25 September 2026

Buying Time Against AI Proliferation: The Economics of Governed Access

RAND Corporation | Tobias Sytsma

A formal model of artificial intelligence (AI) adoption and proliferation developed by the RAND Corporation reveals that compliance burdens on governed access channels can inadvertently accelerate uncontrolled AI proliferation. When policies raise the cost of controlled frontier access without targeting ungoverned alternatives, users frequently redirect their adoption toward unmonitored channels.

This demand-side framework evaluates how price dynamics, rather than technical capability thresholds, dictate user choices across governed and ungoverned pathways. Three critical indicators predict policy success: user responsiveness to cost differences, the ability to raise ungoverned access costs, and switching costs. However, once AI capabilities advance far enough to become highly valuable, cost-shifting policies lose all traction. Governance loses all leverage. Consequently, future regulatory frameworks must track the observable cost of access rather than focusing solely on technical milestones to predict and manage proliferation risks across global networks and markets effectively.

Comment

The shift from supply-side restrictions to demand-side price dynamics exposes the limits of unilateral export controls, such as the US Bureau of Industry and Security restrictions on Nvidia H100 GPUs. While these hardware bottlenecks temporarily restrict physical access to TSMC-fabricated silicon, they incentivise the rapid development of decentralised, low-compute training methodologies. This economic pressure accelerates the optimization of open-source models like Meta's Llama series, which bypass governed cloud environments entirely. Washington's attempts to gatekeep frontier AI capabilities through ASML lithography restrictions and GPU export limits inadvertently catalyse a highly resilient, distributed ecosystem of unmonitored software alternatives.

Downstream, this software-driven proliferation undermines the efficacy of multilateral non-proliferation regimes like the Wassenaar Arrangement, which are structurally unsuited for digital assets. As unmonitored models achieve parity with proprietary systems, non-aligned actors can deploy dual-use cyber-warfare or autonomous targeting algorithms without relying on Western cloud providers. This software diffusion forces US Cyber Command to assume that adversaries possess sophisticated, localized AI planning tools capable of operating entirely offline.

Strategic Question for Discussion
If the proliferation of open-source models like Meta's Llama series renders traditional hardware-centric export controls obsolete, what alternative mechanisms can the Wassenaar Arrangement employ to monitor dual-use software capabilities without stifling commercial innovation?
The trajectory indicates that traditional export control regimes will likely shift toward cryptographic verification and hardware-enabled telemetry embedded directly into next-generation silicon. My assessment is that instead of regulating software distribution, future governance will rely on on-chip monitoring systems to verify compliance at the compute layer. This approach, however, risks driving adversarial development toward entirely unaligned foundry ecosystems that bypass Western supply chains.
Share your assessment in the comments below.