors outside big technology companies. These steps do not exhaust the possibilities.
- Compute governance is not the whole story — approaches beyond it are needed for small-scale uses that could pose major risks, such as specialised AI applied to military use.
- “Policymaker” is used expansively: national security officials, decision-makers at AI companies, lawmakers, standard-setting bodies, and international coalitions.
Background: the AI triad and lifecycle
- The three technical inputs to AI are data, algorithms and compute, with human capital required for all three. Data is the raw material; algorithms dictate the operations; compute is the substrate that executes them.
- The deep learning era (c. 2010–2012) is attributed to the initial use of GPUs for training.
- The AI lifecycle splits into development (design → training → enhancement) and deployment. Training is the most compute-intensive stage; enhancement (fine-tuning, RLHF) typically requires much less.
- Because of the scale of current deployment, the majority of all AI compute is now used for inference, even though a single training run requires far more compute than a single inference.
- Not all AI applications require vast compute — specialised systems have shown impressive abilities using far less than frontier systems.
Why compute is attractive for policymaking
Four properties:
- Detectability — large-scale development and deployment is highly resource-intensive, typically requiring thousands of specialised chips in a high-performance cluster in a large data centre consuming large amounts of power.
- Excludability — the physical nature of hardware makes it possible to exclude users from AI chips, in contrast to data, algorithms or trained models.
- Quantifiability — computational power can be measured, reported and verified.
- Supply chain concentration — AI chips are produced via a highly inelastic and complex supply chain whose key steps (design, EUV lithography, fabrication) are dominated by a small number of actors.
The paper also examines the tradeoff between regulating development versus regulating deployment.
Three governance capacities compute can enhance
A. Visibility — tracking and assessing development and use
- Using public information about compute quantities to estimate actors’ AI capabilities, now and in future
- Required reporting of training compute usage from cloud providers and AI developers
- An international AI chip registry
- Privacy-preserving workload monitoring
B. Allocation — influencing which systems are built, when, and by whom
- Differentially advancing beneficial AI development
- Redistributing AI development and deployment across and within countries
- Changing the overall pace of AI progress
- Collaborating on a joint AI megaproject
C. Enforcement — ensuring compliance with regulations and standards
- Enforcing “compute caps” via physical limits on chip-to-chip networking
- Hardware-based remote enforcement
- Preventing risky training runs via multiparty control
- Digital norm enforcement
The authors note they vary significantly among themselves on which, if any, of these mechanisms would be desirable — and stress that how mechanisms are designed, implemented and updated matters as much as whether they are adopted, since subtle details could determine whether a policy is beneficial or detrimental on balance.
Risks of compute governance
Unintended consequences
- Threats to personal privacy
- Opportunities for leakage of sensitive strategic and commercial information
- Risks from centralisation and concentration of power
Feasibility and efficacy issues
- Algorithmic and hardware progress eroding the meaning of fixed thresholds
- Low-compute narrow models with dangerous capabilities
- Incentives for diversion, evasion, circumvention and decoupling
Proposed guardrails
- Exclude small-scale AI compute and non-AI compute from governance
- Research and implement privacy-preserving practices and technologies
- Only use compute-based controls for risks where ex ante controls are justified
- Periodically revisit which computing technologies are controlled
- Implement all controls with substantive and procedural safeguards
Appendices
- The compute-uranium analogy — comparing compute governance to nuclear materials control
- Research directions for open questions in the field
Note: the paper carries an unusual authorship disclaimer — being an author does not imply agreement with every claim, nor represent an endorsement from any author’s organisation.