Epistemic status: half a day of hackathon research; I haven’t yet run this past anyone who works in export controls or chip security.
Yesterday, I participated in Bluedot’s Breaking Barriers to AI Safety Hackathon in SF and my project A workable blueprint for a chip licensing regime won first place! I had just finished my first-ever Bluedot course on AGI Strategy the day prior. I got absolutely obsessed learning about chip governance towards the end of the course and I wanted to explore the topic further at the hackathon.
The goal for my project was to put together a chip licensing proposal for policymakers. It needed to be brief, easily understandable, and persuasive. I also included a one-pager version for easy sharing and digesting.
One of the key things I wanted to do is outline how you get flexHEG (Flexible Hardware-Enabled Guarantees) from zero to one? Who are the different actors involved and what are their motivations? Given that time is limited, what’s the fastest path available?
I looked at current legislation like the Chip Security Act which seemed to have lost steam since March of this year. I stumbled upon another potential path: the rulemaking powers available to the Department of Commerce’s Bureau of Industry and Security, which can amend export controls by published rule (including license exceptions) without touching Congress. That’s a mouthful. But the point is, this rulemaking approach seems capable of creating exactly what I was looking for: an incentive.
Here’s the problem: while there are standards and designs for flexHEG chips, it’s not something that has been developed at an industrial scale.
Before moving forward, I’m realizing I haven’t even explained what these are. Here’s Fable’s explanation right before it kicked me back to Opus for some reason:
A sealed on-chip governor enforces a signed compute budget that counts down as the chip runs; renewal takes a cryptographic signature, so a smuggled chip becomes a brick.
Got it? Okay. So, academia and philanthropy is working on the challenge, publishing research, setting standards, and developing prototypes. But this will take forever, and by their own account, there needs to be a lot more funding. So I wondered, who out there is wicked smaht about chips, has resources, and is currently prevented from selling stuff other people want to buy because the chips can’t be controlled? Chipmakers!
That’s how the proposal started taking shape. China hawks in the federal government make it difficult for chipmakers like Nvidia to export to middle countries: they don’t want the chips to end up in the wrong hands. FlexHEG represents a way to control chips once they’ve left the border. This is a first. So if the Department of Commerce allows export of chips that meet this FlexHEG standard, there is a potential huge market out there gated by the development and advancement of this technology. We then have the beginnings of a win for everyone at the table.
China hawks lock down chips but not at the expense of the domestic chip industry.
Chipmakers get to sell their wares and entrench CUDA
Middle markets get access to compute.
Federal accelerationists get to go “USA! USA! USA!”
AI safety proponents get a key compute governance technology developed and mass produced.
For those wondering about what to do about current ungoverned compute, I outline a potential buyback program.
The big caveat is that all of this only works if the technology is substantially resistant to tampering. Other solutions that could be layered on top include things like on-site inspections and geolocation. But it all requires the keys living on chips to remain there without being compromised.
I also outlined other challenges to load-bearing assumptions including countries continuing to prefer American governed compute to ungoverned Chinese compute, chipmakers refusing to invest in R&D to take advantage of a rule change that could change with the next administration or a shift in geopolitical winds.
The blueprint itself is the culmination of half a day’s desk research and frantic, last-minute web design from Claude. My “action plan” from Bluedot included actually going out and talking to experts and knowledgeable people in the field over the next thirty days. I haven’t done that yet. It’s entirely possible I talk to an expert and they tell me, as politely as possible, that the plan is one of the most asinine things they have ever heard. But that’s progress, baby!
I’m incredibly grateful to everyone I met this week, all the kind and talented people who are “just doing stuff” out in the open, and I’m looking forward to learning (and doing!) more.
P.S., if you are someone knows a thing about chips or exports, hit me up!
Bluedot SF hackathon submission: A workable blueprint for a chip licensing regime
Epistemic status: half a day of hackathon research; I haven’t yet run this past anyone who works in export controls or chip security.
Yesterday, I participated in Bluedot’s Breaking Barriers to AI Safety Hackathon in SF and my project A workable blueprint for a chip licensing regime won first place! I had just finished my first-ever Bluedot course on AGI Strategy the day prior. I got absolutely obsessed learning about chip governance towards the end of the course and I wanted to explore the topic further at the hackathon.
The goal for my project was to put together a chip licensing proposal for policymakers. It needed to be brief, easily understandable, and persuasive. I also included a one-pager version for easy sharing and digesting.
One of the key things I wanted to do is outline how you get flexHEG (Flexible Hardware-Enabled Guarantees) from zero to one? Who are the different actors involved and what are their motivations? Given that time is limited, what’s the fastest path available?
I looked at current legislation like the Chip Security Act which seemed to have lost steam since March of this year. I stumbled upon another potential path: the rulemaking powers available to the Department of Commerce’s Bureau of Industry and Security, which can amend export controls by published rule (including license exceptions) without touching Congress. That’s a mouthful. But the point is, this rulemaking approach seems capable of creating exactly what I was looking for: an incentive.
Here’s the problem: while there are standards and designs for flexHEG chips, it’s not something that has been developed at an industrial scale.
Before moving forward, I’m realizing I haven’t even explained what these are. Here’s Fable’s explanation right before it kicked me back to Opus for some reason:
Also see RAND’s Hardware-Enabled Governance Mechanisms
Got it? Okay. So, academia and philanthropy is working on the challenge, publishing research, setting standards, and developing prototypes. But this will take forever, and by their own account, there needs to be a lot more funding. So I wondered, who out there is wicked smaht about chips, has resources, and is currently prevented from selling stuff other people want to buy because the chips can’t be controlled? Chipmakers!
That’s how the proposal started taking shape. China hawks in the federal government make it difficult for chipmakers like Nvidia to export to middle countries: they don’t want the chips to end up in the wrong hands. FlexHEG represents a way to control chips once they’ve left the border. This is a first. So if the Department of Commerce allows export of chips that meet this FlexHEG standard, there is a potential huge market out there gated by the development and advancement of this technology. We then have the beginnings of a win for everyone at the table.
China hawks lock down chips but not at the expense of the domestic chip industry.
Chipmakers get to sell their wares and entrench CUDA
Middle markets get access to compute.
Federal accelerationists get to go “USA! USA! USA!”
AI safety proponents get a key compute governance technology developed and mass produced.
For those wondering about what to do about current ungoverned compute, I outline a potential buyback program.
The big caveat is that all of this only works if the technology is substantially resistant to tampering. Other solutions that could be layered on top include things like on-site inspections and geolocation. But it all requires the keys living on chips to remain there without being compromised.
I also outlined other challenges to load-bearing assumptions including countries continuing to prefer American governed compute to ungoverned Chinese compute, chipmakers refusing to invest in R&D to take advantage of a rule change that could change with the next administration or a shift in geopolitical winds.
The blueprint itself is the culmination of half a day’s desk research and frantic, last-minute web design from Claude. My “action plan” from Bluedot included actually going out and talking to experts and knowledgeable people in the field over the next thirty days. I haven’t done that yet. It’s entirely possible I talk to an expert and they tell me, as politely as possible, that the plan is one of the most asinine things they have ever heard. But that’s progress, baby!
I’m incredibly grateful to everyone I met this week, all the kind and talented people who are “just doing stuff” out in the open, and I’m looking forward to learning (and doing!) more.
P.S., if you are someone knows a thing about chips or exports, hit me up!