Why compute became the lever

Lesson 1 of 5 in Compute Governance, Export Controls, and the Science of AI Safety.

Frontier AI is made of three inputs: algorithms, data, and compute. Two of them are nearly ungovernable. Algorithms are ideas — they travel in papers, preprints, and heads, and no border stops them. Data is copied at zero cost and hoarded everywhere. But compute — the physical hardware that turns algorithms and data into trained models — has properties a regulator can actually grip.

Compute is detectable: a frontier training run consumes tens of thousands of accelerators drawing megawatts for months, visible to the utility, the cloud provider, and often the satellite. It is excludable: chips are physical objects that clear customs. It is quantifiable: training runs are measured in floating-point operations, a number you can write into a statute. And above all it is concentrated — the supply chain narrows, at several points, to a handful of firms in a handful of allied jurisdictions.

The AI chip supply chain and its chokepoints

  1. Chip design (NVIDIA, AMD, Google)

    NVIDIA holds the dominant share of AI accelerators. Design is concentrated in US firms — which is what gives US export law its reach.

  2. Design software (EDA)

    Three firms — Synopsys, Cadence, Siemens EDA — supply nearly all electronic design automation tools. A US-controllable chokepoint.

  3. Lithography (ASML)

    One Dutch company makes every EUV lithography machine on Earth. No EUV, no leading-edge chips. The Netherlands restricted EUV exports to China years before 2022, and DUV from 2023.

  4. Fabrication (TSMC, Samsung)

    TSMC in Taiwan fabricates the overwhelming majority of leading-edge AI chips. Geographic concentration here is both a policy lever and the single greatest supply-chain risk.

  5. High-bandwidth memory (SK hynix, Samsung, Micron)

    HBM became a control target in December 2024 — an accelerator without HBM is starved.

  6. Cloud & data centers (AWS, Azure, Google, CoreWeave…)

    Where most actors actually touch compute. The chokepoint argument for cloud KYC: you don’t need to own chips to train a model, just to rent them.

  7. Trained frontier model

    The output the whole chain exists to produce — and the point at which control becomes vastly harder, because weights are just files.

Walk that chain and count the single points of failure: one EUV supplier (ASML), one dominant leading-edge fab (TSMC), three EDA vendors, one dominant accelerator designer. This is why compute governance moved from an academic proposal — the influential 2024 Computing Power and the Governance of AI paper crystallised the case — to the operating logic of actual policy in under three years.

The same logic explains the limits. Controls grip hardware, not knowledge: algorithmic efficiency improves every year, so the compute needed for a given capability keeps falling — any fixed FLOPs line buys time, not permanence. Controls leak: chips are smuggled, rented remotely, and stockpiled ahead of rule changes. And controls concentrate pain on the controlled party’s access, which creates a powerful incentive to build a domestic alternative — the outcome the controls were meant to prevent, arriving on a delay. Every debate you will read in this module is a fight about how these three facts net out.

Key terms: compute governance, FLOPs, training compute, frontier model, export controls

Interactive checkpoint quiz (2 questions) — open this page in a browser to take it.