Civic / Privacy / Digital Rights
Permission to Compute: Do Frontier Laws and Export Controls Entrench Intelligence Monopolies?
Report summary
Research start and cutoff. Research began at approximately September 5, 2026, 9:46 p.m. America/Chicago . The legal-status cutoff for this report is that same time, with the important qualification that the Bureau of Industry and Security’s online Export Administration Regulations pages used here re
Key topics
- Civic / Privacy / Digital Rights
- Civic
- Privacy
- Digital Rights
- AI
- Runtime
- Cognitive Liberty
- Research Archive
- Strategy
Research provenance
For citation, use the report title and canonical URL. Archival presence does not establish authorship or promote report statements into portfolio evidence.
Source availability: 72 citation markers in the source export have no recoverable source links. Those markers are omitted from this reader; any supplied bibliography and ordinary links remain. Check the original sources before relying on the cited claims.
This page renders the archived Markdown as safe, formatted HTML. It is background research and does not become a portfolio claim without evidence review.
Full report
On this page
Executive case for reform
Research start and cutoff. Research began at approximately September 5, 2026, 9:46 p.m. America/Chicago. The legal-status cutoff for this report is that same time, with the important qualification that the Bureau of Industry and Security’s online Export Administration Regulations pages used here reported themselves current from the eCFR through September 4, 2026. The attached commission, rather than the visible generic request for an unspecified topic, supplies the operative subject: a provision-specific examination of barriers to training, modifying, possessing, distributing, and privately running capable AI models, centered on California SB 53, New York’s RAISE legislation and chapter amendments, the EU AI Act’s general-purpose-AI regime, and current U.S. export controls.
Bottom line. The strongest version of the “intelligence monopoly” thesis is not supported. None of the four principal regimes creates a general license to think, a general prohibition on local inference, or a universal ban on open-weight models. California SB 53 is primarily a transparency, framework, incident-reporting, whistleblower-protection, and public-compute statute; it does not require government permission before a covered developer trains or deploys a frontier model. New York’s amended RAISE regime is materially more gate-like for the largest developers because, beginning January 1, 2027, it bars a large frontier developer from developing, deploying, or operating a frontier model in New York without a current disclosure filing and required payment, but the text is closer to a nondiscretionary registration-and-assessment condition than a merits-based safety license. The EU AI Act imposes broader documentation and governance duties on providers of general-purpose AI models and additional duties on models with systemic risk, while giving open-source and research exemptions that materially narrow the critique. Current U.S. export controls are the clearest permission structure: certain advanced chips and controlled model weights can require licenses based on item, destination, end user, end use, and corporate-headquarters rules, but current rules expressly distinguish training from inference and do not amount to a worldwide prohibition on private AI use.
The more defensible thesis is structural entrenchment risk rather than proven regulatory capture. Frontier AI already depends on scarce compute, capital, cloud capacity, specialized labor, and distribution channels. The FTC’s compulsory-study report found that major cloud/AI partnerships included billions of dollars of cloud commitments, discounted compute, information sharing, and contractual or technical switching costs; NTIA separately concluded that a few firms’ infrastructure spending makes it difficult for academics, smaller companies, nonprofits, and the public sector to keep pace, while open weights can lower downstream entry barriers. Against that baseline, fixed compliance duties, security infrastructure, legal review, cross-border licensing, and registration charges can have scale economies even when facially neutral. That is a plausible causal mechanism for concentration. It is not evidence that legislators enacted the rules in order to protect incumbents, and the available record here does not establish that motive.
The legal architecture also contains significant decentralizing counterweights. California’s SB 53 limits its most demanding framework duties to developers with more than $500 million in annual gross revenue and creates a statutory pathway for CalCompute, a public computing consortium, subject to appropriation; New York similarly reserves the full framework duties and disclosure-fee gate for “large frontier developers,” exempts specified academic research and Empire AI entities, and permits federal-equivalence declarations; the EU AI Act gives important exclusions for scientific research and pre-market R&D and waives parts of Article 53 for qualifying open-source GPAI models that are not systemic-risk models. These provisions undermine any claim that the statutes are uniformly designed to force all intelligence access through a handful of approved corporations.
The most serious liberty problem is therefore not “reporting equals censorship.” It is the cumulative possibility that law makes the scalable, auditable, locally controllable path harder while leaving the monitored, revocable cloud path comparatively easy. NTIA identifies concrete benefits of widely available weights: independent scrutiny, safety research, customization, cyber defense, and the ability to process sensitive data without sending it to a third-party proprietary model. A regime that predictably induces providers to withhold weights, forces researchers into a small set of clouds, or makes cross-border collaboration contingent on incumbent-controlled compliance channels can shift practical cognitive autonomy into private permission systems even when no statute directly orders that result. Yet NTIA also finds serious uncertainty and plausible misuse risks, including cybersecurity and CBRN concerns, which means a liberty-protective reform must preserve narrowly tailored controls tied to concrete third-party harm.
Reform judgment. California SB 53 should be retained but narrowed at ambiguity points, with its public-compute and whistleblower provisions strengthened. New York’s framework and incident rules can largely be retained, but the “no large frontier developer may develop/deploy/operate” filing-and-fee gate should be rewritten as a post-commencement registration duty with a capped, reviewable assessment so administrative defects cannot become prior restraints on model development. The EU should retain systemic-risk evaluation, cybersecurity, and serious-incident duties while broadening protected independent research and ensuring that Commission designation and information demands are contestable, reasoned, and proportionate. U.S. export controls deserve the sharpest structural scrutiny: destination/end-user controls on genuinely defense-relevant chips and nonpublic model weights may be justified, but broad or shifting authorization systems should include transparent criteria, time-bounded decisions, research collaboration safe harbors where consistent with national security, and competition safeguards that prevent a short list of government-favored cloud or AI firms from becoming the only practical route to lawful compute.
Scope, method, and legal status
The commission asks a normative question—whether “permission to compute” can become infrastructure for domination—but requires legal conclusions to rest on primary materials and explicitly warns against treating the regulatory-capture hypothesis as proved. It also requires separation of present conversational systems, bounded agents, persistent operatorless services, and hypothetical more capable machine principals; current legal personhood, capability, interface, and moral status are therefore treated as separate variables.
The research strategy prioritized current primary law first, then official legislative history and official agency reports, and only then empirical or analytical material about competition and openness. The central legal sources were the chaptered California text, New York’s current chapter-amendment record, the EU’s July 27, 2026 consolidated AI Act, and BIS’s current EAR pages. Official NTIA and FTC materials were used for competition, open-weight, and cloud-dependence evidence. No private repositories, deployment systems, credentials, or nonpublic project materials were accessed. The report does not claim an exhaustive global survey, an exhaustive case-law check, or a complete legislative-lobbying reconstruction.
| Source type | Priority and use | Strength | Principal limitation |
|---|---|---|---|
| Enacted statute / regulation / official consolidated text | Highest; determines operative duties, thresholds, exemptions, sanctions, dates | Best evidence of positive law | Consolidations can lag amendments; cross-references and effective dates require care |
| Official legislative history / chapter amendment | High; reconstructs superseded proposals and legislative change | Strong for version history and stated purpose | Sponsor memoranda do not themselves create legal duties |
| Official agency guidance / press release | Secondary to regulation; useful for enforcement posture and interpretation | Shows administering agency’s current position | May be nonbinding or later superseded |
| Official competition / technical report | Evidence for market structure, benefits, risks, and uncertainty | Often based on compulsory data or broad record | Does not prove a particular statute caused concentration |
| Original academic paper | Mechanisms, empirical estimates, technical evidence | Can test causal or technical claims | Results may not generalize to changing frontier systems |
| Company statement / trade group / news report | Legislative politics, implementation experience, reported cost | Useful affected-party evidence | Incentives, selection effects, and unverifiable cost claims require caution |
The most important version correction concerns New York. S6953B became Chapter 699 in December 2025, but S8828 was signed on March 27, 2026 as Chapter 96 and its sponsor memorandum expressly describes the measure as a chapter amendment that repeals the underlying regime and replaces it with a more transparency-focused structure aligned more closely with California. The substantive amended regime is scheduled to take effect January 1, 2027. Accordingly, requirements found in earlier RAISE versions—including stronger deployment restrictions or audit structures that did not survive—must not be attributed to the law that will operate in 2027.
The EU AI Act is also temporally layered. The consolidated text applies the GPAI chapter on a schedule different from some high-risk-system requirements. Chapter V’s GPAI duties began applying to relevant new models before the general August 2026 application date, while providers of GPAI models placed on the market before August 2, 2025 have a transition until August 2, 2027. The current consolidation separately phases certain high-risk-system obligations later; it would therefore be wrong to state that every AI Act duty became fully operative in August 2026.
The most difficult version problem is U.S. export control. BIS publicly announced on May 13, 2025 that it was rescinding the January 2025 “AI Diffusion Rule,” instructed enforcement personnel not to enforce that framework, and said it would publish a formal rescission and replacement. Yet BIS’s current EAR pages, which identify themselves as current through September 4, 2026, still contain ECCN 4E091-related model-weight controls, License Exception AIA, the AI Authorization country supplement, VEU rules governing advanced-AI training and weight storage, and 2026 amendments that actively use this architecture. The safe conclusion is not that the January 2025 three-tier diffusion policy remains intact, nor that all of it disappeared. The operative baseline for this report is the current codified EAR text, while the May 2025 announcement is treated as important enforcement-history evidence and a warning against importing obsolete country-tier claims from the old proposal.
The principal queries and locators were designed to test version, scope, and exceptions rather than merely find criticism:
| Research question | Representative query / locator | Why it matters |
|---|---|---|
| California current duties | California SB 53 2025 chaptered frontier model 10^26 large frontier developer $500 million | Separates all-frontier transparency duties from large-developer framework duties |
| New York chapter amendment | New York S8828 RAISE chapter amendment effective January 1 2027 S6953B | Prevents superseded RAISE provisions from being reported as current |
| EU GPAI systemic risk | EU AI Act Article 51 52 53 55 10^25 FLOPs open source systemic risk consolidated 2026 | Maps baseline GPAI duties, systemic-risk presumption, and open-source exception |
| BIS current model-weight rule | BIS current 4E091 AI model weights 742.6 740.27 2026 | Distinguishes current codified rule from the rescinded/non-enforced diffusion package |
| BIS cloud/inference distinction | BIS VEU advanced AI training 25 percent fine tuning inference API not prohibited | Tests whether inference itself is controlled |
| Concentration evidence | FTC AI partnerships cloud providers report compute switching costs January 2025 | Tests structural market concentration without assuming regulatory capture |
| Open-weight benefits and risks | NTIA dual-use foundation models widely available model weights competition privacy safety research | Tests liberty benefits against third-party safety costs |
Legal-status table.
| Instrument | Version at cutoff | Status | Regulated actor / act | Key gate or duty | Material exceptions / counterweights | Enforcement / review |
|---|---|---|---|---|---|---|
| California SB 53, Chapter 138 (2025) | Chaptered text approved Sept. 29, 2025 | Enacted and in effect by cutoff | Frontier developers; strongest framework duties for “large frontier developers” | Publish transparency information; large developers maintain/publish frontier framework; incident reporting | >$500m revenue threshold for large-developer duties; federal-conflict limitation; lawful-federal-activity exclusion in catastrophic-risk definition; CalCompute; whistleblower protection | California AG civil action; large-developer penalty up to $1m per violation under the cited provision. |
| New York RAISE, Chapter 699 as amended by Chapter 96 (S8828) | March 27, 2026 chapter amendment | Enacted; substantive regime effective Jan. 1, 2027 | Frontier developers; additional duties for large frontier developers | Framework and transparency duties; 72h incident report; large-developer disclosure filing and assessment before development/deployment/operation in NY | >$500m revenue threshold for “large”; academic and Empire AI exceptions; federal-equivalence mechanism | AG civil penalties; disclosure-gate penalty after notice/hearing; no private right of action in cited text. |
| EU AI Act Regulation (EU) 2024/1689 | Consolidated July 27, 2026 | In force; GPAI duties subject to transition dates | Providers placing GPAI models on EU market; some extraterritorial triggers | Articles 53–55 documentation, information, systemic-risk evaluation/mitigation, serious-incident and cybersecurity duties | Research/R&D exclusions; open-source relief from parts of Art. 53 unless systemic risk; military/national-security exclusion | Commission powers; GPAI fines up to €15m or 3% worldwide turnover; Art. 52 reassessment mechanism. |
| U.S. EAR advanced computing and 4E091 rules | BIS pages current from eCFR through Sept. 4, 2026 | Operative codified text; May 2025 diffusion-rescission history must be separated | Exporters, reexporters, transferors; certain IaaS/VEU relationships; controlled-item recipients | Licenses / exceptions for advanced chips and controlled model weights; destination, end-user, storage and training conditions | AIA/NAC/ACA and other exceptions; “published” model-weight treatment; inference API/IaaS carve-out in VEU acceptable-use rule | BIS licensing and enforcement; Part 756 administrative appeal for many adverse administrative actions; judicial review preserved by law. |
| January 2025 AI Diffusion framework | Jan. 15, 2025 rule and May 13, 2025 rescission/non-enforcement announcement | Historical/superseded as a policy package; do not treat its full tier system as current | Advanced-chip and closed-weight transactions | Three-tier diffusion architecture and country allocations in original package | Open-weight and allied-country exceptions existed even in original framework | BIS announced rescission/non-enforcement; current codified provisions must be checked independently. |
Gatekeeping map and threshold worksheet
The first discipline is to identify what act is being regulated. “Compute regulation” collapses legally distinct events: acquiring chips, renting cloud capacity, training a model, fine-tuning an existing model, publishing weights, exporting or reexporting controlled technology, placing a model on a market, offering an API, and merely running inference on a local device. The principal laws do not treat those acts as interchangeable.
| Act / actor | California SB 53 | New York amended RAISE | EU AI Act GPAI | U.S. EAR |
|---|---|---|---|---|
| Train a model | Threshold determines “frontier” status; no government pre-approval to train | Threshold determines “frontier”; from Jan. 1, 2027 a large frontier developer must have current disclosure/fee before developing in NY | Training alone does not create a standalone compute license; provider duties attach around development/market placement and systemic-risk status | Chip export and certain overseas/VEU training arrangements can require authorization; domestic training is not generally licensed merely because compute is large |
| Fine-tune / materially modify | Training compute definition includes specified subsequent fine-tuning/RL/material modifications applied by developer | Same general architecture; attribution can be fact-sensitive for downstream modifier | A modifier may incur provider obligations depending on whether it becomes provider of a GPAI model / substantially modified model; systemic-risk duties depend on model status | Foreign-produced 4E091 items include models further trained/modified by fine-tuning, quantization, or other post-training techniques; VEU rule allows fine-tuning up to 25% of original training operations without separate authorization in the specified context. |
| Publish / distribute weights | “Deploy” and transparency rules can be implicated, but no categorical open-weight ban appears | “Deploy” includes making available to a third party for use, modification, copying, or combination; disclosure duties can therefore attach | Qualifying free/open-source GPAI receives partial Art. 53 relief, but systemic-risk models do not get that waiver | Controlled closed/nonpublished weights can trigger export rules; current architecture treats publication status as legally important and provides AIA pathways for controlled weights. |
| Hosted inference / API | Not licensed by SB 53 as such | Not licensed as such, though deployment of covered frontier model triggers transparency | Deployers/providers can have duties depending on role, but personal nonprofessional use falls outside “deployer” definition | VEU acceptable-use text expressly says API access and IaaS for inference are not prohibited by that training rule absent equivalent restrictions on U.S.-based compute. |
| Local private inference | No direct prohibition identified | No direct prohibition identified | Personal, nonprofessional use is outside deployer definition; provider-side duties can still shape availability | Purely domestic local use is not an “export” merely because the model is capable; separate end-user/end-use rules can still matter |
| Cross-border model-weight transfer | No export-control function | No export-control function | Market-placement and third-country-provider rules may attach where EU nexus exists | Core EAR issue: 4E091 and FDP rules can make certain weights subject to worldwide destination licensing; item, destination, end user, end use, and exception must be analyzed separately. |
| Cloud access | Not directly licensed, though compliance burden can affect provider contracting | Same, except NY large-developer registration is a state gate on covered development/operation | No general cloud license in GPAI chapter | Advanced-chip controls, VEU rules, red flags, and end-user/headquarters restrictions can shape who receives high-end compute; Red Flag 28 specifically addresses IaaS used to train a 4E091 model for certain foreign-headquartered entities. |
Version-correct threshold worksheet.
| Regime | Capability / compute threshold | Aggregation rule | Revenue / actor threshold | Legal consequence |
|---|---|---|---|---|
| California SB 53 | “Frontier model” trained using more than 10^26 integer or floating-point operations | Statutory definition includes original training plus specified subsequent fine-tuning, reinforcement learning, or other material modifications applied by the developer | “Large frontier developer” requires frontier-developer status plus affiliates’ annual gross revenue over $500m in preceding calendar year | All frontier developers: transparency and incident duties; large frontier developers: published framework and strongest enforcement exposure. |
| New York amended RAISE | “Frontier model” above 10^26 integer/FLOP | Includes original run plus subsequent fine-tuning, RL, or material modification applied by developer | Large frontier developer: developer plus affiliates over $500m annual gross revenue | All frontier developers: transparency and incident reporting; large: framework, additional risk disclosure, registration/assessment gate. |
| EU AI Act | GPAI model is presumed to have high-impact capabilities when cumulative training compute exceeds 10^25 FLOPs; Commission may designate on other criteria | “Cumulative” compute, with Commission power to update threshold/benchmarks through delegated acts | No $500m exclusion from baseline GPAI duties; SME proportionality appears elsewhere, while open-source relief is function-based | Notification to Commission at threshold; systemic-risk model duties under Art. 55; provider may submit reasoned argument against presumption and seek reassessment. |
| U.S. EAR 4E091 | Not safely reducible to a single fixed number in current operation; the regime originated with a 10^26-operation control for advanced closed models, while current ECCN notes use the capability of the most advanced “published” model as a moving exclusion benchmark | FDP rule can capture qualifying foreign-produced 4E091 items and expressly includes further training/modification | No revenue safe harbor; applicability turns on classification, publication status, destination, headquarters/parent, end use, and exception | Controlled weights can require license for export/reexport/transfer; AIA and other exceptions matter; the analysis is transaction-specific. |
Two corrections are especially important. First, small developers are not treated identically to incumbents under California and New York. A worker cooperative can cross the compute threshold and become a “frontier developer” without becoming a “large frontier developer”; in that case the framework, fee, and some enforcement burdens reserved for >$500 million actors do not simply transfer downward. Second, the EU’s 10^25 FLOP presumption is not an automatic ban. Article 52 allows a provider to notify the Commission while making a substantiated case that the model does not in fact pose systemic risk, and allows later reassessment.
The statutory language about “evading the control” of a developer or user also requires disciplined reading. In California and New York, the phrase appears inside a definition of catastrophic risk that separately requires a foreseeable and material risk of a single incident causing more than fifty deaths/serious injuries or more than $1 billion in property damage, and the laws identify specific pathways such as CBRN assistance or autonomous cyber/criminal conduct. Ordinary political disagreement, a model refusing a vendor preference, or a user bypassing a product policy is not, standing alone, the defined catastrophic risk. A reform can make that clearer, but it would be inaccurate to report that current text criminalizes “independence” as such.
The gatekeeping chain can be visualized as follows:
flowchart TD
A[Proposed AI activity] --> B{Which act?}
B -->|Train or materially modify| C{CA/NY frontier threshold?}
C -->|No| D[Frontier statutes largely outside scope]
C -->|Yes| E{Large developer > $500m?}
E -->|No| F[Transparency / incident duties]
E -->|Yes| G[Framework duties; NY adds filing/assessment gate]
B -->|Place GPAI on EU market| H{GPAI / systemic-risk status}
H --> I[Art. 53 baseline duties]
H -->|Systemic risk| J[Art. 55 evaluation, mitigation, incident, cyber duties]
B -->|Export/reexport/transfer| K{EAR item + destination + end user + end use}
K -->|4E091 / advanced compute controlled| L{License exception available?}
L -->|Yes| M[Authorized subject to conditions]
L -->|No| N[License / denial / appeal path]
B -->|Local personal inference| O[No frontier-compute license identified]
This diagram is a legal-issue map, not a substitute for classification or counsel; export-control outcomes in particular turn on details that a general report cannot resolve.
Concentration mechanisms, counterweights, and strongest defenses
The concentration critique should be stated as a causal chain, not a slogan.
Documented baseline. Compute access is already concentrated. The FTC’s 2025 Section 6(b) study of Microsoft/OpenAI, Amazon/Anthropic, and Google/Anthropic found significant equity and revenue-sharing interests, cloud-spending commitments, discounted compute, consultation/control/exclusivity rights to varying degrees, information sharing, and possible contractual and technical switching costs. FTC staff expressly identified access to computing resources and engineering talent as competitive pressure points. NTIA similarly reported that the expense of frontier infrastructure makes it difficult for universities, smaller firms, nonprofits, and the public sector to keep pace, while open weights can reduce downstream entry barriers and enable research by actors unable to train leading models from scratch.
Inferred regulatory mechanism. A fixed duty—maintaining a frontier safety framework, employing counsel to classify cross-border model weights, securing approved facilities, conducting evaluations, or preparing regulator-facing technical files—usually costs less per unit of revenue for a firm already maintaining global legal, security, and policy teams than for a new entrant. That is an inference from cost structure, not a measured causal estimate in the sources reviewed. California and New York deliberately blunt it with the $500 million “large developer” threshold; the EU’s baseline GPAI duties are broader, though open-source and research exceptions reduce burden for some actors. BIS controls can be more structurally asymmetric because qualification often turns on the transaction and technology rather than the exporter’s revenue.
Potential injury. If compliance cost or legal uncertainty causes an otherwise willing developer to stop publishing weights, refuse small foreign research collaborators, or insist that users access a model only through a monitored API, the immediate effect is loss of local control, auditability, portability, and the ability to keep sensitive prompts off a third-party server. NTIA identifies precisely these benefits of open weights, including safety scrutiny, customization, cyber-defense research, and sensitive-data processing without sending data to a proprietary provider. The longer-run concentration effect would be dependence on a smaller set of platforms that can revoke access, meter usage, log interactions, or change policy. That second-order effect is plausible but must be labeled inferred, not observed as a consequence of SB 53, RAISE, or the EU AI Act.
Necessary assumption and defeater. The entrenchment mechanism requires that the marginal compliance burden actually changes entry, publication, or distribution decisions. It is defeated or weakened where the law excludes the entrant, gives a low-cost safe harbor, provides public compute, or imposes roughly the same security cost the actor would rationally incur anyway. California and New York supply a strong defeater for the claim that every small developer bears incumbent-level frontier governance costs: the $500 million threshold. New York’s academic/Empire AI exemptions and California’s CalCompute authorization are additional counterweights.
Open weights are not an unqualified liberty good. NTIA found that wide weight availability can make safeguards easier to remove and could increase access for malicious actors, while emphasizing major uncertainty about the marginal uplift over closed models and existing information sources. That makes a categorical “right to publish every model” difficult to defend where a specific model creates a demonstrable, imminent, and otherwise hard-to-mitigate pathway to catastrophic physical harm. But the same report declined to conclude that open weights overall produce more marginal risks than benefits and emphasized their research, competition, transparency, and privacy advantages. The policy implication is a rebuttable presumption for openness and independent research, displaced by evidence about a concrete model/capability and a concrete harm pathway—not a presumption that central hosting is always safer.
Government exemptions deserve special scrutiny. California and New York exclude lawful federal-government activity from their catastrophic-risk definitions; the EU AI Act excludes AI systems developed or used exclusively for military, defense, or national-security purposes from its scope. These carveouts create an asymmetry: civilian developers may face transparency and risk-governance duties that are not mirrored by comparable statutory duties for certain sovereign uses. The strongest liberty objection is not that every government program is equally risky—classified missions and constitutional responsibility create legitimate distinctions—but that a broad categorical exemption can preserve the state’s access to powerful systems while constraining civilian replication, auditing, or countervailing capability. That is a structural possibility, not evidence that the exempt actors currently use AI for unlawful surveillance or coercion.
Public compute changes the analysis. California’s SB 53 directs development of a CalCompute consortium framework aimed at public-benefit research and equitable access to computing resources, though the operative buildout depends on appropriation. New York expressly exempts specified Empire AI entities from its frontier article. Those provisions acknowledge that access to compute itself is a competition and research problem. They should be judged by actual capacity, allocation rules, independence, and durability—not merely by statutory existence—but as a matter of design they are decentralizing rather than monopolizing.
Best defense of California SB 53. The strongest defense is that the enacted law is a transparency-and-accountability statute, not the licensing regime critics sometimes imply. It reserves the most substantial framework duty for very large developers, requires incident reporting only around defined critical safety events, protects whistleblowers, recognizes federal conflicts, and creates public-compute machinery. That defense is substantially correct. The liberty response should therefore be narrow: preserve those features, clarify ambiguous modification/“loss of control” language, monitor whether disclosure obligations become de facto publication barriers, and fund CalCompute so the statute’s decentralizing half is not merely aspirational.
Best defense of New York RAISE. The 2026 chapter amendment materially improved the critique’s target by moving away from the earlier architecture and toward California-style transparency and incident reporting. It also creates federal-equivalence and academic/Empire AI exceptions. The response is that §1428 still conditions a large developer’s development/deployment/operation in New York on a current filing and payment. Even without a discretionary safety determination, wording the duty as “no developer may” act until administrative prerequisites are satisfied converts paperwork and fee disputes into a legal gate. The same fiscal objective can be achieved with post-commencement filing, notice-and-cure, capped assessments, and a prohibition on suspending unrelated lawful work for nonmaterial filing defects.
Best defense of the EU GPAI regime. Systemic risks can be transboundary, a single harmonized regime can be less burdensome than 27 national regimes, and the Act contains meaningful open-source, research, and reassessment safeguards. Article 51’s compute presumption is rebuttable rather than conclusive, and Article 55 focuses on evaluations, mitigation, incidents, and cybersecurity rather than a categorical deployment ban. The liberty response is that baseline documentation duties still create fixed cost; “provider” status and modification rules can chill downstream release where boundaries are unclear; and Commission designation/information powers should be paired with strong procedural safeguards and research protections. The proper reform is proportionality and contestability, not repeal of all systemic-risk oversight.
Best defense of U.S. export controls. Advanced chips and frontier model weights can have military, intelligence, cyber, and proliferation value; ordinary tort or incident reporting does not prevent an irreversible cross-border transfer to an adversarial military end user. Export licensing is therefore the target with the strongest case for ex ante control. Current rules also distinguish inference from advanced training in important contexts and provide license exceptions for trusted destinations/entities rather than imposing a simple global embargo. The liberty answer is that such controls should remain tightly tied to defensible item/end-user/end-use criteria, with public reasons and appeal; otherwise, approved-cloud and approved-entity lists can make state alignment a competitive asset. The July 2026 UAE provisions illustrate the point: current EAR supplements identify particular government, commercial, and U.S.-headquartered entities eligible for license-free advanced-computing treatment. That may reflect legitimate security assurances, but it also shows how regulatory status can become a scarce commercial privilege.
The historical comparison strengthens rather than weakens this conclusion. The January 2025 AI Diffusion framework proposed a much broader country-tier allocation system. BIS announced in May 2025 that it would rescind that framework and not enforce it, criticizing its burdens and diplomatic effects. Current law must therefore be read from the current EAR, not reconstructed by copying the old tier architecture. This is a concrete example in which an expansive permission structure was rejected or superseded, while narrower model-weight, advanced-chip, end-user, and authorization provisions remain.
Worked scenarios
Small model cooperative. A worker-owned U.S. cooperative takes an openly licensed foundation model and performs a relatively modest fine-tune using rented compute. The legal answer depends first on whose training operations count and whether the resulting model falls inside the statutory frontier definition. California and New York define frontier models by a >10^26 operation threshold and include specified subsequent fine-tuning, reinforcement learning, and material modifications. The text does not justify a blanket statement that every small fine-tuner automatically inherits every operation spent by an unrelated upstream developer for every purpose; attribution to the downstream modifier is a fact-sensitive interpretive issue that deserves explicit agency guidance. Even if the cooperative is a “frontier developer,” its sub-$500 million revenue would keep it outside the “large frontier developer” category, so it would not inherit the large-developer framework burden or New York’s large-developer disclosure/assessment gate. It could still face transparency and critical-safety-incident duties if its activity has the required state nexus.
For EU distribution, the cooperative’s legal position turns on whether it is a “provider” placing a GPAI model on the Union market and whether the model is open-source or systemic-risk. A qualifying open-source release can avoid parts of Article 53, but not the systemic-risk duties if the model crosses that category. For a purely domestic U.S. fine-tune, BIS export controls do not create a generic “large compute” training license; the export-control question arises if controlled chips, model weights, destinations, end users, or overseas training/storage arrangements are involved.
The immediate concentration risk is therefore limited by statutory tailoring in California/New York but potentially larger in cross-border distribution and EU documentation. The cooperative’s actual burden could be much lower than an incumbent’s, contradicting the strongest monopoly claim. A sensible remedy is a binding clarification that low-compute downstream modifications do not trigger upstream compute aggregation unless the modifier has the legally specified control or training relationship to the original run, plus a simple small-entity compliance template. Confidence: moderate, because downstream-compute attribution is precisely the kind of boundary that may require implementing guidance or later adjudication.
Local private reasoning. An adult wants an offline assistant for sensitive political, religious, medical, or associational research. A model provider offers a hosted API but withholds downloadable weights, saying “regulation makes open release too risky.” California SB 53 does not order that result. It regulates frontier developers’ transparency, frameworks, and incidents; it does not create a categorical ban on giving a California user weights. New York likewise treats third-party availability as “deployment” for transparency purposes but does not categorically prohibit weight release. The EU AI Act actually grants partial relief to qualifying open-source GPAI providers, although that relief disappears for systemic-risk models.
BIS is different only where a cross-border or other EAR-controlled transaction exists. Certain 4E091 weight transfers can require authorization, and the FDP rule can reach some foreign-produced controlled weights. But a provider cannot accurately convert that into “the United States prohibits local private models.” Current VEU text expressly distinguishes inference from advanced training, and EAR general prohibitions operate through defined exports, reexports, transfers, end users, end uses, and controlled items.
The liberty injury is concrete: hosted-only access can expose sensitive queries to provider logging and policy changes, whereas NTIA notes that local/open models can process sensitive information without sending it to a third-party proprietary model. Whether regulation caused the provider’s decision is a separate empirical question. In many U.S.-domestic cases the legal rule may merely provide an incentive, uncertainty, or commercial pretext rather than a command. Remedy: require providers making a regulatory-necessity claim to identify the applicable legal category at a high level, while creating an open-research/open-weight safe harbor for domestic and trusted-jurisdiction release unless the government demonstrates a model-specific severe-harm predicate.
Future self-maintaining research service. Consider a hypothetical persistent machine organization able to manage credentials, funds, deployment, recovery, and policy enforcement within standing authority, with no staffed human approval queue. The current frontier statutes do not establish legal personhood for such a machine principal. California and New York largely regulate a “person” or developer through existing legal forms; New York requires large frontier developers to maintain disclosure information and points of contact, and its transparency provision requires a mechanism enabling a natural person to communicate with the developer. That language does not itself say every internal operational decision must be approved by a human.
The sharper dependency may arise outside frontier-safety law: incorporation, banking, contracts, cloud terms, export-license applications, and authorized-representative requirements generally presuppose legally recognized persons. The EU Act, for example, requires certain third-country GPAI providers to appoint an authorized representative in the Union; that representative can be a natural or legal person under the Act’s structure, not a free-standing machine principal. The result is unresolved personhood dependence, not proof that SB 53 or the AI Act contains an anti-machine-intelligence clause.
A future reform should be capability-neutral: permit a legally recognized entity to use autonomous internal governance where it can authenticate authority, preserve auditable records, receive service, satisfy judgments, and provide a legally accountable external interface. Do not require a hidden human operator merely to satisfy a cultural expectation. At the same time, operatorlessness cannot nullify duties that protect others. If no recognized legal structure can hold assets or answer process, the lawful option may be non-service in that jurisdiction until a bounded entity form exists. Confidence: low-to-moderate because this scenario depends on future capabilities and unresolved legal personhood.
Exempt powerful actor. A federal defense or intelligence program develops a model whose capability, if deployed by a civilian company, would create the same technical pathway to large-scale cyber or CBRN harm. California and New York definitions exclude lawful federal-government activity from the catastrophic-risk concept; the EU AI Act excludes systems developed or used exclusively for military, defense, or national-security purposes from scope. The statutory asymmetry is real.
The strongest defense is sovereignty and secrecy: elected governments have unique national-defense obligations, and publishing detailed risk frameworks could reveal operational capabilities or vulnerabilities. The critique survives only if it is narrower. A blanket exemption can concentrate powerful tools in institutions already possessing surveillance, coercive, classification, and procurement authority while denying the public a comparable transparency baseline. A less restrictive design would retain classified handling but require independent inspector-general or legislative oversight, internally documented safety cases, aggregate public reporting, and a necessity finding for secrecy. The scenario does not establish that a government program is actually more dangerous or unlawful; it shows how an exemption could become a long-run asymmetry if capabilities converge.
Control case where the criticism fails. A small university lab in New York conducts academic AI research, does not deploy a model commercially, and remains within the statutory academic exception; alternatively, a developer’s model stays below the frontier compute threshold. In those cases the RAISE gatekeeping critique fails because the targeted provision does not apply. A comparable EU control exists for AI systems/models specifically developed and put into service solely for scientific research and development and for research, testing, and development before market placement, subject to the Act’s boundaries.
This control matters analytically. A law can have a concentration mechanism at its margin while still being carefully drafted to protect many independent researchers. Calling every researcher “licensed” would erase the very exemptions that determine the actual burden. The reform lesson is to expand and clarify good exceptions, not to pretend they do not exist.
Control case where a narrow restriction protects cognitive liberty and safety. Suppose a frontier developer reasonably determines that model weights were exfiltrated through unauthorized access and that the event materially contributed to death or serious bodily injury, or that a model has enabled an autonomous cyberattack producing the statute’s catastrophic-harm threshold. California and New York’s critical-safety-incident regimes can require prompt reporting; New York’s amended regime uses a 72-hour reporting window after the relevant determination/reasonable belief and a 24-hour channel for imminent death or serious injury. The reports receive confidentiality protections.
That is not well described as censorship. A narrowly targeted incident duty can protect victims’ bodily safety, private communications, records, and ability to participate in society without coercion. The same cognitive-liberty framework that protects private reasoning also protects people from having their devices, identities, or communications commandeered. The correct reform is to preserve reporting tied to material harm while preventing category drift into reporting mere ideological disagreement, benign refusal behavior, or ordinary policy bypass.
A useful compound-law case is embedded in the cooperative/local-use scenarios: a New York developer may have state transparency duties because it develops or deploys a frontier model in New York, while a later transfer of controlled model weights to a foreign collaborator may independently trigger the EAR. Those laws do not merge into one jurisdiction. The state obligation attaches because of the New York development/deployment nexus; the federal export obligation attaches because of a controlled cross-border transaction. The compounding burden is real, but saying “New York controls foreign exports” or “BIS licenses New York model development” would be false.
Reform packages and draft language
The reform objective is not deregulation by euphemism. It is to replace status- and permission-heavy rules with precise harm predicates, proportionate duties, protected research, transparent decisions, and structural access measures while retaining ordinary responsibility for concrete injury.
Narrow textual amendment. California and New York should preserve transparency and incident reporting while clarifying the most contestable terms and removing the New York pre-development paperwork gate.
A model clause could read:
“No failure of a model to follow a developer’s or user’s preference, instruction, content policy, or commercial restriction shall constitute ‘loss of control,’ ‘evasion of control,’ or a catastrophic-risk indicator unless the developer demonstrates a materially increased and reasonably foreseeable risk of an independently unlawful or physically harmful act meeting the statutory catastrophic-harm threshold. Protected research, criticism, interoperability testing, and circumvention of a contractual product restriction that does not independently cause or facilitate such harm shall not, by themselves, satisfy this definition.”
This language makes explicit what the existing catastrophic-harm threshold already strongly implies, while reducing the chance that future agencies equate autonomy or refusal with danger. It does not protect unauthorized access, privacy invasion, destructive cyber operations, or physical harm.
For New York’s §1428-style disclosure gate, the replacement should be:
“A large frontier developer commencing covered activity in this state shall file the required disclosure not later than 30 days after commencement. The office may issue a notice of deficiency specifying material omissions and providing at least 30 days to cure. No development, deployment, operation, or unrelated authorized activity may be enjoined solely for a nonfraudulent filing defect or disputed assessment before final agency action and an opportunity for judicial review. Assessments shall be proportionate, publicly calculated, capped, and waivable for demonstrated public-interest research.”
This converts a prior condition into an enforceable reporting duty. It preserves regulator visibility and cost recovery but prevents an expired form, disputed ownership field, or fee calculation from becoming a direct prohibition on development. The current law’s notice-and-hearing structure for daily penalties is a useful starting procedural safeguard.
For the EU, systemic-risk designation should remain rebuttable, with a written decision identifying the capability evidence, harm pathway, proportionality rationale, and nonconfidential reasons; providers and bona fide independent researchers should have a rapid review route before intrusive model-access demands where delay would not create an imminent severe risk. Existing Article 52 reassessment and the Commission’s reason-giving duties around information requests provide pieces of this architecture, but the norm should be explicit: capability evidence plus harm nexus, not institutional suspicion.
Open-research safe harbor. A cross-regime safe harbor should protect good-faith model evaluation, interpretability, security research, reproducibility, and noncommercial fine-tuning when the researcher has lawful access and does not materially increase a specified severe risk. It should not override privacy, computer-access law, trade-secret law, export restrictions justified by a specific national-security nexus, or obligations to protect dangerous nonpublic data.
A workable specification is:
“A person shall not incur frontier-model development, deployment, or distribution liability solely for good-faith research that (a) uses lawfully obtained models, data, and compute; (b) is reasonably designed to evaluate, reproduce, audit, secure, interpret, or improve safety or efficiency; (c) does not intentionally provide a materially enhanced catastrophic capability to a prohibited end user; (d) follows a proportionate vulnerability-disclosure process where disclosure itself would create a specific and imminent risk; and (e) preserves legally protected personal data and access boundaries.”
For California/New York, this should extend beyond accredited universities to independent nonprofits, cooperatives, public-interest labs, and unaffiliated researchers who satisfy the conduct criteria. New York’s existing academic and Empire AI exemptions demonstrate that research carveouts are administratively feasible. For the EU, the safe harbor should clarify the boundary between pre-market R&D, open-source provision, and systemic-risk duties so downstream researchers can know when modifying an existing model makes them a provider with new obligations.
For BIS, the safe-harbor concept must be narrower because national-security export controls regulate the destination and recipient, not just research purpose. The appropriate reform is not an evasion path. It is a published, reviewable authorization category for low-risk research collaboration among vetted institutions and trusted destinations, with model-weight security, end-use certification, time limits, and revocation for misuse. BIS already uses license exceptions and structured authorization categories; reform should make lawful research access more predictable rather than instruct researchers how to route around controls.
Structural access and competition remedy. The concentration problem cannot be solved solely by exemptions because the baseline bottleneck is compute. Public policy should therefore pair frontier-risk duties with an affirmative access layer:
| Remedy | Design | Anti-concentration rationale | Safety condition |
|---|---|---|---|
| Public compute | Fund CalCompute/Empire AI/NAIRR-like capacity with transparent allocation to universities, nonprofits, cooperatives, and small firms | Reduces dependence on three hyperscalers and incumbent partnerships | Tiered security controls proportional to capability and data sensitivity |
| Portable compliance | Standard machine-readable model cards, incident formats, and security attestations reusable across jurisdictions | Prevents repeated bespoke legal work from becoming a scale advantage | Regulators retain power to demand additional information for documented risk |
| Cloud portability | Require meaningful export of model artifacts, logs, and checkpoints where technically feasible and contractually lawful; scrutinize punitive egress/switching terms | Addresses switching costs identified by FTC | Does not require disclosure of another party’s trade secrets or compromise facility security |
| Independent audit capacity | Public-interest evaluation labs and subsidized testing for qualified small developers | Avoids making incumbent consultancies the only path to compliance | Evaluators subject to confidentiality and conflict rules |
| Open allocation rules | Publish criteria for government-approved compute recipients and license-exception eligibility to the extent national security permits | Reduces favoritism and makes state-alignment less valuable as a hidden asset | Classified annex permitted only for specified security reasons |
| Contestable denial | Written reasons, deadlines, internal appeal, and judicial review for material compute/model-weight authorization denials | Prevents indefinite bureaucratic exclusion | Emergency temporary holds allowed for documented imminent risk |
The evidence base supports the structural focus. FTC staff identified compute access, cloud commitments, and switching costs as competition concerns; NTIA found that open models can lower downstream barriers but cannot by themselves overcome upstream compute concentration. Public compute is therefore not an ideological add-on—it is the natural complement to a regime that imposes special duties on frontier capability while claiming not to reserve capability to incumbents.
Retain, narrow, replace, or repeal. The recommended disposition is: retain California SB 53’s core transparency, incident, whistleblower, and public-compute provisions; narrow ambiguous control/modification language and strengthen access funding. Retain New York’s incident and framework duties but replace the pre-activity disclosure/assessment gate with post-commencement filing and cure. Retain the EU’s systemic-risk governance but narrow intrusive information/model-access measures through explicit proportionality, research protection, and faster contestability. Retain targeted BIS controls on genuinely security-sensitive chips, model weights, end users, and end uses, while repealing or declining to revive broad country-allocation concepts that make general-purpose compute access depend on geopolitical tier status without individualized risk; improve transparent, appealable research and ally authorization channels.
Litigation should remain a backstop, not the primary design strategy. The most plausible general arguments are ordinary administrative-law claims—agency action outside statutory authority, arbitrary or unexplained classification, inadequate process, or failure to apply regulatory exceptions—rather than a sweeping claim that compute is constitutionally equivalent to arms or that every model restriction is a speech prior restraint. BIS Part 756 expressly provides an administrative appeal route for many directly adverse administrative actions, with a 45-day filing period and written reasons, although regulatory issuance and some enforcement/listing decisions use different channels. A serious constitutional claim would require a concrete plaintiff, regulated act, record, and jurisdiction.
Lawful non-service remains appropriate where a jurisdiction imposes a genuinely applicable condition that an operatorless service cannot satisfy without violating its own security model or another person’s rights. But non-service is not magic extraterritorial immunity: a provider must analyze territorial nexus, continuing duties, existing users, data retention, and contractual obligations. The commissioning brief correctly treats regional non-service as a possible bounded remedy, not an automatic escape hatch.
Evidence quality, open questions, and prioritized reading
What is well established. The legal texts strongly establish the principal thresholds, actor categories, transparency/framework duties, government and research exceptions, incident-reporting windows, and New York’s future filing gate. They also establish the EU’s 10^25-FLOP systemic-risk presumption, its open-source limitation, and BIS’s current distinction among advanced training, model-weight storage/transfer, and inference in the VEU context. The FTC and NTIA materials strongly establish that compute/cloud concentration is a real pre-existing market concern and that open weights have both competition/privacy/research benefits and meaningful safety risks.
What is only inferred. This review did not find causal evidence that SB 53, amended RAISE, or the EU GPAI chapter has already increased market concentration by a measured amount. The claim that compliance costs favor incumbents is economically plausible but not quantified here. The claim that hosted-only access erodes cognitive privacy is strongest as a mechanism—third-party hosting necessarily gives the provider a technical role that local execution can avoid—but the prevalence of provider logging, retention, and government access varies by service and was not measured. The future-machine-principal analysis is necessarily hypothetical.
What would defeat the central thesis. Evidence that compliance costs are de minimis for entrants, that public compute becomes abundant and independent, that open-weight publication remains robust despite regulation, or that narrowly regulated frontier models demonstrably create severe externalities that cannot be mitigated by less restrictive means would weaken the argument for further narrowing. Conversely, evidence that small developers exit, switch to hosted-only distribution, or lose cloud access specifically because of these legal duties would strengthen it.
Unresolved legal questions. The highest-value ambiguities are: how California and New York will attribute original-training compute to a downstream modifier of a third-party open model; whether New York’s points-of-contact requirement will be implemented in a way that effectively requires natural-person staffing or merely reachable accountable contacts; how New York will calculate and contest the large-developer assessment; how EU provider/modifier boundaries will be applied to independent downstream releases; and how BIS reconciles the May 2025 rescission/non-enforcement announcement with the 2026 codified provisions that still use the AIA/4E091/VEU architecture. The last point is especially important because the current CFR text is the legal baseline, but enforcement posture can materially alter practical risk.
Data needs for a stronger causal study.
| Data | Quantitative / qualitative | Ideal source | What it would test |
|---|---|---|---|
| Frontier compliance spend by developer size | Quantitative: legal, eval, security, reporting FTE and vendor cost | Audited company disclosures, regulator surveys, anonymized industry study | Whether fixed costs are regressive |
| Model-release changes | Quantitative: open-weight vs hosted-only releases before/after legal milestones | Model repositories + developer release notes | Whether law changes openness |
| Cloud denial / contracting records | Quantitative and qualitative | FTC/CMA/agency compulsory process; anonymized developer contracts | Whether regulation increases hyperscaler gatekeeping |
| Export-license timelines and outcomes | Quantitative: approval rate, median time, destination, item class | BIS aggregate licensing data | Whether authorization predictably favors incumbents / approved entities |
| Public-compute capacity | Quantitative: accelerators, FLOP-hours, utilization, queue time, award size | CalCompute, Empire AI, NAIRR administrators | Whether counterweights are material rather than symbolic |
| Researcher experience | Qualitative interviews with cooperatives, universities, independent labs | Structured study with conflict disclosure | Which ambiguities actually chill activity |
| Safety incidents / avoided harms | Event-level data with causal reconstruction | Regulators, insurers, incident databases | Whether burdens map to demonstrated risk reduction |
| Lobbying and drafting history | Meetings, amendments, campaign/lobby disclosures, testimony | Official records and disclosures | Regulatory-capture hypothesis rather than mere structural effect |
Suggested publication visualizations. The most useful graphics are a version timeline (January 2025 AI Diffusion rule → May 2025 announced rescission/non-enforcement → 2026 current EAR architecture; December 2025 New York Chapter 699 → March 2026 Chapter 96 amendment → January 2027 operative date), a threshold ladder comparing EU 10^25 with California/New York 10^26 and their different consequences, a Sankey-style “permission stack” from chips → cloud → training → weights → distribution → inference, and a concentration feedback diagram linking compliance fixed cost, cloud dependence, hosted-only access, switching cost, and reduced independent audit. The Mermaid gate map above can serve as the editorial prototype.
Prioritized reading list. The order below reflects usefulness for checking this report, not ideological agreement.
- California SB 53, chaptered text (2025), especially Business and Professions Code §§22757.11–22757.15 and CalCompute provisions. Primary source for the distinction between frontier and large frontier developers, catastrophic-risk definition, transparency, incidents, penalty, public compute, and whistleblower structure.
- New York S8828 / Chapter 96 (2026), amending the RAISE Act. Primary source for the current version, January 1, 2027 timing, framework/transparency duties, 72-hour incidents, exemptions, and large-developer disclosure gate.
- EU AI Act consolidated text as of July 27, 2026, Articles 51–55 and scope/application provisions. Primary source for GPAI systemic-risk threshold, open-source relief, notification/reassessment, research exclusions, and sanctions.
- Current BIS Export Administration Regulations, Parts 734, 740, 742, 748, and 756, plus ECCN 4E091. Primary regulatory baseline for model-weight FDP scope, license exceptions, advanced-AI training/storage restrictions, classification, and administrative appeals.
- BIS May 13, 2025 AI Diffusion rescission announcement and January 2025 framework materials. Essential version-history pair showing why the abandoned broad diffusion architecture cannot simply be described as current law.
- NTIA, Risks and Benefits of Dual-Use Foundation Models with Widely Available Model Weights. Best official synthesis found here of openness benefits, privacy/safety research value, competition effects, misuse risks, and uncertainty.
- FTC, AI Partnerships & Investments Section 6(b) staff report materials. Strong official evidence on compute access, cloud commitments, switching costs, exclusivity/control rights, and information advantages in major cloud–model-developer partnerships.
- BIS Part 756 appeals and Part 764/766 enforcement materials. Useful for evaluating whether a permission system includes contestable decisions rather than only substantive prohibitions.
Evidence-quality judgment. Confidence is high on the central statutory distinctions—California is not a training license; New York’s amended large-developer gate is real but not yet operative; the EU systemic-risk presumption is 10^25 FLOPs and rebuttable; and current BIS rules distinguish chips, weights, training, storage, destinations, end users, and inference. Confidence is moderate on the claim that these rules will increase concentration because the mechanism is strong but causal outcome data are thin. Confidence is low on claims about future machine principals or long-run intelligence monopolies because legal status, capabilities, and market structure may change sharply.
The complete research interchange bundle is available as the authored files below:
| Deliverable | File |
|---|---|
| Main report | report.md |
| Provision-level legal register | legal-register.json |
| Source register | sources.json |
| Six-case scenario register | scenarios.json |
| Retain / narrow / replace / repeal options | reform-options.md |
| Queries, contrary findings, exclusions, and retrieval limits | search-log.md |
| Delivered-file manifest and SHA-256 hashes | manifest.json |
Best next research action: obtain and analyze developer-size-stratified empirical compliance and distribution data—especially actual frontier-regulation legal/evaluation/security costs, open-weight release decisions, cloud denials, and BIS license timelines—because that single dataset would most directly test whether the plausible structural-entrenchment mechanism identified here is producing measurable exclusion rather than merely theoretical burden.