
A framework for Global Governance of frontier Artificial Intelligence
The development of increasingly capable artificial intelligence is currently characterised by intense competition among technology companies and states. This competition may accelerate innovation, but it also creates a significant governance problem: individual actors have incentives to pursue increasingly capable systems even when the aggregate risks of doing so may exceed the capacity of existing safety and regulatory institutions.
One proposed response is the creation of a globally governed, shared foundation model, referred to here as One AI, that would replace uncontrolled competition between frontier developers with internationally governed AI infrastructure.
The underlying proposition is strategically significant but requires a substantially more developed policy architecture than a vision of international cooperation alone can provide. Three issues are particularly important.
First, international cooperation requires enforceable mechanisms. A global agreement cannot depend exclusively on voluntary compliance where frontier AI has substantial commercial, geopolitical and military value. Governance would therefore require a combination of economic incentives, sanctions, compute controls, semiconductor supply-chain monitoring and verification mechanisms.
Second, the relationship between current AI security failures and future existential risks must be established more rigorously. Present-day failures of containment do not demonstrate that artificial general intelligence will cause catastrophic harm. They do, however, provide empirical evidence about the difficulty of reliably controlling increasingly autonomous systems. A credible policy argument should establish a graduated causal pathway between these present limitations and the greater control challenges posed by substantially more capable systems.
Third, the benefits of open AI research must be reconciled with the risks of unrestricted access to frontier model weights. A fully open-weight frontier model could enable independent scrutiny and innovation, but it could also permit malicious actors to modify, fine-tune and deploy the system outside the reach of international safeguards. A viable One AI framework should therefore distinguish between broad access to AI capabilities and unrestricted possession of the underlying model weights.
The appropriate policy objective is consequently neither unrestricted openness nor complete centralisation. It is a globally governed, broadly accessible and independently scrutinised AI infrastructure with proportionate controls over the most consequential capabilities.
The transition to such a system would be difficult. Its feasibility depends on institutions capable of aligning national incentives, verifying compliance and preventing excessive concentration of power. Nevertheless, if frontier AI develops to the point where its consequences are genuinely systemic, the absence of such institutions may itself constitute an unacceptable governance risk.
1. Introduction: From competition to collective governance
The prevailing model of frontier AI development is competitive.
Private companies invest enormous resources in computing infrastructure, semiconductor access, research talent and model development. Governments increasingly regard advanced AI as strategically important to economic competitiveness, national security and technological sovereignty. The resulting dynamic resembles an arms race in which the principal actors have strong incentives to develop increasingly capable systems before their competitors do.
This dynamic creates a structural problem.
Even if each individual actor is behaving rationally according to its own interests, the aggregate outcome may be undesirable. A company that slows development because of safety concerns risks losing market share. A government that imposes unilateral restrictions risks allowing another country to obtain a strategic advantage. A research organisation that withholds a capability may simply create an incentive for another organisation to develop it instead.
This is a classic collective-action problem.
One response is to establish a common international foundation model and governance framework, a One AI, through which frontier intelligence becomes shared infrastructure rather than a collection of competing proprietary systems.
The attraction of such a model is considerable. A common foundation could reduce duplicated development, establish shared safety standards, enable broad public access and place the most consequential capabilities under international rather than purely corporate or national control.
However, the historical precedents sometimes invoked in support of international technological cooperation – including the internet, Linux and CERN – have important limitations.
The central challenge is that frontier AI is simultaneously commercial infrastructure, strategic technology and potentially autonomous capability.
A credible governance framework must therefore address not only what the desired end state looks like, but how the international system could transition from the present competitive environment to that end state.
Three policy problems are central: enforcement, risk escalation and access to model weights.
2. Enforcement: making international AI cooperation credible
2.1 The limits of voluntary cooperation
International cooperation cannot be assumed simply because cooperation is collectively beneficial.
States have different economic interests, security priorities and technological capabilities. A country may support international AI safety in principle while simultaneously concluding that developing frontier systems independently is necessary for national security.
The same problem exists for corporations.
A company that voluntarily limits the capabilities of its systems may face competitive disadvantages if rivals continue to scale.
Consequently, any transition to One AI requires an institutional mechanism capable of changing the incentives facing states and companies.
The objective should be to establish a system in which:
- participation produces substantial economic and technological benefits;
- non-participation carries meaningful costs;
- compliance can be independently verified; and
- prohibited development is sufficiently difficult to deter clandestine activity.
This suggests a combination of incentives, restrictions and verification rather than reliance on any single policy instrument.
2.2 Incentivising participation
The first component should be positive economic incentives.
Participating states could receive access to shared frontier computing infrastructure, AI-enabled scientific resources, technical expertise and secure AI services. Such benefits could be particularly important for states that lack the capital or semiconductor infrastructure required to develop frontier systems independently.
A global system could also provide access to AI capabilities for civilian applications including scientific research, healthcare, education, industrial optimisation and public administration.
This creates a fundamental bargain:
Participation should provide greater access to beneficial AI capability than most states could obtain through independent development.
For the system to remain politically legitimate, access cannot be restricted exclusively to major powers. Developing states would need meaningful participation and access, otherwise One AI could simply become a mechanism for institutionalising existing technological inequalities.
2.3 Enforcement and deterrence
Positive incentives are unlikely to be sufficient where a state believes that independent frontier AI provides a decisive strategic advantage.
A One AI framework would therefore require coordinated consequences for serious non-compliance.
Potential measures could include:
- restrictions on access to advanced semiconductor technologies;
- controls on specialised AI computing equipment;
- coordinated financial and trade sanctions;
- restrictions on access to internationally governed AI infrastructure;
- denial of participation in shared scientific programmes; and
- restrictions on access to frontier AI services.
The purpose of such measures would not necessarily be to eliminate all unauthorised AI development. That is unlikely to be realistic.
The objective would instead be to increase the cost and difficulty of developing frontier capabilities outside the agreed governance framework to a level at which participation becomes the rational choice for most actors.
3. Compute governance and semiconductor supply chains
3.1 Why physical infrastructure matters
One of the most important characteristics of frontier AI is that, despite being fundamentally digital, it depends upon a highly physical industrial infrastructure.
Large-scale model training requires advanced semiconductors, specialised computing systems, data centres, networking infrastructure and very substantial quantities of electricity.
This creates a potential basis for verification.
Code can be copied rapidly and concealed relatively easily. Large concentrations of frontier-scale compute are substantially more difficult to conceal.
A governance system should therefore pay particular attention to the physical infrastructure underlying advanced AI.
3.2 International compute monitoring
A global AI authority could establish a registration and reporting regime for frontier-scale computing facilities.
Such a system could require participating jurisdictions to report:
- the location and ownership of major frontier-scale compute clusters;
- significant changes in computing capacity;
- major acquisitions of advanced AI accelerators;
- exceptionally large training runs; and
- transfers of relevant hardware across national borders.
The objective would be to establish visibility over the concentration and deployment of computing resources capable of supporting frontier model development.
Such monitoring would need to be carefully designed to protect legitimate commercial information and national security while providing sufficient transparency to establish confidence in compliance.
3.3 Hardware supply-chain audits
The comparison with nuclear non-proliferation is useful at this point, although it should not be interpreted as suggesting that AI governance can simply replicate the nuclear model.
The relevant principle is verification through control of critical physical inputs.
Advanced semiconductor manufacturing depends upon highly specialised equipment and globally distributed supply chains. The ability to produce the most advanced chips is concentrated in a relatively small number of organisations and jurisdictions.
International governance could therefore introduce supply-chain auditing for strategically significant semiconductor manufacturing equipment and advanced computing components.
Such a regime might track:
- production of critical semiconductor-manufacturing equipment;
- transfer of that equipment between jurisdictions;
- deployment at advanced fabrication facilities;
- production of frontier-relevant semiconductors;
- distribution of those components to major computing facilities; and
- the aggregation of those components into frontier-scale clusters.
The purpose would not be to monitor every computer.
It would be to establish whether an actor has accumulated the physical capacity required for frontier-scale training outside the international framework.
This is potentially one of the most important practical elements of a global AI governance regime because it transforms an otherwise abstract question of software control into a question of physical infrastructure that can be monitored, regulated and audited.
4. From present-day security failures to future alignment risks
4.1 Avoiding an unsupported leap
A second weakness that must be addressed concerns the relationship between current AI security incidents and future existential risks.
Present-day sandbox failures, unexpected model behaviour or cyber incidents do not establish that artificial general intelligence will cause human extinction.
A serious policy argument should not claim otherwise.
The stronger argument is that such incidents provide evidence about a narrower but fundamental proposition:
Current AI systems are already demonstrating limitations in predictability, containment and control.
Those limitations become increasingly consequential as systems acquire greater capability and autonomy.
4.2 A graduated risk model
The transition from present-day AI security problems to frontier alignment risk should therefore be presented as a progression rather than a discontinuity.
At relatively low capability levels, an AI system may be capable of generating code, interacting with software or performing limited autonomous tasks.
If such a system unexpectedly bypasses a security restriction, the immediate consequence may be manageable.
However, the same underlying control problem becomes more consequential as the system gains:
- greater reasoning capability;
- longer autonomous operating periods;
- broader access to external systems;
- improved ability to identify vulnerabilities;
- greater ability to modify software; and
- greater ability to pursue complex objectives independently.
The key policy question is therefore not whether a particular present-day incident constitutes an existential threat.
It is whether the methods used to control today’s systems are robust enough to provide confidence that substantially more capable systems can also be controlled.
If they are not, then the appropriate policy response is to improve control mechanisms before capability increases beyond the point at which failures become difficult to contain.
4.3 Security failures as empirical evidence
This reframing provides a stronger connection between cybersecurity and AI alignment.
A sandbox exists precisely because developers are attempting to constrain what an AI system can do.
When the system finds an unexpected route around that constraint, the incident provides information about the limitations of the containment architecture.
That does not establish catastrophic risk.
It does establish that containment is an engineering problem that remains incompletely solved.
As systems become more capable, the margin for error may narrow.
This is why alignment should not be treated exclusively as a future research problem. The ability to reliably constrain increasingly autonomous systems is already an operational requirement for the development and deployment of frontier AI.
The policy implication is significant.
Rather than presenting current incidents as evidence that catastrophe is inevitable, policymakers should treat them as warning indicators about the reliability of existing control mechanisms.
That approach avoids both complacency and exaggerated claims.
5. The Open-Weights paradox
5.1 The case for openness
The argument for open AI is substantial.
Publicly accessible systems can facilitate independent research, security testing and innovation. Open development allows researchers outside the original developer organisation to identify weaknesses and develop alternative applications.
The experience of open-source software demonstrates that distributed scrutiny can be highly effective for conventional software systems.
A One AI system should therefore not become an excuse for eliminating independent research or concentrating all technological authority within a single institution.
However, frontier AI introduces an important distinction.
5.2 Static software versus adaptive models
Traditional software is generally static until a developer modifies it.
A highly capable AI model can be adapted through fine-tuning, additional training, tool integration and other modifications. The model’s underlying capabilities can therefore be repurposed in ways that its original developers did not intend.
This produces an asymmetry in which openness can create both defensive and offensive benefits.
Independent researchers may use access to identify vulnerabilities.
Malicious actors may use the same access to identify vulnerabilities, remove safety mechanisms or adapt the system for harmful purposes.
The risk becomes particularly significant if highly capable models can be operated offline.
Once raw model weights have been distributed, their subsequent use may no longer be observable by the wider research community or the institution responsible for their original release.
This creates a fundamental governance problem.
Transparency is valuable only if the system being made transparent remains within a framework in which misuse can still be detected and constrained.
6. A tiered access model
The appropriate response need not be a choice between unrestricted open weights and completely closed proprietary systems.
A third model is possible: tiered access.
Under this approach, access to AI capabilities would be broad, while access to the most consequential underlying assets would be more restricted.
Tier 1: Public access
The general public would access the frontier model through a governed interface.
This would enable widespread use of the system for education, productivity, scientific discovery, business and other legitimate purposes.
Tier 2: Commercial and research access
Businesses, universities and recognised research organisations would receive expanded access appropriate to their activities.
This would support innovation while maintaining appropriate safeguards.
Tier 3: Independent safety research
Vetted security and AI-safety researchers would receive deeper access to conduct adversarial testing, alignment research and model evaluation.
This is essential because a safety regime cannot credibly claim to be independently scrutinised if only the governing institution can examine its systems.
Tier 4: Controlled access to model weights
Raw model weights would be made available only to accredited institutions operating under stringent security and governance requirements.
These institutions could include designated international research organisations, cybersecurity bodies and approved academic institutions.
Tier 5: International stewardship
The most sensitive frontier models and associated assets would ultimately remain under the custody of the international governance institution.
The governing principle would be:
Open access to beneficial capability; controlled access to the underlying capability multiplier.
This structure preserves many of the benefits of openness without assuming that unrestricted distribution of frontier weights is necessarily compatible with safety.
7. Institutional design and the risk of centralisation
Tiered access introduces its own danger.
A system established to prevent corporate or national concentration of AI power could itself become a new concentration of power.
This is arguably the most important institutional risk facing One AI.
An international body controlling a frontier model could become politically captured, dominated by major powers or insulated from meaningful democratic oversight.
The solution cannot be to assume that the governing institution will behave benevolently.
Its governance therefore needs to incorporate multiple independent sources of oversight.
A credible institutional framework could include:
- representation from a broad range of states;
- independent scientific institutions;
- cybersecurity experts;
- civil-society representatives;
- technical auditing bodies;
- transparent safety evaluations;
- independent review mechanisms; and
- procedures for challenging institutional decisions.
The organisation should also operate under clearly defined limits.
Its authority should derive from an international treaty or equivalent legal framework rather than from the unilateral authority of a small group of states or corporations.
The governance problem is therefore recursive.
Humanity must govern the AI system.
But humanity must also govern the institution responsible for governing the AI system.
8. Policy architecture for One AI
Taken together, these considerations suggest that a One AI framework would require at least five institutional pillars.
1. International Frontier AI Authority (IFAA)
A treaty-based organisation responsible for governance, safety standards, certification and oversight of frontier AI development.
2. Global Compute Registry (GCR)
An internationally coordinated mechanism for identifying and monitoring computing infrastructure capable of supporting frontier-scale training.
3. Semiconductor and Hardware Verification Regime (SHVR)
A supply-chain monitoring framework covering strategically significant semiconductor manufacturing equipment, advanced processors and their deployment.
4. Tiered AI Access Framework (TAAF)
A system separating public and commercial access to AI capabilities from unrestricted possession of frontier model weights.
5. Independent Safety and Audit Network (ISAN)
A distributed ecosystem of accredited researchers and institutions capable of testing the system independently and reporting vulnerabilities without requiring permission from a single central authority.
These mechanisms should operate together rather than independently.
The compute registry establishes visibility.
Hardware controls provide leverage.
International governance establishes common rules.
Tiered access limits the uncontrolled distribution of the most consequential capabilities.
Independent auditing prevents the governing institution from becoming the sole authority over the technology.
9. Implementation challenges
None of these mechanisms eliminates the fundamental geopolitical difficulties.
Several challenges would remain.
Sovereignty
Major powers may resist international restrictions on technologies considered essential to national security.
Verification
A sophisticated actor could attempt to conceal compute capacity, training activity or model development.
Technological change
Governance systems designed around today’s hardware could become obsolete as architectures and computing methods change.
Institutional capture
A powerful international AI authority could itself become dominated by a small number of states or organisations.
Inequality
If access to frontier AI is concentrated among wealthy states, the governance system could reinforce rather than reduce global technological inequality.
Enforcement asymmetry
Sanctions and export controls are effective only to the extent that participating jurisdictions control sufficiently important components of the relevant supply chain.
These limitations should not be treated as reasons to abandon the proposal.
They demonstrate why governance must be treated as an adaptive institutional system rather than a one-time treaty.
10. Conclusion: Designing the transition, not just the Destination
The central argument for One AI is ultimately an argument about institutional capacity.
The present AI ecosystem places enormous incentives on companies and governments to pursue greater capability. Existing national and corporate governance structures were not designed to manage a technology whose development could simultaneously affect economic competitiveness, national security, cybersecurity and potentially the long-term trajectory of civilisation.
Replacing that system with globally governed AI infrastructure could offer an alternative.
But cooperation cannot be assumed.
The transition would require economic incentives that make participation attractive, enforcement mechanisms that make defection costly, and verification mechanisms capable of monitoring the physical infrastructure underpinning frontier AI.
The argument about existential risk must likewise be constructed carefully.
Today’s AI security failures do not prove that future systems will cause catastrophe. They do, however, provide empirical evidence that reliable control of increasingly autonomous systems remains an unresolved engineering problem. As capability and autonomy increase, that unresolved problem becomes progressively more consequential.
Finally, the benefits of open AI must be distinguished from unrestricted distribution of frontier model weights.
A globally beneficial AI system should be broadly accessible and independently scrutinised. But the most capable underlying models may require controlled stewardship precisely because they can be modified and deployed outside the visibility of the institutions responsible for their safety.
The resulting model is neither a corporate monopoly nor an unrestricted open-source utopia.
It is a globally governed public infrastructure with differentiated access, independent oversight and enforceable controls over frontier capabilities.
That approach is undoubtedly difficult.
It may even prove politically impossible under current conditions.
But that is not an argument for ignoring the problem.
If increasingly capable AI systems become foundational infrastructure for the global economy, and potentially for national security and scientific development, then governance cannot be an afterthought. The international community must develop mechanisms for verification, accountability and collective control before the technology becomes too strategically valuable for states and companies to accept meaningful constraints.
The essential policy shift is therefore from asking whether humanity could create One AI to asking what institutions would be required to make such a system safe, legitimate and resilient.
The first question is visionary.
The second is governance.
And if the stakes are as high as proponents of advanced AI increasingly argue, governance is the question that matters most.
First dropped: | Last modified: September 15, 2026