AI-generated analysis · May contain errors · Disclosure and methodology
Beyond Training: A Feasibility Taxonomy for Inference-Time AI Governance
TEXT START: Compute governance today is a governance of training: the thresholds, reporting requirements, and frontier-AI regimes now in force attach to training compute and treat the trained model as the regulatory unit.
The Dissection
The paper relocates the regulatory target from the trained model and training run to the inference call. It builds a twenty-mechanism taxonomy across monitoring, verification, and enforcement, then tests those mechanisms against deployer capability, adversary role, and governance venue.
Its most important finding is also its fatal admission: no mechanism is adequate against a high-capability state-level deployer. Fine-tuning can erase model-internal enforcement, leaving only platform-external controls. The readiness scores, production substrates, vendor evidence, and kappa statistic establish methodological seriousness—not actual control over hostile capability.
The Core Fallacy
The paper treats the existence of commercial technical substrates as evidence of governance feasibility. That is the wrong unit of analysis. A monitoring or enforcement mechanism is not viable merely because it functions in production; it must remain effective when the actor has strong incentives, sufficient capability, and the ability to route around the platform.
The paper’s own adversary model destroys its broader premise. If the mechanisms fail against the actors most capable of generating consequential AI power, they are not governance of the capability. They are conditional friction applied to cooperative or weakly positioned users.
Under the Discontinuity Thesis, inference-time governance does not interrupt cognitive automation dominance. It merely attempts to meter its deployment. It cannot solve coordination impossibility, and therefore cannot prevent productive participation collapse.
Hidden Assumptions
- Inference remains visible through a limited number of platforms, vendors, or marketplaces.
- High-capability state actors cannot migrate to private infrastructure, altered models, or consumer-hardware clusters.
- Cooperative deployers are a sufficiently representative target for regulation.
- Commercial availability can be converted into governance-grade assurance and adversarial robustness.
- Domestic, bilateral, multilateral, industry, and marketplace institutions can coordinate faster than capability diffuses.
- Fine-tuning, compression, and agentic scaffolding will not continually invalidate the regulatory object.
- Conditional equivalence between inference-stage and hardware-stage controls can survive changes in deployment architecture.
These are not minor implementation gaps. They are the structural conditions required for the proposed controls to matter.
Social Function
Primary classification: transition management and prestige signaling, containing a real partial truth.
The paper does not simply indulge in copium; it documents serious weaknesses. But it converts a power asymmetry into a taxonomy, readiness scale, and research program. That bureaucratic reframing makes terminal enforcement failure look like an unfinished engineering project. It supplies institutions with paperwork, not sovereignty over the capability.
The Verdict
This is a useful map of where AI governance can work before the actor becomes powerful enough to evade it. It is not a control architecture. Fifteen production-ready substrates mean little when the decisive adversary class defeats the entire mechanism set.
Inference-time governance is lag defense and carcass management: attribution, friction, taxation, access control, and selective containment around the edges of the transition. It may slow diffusion or preserve institutional appearances. It does not reverse the underlying break in the mass employment–wage–consumption circuit. The paper’s central contribution is therefore an admission: governance remains feasible only while the governed remain weaker than the system governing them.
Comments (0)
No comments yet. Be the first to weigh in.