SKIP TO CONTENT
THE ASHBY INSTITUTE
POLICY BRIEF·FORTHCOMING 2026

Compute Export Controls and the Good Regulator Theorem

Why effective controls require regulators to model the full variety of compute applications

TAI

TAI Research Staff

The Ashby Institute

Export ControlsCompute SecurityGood Regulator TheoremPolicy Design
CELLULAR · COMPUTE GOVERNANCE

PROGRAM

Compute Governance

TYPE

Policy Brief

PAGES

18

DOC NO.

TAI-PB-2026-001

ACCESS

OPEN ACCESS

ABSTRACT

Applies the Good Regulator Theorem to the design of compute export control regimes, arguing that effective controls require regulatory bodies to model the full variety of compute applications. Current export control frameworks exhibit significant variety deficits that undermine their effectiveness.

KEY FINDINGS

01

Current compute export control frameworks are designed around a narrow model of compute applications that does not capture the full range of uses relevant to national security.

02

The Good Regulator Theorem implies that export control bodies must develop modeling capacity for novel compute applications before those applications become security-relevant.

03

Effective export controls require international coordination to prevent regulatory arbitrage.

FORTHCOMING

This publication is forthcoming. The abstract and key findings above are from the working draft. Subscribe to TAI's newsletter to be notified when the full text is released.

Introduction

Compute export controls have emerged as a central instrument of technology governance in the current geopolitical environment. The United States, the European Union, and other jurisdictions have implemented or are considering controls on the export of advanced semiconductors, AI chips, and related technologies.

The design of effective export controls requires regulatory bodies to model the full range of compute applications that are relevant to national security. This is a demanding requirement: compute capabilities are general-purpose, their applications are diverse and rapidly evolving, and the relationship between compute access and security outcomes is complex and context-dependent.

The Good Regulator Theorem provides a precise criterion for evaluating export control design: a regulatory body can effectively control the security-relevant applications of compute only to the extent that it can model those applications. Regulatory bodies that cannot model the full range of security-relevant compute applications will systematically fail to control them.

Current Export Control Frameworks

The US Bureau of Industry and Security (BIS) administers the primary US compute export control framework through the Export Administration Regulations (EAR). The current framework focuses primarily on the technical specifications of hardware — chip performance thresholds, memory bandwidth, interconnect speeds — rather than on the applications for which the hardware is used.

This hardware-focused approach reflects a narrow model of the relationship between compute access and security outcomes. It assumes that security-relevant applications require hardware above specific performance thresholds, and that controlling access to such hardware is sufficient to control access to the applications.

The Good Regulator Theorem suggests this assumption is incorrect. As compute capabilities diffuse and software efficiency improves, the relationship between hardware specifications and application capabilities becomes increasingly complex. A framework designed around 2023-era hardware thresholds will exhibit growing variety deficits as the compute landscape evolves.

"Every good regulator of a system must be a model of that system." — Conant & Ashby, 1970

Policy Recommendations

Three reforms are needed to bring compute export control frameworks into compliance with the Good Regulator Theorem. First, export control bodies must develop technical modeling capacity for the full range of compute applications, not just hardware specifications. This requires sustained investment in technical expertise and modeling infrastructure.

Second, export control frameworks must include adaptive mechanisms — formal processes for updating control parameters in response to new information about compute capabilities and applications. Static frameworks will exhibit growing variety deficits as the compute landscape evolves.

Third, international coordination is needed to prevent regulatory arbitrage. Unilateral export controls create incentives for firms and states to route compute access through jurisdictions with weaker controls. Effective governance requires multilateral coordination on control parameters and enforcement mechanisms.

CITATION

TAI Research Staff, Compute Export Controls and the Good Regulator Theorem. The Ashby Institute, Forthcoming 2026. TAI-PB-2026-001. DOI: https://doi.org/10.0000/tai.2026.pb001

RELATED PUBLICATIONS

← ALL PUBLICATIONSSUBSCRIBE TO NEWSLETTER →