everyonedies

Archive 2026-09-24 · 185 entries · 14 chapters

A Draft of a Treaty, with Annotations

Article VIII: Restricted Research: AI Algorithms and Hardware

  1. For the purpose of preventing specific research that advances the frontier of AI capabilities or undermines the ability of Parties to implement the measures in this Treaty, this Treaty designates research meeting any of the conditions below as Restricted Research:

    1. Improvements to the methods used to create frontier models, as defined in Article II, that would improve model capabilities or the efficiency of AI development, deployment, or use
    2. Distributed or decentralized training methods, or training methods optimized for use on widely available or consumer hardware
    3. Research into computer artificial intelligence paradigms beyond machine learning
    4. Advancements in the fabrication of AI-relevant chips or chip components
    5. Design of more performant or more efficient AI chips
  2. The ISIA’s Research Controls division shall classify all Restricted Research activities as either Controlled or Banned.

    1. Each Party shall monitor any Controlled Research activities within its jurisdiction, and take measures to ensure that all controlled research is monitored and made available to the Research Controls division for review and monitoring purpose.
    2. Each Party shall not conduct any Banned Research, and shall prohibit and prevent Banned Research by any entity within its jurisdiction.
  3. No Party shall assist, encourage, or share Banned Research, including by funding, procuring, hosting, supervising, teaching, publishing, providing controlled tools or chips, or facilitating collaboration.

  4. Each Party shall provide a representative to the ISIA’s Research Controls division, under the Technical Secretariat (established in Article III). This division gains these responsibilities:

    1. Interpret and clarify the categories of Restricted Research, and respond to questions as to the boundaries of Restricted Research, in response to new information, and in response to requests from researchers or organizations or Party members.
    2. Interpret and clarify the boundary between Controlled Research and Banned Research, and respond to questions as to this boundary, in response to new information, and in response to requests from researchers or organizations or Party members.
    3. Modify the definition of Restricted Research and its categories, in response to changing conditions, or in response to requests from researchers or organizations or Party Members.
    4. Modify the boundary between Controlled Research and Banned Research in response to changing conditions, or in response to requests from researchers or organizations or Party Members.
    5. The Technical Secretariat may modify the categories, boundaries, and definitions of Restricted Research in accordance with the process described in Article III.

Precedent

Pre-emptive restrictions on the dissemination of information related to dangerous technology find precedent in the Atomic Energy Act of 1946, still in force, which established information on certain topics as Restricted Data by default (the “born secret” doctrine); exclusions were at the discretion of the new Atomic Energy Commission created by this legislation:[1]

The term “restricted data” as used in this section means all data concerning the manufacture or utilization of atomic weapons, the production of fissionable material, or the use of fissionable material in the production of power, but shall not include any data which the Commission from time to time determines may be published without adversely affecting the common defense and security.

Unlike other types of government classification, Restricted Data can be created (deliberately or accidentally) by the private sector, a matter of unresolved constitutionality[2] that highlights the need for a regulatory arm authorized and capable of making everyday decisions about the exact boundaries of Restricted Data. The National Nuclear Security Administration (NNSA) does this for nuclear secrets in the U.S.. Under our Article VIII, Paragraph 5, the Research Controls division of the new ISIA would take on this role for restricted AI research. It would also fill other NNSA-analogous functions, outlined in our Article IX, by (1) maintaining relationships with researchers and and organizations working on projects that approach the classification threshold, and (2) establishing secure infrastructure for reporting and containment of inadvertent discoveries.

There is also precedent for containing and controlling research in dangerous fields. In the final months of World War II, the U.K. and U.S. collaborated on the Alsos Mission to capture German nuclear scientists, gather information about German progress toward an atomic bomb, and prevent the USSR from obtaining these resources for its own nuclear program. Project Overcast (also called Operation Paperclip) was a secret U.S. program to take German rocket engineers into U.S. employment after the war.

Containment of Restricted AI Research within Party states might run through existing regulatory frameworks. In the U.S., these include:

  • The “deemed exports” concept in export control law, which obliges a U.S. entity to obtain an export license from the Bureau of Industry and Security[3] before sharing controlled technologies with foreign persons by deeming such sharing as an export.

  • The International Traffic in Arms Regulations (ITAR), a set of U.S. State Department regulations that control the export of military and some dual-use technologies. ITAR was used to prevent the broader development and use of cryptographic techniques by the private sector until 1996, as these were classified as a “defense article” on the United States Munitions List.

  • The Invention Secrecy Act of 1951, which gives U.S. government agencies the power to impose “secrecy orders” on new patent applications with national security implications. Inventors can not only be denied patents, but legally prohibited from disclosing, publishing, or even using their inventions.[4]

Project Overcast also provides precedent for controlling researchers by simply paying them well to act in the interest of the state. Additional precedent for such incentives is discussed with Article IX.

Notes

Banning several broad categories of research, when relevant know-how is already distributed in the private sector, presents a challenge. In our draft, research is restricted if it advances AI capabilities or performance, or if it endangers the verification scheme laid out in previous articles.

Some research must be banned to prevent AI capabilities from advancing, even when holding the amount of training FLOP constant. This ban would need to cover all research that might make AIs more efficient to train or that might increase the capabilities of AIs, often referred to as “algorithmic progress.” In current paradigms, this includes advances in the algorithms used in pre-training, post-training, and inference. As paradigms change, these distinctions may become less clear and new categories may arise.[5] For this reason, the treaty uses the terms “development, deployment, or use.”

Previous algorithmic innovations, such as the development of the transformer architecture, demonstrate the potential for rapid advances in AI capabilities. Continued innovation could dramatically lower the amount of computational resources required for a given level of AI capability. As a feasibility argument, observe that modern AIs are much less data-efficient than human beings, which suggests that much more data-efficient algorithms can be found.

It is much harder to prevent the training of dangerous AIs when they can be trained with a small number of AI chips, or with many chips geographically dispersed in small clusters.

Separately, a ban must preclude research into new ways to manufacture untracked AI chips. Monitoring and verification of AI chips is feasible in large part because of the present complexity and centralization of advanced AI-relevant semiconductor manufacture.

Article VII also bans research into the design of more performant or efficient AI chips, which otherwise become substantially more efficient year over year. A datacenter using more efficient AI chips would be easier to conceal, as these chips would use less electricity for the same or greater performance.

The specific types of research that are restricted would need to be updated in response to changing conditions. One example of an activity the ISIA may later want to restrict is research into consumer hardware that can efficiently perform AI training activities, if such progress would pose a risk to verification.

Domestic efforts to restrict research could start by focusing on the publication and funding of research. Most researchers want to be law-abiding, gainfully employed citizens; steps that push dangerous AI research outside of accepted social norms would likely be impactful.

The diversity of restricted actions in Paragraph 3 addresses a need to ensure that if research activities are split between multiple jurisdictions, the Treaty still unambiguously holds each state responsible for prohibiting and preventing the individual activities. Paragraph 3 applies, for example, in the case where a company in one jurisdiction hires an employee in a second who remotely operates chips hosted in a third.


  1. The 1946 Atomic Energy Act was later augmented by the Atomic Energy Act of 1954 with the goal of allowing for a civilian nuclear industry, which required allowing some Restricted Data to be shared with private companies. ↩︎

  2. The 1979 case of United States v. The Progressive, in which a newspaper intended to reveal the “secret” of the hydrogen bomb, might have given the U.S. Supreme Court an opportunity to rule on whether the “born secret” doctrine violates the First Amendment’s protections on speech, if the government hadn’t dropped the case as moot. ↩︎

  3. An arm of the U.S. Department of Commerce. ↩︎

  4. Hundreds of such orders have been placed on cryptography-related patents over the decades. ↩︎

  5. For instance, the development of AlphaGo — a state-of-the-art AI in 2016 — doesn’t fit cleanly into the modern “pre-training, post-training, inference” paradigm. ↩︎

Source: ifanyonebuildsit.com/treaty/article-viii-restricted-research-ai-algorithms-and-hardware