A single proposal combines three existing mechanisms — compute governance, a hybrid public/private certification market, and US domestic regulation — into one ecosystem. This map traces how the three pieces connect, where the combination quietly breaks, and what it takes to hold under a real emergency.
The three pillars
Each piece is already in motion somewhere. The proposal's bet is that layered together, their gaps don't overlap — each pillar carries a matched cost.
01
Track and report frontier training runs at the hardware level.
Strengths
Weaknesses
02
A market for certification providers; courts and certifiers handle deployment harms.
Strengths
Weaknesses
03
Agencies oversee; power stays spread across companies; export controls hold the China lead.
Strengths
Weaknesses
Where it breaks
All three pillars lean on the same shortfall: government doesn't have the technical staff to verify anything itself. Follow what happens when that job gets handed off.
The verification job gets handed to a certifier — chosen and paid by the company being checked.
Right as a company nears a dangerous capability threshold, its own hand-picked certifier signs off.
Nobody independent is watching, and liability can't backstop it — no company can pay for a true catastrophe.
Net result: paperwork that looks like oversight, but isn't.
The fix
Each fix targets a specific point in the failure chain above — replacing trust in paperwork with structural checks.
Build reporting into the chips themselves, so oversight doesn't depend on hiring more government auditors.
Short term · fixes Step 1Companies contribute talent to design certifications across every frontier lab, double-blind. They pay into a shared fund; certifiers are assigned by rotation, not chosen by the company they're checking.
Fixes Step 2Courts and certifiers handle everyday harms. A small, focused agency — like an AISI — gets the sole power to halt a training run, but only for defined catastrophic thresholds, reauthorized by Congress on a set schedule.
Fixes Step 3Big problem: who watches the watchers?
The plan concentrates the reporting system and the halt authority in one place. A fully distributed system would resist abuse but move too slowly for a real emergency — so different risks get different structures.
Distributed & slow
Courts & certifiers
Handle everyday harms — the rotation-assigned, double-blind certification market.
Centralized & time-limited
AISI-style agency
Sole halt authority. Power kept narrow; members are non-political joint appointees approved by both labs and Congress.
Centralized & fast
Catastrophic thresholds
Triggered automatically if a certifier is later caught missing something.
Courts and Congress back up the halt authority — knowingly slower than the agency itself, slow enough to act as a commercial deterrent to release. The highest cost: responding fast to a catastrophe means trusting one body's judgment before anyone can double-check it.
"Different risks need different structures: slow and spread out for everyday problems, fast and centralized for the worst-case ones."