White paper · September 2026 · Published ahead of the U.S.–China AI safety talks

Govern superintelligence the way the world governed the bomb.

The argument that we cannot slow down because our adversaries will not is correct. It is also the case for verification, not a reason to avoid it. The Threshold Compact is a binding charter among the world's frontier AI labs, led by the people who build them, overseen by governments, co-chaired by American and Chinese members, and enforced through the one thing that can be counted: the chips. Verification is the price. Abundance is the prize.

By Logan Reed, former U.S. Army Captain, former intelligence contractor supporting U.S. and partner special operations forces, technology modernization and responsible AI

Page from the white paper: The problem no one has solved White paper cover: The Threshold Compact Page from the white paper: the enforcement ladder

Built on the public record. Sources cited include

OpenAIGoogle DeepMindAnthropicInternational AI Safety ReportScienceBrookingsCNASCentre for the Governance of AIReutersAssociated Press

Nobody trusted the Soviets in 1970. The treaty got signed anyway.

The parties did not agree to trust each other. They agreed to let each other look.

Every leader in AI says the same thing about restraint: we cannot slow down, because our adversaries will not. That is true. But look at what it proves. It proves that restraint by agreement is impossible. It says nothing about restraint by verification, and those are different things.

Frontier AI has something a promise does not: a physical input that is scarce, traceable, and impossible to do without. A frontier training run needs tens of thousands of the most advanced chips on earth, made by a handful of firms, running in facilities that draw power on the scale of a small city. Compute is to AI what fissile material was to the bomb. That is what makes verification possible, and it will not stay true forever.

This month the United States and China are preparing a new round of talks on AI safety ahead of a meeting of the two presidents. Beijing's stated conditions, a co-equal role in defining safety and identical rules for American labs, are the same conditions every American negotiator has demanded since 1946. Two rivals are describing, from opposite sides, the only agreement either would sign.

Read the full argument in the paper →
"We are likely to eventually need something like an IAEA for superintelligence efforts... Tracking compute and energy usage could go a long way."
OAAltman, Brockman, Sutskever · OpenAI · May 2023
"Mitigating the risk of extinction from AI should be a global priority alongside other societal-scale risks such as pandemics and nuclear war."
CAISStatement signed by the CEOs of OpenAI, Anthropic, and Google DeepMind · May 2023
"Some of the strongest safeguards might prove outright impossible to implement without collective action."
AAnthropic · Responsible Scaling Policy, Version 3.0 · February 2026
"We must slow the pace at which we improve the capabilities of AI models."
DADario Amodei · CEO, Anthropic · "We Must Pace the Frontier," September 2026
"They are racing straight to self-improving superintelligence and gambling with our lives."
JCJacob Coxon · pretraining researcher, on resigning from Anthropic · September 8, 2026
75%

of the world's frontier AI compute is in the United States. 15% is in China. Everyone else shares the remaining tenth.

9

nuclear states today, not the 15 to 25 President Kennedy feared in 1963. Verification, not trust, did that.

12to 18 months

to stand up a working Authority on the recommended fast path, using executive action and existing authorities, with statute and treaty following rather than leading.

Reaching superintelligence first does not mean being able to control it.

Reliable human control over artificial superintelligence remains unproven, regardless of which laboratory or country develops it.

A nuclear weapon does what its owner tells it to do. The danger was always in the owner. Superintelligence, if it is built, is a system whose capabilities would by definition exceed our own and whose behavior its creators cannot fully predict. Whether it would reliably do what its owners intend is an open scientific question, and the people closest to the work say so.

Good intentions and national allegiance do not resolve that uncertainty. An American superintelligence that no one controls is not an American victory. The consequences of losing control are too serious to cross that threshold on the promise that we will figure out the safeguards afterward.

So the Compact must do something the nuclear arrangements never had to. It must govern not only who crosses the threshold and how openly, but whether, and on what evidence, anyone crosses it at all. That is why the design pauses at defined capability tripwires, puts the burden of proof on the developer, and works the hardest technical problems jointly and in the open.

Advanced systems could come to "operate outside of anyone's control." Early signs of such behaviors have been observed in current systems, and expert views on their likelihood vary widely.
AIInternational AI Safety Report · February 2026
Control before crossing. No member deploys, and no member continues training, a system that has tripped a defined capability tripwire until the Board has reviewed the developer's evidence that the system remains under reliable human control. The burden is on the developer. The default is the pause.
TCFounding principle seven · The Threshold Compact
The charter cannot solve the control problem. It can pause, review, pool the research, and make the evidence public. It cannot legislate a scientific result.
TCPart Three · What the charter cannot do by itself

How the Threshold Authority works

Led and operated by the labs' own professionals, because that is where the knowledge lives. Overseen by governments through an Oversight Council and national law, because that is where legitimacy lives. Verifies the hardware, not the code. Reports to every government and to the public on a schedule no member can alter.

MEMBERS Frontier Labs U.S., China, and every other lab able to train a frontier model Infrastructure Members Chip designers, fabs, lithography, cloud operators THE THRESHOLD AUTHORITY Board of Principals Chief executive of every Frontier Lab · votes by name American and Chinese Co-Chairs Independent Inspectorate Inspector General, single 7-year term Inspections · Registry audits Whistleblower channel Technical Secretariat Compute Registry · Standards Evaluation suite · Reports Budget and levy Safety Research Commons Pooled alignment, evaluation, security and containment work Council on Human Dignity Independent ethicists, jurists, faith traditions · dissents published Funded by a levy on members' registered compute. No government funding of the Inspectorate or Secretariat. National Liaison Offices receive the restricted annex. GOVERNMENTS Oversight Council One seat per anchor government Receives every report and referral Compels answers · Orders reviews Audits the Inspectorate Enacts the anchor statutes THE PUBLIC Public Reports Quarterly Compliance Report Annual State of the Frontier declare · pay · submit compute restrictions reports oversight same day

Training declarations

Before any run above a public compute threshold, a lab files what it is training, where, with what compute, and under what safety plan. Notice, not permission.

Evaluations and the tripwire pause

A standard suite for biological and cyber uplift, autonomous replication, recursive self-improvement, and deception, run before deployment and at checkpoints during training. Trip a defined tripwire and everything pauses until the Board has reviewed the developer's evidence of control.

Compute Registry

Every advanced accelerator registered at manufacture and tracked for life, as enriched uranium is tracked from reactor to storage. Facilities above a threshold are declared.

Inspections and independent means

Announced and unannounced access to declared facilities. Power draw and satellite imagery reconciled against declarations. Managed access protects legitimate secrets.

Hardware-enabled safeguards

Successive chip generations built to attest to location and workload and to require periodic authorization, so within a decade the Registry is enforced by the silicon itself.

Protected disclosure

A legally protected, financially rewarded channel for the engineers most likely to know that a member is cheating. The nuclear arrangements never had this.

You don't verify the model. You verify the chips.

A model is a file. A frontier training cluster is tens of thousands of registered accelerators drawing power visible from orbit.

The Compact does not ask anyone to trust anyone. It builds on the fact that frontier AI, like fissile material, has physical inputs that can be counted. The number of firms capable of producing advanced accelerators, or the tools that make them, can be counted on one hand, and every one is domiciled in a nation with an interest in this framework.

Routine inspections do not need a lab's code, data, or weights. They need to see that the hardware is where it is declared to be and doing what it is declared to be doing, with managed access to records and models where hardware alone cannot answer the question. That chokepoint exists today. It will not exist forever, which is why the Registry must be built now.

Compute Registry · Facility view · Illustrative
FacilityRegistered acceleratorsDeclared runsPower vs. declaredStatus
US-VA-014248,2002 active+1.8%Verified
CN-HB-002736,9001 active+0.6%Verified
US-TX-031191,4001 active · 1 pending+14.2%Inspection scheduled
AE-AZ-000912,3000+0.2%Verified
UnregisteredEst. 6,000 to 9,000UnknownSatellite anomalyReferred
Illustrative mock-up of what Inspectorate staff would see. Facility codes and figures are invented for the example.

A violator does not need to be prosecuted. It needs to be unplugged.

A five-rung ladder, public and graduated, automatic at the bottom. The decisive penalty is executed by the members who control the chips and the clouds, under anchor statutes that make it lawful, with every anchor government and the Oversight Council notified.

Rung 1

Public notice

Late or incomplete declaration. Corrective plan within 30 days. Decided by the Inspector General.

Rung 2

Penalties and bonds

Repeated violation or failure to correct. A contractual penalty on top of the levy, and forfeiture of the compliance bond every member posts at accession.

Rung 3

Suspension and censure

Material misstatement, obstructing an inspection, or continuing past a tripwire without review. Loss of vote, suspension from the Commons, censure by name.

Rung 4

Compute restrictions

Undeclared frontier run or deployment past a tripwire. Infrastructure Members limit new supply, service, and support, lawfully under the anchor statutes. Governments notified.

Rung 5

Expulsion and sanctions

Concealed weapons-relevant capability or exfiltration of weights. Referral to all anchor governments for sanctions on the company and its executives. No veto.

Why the alternatives fall short

Every existing approach is missing at least one of the things that made the nuclear arrangements hold.

RequirementVoluntary lab pledges
Status quo
Industry standards body
Proposed 2026
Government treaty
Traditional route
Threshold Compact
Includes China and the United States as equals~
Verification anchored in hardware, not promises~~
Identical obligations for every frontier lab~
Public reports on a fixed schedule~~
Consequences that end in loss of compute~
Run by practitioners who understand the systems
Governments oversee it without running it~
Pauses at the threshold until control is shown~~
Can be stood up in twelve to eighteen months
Survives competitive pressure~

✓ yes   ~ partial or possible in principle   – no. Assessment is the author's; the reasoning is in Parts Three and Five of the paper.

Each party gains more by joining than by staying out

Proposals like this usually die of one question: why would anyone sign? Here is the answer for each of the four parties whose signature matters.

The frontier labs

A level field, a statutory safe harbor for compliant conduct, one set of standards instead of fifty, and the thing they now say in public: they would slow down if they knew their rivals had too. This is the mechanism that lets them know.

The United States

Holds three-quarters of frontier compute today and will not forever. The NPT converted a temporary American nuclear lead into fifty years of advantage. You write the rules when you hold the strongest hand.

China

Gets exactly what it demanded in August: a co-equal seat in defining safety and identical obligations for American firms, plus a basis for negotiating lawful, predictable access to the hardware supply chain. Outside the Compact it faces restrictions from every participating supplier.

Everyone else

An Abundance Program delivers the safe fruits of frontier AI in medicine, agriculture, education, and energy without requiring nations to race for it. The same bargain that kept the nuclear club small.

The fast path: a working Authority in twelve to eighteen months

Three years is the careful timetable. We do not have three years to spare. The recommended path builds on executive action and authorities that already exist, and lets the law catch up.

Days 0 to 30

Ignition

The two presidents agree one sentence. American and Chinese frontier labs convene with their hardware suppliers. Each government names its Oversight Council member by executive action.

Days 30 to 90

Founding Declaration

Interim compact in force: training declarations, 72-hour incident reporting, bonds posted. Export-control data becomes a provisional Registry. First public Compliance Report at day 90.

Months 3 to 9

Standing up

Charter signed. Co-Chairs elected. Inspector General appointed. Registry live for new production. First announced inspections. Anchor statutes introduced in both legislatures.

Months 9 to 18

Full operation

First unannounced inspections. Anchor statutes enacted, activating the top of the ladder. Hardware safeguards roadmap agreed. Abundance Program pilot. Oversight Council's first public audit.

Until the statutes pass, the teeth are bonds, censure, suspension, and publication. The nuclear framework was provisional for a decade, and it held. A 36-month legislative path, with statutes preceding coercive powers, is set out in the paper as the fallback if the two presidents cannot agree the sentence.

The objections, answered

Each is stated in its strongest form. Fuller answers are in Part Five of the paper.

"China will cheat."
Probably someone will, at some point. The question is whether cheating is detectable and costly. A concealed frontier run requires tens of thousands of chips diverted from declared facilities or obtained outside the Registry, a power draw that leaves evidence in utility records and from orbit, a facility inspectors cannot enter, and the silence of every engineer who works there. None of those signals is conclusive alone, and the Compact must publish the limits of its own detection. But the nuclear arrangements caught cheaters with far less, and the consequence here is not a letter; it is the loss of the chips.
"The United States would be giving away its lead."
The Compact asks the United States to give away nothing it can keep. Weights, architectures, and training data stay proprietary. What it shares is safety research, and what it accepts is inspection of hardware it already knows it possesses. In exchange it gains independently checked visibility into Chinese frontier development that no intelligence program reliably provides, and it locks in compute-based verification while it controls the compute.
"Private companies cannot be trusted to govern themselves."
They cannot, and the Compact does not ask them to. It asks them to govern one another, under an independent Inspectorate they fund but do not control, beneath an Oversight Council of governments that can compel answers and order reviews, with every vote published and every serious finding backed by national law. This is not self-regulation. It is industry regulation under public oversight, which is how the safety of securities markets actually functions. Governments set the consequences and supervise the supervisors. The professionals do the inspecting, because they are the only ones who know what to look for.
"Governments will never cede this to the private sector."
They are not asked to cede anything. Every government retains full sovereign authority over the companies within its borders, and the anchor statutes expand that authority. Governments gain a standing seat on the Oversight Council and a source of independently checked information about foreign frontier development that they presently lack, delivered on a schedule they do not have to negotiate, in a format their rivals receive too. No head of state has ever refused a reliable intelligence source because it came from an inconvenient direction.
"Military and intelligence AI programs will never be included."
The Compact governs the training of frontier models, not their every application. A government may apply a declared, evaluated model to any lawful national security purpose; what it may not do is train a frontier model in secret. And the compute chokepoint applies to defense programs as to everyone else. A classified lab still needs chips, and the chips are registered.
"This will slow down the benefits."
It will slow some things down, and it should. A model that trips a capability tripwire will wait for a review it would not otherwise face. Everything else points the other way. Labs today duplicate safety work, hoard evaluation results, and deploy under legal uncertainty. The Commons reduces the duplication, the shared evaluation suite reduces the hoarding, and the safe harbor reduces the uncertainty. The Abundance Program is the only mechanism on offer that would deliver the benefits to the majority of humanity. Safety and abundance are not in tension. Unverified racing is the enemy of both.
"It is too late; the technology is moving too fast."
It is later than it should be. It is not too late, because the compute chokepoint still exists. The number of firms that can manufacture frontier accelerators is still small enough to count. Manufacturing will diffuse, efficiency will improve, and the day will come when a frontier run can be assembled from hardware no registry tracks. The window in which verification is physically possible is open now and closing. That is the reason for the fast path, and the reason to act this year rather than study the question for another five.

Three asks. None requires waiting for anyone else.

To the Presidents of the United States and China

Agree on one sentence: that the frontier labs of both nations should convene within thirty days, with their hardware suppliers, to draft a compact for the verified and collaborative development of advanced AI, co-chaired by both industries, overseen by both governments, and open to all who meet its obligations.

To Congress and every legislature hosting a frontier lab

Begin drafting the anchor statute now: recognize Authority standards, protect those who report violations, provide a defined safe harbor for those who comply, and set lawful procedures for acting on referrals. None of this requires waiting for the diplomats.

To the chief executives of the frontier labs

You have said you cannot slow down alone because your competitors will not. Some of you have now called for pacing agreements and outside evaluators. Here is the mechanism. Say publicly that you would join such a compact if your peers did, and name one member of your leadership team to attend the founding convening.

Add your name

If you believe frontier AI should be governed by verification rather than trust, sign on. Disagreement is welcome too; there is a field for it.

  • Names are listed publicly only with your permission.
  • Your email is used only for updates about the Compact.
  • Signatures are grouped by sector so we can show who is asking for this.

Prefer to write? hello@thresholdcompact.org. Press and interview requests: press@thresholdcompact.org.

If the form does not load, sign on here instead.

Logan Reed

Logan Reed

Former U.S. Army Captain · Former intelligence contractor · Technology modernization and responsible AI

Logan Reed works on technology modernization and the responsible adoption of AI at a professional services firm serving the federal government, where his experience includes leading a Responsible and Ethical AI subgroup and facilitating an AI strategy workshop with senior executives. He is also Co-Founder and President of Volo Match.

He served for eleven years as an air and missile defense officer in the United States Army, with operational assignments including NATO exercise planning in Europe and coalition operations in Iraq, Syria, and Kuwait in support of Operation Inherent Resolve. He later returned to Iraq as an intelligence contractor supporting United States and partner special operations forces with intelligence collection and analysis. His civilian career includes operations and technical leadership roles at Amazon and federal strategy consulting at Deloitte for defense and veterans' health organizations. He holds a B.A. in Philosophy from Loyola University Maryland, has held a Top Secret clearance with access to Sensitive Compartmented Information, and lives with his family in Boiling Springs, North Carolina.

hello@thresholdcompact.org  ·  press@thresholdcompact.org  ·  LinkedIn

The views expressed are the author's alone and do not represent any employer, agency, or client, past or present.

Read it before September 24.

Thirty-nine pages, thirty-six footnotes, and a two-page brief for anyone who runs a country or a lab. Then send it to one person who should see it.