The governance architecture, three-layer framework, and institutional analysis reflect my own research agenda. I directed the research and endorse all arguments.
The detailed version was originally published at: https://taha-research-platform.vercel.app/governance/beyond-threshold-compute-governance-2026
The Wrong Debate
The contribute discussion points approach information in the debate over compute governance in a specific, binary manner. Some argue that compute thresholds are the best tool for the possible risks posed by frontier AI. Drafters cite the quantifiable measure of FLOP counts and control over the manufacture of computing chips. Others counter that the threshold of DeepSeek was established at far too high of a compute measure, and hardware controls will be rendered obsolete before they are even enacted.
Both arguments are faulty, and their simultaneous opposition frames the discussion in an unhelpful manner.
The most accurate framing would be that compute governance is not obsolete, nor is it sufficient to address the concerns of frontier AI. It is one component of a multi-level governance system. The issue is not inadequate tool selection; the issue is insufficient progressive development.
This essay seeks to determine where compute governance is, in fact, an adequate measure, where it structurally fails to provide adequate measures, and what a more adequate containment and control system through integration of compute, capability, and threshold controls would look like. The elements of such a system already exist. The IAEA safeguards, the EU AI Act's AI risk classification, and the pro-innovation Principles of the DSIT collectively incorporate elements of an adequate answer. What has not been done is to integrate them.
1. What Compute Governance Gets Right
The foundation of compute governance is solid. There are three reasons why hardware constraints on regulation could be an attractive policy option.
Measurability
The definition of FLOPS means they can be measured. Either a training run of 10^26 FLOPs was done, or it was not. This is not the case for capacity-based thresholds or intent-based regulation, which rely on contested benchmarks and inferences on the intent of regulators, respectively. The choice of the European Union AI Act to set a framework for GPAI models that impose systemic risk at 10^25 FLOPs, while this framework has its problems, includes an interesting yet sensible preference of choosing a hard limit over a soft one.
Enforcement along supply chains.
The global market for AI training accelerators is concentrated. TSMC manufactures almost all top-end AI chips. ASML has a near monopoly of extreme ultraviolet lithography machines. Applied Materials and Lam Research have a near monopoly of deposition and etch machines, respectively. This creates natural enforcement points for regulation of AI with very little need to even monitor AI development activities.
Historical precedent
The design of the Bureau of Industry and Security's export control system for dual-use technologies over the years has ready infrastructure for compute governance. The October 2023 and subsequent 2024 export control rules were able to apply this flexibility to AI chips with low burden of implementing, because the frameworks and rules had already been set.
The Hiroshima Process G7 AI Principles, adopted in October 2023, make a case for compute governance by including some advanced AI systems, which are defined in capability-adjacent terms that interface with compute. While the international coordination architecture is weak, these do exist.
These are real strengths. The critique of compute governance should not overlook them.
2. Where Compute Governance Structurally Fails
Compute governance fails at three structural points that cannot be addressed by moving thresholds.
The “efficiency substitution” problem.
First, on DeepSeek-R1. It shows that with some clever algorithm design, it’s possible to reach capabilities at a fraction of the cost of existing systems. While it might seem like a one-time thing, in the grand scheme of computing history, this is simply the proverbial next step in the progress of efficiency. The history of computing is the history of increasing efficiency and thus more computing. It’s likely we will start seeing examples of systems getting cheaper. Compute thresholds at the current frontier get redefined to be less restrictive as the efficiency frontier progresses. More importantly, a system of rules with fixed thresholds against a moving target will always become outdated.
The EU AI Act's implementing regulations, which the EU AI Office is currently drafting, have this issue. The 10^25 FLOP threshold used to define systemic risk in the GPAI is already being questioned by models that may reach systemic risk through inference-time computations of architectural efficiency as opposed to brute-force training. The implementing regulations have no provisions to address this, and will need to wait for revisions that take years to address.
The post-training capability amplification gap
Compute governance addresses the bounding and resource allocation for training runs. It has no solutions for the capability amplification that occurs through focused fine-tuning, reinforcement learning with human feedback on a base model, or retrieval-augmented generation models, which can drastically improve capability with little incremental training compute. A model trained at 10^24 FLOP, well below most suggested thresholds, can be fine-tuned on targeted datasets to showcase advanced and potentially harmful behavior in certain domains with a fine-tuning cost that is many orders of magnitude smaller than the cost to train the model.
The UK DSIT's 2023 AI Regulation Consultation recognized this gap, but proposed no solution. The pro-innovation framework's prioritization of sector-specific regulation in the downstream results of development means that fine-tuning-based capability amplification is situated in a regulatory gap between compute-centric controls in the upstream and regulation of the downstream application.
The problem of weights proliferation.
After weights are trained and either released or leaked, the compute required to create them is irrelevant for their distribution. We see with the Meta LLaMA series that once weights are public, there is no way to signficantly get them back. With open-weight models, train compute becomes the sole factor of deployment risk. As a foundational principle, compute governance is relevant prior to this. After training is complete, weight governance is of no concern.
The IAEA safeguards model is applicable in this scenario. In this case, after the production of enriched uranium and plutonium, control and restraint can in theory be physical. Model weights are, in fact, information. There's no cost to copy or transmit them as there is information. The control of information and the control of physical material is not the same. The nonproliferation analogy is helpful in addressing the upstream chokepoints, but in this case, the breakdown of the analogy is when compute governance ends and the deployment risk begins.
3. Three Layers of Architecture
Fulfilling the requirements of governance frameworks operating within the realm of identified risks requires the sequenced operation of three layers. Layer 1 deals with compute governance and needs Layer 2 (evaluation of capability) and Layer 3 (verification of deployment) to operate as a system.
Layer 1 - Compute Governance (Existing, Reform Needed)
Retain computation thresholds as concerns triggering enhanced regulatory oversight, and reform them in two ways. First, rather than setting absolute values, index thresholds to the capability frontier. A threshold of “two orders of magnitude of the most capable publicly known model” will automatically follow the capability frontier through the absence of a need for legislative amendment. Second, extend the regulatory perimeter to cover fine-tuning runs that reach capability thresholds, as opposed to only the base training runs.
Layer 2 — Capability evaluation (required, largely absent)
The IAEA safeguards model serves as the foundation. In this model, IAEA inspectors evaluate nuclear facilities declared by member states against established standards. Inspections can be conducted unannounced, and inspectors can report their findings to member states without prior approval from the inspected party. In the AI equivalent, there would need to be mandated capability evaluations performed by institutions with institutional independence from developers, evaluations must be based on publicly available and challengeable protocols, and the results of evaluations must be made public to the relevant national oversight body.
The UK AISI’s evaluation work with frontier labs is a prototype, but has two major gaps compared to the IAEA model: compulsory participation and independent publication. While voluntary cooperation from labs is valuable, it is not sufficient, it creates persistent incentives to make systems appear less capable during evaluation than they perform in deployment.
An evaluations framework would be mandatory, and would be triggered by any training run which meets the compute requirements of Layer 1. The evaluation would be conducted for a pre-defined dangerous capability domains within an evaluation environment. Domains would include: autonomous cyber-offense, biological synthesis aid, autonomous replication, deception, and other similar constructs beyond these examples. The results of the evaluation would be released to the national oversight body. Deployment would be permitted only if evaluation results fell below pre-defined thresholds for each of the domains.
Layer 3 - Deployment verification (required, does not yet exist)
Layers 1 and 2 - training.
Layer 3 - refers to the time after deployment (e.g. after training) where risks of weights proliferation and fine tuning based capability amplification are impossible for compute governance to control.
The solution is based on interpretability auditing with defined reporting requirements. Mature mechanisms of interpretability are driving research in Sparse autoencoders at Anthropic and circuit analysis at DeepMind which might, in the future, provide runtime verification that a deployed model does not exhibit capability profiles that deviate from its pre-deployment assessment.
Although not yet possible at frontier scale, the research is likely to converge in 2-4 years. The governance framework should be designed for the tools that will exist within its operational lifetime, even if only the tools that exist today are known.
4. The Institutional Design Problem
The three-layer architecture needs institutions that do not currently exist.
The primary design problem is independence. Each layer needs a supervisory body that has the ability to enforce its mandate and publish its findings, without needing approval from the regulated party. Without this, the FDA is a voluntary industry certification body, the PCAOB is a self-regulatory accounting body, and the IAEA is a gentlemen’s agreement among nuclear nations.
Existing AI oversight institutions do not have this property. The US AISI is established through Voluntary Cooperation Agreements. The UK AISI has published capability assessments of Advanced or Frontier AI Systems, but lacks the ability to mandate either participation or disclosure. The AI Office in the EU has regulatory power under the AI Act, but has not yet developed the necessary infrastructure to exercise this effectively.
The only way to achieve true independence is through the two mechanisms: first, requirements for civil liability for material non-disclosure, as in the Sarbanes-Oxley Act; and second, requirements for pre-market approval, as in the FDA.
5. Why This Architecture Is Politically Achievable
The strongest critique of the three-layer architecture is political rather than technical. The response is three-fold.
First, the political economy of AI governance is developing faster than most analysts anticipated. Mandatory capability evaluation framed as national security screening is politically acceptable, whereas AI safety regulation is not.
Second, the model is accepted in adjacent domains. CFIUS conducts mandatory national security reviews of foreign investments in US technology companies. A capability evaluation framework based on the model of CFIUS screening for dangerous capabilities would be dealing with a different political scenario than broad AI safety regulation.
Third, the alternative is highly vulnerable to concentrated efforts to block the implementation of certain kinds of regulation. History shows that a crisis is a much better motivator of the construction of governance frameworks than the prevention of such a crisis.
6. Implementation Sequencing
2025–2026 (Layer 1 reform): Adjust the compute threshold frameworks to utilize adaptive as opposed to fixed thresholds. Incorporate fine-tuning rules in the implementing regulations of the EU AI Act.
2026–2028 (Layer 2 deployment): Implement frameworks for mandatory capability evaluations for models meeting Layer 1 thresholds. Create the necessary evaluation capacity at US AISI and UK AISI via compulsory participation.
2028–2030 (Layer 3 development): Incorporate deployment verification into the framework once interpretability tools become available for frontier-scale deployment.
Conclusion
Compute governance is a must. Yet, it is insufficient. The widest tractable gap between training compute and what Compute governance needs to cover includes risks amplification, weights proliferation, and capability drift post deployment, which all present the most significant risks in the near term.
This three-layer architecture provides a mixture of components developed to deal with the frontier of AI that the IAEA, the FDA and CFIUS have developed independently.
The design window is open. The outcome will show whether a design adequate to the risks will be built, or if threshold-framing obsolete regulations will be built, while the implementing regulations are still in process.