Commentary

AI 2040's concrete plan to slow down AI: chip counts, 1 Mbps data pipes, and Faraday cages

Sep 11, 2026

Key Points

  • AI 2040 proposes delaying superintelligence to 2040 by capping chip deployment at data centers, blocking new training runs while permitting inference on existing models.
  • The framework borrows from nuclear nonproliferation playbooks: chip counts, supply chain transparency, 1 Mbps bandwidth caps on R&D facilities, and dual US-China encryption for frontier model weights.
  • International enforcement remains fragile; if compute-optimal training scales dramatically or secret projects multiply under regulation, the entire architecture collapses.

Summary

AI 2040's Concrete Plan to Slow Down AI

AI 2040, a policy initiative backed by nonprofits focused on existential risk, proposes a framework to delay superintelligence by roughly a decade—reaching it in 2040 rather than 2028—under government control. The plan is not to stop AI development but to maintain inference on current models while blocking new training runs that could produce more capable systems.

Congress is stirring. The Wall Street Journal reports lawmakers are suddenly focused on AI doomsday scenarios. Anti-AI sentiment is building, though it remains fragmented: protests around AI risk exist but remain small (150 people in Chapel Hill, North Carolina, tracking toward 10,000 predicted by year-end), while deflock activism from artists has proven more mobilized. The irony is sharp: AI 2040 proposes the opposite of grassroots action—it hardening data centers with government oversight, not dismantling them.

The compute cap mechanism

AI 2040's core lever is controlling chip deployment. Any facility holding more than 10,000 H100-equivalent GPUs (roughly $100 million in equipment) would face mandatory restrictions. Physical chip counts are straightforward to enforce: inspectors enter the data center, count the NVIDIA chips, and issue permits or denials based on how the hardware will be used.

Training would pause. No new frontier models, no R&D experiments. Facilities could only run inference on existing models—current versions of GPT, Claude, Grok, and their peers. Independent auditors, probably government agencies or specialized NGOs, would verify that workloads match declared permits. The goal: hardware innovation can continue, but algorithmic breakthroughs that could leak to secret projects are blocked. Models improve by adding more chips, not through clever tricks.

Supply chain transparency and physical controls

Semiconductor companies and major data center operators would disclose sales records. Who buys chips, where they go afterward. Large chip transfers would only flow to registered counterparties. Foreign inspectors would conduct routine on-site chip counts. The framework borrows from decades of nuclear nonproliferation work—countries declare arsenals, share inventory, coordinate oversight.

New R&D facilities would face nation-state-level physical security. Faraday cages to prevent external communication. Air-gapped networks. Controlled access. Most striking: any external communication would be capped at 1 Mbps. That bandwidth bottleneck serves a dual purpose. It allows researchers to send training instructions inward but makes model weight theft impractical—copying a 100-terabyte model across a 1 Mbps pipe would take years. Theft becomes obvious: if the pipe runs at full capacity for months, someone is stealing weights.

When frontier models move from R&D facilities to inference centers, weights would be encrypted independently by both the US and China, then physically escorted by representatives of both countries. Frontier models would also be deliberately made larger than compute-optimal—100 terabytes instead of streamlined to one terabyte—to make smuggling harder.

Disclosure and internal-external parity

Labs would share model specifications, compute allocation for internal use, and qualitative descriptions of model power. The idea is to shrink the gap between what researchers use internally and what customers can buy. Current practice—where labs deploy Astra internally while selling older models externally—would be restricted. This has crossover appeal with businesses competing in web design or legal services who complain about unfair asymmetry.

The timeline

The goal is not AGI prevention but delay. AI 2040 proposes reaching human-expert-level capabilities around 2035, holding at that level for five years, then unlocking superintelligence in 2040. Many researchers estimate human-level performance could arrive by 2027 or 2028, which AI 2040 sees as premature. The proposal is a slowdown with endpoint—not a halt.

Tension: enforceability and unintended consequences

The framework faces two hard problems. First, international coordination is fragile. Countries routinely defect on nonproliferation agreements. Nuclear oversight has worked for 60 years, but it operates in an environment where fissile material is scarce and localized. GPUs are infinitely more widespread. Compute is sitting in data centers globally, and incentives to hide research would intensify under hard caps. If regulation tightens, secret projects multiply—countries, militaries, and private actors could pursue breakthroughs in basements and bunkers. Nuclear precedent suggests people keep trying; the framework doesn't prevent that.

Second, scale may be irreversible. Most researchers believe superintelligence requires massive compute—big heat signatures, visible from space. But if someone discovers a Python script that runs AGI on a laptop, or if researchers crack compute-optimal training dramatically, the entire enforcement architecture collapses. Even Ilya Sutskever, recently starting NeoLab with NVIDIA's backing, is pursuing scale despite his reputation for orthogonal thinking.

The tradeoffs

For safety advocates, AI 2040 offers a concrete path. It's not hand-waving about "we need to talk about it." It's chip counts, bandwidth limits, and escrow arrangements.

For skeptics, it reads as authoritarian overreach. The plan restricts what people can do with their own computers—even $100 million computers. It could entrench a few major players, delay economic gains from aligned AI, or prove self-defeating if the existential risk fades and society regrets the slowdown. (If alignment is solved and x-risk drops, tighter regulation might feel as relevant as asteroid-impact policy.)

The calculation is unresolved. Current models can do substantial work. New uses surface even for non-leading-edge systems. A slowdown to 2040 would not prevent interesting applications, but it would delay the next capability jump. Whether that's optimized restraint or missed upside remains contested. The proposal's value lies in its specificity—it gives shape to what a concrete safety policy might look like, rather than leaving the conversation abstract.

Every deal, every interview. 5 minutes.

TBPN Digest delivers summaries of the latest fundraises, interviews and tech news from TBPN, every weekday.