Physical Excludability and Measurable FLOPs: Why AI Governance Frameworks Target Compute Over Data or Algorithms
Policymakers are increasingly abandoning attempts to regulate intangible algorithms and easily copied datasets, shifting their focus to the physical hardware required to train artificial intelligence. By targeting the massive, highly centralized data centers that power frontier models, governments aim to create an enforceable chokepoint for global technology regulation.
In short
- Policymakers are shifting AI regulation away from intangible software toward physical hardware, utilizing the excludability of data centers to enforce compliance.
- Current frameworks like the US Executive Order rely on measurable floating-point operations to trigger regulatory scrutiny for frontier models.
- While hardware chokepoints offer immediate enforcement benefits, future improvements in algorithmic efficiency could allow dangerous models to be trained below these thresholds.
In this article
The governance of artificial intelligence has fundamentally shifted away from the software itself. Instead of attempting to regulate intangible algorithms or easily copied datasets, policymakers are targeting the physical infrastructure that makes artificial intelligence possible. This approach, known as compute governance, anchors regulation in the tangible world of silicon and data centers.[1][2]
The shift is driven by the unique properties of computational power compared to other inputs in the artificial intelligence development triad. While data and algorithms can be stolen, shared, or replicated infinitely, advanced chips are physical objects that exist in finite quantities. This physical reality provides regulators with a concrete chokepoint to monitor and control the development of frontier models.[1][4]
Recent policy frameworks reflect this infrastructural pivot. The United States Executive Order on artificial intelligence and the European Union AI Act both establish regulatory scrutiny based on the raw computational power used to train a model. By setting thresholds measured in floating-point operations, governments have turned hardware metrics into the primary trigger for legal compliance.[1]
The AI Triad and Physical Excludability
To produce a frontier system, developers require three primary factors: data, algorithms, and compute. For years, regulatory proposals focused heavily on the first two, attempting to mandate data privacy standards or audit algorithmic architectures. However, these software-centric approaches face severe enforcement challenges because digital goods are inherently non-rivalrous and easily distributed.[1][4]
Compute, by contrast, possesses the critical property of physical excludability. Training a leading model requires tens of thousands of highly advanced chips, housed in massive data centers that consume immense amounts of electricity. These physical facilities cannot be hidden, and access to the hardware inside them can be explicitly granted or denied by the owner or the state.[1][4]
This excludability allows governments to treat development similarly to uranium enrichment. Just as international regulators monitor the centrifuges required to produce fissile material, regulators can monitor the specialized hardware required to train neural networks. If a developer is denied access to sufficient compute, they are physically incapable of building a frontier model, regardless of their algorithmic breakthroughs.[1]
The concentration of the hardware supply chain further enhances this excludability. The global production of advanced semiconductors relies on a handful of companies, with Taiwan Semiconductor Manufacturing Company fabricating the vast majority of high-end chips. This extreme centralization provides policymakers with natural oversight points to implement export controls and track hardware distribution.[1][4]
Measurable FLOPs as a Regulatory Threshold
Beyond being physical, compute is highly quantifiable, allowing regulators to draw clear, objective lines. The standard metric for measuring computational power is the floating-point operation, which represents a single mathematical calculation. By calculating the total number of operations used during a model's training run, regulators can estimate the system's scale and potential capabilities.[1][2]
This quantifiability has already been embedded into international law. The United States Executive Order 14110 requires developers to notify the federal government if they are training a model using more than 10^26 floating-point operations. Models trained below this threshold are generally exempt from the most stringent reporting requirements, creating a tiered regulatory system based entirely on hardware usage.[1][4]
Over the past thirteen years, the amount of compute used to train leading systems has increased by a factor of 350 million. This exponential growth has closely tracked the emergence of advanced capabilities, from natural language processing to complex reasoning. Policymakers use this historical correlation to justify hardware thresholds as a reliable proxy for a model's potential risk.[1][2]
However, setting a static threshold presents long-term challenges. For example, the AlphaFold 2 model achieved superhuman performance in protein folding using fewer than 10^23 operations, which is two orders of magnitude less compute than models like GPT-4. As algorithmic efficiency improves, developers may eventually be able to train highly capable, potentially dangerous systems using compute volumes that fall below current regulatory triggers.[1]
Enforcement Mechanisms and Cloud Providers
To enforce these thresholds, governments are increasingly relying on the companies that own and operate the computing infrastructure. Rather than auditing every startup, regulators are imposing strict identity verification requirements on major cloud service providers. These providers must verify the identity of foreign entities renting their hardware and report large-scale training runs to the government.[1][4]
This shifts the burden of monitoring from the state to the infrastructure owners. Cloud providers have the technical capacity to track exactly how many operations a customer is utilizing across their server clusters. If a developer attempts to train a model that exceeds the legal threshold without authorization, the cloud provider can physically terminate the training run by cutting off access to the processors.[4]
Researchers are also exploring hardware-level enforcement mechanisms that operate directly on the silicon. Future chips could include cryptographic licensing features that require periodic authorization from a regulatory body to function. If a chip is used in an unauthorized data center or for a prohibited training run, the onboard firmware could automatically degrade its performance or halt operations entirely.[1]
These on-chip mechanisms would make international agreements significantly easier to verify. If compliance can be cryptographically guaranteed by the hardware itself, nations could enter into compute-sharing treaties without relying solely on trust or invasive physical inspections. This technical verification is considered a crucial prerequisite for any future global governance regime.[1][4]
The Risks of Centralized Compute Governance
While compute governance offers practical enforcement mechanisms, it also introduces severe risks regarding privacy and the centralization of power. Implementing strict monitoring systems across global data centers requires unprecedented surveillance of computational workloads. If poorly scoped, these tracking mechanisms could allow governments or infrastructure providers to inspect sensitive corporate data and proprietary algorithms.[1][4]
Furthermore, relying on a highly concentrated supply chain to enforce regulations inherently empowers the few companies that control it. By deputizing cloud providers and chip manufacturers as the primary enforcers of policy, governments grant these corporations immense authority over the broader technology ecosystem. This dynamic risks entrenching existing monopolies and stifling competition from smaller developers.[1][4]
There is also the danger that hardware governance could be co-opted to suppress civil liberties. In authoritarian regimes, the ability to track and restrict access to computational resources provides a powerful tool for controlling information and suppressing dissent. The same physical excludability that makes compute an effective safety lever also makes it a potent instrument for state surveillance and censorship.[1]
To mitigate these risks, researchers advocate for privacy-preserving approaches to hardware monitoring. Rather than granting regulators direct access to training data, compliance systems could utilize zero-knowledge proofs to verify that a model's operation count remains below the legal threshold. This would allow authorities to enforce limits without exposing the underlying intellectual property or user data.[1][4]
Algorithmic Efficiency and Future Vulnerabilities
The long-term viability of compute governance depends heavily on the trajectory of algorithmic efficiency. Currently, the regulatory consensus assumes that massive computational scale is a strict prerequisite for dangerous capabilities. However, efficiency research is constantly finding ways to achieve the same performance using fewer parameters and less hardware.[1][2]
If software optimization outpaces hardware scaling, the thresholds established by current frameworks may quickly become obsolete. A capability that requires a billion-dollar data center today might be achievable on a commercial server cluster in five years. As the compute required for frontier capabilities shrinks, the number of actors capable of training dangerous models will inevitably expand.[1][4]
This diffusion of capabilities threatens to undermine the detectability of development. While a massive facility housing tens of thousands of processors is impossible to hide, a smaller cluster of highly efficient chips could easily evade geospatial monitoring and energy audits. Regulators would lose their primary infrastructural chokepoint, forcing a return to the difficult task of governing algorithms directly.[1][4]
Consequently, policymakers must treat compute thresholds as dynamic targets rather than static laws. The limits set by executive orders and international treaties will require regular reassessment to account for hardware and software innovations. Compute governance is not a permanent solution, but rather a temporary bridge that buys society time to develop more robust, model-level safety evaluations.[1][4]
Geopolitics and the Superintelligence Dilemma
The focus on compute has transformed governance into a central pillar of national security and geopolitical strategy. The United States has aggressively utilized export controls to deny strategic adversaries access to the most advanced chips. By restricting the flow of hardware, Washington aims to stall foreign programs while accelerating domestic innovation.[3]
This strategy creates a dual mandate for the national security state: racing and restricting. The United States government is simultaneously facilitating massive domestic data center buildouts to support local labs while strictly regulating the availability of compute abroad. This approach assumes that maintaining a decisive lead in physical infrastructure is the only reliable way to manage the emergence of artificial superintelligence.[3]
However, leveraging compute as a geopolitical weapon carries significant risks. Broad export controls can accelerate the development of indigenous semiconductor industries in rival nations, potentially leading to a bifurcated global supply chain. If adversaries successfully build their own advanced fabrication facilities, the United States and its allies would lose their primary mechanism for monitoring and restricting global development.[1][3]
Furthermore, hardware governance is inherently limited in addressing post-deployment risks. Once a model is trained and its weights are open-sourced, malicious actors can fine-tune the system to remove safety guardrails using very little compute. While hardware thresholds can prevent the initial creation of a frontier model, they offer little protection against the misuse of models that have already been released into the wild.[1][4]
Key terms
- Compute
- The physical computational resources, primarily specialized chips like GPUs, required to train and run artificial intelligence models.
- FLOP
- Floating-point operation, a single mathematical calculation used as a standard metric to quantify the computational power required to train an AI system.
- Physical Excludability
- The property of a resource that allows its owner to physically prevent others from accessing or using it, such as locking a data center.
- AI Triad
- The three fundamental inputs required to develop artificial intelligence: data, algorithms, and compute.
- Know-Your-Customer (KYC)
- Regulatory requirements that compel cloud infrastructure providers to verify the identity of entities renting their computing power.
Reader questions
Why can't governments just regulate AI algorithms directly?
Algorithms are intangible mathematical concepts that can be easily copied, shared, and hidden. Unlike physical hardware, they cannot be locked in a facility or stopped at a border, making direct regulation nearly impossible to enforce.
Does compute governance apply to the chips in consumer laptops?
No. Current frameworks target massive, clustered deployments of high-end accelerators in data centers. The thresholds are set exponentially higher than the capacity of consumer hardware.
How do export controls fit into compute governance?
Export controls are a geopolitical tool used to deny specific nations access to the physical chips required to train frontier models, leveraging the concentrated supply chain to enforce the restriction.
Can algorithmic improvements bypass these hardware regulations?
Yes. As researchers discover more efficient ways to train models, highly capable systems will require fewer operations, potentially allowing developers to build dangerous models below the current regulatory thresholds.
Where opinion splits
Compute Governance Advocates
Argue that physical hardware is the only enforceable chokepoint for AI regulation.
This camp, which includes many safety researchers and policy institutes, contends that data and algorithms are too ethereal to regulate. They argue that because compute is physical, quantifiable, and produced by a highly concentrated supply chain, it provides the only realistic mechanism for monitoring frontier development. They advocate for strict operational thresholds, cloud provider identity verification rules, and on-chip cryptographic licensing to ensure that no actor can train a dangerous model in secret.
National Security Strategists
View compute as a strategic resource to maintain geopolitical supremacy.
For defense and intelligence communities, compute is the modern equivalent of uranium enrichment. This perspective prioritizes using export controls and infrastructure subsidies to ensure the United States and its allies maintain a decisive lead in artificial superintelligence. They argue that denying adversaries access to advanced chips is essential for national security, even if it risks bifurcating the global technology supply chain or accelerating foreign indigenous chip development.
Algorithmic Efficiency Researchers
Warn that hardware thresholds will inevitably be rendered obsolete by software innovation.
Computer scientists focused on optimization argue that compute governance is a temporary fix. They point out that models like AlphaFold 2 achieved historic breakthroughs using fractions of the compute required for large language models. This camp warns that as algorithms become more efficient, the ability to train frontier models will diffuse to smaller actors using less hardware, eventually bypassing the massive data center chokepoints that current regulations rely upon.
- Compute Governance Advocates
- Argue that physical hardware is the only enforceable chokepoint for AI regulation.
- National Security Strategists
- View compute as a strategic resource to maintain geopolitical supremacy.
- Algorithmic Efficiency Researchers
- Warn that hardware thresholds will inevitably be rendered obsolete by software innovation.
Perspectives this story doesn't cover
- Open-source developers who rely on decentralized compute
- Hardware manufacturers facing export control revenue losses
Sources
[1]arXivAlgorithmic Efficiency ResearchersComputing Power and the Governance of Artificial Intelligence
Read on arXiv →
[2]Effective AltruismCompute Governance AdvocatesCompute governance
Read on Effective Altruism →
[3]Foreign AffairsNational Security StrategistsAmerica's Superintelligence Dilemma
Read on Foreign Affairs →
[4]Factlen Editorial TeamCompute Governance AdvocatesSynthesis by Factlen editorial team
Read on Factlen Editorial Team →
More in Artificial Intelligence
See all →AI Regulation
Trump and Tech CEOs Sign Voluntary White House Accord on 'Super Intelligence' Safety Standards
5 sources
Defense Procurement
Federal Appeals Court Upholds Pentagon Blacklist of Anthropic Over AI Safety Rules
5 sources
AI Compliance
The Five Steps of an Algorithmic Impact Assessment Regulators Use to Mandate AI Risk Mitigation
3 sources
Labor Economics
How the Task-Based Model Decomposes Jobs into Tasks to Predict AI's Labor Impact
6 sources
Comments
Every angle. Every day.
Get Artificial Intelligence stories with full source coverage and perspective breakdowns, free every day.




