What's the fundamental difference between Compute Governance and directly regulating an AI model itself?
The biggest obstacle to regulating a model directly is that model weights are software — once training is complete, they can be copied infinitely at near-zero cost, making them hard to intercept or trace after the fact. And "how dangerous is this model" itself requires complex capability evaluation to answer, making it difficult to build an objective, enforceable quantitative threshold around.
Compute governance instead shifts the point of Leverage to "before" training happens — indirectly shaping what kind of model could even be trained by restricting who gets access to how many chips and how much compute. The advantage is that chips are physical objects with countable numbers and a highly concentrated supply chain, making enforcement far more tractable than regulating software directly. The trade-off is that it targets the preconditions for capability formation, not the risk level of the capability itself — which is exactly why compute governance is generally treated as one piece of the AI governance toolkit, not a universal solution.
How was the TPP (Total Processing Performance) threshold set, and what does the number 21,000 represent?
TPP is a technical metric the Bureau of Industry and Security uses to measure chip compute capability, combining factors like floating-point operation speed into a single number representing a chip's overall performance. The logic behind setting a threshold is to find a reference point below which chips, even aggregated together, would struggle to support training the most frontier, highest-risk models — concentrating regulatory resources on hardware genuinely close to the capability frontier, rather than restricting every tier of compute chip uniformly.
Worth noting: this kind of technical threshold isn't fixed forever — the new BIS rule mentioned in this piece is itself an update to earlier performance thresholds (the first of which was set back in October 2022). As chip performance keeps advancing and algorithmic efficiency keeps improving, the same numeric threshold can end up covering more and more chips that were originally outside the controlled range as time passes. That's why setting a Compute Governance threshold generally needs to come with a regular review mechanism, rather than being fixed once and left unchanged indefinitely.
How would "cloud compute KYC" rules actually work, and why are they different from chip export controls?
Chip export controls govern whether a given chip can be shipped to a given country — fundamentally a border-control logic. But once a chip has legally arrived at a data center, in principle any customer with an account and the ability to pay can remotely rent that compute capacity through a cloud service, without the chip itself ever crossing a border again. That's exactly the core problem behind the "remote-access loophole": export controls can stop the physical movement of a chip, but they can't stop its compute capacity from being remotely used over a network.
Cloud KYC rules are trying to close precisely that gap: requiring cloud providers to verify a customer's genuine identity and stated purpose before they can rent large amounts of compute — modeled on anti-money-laundering practices at financial institutions — and to apply heightened scrutiny to rental requests coming from restricted regions or restricted entities. This means the point of Leverage in Compute Governance is gradually expanding from "where is the chip" to "who is using the chip," and the two require different enforcement mechanisms and different responsible parties — the former falls mainly on exporters, the latter on cloud service providers.
I'm not a policy researcher, just a general reader following AI industry news — what practical use is there in tracking Compute Governance changes?
Changes in compute governance often signal whether a company's future room to grow will be constrained earlier than the company's own model capability scores do. For example, if a company relies heavily on a specific tier of advanced chip, and that tier happens to sit close to a new TPP control threshold, then any minor adjustment to export rules going forward could directly affect whether that company can keep obtaining the compute it needs to train its next-generation models — and this kind of information tends to show up earlier and more clearly in regulatory notices and supply-chain news than in capability benchmark results.
For a general reader, practical steps include: watching what major chip suppliers (like Nvidia) say specifically about shipment restrictions in restricted markets (like China) in their earnings reports; watching whether cloud providers publicly disclose new customer identity-verification measures they've adopted; and tracking any policy updates related to "compute reporting thresholds" or "chip performance thresholds." These numbers are technical, but shifts in how tight or loose those thresholds are tend to be an early signal for whether the broader AI industry's supply side is heading toward a bottleneck.
If you try to regulate an AI model directly, you run into a fundamental problem: a model's weights are just a string of numbers that can be copied infinitely, at essentially zero cost, once training is complete — and almost impossible to fully intercept. But swap the regulatory target to the chips required to train that model, and the picture changes entirely. Chips are physical objects that require an extraordinarily complex, highly concentrated supply chain to manufacture. They can be counted, and their usage can be detected. That's the core logic behind why Compute Governance has heated up so quickly in policy circles in recent years: rather than trying to control the model, control the pile of chips that made the model possible in the first place.
Researchers at Governance.ai break down why compute makes such an appealing governance lever into four properties: detectability (large-scale AI training requires thousands of specialized chips running in extremely power-hungry data centers, and activity at that scale is very hard to fully hide); excludability (who can get chips, and how many, can be restricted at various points in the supply chain); quantifiability (chip counts and compute scale are concrete numbers, unlike "how dangerous is this model," which requires subjective judgment); and a highly concentrated supply chain (advanced chip manufacturing globally is concentrated in a tiny handful of companies, meaning regulators don't have to deal with thousands of dispersed actors). By contrast, data and algorithms are intangible assets that can be copied infinitely, are hard to trace back to their source, and naturally tend to diffuse — which makes them far harder to regulate in practice than chips.
The most intuitive form compute governance takes is chip export controls, and U.S. policy here underwent a clear shift in 2026. The Biden-era AI Diffusion Rule had planned to sort every country into three tiers, with export leniency determined by tier, but the rule was shelved by the Trump administration before it took formal effect. On January 15, 2026, the Bureau of Industry and Security (BIS) published a new rule replacing country tiers with concrete performance thresholds: chips at or above a Total Processing Performance (TPP) of 21,000, or memory bandwidth at or above 6,500 GB/s, are fully restricted; chips below that threshold shifted from a default "presumption of denial" review to case-by-case licensing. The day before the new rule took effect, the White House separately announced a 25% tariff on advanced computing chips meeting the same performance thresholds — producing an unusual policy combination of loosened export licensing paired with a tightened import tariff, running side by side.
Chip export controls are the most media-visible end of the compute governance spectrum, but the concept actually spans a much broader set of tools. The U.S.'s 2023 executive order requires developers of models trained above a specific compute scale (10^26 floating-point operations) to report that fact to the government; the EU's AI Act sets a similar compute-reporting threshold for general-purpose AI models, though the number of models currently covered remains fairly limited. Beyond that, policy circles have recently been discussing Know-Your-Customer rules for cloud computing — requiring cloud providers to verify the identity and purpose of customers renting large amounts of compute, modeled on anti-money-laundering practices at financial institutions. This connects directly to another policy shift in August 2026: rather than only controlling the physical export of chips, regulators are also moving to control who can remotely rent restricted chips already sitting in overseas cloud data centers — since border controls on chip shipments alone can't reach a situation where the chips are already offshore but being remotely rented by restricted parties.
Although compute governance is technically feasible, it comes with a structural dilemma. Analysts broadly note that a very stringent compute governance regime — say, a government-run centralized "compute reserve," or consolidating advanced AI development into a single national or international project — could substantially increase regulatory effectiveness in theory, but at the cost of potentially concentrating compute (and by extension, advanced AI capability) in the hands of very few actors, which is itself a risk worth scrutinizing. Beyond that, effectively regulating compute usage typically requires governments to gain significant visibility into what that compute is actually being used for — but compute resources are also used extensively for consumer and enterprise applications that have nothing to do with AI, which unavoidably entangles compute governance with data-privacy concerns. And algorithmic efficiency keeps improving over time, meaning the Compute Threshold required to achieve a given level of capability keeps falling — a control threshold set today may look far too loose, or simply outdated, before long.
For readers assessing AI-related investments or supply-chain exposure, the most direct implication of compute governance is that chip export rules, cloud compute reporting requirements, and any future cloud KYC framework will all directly affect whether a given company can access the compute it needs to train frontier models — and by extension, how fast it can develop capability and how it positions itself commercially. Rather than fixating on any single model's capability benchmark score, tracking the concrete numbers behind compute control thresholds (where the TPP threshold is set, for instance), who ends up on a restricted list, and how much new compliance burden cloud providers are being asked to shoulder, tends to let you gauge earlier and more concretely whether a company's future access to compute is likely to be constrained. That's exactly why policy circles have come to see compute as the real governance lever — it tends to signal what's coming well before any individual model's capability score does.