Compute Governance
Compute governance is the umbrella of policies, institutions, and technical mechanisms that use computing resources and infrastructure as levers for governing AI. It can include measuring and reporting large training runs, managing access to advanced chips or cloud capacity, auditing infrastructure, setting procurement conditions, and using compute thresholds to trigger particular duties. A threshold is one instrument within the umbrella, not the definition of the field.
Origin and context
A 2024 multi-author synthesis argued that compute can be useful for governance because important parts of its supply chain are concentrated and computing resources may be quantifiable, detectable, or excludable. OECD's AI compute work provides public data and methodological analysis about cloud GPU availability while documenting important limitations. Independent research published the same year warned that fixed compute thresholds can become inaccurate proxies for risk as algorithms and hardware change.
Why it matters
Compute can provide visibility into some high-resource development that model-output monitoring alone cannot supply. It may support reporting, enforcement, research access, incident investigation, and allocation of scarce infrastructure. It also creates governance risks: surveillance of legitimate activity, privacy loss, concentration of power, barriers for smaller actors, and false confidence in a measurable proxy. Good policy states which objective each compute intervention serves and how errors or exemptions are handled.
Example
A jurisdiction could require cloud providers to retain narrowly specified records for training runs above a defined computational level and notify a competent authority when the trigger is met. That rule would be a compute-governance instrument. A fuller program might also include chip-supply controls, privacy safeguards, secure research access, audits, and periodic recalibration against observed capability. The threshold should not be presented as proof that every covered model is dangerous.
How it differs
Frontier Models
Frontier models are identified through a moving assessment of advanced capability and possible severe risk. Compute governance concerns the broader set of infrastructure and resource levers that may be used before, during, or after model development. A compute threshold can help select models for review without fully defining the frontier category.
EU AI Act
The EU AI Act is a particular legal regime. Compute governance is a cross-jurisdictional policy field whose tools can appear in legislation, export controls, cloud practices, procurement, or voluntary arrangements. The field should not be reduced to one Act or one numerical trigger.
Maturity and evidence
Maturity is rated 4. The field has a detailed research synthesis, international measurement work, multiple policy applications, and independent critique of a central instrument. Definitions and safeguards remain unsettled, and thresholds can age quickly. The umbrella is established, but no single technical or regulatory standard governs all compute-governance programs.
Limits and open questions
Compute is not capability, intent, deployment context, or harm. Algorithmic efficiency can change the capability produced by the same amount of computation; distributed or fine-tuned systems complicate measurement; and access controls can produce geopolitical or competition effects. Implementations need proportional data collection, security, appeal or correction paths, evaluation of distributional effects, and scheduled threshold review. Capability and system evidence should complement rather than disappear behind a compute proxy.
Related terms
References
- Computing Power and the Governance of Artificial IntelligenceIndependent academic collaboration / arXiv · 2024-02-13 · class A
- AI compute from OECD and Oxford UniversityOECD.AI · 2025 · class A
- On the Limitations of Compute Thresholds as a Governance StrategySara Hooker / arXiv · 2024-07-08 · class A
Last updated: 2026-09-07
This term is also covered in the Skills Atlas as ai risk management skill.
This term is also covered in the Skills Atlas as hpc cluster computing skill.