Abstract

Governing AI compute can play an important role in the governance of AI. Unlike data, algorithms and trained models — which are easily shareable, non-rivalrous intangible goods — computing hardware is tangible and produced through an extremely concentrated supply chain, making it a uniquely tractable lever for increasing regulatory visibility, steering resource allocation, and enforcing restrictions.

Central thesis

  • Compute has been the key enabler of the current AI wave, with general performance improving predictably as more compute is applied.
  • Policymakers are already making significant compute decisions: investing in domestic production, imposing export controls, and subsidising access for actors outside big technology companies. These steps do not exhaust the possibilities.
  • Compute governance is not the whole story — approaches beyond it are needed for small-scale uses that could pose major risks, such as specialised AI applied to military use.
  • “Policymaker” is used expansively: national security officials, decision-makers at AI companies, lawmakers, standard-setting bodies, and international coalitions.

Background: the AI triad and lifecycle

  • The three technical inputs to AI are data, algorithms and compute, with human capital required for all three. Data is the raw material; algorithms dictate the operations; compute is the substrate that executes them.
  • The deep learning era (c. 2010–2012) is attributed to the initial use of GPUs for training.
  • The AI lifecycle splits into development (design → training → enhancement) and deployment. Training is the most compute-intensive stage; enhancement (fine-tuning, RLHF) typically requires much less.
  • Because of the scale of current deployment, the majority of all AI compute is now used for inference, even though a single training run requires far more compute than a single inference.
  • Not all AI applications require vast compute — specialised systems have shown impressive abilities using far less than frontier systems.

Why compute is attractive for policymaking

Four properties:

  • Detectability — large-scale development and deployment is highly resource-intensive, typically requiring thousands of specialised chips in a high-performance cluster in a large data centre consuming large amounts of power.
  • Excludability — the physical nature of hardware makes it possible to exclude users from AI chips, in contrast to data, algorithms or trained models.
  • Quantifiability — computational power can be measured, reported and verified.
  • Supply chain concentration — AI chips are produced via a highly inelastic and complex supply chain whose key steps (design, EUV lithography, fabrication) are dominated by a small number of actors.

The paper also examines the tradeoff between regulating development versus regulating deployment.

Three governance capacities compute can enhance

A. Visibility — tracking and assessing development and use

  1. Using public information about compute quantities to estimate actors’ AI capabilities, now and in future
  2. Required reporting of training compute usage from cloud providers and AI developers
  3. An international AI chip registry
  4. Privacy-preserving workload monitoring

B. Allocation — influencing which systems are built, when, and by whom

  1. Differentially advancing beneficial AI development
  2. Redistributing AI development and deployment across and within countries
  3. Changing the overall pace of AI progress
  4. Collaborating on a joint AI megaproject

C. Enforcement — ensuring compliance with regulations and standards

  1. Enforcing “compute caps” via physical limits on chip-to-chip networking
  2. Hardware-based remote enforcement
  3. Preventing risky training runs via multiparty control
  4. Digital norm enforcement

The authors note they vary significantly among themselves on which, if any, of these mechanisms would be desirable — and stress that how mechanisms are designed, implemented and updated matters as much as whether they are adopted, since subtle details could determine whether a policy is beneficial or detrimental on balance.

Risks of compute governance

Unintended consequences

  • Threats to personal privacy
  • Opportunities for leakage of sensitive strategic and commercial information
  • Risks from centralisation and concentration of power

Feasibility and efficacy issues

  • Algorithmic and hardware progress eroding the meaning of fixed thresholds
  • Low-compute narrow models with dangerous capabilities
  • Incentives for diversion, evasion, circumvention and decoupling

Proposed guardrails

  1. Exclude small-scale AI compute and non-AI compute from governance
  2. Research and implement privacy-preserving practices and technologies
  3. Only use compute-based controls for risks where ex ante controls are justified
  4. Periodically revisit which computing technologies are controlled
  5. Implement all controls with substantive and procedural safeguards

Appendices

  • The compute-uranium analogy — comparing compute governance to nuclear materials control
  • Research directions for open questions in the field

Note: the paper carries an unusual authorship disclaimer — being an author does not imply agreement with every claim, nor represent an endorsement from any author’s organisation.