Thresholds, cloud KYC, and the data-center fight
Lesson 3 of 5 in Compute Governance, Export Controls, and the Science of AI Safety.
Export controls govern where compute goes. A second family of rules uses compute to decide which developers the law grabs: write a FLOPs number into a statute, and everyone who trains above it inherits duties. You met the canonical example already — the EU AI Act’s presumption that a GPAI model trained above 10²⁵ FLOPs poses systemic risk (GPAI) (that regime lives in the EU domain; here we study the technique).
The threshold idea spread fast because it solves a real drafting problem: "frontier model" is vague, but a FLOPs count is administrable, estimable before training even finishes, and hard to litigate about. It also inherits every proxy weakness from lesson one — so watch how each regime hedges.
| Regime | Status | Threshold | What it triggers | How it hedges against proxy decay |
|---|---|---|---|---|
EU AI Act Art 51 | In force; GPAI duties applied from Aug 2025 | 10²⁵ FLOPs training compute → presumption of systemic risk (≈10²³ FLOPs as the Commission’s indicative floor for being a GPAI model at all) | Notification to the AI Office, model evaluations, adversarial testing, incident reporting, cybersecurity (Arts 52, 55) | It is a rebuttable presumption, and the Commission can designate below-threshold models on other criteria (Annex XIII) and update the threshold by delegated act |
US EO 14110 (rescinded) | Oct 2023 – Jan 2025, rescinded by the incoming administration | 10²⁶ FLOPs general models; 10²³ for biological-sequence models; cluster reporting above a compute-capacity line | Reporting of training runs, red-team results, and cluster ownership to the federal government under the Defense Production Act | Thresholds were explicitly interim, revisable by the Commerce Department — then the whole EO was revoked, the sharpest lesson in executive-order fragility |
California SB 53 (2025) | Signed Sept 2025; the Transparency in Frontier AI Act | 10²⁶ FLOPs defines a frontier developer; frontier developers above $500M annual revenue are large frontier developers | Publish a frontier AI framework, transparency reports, report critical safety incidents to the state within set deadlines, whistleblower protections; civil penalties up to $1M per violation | A two-factor trigger (compute and revenue for the heaviest duties) so garage-scale actors aren’t swept in as efficiency rises; agency authority to update definitions |
AI Diffusion Rule (rescinded) | Jan–May 2025 | ≈10²⁶ FLOPs for controlled closed model weights | Export license required to transfer covered weights outside trusted tiers | None to speak of — rescinded before its hedges could be tested |
Cloud know-your-customer closes the loophole thresholds leave open: you don’t need to import chips if you can rent them. In January 2024, the US Commerce Department proposed a rule requiring US infrastructure-as-a-service providers to run customer identification programs — bank-style KYC for compute — and to report when foreign customers train large AI models on their platforms. The proposal borrowed its architecture wholesale from anti-money-laundering law: identify the customer, know the beneficial owner, watch for structuring (splitting one big training run across many accounts), and report suspicious activity. As of September 2026, check whether a final rule has issued and in what form — the proposal outlived the executive order that expanded it, but its finalisation has been repeatedly in flux.
The endgame of all supply-side policy is physical: data centers. Frontier training clusters now demand gigawatt-scale power, and the constraint on AI buildout has shifted visibly from chips to electricity, land, water, and grid interconnection queues. Both US administrations — otherwise opposed on nearly everything in AI policy — pushed to open federal land and accelerate permitting for AI data centers, and hyperscalers signed nuclear power deals (including restarting a Three Mile Island reactor for Microsoft) that would have been unthinkable a decade ago. Governance follows the megawatts: siting fights, local moratoria, water-use disclosure demands, and grid-cost allocation are now AI policy venues as real as any parliament. The environmental measurement and disclosure side of this — including the EU AI Act’s energy-documentation duty for GPAI providers — is taught in the next module.
Key terms: compute threshold, systemic risk (GPAI), kyc, data center, model weights
Interactive checkpoint quiz (2 questions) — open this page in a browser to take it.