Compute Allocation Is Governance
The strongest shift in AI “governance” since 2025 isn’t a principle. It’s a blunt material fact: the people who control the silicon, the power, and the hosting decide who gets to build frontier AI.
Everything else, ethics frameworks, safety boards, policy papers, is noise management for the people who already won the allocation game.
This is governance in the only sense that matters: shaping who can do what, who captures the rents, and who absorbs the burden.
For three years, the policy discussion treated AI as a model problem. Regulation, alignment research, fairness audits. The model was the object.
The regulation would be written about the model. But that was an optical illusion. The battle was always about compute: who gets access to enough GPUs to train frontier systems, who decides where the datacenters sit, who owns the cloud infrastructure that runs them, and crucially, who pays the grid when the load spikes.
From 2025 onward, the literature and institutional moves make it clear: compute is now the governance primitive. And that changes everything about how you should think about AI power, national advantage, and where actual value concentrates.
The shift is not a policy choice. It’s an admission. Regulators looked at the stack, chip fabrication, datacenters, cloud access, power systems, capital flows, and realized: this is where control actually lives. You cannot regulate a model’s behavior if you do not control its training run.
You cannot impose safety standards on inference if you do not control the cloud that runs it. You cannot claim sovereignty over AI if your country depends on foreign chips, foreign colocation, and foreign cloud operators.
So the “governance” of AI became the governance of who builds, operates, and allocates the infrastructure that makes AI possible.
That is not a metaphor. That is a better description of what the consequential decisions actually are.
The Five Ideas That Now Define the Debate
The 2025–2026 literature converges on five operating assumptions. These are not values. They are empirical convergences that everyone from the UN to OpenAI to the OECD now acts on.
First: Compute is measurable enough to support policy, though imperfectly.
You cannot regulate what you cannot measure. That used to rule out compute. You could not count how much of it existed, where it sat, or what it was being used for. Now you can. Datacenters are physical objects with power meters, cooling systems, and colocation agreements.
Chips have serial numbers. Cloud allocations leave audit trails. The IEA can estimate AI-driven electricity demand. The OECD can measure domestic public-cloud AI capacity. The measurement is imperfect, distributed training, undisclosed runs, efficiency gains outpacing benchmarks, but it is no longer impossible. Once something is measurable, it becomes governable. That is why compute went from an ignored bottleneck to the central lever.
Second: Sovereignty is layered, and the layers do not align.
This is the most dangerous insight for anyone who thinks national control is a binary. It is not. A country can have massive datacenters on its soil, but if those datacenters are run by foreign cloud operators, owned by foreign capital, powered by leased infrastructure, and filled with foreign chips, what does “sovereignty” actually mean?
The 2025 literature splits sovereignty into three separate questions. How much AI compute sits on your territory? Who owns and operates the cloud infrastructure? Whose accelerators power it? These are not the same lever. A government can increase territorial supply, build datacenters, light up fiber, negotiate hosting, while remaining structurally dependent on foreign cloud vendors, foreign fabs, and foreign capital.
This is the trap: prestige infrastructure that looks sovereign but is operationally dependent. When the pressure comes, export controls, sanctions, supply chain disruption, the dependency becomes visible.
Third: Concentration in chips, cloud, and datacenters is a first-order competition problem.
The market solved this badly. NVIDIA controls the accelerator market. AWS, Microsoft, and Google control most cloud compute. A handful of firms, Broadcom, Intel, TSMC, control advanced chip fabrication. When you pile those concentration points on top of each other, you get vertical integration on a scale that most antitrust frameworks were not designed to see.
This matters because concentration is a lever. A firm that controls chips, cloud, and model training can foreclose access. A government that depends on that firm’s infrastructure cannot credibly threaten to regulate it. The OECD 2025 analysis made this explicit: the AI stack is collapsing into a few gatekeepers. That is not normal market consolidation. That is infrastructure capture.
And the moment you see it as capture, the question is not “should we allow this?” but “how do we prevent it before the gatekeepers have enough power to make the question rhetorical?”
Fourth: Energy, permitting, and capital are no longer side constraints. They are central bottlenecks.
This is where the abstract governance discussion crashes into physical reality. AI datacenters are not offices. They are power-hungry industrial facilities. A large training run can draw megawatts of continuous demand. That demand has to come from somewhere. From grids that are already strained, from regional capacity that might not exist, from water systems that might not sustain the cooling load.
The IEA has started putting numbers on this. The U.S. Department of Energy is siting datacenters on federal land and running into grid interconnection delays. Regional utilities are discovering that AI buildout is not just another commercial customer. It is a load spike that reshapes generation planning for years.
This creates a hard constraint that no amount of Silicon Valley will-to-power can overcome. You cannot build a datacenters faster than the grid can handle it. You cannot train a model if the power is not there. Energy and permitting do not just increase cost. They set the ceiling on possible compute allocation. Once you hit that ceiling, allocation becomes genuinely constrained, and the fight over allocation becomes violent.
Fifth: Verification remains the weak link.
Here is where governance theory meets engineering reality and loses. The most useful mechanisms for treaty-grade assurance, hardware-level monitoring, on-chip metering, tamper-proof attestation, are still immature. The 2026 hardware taxonomy found that the mechanisms most useful for actual verification are the least ready for deployment.
This creates a perverse situation. Everyone agrees compute should be governed. But the tools to verify that governance works are not ready. So policy has to choose: announce governance frameworks and accept that compliance is mostly voluntary, or wait for verification technology to mature and cede the interim years to uncontrolled buildout. Most regimes are choosing the first option and hoping no one notices.
What Governance Actually Looks Like: The Allocation Stack
Stop thinking of AI governance as a regulatory framework. Think of it as infrastructure allocation architecture. It runs from the bottom of the stack to the top:
Chip designers and fabricators → Server makers and integrators → Cloud operators and datacenters → Electric grids and power generation → Financiers and credit providers → Model developers → Enterprises → Public sector and research.
Each layer makes allocation decisions. TSMC decides which customers get N3 wafer capacity.
NVIDIA decides which countries get A100s.
AWS decides which accounts get GPU queue priority.
The grid operator decides which loads get power when supply is tight. The venture capitalist decides which frontier lab gets $100M. Each of these decisions is a governance decision. The people who control that layer get to shape the production frontier.
The 2025 compute-sovereignty literature broke this down cleanly: governments need to ask three separate questions about each layer.
How much AI-relevant compute sits on your territory? Not how much you claim. How much is actually there, physical chips, racks, colocation. You can measure this. Datacenter permits, utility interconnections, property registries. You can see them.
Who owns and governs the cloud infrastructure operating that compute? This is the catch. Your territory might host AWS datacenters that Amazon owns, that Amazon controls, that Amazon can shut down or deprioritize whenever it chooses. You have the real estate. Amazon has the power.
Whose accelerators power it? Because if every accelerator is a NVIDIA chip made in Taiwan and controlled by U.S. export rules, then your “sovereignty” is leased. The moment the U.S. tightens export controls—which it does, and will, your datacenters turn into empty shells.
Most governments have not worked through these three questions. They talk about “building sovereign compute” and mean some combination of all three, as if they were the same thing. They are not. A country can increase territorial hosting while remaining dependent on foreign operators. A country can build public datacenters while remaining dependent on foreign chips. The trade-offs are real.
This is why the World Bank’s 2025 “four Cs” framing is more honest than the sovereignty discourse. Compute is one of four foundations of an AI ecosystem. The others are connectivity, context (local data, local use cases), and competency (skills, institutions). You need all four. A country with world-class compute but no fiber, no coherent data strategy, and no engineers is just subsidizing foreign model companies to build their datacenters on your soil.
The Four Logics of Compute Governance
Everyone agrees compute matters. They disagree on what it is for. The 2025–2026 literature reveals four separate governance logics competing for dominance. They are not compatible.
Compute as a Choke Point
This logic says: frontier AI training is dangerously powerful. Control the training runs. This means threshold reporting, export controls, licensing, and cloud provider monitoring. If a training run exceeds the threshold, it gets flagged. If it involves certain technologies or actors, it gets blocked. This is the safety logic. It assumes you can make frontier training legible enough to regulate.
The problem is obvious. Legibility is not possible if you cannot verify. And the most useful verification mechanisms, hardware attestation, on-chip metering, are not mature. So this logic defaults to threshold-based monitoring, which has detection gaps. You can hide compute in distributed training runs, use efficiency tricks to reduce the FLOPs, run the training in countries that do not report. The RAND 2025 analysis showed that FLOP-threshold monitoring will catch obvious cases but miss sophisticated actors.
Despite this, the choke-point logic is seductive because it is simple: give safety researchers a compute budget, cap the big runs, verify when possible. It is the logic that Anthropic has pushed hardest. The theory is that if you control frontier training, you can ensure safety compliance before dangerous models get released.
The rents flow to whoever issues the licenses.
Compute as Sovereignty
This logic says: frontier AI is national advantage. You need your own compute. This means sovereign datacenters, public compute pools, national procurement rules, and whatever control you can extract over the cloud operators on your territory.
The EU has operationalized this faster than anyone. AI Factories, AI Gigafactories, Apply AI Strategy, all designed to build territorial compute capacity and reduce dependence on foreign operators. The logic is: we cannot control what the Americans and Chinese build, but we can control what we build. We can reserve it for European enterprises, research institutions, and startups. We can build the infrastructure, own the assets, and decide the allocation.
The problem is that this logic treats datacenters as the productive asset when they are actually just pipes. What matters is what runs through them. And if the software, the models, the chipsets, and the core R&D are all foreign, then the datacenters are just expensive warehouses. The EU is trying to solve this by funding local model development, but the economic logic is harsh: frontier model development requires massive capital, frontier talent, and continuous iteration on frontier problems. You cannot build that in two years with government money. You can build datacenters in two years.
The rents flow to the entities that control territorial infrastructure.
Compute as an Industrial Bottleneck
This logic says: concentration in chips, cloud, and infrastructure is anticompetitive. Break it up. Fund public compute and open-source alternatives. Mandate interoperability. Force cloud providers to offer non-discriminatory access.
The OECD has pushed this logic. It points out that if three firms control 70% of cloud capacity, and those firms can also train models, buy chips preferentially, and integrate vertically down to hardware design, then the market is not functioning. New entrants cannot get access. Established competitors face arbitrary cloud pricing. The infrastructure becomes a moat instead of a commodity.
The remedy is competition policy: block mergers that increase concentration, require interoperability, fund public alternatives, and invest in open hardware so that no single firm controls the stack.
The problem is that this logic is slow. Antitrust cases take years. By the time a merger remedy is imposed, the market has moved on. And the open-hardware alternative is economically inferior to proprietary hardware for most workloads. You can mandate interoperability, but you cannot mandate that it works as well as the proprietary option.
The rents flow to the competitors who survive the enforcement process.
Compute as a Public Utility Problem
This logic says: datacenters consume massive electricity, water, and land. This is not just a private allocation problem. This is infrastructure planning. Grid capacity, permitting, financing, community opposition, resilience.
The IEA and DOE have started treating this seriously. The electricity demand curve for AI is not linear. It is exponential. Without coordinated grid planning, you get brownouts and spikes. Without community engagement, you get opposition and delays. Without financing coordination, you get stranded assets and financial instability.
This logic requires cross-agency coordination: energy ministry talks to planning authority talks to finance regulator. But most governments still treat AI datacenters as just another commercial customer. The power is allocated by market price and queue. The grid is managed by existing rules. The permitting is standard. This works fine until the load grows faster than capacity can expand.
The rents flow to whoever controls the scarce input—in this case, grid capacity and siting permits.
What the Institutions Actually Say
The smart move is to follow the actors. What are the international bodies and major labs actually doing?
The UN is now framing AI inclusion partly as a compute access problem. The formal position is that capacity building, affordability of computing power, and shared scientific knowledge should be part of global governance. This is different from saying “we need ethics principles” or “we need safety research.” It is saying: people in poor countries cannot access frontier AI if they cannot afford or access compute. That is not an ethical problem to solve with fairness research. That is an infrastructure problem. The remedy is to make compute more available and more affordable. The UN is still learning how to operationalize this, but the framing is honest.
The OECD has moved compute from a vague bottleneck discussion to a measurable, policy-trackable variable. It now has a dedicated compute policy track, measurement work on domestic public-cloud AI compute availability, and competition analysis of the AI infrastructure market. This is significant because it means compute is no longer something governments wave at as a “challenge.” It is something they are going to measure, compare, and use in policy decisions.
The EU has effectively operationalized compute governance as industrial policy plus diffusion policy. AI Factories, AI Gigafactories, sovereign compute pools, all designed to build territorial compute capacity and reduce dependence. The economic bet is explicit: we cannot compete on models, but we can own the infrastructure those models run on. If we own the infrastructure, we can allocate it to European enterprises and protect them from foreign lock-in. The honest framing: this is not about fairness or global good. This is about economic power.
The G7 moved compute from aspirational language to operational reporting. The Hiroshima AI Process now has a standardized transparency-reporting framework. It is not compute regulation per se, but it is the beginning of interoperable governance of the high-end ecosystem that consumes the most strategic compute. This matters because it means frontier labs will have to report on risk management, model capabilities, and deployment. The scope is still narrow, but the precedent is set.
The ITU explicitly named “governance of compute and models” as a core issue. This is unusually direct language for an international standards forum. It signals that the ITU is moving from protocol standardization into infrastructure governance. Once the ITU is involved, compute becomes a global coordination problem, not just a national one.
The IEA has quantified the electricity consequences. AI-driven datacenter electricity demand is growing exponentially. If current buildout projections hold, datacenters could account for 4-6% of global electricity demand by 2035. That is not a side constraint. That is a primary infrastructure challenge. The energy system has to be planned around it.
OpenAI has moved from “we build the best model” to “infrastructure is destiny.” OpenAI for Countries is explicitly designed to help governments build in-country datacenter capacity and reduce dependence on U.S. infrastructure. The framing is straightforward: we want to operate globally, but countries want sovereignty. We will help you build the infrastructure. Some of the capacity figures are still unspecified or early-stage, but the bet is explicit.
Anthropic has staked the hardest position: compute advantage should be preserved via export controls, stronger enforcement, and tighter restrictions on advanced chips. Anthropic’s Responsible Scaling Policy keeps governance tied to catastrophic-risk thresholds—which means that if the risk increases, the compute gets restricted. This is the most direct major-lab argument that compute allocation is national-security governance. The argument is: the U.S. has an advantage in chips and capital. We should use that advantage to control the frontier. Export controls are the mechanism.
Google and Google DeepMind emphasize Sovereign Cloud and Sovereign AI, plus internal infrastructure measurement. The message is: diffusion depends on secure, compliant infrastructure. We will help you build it and help you control it. Google also reports that 98% of organizations are exploring generative AI, and 39% are already in production. This is the enterprise truth: compute governance is not just a frontier-lab problem. It is an enterprise problem.
Meta argues for open hardware, standardization, and large-scale AI datacenter buildout. Meta is the heretic in this conversation: it thinks openness and interoperability are stronger than control and lock-in. The latest Meta scaling framework tightens preparedness around advanced models, but the infrastructure posture remains pro-open. This is different from every other actor because Meta is trying to win on scale and reach, not proprietary moat.
The synthesis: These actors are not offering a shared doctrine. They are converging on a shared arena—access to compute infrastructure—and disagreeing about purpose. International bodies want inclusion and interoperability. Labs want sovereignty, security, or open competition depending on business model. The insight is that those are not separate debates. They are rival answers to the same allocative question: who gets the compute?
Where Allocation Actually Happens: The Sectors
If compute allocation is governance, it should show up in how sectors actually operate. It does. Here is the sector pattern.
Frontier labs and hyperscalers: The compute question is: who gets priority for the chips? OpenAI country programs, Anthropic’s security playbook, Meta’s datacenter buildout—all competing for accelerators and colocation. The constraint is brutal. There are not enough chips. There are not enough power connections for all the datacenters that want to exist. The labs that can pay most, negotiate hardest, and secure government support get the compute. Everyone else waits or builds on lower-tier hardware.
Enterprises: The compute question is not “how do we compete with frontier labs?” It is “how do we allocate expensive compute internally?” Google Cloud reported that 39% of organizations are in production with generative AI. Most of that is not frontier training. It is inference at scale, fine-tuning on proprietary data, and agent-style automation. The governance problem is internal: which business units get GPU quota? What gets routed to cheaper inference? What gets reserved for regulated functions? Enterprise success depends less on frontier access than on governed internal allocation and cost discipline.
Mining: This is the interesting case because it is both an AI adopter and a supplier to the compute buildout. BHP uses digital twins and generative AI for decision-making and geological interpretation. But mining is also the source material for compute: copper is essential for datacenters, lithium for batteries, critical minerals for chips. The governance problem is dual-sided. As an adopter, mining firms need reliable compute. As a supplier, they face demand spikes from AI buildout that can constrain supply chains. The intersection creates a weird position: mining is an AI adopter that benefits from the infrastructure buildout, but it is also the input provider that the buildout depends on.
Aviation: Regulated industries have a different problem. Predictive maintenance, simulation, defect detection—these are valuable applications. But certification, explainability, continuous monitoring, and human-in-the-loop requirements create governance constraints. Aviation does not have a “compute shortage” problem. It has a “compute allocation within regulation” problem. The governance question is: how do I run AI models that satisfy regulatory oversight and continuous assurance? This requires compute that is auditable, logged, and verifiable. That is more expensive than raw inference. The constraint is not silicon. It is assurance.
FMCG and consumer brands: Unilever, Nestlé, Colgate—all running AI on seasonal supply chains, digital product twins, and generative design. The compute constraint is not frontier access. It is integration. The models have to talk to legacy ERP systems, supply-chain networks, and customer databases. The governance problem is data integration and cost discipline. You need reliable inference at scale, not training-run capability. The allocation question is: which workflows get priority access to GPUs versus which get routed to cheaper CPU inference?
Finance: JPMorgan, Goldman, major central banks—all integrating generative AI and foundation models. The compute governance is about risk and controls. Model risk management, audit logs, regulatory scrutiny, data residency. Finance has less interest in frontier scale and more interest in governed access tiers. The allocation question is: which functions need audit trails? Which data is sensitive? Which models require continuous monitoring? Finance would rather have less compute with more assurance than more compute with audit gaps.
Energy: The irony is perfect. The sector that is the constraint is also the sector that uses compute to optimize itself. The U.S. Department of Energy is siting AI datacenters on federal land while simultaneously trying to manage grid load. The IEA is quantifying power demand while coordinating with grid operators. The allocation question is: how much load can the grid sustain? What level of buildout is physically possible given generation capacity? This is the hard constraint. You cannot allocate compute faster than the grid can deliver power. The queue for new datacenter connections is now an energy governance queue.
The pattern across sectors is consistent: The frontier labs and hyperscalers are fighting over chips and power. Enterprises are optimizing internal allocation and cost. Regulated industries need assurance and audit. Energy systems are the constraint. The allocation architecture is not uniform. It is tiered by actor and by constraint.
Four Scenarios for 2035–2045
The next decade will be defined less by whether AI gets bigger and more by how compute gets rationed. The 2025–2026 literature and institutional moves suggest four plausible scenarios. These are not forecasts. They are coherent narratives about what different patterns of incentives and constraints could produce.
Scenario 1: Managed scarcity (35% probability)
States and large firms accept compute as critical infrastructure and build mixed public-private allocation systems. The gridConstraint is real. The safety concerns are real. The sovereignty pressure is real. The response is to treat compute as a strategic input, like oil or uranium. Some is reserved for frontier labs, some for public research and public services, some for enterprise, some stays unallocated as a reserve. Cloud providers have to report usage and allocate fairly. Export controls remain in place but are predictable. The economic rent goes to whoever controls the reserved allocations and whoever negotiates the fairest access terms.
The political economy is: governments accept that they cannot build frontier capability themselves, but they can ration access to it and build infrastructure for their own enterprises and research. Frontier labs accept that training runs will be monitored and that there are hard resource constraints. Enterprises learn to work with compute quotas and plan around them.
Scenario 2: Bloc sovereignty (30% probability)
The world splits into three blocs: U.S.-aligned, China-aligned, EU/partner. Each builds its own stack and tries to minimize dependence. Export controls harden into de facto embargoes. Accelerators go to ideologically aligned countries. Cloud infrastructure gets nationalized or brought under state control. Data flows are restricted. The United States maintains the technological edge because it has capital, talent, and existing infrastructure. China builds rapid-follower capability with state coordination and massive capital. Europe falls behind but maintains autonomy.
The economic rent goes to the state that controls the compute, not the firm that might want to access it. Firms operate within their bloc. Startups in non-aligned countries get cut off. The global AI market fragments into three zones with limited interoperability.
Scenario 3: Oligopoly with contractual access (20% probability)
A small number of vertically integrated firms dominate, but states impose selective transparency and competition remedies. The firms are NVIDIA, OpenAI, Google, maybe Meta. They have control over chips, software, and infrastructure. But states force them to publish reports, offer non-discriminatory cloud access, license chips to approved competitors, and invest in public research. The firms accept this because the alternative is forced breakup or nationalization.
Access is mostly commercial and contractual. Governments intervene mainly at the margins—blocking a merger here, requiring a licensing deal there. The firms maintain dominant positions but under constant political pressure. The economic rent goes to the oligopolists, but they are forced to share some of it with public interest via licensing, transparency, and compliance costs.
Scenario 4: Efficiency shock and distributed inference (15% probability)
Model and hardware efficiency improve faster than anyone expects. Frontier training remains concentrated—you still need massive scale to build the next GPT. But inference diffuses. The models get smaller, faster, and more efficient. Edge compute becomes viable. Specialized accelerators compete with GPUs. Small models fine-tuned on proprietary data outcompete large frontier models in most tasks.
Governance shifts from scarce training allocation toward audit, provenance, and secure deployment. The compute bottleneck eases because most compute is no longer frontier training. The governance problem becomes: how do we monitor and assure all the inference happening everywhere? This is different and harder than controlling the big runs.
The consensus: The high-probability scenarios are not utopian. The likely medium-term world is one where governments do not nationalize compute, but they do stop treating it like a neutral service. The boundary between industrial policy, platform regulation, infrastructure planning, and AI safety becomes blurry and contested. The rents are concentrated. The allocation is political.
Four Implementation Mechanisms: How This Actually Works
Theory is not practice. The literature identifies four mechanisms that could operationalize compute governance. Each has upsides and weaknesses.
Tradable compute permits for very large training runs, with dynamic thresholds
The idea: if you want to train a frontier model, you need a permit. The threshold adjusts as algorithmic efficiency improves. You can trade permits if you do not use them. This creates a market signal: scarce permits get expensive, so wasteful uses get discouraged.
Upside: Creates legibility and incentive alignment. If you want to train a large model, you know the rules and the cost. If you become more efficient, you can sell your permits and profit.
Weakness: Gaming and threshold drift. Actors can hide compute in distributed training. Efficiency gains can make thresholds stale faster than policy can adjust. And permits are expensive, so frontier labs pass the cost to customers.
Risk bonds or insurance premia that rise with estimated catastrophic-risk externality
The idea: if you are training a very large or very capable model, you post a bond. If the model causes harm, the bond is forfeited. The bond size rises with estimated risk. This prices the externality directly.
Upside: Targets the problem directly. If you are willing to build a system with catastrophic risk, you have to pay for it in advance.
Weakness: How do you estimate catastrophic risk? The models are opaque. The scenarios are speculative. You end up with a system where bond prices are arbitrary and political. And the worst-case scenarios might not be insurable at any price.
Public-interest vouchers or reserved allocations for science, public services, and competitive SME access
The idea: some compute is reserved and given to unprofitable uses. Research universities get access to frontier compute for free or cheap. Public services get compute reserved for critical applications. Startups get access on fair terms.
Upside: Prevents compute from becoming a pure private good. Enables public research and competitive dynamics.
Weakness: Expensive. Someone has to subsidize the cost of computing for public interest. And it can turn into subsidy theater: governments announce public compute pools, but the pools are too small or too expensive to actually change behavior.
Concentration penalties or merger remedies when additional compute control materially raises concentration cost
The idea: if a merger would increase concentration and foreclose access, block it. Or require remedies: open up APIs, license technology, commit to non-discriminatory access.
Upside: Preserves market dynamism and prevents hard lock-in.
Weakness: Slow and legally complex. By the time a merger remedy is imposed, the market has moved on. And you cannot force a firm to offer services that are not profitable.
The honest framing: none of these mechanisms is perfect. They all involve trade-offs between clarity, cost, effectiveness, and fairness. The question is not which one is “right.” The question is which combination of mechanisms produces the least bad outcome in your specific context.
The Likely Adoption Path: What Actually Gets Implemented
If current trends continue, here is the sequence that the 2025–2026 literature suggests:
2026–2027: Visibility phaseCloud providers publish threshold notices for very large training runs. Labs report on compute usage by cluster and jurisdiction. Export control enforcement tightens on advanced chips. The goal is just to make what is happening visible.
2028–2029: Sovereignty and access phaseAI Factories and sovereign compute pools launch in major jurisdictions. Competition reviews of AI infrastructure accelerate. Grid operators and datacenter developers start coordinated planning. National compute registries emerge.
2030–2032: Market structure phaseMerger remedies and interoperability requirements start taking effect. Public-interest compute carve-outs become standard. Open-hardware investment accelerates. The question shifts from “how much compute exists?” to “who can access it?”
2032–2034: Energy integration phaseGrid-datacenter co-planning becomes mandatory in most jurisdictions. Dynamic tariffs and flexibility contracts tie compute allocation to grid capacity. The energy system becomes the visible constraint.
2034–2036: Assurance phasePublic R&D on hardware attestation matures. Hardware-security pilots begin in production systems. On-chip metering becomes standard. Verification mechanisms that were immature in 2026 become available.
2036–2040: Treaty-grade capabilityCompute governance mechanisms mature enough that international agreements become possible. Verification is strong enough that countries can actually monitor each other’s compliance. The architecture shifts from unilateral national policy to coordinated international allocation.
This timeline is not a forecast. It is a roadmap based on current institutional momentum. Actual adoption will depend on geopolitical pressure, capital availability, technology maturity, and whether some of these mechanisms actually work at scale.
The Practical Playbook: What To Do Now
Theory is interesting. But actors need to know what to do. Here is the practical playbook.
For frontier labs: Stop pretending compute governance is just a government problem. Build internal compute registries by cluster, project, jurisdiction, and model lineage. Publish threshold-based risk reports. Pre-negotiate emergency de-allocation and pause procedures with cloud and power partners. Invest in secure weight handling, auditable scheduling, and verifiable usage logs.
The honest test: if your governance proposal does not specify how compute is metered, reserved, and curtailed in practice, it is still just rhetoric. Move from words to systems.
For enterprises: Do not chase frontier scale. That is a trap. Build an internal allocation regime. Reserve expensive GPU access for workloads that genuinely need it. Route most use cases to cheaper inference or small-model workflows. Set business-unit quotas. Log prompt and model provenance for regulated functions. Make cost, latency, security, and data residency visible at the point of use.
The enterprise constraint is not access to frontier models. It is cost discipline and security assurance. Optimization beats scale.
For regulated enterprises (finance, healthcare, aviation, energy): Compute is not your bottleneck. Assurance is. Build audit trails, model risk frameworks, and continuous monitoring. The governance question is: can I run this model and prove to a regulator that it is safe? That requires compute that is auditable and logged, not raw compute that is fast.
For policymakers: Measure first, then allocate, then discipline, then verify. Do not reverse that order.
Start by measuring domestic compute and dependence by territory, provider, and accelerator nationality. What compute exists on your soil? Who owns it? Who can control it? This is simple but is almost never done rigorously.
Reserve some compute for public-interest use—research universities, public services, SME access. This requires political will and sustained funding. But it prevents compute from becoming a pure private good.
Discipline the stack with competition tools, energy planning, and threshold reporting. Do not assume the market will allocate compute optimally. It will not. Use policy to shape allocation toward strategic goals.
Fund the harder verification work. Treaty-grade hardware assurance is not ready. But the foundations need to be laid now. Fund chip-security R&D, hardware-metering standards, and attestation pilots. The alternative is governance that cannot verify compliance.
Here is the concrete action matrix for the next 12 months and next 2–5 years:
Frontier labs (12 months):
Internal compute registry by cluster, project, jurisdiction, model lineage
Threshold triggers that auto-pause training if guidelines are exceeded
Auditable usage logs for every compute allocation
Emergency pause protocols with cloud and power partners pre-negotiated
Frontier labs (2–5 years):
Secure scheduling systems that prevent unauthorized compute access
External review of high-risk training runs
Hardware-attestation pilots in production systems
Success metric: What percentage of your compute is under auditable governance? Target should move from 0% to 80%+.
Enterprises (12 months):
GPU quotas by business unit and by workload type
Costed access tiers: what does each tier cost? Who pays?
Secure data-routing for models trained on proprietary data
Model provenance logs for regulated functions (finance, healthcare, etc.)
Enterprises (2–5 years):
Portfolio optimization across small models, cloud inference, edge compute, and sovereign-hosted workflows
Cost per GPU-hour becomes a tracked KPI
Compliance incident rate approaches zero
Success metric: Value created per GPU-hour and compliance incident rate. Target: 50% improvement in efficiency, zero unlogged model deployments.
Policymakers (12 months):
Compute mapping: how much AI-relevant compute exists in your jurisdiction? Who owns it? Who operates it? Whose accelerators does it use?
Cloud-provider and accelerator-manufacturer dependence assessment
Datacenter-energy coordination: what is the grid capacity? What is the interconnection queue? What is the timeline for expansion?
Policymakers (2–5 years):
Public compute pools for research, public services, and SME access
Competition remedies and public-compute investment based on concentration assessment
Dynamic compute thresholds that adjust as algorithmic efficiency improves
Verification R&D: fund hardware-security research, standardize metering, pilot attestation
Success metric: Compute access diversity (percentage of compute not controlled by top-3 firms), monitoring quality, and reduction in strategic dependencies.
The Bottom Line
Compute allocation is not governance. It is the only thing that was ever governance. Everything else is negotiation around the margins.
The actors who control the silicon, the power, and the hosting decide who gets to build frontier AI. The rents flow to whoever controls the scarce input. The risk is concentrated in whoever decides the allocation. The political power goes to whoever can shape it.
The 2025–2026 institutional moves make this explicit. Governments stopped pretending they could regulate AI through principles and frameworks. They started controlling the infrastructure. Labs stopped pretending they could operate without state permission. They started negotiating for access. Enterprises stopped asking for frontier capability. They started asking for governed internal allocation.
The serious questions are not “should compute be governed?” They are: “How do we allocate compute across frontier labs, public-interest research, enterprise adoption, and traditional sectors without drifting into cartelization, geopolitical fragmentation, energy backlash, or unverifiable theater?”
That is not a philosophy question. That is an optimization problem. And the literature and institutions have converged on the answer: measure, reserve, discipline, verify. Build allocation systems that are tiered by actor and by constraint. Account for energy, risk, concentration, and dependence costs.
Do it now. Because the alternative is governments realizing too late that they have no control over the infrastructure their economies depend on, and then implementing emergency measures that are crude and destructive.
The compute allocation race is not coming. It is already here. The question is whether you are building it intentionally or whether it is building itself without you.

