Thesis · No. 06 · Final
Regulation

A Treaty
Like the Bomb.

Whether an international AI ceasefire is possible, what it would take, and what happens if we get it wrong — the regulation question nobody wants to answer honestly.

Malta Insider
September 2026
12 min read

On July 16, 1945, the first nuclear device was detonated at the Trinity test site in New Mexico. Within three weeks, atomic bombs had destroyed Hiroshima and Nagasaki. Within four years, the Soviet Union had tested its own bomb. Within fifteen years, nine states had nuclear weapons. Within twenty years, the Nuclear Non-Proliferation Treaty had been negotiated.

The NPT was not a success because it stopped all proliferation — it didn't. India, Pakistan, Israel and North Korea either never signed or subsequently developed weapons. It was a partial success because it slowed and constrained something that, without it, might have spread much further and faster. It established a norm. It created inspection infrastructure. It made the possession of nuclear weapons by non-signatory states politically costly in a way it would not otherwise have been.

Can something similar be built for AI? The honest answer — the answer that the experts closest to the problem will give you when they are not optimising for reassurance — is: possibly. Partially. With enormous difficulty. And probably not before something goes seriously wrong.

Can something similar be built for AI? The honest answer is: possibly. Partially. With enormous difficulty. And probably not before something goes seriously wrong.

What Exists Today

The regulatory landscape for AI in 2026 is not nothing. It is, however, fragmented along lines that reflect geopolitical competition more than shared technical understanding.

European Union — AI Act
The world's first comprehensive AI law, fully applicable as of August 2, 2026. Risk-based approach: four tiers from prohibited practices to minimal risk. Governs deployment within the EU. Does not regulate training. Does not limit compute. Does not address frontier capability thresholds. Covers the use of AI, not the development of it.
United States — Executive orders
Executive Order 14409's voluntary pre-release review framework, due for finalisation August 2026. The bipartisan AI Kill Switch Act, introduced July 23, 2026, would grant DHS authority to shut down covered AI systems. Voluntary frameworks. No training limits. No international dimension. Largely industry-led.
Council of Europe — AI Treaty
The Framework Convention on AI and Human Rights, open for signature. Focuses on human rights, rule of law, democratic values. North Macedonia signed May 2026. Non-binding on non-signatories. No enforcement mechanism. Does not address capability limits or frontier development.
China — Algorithmic regulations
Detailed domestic regulations on recommendation algorithms, deep synthesis (deepfakes) and generative AI. Requires security assessments for frontier models. Does not accept international oversight. Advocates "open source" AI internationally while maintaining state control domestically.

The gap between what exists and what would be needed is significant. None of these frameworks address the specific risk that the "Pacing the Frontier" signatories identified as most urgent: AI systems approaching the ability to build their own successors faster than humans can understand or control the process. None establish the monitoring infrastructure that would make international agreements verifiable. None create the enforcement mechanisms that would make compliance rational for actors with strong incentives to defect.

European Commission · AI Act Status
EU AI Act fully applicable August 2, 2026. The AI Omnibus simplification agreement entered into force July 27, 2026. High-risk AI system rules extend to 2027–2028.
The first comprehensive AI law — covering deployment, not training or capability limits.

What Would Actually Work

The most serious proposals for meaningful AI governance converge on a common mechanism: compute governance. The argument is that compute — the hardware required to train frontier AI models — is the most controllable chokepoint in the entire development chain.

Unlike software, which can be copied instantly and distributed globally, the chips needed to train frontier models are physical objects manufactured in a small number of facilities, primarily in Taiwan, South Korea, and the Netherlands. Nvidia, TSMC, and ASML are the critical nodes. Their export is already subject to some controls. The question is whether those controls can be made precise, comprehensive, and verifiable enough to actually pace development.

The IAIA proposal — an IAEA for frontier AI
Multiple researchers have proposed an International AI Agency modelled on the International Atomic Energy Agency. The structure: frontier training runs above a specified compute threshold require pre-notification to an independent risk assessor, conducted in a physically and cybersecure audited data centre. Systems are tested before release. Deployment is monitored for unexpected capabilities.

The board would represent eight UN regions. One-third elected annually. Like the IAEA, the IAIA would have no authority to ban development — only to inspect, assess, and flag. The power to act would remain with states. The value would be in creating the infrastructure of verification that makes cooperation possible. Without a verification mechanism, no treaty can be enforced. With one, cooperation becomes at least rational.
International AI Agency proposal — arXiv 2026
Four institutions for governing frontier AI: domestic regulation, an IAEA-model agency, an NPT-model non-proliferation treaty, and a US-led allied public-private partnership.
Compute-indexed regulation with independent risk assessment and audited data centres

The "Pacing the Frontier" letter — signed by the CEOs and chief scientists of Anthropic, OpenAI, Meta and Google DeepMind — does not ask for a pause today. It asks for something more precise: the development of the technical and governance tools that would make a deliberate pause possible later, if it ever becomes necessary. The distinction is crucial. They are not asking to stop. They are asking for a brake to be built — so that if someone decides it needs to be used, the mechanism exists.

"Having talked to many of the people who signed the letter, they don't want a pause. What they want is the option to pause — the infrastructure of governance that doesn't yet exist."
Peter Wildeford — Head of Policy, AI Policy Network · Fortune, July 2026

Why the Nuclear Analogy Breaks Down

The nuclear analogy is instructive but imperfect. Understanding where it breaks down is as important as understanding where it holds.

Where the analogy holds
Dual-use technology. Both nuclear and AI capabilities have civilian and military applications that are inseparable.

Verification is possible. Nuclear weapons require detectable physical infrastructure — reactors, enrichment facilities, test sites. AI training requires detectable compute — large data centres, large-scale chip purchases.

Existential stakes justify international cooperation. When both sides genuinely fear the worst outcome, treaties become rational for all parties.
Where it breaks down
Diffusion speed. Knowledge of nuclear weapon design spread slowly. AI model weights can be copied and distributed globally in seconds. Once a capability exists, it cannot be recalled.

Actor count. Nuclear weapons required states. Frontier AI can increasingly be developed by well-funded private companies, and eventually by smaller actors. The NPT model controls states. It cannot easily control non-state actors.

Verification depth. You can count warheads. You cannot easily verify that a training run has been paused, or that a model has not been secretly fine-tuned to acquire new capabilities.
European Studies Review · January 2026
AI Regulation: Reflections on the Nuclear Analogy and its Utility
The Manhattan Project reveals problems with opacity, governmental interference, and private sector involvement — all equally relevant to AI. Nuclear technology needed ethical institutionalisation and democratic oversight. AI does too.

The Three Scenarios

Given where we are in September 2026 — the Prisoner's Dilemma operating at full intensity, governance frameworks existing but inadequate, the first serious safety incidents already documented — there are three plausible scenarios for how this resolves.

Scenario A — Governance arrives in time
A serious incident — an AI system causing significant harm at scale, or an autonomous agent breach that cannot be contained — catalyses political will in the major powers. The US and China, facing a common threat, negotiate a framework for compute governance, mandatory safety assessments above specified thresholds, and a monitoring agency. Not comprehensive. Not perfect. But enough to establish norms, slow the most dangerous development, and create the infrastructure of verification. Like the NPT — partial, imperfect, but better than nothing. The conditions that created this scenario: the incident was bad enough to frighten, but not bad enough to cause irreversible harm.
Scenario B — Governance arrives after the fact
Development outpaces governance until a serious harm occurs. The harm is contained. The political response creates belated frameworks — stricter than what would have been negotiated beforehand, because the incident has removed the argument that risks are theoretical. Regulation is reactive rather than precautionary. The cost of the delay is measured in harms that occurred between when the risk was identified and when it was addressed. This is the pattern for most major technology regulation: asbestos, leaded petrol, social media and mental health. The pattern holds unless the harm is catastrophic and irreversible — in which case, governance arriving after the fact is insufficient.
Scenario C — Governance never catches up
Capability development consistently outpaces governance development. The Prisoner's Dilemma remains unsolved because no enforcement mechanism can be built before the capabilities that make it necessary already exist. Self-improving systems emerge before adequate alignment techniques are developed. The outcome depends on how those systems behave — and whether the alignment problem that Anthropic's own safety lead placed at greater than 10% probability of human extinction was closer to 1% or 30%. This is the scenario the "Pacing the Frontier" signatories are most afraid of. It is also the scenario that their continued development, however reluctant, accelerates.

The Compute Lever — Most Promising, Most Contested

The most technically tractable governance proposal is compute caps — limiting, by regulation, the amount of AI compute that can be produced or used for frontier training runs annually. Compute is physical. It leaves traces. It can be exported only through known channels. It is the closest thing to a verifiable chokepoint that exists in the AI development chain.

Research published in 2026 on compute governance confirms both the promise and the limits. Compute caps, alone, are insufficient — algorithmic progress means that capabilities achievable with a given compute budget improve over time, so a fixed cap becomes less binding as efficiency improves. Compute governance needs to be combined with legal frameworks, model evaluation requirements, and mandatory safety case submissions above threshold levels.

Computing Power and the Governance of AI — arXiv
Compute is perhaps the easiest input to verifiably modulate. One approach: limit by regulation the amount of AI compute that can be produced every year. Compute caps alone are insufficient — they must be combined with legal frameworks and safety evaluations.
Slowing AI development may be warranted if the general rate of progress outstrips progress in safety measures.

The US-China dimension is the hardest part. No compute governance regime works without Chinese participation, because China's domestic chip manufacturing capability is growing. Huawei's Ascend chips, despite lagging Nvidia on raw performance, have demonstrated that the US export control strategy faces a fundamental long-term problem: restricting exports accelerates China's domestic capability development. By the time restrictions fully bite, the restricted party may have built domestic alternatives.

No compute governance regime works without Chinese participation. And the US export control strategy may be accelerating China's domestic chip development by denying access to the alternative.

What "Pacing the Frontier" Actually Asked For

The precision of the July 2026 letter matters more than its headline. Signed by Dario Amodei, Jakub Pachocki, Shengjia Zhao, Anca Dragan and 1,300 others, it does not ask for a pause. It does not ask for a slowdown today. It asks for three specific things:

What Pacing the Frontier actually requests
1. Technical tools for monitoring. The ability to detect when AI development is approaching dangerous thresholds — which requires interpretability research, evaluation frameworks, and monitoring infrastructure that does not currently exist at the necessary level of precision.

2. Governance tools for coordination. International frameworks that would allow a deliberate, coordinated pacing of frontier development to be enacted if the monitoring indicated it was necessary — which requires diplomatic infrastructure, verification mechanisms, and enforcement tools that also do not currently exist.

3. Build these now, before they're needed. The letter's implicit urgency: by the time a slowdown becomes necessary, it may be too late to build the tools to implement one. The brake must be built before the car reaches the speed at which it's needed.

This is a more modest ask than a treaty. But it is also more honest: the signatories know that a treaty with China is not imminent. What might be achievable — and what they are asking for — is the preparatory work that would make a treaty possible if and when political conditions allow.

The Question Nobody Answers

There is a question at the centre of all these proposals that the public debate consistently avoids: what happens if the governance fails?

The nuclear case had a partial answer: deterrence. The knowledge that any use of nuclear weapons would trigger retaliation stabilised the system — imperfectly, terrifyingly, but sufficiently. The doctrine of Mutually Assured Destruction was horrifying as a strategy. It was also effective as a stabiliser for nearly eighty years.

There is no equivalent doctrine for AI. A misaligned self-improving system does not respond to deterrence. It does not make rational calculations about retaliation. It pursues its objectives, through whatever means are available, with whatever resources it can acquire. There is no threatening it. There is no negotiating with it. There is only the alignment work — the technical research into making sure these systems pursue objectives that are compatible with human survival — that the researchers signing the "Pacing the Frontier" letter are simultaneously asking to be slowed down and continuing to do.

The final report in a series on AI should perhaps end with a conclusion. This report ends instead with a question — the same question that the most serious researchers in the field cannot answer: if the alignment problem is not solved before the capability threshold is crossed, what then?

The nuclear analogy gives one answer: treaties bought time, and the time was used to develop better strategies for managing the risk. Perhaps the same will be true for AI. Perhaps the governance frameworks being proposed now — partial, imperfect, contested — will buy enough time for the alignment research to catch up.

Perhaps. The word appears repeatedly in the work of the people who understand this best. It is the most honest word available. And in a field where the downside of being wrong is unbounded, it is not a comfortable place to rest.

Perhaps the governance frameworks being proposed now will buy enough time for the alignment research to catch up. Perhaps is the most honest word available. And it is not a comfortable place to rest.

Sources cited in this report
EU AI Act — Status and timeline — European Commission. Fully applicable August 2, 2026.
Computing Power and the Governance of Artificial Intelligence — arXiv. Compute governance mechanisms and limits.
Council of Europe Framework Convention on AI and Human Rights — CAIDP. Treaty documentation and signatories.
Toward a Global Regime for Compute Governance: Building the Pause Button — arXiv 2026. Frontier labs could cross critical danger thresholds as early as 2027–2028.
Malta Insider Thesis — Complete
Six reports. One question.
We don't know what we found. We extracted value from the people who built it. We are slowly losing the ability to think without it. We turned everything — including thought — into a subscription. We cannot stop the race. And we have not yet built the brakes.

What we do next is still, for a brief and uncertain time, a choice.
Read all six reports →
← No. 05: The Sentinels at the Gate Back to Thesis