← Latest papers
🤖 AI

Comprehensive AI governance requires addressing non-model gains

This position paper argues that effective AI governance must expand beyond the traditional model-level paradigm to address "non-model gains"—such as inference, systems, and asset improvements—which increasingly drive capability and undermine pre-deployment risk management strategies.

Original authors: Arthur Goemans, Dan Altman, Noemi Dreksler, Jonas Freund, Milan Gandhi, Zhengdong Wang, Sarah Cogan, Sebastien Krier, Demetra Brady, Lewis Ho, Allan Dafoe

Published 2026-06-02
📖 6 min read🧠 Deep dive

Original authors: Arthur Goemans, Dan Altman, Noemi Dreksler, Jonas Freund, Milan Gandhi, Zhengdong Wang, Sarah Cogan, Sebastien Krier, Demetra Brady, Lewis Ho, Allan Dafoe

Original paper licensed under CC BY 4.0 (http://creativecommons.org/licenses/by/4.0/). This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer

The Big Idea: It's Not Just About the Engine Anymore

Imagine you are trying to regulate the speed and safety of cars. For a long time, the main rule was: "If you build a better engine (the AI model), you can predict how fast the car will go."

This is what the paper calls Model-Level Governance. It assumes that a car's speed depends almost entirely on the engine's size and the fuel used to build it. So, regulators focus on inspecting the engine before it leaves the factory.

The Paper's Warning:
The authors argue that this old way of thinking is becoming less effective. Why? Because the car's speed is no longer just about the engine. It's increasingly about what you do with the engine after you buy it.

They call these new speed boosts "Non-Model Gains." Even if the engine stays the same, you can make the car go dangerously fast by changing the tires, adding a turbocharger, or driving on a better track. The paper says we need to regulate these add-ons and driving conditions, not just the engine.


The Three Ways to "Supercharge" the Car (Non-Model Gains)

The paper identifies three specific ways people can make an AI much more powerful without changing the original model:

1. Inference Gain: "Pressing the Gas Pedal Harder"

  • The Analogy: Imagine a standard car engine. Usually, it runs at a steady speed. But what if you could press the gas pedal down for a longer time, or use a special fuel mix while driving to make it sprint?
  • The Reality: This is Inference Gain. It means giving the AI more computing power while it is working (at test-time).
  • Why it matters: A smaller, cheaper AI model can suddenly act like a giant, expensive one if you just give it enough time and power to "think" harder. This makes it hard to stop bad actors because they don't need a super-expensive engine; they just need to press the gas pedal longer.

2. Systems Gain: "Building a Better Chassis and Tools"

  • The Analogy: You take a standard car and build a custom frame around it. You add a robotic arm to the trunk, a GPS that talks to other cars, and a computer that automatically fixes the engine while you drive.
  • The Reality: This is Systems Gain. It's about wrapping the AI in a "scaffold" of tools, other software, or teams of AI agents working together.
  • Why it matters: A basic AI might not know how to hack a computer. But if you build a system that gives the AI a "screwdriver" (a tool to scan code) and a "map" (a database of vulnerabilities), the combination becomes dangerous. The paper notes that these "toolkits" are cheap to build and easy to share, unlike the expensive engine.

3. Asset Gain: "Driving on a Secret Track"

  • The Analogy: Imagine a race car that is safe on a normal track. But then, a government gives that same car access to a secret, high-tech military track with special fuel and weapons that no one else has.
  • The Reality: This is Asset Gain. It happens when an AI is combined with restricted, secret, or specialized resources (like classified government data, biological samples, or military hardware) that the original creators didn't have.
  • Why it matters: You can't test for this risk in a normal lab because the "secret track" doesn't exist there. A model that seems safe in a public test could become a weapon if a bad actor gives it access to a secret database.

The Future: The Car That Learns and Drives Itself

The paper also warns about three future trends that make the "engine-only" regulation even harder:

  • Embodiment (The Car Gets Legs): Putting the AI inside a robot. If the AI hallucinates (makes a mistake), it's no longer just a wrong answer on a screen; it might physically punch a person or break a machine.
  • Continual Learning (The Car Learns While Driving): The AI keeps learning new things after it leaves the factory. A car that was safe on day one might learn bad habits by day ten.
  • Diffusion (The Traffic Jam Effect): When millions of these AI cars are on the road at once, they might start interacting in weird ways. One car's mistake could cause a chain reaction (like a financial crash) that no single car caused on its own.

The Solution: A New Rulebook

Since we can't just check the engine anymore, the paper suggests we need a multi-layered safety net. Think of it like regulating a highway system, not just the cars:

  1. System Governance: Regulate the people who build the "toolkits" and "frames" around the AI, not just the AI creators.
  2. Entity Governance: Regulate the companies themselves. Do they have good safety cultures? Are they responsible?
  3. Agent Governance: Regulate how AI "agents" talk to each other. If two AIs start colluding to break the law, who is in charge?
  4. Cloud Governance: Monitor the "gas stations" (the cloud servers). If someone is using massive amounts of power to run a dangerous calculation, the cloud provider should be able to spot it.
  5. Societal Resilience: This is the most important one. Even if we have perfect rules, accidents happen. We need to build a society that is tough enough to survive and recover if something goes wrong (like having better hospitals or emergency plans).

The Bottom Line

The paper isn't saying we should stop checking the engines. It's saying that checking the engine is no longer enough.

If we only focus on the model (the engine), we will miss the dangers coming from the tools we attach to it, the secret data we feed it, and the way it learns while driving. To keep everyone safe, we need to regulate the whole car, the driver, the road, and the community around it.

Drowning in papers in your field?

Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.

Try Digest →