You know how systems behave. This primer is the institutional half of the strategic foundations: how promises get hardened into things rivals can believe, what answers a violation when there's no court, and who the actual players are. No history of Westphalia, no UN org charts. Eight short sections and a self-check; anything with a + opens into detail. (Part one — the game theory: dilemmas, credibility, inspection — is the Strategic Foundations map; take it first.)
One fact generates most of international relations. Internalize it and the rest of this primer — and this course — follows.
Inside a country, agreements work because an enforcement layer sits above the parties. Sign a contract, break it, get sued: courts and police exist, and neither party runs them. Between countries, no such layer exists. There is no world government, no global police, no court with compulsory jurisdiction over unwilling great powers. IR calls this condition anarchy — not chaos, just the absence of a ruler.
The international system is a distributed network of self-interested agents with no trusted third party and no admin. Nobody has root. Agreements between states are protocols that any node can silently stop following. There is no runtime that executes a treaty and no exception handler when one party defects — only whatever detection and response the other parties built for themselves.
Part one showed the blackboard version of life under this constraint — dilemmas, repetition, credibility, inspection. This primer builds the institutional half on top of it: how promises get hardened (section 3), what answers violations (section 4), and who the players actually are.
IR routinely says things like "China wants X" or "the US seeks Y." Learn what that abstraction hides, then replace it with a better question.
Treating a state as a single decision-maker with coherent goals — the unitary actor model — is a lossy abstraction, like calling a distributed system "the server." Real states are bureaucracies, factions, leaders, and firms pulling in different directions. The abstraction is still useful; just know it leaks — Module 1 is largely about where, and its opening primer, Who Actually Says Yes?, is the toolkit for opening the box. (Labs and states, for instance, are not the same actor and do not want the same things.)
"What does an actor want?" is nearly useless, because the answers are universal: every state wants security, prosperity, status, and a lead in strategic technology. Every lab wants to build powerful AI safely. Stated preferences are free to produce and therefore carry almost no information.
The analytically useful question is about cost tolerance: what is the actor willing to pay, risk, forgo, or endure to achieve X — and to avoid not-X? Willingness is expensive to fake, which is why costly actions are data and statements are, mostly, noise. Engineers know this distinction as revealed preference; IR knows it as costly signaling versus cheap talk — part one's vocabulary, now applied in the wild.
Every actor analysis in this course runs on this question. Not "does Beijing want to avoid an ASI catastrophe?" (yes, presumably — so does everyone). Instead: is it willing to accept foreign inspectors inside military-adjacent data centers? To cap the compute of its national champions? To forgo a covert program even when it suspects the US is running one? Those willingnesses — not the wants — determine what a treaty can be.
For each item, ask: how expensive would this be to do insincerely? Click your call.
Verification is the machinery that forces willingness into the open. A state that merely wants a pause and a state willing to pay for one answer a demand for intrusive monitoring very differently. Every mechanism you'll study in Modules 2–4 is, at bottom, a device for making cheap talk expensive.
Part one left you on the second rung of a ladder: sunk costs and tied hands — promises you make expensive for yourself. The next two rungs aren't game theory. They're institutions and silicon.
The ladder orders commitment devices by how much future choice survives. Climb it left to right — click any rung.
Credibility isn't a device you bolt on; it's what the devices produce, and you can score it. Three columns for any commitment, on any rung: can the other side see it was made — and see it still holds? What does breaking it cost, and who collects? Could it be quietly undone? The columns multiply rather than add — a zero anywhere zeroes the product.
| Commitment | Observable | Costly to break | Hard to reverse | Verdict |
|---|---|---|---|---|
| Summit pledge to “never weaponize AI” | no | no | no | Cheap talk |
| Ratified treaty + implementing law with penalties | yes | yes | partly | Real signal — tied hands |
| Secret hardware limit the state could remove | no | unclear | no | Worse than nothing: false assurance |
| Monitored, attested on-chip limits | yes | yes | yes | The design goal |
Treaty design sets the “costly” and “hard to reverse” columns. Verification's entire job is the observable column — and a commitment nobody can observe scores zero no matter how sincere it is. Run every mechanism you meet in this track through the three columns first.
A violation just happened. There is no court. What actually answers it — and what has to be true before anything can?
Guzman's inventory of what enforces international law without an enforcer — the three R's. Click each.
All three run on the shadow of the future — part one's repeated game, wearing institutional clothes. And all three share one dependency, which the pipeline below makes explicit.
Enforcement is a pipeline with three stages, each an independent failure point. The three R's all live in stage three — which puts them downstream of the first two. An undetected violation moves nothing; an unattributed one punishes no one. Click each stage.
Verification's deliverable is a proven, attributed violation. Then it hands off: whether anyone acts is a political choice no sensor can make. Two cases, same stage-one success, opposite endings:
| Case | Stages 1–2 | Stage 3 | Outcome |
|---|---|---|---|
| Krasnoyarsk radar (ABM Treaty) | worked US satellites caught the siting violation | worked years of public pressure, reputation and linkage | USSR admitted the violation and dismantled the site — the pipeline ran end to end |
| 9M729 missile (INF Treaty) | worked called publicly for half a decade | no lever no response short of leaving the treaty was ever found | The regime died in 2019 — the epitaph is not “verification failed” |
What an unanswered violation actually costs: it reprices everyone's promises, not just the violator's — every player updates on what the system tolerates. Two accelerants: ambiguity (a violation nobody can cleanly prove is a violation nobody can punish — why part one's bright lines are load-bearing) and false alarms (each one spends the forgiveness a regime needs to survive noise, and discredits the next true alarm). Regimes rarely die of one spectacular breach. They decay — through small, deniable, unanswered ones.
Self-binding (part one, and section 3) works because this compliance system exists: sunk costs and delegations mean nothing unless someone would notice reneging and respond. The compliance system works because its threats — reputation, reciprocity, retaliation — are themselves credible commitments. Neither half stands alone.
And both halves rest on the same stone: violations getting detected and attributed. Verification is that stone — the load-bearing wall of the whole structure. Every module after this primer is about making detection and attribution actually work.
A treaty is code with no runtime. Nothing executes it. Knowing its lifecycle tells you where willingness gets tested — and where the escape hatches are. Click any stage for detail.
Read the lifecycle as an escalating series of costly signals. Signature is cheap talk with a pen. Ratification spends real domestic capital — the United States signed the Comprehensive Nuclear-Test-Ban Treaty in 1996 and has never ratified it, which tells you exactly what the willingness question would predict it tells you. Sustained compliance under monitoring is the most expensive signal of all, which is why it's the most informative.
| Term | Meaning |
|---|---|
| Regime | The whole bundle around an issue — treaties, institutions, norms, monitoring practice. "The nonproliferation regime" ≫ the NPT text alone. |
| Safeguards | Technical + legal measures verifying that declared materials/facilities aren't diverted to prohibited use. The IAEA's core function; the closest existing analog to compute verification. |
| National technical means (NTM) | A state's own unilateral monitoring: satellites, signals intelligence, cyber. Arms-control treaties explicitly protect NTM — parties agree not to interfere with each other's spying, because it stabilizes the deal. |
| Confidence-building measures (CBMs) | Low-stakes transparency steps — notifications, hotlines, data exchanges, observer visits — that build the track record needed before states accept intrusive verification. |
| Bilateral / multilateral | Two parties vs. many. Bilateral deals (US–Soviet arms control) verify more deeply; multilateral ones (NPT) cover more of the world. An ASI agreement needs both properties, which is part of why it's hard. |
| Compliance / defection / breakout | Keeping the deal; secretly breaking it; openly racing out of it faster than others can respond. Verification design cares most about the time between defection and detection vs. the time defection needs to become irreversible. |
| Securitization | Reframing an issue as an existential threat, which suspends normal cost-benefit politics and unlocks extraordinary measures. Module 0 argues ASI qualifies. |
IR "theories" aren't ideologies to pick between. Treat them as modeling assumptions — different priors about what drives willingness. Click each lens; each makes different predictions, and each is right about something.
Scenario: State A proposes an intrusive international compute-monitoring regime. State B, its chief rival, agrees to join. Toggle the lens:
Suspicion. B joined because it calculated the regime favors it: perhaps its covert path is harder to detect, or the freeze locks in its current advantage, or membership buys time. Watch what B does, not what it signs — the treaty will hold exactly as long as B's expected gain from compliance exceeds its expected gain from undetected defection. Failure mode this lens catches: a regime that's really a cover for the leader to consolidate its lead.
Progress. Both states feared an unconstrained race more than they valued winning one; the regime lets each verify the other's restraint, converting an unstable arms race into a stable, monitored equilibrium. Expect CBMs first, deeper inspections later, as compliance data accumulates. Failure mode this lens catches: under-investing in the institution — a monitoring body too weak or slow to make defection visible in time.
Norm formation. The regime's deepest effect isn't detection — it's making unrestricted ASI development deviant. Once restraint becomes part of what responsible states do, violation costs identity and standing, not just sanctions. Failure mode this lens catches: a technically sound regime that never builds normative buy-in, so states comply with the letter while racing in spirit.
| What is verification for? | Why regimes fail | |
|---|---|---|
| Realist | Protecting yourself while the deal lasts — early warning of a rival's breakout. | Power shifted; the deal stopped reflecting reality. |
| Institutionalist | Making cooperation rational — solving the information problem that causes defection. | Monitoring was too weak, slow, or underfunded to sustain confidence. |
| Constructivist | Ritualizing the norm — inspections as repeated public performance of restraint. | The norm never internalized; compliance stayed purely transactional. |
These are working tools, not trivia: Module 1's actor briefs run on them. A good verification designer is a realist about evasion, an institutionalist about machinery, and a constructivist about the long game. Now put names on the players.
Everything so far said "State A" and "State B." In the AI race the names are known: this is primarily a two-player game between the United States and China, with the EU as a chokepoint-holder and rule-writer rather than a racer. Module 1 dissects these actors properly; here is the minimum background a technical person needs.
The US is the incumbent power; China is the rising one — the classic power-transition setup realism worries about. Since roughly 2018 the relationship has shifted from economic engagement to open strategic competition, and since October 2022 the US has treated frontier compute itself as a strategic controlled substance, using export controls to slow China's AI buildout. China answers with a whole-nation push for self-sufficiency plus counter-leverage of its own. Both sides say they want AI safety; apply the willingness question to everything below.
The AI stack runs from rocks to deployed models. Leverage is unevenly distributed along it — and almost every US-China move in the AI race is an attempt to exploit or escape a chokepoint. Click each stage.
Wrong question as asked — decompose it by layer, then notice the time dynamics.
| Layer | Ahead today | Why it can shift |
|---|---|---|
| Frontier model quality | US — but measured in months, not years | Chinese open-weight fast-followers (the DeepSeek shock, Jan 2025) compress the gap with algorithmic efficiency. |
| Installed AI compute | US, by a wide margin | US grid and permitting are the binding constraint; China adds electricity capacity several times faster. |
| Hardware chokepoints | US + allies (design, EDA, litho, fab) | Every tightening of export controls raises China's incentive to indigenize — leverage is a depreciating asset. |
| Energy & buildout capacity | China | Structural: state-directed grid expansion vs. interconnection queues. Hard for the US to reverse quickly. |
| Global diffusion | Contested — China lean in the Global South | US exports APIs and cloud; China exports open weights and cheap infrastructure. Whoever's stack the world runs on gains standard-setting power. |
| Rules & standards | EU writes them (for its market) | The Brussels effect shapes compliance defaults globally, but the EU regulates a race it isn't running. |
The leverage map is the treaty map. The US wants any deal to lock in its lead; China won't ratify formalized second place — that's the realist relative-gains problem with names attached. But the chokepoints also mean the machinery of compute verification (chip tracking, know-your-customer rules, facility monitoring) is already being built for competitive reasons — export-control enforcement and treaty verification need much of the same infrastructure. And because chokepoint leverage decays as China indigenizes, the window in which a verification-for-access bargain is attractive to both sides opens and closes with the hardware gap. Timing is not a detail; it's the deal.
The closest thing history offers to a template for an anti-ASI regime. One page, read through the tools you just acquired.
The Nuclear Non-Proliferation Treaty (1968) is a grand bargain: non-nuclear states forgo weapons; the five recognized nuclear states commit to pursue disarmament and share peaceful nuclear technology. Verification is delegated to the IAEA, whose safeguards inspectors audit declared nuclear material worldwide. After the 1991 Gulf War revealed Iraq had run a covert weapons program while under routine safeguards, the regime shipped a patch — the Additional Protocol, granting inspectors access beyond declared sites. North Korea joined, cheated, and in 2003 used the withdrawal clause and tested a weapon three years later. Meanwhile, dozens of states with the technical ability to build weapons — Japan, Germany, South Korea, Brazil — never did.
Read the same regime through each lens — click to expand:
The NPT never changed what states wanted — security, status, leverage. It changed the price of the paths. For most states, weapons became expensive (inspections, sanctions, stigma) and restraint became cheap and safe (verified neighbors, shared technology). The regime failed precisely where a state's willingness to pay was effectively unbounded. No verification regime stops an actor who will pay any price — the design goal is to make sure you see them paying it in time to respond.
The question this track spends the remaining modules answering: nuclear verification had fissile material — physical, scarce, detectable. What is the fissile material of AI, and what does an IAEA for compute look like?
Ten questions. If these feel easy, you're ready for Module 0.
Carry three habits into Module 0: read every statement of preference by asking what the actor is willing to do about it; run every claimed commitment through observable × costly × hard to reverse; and read every proposed agreement by asking how a violation would be detected, attributed, and answered in time. Everything else in this track is elaboration — and Module 1 opens the actors themselves, starting with unit 1.0's own primer.
If no one above you will protect you, you must provide for your own security. Every state's baseline strategy is self-help, which is why "just trust each other" fails structurally, not because leaders are unusually dishonest.
Design consequence: any agreement between states must be self-enforcing — each party has to prefer staying in, given only what it can observe and do for itself. Verification is what makes "given what it can observe" a meaningful phrase.
One state's defensive measure is indistinguishable, from outside, from preparation for offense. So defensive moves trigger counter-moves, and two states that each only want safety can rationally arms-race. This is the engine behind the ASI race dynamic in Module 0.
The AI version: a national compute buildup "for economic competitiveness" and one "for a military breakout" look identical from a satellite. Ambiguity is the fuel; transparency mechanisms exist to drain it. When you meet the US–China compute race in the Actors section, you're watching a security dilemma run in real time.
Most treaties are honored most of the time — states keep agreements when keeping them is cheaper than the consequences of breaking them. The interesting questions are always at the margin: which agreements hold, when do they break, and what makes defection visible early enough to matter? That last question is this course.
Sunk costs: pay now — mobilize, build, dismantle. The spending proves you're serious, but nothing stops tomorrow's reversal. Tied hands: arrange a price for your own future retreat — public pledges your own audience will punish you for breaking. On both rungs the committed party still holds the pen; the devices just make using it expensive.
Part one covers these properly (Fearon, Schelling, and the burned bridge). One carry-over to hold onto: what made the burned bridge persuasive is that the enemy could see it and knew it couldn't be quietly rebuilt — that's the rubric below, in embryo.
The classic demonstration is monetary, not military. Governments couldn't credibly promise low inflation — everyone knew they'd want to break the promise later — so they delegated the decision to independent central banks they deliberately couldn't overrule day to day. Kydland & Prescott named the disease (time inconsistency); delegation is its institutional cure. International versions: standing treaty bodies, compulsory arbitration, sanctions that trigger automatically rather than by fresh vote.
You can still renege — but reneging now means visibly seizing the pen back: overriding or exiting your own institution, in daylight, on everyone's cameras.
The AI translation: an international AI regulator is a delegation device — rivals who can't trust each other's promises can sometimes trust a body neither one fully controls.
→ Kydland & Prescott 1977 · dynamic inconsistency · IAEA safeguards — a delegation device you can visit
The top rung: nobody decides — the mechanism does. Schelling's limit case was the doomsday machine, a deterrent wired to fire on its own precisely so no future leader could lose their nerve (and which fails only if kept secret). The modern, less apocalyptic descendant is hardware-enabled governance: compute limits, licensing, and attestation enforced by the chip itself, so compliance stops depending on anyone's continuing goodwill — or on winning next year's domestic argument.
The price is the point: a commitment you can't escape when breaking it would be wrong is the same commitment you can't escape when breaking it would be right. And it's the only rung that binds a committed party who later wants out — a future government, or a future model. What happens when that last clause stops being hypothetical is the scheming-and-evasion module's problem.
→ Aarne, Fist & Withers 2024, “Secure, Governable Chips” · Sastry et al. 2024, “Computing Power and the Governance of AI”
Bodies like the IAEA enforce nothing — no root authority, remember. What they do is reduce information asymmetry: standardize what counts as compliance, pool monitoring data, provide neutral inspectors whose findings all sides accept. In systems terms, they're the observability layer, not the runtime.
But the “instrument” framing leaks. A standing inspectorate grows a budget, staff, career incentives, and an institutional reputation — it wants to be trusted, funded, and renewed. Usually those interests point the same way as the mission; the actor-analysis habit is to check, not assume. Module 1 picks this up properly.
Other states are watching. A state caught cheating on one agreement pays a premium on every subsequent negotiation, with everyone — reputation is a shared cache of past behavior, priced into every future deal.
Note the dependency: reputation only updates on caught. An undetected violation is reputationally free — which is precisely what makes weak verification corrosive.
→ Guzman 2002, “A Compliance-Based Theory of International Law” — the intro carries the argument
Compliance can be made conditional — I comply while you do — so the cost of cheating is losing the arrangement itself. This is part one's repeated game running at treaty scale: the shadow of the future, formalized.
The catch for AI: reciprocity only disciplines behavior if the game continues. A successful ASI breakout is a move that ends the repeated game — which is why detection speed has to do more work here than in trade or even nuclear arms control.
Targeted punishment — and it doesn't have to stay in-domain. Issues can be linked: cheat on arms control, lose trade access. Linkage lets states borrow costs from any domain where they hold leverage.
This is why the supply-chain map in the Actors section matters so much: export controls, market access, and materials leverage are exactly the cross-domain costs an AI agreement could borrow for enforcement.
Something happened: a training run over the threshold, a diverted shipment, a facility that doesn't match its declaration. Sensors, declarations, on-site inspections, supply-chain records, whistleblowers.
This stage fails quietly — you don't see what you don't detect, which is why a regime that reports zero violations for a decade deserves suspicion, not congratulations (part one's inspection game, deep end).
Someone specific did it — whose training run, whose compute, whose warhead. The nuclear era's hard stage was detection; attribution came nearly free, because missile fields and test sites have return addresses. AI inverts that: a training run has no seismic signature, and compute can be rented, resold, and rerouted. Attribution is AI's hardest stage.
One seam to respect: attribution answers “whose compute did it.” Whether the state chose it — deliberate cheating versus a government that couldn't deliver its own players' compliance — is a different question, and it belongs to Module 1.
→ Shavit 2023, “What does it take to catch a Chinchilla?” · nuclear forensics — attribution as a discipline
A lever actually gets pulled: reciprocal suspension, sanctions, linkage costs, reputational pricing. All three R's live here — which means all of them are downstream of stages one and two. Blind the sensor and every lever goes limp at once.
And this stage fails politically, not technically: the INF case below is a proven, attributed violation that no one would act on. Verification can put the decision on someone's desk; it cannot make the decision.
Parties draft text; scope, definitions, and thresholds are fought over word by word. Cheap to participate in — states negotiate things they never intend to join — but this is where the technical substance gets decided.
For an AI treaty, negotiation is where "frontier model" gets an operational definition and where the compute threshold gets a number. Engineers who aren't in the room at this stage inherit whatever the lawyers guessed.
The executive signs. It signals intent and creates a weak obligation not to defeat the treaty's object and purpose — but binds almost nothing. Signature is cheap talk with a pen.
The domestic legislature approves and implementing law follows. This is where treaties die — it spends real political capital and creates internal enforcement machinery that is expensive to quietly reverse. Who exactly must say yes at home, and why a narrow home board is bargaining leverage, gets a full treatment in unit 1.0's primer (Who actually says yes?).
US-specific note that matters for AI: Senate ratification needs a two-thirds vote, which modern polarization makes nearly unreachable — so expect any US–China AI arrangement to be shaped as an executive agreement or political commitment rather than a formal treaty, with all the durability questions that raises.
Enough parties ratify — a negotiated threshold — and obligations activate. Threshold design is strategic: set it too high and the treaty idles forever (the CTBT has been signed since 1996 and is still not in force because specific named states must ratify); too low and it binds a club too small to matter.
Ongoing implementation, reporting, inspections. The long game — and where verification lives. Sustained compliance under monitoring is the most expensive signal a state can send, which is why it's the most informative.
Almost everything in Modules 2–4 of this track is about engineering this stage for compute: what to monitor, how often, with what access, and how fast anomalies surface.
Most treaties include a legal exit with notice — NPT Article X requires 90 days. North Korea used it in 2003 and tested a weapon three years later.
Design implication: a treaty's real strength is bounded by what the world can do within the notice period. For ASI, ask: what does "90 days" buy you against an actor who withdrew because it was already close to breakout? Withdrawal clauses are the legal wrapper around the breakout-time problem.
Definitions of prohibited activity, thresholds (the measurable trigger — for us, compute), covered entities, obligations, inspection and reporting rights, duration, amendment procedures, withdrawal clauses, and often reservations — unilateral opt-outs from specific provisions a state files on joining.
How intelligence agencies will actually monitor (states never disclose sources and methods), what specifically happens on violation (often left vague to preserve flexibility), and side understandings. Treaties are the explicit layer of a mostly implicit system — a theme Module 0.2.4 develops.
Hard law is a ratified treaty: legally binding, costly to exit. Soft law is declarations, codes of conduct, summit communiqués: fast to produce, cheap to abandon. Soft law isn't useless — it builds vocabulary and focal points — but never mistake a declaration for a commitment. Apply the willingness test.
Nearly everything that exists in AI governance today — summit declarations, voluntary commitments, codes of practice — is soft law. That's not a failure; it's the normal first stage of a regime. The question is whether the hard layer arrives before it's needed.
Treaties get extended by attached protocols — the IAEA's Additional Protocol (1997) massively expanded inspection rights after Iraq exposed the old system's blind spots. Regimes are versioned, and versions ship after failures. Expect the same for AI — and note the uncomfortable corollary: the first version of an AI verification regime will have blind spots, and the patch cycle had better be faster than the capability cycle.
Anarchy dominates everything. States care about relative gains — not "do I benefit?" but "do I benefit more than my rival?" — because today's partner is tomorrow's threat. Treaties are epiphenomenal: they hold when they mirror the balance of power and shatter when they don't.
Predicts: states will pay almost anything to avoid falling behind in strategic tech, and will cheat on any deal that freezes them in second place.
States are self-interested, sure — but cooperation failures are mostly information failures: fear of being cheated, not desire to cheat. Institutions fix this by monitoring, standardizing, and lengthening the shadow of the future. Absolute gains can trump relative ones when defection is detectable.
Predicts: states will pay for verification machinery because it's cheaper than an unconstrained race; regimes deepen over time as trust compounds.
Interests aren't fixed inputs — they're constructed by identity and shared norms. Nuclear weapons haven't been used since 1945 not only from deterrence math but because a taboo formed: use became unthinkable for a certain kind of state. Stigma is a real cost.
Predicts: states will pay to avoid pariah status; a strong norm against ASI development would do enforcement work no inspector can.
China dominates the unglamorous bottom of the stack: roughly 60% of rare-earth mining and about 90% of refining, plus commanding positions in gallium and germanium. Since 2023 it has turned this into policy — export controls on gallium/germanium, then rare-earth licensing regimes — explicitly mirroring US chip controls.
Nuance: leading-edge chips themselves need modest amounts of this stuff. The leverage is broader — magnets, optics, defense systems, the industrial base around the AI buildout — and it works as cross-domain linkage: pain China can impose in response to compute controls. The US and allies are rebuilding refining capacity, but that's a years-long project.
The blueprints layer is overwhelmingly American: NVIDIA holds most of the AI-accelerator market, with AMD, Google (TPUs), and Amazon designing the rest of the West's serious silicon. Deeper still, the electronic design automation (EDA) software every chip designer needs comes from essentially three firms — Synopsys, Cadence (both US), and Siemens EDA — a chokepoint so narrow it's been used as an export-control valve.
China's answer: Huawei's HiSilicon designs credible accelerators (the Ascend line). Design talent is not China's constraint — fabricating those designs at the leading edge is (see Stage 4).
The single tightest bottleneck in the entire stack: ASML (Netherlands) is the only company on earth that builds EUV lithography machines, required for the most advanced chips. No EUV tool has ever been exported to China, and since 2023 the Netherlands — under heavy US pressure and with its own decisions — restricts advanced DUV immersion tools too. US firms (Applied Materials, Lam Research, KLA) and Japan (Tokyo Electron) control most of the rest of the toolchain.
This is the EU's realest form of power in the AI race, and it's why "US export controls" are really alliance export controls — Washington's leverage runs through Veldhoven and Tokyo. China's domestic tool effort (SMEE et al.) is the long pole in its self-sufficiency tent: probably a decade behind at the leading edge.
TSMC fabricates on the order of 90% of the world's leading-edge logic chips — including essentially every NVIDIA accelerator — on an island Beijing claims and Washington ambiguously defends. Samsung (Korea) is the only other leading-edge player; Intel is trying to re-enter with CHIPS Act support; new TSMC fabs in Arizona shave the concentration but lag the frontier in Taiwan.
China's SMIC produces 7nm-class chips without EUV using multi-patterning — genuinely impressive, expensive, yield-constrained, and a sign that export controls slow rather than stop. The strategic upshot: the AI supply chain's most critical node sits on the world's most dangerous flashpoint. See the Taiwan tile below — this single fact couples the AI race to war risk.
AI accelerators are bandwidth-hungry: high-bandwidth memory (HBM) comes from SK Hynix (leader), Samsung, and Micron — Korea and the US. And stitching HBM to GPU dies requires advanced packaging (TSMC's CoWoS), which has repeatedly been the actual constraint on how many accelerators the world can produce per quarter.
China's CXMT is pushing into HBM from behind, and packaging plays to China's strength in mature-node, high-volume manufacturing. Watch this layer: it's less famous than lithography but has been the binding constraint more often.
Today the US holds by far the largest stock of frontier AI compute, fed by hundreds of billions per year in hyperscaler capex. But the binding constraint on the US buildout is electricity — interconnection queues, permitting, transmission. China adds grid capacity at a pace the US hasn't matched in decades and runs a state-directed datacenter program on top of it.
China's mirror-image constraint is chips per watt: abundant power feeding scarcer, less efficient accelerators (Ascend vs. NVIDIA). The race in one line: the US has the chips and not the power; China has the power and not the chips. Each side's treaty calculus depends on which constraint it expects to solve first.
The frontier itself is American: OpenAI, Anthropic, and Google DeepMind have set the pace since 2022. But the gap to Chinese labs — DeepSeek, Alibaba's Qwen, Moonshot, and others — is now measured in months, not years. The DeepSeek moment (January 2025) was the load-bearing proof: a Chinese lab producing a near-frontier reasoning model at a fraction of the assumed compute cost, despite export controls.
Strategic reading: compute controls raise the cost of the frontier but don't fence off the territory — algorithmic efficiency leaks around hardware chokepoints. For verification design this is a crucial humility: a compute-only regime watches the biggest driver of capability, not the only one.
Whose AI does the rest of the world actually run? The US exports the top of the market: proprietary APIs, hyperscaler cloud, enterprise deals — but export controls deliberately shrink where its best hardware can go. China exports the bottom-up path: open-weight models anyone can download and fine-tune, plus the Huawei-style bundle of cheap infrastructure — a strategy with a proven track record from telecoms.
The EU shapes this layer differently: it can't supply the models but regulates access to 450 million rich-world consumers, so its rules (the AI Act) become global compliance defaults — the Brussels effect. Why the layer matters for this course: whichever stack diffuses becomes the installed base any treaty must monitor, and the supplier gains standard-setting power over what "compliant AI" even means.
Position: leads frontier models and installed compute; controls the hardware chokepoints, but indirectly — through Dutch, Japanese, Taiwanese, and Korean firms it must keep aligned.
Strategy: run faster (massive private capex, CHIPS Act) while slowing the rival — the October 2022 export controls and their successive expansions. The stated doctrine began as "small yard, high fence"; the yard has grown every year since.
Structure quirk that matters: the US frontier is privately owned. Washington doesn't control OpenAI, Anthropic, or Google the way Beijing can direct its champions — the unitary-actor abstraction leaks hardest here (Module 1 territory).
Willingness profile: demonstrably willing to pay large economic costs to keep a compute lead. Historically unwilling to ratify treaties (CTBT, signed 1996, never ratified) — so expect US commitments shaped as executive agreements, with durability across administrations as the open question. One more tell: by building export-control enforcement (chip tracking, end-use checks), the US is already constructing half the machinery a verification regime would need — for competitive reasons.
Position: behind at the leading edge of chips (no EUV, constrained fabs) but ahead on energy buildout, manufacturing scale, materials, and increasingly competitive at the model layer via efficiency and open weights.
Strategy: whole-nation self-sufficiency (the "Big Fund," SMIC, Huawei's Ascend stack) to escape the chokepoints; fast-follow plus open-weight diffusion to win the installed base abroad; counter-leverage (rare earths) to raise the price of US pressure. Since 2018, Beijing has repeatedly accepted short-term economic pain for long-term autonomy — that is a willingness signal, and you should read it as one.
What Beijing actually optimizes for: regime security first. This cuts both ways: it fuels the race (falling behind the US is a security threat) but also creates a real, narrow basis for restraint — an uncontrolled ASI is a threat to Party control too, and Chinese officials have said versions of this out loud.
Verification-relevant frictions: civil-military fusion blurs the declared/covert boundary that regimes like the IAEA's rely on; sovereignty sensitivity makes intrusive inspection a hard sell. But the record isn't empty — China hosts international monitoring stations under the CTBT and participates in verification machinery when the deal is symmetric. Symmetry is the price of admission.
The EU is not a frontier racer — Mistral and a handful of others are respectable, not pace-setting. Its power in this game is of three different kinds:
Others worth naming: the UK (AI Security Institute, convener of the summit series begun at Bletchley 2023 — the first genuinely international AI-safety track), Japan and Korea (toolchain and memory), Taiwan (the fab), and the Gulf states (capital plus datacenter ambitions, courted by both sides). The EU's structural risk: rule-taker squeeze — regulating a race run by two powers that can, where it matters, ignore it.
The arc to internalize: engagement → competition → managed rivalry(?) — and the entire verification agenda is a bet on what goes in the parenthesis.
Beijing regards Taiwan as sovereign Chinese territory and has never renounced force; Washington maintains "strategic ambiguity" about defending it; and TSMC fabs ~90% of the world's leading-edge chips there. The AI supply chain's most critical node sits directly on the most plausible great-power flashpoint.
Three consequences for this course. First, escalation coupling: a Taiwan crisis is instantly a global compute crisis, which disciplines both sides — the "silicon shield" argument — but also gives each an incentive to reduce dependence, and every fab built elsewhere thins the shield. Second, any US–China AI agreement implicitly prices Taiwan risk: a regime that collapses on day one of a blockade wasn't a regime. Third, breakout math: if a war took TSMC offline, the existing stock of accelerators — who holds them and how visible they are — becomes the whole game overnight. Compute accounting isn't an accounting exercise.
By the 1980s, the US and USSR had decades of arms-control muscle memory: a hotline (installed 1963, after Cuba), SALT/START negotiating cadres, agreed counting rules, and eventually thousands of on-site inspections under INF and START. Adversaries, but adversaries with protocols.
US–China have almost none of this. Military-to-military channels are thin and get suspended in every crisis; there is no arms-control treaty between them at all (China declined to join US–Russia strategic frameworks, noting its far smaller arsenal); the first intergovernmental AI dialogue met only in 2024 and produced little beyond an in-principle understanding that humans, not AI, should control nuclear launch decisions.
Implication for the track: the CBM stage — hotlines, incident notifications, data exchanges, observer visits — isn't a warm-up you can skip. It's where the muscle memory gets built, and for AI it has to be built from scratch, fast, between rivals with very little practice trusting each other's paperwork.
The historical pattern: rivals sign verified agreements at maximum hostility, not after it — provided one condition holds. The Limited Test Ban Treaty came ten months after the Cuban Missile Crisis; the hotline, the same year; INF inspections happened between powers pointing thousands of warheads at each other. Fear, not friendship, is the input. The condition is that both sides fear the uncontrolled outcome more than they fear the deal — and that verification exists to make the deal survivable for the suspicious.
The AI translation: both Washington and Beijing have reasons to fear an uncontrolled race — loss-of-control risk, proliferation to non-state actors, and for Beijing specifically, an ASI that threatens Party control. Neither will trust; that was never the requirement. The requirement is machinery that lets each check. Which is why the remaining modules are about the machinery.
The NPT codified the existing power distribution — the five who had weapons kept them. It held where great powers wanted it to hold and failed where a determined state (DPRK) valued the bomb above every cost the system could impose. Safeguards exist because no one trusted anyone: verification is institutionalized suspicion, and that's a compliment.
Fifty-plus years, 190 parties, and far fewer nuclear states than 1960s forecasts predicted — because the IAEA made restraint observable. Neighbors could forgo weapons without fearing each other's secret programs. And the Iraq failure produced a stronger protocol: institutions learn. The regime is imperfect and indispensable at once.
The treaty's quiet triumph is that acquiring nuclear weapons became deviant — states that could easily build them don't, partly because "nuclear-armed" is no longer an identity most states want. The taboo does enforcement work no inspector performs. Question for this course: can ASI development be stigmatized the same way, and how fast?