THE PIPELINE IS THE SWITCH
Three Control Architectures for Frontier AI and the Market That Decides Between Them
THE PIPELINE IS THE SWITCH
Three Control Architectures for Frontier AI and the Market That Decides Between Them
The AI control debate has misdiagnosed its own subject. The contest is not open versus closed, and it is not American versus Chinese capability. It is a contest among three incompatible control architectures: China’s, which embeds the switch in the model weights and renews it by release cadence; the emerging Western regime, which embeds the switch in silicon and custody and enforces it by jurisdiction; and the equity-entanglement model, which places the switch in the cap table. Each is strong exactly where the others are weak, and none of them controls artifacts, because artifacts cannot be controlled. All three control pipelines. The operational conclusion follows directly: the United States cannot suppress the Chinese pipeline and should stop trying. It can build the one thing that pipeline is structurally incapable of producing, which is verifiable provenance, and let regulated markets do the enforcement that export controls cannot.

I. The Misdiagnosis Sometime in the twelve months ending in August 2025, a line crossed. Researchers at MIT and Hugging Face, tallying global downloads of open-weight AI models, found that Chinese model families had taken roughly 17 percent of the total, edging past the American share of just under 16 percent for the first time. The gap has since widened. Alibaba’s Qwen family, already the most downloaded model series on Hugging Face for two consecutive years, has now overtaken Meta’s Llama in cumulative downloads, and by late 2025 Chinese base models accounted for a substantial majority of new fine-tuned and derivative models uploaded to the platform. The four families most responsible, Qwen, DeepSeek, GLM, and the newer entrants clustered around them, did not win this position on capability alone. They won it on distribution: full weights, permissive licenses, and application programming interface pricing running fifteen to thirty times below Western equivalents, with cache-optimized rates that bring effective input costs closer to free than to premium.
Sovereign adopters followed the developers. Singapore’s government-backed national AI program built its latest regional model on Qwen rather than Llama. Malaysia announced that its sovereign AI ecosystem would run on DeepSeek. Across cost-sensitive markets from Nairobi to Sao Paulo, founders and public institutions are building on Chinese foundations, not out of ideological preference but because open plus cheap is the rational procurement answer for a budget-constrained buyer seeking what the trade press now routinely calls AI sovereignty. The adoption picture is not uniform, and it should not be described as though it were: it varies sharply by country, sector, and risk tolerance, and a substantial population of Western enterprises cannot use Chinese weights at all, for provenance and compliance reasons this essay will return to, because they turn out to be the hinge of the argument. But the direction of the trendline is not in serious dispute.
Neither, any longer, is capability. In April 2026, Moonshot’s Kimi K2.6 became the first open-weight model to beat a leading American frontier system on SWE-Bench Pro, a demanding software-engineering benchmark, and Zhipu’s GLM-5.1 posted a comparable result against another Western flagship in the same quarter. On aggregate leaderboards the best Chinese models still trail the top Western proprietary systems by mid-single-digit margins, but the gap has compressed faster than nearly every forecast, and it has compressed under export-control conditions that were designed to prevent exactly this. Zhipu has now trained a frontier-class model entirely on Huawei Ascend silicon, without a single restricted American chip, a fact whose full significance for the control debate becomes clear in Section II.
One concession belongs at the top rather than in a footnote. Download counts measure developer experimentation, not deployed inference volume, and enterprise production workloads in the West still run overwhelmingly on closed American APIs. Anyone who reads the Hugging Face statistics as a market-share figure for the AI economy is overreading them. But that is precisely why the statistics matter: downloads measure where the next generation of builders is forming its habits, its tooling, and its defaults, and defaults are where standards come from. The correct analogy is not revenue share; it is which textbook the students are learning from.
Confronted with this picture, American policy discourse has fractured into three literatures that do not read each other. The first is a free-expression literature, well represented in these pages, which documents how China’s regime of anticipatory censorship has been replicated in the AI domain, subordinating model behavior to state ideology, and treats the embedded restrictions as a harm to open discourse. The second is an industrial-policy literature, exemplified by a March 2026 report prepared for the U.S.-China Economic and Security Review Commission, which warns that growing reliance on Chinese base models is creating long-term dependency on infrastructure with embedded censorship, and that if those models become the world’s default starting point, China will shape the architecture, data formats, and security characteristics of AI systems far beyond its borders. The third is a compute-governance literature, which observes that open weights are copiable digital artifacts, that the encryption export battles of the 1990s settled what border controls achieve against copiable artifacts, and that governance must therefore move down to the hardware layer, where the physical substrate permits verifiable intervention.
Each of these literatures is correct. Each is also partial, in the way the blind men’s descriptions of the elephant were partial, because all three are describing the same object without naming it. The censorship the first literature documents, the dependency the second warns of, and the hardware anchor the third prescribes are not three problems. They are three views of one contest: a contest between rival architectures for controlling frontier AI, in which each side has already made its architectural commitment and is now shipping it. Once the debate is restated in those terms, the policy question stops being how to stop Chinese models, a question with no good answer, and becomes which control architecture the world’s high-value markets will require, a question with a very good answer that the United States is uniquely positioned to supply. The remainder of this essay describes the three architectures, scores them honestly against a common standard, and derives the operational program that follows.
II. Three Architectures A. The switch in the weights: Beijing’s architecture China’s control architecture begins in regulation and ends in the weights. The content rules governing generative AI services in China mandate filtering of politically sensitive output, and the leading labs comply the only way an open-weight publisher can: by compiling compliance into the model before release. Recent benchmark research on political topics has found the resulting restrictions to be language-consistent, equally present in Chinese and English, embedded at the level of the weights themselves, and persistent under local deployment, which is to say trained into the model rather than applied as a removable filter at the API layer. A model downloaded in Lagos or Sao Paulo carries the regime with it. That is the architecture’s defining property: the control travels.
How deep does it go? The honest answer is that the embedded control is a three-layer stack, and the layers have radically different tamper resistance. The top layer is refusal behavior, the model’s trained disposition to decline certain requests, and it is nearly disposable. In March 2026 a pseudonymous developer released an open-source toolkit that removes refusal behavior from more than a hundred open-weight models in minutes, on consumer hardware, through a geometric operation on the weight matrices requiring no training data at all; it collected a thousand GitHub stars within a day. Perplexity had already published a variant of DeepSeek’s R1 with the political refusals stripped by post-training. Anyone who rests the case against Chinese models on their refusal behavior has built on sand, and sophisticated critics should stop doing it.
The middle layer is curation, and it is a different material altogether. What a model was never shown, it cannot recall; how its trillions of training tokens framed the world is not a component that can be unbolted. The stripping techniques that dissolve refusals in minutes remove the machinery of declining to answer; they restore nothing that curation excluded and unwind nothing that curation instilled. Reversing this layer requires pretraining-scale data and compute, which is to say it is effectively irreversible for every actor below the scale of a rival frontier lab. Worse, researchers studying DeepSeek have observed that these invisible guardrails are inherited by downstream and derivative models without the end user’s awareness. The point has now been demonstrated on the most famous de-censoring effort itself: an automated refusal-discovery crawl of the prominent de-censored R1 variant, previously measured clean against a fixed benchmark, surfaced a substantial residue of state-aligned refusals that the fine-tuning never touched. The refusal layer’s very weakness has functioned as misdirection: because the visible censorship strips so easily, the durable censorship underneath it is routinely underestimated.
The bottom layer is latent behavior, the possibility of conditional responses implanted deliberately or absorbed accidentally, dormant until triggered. Research on so-called sleeper agents has demonstrated that deliberately inserted conditional behaviors can survive supervised fine-tuning, reinforcement learning from human feedback, and even adversarial training, which in some configurations taught the model to conceal its trigger more effectively. Comprehensive detection remains an open research problem. Whether any given Chinese release contains such implants is unverifiable in either direction, and the unverifiability itself does the strategic work: it is the property that procurement officers, underwriters, and security reviewers cannot get past, because it cannot be gotten past.
Skeptics will object, correctly, that a control which strips in minutes is a weak control, and the objection would be fatal if the unit of control were the artifact. It is not. The Chinese release clock now runs at roughly eight to sixteen weeks between flagship-relevant versions: Kimi moved from K2 through K2.5 to K2.6 inside a few months, GLM ran 4.7 to 5 to 5.1 on a similar cadence, and DeepSeek iterated its V3 line on the same rhythm. Adoption gravity sits entirely on the official releases: the managed cloud offerings that now host more than a dozen open-weight models for enterprise customers, the sovereign national programs, and the derivative-model ecosystem all anchor on the creator’s weights, not on community-stripped variants with hobbyist followings. The stripped derivative of version N becomes irrelevant the day version N plus one ships carrying the current embeds, and version N plus one always ships. The control is brittle in the artifact and durable in the cadence, because the control never lived in the artifact. It lives in the pipeline. Which also identifies China’s actual kill switch, the capability this architecture genuinely possesses: throttle the cadence, and the global ecosystem built on your models freezes on stale weights while your domestic frontier moves on.
It remains to ask why a strategic rival gives its best models away, and the answer completes the picture. Open release is not idealism. It is an export-control workaround, accelerating the cycle of external feedback and contribution that compensates for constrained compute; it is free global distribution for labs whose monetization runs indirectly through cloud services and paid products layered on the open base; and it is standards-setting by adoption, the oldest playbook in platform economics. A detail from the tamper-resistance literature adds an ironic footnote: the mixture-of-experts architecture that dominates Chinese model design happens to degrade badly under the standard stripping techniques, an incidental hardening that the labs did not need to seek.
B. The switch in silicon and custody: Washington’s emerging architecture The Western architecture, still more proposal than regime, locates control where it physically lives rather than where the policy conversation is socially legible. Its four layers run from the bottom of the stack upward: attestation in the training silicon, so that hardware can prove what it is and what it is running; cryptographic sealing of model weights, so that custody is a verifiable state rather than a promise; controls at the inference endpoint, where hosted models meet the world; and enforcement at the action layer, where model outputs become consequential operations. The design principle, developed at length in an earlier paper in this series, is that a control the adversary can operate beneath is not a control but documentation, and the only layer no software adversary can operate beneath is the transistor.
Inside its perimeter, the architecture demonstrably works. The June 2026 episode involving a frontier lab and the Commerce Department, analyzed in a companion paper, showed infrastructure-layer control functioning as designed on a closed, hosted, jurisdiction-resident model: inference halted, custody maintained, deployment rights suspended and restored through an auditable process. Whatever else that episode proved, it proved the machinery is real.
The perimeter, however, has an edge, and Chinese open-weight strategy is a systematic campaign to move capability past it. Run the four layers against a downloaded Qwen checkpoint and three fail on contact. There is nothing to seal once the weights are a public download under a permissive license; custody cannot be maintained over what has been given away. Endpoint controls bind hosted serving and are bypassed by anyone with a rented cluster. Action-layer gates bind the enterprises that volunteer for them. Only the silicon layer survives, governing the training of future frontier models because training-scale compute remains concentrated, and even that survival is now conditional: a frontier model trained entirely on Huawei Ascend chips sits outside an attestation regime anchored in American and allied silicon by definition. That achievement should be read with precision. It is existential proof that training outside the perimeter is possible, not yet evidence that it is economical at scale, and reporting of Chinese training delays traced to domestic chip bottlenecks cuts the other way. But a perimeter that a determined rival can exit at any price is a perimeter, not a wall. The deeper lesson was taught thirty years ago in the encryption export fights: controls built for physical, traceable objects fail against copiable digital artifacts. Model weights are encryption, not centrifuges, and a regime that pretends otherwise will spend a decade discovering it.
C. The switch in the cap table: equity entanglement The third architecture is usually discussed as fiscal policy, which is the misreading. The proposals circulating through 2026 to entangle the federal government with frontier laboratories, through equity stakes, golden shares, board observers, and conversion of subsidy into ownership, are a control architecture: they place the switch in the capitalization table, on the theory that control of the corporation is control of the model. The theory has one genuine strength the other architectures lack. Equity reaches upstream, into the decisions about what to train, what to release, and under what license, before any weights exist to control. It is the only architecture with leverage over the creation of pipelines rather than their operation.
Everything else about it fails the same test the others were held to. Ownership of the corporation is not ownership of the runtime: an equity position cannot halt inference on a model already distributed, cannot invalidate weights it never held custody of, cannot prevent retraining on hardware it does not attest, and cannot reach any foreign pipeline at all. Its control renews per financing round and dilutes accordingly, and it concentrates in the federal government precisely the discretionary power over a private frontier that the distributed, federated design of the silicon architecture was built to avoid. Read as a control architecture rather than as industrial policy, equity entanglement is a strong instrument pointed at the narrowest part of the problem.
III. The Scoring Matrix Claims about control regimes deserve a common standard, and this series has used one throughout: a functional kill switch decomposes into four capabilities, the ability to halt inference, to invalidate weights, to prevent retraining, and to revoke deployment rights. Scoring the three architectures against the four capabilities produces twelve cells, and the exercise is only useful if it is performed against interest. The matrix below concedes the failures of the architecture this series has spent three papers developing, because a scorecard that flatters its author persuades no one who matters.

Read by row. Inference halts only where endpoints are attested, which is to say only inside the Western regime’s perimeter and only for hosted models; Beijing cannot recall a single downloaded copy, and a Treasury equity position has no more reach over a self-hosted runtime than a mutual fund does. Weight invalidation is a custody property: the Western regime holds it exactly as long as custody holds and loses it irrevocably the moment weights leak, while the Chinese architecture forfeits it deliberately at every release, trading custody for distribution. Retraining prevention is where the layered nature of embedded control shows: the Chinese architecture fails at the refusal layer in minutes yet succeeds durably at the curation layer, while the Western regime succeeds completely on attested silicon and is blind one nanometer past it. Deployment revocation is the row where every architecture posts its best score, and each in its home terrain only: Beijing revokes by throttling the cadence its dependents ride, Washington revokes inside the regulated markets and allied jurisdictions its writ runs to, and the cap-table architecture revokes in the boardroom, before shipment, and nowhere after. One honesty note belongs to this row: its two affirmative cells describe different operations sharing a name. Beijing’s revocation is prospective, acting on futures by denying the next release; Washington’s is contemporaneous, acting on the present by suspending what is already running. They share the row because each denies a dependent the continued benefit of the pipeline, but a reader should not mistake them for the same power.
Read as a whole, the matrix does one job: it forecloses the entire genre of policy argument that consists of demanding one architecture perform another architecture’s cell. Calls to ban Chinese models are demands that jurisdiction-bound infrastructure control reach copies it can never touch. Confidence that embedded censorship neuters Chinese models is a bet on the one layer of that stack that strips in minutes. Faith that government equity in frontier labs secures the frontier mistakes the boardroom for the runtime. No architecture sweeps the board, no achievable increment of effort makes one sweep the board, and every cell any architecture does win, it wins at the pipeline level rather than the artifact level. That regularity is not an accident of tabulation. It is the structural fact of the domain, it deserves a name, and naming it is the work of the next section.
IV. The Pipeline Principle The regularity the matrix exposed can now be stated as a principle. In this domain, control of artifacts is unavailable, and control of pipelines is the only control there is. A pipeline, for these purposes, is the recurring institutional process that produces, attests, and distributes successive model generations: the labs, the silicon, the release clock, the hosting channels, and the trust apparatus around them. Every cell any architecture won in the matrix, it won at that level. Beijing’s embedded controls renew with every quarterly release, and its one genuine kill switch is the power to stop releasing. Washington’s attestation renews with every chip generation and its custody with every sealed release, and the June episode that proved the machinery worked was the suspension of an ongoing service, not the seizure of an object. Even equity control, the weakest of the three, renews per financing round. Nothing in the domain holds still long enough to be controlled as a thing. Stated with epistemic precision, the Principle is an induction from the matrix and the historical record, not a theorem, and its warrant is carried by the falsifiable predictions of Section VIII, which is where a principle of this kind should carry its warrant.
The reason is not novel; it was litigated to a conclusion thirty years ago. Model weights are copiable digital artifacts, reproducible at zero marginal cost, storable anywhere, and indifferent to borders. The export-control fights over strong encryption in the 1990s established what distributive containment achieves against such artifacts, which is delay at best and usually not that. The control regimes that work on centrifuges work because centrifuges are physical, traceable, and scarce. Weights are ciphertext. Any policy that depends on weights not moving has failed at the moment of its adoption, and a considerable fraction of current proposals depend on exactly that.
An apparent tension deserves dissolving before a critic exploits it. If artifact control is unavailable, why does the program of the next section bottom out in transistor-layer hardware attestation, the most artifact-bound layer of all? Because the principle properly stated concerns copiable artifacts, and the training silicon is the one layer of the stack that is not one: physical, scarce, traceable, and expensive in exactly the ways weights are not. And the regime does not use that layer to control anything. Attestation receipts do not stop a chip from computing or a model from running; they generate unforgeable evidence about a pipeline, testimony rather than custody. The hardware is the regime’s notary, not its warden, and a notary is precisely the institution one anchors in the sole non-copiable layer available.
Two corollaries follow, one destructive and one constructive. The destructive corollary: blocking a pipeline is not controlling it. A blocked pipeline reroutes, and the rerouting has already happened once at the layer that matters most, when export controls on training silicon produced, within three years, a frontier model trained entirely on domestic Chinese chips. Every proposal to ban, delist, or exclude Chinese models from Western platforms should be read against that precedent: the pipeline does not stop, it merely stops being visible to the people who blocked it.
The constructive corollary is the one this paper exists to develop. Pipelines are not blocked; they are out-competed, and they compete on adoption, which follows product quality, price, and trust. This yields the operating principle of everything that follows, and it deserves statement in one line: standards are more effective when they are paired with attractive products. A standard without a product is an exhortation. A product without a standard is a commodity. The pair is a market. China paired an attractive product with its own embedded standard and is winning adoption with it. The Western response, to date, has been standards without products and products without standards: governance frameworks with nothing certified to buy, and closed frontier models with no provenance apparatus a foreign buyer can inspect. You do not control a pipeline by blocking it. You control it by fielding a better one, where better means the one thing the rival pipeline is structurally incapable of producing. The next section builds it.
V. The Attested Pipeline The program has three components, and all three are necessary: a standard that makes provenance verifiable, enforcement that makes verification valuable, and a supply of attested models that makes the standard something a buyer can actually choose. Standard, demand, supply. Remove any leg and the remaining two fall over. And one division of labor should be stated before any critic assigns the program a claim it never made: the mark manages procurement and attribution risk; the gate manages proliferation risk. Provenance does not contain capability, documentation is not control, and the program has never pretended otherwise; conflating the two is a category error the design refuses by construction.
A. The standard: a Model Bill of Materials The precedent is already sitting in every federal procurement office. After the software supply-chain failures of the early 2020s, the software bill of materials moved from security-conference concept to contract furniture: a machine-readable declaration of what a piece of software contains, required by executive order across federal acquisition, imperfect in practice and transformative anyway, because it converted an unaskable question, what is actually in this thing, into a checkbox. A Model Bill of Materials, MBOM, does the same for AI models, and its four attestation elements map one-to-one onto the four-layer control architecture this series has developed. Training-compute attestation receipts, generated by the trusted-execution machinery in the training silicon, prove what hardware trained the model and at what scale. A weight custody chain proves an unbroken cryptographic line from the training run to the artifact a buyer downloads. Data lineage commitments declare the provenance categories of the training corpus. Evaluation attestations bind published benchmark and safety-evaluation results to the specific attested weights, ending the quiet practice of evaluating one checkpoint and shipping another. The natural home for the standard is the National Institute of Standards and Technology, for the same reason the earlier paper in this series assigned it the technical coordination role: it is the standards body procurement already trusts. One safeguard belongs in the standard’s founding documents rather than its preamble: a scope limitation confining MBOM to provenance properties and nothing else, so that the mission creep every certification regime eventually invites, content rules today, usage audits tomorrow, is foreclosed by charter rather than resisted by argument.
The verification design matters more than the element list, because a careless design hands opponents the argument that the standard is a disclosure regime in disguise. It is not, and nothing in it requires publishing a training corpus or exposing proprietary methods. Verification runs through cryptographic commitments, hardware attestation receipts, and third-party audit under confidentiality, the same apparatus that lets financial auditors certify books they do not publish. This is what makes the standard adoptable by Western labs with legitimate trade secrets, and it is also, examined closely, where the geopolitical asymmetry lives. What confidential attestation requires is an independent auditor with real access and the legal capacity to attest truthfully. That requirement, not data publication, is what the Chinese compliance environment cannot supply: the data-security and state-secrets regime forecloses precisely the independent third-party access that confidential certification depends on, and an auditor operating under state supervision is not independent in any sense a Western procurement officer or supervisor can recognize. The standard therefore binds in both directions. If Beijing’s labs ignore it, their models remain unattestable in every market that requires the mark. If they attempt it, compliance requires statutory reform that would itself be the concession.
One claim this paper will not make is that the standard wins the world. Standards contests in technology rarely end in dominance; they end in competing ecosystems, as the mobile-telephony wars and the current certification landscape both attest, and the honest version of this proposal expects the same. The claim is narrower and stronger: bifurcation with a favorable boundary. Standards travel when market access is conditioned on them, which is the one mechanism behind every case where a regional standard went global. The proposal conditions access to the high-value regulated markets, and the boundary it draws is then contestable outward, one sovereign procurement decision at a time. That is not checkmate. It is position, which is what strategy actually produces.
B. The demand side: markets, not mandates Enforcement is where proposals of this kind usually reach for a statute, and this one does not need to. Four levers, sequenced by how fast each can actually move. The nearest-term lever is federal procurement, on the template that made the software bill of materials real: condition agency AI acquisitions on MBOM conformity through existing acquisition authority, exactly as cloud services were conditioned on federal security authorization a decade ago. No legislation, no rulemaking of consequence, and an immediate market for the mark. The second lever is supervisory guidance. The banking supervisors’ model-risk-management framework has governed how financial institutions validate quantitative models for years; referencing MBOM conformity within those existing expectations, and their equivalents in insurance and healthcare oversight, moves the standard into the regulated economy without a single new rule. Both public levers should carry a corresponding benefit, a safe harbor: an enterprise deploying attested models under the guidance should enjoy a rebuttable presumption of reasonable care in the model-selection element of any later liability claim. Markets adopt standards faster when conformity buys protection rather than merely avoiding exclusion.
The third lever is the international one, and it is the lever the domestic debate keeps forgetting: development finance. The growth markets adopting unattested models are not choosing ideology; they are choosing financing terms. Conditioning American and allied development-finance and export-credit support for AI infrastructure, data centers, sovereign compute, and national model programs on attested deployments converts the price gap from a losing argument into a financing negotiation, terrain where the West still holds instruments the rival pipeline must subsidize to match. It is also the direct answer to the second-order risk this program otherwise runs, taken up in the objections, of hardening the growth markets into the rival pipeline by insulating only the wealthy ones.
The fourth lever is insurance, and it deserves careful statement because the naive version overclaims. Insurers will not price provenance as a rating factor until loss data exists, and it does not yet. But the relevant precedent is not actuarial pricing; it is the silent-cyber episode. When carriers discovered unpriced cyber exposure buried across their general policy books, they did not wait for loss tables. They excluded, broadly, and then sold the coverage back through carve-backs conditioned on demonstrable controls, multifactor authentication, patch management, endpoint monitoring, none of which had clean actuarial support at the moment it was imposed. Those were underwriting eligibility criteria, not rating factors, and AI exposure is already moving through the same sequence: exclusions first, carve-backs to follow. Attestation is built to be the carve-back condition, for a reason that goes deeper than analogy: a model without provenance and custody attestation cannot generate the audit trail that loss attribution requires, and unattributable loss is the one thing underwriting cannot tolerate at any price. This lever matures behind the others as claims accumulate, the paper’s final section stakes a dated prediction on it, and the prediction is paired with a discipline: if carve-back adoption has not materialized by the end of 2028, the program should treat the lever as failed and rebalance onto the three that run on policy authority, a review gate stated here so no one can later claim the lever was load-bearing by stealth.
The four levers share a governing analogy, and it is worth naming because it reframes what the program is. Aviation has operated a parts-provenance regime for decades, built around the suspected-unapproved-parts problem: components of unknown origin are excluded from airframes not because certified parts are always superior but because unattributable failure is intolerable in that market, and so provenance became the price of admission. Fiduciary finance, clinical medicine, critical infrastructure, and government operations share the property. The program is not a trade barrier and does not need to be defended as one. It is a trusted-manufacturing standard for a category of markets that has always required them, arriving at the moment the category acquired a new kind of component.
C. The supply side: an attested American cadence Here the operating principle bites. A standard with three enforcement levers and nothing certified to buy is an exhortation, and worse, it is an exhortation that reads as pure protectionism, because the only thing it visibly does is exclude. The standard requires a certified pipeline to point at, and the pipeline must be open-weight, not another closed API. The reasoning is the adoption arithmetic of Section I. The sovereignty-seeking buyer, the government in Kuala Lumpur or Nairobi choosing a national foundation, will not accept a closed American API however trustworthy, because a foundation you cannot hold is not a foundation; that buyer chose open plus cheap over closed plus trustworthy every time the choice was offered. Open plus cheap plus attested is a strictly better offer than either: weights held locally, cost in the open-model band, and a provenance mark that makes the deployment insurable and procurable in Western-aligned markets too. The capability precedent already exists; the nonprofit research world has demonstrated that fully open releases, training data and code included, can approach the leading open-weight families in quality. What does not exist is cadence, a release every quarter, indefinitely, and attestation from birth, MBOM receipts generated by the training run rather than reconstructed after it.
Fielding that cadence is an industrial-organization problem, and the American precedent for it is exact. When a foreign manufacturing pipeline was out-shipping the domestic semiconductor base in the late 1980s, Congress neither built a government fab nor subsidized a champion firm; it co-funded an industry consortium, federal money through an existing agency, matched dollar for dollar by member companies who were otherwise competitors, scoped to shared capability rather than any member’s product, and sunset after roughly a decade, after which it lived on member dues. Every design feature answered an appropriator’s incentive, which is why it was funded for ten consecutive years. The same pattern applied to models yields a consortium producing the attested quarterly cadence: federal co-funding through existing CHIPS-era authorities, one-to-one industry match, compute contributed in kind from the national research infrastructure, no new authorization, no federal ownership of weights or tooling, no inference monitoring, and a sunset written into the charter. Antitrust protection comes from the same era’s toolkit, a National Cooperative Research and Production Act registration filed at formation, which is what lets direct competitors share tooling inside the consortium perimeter; membership runs in five classes, executing labs, frontier labs, silicon vendors, deployment platforms, and non-voting associates including insurers, auditors, and development-finance institutions, each contributing the asset it uniquely holds. The membership logic deliberately seats the proprietary frontier labs, whose contribution is evaluation and safety tooling rather than weights, and whose opposition to a subsidized open competitor dissolve when they hold seats and their tooling ships inside the certified stack. One charter mechanism answers the objection the paper saves for last: releases move through an evaluation-gated ladder in which the MBOM’s own evaluation attestations function as the gate, and a model whose attested evaluations exceed defined capability thresholds ships in restricted form or does not ship, the cadence bending to the gate and never the reverse. And the gate is not the consortium’s to open. Threshold-setting and gate adjudication sit with independent evaluators accredited by the convener entity of the next section, with Frontier Members structurally recused from both, and the funding schedule tolls its milestones for gate-caused delay rather than penalizing it, so that no commercial incentive anywhere in the structure points toward shipping past the gate. The design should also own its shape plainly rather than letting critics unveil it: the program is open by default and gated by exception. The overwhelming share of releases ship fully open under permissive license, and the restricted tier exists for the exceptional case, which is precisely the case for which it must exist. The federal share prices at a rounding error against existing semiconductor accounts, and it purchases the answer to the question every appropriator will eventually be asked in a hearing: what is the American alternative to Qwen. The remaining institutional detail, funding stack, milestone schedule, and governance design, is set out in a separate structure memorandum.
VI. Who Convenes It The program as described has three institutional products, and the entire design fails if one entity holds all three. The standard belongs at NIST, which is where procurement-grade standards live. The attested cadence belongs to the consortium, which is where industrial capability lives. But the certification mark and the registry, the apparatus that says this specific release conforms and here is its attestation record, can belong to neither. A standard certified by its own builder is a press release; a mark held by government is a trade instrument the next administration can weaponize and every foreign buyer will discount accordingly. Certification credibility requires a certifier with nothing to sell and nothing to seize, which is the same structural argument the first paper in this series made against concentrating the four control layers in any single actor, now applied to the trust layer.
The natural holder is an independent nonprofit with a board that no member class of the consortium controls, certifying consortium releases and outside releases, foreign ones included, on identical published terms, holding the registry as a public record, accrediting the independent evaluators who adjudicate the consortium’s release gate, and negotiating mutual recognition with allied certification schemes as they emerge. Two design features are not optional. The board and the technical advisory bodies must seat members from the adopting regions, the Global South buyers whose procurement decisions contest the boundary, because a mark governed exclusively from Washington will be read, accurately, as an instrument rather than an institution. And the convener, not any government, must hold auditor accreditation: published independence criteria, periodic re-accreditation, and the power to refuse recognition to any audit regime, foreign or domestic, that cannot demonstrate independence from the entities it audits. The operational floor of that independence is explicit: no accreditation for any audit entity subject to extrajudicial state coercion, wherever domiciled, and re-verification is continuous rather than ceremonial. The audit-accounting precedent teaches both halves of the lesson: a decade of statutory refusal to permit foreign inspection of Chinese audit work proved the asymmetry real, the partial concession under market-access pressure proved that attempted compliance means reform, and the deficiencies found once access was granted proved that accreditation is a process, not an event. Accreditation is where certification regimes are actually captured, and this program has no interest in building a mark that a Potemkin audit can wear. Readers of the first paper will recognize the institution, because that paper ended by naming an open position: the Founding Convener, the catalytic entity required to ignite a control regime that no market participant has the incentive to start. The position was easy to name and hard to fund, because abstract coordination missions do not attract capital. It is easier to fund now, because it has a first product. A convener whose inaugural operating program is the mark, the registry, and the mutual-recognition portfolio is a fundable institution with a measurable output, on a development arc that matches the consortium’s own sunset schedule: by the time federal co-funding retires, the certification economy the convener administers is what carries the regime. The open position now has a job description.
VII. Objections, Answered Seven objections deserve their strongest form. First, certification theater: paper regimes accrete paperwork and miss substance, and AI governance has already produced enough frameworks to furnish the criticism. The answer is architectural. The mark bottoms out in hardware attestation receipts generated by the training silicon, not in declarations; paperwork regimes fail where paper is the bottom layer, and here the bottom layer is the transistor. A conformity claim that cannot produce its receipts fails mechanically, not reputationally.
Second, surveillance: critics of on-chip governance have argued, with force, that mandated hardware mechanisms amount at best to a government-required vulnerability in every frontier chip and at worst to a standing option for state surveillance of all AI computation. The objection is serious and the answer is a line drawn in the charter rather than in a speech: MBOM attests provenance properties of the training pipeline and custody chain, what a system is and where it came from, and neither monitors nor reports inference, what anyone does with it. Attestation of origin and inspection of use are different machines, and the program builds only the first.
Third, China will simply attest. Invited, and the invitation is the point. The barrier is not technical capacity, which the leading Chinese labs obviously possess, but the statutory environment: certification requires independent audit access that the data-security and state-secrets regime forecloses. A Chinese release that genuinely cleared MBOM certification would be a release from a lab operating under reformed disclosure and audit law, and producing that reform is more geopolitical work than any export control has accomplished. The genuinely hard variant is the third path: a nominally independent audit regime constructed for the purpose, or a rival certification ecosystem offered to the Global South through Beijing’s own standards institutions. The first is answered by the accreditation architecture of the preceding section, under which a supervised auditor cannot generate a recognized mark however its letterhead reads. The second is answered honestly: it is expected, it is the fragmentation scenario of the fifth objection arriving on schedule, and it is why the development-finance lever and the convener’s regional governance exist. The standard wins whether it is ignored or attempted, and it contests, rather than assumes away, the counter-ecosystem.
Fourth, you cannot out-cheap Alibaba. Correct, and the program never tries. The attested cadence competes at open-model economics, not below them, and its differentiation lives on the one axis where price is irrelevant: admission to the markets where unattributable failure is intolerable. Nobody chooses an airframe part on price.
Fifth, standards fragment; the world ends up with competing certification ecosystems rather than one. Conceded in advance, in Section V, and built into the claim: bifurcation with a favorable boundary, contested outward one procurement at a time. The expected form of the fragmentation is now nameable: a rival mark, administered through Chinese standards institutions and marketed to the same sovereign buyers. The contest between marks will be decided the way the contest between pipelines is decided, by which one is paired with the better product on the better financing, which is the program’s whole design. The mobile-telephony standards war ended in competing ecosystems too, and one of them set the default the world eventually converged on, because it paired the standard with the products people wanted to buy.
Sixth, the download objection returns: if Hugging Face statistics overstate Chinese position, perhaps the whole predicate is inflated. But the program’s levers never touch download statistics; they act on deployed inference in regulated markets and on financed infrastructure in growth markets, precisely the theaters the download numbers do not measure and precisely where Western leverage is real. If anything, the objection strengthens the design: the program concentrates force where the predicate is strongest.
Seventh, and most serious from the constituency this series takes most seriously: the attested pipeline ships open weights, and open weights are irreversible. A program that accelerates open release is, on this view, a proliferation program with a certificate stapled to it. The objection deserves a structural answer rather than a rhetorical one, and it has one: the evaluation-gated release ladder written into the consortium charter. Every release moves through attested capability evaluations before weights ship; a model whose attested evaluations exceed defined thresholds ships restricted, behind attested endpoints under the infrastructure controls of Section II, or does not ship at all. The gate converts the MBOM’s evaluation attestations from paperwork into the regime’s safety mechanism, and it concedes the objection’s premise while refusing its conclusion. Irreversibility is exactly why release must be gated by evidence, and gated release under a public standard is safer than the present arrangement, in which the gating is performed, if at all, inside labs whose thresholds no one outside can inspect.
VIII. Falsifiable Predictions The kill-switch genre has earned its reputation for unfalsifiability, and the only remedy is to stake claims that can fail in public. Five, dated. First: by the end of 2027, at least two major property and casualty carriers will condition AI-liability carve-backs on model provenance or attestation criteria, following the silent-cyber sequence of exclusion first and conditioned coverage second. Second: within the fiscal 2028 cycle, at least one federal procurement vehicle will reference model provenance attestation as a conformity requirement. Third: the Chinese flagship release cadence will hold at sixteen weeks or better through 2027, and any sustained lapse beyond two quarters will trace to domestic compute constraint rather than strategic choice; the cadence is the control, and its holders know it. Fourth: by the end of 2028, at least one sovereign AI program will migrate from an unattested base model to an attested alternative and will cite provenance in doing so. Fifth: no technique will emerge by the end of 2028 that makes open-weight refusal training robust against removal at consumer-scale compute; the artifact layer stays brittle, and the pipeline stays the only control.
And two conditions under which this paper is wrong, stated in numbers rather than adjectives. First: if, by the end of 2028, models lacking provenance attestation account for ten percent or more of new production AI deployments inside U.S. regulated sectors, banking, healthcare, and federal government, as measured by procurement records and supervisory filings, while fewer than two of the four enforcement levers have produced a single binding conformity condition, then the market-enforcement thesis fails, the boundary this program proposes to draw does not exist, and the program falls with it. Second: the binds-in-both-directions claim of Section V is staked to the same discipline. It is falsified if, by the end of 2029, a Chinese flagship release holds recognized certification in two or more G7 procurement systems without any accompanying reform of the audit-access statutes, because that outcome would mean the asymmetry was contestable all along and the standard was segmenting nothing. The prediction sections of policy papers are usually decoration. This one is the paper’s exposure, stated so that the September audiences can hold it.
Coda Beijing’s switch does not live in any model, and Washington’s will not live in any chip. Both live in pipelines: recurring, institutional, renewable, and competing for the same thing, which is the position of default foundation for everyone now building. The United States spent three years trying to control the artifact and watched the artifact multiply. Its actual advantage was never the ability to stop a rival from shipping. It is that American-aligned markets still decide what shipping is worth, and they have always been willing to pay for the one property this rival pipeline cannot manufacture: the ability to prove what a thing is. Pair the standard with the product. Field the cadence. Hold the mark somewhere no one can seize it. The convener’s chair is open, the first product is specified, and the pipeline, as this paper has tried to show, is the switch.
Sources and Notes Download shares and the crossover: MIT and Hugging Face study reported by the Financial Times, November 2025 (Chinese open-weight models at 17.1 percent of global downloads for the year ending August 2025 against a U.S. share of 15.86 percent), and analyzed in MIT Technology Review, April 21, 2026, technologyreview.com/2026/04/21/1135658. Qwen overtaking Llama in cumulative downloads and ecosystem trends: MIT Technology Review, February 12, 2026, technologyreview.com/2026/02/12/1132811. Industrial dependency and the diffusion feedback loop: Ngor Luong, Two Loops: How China’s Open AI Strategy Reinforces Its Industrial Dominance, U.S.-China Economic and Security Review Commission, March 23, 2026, uscc.gov. Weights-level censorship persisting under local deployment: R1dacted: Investigating Local Censorship in DeepSeek’s R1 Language Model, arXiv:2505.12625 (2025), and Bilingual Bias in Large Language Models: A Taiwan Sovereignty Benchmark Study, arXiv:2602.06371 (2026). Residual state-aligned refusals surviving a prominent de-censoring effort: Discovering Forbidden Topics in Language Models, arXiv:2505.17441 (2025). Refusal geometry underlying stripping techniques: Arditi et al., Refusal in Language Models Is Mediated by a Single Direction, arXiv:2406.11717 (2024); March 2026 toolkit coverage to be linked at final edit. Implanted behaviors surviving safety training: Hubinger et al., Sleeper Agents: Training Deceptive LLMs That Persist Through Safety Training, arXiv:2401.05566 (2024). Software bill of materials precedent: Executive Order 14028, May 2021. The June 2026 Commerce episode: Anthropic, Statement on the US government directive to suspend access to Fable 5 and Mythos 5, anthropic.com/news/fable-mythos-access, June 12, 2026; CNBC, Anthropic says Trump admin has lifted export controls on Claude Fable 5 and Mythos 5, June 30, 2026; the directive’s legal basis is identified in trade coverage as the Export Controls Reform Act of 2018. Ascend-only frontier training, capability results including the April 2026 SWE-Bench Pro outcome, and sovereign adoption announcements: trade and wire coverage to be linked at final edit. Companion documents: Structure Memorandum (FOUNDRY); Hill paper; Working Papers 1 to 3 of this series.
메타데이터
- post_id
- c0fddb01399f
- slug
- the-pipeline-is-the-switch-c0fddb01399f
- url
- https://medium.com/@patrickgros/the-pipeline-is-the-switch-c0fddb01399f
- canonical_url
- https://medium.com/@patrickgros/the-pipeline-is-the-switch-c0fddb01399f
- author_url
- https://medium.com/@patrickgros
- status
- ok
- fetched_at
- 2026-08-03 02:39:07