Why artificial intelligence needs its own version of the atomic watchdog — and why copying that model outright won’t work
Yakub Aliyu and Chris Uwaje
In the summer of 1945, the world got a brutal lesson in what happens when technology outruns the institutions meant to contain it. It took less than a decade for the international community to answer with the International Atomic Energy Agency — a body built not to stop nuclear science, but to make sure the world could see what was being built, and by whom, before things went catastrophically wrong.
Eight decades later, we’re living through a strange rerun of that story. Except this time the technology of concern has no mushroom cloud, no radioactive signature, and no physical border it has to cross to reach anywhere on Earth. It lives on servers. It moves at the speed of a download. And it is being built simultaneously — right now, today — by governments, billion-dollar labs, and increasingly, by anyone with a laptop and a cloud computing account.
Artificial intelligence has become this century’s defining dual-use technology: an engine of extraordinary economic promise, and, in the wrong hands or the wrong configuration, a genuine security risk. The comparison to the nuclear era isn’t hyperbole for effect. It’s the closest precedent history offers for a technology this powerful, this fast-moving, and this consequential to get wrong. But here’s the uncomfortable truth policymakers are only beginning to reckon with: the nuclear playbook doesn’t transfer cleanly. AI is a different kind of beast, and pretending otherwise could waste the narrow window we have to govern it well.
A Bomb You Can’t Weigh
Nuclear weapons required something artificial intelligence does not: scarce, traceable material. Uranium has to be mined, enriched to a specific purity, and shipped through a supply chain narrow enough that international inspectors could plausibly watch every step. That physical bottleneck — heavy, radioactive, and hard to hide — is precisely what made the Non-Proliferation Treaty enforceable for fifty years.
A trained AI model has no equivalent signature. It’s a file. It can be copied in seconds, emailed across a border, or released to the public as “open weights,” at which point it is effectively impossible to recall. You cannot send inspectors to count something that costs nothing to replicate.
What AI does have, though, is a bottleneck of its own: compute. Training a frontier model today demands staggering amounts of specialized computing power, delivered through a small number of chip designers and an even smaller number of data centers capable of running them at scale. That is the closest thing AI governance has to enriched uranium — and it’s already, messily, becoming the main lever governments are pulling.
Look no further than the running saga between Washington and Nvidia. Since 2022, the U.S. has tightened and loosened export controls on advanced AI chips bound for China in fits and starts — banning the H100, then the specially downgraded H20, then striking a deal that let exports resume in exchange for a cut of the revenue and a hard cap on volume. Nvidia’s own chief executive has said the company’s share of the Chinese AI chip market fell from roughly 95 percent to almost nothing within about two years — not because of a shortage, but because of policy. Whatever one thinks of how that fight has been managed, it proves a point worth sitting with: hardware, not code, is where AI’s supply chain can actually be gripped.
A Framework With Three Floors, Not One Referee
None of this means AI governance should be handed to a single global regulator any more than it should be left entirely to the companies building the technology. Both extremes fail in practice — one moves too slowly to matter, the other trusts commercial incentives to police themselves in a market where the reward for shipping first is enormous and the cost of a safety shortcut is often invisible until it isn’t.
What’s needed instead is a layered system: three tiers, stacked so that each covers ground the one below it cannot reach.
Figure 1: The layered AI governance framework — self-regulation as foundation, national law in the middle, international oversight at the top.

Layer one sits inside the labs themselves. Frontier AI developers should be required, not merely encouraged, to build safety testing, red-teaming and interpretability into how they develop and release models — and to share near-miss data across the industry the way aviation safety boards do after a close call on the runway. Self-regulation isn’t worthless. It moves at the speed of the technology and draws on expertise no outside regulator can match on day one. But left alone, it becomes a race to the bottom, where the company willing to cut the most corners sets the market pace. Foundation, not ceiling.
Layer two belongs to national governments — and it’s already happening, messily. The European Union’s AI Act reaches full enforcement this August, built around exactly the kind of risk-tiered approach this argument calls for: light-touch for everyday applications, serious scrutiny — and fines of up to 7 percent of global revenue — for systems trained above a defined computational threshold. The United States, by contrast, has no single federal law and is instead assembling a patchwork: California’s SB 53 now requires frontier developers to publish safety transparency reports, Colorado’s algorithmic-discrimination law takes effect this summer, and a growing list of state bills fill in whatever Washington leaves open. It isn’t tidy. But it is, in its own way, a live experiment in regulating by risk rather than by blanket ban — one that has so far avoided strangling the open-source ecosystem that drives much of the field’s progress.
Figure 2: Three governance philosophies, three bets on how to balance innovation against risk.

China offers a third template entirely: tight state control over content and deployment domestically, paired with an unexpected diplomatic move — proposing its own UN-adjacent body, sometimes referred to as WAICO, to help shape how AI is governed globally. Whatever one makes of Beijing’s motives, the proposal is a signal that even the governments most committed to keeping AI on a short domestic leash see value in an international table where the rules get negotiated jointly rather than imposed by whoever gets there first.
Layer three is the piece still largely missing: a genuine international body, modeled on the IAEA’s function rather than its method. Its job wouldn’t be inspecting algorithms — that’s a fool’s errand for something as intangible as software — but tracking the hardware that makes frontier AI possible: monitoring advanced chip supply chains, maintaining registries of large-scale compute installations, and giving rival powers a forum to negotiate the rules before an incident forces their hand. The appetite for this exists. The United Nations convened its first Global Dialogue on AI Governance this year, drawing more than 140 countries to the same table for the first time. What’s missing isn’t interest. It’s architecture — the treaties, the verification mechanisms, the shared vocabulary that took the nuclear world the better part of a decade to build after 1945.
Why This Isn’t Just a Policy Argument
It’s worth pausing on why any of this should matter to someone who has never trained a model or read a line of policy text. The answer is the same one that made nuclear governance a kitchen-table issue in the 1950s: technology this powerful doesn’t stay contained to the industry that builds it. It reshapes labor markets, shifts military balances, and — when it fails — fails at a scale that ordinary regulation was never designed to catch. A financial model that discriminates in a loan decision, a content system that misinforms an electorate, an autonomous system deployed faster than anyone tested it for edge cases — these are not hypothetical. They are the reason Colorado wrote a “duty of reasonable care” into its AI law, and the reason the EU decided that fines needed to be large enough to change corporate behavior rather than simply become the cost of doing business.
The honest case for a tripartite framework isn’t that it guarantees safety. Nothing does, with a technology this new. It’s that it distributes the burden of getting this right across three different kinds of expertise — technical, legal, and diplomatic — so that no single failure point can bring the whole system down. Industry self-regulation catches what regulators are too slow to see. National law catches what individual companies have no incentive to police. And an international body, however imperfect, is the only mechanism capable of stopping the kind of race-to-the-bottom competition between nations that no single country can opt out of alone.
We built that third layer once before, out of necessity, in the shadow of a weapon we’d just watched change the world. We have the advantage, this time, of building it before the equivalent moment arrives rather than after. Whether we use that advantage is still, for now, an open question — and one that will be answered less by any single treaty than by the everyday decisions being made this year in Washington, Brussels, Beijing, and the boardrooms of the companies racing to build what comes next.
Prof. Yakub Aliyu is a senior engineering and operations executive with more than two decades of experience in quality, compliance, and technology leadership, and holds a PhD in Electronics Engineering.
Sources & Further Reading
- Regulation (EU) 2024/1689 (the EU AI Act) — European Parliament and Council
- California SB 53 (2025) and the Colorado AI Act (effective June 2026)
United Nations Global Dialogue on








