The Sequence · Part II · What To Do
10. Making It Global
Treaties, coalitions, extradition, and the jurisdictions that will not play.
Here is the objection that should worry you most, and it is not subtle.
Suppose one country enacts everything described so far. Statutory penalties on defined frontier activity, bounties payable to anyone who supplies evidence, mandatory liability insurance, the whole apparatus. What happens next is not that the research stops. What happens is that a lab incorporates somewhere else, the senior people take the relocation package, and the work continues in a jurisdiction with a shorter list of questions and a weaker press.
There is a version of this objection that says the mechanism is therefore worse than doing nothing, on the grounds that it applies a selection pressure pointed the wrong way: the labs most willing to relocate are on average the labs least interested in the constraints they are relocating away from, so you have not reduced the amount of frontier work, only sorted it, keeping the conscientious end of the distribution at home.
I used to find that argument compelling. I no longer do, and I think it is actually rather weak.
Start with revealed preference. Permissive, cheap, low-tax jurisdictions with a light regulatory touch are not hypothetical. They exist now, they have existed the whole time, and frontier AI has resolutely failed to move to any of them. The work concentrates instead in a handful of the most expensive, most heavily regulated, most litigious metros on earth. If regulatory arbitrage were the dominant force acting on where this research happens, the current map would look nothing like it does.
The cluster is an input, not a perk. What the Bay Area sells is proximity to the other few thousand people who can do this work, to the capital that funds it, to the compute that runs it, and to the labour market you will need when this job ends. A researcher who relocates to a jurisdiction chosen for its permissiveness is not taking the same job somewhere cheaper. They are leaving the thing that made them productive, and taking a bet that their next employer will also be located somewhere nobody else works. Elite scientific talent is notoriously sticky to clusters, and the number of genuinely eminent people who would emigrate to a research backwater out of pure commitment to the cause is small.
What moves is the shell, not the staff. Incorporation is nearly free to relocate. People are not. A lab can redomicile its holding company overnight without a single researcher changing address — which would completely defeat a firm-level mechanism, and which is one more reason this one attaches to individuals . The bounty follows the person and the passport. Where the parent company is registered is close to irrelevant to it.
And the compute does not move at all. Frontier training needs datacentres, grid interconnects measured in tens of megawatts, and chips subject to export control. None of that relocates quickly, cheaply, or invisibly. The physical substrate of this work is the least portable thing about it.
Finally, the objection contradicts the rest of this site. The argument everywhere else here is that the danger comes not from a lone genius but from large, well-funded groups — that capability is bottlenecked on assembling many capable people at once. If that is true, then shrinking the pool of people willing to do the work matters more than worsening its composition. Cut the available workforce substantially and you have made the binding constraint bind harder, even if the residue is less scrupulous than the people who left. You cannot hold the team-size thesis and simultaneously believe that a smaller, worse-selected workforce is a net loss. I hold the team-size thesis.
So: not worse than nothing. The honest claim is that this heavily undercuts the workforce willing to do frontier work in adopting jurisdictions, and that the undercutting is the point.
What I will concede
Two things, and the first is the one people get wrong in my favour.
The realistic destinations are not backwaters. It is comfortable to imagine the alternative as some jurisdiction nobody can find on a map, because nobody would move there. But the actual competitors are London, Zurich, Singapore, Tokyo, Tel Aviv, and the Gulf states — wealthy, pleasant, well-connected places with functioning universities, existing tech labour markets, and governments that would be delighted to host a frontier lab. Relocation to one of those is a much easier sell than the strawman version, and the selection-pressure worry has real force when the destination is Zurich rather than nowhere.
It does not indefinitely pause anything. A single adopting country buys time and raises costs. It does not stop the work, and I am not going to claim it does. What actually stops it is enough of the places where frontier capability can feasibly be built adopting something compatible — which is a question about coalitions, not about any one statute, and it is the question the rest of this page is about.
So the question is not whether this needs to be international. It obviously does. The question is what international adoption would actually have to look like, and whether anything in the historical record suggests it is achievable.
What has actually worked, and what has not
There are four regimes worth borrowing from, and they have different track records. Being honest about which is which matters more than assembling an encouraging list.
Nuclear non-proliferation is the encouraging one, and encouraging in a specific and limited way. The regime did not prevent proliferation so much as make it slow, expensive, and diplomatically costly — which turned out to be enough to change most decisions and not enough to change all of them.
Chemical weapons inspection is the mixed case. It shows that intrusive verification is politically possible, and it shows that verification is not the same as compliance.
Tax information exchange is the one I find most instructive, because it is the case where extraterritorial reach actually worked, and it worked through a mechanism this proposal could copy. Banking secrecy as a business model did not survive it.
The three regimes, and what each actually did
Nuclear. In the early 1960s the expectation was that nuclear weapons would spread to dozens of states within a generation, simply because the physics was published and the engineering was tractable for any industrialised country that wanted it badly enough. That did not happen — the number of nuclear states is in the high single digits, and the gap between expectation and outcome is one of the largest successes in the history of arms control. It is also incomplete in exactly the way that matters here: several states never signed, and one signed and withdrew.
Chemical. The Chemical Weapons Convention established an international body with authority to conduct on-site inspection of declared facilities, and declared stockpiles really were destroyed under it. It also failed to prevent use in more than one conflict since.
Tax. The United States required foreign financial institutions to identify and report accounts held by US persons, with non-compliance punished by withholding on US-source payments. The OECD then built a multilateral version.
Notice what did the work in the tax case. It was not a treaty obligation between states and it was not moral suasion. It was that access to the dollar clearing system is worth more to a bank than any particular set of clients, and the United States was in a position to condition that access on compliance. The lever was market access, applied to private institutions rather than to governments.
A personal aside — how I found out, the expensive way
I can report on how far that reach extends, because I am standing in it. I am a dual EU/US citizen living in Finland, and I cannot buy a Vanguard index fund. Not should not — cannot. Two rules built by people who never spoke to each other close from both sides. The EU’s PRIIPs Regulation has required since 2018 that any packaged investment product sold to a retail investor here come with a Key Information Document in the prescribed format; American funds produce American disclosures, so my Finnish broker is not permitted to sell me one. Fine, buy the European equivalent — except that a UCITS fund is a passive foreign investment company as far as the IRS is concerned, which means the punitive PFIC regime and an annual form per fund. Neither rule is aimed at me. Brussels was protecting consumers and Washington was closing an offshore loophole, and the intersection of the two is a Finn who cannot own an index fund.
It is a very funny way to discover the thesis of this page. Nobody designed that outcome, nobody could have negotiated it, and it happened anyway — because financial regulation propagates through private institutions that cannot afford to be cut off, and it keeps propagating long after it has passed the last person anyone meant to regulate. FATCA was built to catch wealthy Americans hiding money in Switzerland. It reaches all the way down to the brokerage menu of a salaryman in Helsinki, via an interaction with EU consumer law that no treaty contemplated. If you want evidence that financially-mediated rules travel across borders better than almost anything else states do, I am it.
Which is encouraging for this proposal and ought to be slightly alarming too. The same property that would let an insurance-and-bounty regime reach a researcher in a non-adopting country is the property that locks ordinary dual nationals out of index funds and has made “accidental Americans” unbankable in parts of Europe. Extraterritorial financial rules are effective and indiscriminate, and the collateral damage lands on people who did nothing and have no standing to complain. I want the reach. I would rather count the cost of it honestly than pretend this one only has an upside.
FATF greylisting is the weakest of the four and still not nothing. A country placed on the list finds that correspondent banking relationships get more expensive and that capital becomes more cautious. It is reputational pressure with a price tag attached, and it moves policy in small countries more reliably than any amount of diplomatic argument.
The one structural advantage
There is a feature of this mechanism that makes international adoption cheaper than it looks, and I want to state it carefully because it is easy to oversell.
Most proposals for governing frontier AI require a competent regulator. Someone has to define the threshold, evaluate the models, audit the labs, and keep pace with a field that moves faster than any civil service. That is a standing agency with a standing budget and a permanent recruitment problem, and it is why most governments have not built one. For a mid-sized country the honest calculation is that a credible AI regulator would cost more than the entire domestic AI industry is worth.
Extinction bounties do not need that. What a legislature has to supply is a statute defining the prohibited activity, a penalty schedule, an evidentiary standard, and courts willing to hear the cases. Detection is done by bounty hunters at their own expense. Prosecution is funded by the prospect of the award. The insurance market prices the risk without anyone being appointed to price it. A country that cannot afford a regulator can still host a court.
You may not even need the court
That understates it, and the stronger version is worth following because it changes what adoption means.
The transfer at the centre of this mechanism is private-to-private. An insurer pays a claimant. That is not a criminal forfeiture and it does not obviously require a state’s own judiciary to be involved at all — and the world already has extensive machinery for resolving private disputes across borders without anybody’s national courts hearing the merits.
Arbitration is the obvious route, and it is already global. A 1958 treaty obliges the courts of 172 states to enforce arbitral awards made in any of the others — a wider and more reliable enforcement network than exists for ordinary court judgments, running for sixty-odd years on exactly the premise this mechanism needs: two private parties, a determination made somewhere neutral, enforceable almost everywhere.
There is an elegant way in, too. The objection to arbitrating a bounty claim is that arbitration requires consent, and a bounty hunter has no contract with the researcher they are reporting. But the researcher has a contract with their insurer. Put the arbitration clause in the policy — accept this forum as a condition of coverage — and the consent problem dissolves into ordinary insurance drafting.
Borrowing a whole court is also a real thing that has happened, repeatedly, and none of it is exotic. Legal capacity is a service, and it is already traded.
Four ways jurisdictions have borrowed a bench
- The New York Convention of 1958 binds 172 contracting states to recognise and enforce each other’s arbitral awards.
- When Scotland needed to try the Lockerbie case somewhere neutral, the UK and the Netherlands agreed that a Scottish court would sit at Camp Zeist on Dutch soil, applying Scots law before Scottish judges, with the venue treated as Scottish territory for the duration.
- The Singapore International Commercial Court seats international judges from both common and civil law systems; Dubai, Abu Dhabi and Qatar all run English-language commercial courts staffed substantially by foreign judges.
- A number of Commonwealth states still send their final appeals to the Judicial Committee of the Privy Council in London.
So the picture is one where a country that wants the deterrent but has neither regulator nor competent bench can plausibly obtain both off the shelf: adopt the statute, recognise the forum, and let the enforcement happen through machinery it did not have to build.
There is a fun way to describe the country that supplies that machinery. The US dollar is useful in places the United States does not govern — a ten dollar bill left in a tip jar almost anywhere is worth something and moves easily — not because anyone was persuaded of American virtue, but because a sufficiently trusted instrument becomes the default medium and everyone economises on thinking about it. A state could pursue the same position in law rather than currency: a reserve legislative power, exporting adjudication as a service because being the default venue is itself worth having. I am not saying the United States should be that state, and the concept does not require any particular one. It requires courts people will accept, which is a property several jurisdictions have and no jurisdiction owns.
Three reasons this is harder than it sounds
Penal judgments do not travel. This is the serious doctrinal obstacle. Courts have long declined to enforce the penal and revenue judgments of other states, and a bounty attached to a statutory prohibition looks penal no matter how it is packaged. Whether this machinery is available turns almost entirely on whether the claim can be characterised as a private civil action — the qui tam posture, a relator suing in their own name — rather than as one government collecting another government’s fine. I think that characterisation is arguable. I do not think it is safe, and anyone drafting this should treat it as the central question rather than a technicality.
Public policy is an escape hatch and it is deliberately wide. Article V(2)(b) of the New York Convention lets a state refuse enforcement where it would be contrary to that state’s own public policy, and the phrase is read against each country’s own standards rather than a transnational one. Any state that wishes to shelter frontier AI work has a ready-made and entirely lawful way to decline. The convention makes enforcement easy among the willing. It does not compel the unwilling, and I should not imply otherwise.
Arbitral neutrality is not free. It is tempting to say arbitrators have no stake because they collect their fee either way. The standard criticism of commercial arbitration says close to the opposite: arbitrators depend on repeat appointments, and the repeat players are the institutional parties. In this design the institutional repeat players would be the insurers — the very parties whose payouts are at issue. That is a structural bias pointed against the individual claimant, and it would need answering with appointment rules rather than with optimism about fee structures.
The overselling I want to avoid: this lowers the cost of joining, which is not the same as making states want to join. The binding constraint on international AI governance is not that regulators are expensive. It is that some governments believe frontier capability is a strategic asset and do not wish to slow it down. No amount of cheapness fixes that. What the cheapness buys is that “we cannot afford this” stops being an available excuse for the countries whose objection is budgetary rather than strategic, which is most of them. There is also a frame worth having for what is being asked here, which is not a world government but one more overlapping layer in a world that already has several.
Enforcement as an export industry
There is a better argument than cheapness available here, and it occurred to me late: for a poor country, this is not a cost centre. It is a plausible export.
Bounty hunting in this design is investigative and analytical work — document review, financial forensics, technical assessment, case preparation — and almost none of it requires being physically near the target. The award, though, is denominated in the target’s currency and calibrated to the target’s salary. Two and a quarter million dollars is a nice year in the Bay Area and a generational sum almost anywhere else. The same claim supports a far larger and more patient investigative team in Manila or Nairobi or Chisinau than it does in Palo Alto, which means the marginal economics of pursuing a difficult case are simply better outside the rich world.
This is not speculative, because the industry already exists in miniature and already has this geography. Bug bounty hunting is global, legal, remote, and paid in rich-world money — and the same award that is a useful side income in California is a career in Manila. People respond to that exactly as you would expect: India, not the United States, is the single largest source of registered hackers on HackerOne.
What a bounty is worth, by country
Top bug bounty hunters in India earn around sixteen times the local average software engineer’s salary. Argentina is about fifteen-and-a-half, Egypt around eight, the Philippines above five — against roughly 2.4 in the United States and 1.8 in Germany.
There is a pleasing symmetry in it. Cybercrime concentrates where technical education is strong, local wages are low, and enforcement against foreign-victim offences is weak. A bounty industry needs the first two conditions and inverts the third: the same labour pool, aimed at the same rich-country targets, paid legally and for finding misconduct rather than committing it. A country currently exporting fraud has most of the inputs for exporting enforcement.
That changes the pitch. “This is cheap to adopt” answers an objection. “Your graduates could earn hard currency doing this” is an argument for adoption, and it is aimed at exactly the countries whose reluctance is fiscal rather than strategic.
I want to be careful about how much weight this bears, because it is the sort of idea that is more fun than it is load-bearing.
The evidence still originates with insiders. Bug bounty works because the target system is reachable from anywhere. Frontier misconduct is visible mainly to colleagues, who are wherever the lab is. An offshore firm cannot generate that observation; what it can do is receive it and then perform the expensive work of turning a nervous suspicion into an admissible claim — forensic reconstruction, documentation, funding, and carrying the case. That is a real profession, roughly what the qui tam relator’s bar and the litigation-finance industry already do. It is not “poor countries hunting rich targets” in the buccaneering sense, and I should not let the phrase run away with me.
Standing has to be engineered. A claimant in one country pursuing a claim arising in another needs a forum that will hear them, which brings back every question in the previous section, plus the separate one of whether such claims can be assigned to a firm at all.
And a global claims industry with low local costs is exactly what produces a flood of weak claims. If filing is cheap and the upside is enormous, volume follows, and most of that volume will be worthless. That is page 12’s problem with a much larger denominator, and it argues for fee-shifting and a serious evidentiary threshold rather than against the industry existing.
The ugly parts
Extraterritorial enforcement is the part of this argument I am least comfortable with, and it deserves to be stated plainly rather than folded into a subordinate clause.
For unilateral enforcement to work, a state has to assert that its statute binds conduct that occurred entirely outside its territory, carried out by people who are not its nationals, on the theory that the conduct touched its markets, its payment systems, its cloud infrastructure, or its citizens. There is real precedent for this — anti-bribery enforcement against foreign firms and the dollar-clearing jurisdiction asserted in financial crime cases both work exactly this way, and both are broadly accepted by the states on the receiving end, which is to say tolerated.
But precedent is not the same as legitimacy, and I do not want to pretend the question is closed by pointing at the FCPA. What is being proposed is that one government’s view of which research is dangerous should be enforceable against researchers who never agreed to it, in courts they cannot vote for.
Where I actually come down
Having set the objection out at full strength, I should say that I am more comfortable with it than the last few paragraphs suggest, and it would be cowardly to leave the section at “this troubles me” and move on.
Three things move me. The first is that this is not a novel power being invented for AI. The United States asserts it routinely — securities law, sanctions, export controls, anti-bribery, dollar clearing — and the international system has absorbed it without collapsing. The second is that the affected population is extraordinarily small. There are a few thousand people on earth doing frontier work at any given moment. Compare that to the tax regime I described above, which reaches millions of ordinary dual nationals who are not doing anything interesting at all. As extraterritorial impositions go, this one has a remarkably narrow footprint. The third is the magnitude of what is being insured against, which is the argument of this entire site and which I will not re-run here.
There is a specific escalation fear attached to all this that I think deserves deflating rather than answering solemnly: the worry that a bounty claim reaching a Chinese national, or an American one, touches off a great-power confrontation.
Picture what that scenario requires. Two nuclear-armed states, with several trillion dollars of annual trade between them, going to the brink over a Tsinghua graduate or a second-year PhD candidate at Yale. It is Helen of Troy, except Helen is a postdoc with a visa problem and an unusual insurance premium. The face that launched a thousand ships, now launching an arbitration.
And notice what the original story actually shows, because it is the better point. Helen was not the cause of that war. She was the pretext. The Achaeans came for power, plunder and the obligations of a coalition already sworn, and if she had never existed something else would have served. States that want a confrontation locate a reason. States that do not, do not — and no policy anywhere clears the bar of “could never be invoked as a pretext by somebody already looking for one.” That objection applies to every statute ever drafted.
We have also, usefully, run something close to this experiment. Canada arrested the chief financial officer of Huawei on an American warrant; China retaliated by detaining two Canadians; the standoff ran for very nearly three years. That is a far more provocative act than anything proposed here, aimed at a far more prominent person. It was a serious diplomatic crisis. It was not a war, and nobody sensible expected one.
The Meng Wanzhou standoff, in dates
December 2018: Canada arrests Meng Wanzhou — CFO of Huawei, daughter of its founder — at Vancouver airport on a United States extradition request, for alleged sanctions violations.
Nine days later: China detains two Canadian citizens, Michael Kovrig and Michael Spavor.
September 2021: after 1,020 days , it ends with a deferred prosecution agreement and three aeroplanes going home on the same day.
I do want to keep the sting in that example rather than use it as reassurance, because the honest reading is uncomfortable. “No war” is not “no cost.” Two men who had nothing whatever to do with Huawei, sanctions, or Meng spent very nearly three years in Chinese detention because of a decision taken in Vancouver on an American warrant. The system absorbed the shock by passing it to bystanders, which is the same pattern as every other collateral-damage observation on this page. That is the price of extraterritorial enforcement, it is real, and it lands on people with no part in the dispute.
One asymmetry makes me more relaxed than that story alone would warrant. Meng was detained. What this mechanism generates is a bill — a claim against a policy, arbitrated, paid by an insurer. If arresting the CFO of Huawei at an airport did not produce a war, it is difficult to construct the path by which a repriced premium and a civil award does. That is the whole point of deterrence arriving as a bill rather than as a raid: it gives the other side much less to react to.
So here is the test, and I want to pass it in public rather than quietly fail it. Would I accept the same statute pointed the other way? If China enacted an extinction bounty regime of the kind described on this site, and a US citizen fell within the lawful reach of Chinese courts, would I accept that as a legitimate exercise of the principle I am asking for?
Yes. I think the cost of that is justified, and I think saying otherwise would mean I was never arguing for a principle at all — only for my own side holding an advantage. A rule you would accept only when it runs in your favour is not a rule.
There is a stronger version of this argument that I only saw once I had written the concession out. Declining to endorse extraterritorial enforcement does not abolish it. It is already here, asserted by whoever has the leverage to assert it, and my personal discomfort removes precisely none of it. The realistic choice is not between extraterritorial reach and its absence. It is between a reciprocal version with a defined trigger, which anybody can invoke and therefore everybody can anticipate, and the status quo, in which the same power operates with no reciprocity and no principle beyond who is strongest. I prefer the first. That is a lower bar than legitimacy, and I am claiming to clear it rather than to clear something higher.
What I still hold against it
Three costs survive, and accepting the principle does not dissolve them.
“Lawful reach” is doing enormous work in that sentence. Legal systems differ in how easily their machinery can be turned to a pretext, and a statute defining which research is dangerous is a statute that can be aimed at a researcher for reasons having nothing to do with safety. The small population cuts both ways here: few enough people that the collateral damage is limited, and few enough that each individual is valuable enough to be worth acquiring for other reasons.
The argument form is one I distrust. “The stakes are enormous, so the usual objections weaken” is the skeleton of a great many bad arguments, and I have complained about versions of it elsewhere on this site. I think it survives here only because what is being accepted is bounded and specific — a narrow reciprocal jurisdiction over one defined activity, with a fine at the end of it rather than a prison — and not a general licence to do whatever the magnitude seems to justify. If the bounds came off, the argument would go with them.
This is the section where the disclaimer at the top of the page is doing real work, and I mean that literally rather than as a formality. What is on this page is an argument about what a statute could look like. It is not directed at any identifiable person, it names nobody, and it is not an invitation to anyone to act against anybody — see non-targeting . Any real version of this would require democratic deliberation, statutory authority, and safeguards designed specifically against the misuse I have just spent three paragraphs describing. I would rather write the misuse down myself than have it discovered in the drafting.
Extradition, and why it matters less than I first thought
Extradition is mostly unavailable, and the reasons are sound. States do not generally hand over their own nationals for conduct that was lawful where it happened, and dual criminality is a requirement in most extradition treaties for good reasons that I would not want removed.
I originally wrote this passage as a lament. Having worked through the borrowed-forum material above, I think it was a section about the wrong instrument.
Extradition is how you move a body for a criminal proceeding. This mechanism does not want a body. It wants an award enforceable against an insurance policy. The things that travel well across borders are money, contracts, and arbitral awards — the last of these across 172 states. The things that travel badly are defendants and penal judgments. A design that leans entirely on the first list and never requests anything from the second is not working around a limitation; it is declining to need the part that causes all the trouble.
The Meng Wanzhou episode makes the point better than I can. What produced that crisis was an extradition request. The arrest, the hostage retaliation, the 1,020 days — all of it followed from one state asking another to physically hand over a person. A regime that never makes that request never generates that class of incident. Extradition being off the table is a feature of this proposal and I should have presented it as one.
What survives, restated properly, is a coverage problem rather than a custody problem — and it is the more serious of the two.
The people this mechanism reaches are the ones holding policies, or with assets or employers inside an adopting jurisdiction. That set correlates uncomfortably well with being cooperative in the first place. A determined offender in a non-adopting state who simply declines to insure, holds nothing reachable, and never travels is outside the whole apparatus, while an ordinary researcher with a mortgage, a broker and a conference schedule is thoroughly inside it. Reciprocity does not fix that — a symmetric rule with regressive incidence is still regressive, just regressive in every direction at once.
But notice where that problem now lives. It is not a question about enforcement reach; it is a question about how much of the world is covered and whether going uncovered is made unattractive enough. Those are the subjects of the bloc-size section below and of the voluntary-or-mandatory note , where I argue for leaving the uninsured position legally available and financially miserable. I do not think that fully solves it. I do think it is a better place for the problem to sit than in a discussion of who can be put on an aeroplane.
How large does the bloc need to be
Not universal. That is the useful finding, and it follows from the tax case.
The relevant threshold is not the fraction of states that adopt, but the fraction of revenue that becomes unreachable if you relocate. Frontier development is expensive, and the money comes from selling into wealthy consumer and enterprise markets. A lab that relocates to escape liability has to be willing to give up selling to the markets it escaped from — and if those markets are where the customers are, the relocation is not a tax arbitrage, it is a business decision to become a much smaller company.
That is the same shape as the Brussels effect, which is worth a paragraph of its own because it is the most direct precedent this page has and it is not widely known outside trade law.
The term is Anu Bradford’s, from a 2012 article she later expanded into a book. The observation is that the European Union routinely sets global standards without signing a treaty, winning an argument, or asking anyone. A firm that wants access to the EU market must meet EU rules; having rebuilt the product to meet them, it usually finds that running two versions costs more than running one, so the stricter standard propagates everywhere the firm operates. Bradford calls this the de facto Brussels effect. Data protection went that way. Chemicals and product safety go that way routinely.
Then comes the part I find genuinely clever, because it is where the thing becomes self-propagating. Firms that have already absorbed the cost of compliance have an incentive to lobby their own governments to impose the same rules domestically — not out of conviction, but to stop non-exporting competitors at home from enjoying an advantage they no longer have. Bradford calls that the de jure Brussels effect: the standard gets written into other countries’ law by their own industries. That is an adoption path that requires no diplomacy at all, and it is the one I would expect a bounty regime to travel down.
Bradford is precise about when this works, and her conditions are worth checking against this proposal rather than waving at.
Bradford's conditions for the effect to fire
A jurisdiction needs a large domestic market, significant regulatory capacity, and a propensity to enforce strict rules over inelastic targets — consumer markets rather than capital, which can simply leave.
And the effect only fires when the target’s conduct is nondivisible, which she defines as when it is “not legally or technically feasible, or economically viable, for the firm to maintain different standards in different markets.”
On non-divisibility, frontier AI scores unusually well. You train one model and serve it globally; the weights do not come in a European variant and a domestic variant, and a lab maintaining a separate compliant pipeline for one bloc is paying twice for the most expensive thing it does. The elasticity condition is where I am less comfortable, and I should say so plainly: Bradford’s framework predicts the effect works badly on targets that can relocate, and people are more elastic than consumer goods. A researcher can move. That is the same objection this page keeps running into from different directions, and the Brussels effect does not dissolve it — what it does is suggest the pressure should be applied to the thing that cannot move, which is the lab’s access to markets, capital, and customers, rather than to the researcher’s body.
The limits are worth stating. The Brussels effect works best where compliance is a fixed cost of building the product and worst where the requirement is separable — where you can run one version of the business inside the bloc and another outside it. Research is separable in exactly that way. A lab can straightforwardly do its frontier training in one jurisdiction and its selling in another, and nothing about the finished product reveals where the training ran. So market access is a real lever and a partial one, and it constrains commercial labs far more tightly than it constrains anything funded for strategic rather than commercial reasons.
The residue
Some states will not join. Some will join and not enforce. Work funded by a government that considers frontier capability a national security asset will not be reached by any of this, and I should not pretend otherwise — I said in the previous page that state programs fall outside what this mechanism can do, and nothing in this one recovers them.
So what is left is a mechanism that raises the cost of frontier work across most of the commercial world, does not touch the most determined state actors, and therefore slows the field rather than stopping it.
I want to be careful about how I take that, because the temptation is to treat it as a refutation and it is not one. Read against Part I , a delay mechanism is closer to the point than a prevention mechanism would be.
I am not going to defend it by promising that the delay gets used well. The version of this argument that says buy a decade and interpretability will mature, or the philosophy of mind will produce something better than a similarity prior is a hedge, and I do not believe it. It makes the value of delay contingent on a research programme nobody can schedule. If that is the case for slowing down, the case is weak.
Here is the one I actually hold, and it has two parts.
Delay compounds. One country adopts and the field is slowed by a year, with coverage full of holes. That year is a year in which a second country can adopt, and the next increment is bought at lower cost because the first one already shifted where the work happens and what it costs. Two more years, with slightly less incomplete coverage. Then five, with coverage that is actually fairly good. The question is not whether any single intervention is watertight — none of them ever is — but whether each increment of delay buys a larger one than it cost. Where it does, the series does not converge to a fixed total. It just keeps going, and “keeps going” is the only form long-term survival has ever taken. No civilisation is permanently safe. They are all only still here.
I want to be honest that this is a claim about a rate and not a theorem. Whether the increments grow or shrink depends on whether coverage broadens faster than capability advances, and I cannot prove which way that goes. If the increments shrink geometrically, the sum is finite and the thing arrives anyway, later.
Which brings me to the part that does not depend on any of that. A finite delay is not a consolation prize. If the increments do shrink, and the sum is forty years rather than forever, those are forty years in which the universe contains people who are experiencing things. On the account this site is built on , that is not a lesser outcome awaiting a better one. It is the thing of value, delivered, in the quantity that was available.
Nobody argues that medicine is pointless because the mortality rate is one per person. Public health has never cured death; it has pushed it back by decades, and those decades are the entire achievement rather than a down payment on something else. I am making the same claim about this. If extinction bounties buy humanity another century and then fail, the century happened. The people in it were real, their experiences occurred, and no later failure reaches back and un-does them.
So the case for delay does not require the mechanism to be watertight, and it does not require anybody to solve consciousness on a deadline. It requires only that the mechanism be expensive enough, across enough of the world, to change the rate — and that years of ordinary human life be worth having for their own sake, which I take to be the least controversial thing on this website.
That is a considerably more modest claim than the one this page opened by defending. I think it is the one that survives.