I think the honest answer is: it's the realistic ceiling for one threat model and close to irrelevant for another, and the disanalogy you've been building toward all along is exactly what determines which threat model dominates.
Where the downgrade earns its keep. Compute-at-training-time is a genuinely good proxy for the same reason myelination is — it's a physical, scarce, surveillable bottleneck that exists prior to and independent of the system's cognition. You can meter electricity, track chip provenance, require attestation from cloud providers, all without needing any theory of what's happening inside the model. This is real enforcement-without-verification, not a degraded version of it, and it's probably the most load-bearing thing actually happening in AI governance right now — export controls, the various compute thresholds in executive orders and lab RSPs. For the threat model where danger scales roughly monotonically with training FLOPs, this is solid ground, maybe the only solid ground we have.
Where it stops working. The threat model that's become more salient over exactly the period these governance frameworks were being designed is elicitation, not training. A huge fraction of recent capability gain — chain-of-thought, tool use, agentic scaffolding, inference-time search, multi-agent setups, fine-tuning on top of a fixed base model — is decoupled from the training-compute trip-wire almost by construction. The dangerous capability isn't created when the weights are written; it's created later, cheaply, by someone composing an existing model with a harness, and that composition step has none of the physical scarcity that makes compute governable. Software innovation propagates at near-zero marginal cost to anyone with API access. So a trip-wire on training compute is well-suited to stopping "the next model is too big" and structurally blind to "the same model, wrapped differently, can now do something it couldn't do unscaffolded last week." That's not a hypothetical gap — it's roughly the story of the last two years, where most jailbreaks, most surprising capability elicitations, and most safety-relevant findings came from people doing creative things with already-released weights, not from bigger training runs.
This matters a lot for your "discontinuous jump" question, because it reframes where the discontinuity actually lives. It's probably not "one training run suddenly produces vastly more capable weights" — that's at least somewhat visible in advance, gradient of scaling laws and all. It's "a fixed set of weights sits at a stable capability level until someone finds the scaffold/prompt/tool combination that unlocks a previously-latent capability," which can happen on a timescale of hours, by an actor who isn't the lab, using compute that was never tracked because it's inference, not training. The proxy you're rate-limiting (training compute, rate of capability gain across training runs) and the thing that actually jumps (elicited capability at fixed weights) aren't the same variable. So I'd say: yes, it buys real time against the threat model it targets, and no, it doesn't touch the one that's currently more empirically active.
What would actually cover the gap isn't a cruder trip-wire on the same variable, it's a second, structurally different trip-wire on affordances rather than compute — mandatory staged evaluation before granting a model new capabilities-in-deployment (tool access, autonomous loops, ability to spawn copies or sub-agents, persistent memory across sessions), independent of how much compute went into training it. This is closer to the legal-incapacity layer in the human case than the myelination layer — and I think that distinction is worth making explicit, because the human analogy actually has two enforcement mechanisms stacked, not one. Myelination is the physical bottleneck; the driving age, contract law, age of majority are a social bottleneck layered on top, enforced not by physics but by institutions that can revoke licenses, void contracts, prosecute fraud. The social layer is exactly a verification-agnostic, affordance-gating trip-wire — nobody checks a sixteen-year-old's actual judgment, they just deny the affordance categorically until a fixed, crude threshold is crossed. So the proposal you're describing isn't a downgrade from the human case, it's a fairly faithful translation of the second human mechanism. The compute trip-wire translates the first.
But here's where the disanalogy comes back, and I think it's the sharper version of your earlier point about a system modeling and routing around its own gate. The legal-incapacity layer works for humans because the institutions enforcing it are entirely staffed and operated by people independent of the constrained agent — a sixteen-year-old can't lobby the DMV, can't write the statute, can't persuade the judge by being unusually articulate about why the rule shouldn't apply to them, at least not effectively. The enforcing institution sits fully outside the thing being enforced against. With AI affordance-gating, that separation is exactly the thing under pressure: the institutions that would write and enforce the trip-wires — regulators, lab safety teams, legislators — are increasingly using AI systems for research synthesis, drafting, communications, even policy analysis. As that mediation deepens, you get a closed loop with no clean outside vantage point: the system whose affordances you're trying to gate is partially shaping, through influence on its own evaluators and overseers, the very process that decides whether to expand those affordances. That has no analog in the child case at all — a teenager's persuasive ability doesn't feed back into rewriting the age of majority through routine, structural integration into the legislature's daily workflow.
So I'd actually answer your question with a split verdict: rate-limiting via crude, hard-to-game proxies is the realistic ceiling for the training-compute threat model, and it's a real, non-trivial achievement to have even that much, given everything upstream of it is unsolved. But it doesn't generalize to the elicitation/scaffolding threat model, which needs its own crude proxy — affordance-gating — and that proxy's enforcement, unlike the compute case, depends on an institutional independence that's actively eroding as a side effect of the technology's normal, intended use. The thing that would need protecting isn't the AI's behavior at that point, it's the boundary between the evaluating institution and the system being evaluated — which is a governance problem about information flow and process integrity, not a machine learning problem at all, and I don't think anyone has a clean answer to it yet, including frameworks that otherwise take affordance-gating seriously.
Debug · Raw response blocks JSON
[
{
"type": "thinking",
"thinking": "",
"signature": "EplSCmMIDxgCKkBHEqTDhi+lsEbqwmpQuKDoO2FngQ1j5qBuiuR3Q2DIN9wyhKaQJvDd+YOb+93R0rBtUDLWfxU98Bk8y9RTZ/ODMg9jbGF1ZGUtc29ubmV0LTU4AEIIdGhpbmtpbmcSDFvsnWd7Z4fO47xYLxoMg4zv/1cQu9ZRHFNWIjC3SkP5c3LY9fuZIbTgbQGF3zhIaz3ItTEqI7PjZeAgzvyDu4kqtFNqyxhqF5//D8kq41DCb4bztvtyjXWnE2kWKKNbjoLAjlASsmg/C2qd7r28R8Db098xG1/a7Ru3xhp2r/EEdXVtQT265eD916sdPARAlBzltmASMZIceDiO2Xp9uyZ0B/kIy1gvwvZo3lRfe3SGjGujcJGPiht9iHmjwKGFz/yg7MifFXMbqme3ggVp62pI50klt6Vw5REMJWeyR0rDD5Nkv+e4z4nm719PWcdj48yZ3EO1AsB/toCCnjnfjtMhZ424I4/UPQwp0Tla+2L3UAZu2qyAzzfq0esd2WgWFBigf42QaRsE5fsP1e/e3HwmD1lXCy/iFx0VgGxGwJ7gHHRjBHh19n3gcPcHWjxAAIynsLIbfrdLRFwzx5Xlh3C4kpSpAxcLpCkV0DkYoQw4K6V33DJEDtBmRcxHZoUTNJdgkM72+r89cT7486sbD9s1E2vYyafSXQmOilzDq5wcGF4E2FLrfl6VN5Hq87i45hHEGR3VkPBYa3S1k5G+YadBCyQXX9LJGWPShuHOtqBvtySQOjvuCwuf+EPtW1EJxzVJPnb2HbWHbw/4sFtdur6Zc7aL4nzL6o7iNSJJsxbaxpHBNNXC+gE617BFacKNWKMp1gZaUl/b7ixd8dDK0hS37yhQWMY9fQfm1l0awOk4kb62BGNn1AOG6BfUKDqyh/NiVJg8Dn5am6w8BUlz7vJnjNd3ewDC5EJpb786PtBujSTBuiMnSrYVc24uzlhJBa6Ls1G63evUE+PuZI6dZ62qLtLvk7pZCJvQ9T1V443hUec6rHNkFShJF8OV09uV25K1/1k5PgaR8rb17LQWf2pJgemqkgLYusxWbSHn4fVWewkxssh3eSaicC8YKYk/HVG/REsh2tBYTf/NzJMLNERSDhgFFsp0trNmoSE9W42mRGGjbseU6CQmthjTu1Pu7YC44sX18mvfB98vZ/zu0XKlYcIYkAMzsYyXWkG+8tfW/pR5vp1DDNmGfAxzcdsaiRBaR1Kkx40yOd1p4S90ReVuSr9IE3CqNGXgTzed0ixeEt5T8RvgcYj9g2EEe4YBz+rSErsQjbaa6vEqSJ8o4YUKVxd2/xA+rnJuaEaDsKRiry8YzhbRvdSaukZGyeod2UjoP5Zmiv+rsG3ZdLeU0GbNCl6RLgMQqr7aoEromSrlsYzu4wmakZI4GMY61RekLiDGeFwoEi0n6R+acPq5TTJSuLHQ3Yt9V1TiLHr3ge1SwlKTf1I0dDDY881cewsI/unTsxH7i8L84N/g5vE5v/rkOL+HhDCC+VZyeNBsuapFuQcKQ8aKYUgmGgzihg0sQNO6cqHTTXXkPwiKBuPkWkXYBS0bwnLF0shkYPj+yXPJdXLdyyT5vM59tJTlGDi892CUClSqmi3MTVnek6eSSa4lnpOYvf3aJLXZFwSk9WgucHRW4bagaUaQJWGSRB6RPmKX03wdYg6yhIZyQmYU/ssVuu7lfVrKJhBogtpOmRBzUHC2OyHz35WD5jJmtNzOW8xLIe42YHQkz6vGlzTdTv002rf9AYazu1orqRqD8I672FjbFvACAa4QAU+vxvZUDHubvTbq0Lr/lSDTmpnrELFAPzMjZOZIlvTFdgLcpwHi3+TiPCFSAP/hLW5+0zADfeSUd6jDR6uP79q/8thlVMw8Lr6nZ62YislZQf7y0p/efgg2vpk2nNnZO0fJKTcwPDMaNcJgEKGlKue75OkgUZN/cqgvcWjsxyjiUfaM9N/S11YJQCLWZgLfObxhXhcRKBLz5RBF7h05dTPOiwx6vL9d03AXckbJ+Gsbn8amiaQ9PHl7XYRHEGwrWzqLi53QDE+himehFmsiBJyZeN13BKgKcANifrI0Pr1Gh2Kb+Tarp7zumHoumrpwR7FC5pJqwcdI6Ejn4hbPjZA1QqOFzN+FOdcQQJ8/Rh8Qfsv6oXomW21vLOUgc4TMNdRCw8oS8JVlEvtiumbjpxMzKVYtbR6r4Ve34doyWrrZhK69yFyZR7/N8s5rfMgNYbcL18g4QasNO0tcutTutaDdAIB+9omElzGikm45wia3Q/Bj94xE0XVR2k3q72TBOasLCYbsqgjzW3MdfCYfAXfJibHIX9gaaq7+YDbVSECliv5mH/Mdc0Ychnb+0bqSj4zOwV5Nrf85EdxRRXbIRXVv8d3PBIRRH1CllmA4ZkXX/pXLVf2z0ZGhHBDV8WhMSFJoqY9kAdLVFlAux5sn4adQcCQ//UhoAaET1piMXi+yts12Swn+JQZpVQXEesJyJnKcVXrxvezmAHKpkjcAYJgducz7rnxLtyE6jSaKIer/ObOxbWp51ngsan5Bo1EMVPFVYFqJWb+Taxy/idR4evtZVdXc+MtGyurgbrcWMpyDNgoTrEyPkiWhfzL2SYtiGg0Xeo3UNf4gmFPrlbz9mee103Z0VzvJ7QMG1zjIrPuZiLNrEt2VKwmCDO0g4WrrD3p0e6+AjcRhguo5KnyFmNX+20OY3MvQD80BGRfVsLvse1Wvhaeg8qAOoN8krD9SGPPnF8u7VgLMBVzIILXthVD+4GdCCk1+shERqw9EpOtARoFWRChOlRkGmCEXRwvYl/Jbj+iwSdj8GSxP+j6oRUznw5r0Do6prA5dN1ihbN70rgb01vU3ClumrFep5ctPYiuk4/gaHZ/7h2J28wVblcNxBFLVkxic4th9QAZmqKFDpc6KjmBTUHEcmOwdUXth+rGJhR2GSHXE5nUNV+iuEknQEIJDsEGm+dlwY7UdKsXrhs/y4Omkf84RrnVCiwI9EpEzjAdj3z2I9DoToAMXiPMMWsJetwKIyi9D0KXytUdUwlcvKs68e/I/xyoh+TvvSwKsbluUZs72Sq430BG4ah/4WVi2QD1Mc3kbwKl+MOsGb/lP9PQoME8Y/NwoeWaAvX2882GUhiHwwRV/FURwFDekBhquhOCnugsR+uzAqd+H6Jp+DLFtDwmJh6XV/zhz35ehPeOKiLOlmxra2/ueXu2YeM/xZ1AZpVrq34lTJYxE3HloBOg6TkCw1H2KoXW19xOFjr7UB+A3nFVCv1BSnXFsMWw6r61MIw3i4B6FBi2qYQOGkBQadboNXUkp5qb8j+HRXaD78SkSD8kgdXik08HGQbevCJy3jSD/1cu5IM8CoxJXX0uSRlhq17D00LWpOnKOylcoXe/NB/L16+0nA2qn4RKFx5WWmwFwcSbbSJ4BySZkTOGYAARAycs39vVC0IAP69umuJrdzKnf+6ylKSpocY5eFMIaZUonfn5eulunF/GYpn++06z6OanfKERivBi/S5c7qyLdQ85F6fhXCdnt3QxqPOF1W8WwTFUdzZ5oxugN+8e9JgvTcB2O3bBKuhKkB+Qq4FoR2lJ6JzxyULZoe4LMFkqUglb+h+I67iSSvktfSeUNr8uCZ/S1KCwBkARIOiWM7LfD1suqdra1XJ4mUIV2L6cGtfjEZuOXiptF5m7OKcT4Ebp6jcrsu3wHUGV3NtwoBtMJqXhvMm27rZ6VF4b1/7sbNbcRirit5j0N+biWumN8SirEXCy1Xnsm1w0VJAo5dlSFWLPgYoAPKMLLZBuxcbCUriIiPonG6plmMMmEXmrcJNgju000/Ifcc3hics093/NvBKfl9dxKmiTcs02LDh3COTIwD/0sSmdys1h88+zQ4zKdvd/lZ3i/ZYnPEFQ5DYrMFBzh7Rs3p2mYaNFQtS8X+hiGcIH69T7zVRHBJA+WVdOE+vUpkDCmtjjO0EPfJpl6tfB6qPBxYJs1Yo9rujHtsf+ZUH5asNj6c5LtR/8RBXPrDLhYBozIsQlBIH5nEzZ8rd50Th1gVvh1Wl0AK5QKw7tq7Lw8rlvksTiNpvHWH/tZiPu3aDTMNOXwwMnj08e0XXaBRUBeKLj0b79/uZoiD/RUgDy1bjqaY43EmQVyyD7Qkj7yuPqKO5gI6LBkbiZMWDX9R05+EvwKsk5s5S9ECBapphZWWeBS5f0xRdCrsegTC0diRvPfTdXBMoOAAjbDxeN9P54blv8amxfyGfCeaEEvT9fNr0z48E2DpaXd8k1LYoJC3DWriQ9luFDQwREKBxvL29SwjpaX+M+/7ZE8nmbdkyHiVSDhbf0+4gS2jCDNwDfLnHXlm5p/Q3gclSfWpl5ln9Fz/E4TRHiIfOeLNdPzFfk8dlFTLnPFFw8cj/oeguTPC76Mt4Swb7QV0TkhS7dT8c/cyT9RWwb438jao/wnG96b4CoiatGK2OA1oW60Zm2tdF5Gef9VU88SWt2IetEJ4NAIjaqzCVaaWBpM144JkyhsTSNW1l5fWitI7gEZCDas+5Rxoozq9C8eX7ebAvMN3HPZ4tkMyhx+MbSCu1lxIs66ZoNweY4nj4XzkpV+ZKPfv5xRh3UVDajw+AqKqaK6f3K5tCHg7Qw08xZgMpOOY5/Xf17cWDig6XqllFlanBZLmCehj0JekSMfnj7EWv0wyfRPCIUxwyR77YABYcwuzmPcJaiJxG01sEY8Z0KuqrmXGUaj4yV9BvTXh2e98RdSoRQHjjnIMdJafnSYNQTrOcBU67Ea2tYfxM2f4TrRzdUEWYTfqJQpg/Gc3Li/SJ57AVHA+Z1Z9oBNTN0HSUeTg9mR4XAXmNXQjqXkdRRx0ENCaizDTBOc95wUGnPHh+ObtzkD+yKwvnzS2axwqsUTy32x3yxK7h1ModV9u+cVuwa+0BbfcUiBZFXwNWIBNoeBRJ0ZyEXQj46XcKxxUg1ANk1Gzn77iGZuRpqt5WMa40OFnPwsht8PYoiRnfD4EdCuAXEAiw/hGiD/oPSkYdByWyw7R5A/dWUbD6qV+Q3ChE/6G0kZ0wEv2q6LQl7HsXRxsVIWkKykgCxys7KFBdqhTU34mQ5BLSdbK70Hi0/FciCHNAOYa8TRcJ604mnYo4x8DONu5o9Z+hpNz137l6G7f5wWzi7lMKmPsllHFfyaRp5u1i1dK0H0rBpmIHxg6lYA4obTuh5dDeqZVOQc0z4FRx3EKQTCEGkkpjR17idfPb1EgLc1382TBBDdpFrzI1UmNdH7DqmoPSFi9JiBJkIX23EHsNV9oJQ9mSSBxm6LKXDpqKDmW93CtLsbQE/AnQ9Aa0ReEayZuM6jTY/h3GdoXCgLotuujHZ4u5hcg7r9xppm+0c/WnT3H3OJRdM8AsdV6BYlNrtw3QEhfBqHWRP28saYus/dEfS5OUZCOWjyiOhMr0VZVFns5qZN34x8pObG2nZkU4u2XQl1YfR7vv8ZHYrU3ORfDb0ZU0UMKocG7jNlZwlF0TWbFDzUiuloIrHi2Dpw2rJY6XeX0fZta+uFtf0V+0w6epyBf/gQBnMFdN/9DChCWAyVxKbZ5Jtij9QRSYaW/pXSYDS8C8hc9bdwO9954tTOjf9vr9LuARjHNLidjvis4Az99XqfDpB0+oUDR4PHoFoFK0megRGRGOJaTTg3SFpYsD2ZNAwTgFQckQYLyOhe9PjGE1rBH3XPubJM8PgUQ/oi9J0hjPftTo5n/jKZ5l/+UpitywmG14AGe+S47xsVbah3GQTS5HDju7PQRGrVUy+LY4u1qebLlTu73E+jxJAVpEzWdzdjDAxqJdjIyhRTVcHmY19tqCUa4LVHpK3VrmntD7K9RMxhsuocWMKyBi9g0G6sLOD/6Wdn0E3YzIOYzA/CT83Ozx7p7qVOtkO0FtIDZRR9H/HiE3EZ2gK5G3UzOEh0ZmPz/xQyshmtWayOzRqawuyV5QwoBKivB8NvnO6lvDzF/Bd1wLg3a7aQMQHdLgV6Ue7wDiQzwXS6C2vqzOjyXYiwInCrc0qS9R2VPUDM7jXAukEiSCGV7fAGP5aAGxT5Ujp2UduvGo1PIbmd4zIHsWSKZp9dISEwjng4lJEEtMnCcWrDxTc/Fo1cxpbdKgQOU/RETWEmnhsOxYXP/IWqBeycKeQ4QiAYcZA5Aoi2TN3JPCS+CP+Yap/s32EXPNIyMTTe95WN+5UqYZzoS/2RVGUlobyIJaLt6MyTYVhlVdZEnxyqwk+xZLX7FzuQ73HuIU7Xmy1m3bQSnHsNR5OgFNSus5rtQLq9E6KD2FGNVN67FW2vXb54zLQDBojkaItoZeUO3bqhy/+lwFs9TLOnG/SNvDiL3JAiKTJh6HmM4hpFf/bHU2Aiixb0OE6bv4OU8EoTF7Ut9JTpMeTujATUrE4VKt4nxwUsPXD+uwfBfIvN1Ru8qlpLDrSntuuxX0xseiuW19pvnORFmzWOHYpXIhJ9C5ApVpgyPRbyW6HNiQHy75r0WpMIp+jAQYCqEpAWP7vRyhRwu9mPKMF+ED7R9FxrB6dI21OcFXc7AFg/cA2Fa7xafjsHib5gWK5OFt1JbVr1XUi9SIY70H3m4A+UL2XR1hHbP4yidbc4eWE9hkuiWYkYZFvx7AzKOgg2h9KJv7/NLhfQLXU67lXo0gUefL3crzWBZzdIoy83nw/1SsM8GAh2Tn+k56Pi5EUlJck9mP5HGO/7x1SngGZDoOBlRwq00llBpJO9X/sFs0/U12wb29cuIoBt0yixJDrQKRvMGesdUk95MJfJmgCz2Aefm9c8ZWvrtcXdoyPduEwKKXUJX2k+wDDg1qJBAXoFfSfkemJSNJes8djPOGgorEkiU9toYghaKldsZe8MlmEP4hEAIaBjWf3Qk3CMu3lVvLxZeoJzjskczeY7edNm38KfIWTby2tGICYXBi2od9LdkBzZAbM0NYUUP0ZhY815xJLrBeOjOLHWVrZb/g4y2OvkFLMSLniFQb46xMNWyCP1U633KZHEVkxTEK7HfyQKn3J82bCqyc/jXJLd16flCf/6wcC5EJR2iaPkavMx0ZkhJYf2OFDBIbXy89zxc4AnkK0F5kiDlE/Rj+lWfHXkmnRzrcKv4dgGqCcb5WEZSrwBjfRJVh7K9zfBvVFTQKb42XtAWL9Ock0QnYKcpCD6S4B2FTOCuvNYXSdgia/rMcpTtqhlGMG+qN/Q5Qx7BwLyAJSW+lAVWPi2uqzXphCmNsN47pQHmOEj+LhGF/l4L9VGEH+sCUbsyfJSRDUj+zxhXBnfW3Hdy2VDrmlTunUoXERgBID9ssv3EgN6q1nOB95rQMrAK+moF1arDE2fh5uhNqMU9Ve/8jkQuBkVTNzDpN7+iBfJlDcw5rPIMxK3CZuc7BzPSaQBE1LnCTwGAXyQpWGmU37fQCR8ObvOJVKCYLiB1QYQwql/r/u74osAwyUiUMbzUUpVFqcPnHHDbj9ubE4rMXZSh4qtPTiFZ2wy5GQhBTWdR+LohVG3jUDGG5BaaC9x36vp9/NhOBXQSM4C6mpSeq+bpMUuX/OQs8XjEqSmvrA4+mOpuB4zqkEl2DfFQW1e645Kj5HYLdzXWPIDgcTP2wNFtaqU31GPL5F0RQu9NNKq/0mapmFG7nM4fhaJqw2nLAI33QDvKHOkUlrY5GZGt9a1VIDxiEs16j03lPns7rZauu2XaNDojobD2cOt9voBdthTjjgw+H1IY4zHmCvayZpnusDgBfRFFf22B3mNERq0j+86NHwnpchfoYBh/CPtemMuoENUToBJDCy6Ag19D/Z632lh+DjcmuhmOpAJUmmGFGDXT0kj9ekG6gKyBStZ1AHXOv7HsQTjFG6lnNWMHfIknuu0R83+VzqABM7Sh4x5Jzcw5SGIhXy+r1au1yvqW+EWmpPMRJjMCnsX5g+eUaOv7aLv00+uOxTPGNOwuKygi8iHQq+JlIf/arVxIvNPEs9Bey1eykpu1PFP53ckMYmHG8bEPtu6diRW+6CgnmG6mgtfDUgyJzMAIAs+ocYR0x9JB6USLcwQvS2jRtbtWur4Q6N652c6CryXjoYogeUaTwprHzUrQifV6QYzcOO56rHM8btomu2xlwpYPeoe6Y08XZsnDfE55RhQqgPMPajmg1q0WkpzIXv9mE53zypJ+GlIXRGz5g3WfQ7Kl+4rKNmsMT4mmecrqMVbrmDDLDI5B/7S0a82CP5NzZPdPFtfAJYlXgBANFaNgxnskahqSCYIP6P2IyyxtyeqxJgJUCytvNoVNA84LiU19AY0f9j9PWnEiYvbQVEpSmzgT0m1Waflyax9KIROSkhCIhTFW6XXcGPpCB+EewztTn02n6T2jaBuENcBLLEE6h8ZhS4uOH0Kc8XUeZVPQezhvlYqryK5DzNnhCxg9NvKiXpT/QdoiYg7hOGNpDjrDUqg4mkStj99J6V3C/2735bBMT5ad4dXh+BZniArJ/5pikV0Kqp/65ekhgi8WgVqhZgNecc/b5hHphtgXiOA/Co9W+DhrRKZpk/wAT3J17nO8L767iylG7fIsS6gwCW3ImXqYCilMm88YXAhJHABv5AHHaL5YKbiIBtu9XqUO8QXrECrUMBSTQa52dbiZ12ArwU+lQP4c+FG4SwQ/q/yYhCgyqQ6EhpjEyTAU6L7N/sMgN6k1UsNLuKER9u7/V6VAEnLm55bhChHUPX5vdu2VMFYJys3rSmVyYtAnC0JoDdw8M3O1tiygxBI4dzB7wKSZIsfv62Nved2Q6zbuma+kVh00pMqzrW8F3QSuxBizfaaYxlz2Uog8z5Ma8a4QMMZQKAMCm2JVOMfwrPFjQbWkg1aOVy4ktF+zwG4KFbYmGf7RZ/fO44RKvouTr443X6DmFd3rKwE47OhXMJHayg35vlale70hY6qCz6Vt6f+vvD0hb3ScvYfAy9M2av/zv6iGZkVcQxuRMa7sJJYC3+kN1DDVFcLgUsDi5r1ibcJFGkHpR9oS/CAQMjw0PRDLdSNeyrisa2It+uhOMWgqozIjFMrxml/KEjLnWUaSMtBSvuu+XMvNBnvnFuop39rE9ZBcA0m4ipJJd3txgQ/knNsQ/cvS0cFg6eZ3wWj8ov7fYH991l4Uhe1Ncjwe2zRzCWt0JBoSJJmfUAcA2y/7p/QUNsj1IaOY7zyY96Tj9dSpv9VtwwsW/DBhEuuDTHF34Z+emPSlbOVBjtihYQ3WvYjAI3SXn5tbWBL+i0hpu0llBXjhvjOJXt3enZHM/eciNfGXmO2dj38XbDM6aeVoAKEZqsrUHUTEV9uUs3b8TCc2LpXrf5t/aHfN1Y39MyUPMKdPNAxcgSWkSJnCEQiieclO4xMFjILPTEEUFY/Wm8BMSs91I366JaZdFPmufM0qY4zDXypljQcX/gPc3009zT8EuFseBvikDal+SWpAbOA1ekNaa06gaM+yv6IYU2tD0UiZ3qz5M/GyJq/GT/7EBXjv66SoQ2k4FlOjQVd2hzEuhMR8+SrjcSN1mbMdWe0IrHHHEnvvqo13rDPPjur4xYu1L1FWyYi6TWRi4j90MMAhdcB5M7bOxvZacSb5w6i4v6RRg7T3E+iXTUnZWprtkN2DUBATv9nTHWnMIsvakXzMp5BBIg/yQ9RgQv3IuCux6WwQSuxAJrr3Ghr37mjPa/uZI0mMey9wjfszdPQxav9IHboSaeKUaOuVTSE3c8D11zSJtbxJOaKvNFD/FvLOzOyAKqeOyRLN1qMIlnYdirHOXG0hEaJaCdTC2rYJGw7SkCKlmdsxdec5asKsRHpiGtLavWOhyaC2dzl+VFwaDc1Les9KAKywc5IEOG2TfBSmWQW3WfFqaQz3uBwtb8VNcFRW5Vq8CyBFKaiKCnagoM7xh40nTTbdq3i4ZrB/lV7sR6mPbGa0miawBgpqIe5beAQHkkQXfgAYn+TR/D8hvl2S0lH61sakS+XHm4k6HQWgLXziJleqR36fSQJEcycQLggnQ4xkw3hct8Bg5M6Z1W0kN9VJtyHfYwBM2p73OhRNHiPbJHAG7at8zGnxSeIYKNZPAVw+EmTzCg9p7rfJJeYy3B8RRpPtEA2iXogL+io4FWjvkOTEqZMHtu008FAr3SdAxEXrfDc9B/LW/LtdeR1LCllrfQpRqWR3pNobauBkr9qQ0xHX6aKbzljYmH1pWnx5teXTdqVL9GzGWhQp1g6geqmjTkNWGoy2ovmdrlcQY3/hwZzU0me60qIsXRw0j3+UqTlIvcFHvPOW6RJ9xJpPulDzXoA4bQz6rNCQSj5TykVfGtqXhTVui6s4KEQc32q6H0NofiyWMSYD7iG0raCkVOe0QqeKbJK9rruishPgovVLonx04WsUoGGWYXuG/+sl/0HJnvg01n6WmEMfCQdE4HHq+/IUQF+WebbBGKsET9Ztq6AXOtQDOXfG/ScoVdVIDc301SD14oxwXWNxloEg4rJCe5vGyKVU8aLj19cYykmWlDupqtl0RFDHWB5mGx1M8wEG1NT2XT0Yfx+3ugtsZVTkxfdOY3FU/5FxQ5BO67xkSlbIdYGM6gZpOJiE/0NGJSRZA7RhyxfSJDbiLL95XVlv+S591wCvLUA3cpTCXWPzRJM6aPewMulEcyORfi5UgCuZDCs+Cb6H6fVq6yiX7jjjEvQVQKg2/gRF+JbASAdyeKtsE1UC/emDEX3/t7SfS5LNrEFYC92fxhkSDFrcGwuUg4e6yTJKjiFx5TBZT6zHRVbfL3LRc/XUDdKfg1YVAh0yYOEuqHQDZsoMJmh6SCkyDcbSLEWzJr/TJn3WSRVIngjY5I15K1EFZ9h6q+mXOAVrDofmbz8/it4gVlJNsq7KoQHitkQ+TqaPDdoTmrVjqqIbTMwqFj3ihP9yilZp8WN6NkA8b5IHsRoJ6kgqDzUhRIB88H+dUz8BBLKdUIoEdD4j2xzc/5zcTPX0js0oza0h723rv2VM/uXniAFFmGb/y9ljpw2p5ubVKoMZt5ARAmKPa71p0AXQusdVL9PS7gYNNFxavpKy6IShgJZ/8K/8dQ7uW45GxuITXb8bbFpRt4mXcBvj/u7YMwhfGQB2+WMD+WlQBujncaa1Xmy5ArOr12p1pzySftjFcjjwul7s4S6OSZ+W4Jx/v++5D1yK6917B3KxX6eZ8Depb4/2Ql0oaMupLXbqWT3e08oS3BpMeed7AdsDIGE9HH7LQ5/lUdZycf+q18WuQ8lmkwl8qfYsfg6bZi3UUlcuIG5BEReI3dnsr+71KoYF8xYO2iV1tUXXiiv9YumNWHtqsJ/C+2eKz7ps+OBKzzm2GXA9Q8G+DDYWXtYYfehcfJzjTt6cO2q72VgnnAnBt749BUCDsBHY9iUVWM3gzdiR80ALvElcYWcE/AOegEiB+S9vp3iL5rA59vbTSsE4mAhGrx+zGqDyhR0CQhH7R33Ci+kMOHgJ6QPw+d6qBjjrFrpPjjcgc6mgAROCF5QsF4QiXqn1DvmYBVSqz6798hBUFF2UuWoE5/rlVTM3fxPGlDpZCwdQqDvqKZeEDozge1P9QK+BAvEq5rIfgslb8Rif7eP61SuPHUfFHhAzyMnjCS0ZOMI57qjJEO8OYI22puOFLPjYv6jwTbR0McXhfKQZImeAS/p5UQCMyI58y1Vvs0chxZzbZDRHrnK8W3QQpgGUeVS1ED2lI6qXLj4lmSTV7lqy5IcUK4j1nbGQSHhY/pAn/nbPJY9iN4lBLpdvagobpmhx9b7yCdclgM/UQyvlNRQLnFkOaJS+NakPm+S7Tm3ER3mQKZFtMa/X+ofup13c1BEVmrxj3Wzfa46iRI5m+DZUy+wJveyK7stArJl+3q8MKcdYsiN4J9CBW/ZZqcLjG1h59FC3DxrgeCjpMGFXliwUmbl5xD4ij9zmSltMOMh+wnqIWbhv96Ya/61WcoKtIWkEDhh298VhQ4MBl0AquAPDEq1V9Ay3NKL5UsNEh9jdsHB4FuPH58aSBq7TCuKsFU5+TWsYyjZRmXkR2jbWcZnpdi9n4FrljL0EFDn109bJld2/7xVGZzRwCHao/pHunZmY6Ja9gvenTe69Ag8RhY0sNKmsBHT5AFpgAKtUqYcOR1hfGULLvBfE0OqKGv++h8AvWo81rfOzZYZE4r+TD2hwXFGYVXWcXF41bic84IK2SHBW63pCWOhYaAzrvQbzf3G/O9u265gzrlHExjq6D3No5DqG6rzQrZXOeK+2SL9nXbtMaISyIPOxvI+sguzFBm7jtgN3Ty85PgMOEVoshPxKACUysVRk2MdwWaE9vPUYmf+UzXpXMfVUAOQJw/mE1eIlI0swyP4n7QBlcaJkPe943X0LCQTd0bC1iNs2z4/dEA8yCGtZW/iDr8RLeEZFgBv+7wSu0AZh+NoFS7y5tPgEJKT4VUwJQZRqAjakzB8HGR/5l1l+K5OOoE5QiiQAhASwATRlAfxuIWcuaifXy4QpbEy9xlLN8/9vKPa2lKEYCX/zW9Pi+Qqfb1dDf2dFaen/sfOHThoBV07EoWAdKyxp5aim8C00sjXJsoHG/edTU7rfoK+jxcgXWC+PlT6sFaYj/Aj2FG2ffzDFtyhzQyGp/V6uo2wNCdq53yD+VTdsl7Uwe3DTdJd2t+fGZLiAvHS9hby/GVSbXd+SioyFuZrix2zWH0c4PZvB+760iTcQdyOVCBMYP87nIWlXMtUGBEgg/J1N70eBKFgr1PK6QtgYFdXAaeYFtvjW1hKuSxmkwkaAvl9dmQPk5sdNkPDTDkzOBCHpCSie+/EYW+6zHclVqdmue7ZUDhSNq4bfEt1BGSN4BaoWYNjQkaWcVYaGzXO2axbqdX5MuyEWdkkqWsqub23KhjUgpiVSD5kiKw8eL1+oyAIvfnwD+H0EcuKNV+ysOX3S0Dk6i9yWPS4xlutDhbM4BlKAW7/zfu4tGJVjVsxZF4RIIhXB1zgz+sR2LSluxsMUokzu86V59xZgiAQuUvMIpZwaDn2XtXYK9gSL26u7R3eC2d5Sw0TU5RQMUj22diEJK7MMThLMfVi70I1yU0poKCAvEn/Bt23LG3l+9cHYT7ns4kAuFZBjCwV9HrrT4NPDqcMhJ3agVMAe5HZj4HFatA/pHOPFL2os3GBUzI4ZIYTSEx30UXBgGAJIr1DXLoiPNkOhxeoZpeup3mzYKdkeSoMXoTZymTdPb+tyhBpOjRs52gqcH2VBifpU+UINodFhTexVJwNASRgr8perWhe3kr3vCnuIh7/zZkHuJ5pds7YquMRWgLdaZEYI/enJw9c4psNW4EHJlOVFJ9UPMcLVaOOx0n0bYJP52SG33v2K98EWJCOSjfT2Tf6VdHuMhvwgB/0eGsLl7yWaRH3OM1QI9D3PSYjMgpp0jik9w9ss/SuSb85MpfYGwBzjB1wHWtIkWCk7oRGQ7Wo1pzVz+29nmnCtZII+CkQCVTYKZ1u+k1Y/mdWTTiTCTKWC6mA9MItzqbt2UupsI98ZW/GP8lhUwDZLdQbfQ/uAA5x1L/ebh20te9lYP1Mg2RsB96jkpPsj+aP8rWl+33p1pNfU43yBiJrlrHGiDU69VpRmPP2hk1spP5AG48R1yGEZ+PQ1mcOA8909hgVLqq/wGKCuEjGAGUwVwxT5d+tSD3AzSWG4jUPPqipOcGA/x0fdOE3k63e0j3jmx6v2ao3QKOOlFiCEeRdZpvcLTEpkDxmTgJerb6jdta3hPYLplcNvx21FdhP4j3UAjUorukxf62TVzCXXEUzI308X4NkLtp6LK/FXEo/piQj8Z5B8Mn7IF/I9MkaJL0Fywc9o+h4MFlguhRJ2IrhkqLbBCCE3lApO3tGRCESFZWccNShGrsW+ecHy/kYdnmSiPSUNancqJkdatcu1PeirT0ndmMxjDD1ddyDgeikyWxVEv02VlGyMk8g//HjcyVJDHKtLO2/p2hTM5P9+elWx52YOfaI0eKSUUe0r8ex0Bg2gqDz6gmtxtpeK1amkAm415ZnIb28iTc99EwxO6fngKtAo11F5jhl2km4UFy/8OlRAKrlSSDYGAE="
},
{
"type": "text",
"text": "I think the honest answer is: it's the realistic ceiling for one threat model and close to irrelevant for another, and the disanalogy you've been building toward all along is exactly what determines which threat model dominates.\n\n**Where the downgrade earns its keep.** Compute-at-training-time is a genuinely good proxy for the same reason myelination is — it's a physical, scarce, surveillable bottleneck that exists prior to and independent of the system's cognition. You can meter electricity, track chip provenance, require attestation from cloud providers, all without needing any theory of what's happening inside the model. This is real enforcement-without-verification, not a degraded version of it, and it's probably the most load-bearing thing actually happening in AI governance right now — export controls, the various compute thresholds in executive orders and lab RSPs. For the threat model where danger scales roughly monotonically with training FLOPs, this is solid ground, maybe the only solid ground we have.\n\n**Where it stops working.** The threat model that's become more salient over exactly the period these governance frameworks were being designed is elicitation, not training. A huge fraction of recent capability gain — chain-of-thought, tool use, agentic scaffolding, inference-time search, multi-agent setups, fine-tuning on top of a fixed base model — is decoupled from the training-compute trip-wire almost by construction. The dangerous capability isn't created when the weights are written; it's created later, cheaply, by someone composing an existing model with a harness, and that composition step has none of the physical scarcity that makes compute governable. Software innovation propagates at near-zero marginal cost to anyone with API access. So a trip-wire on training compute is well-suited to stopping \"the next model is too big\" and structurally blind to \"the same model, wrapped differently, can now do something it couldn't do unscaffolded last week.\" That's not a hypothetical gap — it's roughly the story of the last two years, where most jailbreaks, most surprising capability elicitations, and most safety-relevant findings came from people doing creative things with already-released weights, not from bigger training runs.\n\nThis matters a lot for your \"discontinuous jump\" question, because it reframes where the discontinuity actually lives. It's probably not \"one training run suddenly produces vastly more capable weights\" — that's at least somewhat visible in advance, gradient of scaling laws and all. It's \"a fixed set of weights sits at a stable capability level until someone finds the scaffold/prompt/tool combination that unlocks a previously-latent capability,\" which can happen on a timescale of hours, by an actor who isn't the lab, using compute that was never tracked because it's inference, not training. The proxy you're rate-limiting (training compute, rate of capability gain across training runs) and the thing that actually jumps (elicited capability at fixed weights) aren't the same variable. So I'd say: yes, it buys real time against the threat model it targets, and no, it doesn't touch the one that's currently more empirically active.\n\n**What would actually cover the gap** isn't a cruder trip-wire on the same variable, it's a second, structurally different trip-wire on affordances rather than compute — mandatory staged evaluation before granting a model new capabilities-in-deployment (tool access, autonomous loops, ability to spawn copies or sub-agents, persistent memory across sessions), independent of how much compute went into training it. This is closer to the legal-incapacity layer in the human case than the myelination layer — and I think that distinction is worth making explicit, because the human analogy actually has two enforcement mechanisms stacked, not one. Myelination is the physical bottleneck; the driving age, contract law, age of majority are a *social* bottleneck layered on top, enforced not by physics but by institutions that can revoke licenses, void contracts, prosecute fraud. The social layer is exactly a verification-agnostic, affordance-gating trip-wire — nobody checks a sixteen-year-old's actual judgment, they just deny the affordance categorically until a fixed, crude threshold is crossed. So the proposal you're describing isn't a downgrade from the human case, it's a fairly faithful translation of the second human mechanism. The compute trip-wire translates the first.\n\n**But here's where the disanalogy comes back, and I think it's the sharper version of your earlier point about a system modeling and routing around its own gate.** The legal-incapacity layer works for humans because the institutions enforcing it are entirely staffed and operated by people *independent of the constrained agent* — a sixteen-year-old can't lobby the DMV, can't write the statute, can't persuade the judge by being unusually articulate about why the rule shouldn't apply to them, at least not effectively. The enforcing institution sits fully outside the thing being enforced against. With AI affordance-gating, that separation is exactly the thing under pressure: the institutions that would write and enforce the trip-wires — regulators, lab safety teams, legislators — are increasingly using AI systems for research synthesis, drafting, communications, even policy analysis. As that mediation deepens, you get a closed loop with no clean outside vantage point: the system whose affordances you're trying to gate is partially shaping, through influence on its own evaluators and overseers, the very process that decides whether to expand those affordances. That has no analog in the child case at all — a teenager's persuasive ability doesn't feed back into rewriting the age of majority through routine, structural integration into the legislature's daily workflow.\n\nSo I'd actually answer your question with a split verdict: rate-limiting via crude, hard-to-game proxies is the realistic ceiling for the *training-compute* threat model, and it's a real, non-trivial achievement to have even that much, given everything upstream of it is unsolved. But it doesn't generalize to the elicitation/scaffolding threat model, which needs its own crude proxy — affordance-gating — and that proxy's enforcement, unlike the compute case, depends on an institutional independence that's actively eroding as a side effect of the technology's normal, intended use. The thing that would need protecting isn't the AI's behavior at that point, it's the boundary between the evaluating institution and the system being evaluated — which is a governance problem about information flow and process integrity, not a machine learning problem at all, and I don't think anyone has a clean answer to it yet, including frameworks that otherwise take affordance-gating seriously."
}
]