Your Undivided Attention
Your Undivided Attention

We Need AI Treaties. This is How We Get Them

To agree to international AI red lines, we need to build the technology that makes it possible to adhere to them. In this episode, Tristan sits down with two experts in this field to discuss the kinds of verification technology we need for AI, the challenges of building it, and the world it could un

Featured Speakers

Janet Egan Guest

Topics Discussed

Episode Summary

Executive Summary: The episode argues that AI governance should borrow from nuclear nonproliferation: because trust is low, verification technology is essential. Guests Tim Fist and Janet Egan explain how chip telemetry, location attestation, cryptography, inspections, and data-center monitoring could let governments and labs verify AI slowdowns or red lines without exposing sensitive IP, while noting the field is immature, under-resourced, and time-constrained by rapid AI progress.

Main Topics: Why AI coordination matters globally (Priority: 5/5): The hosts and guests argue AI risks and benefits will cross borders regardless of which country develops the most advanced systems first, making international coordination necessary. Nuclear verification as the historical template (Priority: 5/5): The discussion uses nuclear test bans and arms control as proof that verification technology can enable agreements even among adversaries with low trust. Compute as the most governable AI chokepoint (Priority: 5/5): Compute is presented as the best target for verification because chips are physical, concentrated in a narrow supply chain, and required for frontier AI. Verification tools: chips, telemetry, cryptography, and inspections (Priority: 5/5): The guests outline concrete mechanisms such as trusted execution environments, location verification, telemetry, cryptographic attestations, retrofit devices, and human inspections. Implementation constraints and brittleness (Priority: 4/5): Current verification systems are described as technically promising but fragile, with tamper-proofing, retrofits, and global coverage still in early research stages. Policy and industry incentives (Priority: 4/5): The conversation highlights conditional export controls, the Chip Security Act, lab self-interest, and the need for government institutions and broader international buy-in. Timeline pressure and the need to start now (Priority: 5/5): Because frontier labs may reach recursive self-improvement within roughly 18 months, the guests argue that imperfect verification infrastructure must be built immediately.

Key Arguments: AI coordination matters because AI impacts will be global even if development begins in one country; risks such as misuse, cyber offense, and loss of control can cross borders. Nuclear nonproliferation succeeded not through trust alone but through verification technologies that made agreements enforceable. The most useful AI verification target is compute, since chips are physical, concentrated, and easier to monitor than data, algorithms, or weights. Trusted execution environments and cryptographic attestation can let a lab prove what ran on a chip without revealing proprietary information. Telemetry from chips can help distinguish training from inference and support claims about how compute is being used. Location verification is already possible on some NVIDIA chips and could be used to detect diversion or smuggling. A workable regime would combine chip-level attestations, data-center monitoring, retrofits, random inspections, and international oversight. The field is tiny and underbuilt; more researchers, red-teamers, chip experts, and government capacity are needed. Policy should use conditional export controls: easier export for chips that are more governable and verifiable. Broad international legitimacy matters; independent verification bodies can reduce suspicion that one side is manipulating the process. The goal is not perfect certainty but making cheating expensive enough that agreements are credible and enforceable. Because design and manufacturing cycles take time, waiting for perfect tools could make coordination impossible once advanced AI arrives.

Data Points: Countries with nuclear weapons today: 9 - Used to show nuclear proliferation was limited through verification and diplomacy over decades. Countries that had atomic bombs at the time of Oppenheimer quote: 5 - The comparison point in 1965 when he said it was too late to stop proliferation. Seismic monitoring stations: 300 stations across up to 100 countries - Described as the network enabling verification for underground nuclear test bans. Nuclear test ban signatories: every single signatory - The transcript says signatories to the treaty did not engage in nuclear testing. Flight-time threshold for dangerous missiles: less than 10 minutes - The Intermediate Range Nuclear Forces Treaty targeted this category of missiles. Share of AI chips made by NVIDIA: about 90% - Used to illustrate concentration in the AI chip supply chain. Share of those chips manufactured by TSMC: about 90% - Highlighted as part of the narrow AI hardware supply chain. Share of chips used by major US cloud providers: around 70% - Used to show that a small number of actors host much of frontier compute. Estimated AI chip stock in the world: about 20 million - Referenced in estimating the scale of potential inspections. Inspections needed for 90% confidence: around 10,000 per year - Estimated for global AI chip accounting with the current stock of chips. IAEA annual inspections: about 3,000 per year - Provided as a comparison point for nuclear verification scale. Frontier lab timeline to RSI: within 18 months - A quoted estimate from labs about reaching recursive self-improvement. Chip design lead time: about 1 year before manufacture - New chip designs must be locked well before fabrication begins. Time to volume production: another year - Additional time needed before new chips reach large-scale deployment. CACE staffing: about 30 staff - The U.S. Center for AI Standards and Innovation is described as very small. CACE budget: about $15 million - Used to show limited government capacity for AI risk tracking. Estimated number of people directly working on this verification problem: less than 50 - One guest says the technical field is extremely small.

Pivotal Quotes: "20 years too late. It should have been done the day after Trinity." — Robert Oppenheimer: Cited in the opening to contrast pessimism about nuclear proliferation with the later success of verification and disarmament. "Trust but verify." — Ronald Reagan / cited Russian proverb: Used to frame the core challenge of AI governance: agreements need verification, not just promises. "The one thing I'll go back to double-click on... we're also seeing a policy window open between the US and China" — Janet Egan: Explains why the current moment may be unusually favorable for building verification regimes and diplomatic channels.

Implications: The episode frames AI governance as a buildable technical problem, not an impossibility. For listeners and industry, the message is to fund verification R&D now, push for chip/location attestation and inspections, and use imperfect tools to make future AI agreements credible before capabilities outrun policy.

🔓 Sign Up for Unlimited Episode Search

About Your Undivided Attention

View all episodes from Your Undivided Attention