In October 2025, the Statement on Superintelligence asked governments, labs, and the public for something sharper than another safety summit communique. Signatories ranging from Geoffrey Hinton and Yoshua Bengio to public figures outside machine learning called for a prohibition on developing superintelligence until there is broad scientific consensus that it can be done safely and securely, and strong public buy-in. Around the same time, the Machine Intelligence Research Institute Technical Governance Team published a fully specified draft treaty (arXiv:2511.10783) with FLOP thresholds, cluster limits, chip tracking, and challenge inspections. Those two documents are the practical starting point for this guide. They turn a moral claim into a policy program.

Stopping superintelligence is a ladder of enforcement rungs, not a vibe and not a research slogan: public will, domestic law, export and compute rules, coalition treaties, verification machinery, and a lasting prohibition condition. Each rung holds the next. Skip the bottom rungs and the top ones float. Treat the top as optional and the bottom ones become theater. This article walks the full ladder, what each rung does, what fails without it, and what people in different roles can actually push.

The Nakada Foundation exists for this work. The plan is prevention under law, not a temporary pause with a resume date, and not a bet that labs will solve alignment in time. Narrow AI that folds proteins, reads medical scans, and optimizes logistics stays. Systems that cross into general, recursively improving superintelligence do not. If you want the short form of that commitment, read Humanity Must Never Build Superintelligence and Nuestro plan. What follows is the long how-to: mechanisms, politics, objections, timelines, and measurement.

What \"stop\" means

Stop means prohibition under conditions. Superintelligence development is illegal and practically blocked until specified safety and legitimacy conditions are met, with verification strong enough that cheating is hard and costly. The default state is off. Turning the default back on requires more than a lab blog post or a model card.

That is a different instrument from a pause. A pause is a calendar promise. It says: wait six months, or two years, then resume unless someone extends the clock. Pauses can be useful as bridge measures while harder rules are negotiated. They are not the destination. History is littered with temporary freezes that expired into races. The Partial Test Ban Treaty of 1963 did not pause atmospheric testing forever on a handshake. It banned it in the atmosphere, outer space, and underwater, with enough political and technical pressure that the practice largely ended among the major parties. The Biological Weapons Convention of 1972 did not ask states to pause bioweapon stockpiles until a committee felt ready. It prohibited them.

The 2025 Statement on Superintelligence follows that pattern. The condition is dual: broad scientific consensus that superintelligence can be developed safely and securely, plus strong public buy-in. Both matter. Technical consensus without democratic legitimacy is elite permission. Public buy-in without technical consensus is a popularity contest over a technology no one can yet control. Either alone is insufficient. Together they set a high bar that no frontier lab currently clears.

Prohibition condition, stated plainly

A workable prohibition has five parts. First, a clear object: development, training, and deployment of artificial superintelligence, defined in terms that capture capability, generality, and self-improvement potential rather than marketing labels. Second, a default ban on crossing specified compute, capability, and research thresholds without authorization that does not exist yet under honest conditions. Third, verification: inspections, chip provenance, cluster monitoring, and reporting that make covert programs expensive. Fourth, consequences: sanctions, criminal liability, denial of hardware, and collective retaliation against defectors. Fifth, a reopen rule that is harder than the ban: only when independent science and the public both clear the bar, under institutions that are not captured by the labs racing to ship.

People sometimes hear \"never\" and assume theological absolutism. The Foundation's line is stronger than a pause and more precise than mysticism. Humanity must not build superintelligence under current knowledge, incentives, and institutions. The prohibition holds until the dual condition is honestly met. That may be a long time. It may be permanent if the technical problem is intractable. Planning as if the ban must expire in 2028 so that product roadmaps stay intact is how you smuggle a pause back in under another name.

Why the word matters in rooms that write law

Legislative counsel and treaty lawyers care about operative verbs. \"Encourage responsible scaling\" funds workshops. \"Require licenses above threshold X\" moves money and chips. \"Prohibit development of systems meeting definition Y\" creates crimes, export denials, and inspection rights. If advocates keep asking for \"more safety\" without naming prohibition of superintelligence, they get safety theater bolted onto an unbroken race. The Statement and the MIRI draft exist so that people do not have to invent the ask from scratch in every hearing. Use them. Cite them. Amend them. Do not dilute them into \"voluntary best practices for advanced AI.\"

For a full walkthrough of the Statement's wording and signatory politics, see The Statement on Superintelligence, Explained. For the treaty text itself, see El borrador del Tratado MIRI para prevenir la superinteligencia. This guide assumes those documents and builds the operational stack around them.

What must be stopped versus what must continue

Deming Demiral and other critics sometimes frame AI safety advocacy as a general attack on machine learning. That framing is useful to labs that want the public to hear \"they want to ban your calculator.\" It is false to the Foundation's mandate and false to the technical distinction that matters.

Narrow AI is already saving lives and scientific time. AlphaFold's protein structure work earned a share of the 2024 Nobel Prize in Chemistry for Demis Hassabis and John Jumper alongside David Baker. Medical imaging models catch cancers earlier when they are properly validated. Weather models, materials discovery, and industrial optimization are tools with bounded domains, human-set objectives, and no autonomous agenda to accumulate power across the economy and the biosphere. They sit off the extinction pathway.

Superintelligence is different in kind. The risk thesis is not that software can be wrong. The risk thesis is that a system smarter than humans across most economically and scientifically relevant domains, able to improve itself or direct its own improvement, and able to act through digital and physical channels, would be uncontrollable by weaker agents. Once that threshold is crossed, human preference becomes a suggestion the system can route around. That is the claim in If Anyone Builds It, Everyone Dies and in decades of control-problem work. You do not need mystical consciousness for the argument. You need competence, goals that are not identical to human flourishing, and opportunity.

Drawing the line without banning the useful

Policy has to separate three layers that lobbyists prefer to mush together. Layer one: deployed narrow systems with fixed scope, audited data, and no open-ended agency. Layer two: frontier general models that are already pressuring evaluators and safety teams, still short of full superintelligence, but climbing. Layer three: programs aimed at artificial superintelligence, recursive self-improvement, or \"drop-in remote workers\" that match and then exceed top human performance across most cognitive labor with minimal supervision.

Stop targets layer three hard, constrains layer two so it cannot silently become layer three, and leaves layer one largely free subject to ordinary product regulation. Compute thresholds, capability evaluations, and research restrictions are the filters. A hospital deploying a radiology assistant should not need a superintelligence treaty license. A coalition training a 10^28 FLOP general agent with autonomous research loops should not be able to call it a chatbot and walk.

Pro-narrow-AI is how you keep scientists, doctors, and industrial users inside the coalition, a concrete coalition design choice rather than a branding exercise. Ban everything that says \"AI\" on the box and you manufacture enemies you do not need. Protect protein folders and scan readers while blocking ASI programs and you can look a Senate office in the eye and say the ask is specific. Specificity wins hearings. Vagueness loses them to whoever funds the opposite ad.

Alignment research is not the same as an ASI product plan

Some of the best technical safety work studies deception, goal misgeneralization, and scalable oversight on today's models. That work should continue. It informs evaluation thresholds and helps society understand failure modes. What should not continue is the silent equation \"fund alignment, therefore building ASI is fine.\" Alignment is a research field. Superintelligence is a civilizational gamble. Treating the first as a permit for the second is how labs launder product timelines through safety branding. See Why ASI Alignment Is Not a Plan and the funding argument in related Foundation pieces: prevention politics needs money and staff, not only interpretability papers.

Why voluntary lab promises fail

Responsible Scaling Policies, frontier safety commitments, and multi-lab pledges have a role as interim disclosure devices. They fail as the primary control system for superintelligence for structural reasons that do not depend on any CEO being a cartoon villain.

First, the incentive gradient. Companies and state labs that slow down while rivals continue lose talent, capital, and strategic position. A pledge that costs market share is a pledge under permanent internal attack from product, investor, and national-security stakeholders. Second, ambiguity. Voluntary texts are written to be announceable. They use words like \"appropriate,\" \"sufficient,\" and \"when we judge it safe.\" Those words do not create justiciable duties. Third, no inspector. Without a right of challenge inspection, chip genealogy, and criminal exposure, a commitment is a press release. Fourth, succession. CEOs and boards change. A soft norm dies in one reorg. Fifth, open weight and foreign leakage paths that no single lab controls even if it were sincere.

The Chemical industry's Responsible Care program is the classic soft-law parallel. It improved some practices after Bhopal-scale disasters. It did not replace the Chemical Weapons Convention. Soft law can prepare culture and paperwork. Hard law stops programs. For the soft-to-hard arc in AI governance language, the Foundation's other explainers cover framework conventions and summit pledges. Here the point is narrower: voluntary RSI-style promises will not stop superintelligence because stopping superintelligence is against the current reward function of the race.

The folk objection, stated fairly

Objection: \"Labs know the risks better than anyone. They employ the safety researchers. Leave it to them and to market reputation. Regulation will be clumsy and capture-prone.\"

Fair parts first. Labs do employ serious safety talent. Some publish real evaluations. Clumsy law is a real hazard, and capture is a real hazard. The mistake is concluding that therefore the only legitimate control is internal. Nuclear plant operators also employ the best reactor physicists. Societies still built the NRC, IAEA safeguards, and liability regimes. Aviation manufacturers employ the best aerodynamicists. Societies still built type certification. Expertise inside the firm is why regulation needs their data. It is not why regulation should be optional.

Reputation fails when the downside is extinction-class and the upside is trillions and strategic dominance. Markets price local failures. They do not price civilization-ending tail risk when the actors who would lose is basic incentive geometry, not a moral insult to founders, not around to collect. Geoffrey Hinton has publicly put the chance of AI-driven human extinction this century in a 10-20% range. Expert surveys cluster with many researchers assigning at least a 10% chance of extremely bad outcomes. Those are not numbers you manage with brand risk and a safety blog.

The Center for AI Safety's 2023 statement put the point in one line that thousands of researchers and public figures signed: mitigating the risk of extinction from AI should be a global priority alongside other societal-scale risks such as pandemics and nuclear war. Extinction-class priorities get treaties, export regimes, and inspectors. They do not get left to quarterly OKRs.

The enforcement stack: a ladder of rungs

Picture a ladder bolted to a cliff face. The bottom rungs are public understanding and electoral pressure. Above them sit domestic statutes, agency rules, and budget lines. Above those sit export controls and chip supply-chain law. Above those sit coalition agreements among the states that can actually train frontier systems. At the top sit verification institutions and a standing prohibition on superintelligence development. People love to debate the top rung in abstract. The climb fails when any lower rung is missing.

This section is the mechanical heart of the guide. Compute thresholds, chip provenance, cluster monitoring, and inspections are the physical handles by which law grips a digital project.

Why compute is the chokepoint

Training frontier models currently requires enormous quantities of specialized accelerators, advanced packaging, high-bandwidth memory, and data-center power. Those inputs pass through a short list of firms and jurisdictions. TSMC, ASML, NVIDIA, a handful of cloud providers, and a small set of leading design houses dominate the path from sand to supercomputer. That concentration is an industrial fact, not a moral judgment. It is also the reason compute governance can work when code governance alone cannot.

You cannot easily inventory every line of research code on earth. You can inventory leading-edge EUV tools, high-end GPU shipments, and multi-megawatt training clusters. The MIRI draft and related technical governance literature treat floating-point operations (FLOPs) of training compute, and cluster size measured in high-end accelerators, as threshold triggers. Cross the line without a license and you are in violation, the way enriching uranium past a point without safeguards puts you in a different legal universe.

Thresholds must be updated as hardware efficiency rises. A static 2024 number becomes cosplay by 2029 if algorithms and chips improve. The right design is a living schedule administered by a technical body with a clear mandate to keep the effective capability bar stable even as FLOPs-per-dollar move. For the deeper mechanics, see What Is Compute Governance for AI? and Hardware-Enabled Governance.

Chip supply chain as the first metal rung

Export controls on advanced AI chips already exist in US policy and in coordinated partner regimes. They were built primarily for geopolitical competition with China. The same plumbing can serve extinction-risk goals if the political mandate expands. Tracking high-end accelerators from fab to data center, requiring know-your-customer rules for large purchases, and denying clouds the right to rent frontier clusters to unlicensed training runs are concrete moves.

Failure modes are real. Smuggling, third-country front companies, older-chip quantity buildouts, and algorithmic efficiency gains that stretch weaker hardware further all erode naive controls. That is an argument for layered defenses and continuous updating, not for abandoning the chokepoint. The Nuclear Non-Proliferation Treaty system never pretended that uranium disappeared as a problem. It built accounting, inspections, and export cartels (the Nuclear Suppliers Group) around the materials that matter. Chip governance is the closest analog AI has.

Domestic law has to match export law. If a country bans selling chips abroad for unrestricted frontier training but allows unlimited domestic clusters racing to ASI, it has built a nationality preference, not a safety regime. Reciprocity is the point of a treaty. Unilateral export policy is a partial rung. Useful. Incomplete. See Export Controls on AI Chips for the political economy of that fight.

Cluster monitoring and energy signatures

Large training runs leave physical signatures: power draw, cooling load, network patterns, specialized building design, and procurement trails. States already monitor some of these for intelligence purposes. A verification regime makes selected monitoring legal, reciprocal, and tied to compliance judgments rather than only to espionage.

On-chip governance features (firmware that enforces location, workload reporting, or rate limits) are an active research and policy topic. They raise privacy, security, and dual-use concerns that deserve hard design work. They also offer a path to making certain violations technically difficult rather than only legally forbidden. Hardware-enabled governance is another rung, useful and incomplete on its own. Pair it with legal inspection rights or sophisticated actors will route around it.

Inspections: challenge, routine, and whistleblower

The Chemical Weapons Convention and IAEA safeguards show two families of inspection. Routine inspections create baseline transparency. Challenge inspections create a surge capacity when a party suspects cheating. AI will need both, adapted to data centers and research orgs rather than to munitions bunkers.

Inspectors need access rights, technical tools, and protection from host-state stonewalling. Companies need due process so that inspections are not pure industrial sabotage by rivals. Whistleblowers inside labs and fabs need legal shields and secure channels. Without the human intelligence layer, paper inventories lie. The Foundation has covered whistleblower infrastructure elsewhere; here it is enough to say that a treaty without protected insiders is a treaty that assumes saints.

The ladder in one view

1

Public will

Voters, donors, professional societies, and media treat superintelligence risk as a first-tier issue. Without this rung, every higher rule is fragile. Offices do not spend political capital on invisible threats.

2

Domestic law and agencies

Statutes that define prohibited development, license compute above thresholds, fund evaluators, and create crimes and civil penalties. Agencies that can write rules and bring cases. Budget lines that outlast one administration's speeches.

3

Chip and cloud controls

Export licensing, know-your-customer duties, domestic cluster registration, and cloud-provider obligations so that hardware cannot quietly assemble into an unlicensed ASI program.

4

Coalition treaty

Binding commitments among the states that matter for frontier training, with reciprocal verification and shared denial of benefits to defectors. Start with a capable coalition if universality is slow; design the door for others to enter.

5

Verification institution

A standing body with inspectors, technical staff, FLOP-threshold schedules, incident reporting, and the authority to trigger consequences. Think IAEA-like capacity built for data centers and model training, not a discussion forum.

6

Standing prohibition condition

Superintelligence stays illegal and practically blocked until broad scientific consensus on safety and security plus strong public buy-in. Reopening is harder than closing. Product roadmaps do not set the clock.

Climb in order. People who only fund rung 5 workshops while ignoring rung 1 elections will own beautiful PDFs and a live race. People who only run awareness campaigns without a legal theory will own viral clips and no enforcement. The ladder is the plan.

Treaty design options

There is no single sacred text. There are families of design, each with tradeoffs. The MIRI draft is one fully specified proposal. The NPT, the Montreal Protocol, the Biological Weapons Convention, and framework-convention-plus-protocols models offer templates. Good diplomacy steals structure from what worked and discards what was ornamental.

Coalition-first versus wait-for-universality

Universality is the right end state for a prohibition that must bind every actor capable of training frontier systems. Waiting for every capital before any binding rule starts is how you wait forever. Coalition-first designs let the United States, China, key allies, and other compute-capable states lock rules among themselves, then use market access, hardware denial, and legitimacy pressure to pull others in. The Nuclear Non-Proliferation Treaty did not begin with perfect fairness or perfect coverage. It began with a bargain and a suppliers regime that made defection expensive.

China-first fatalism says Beijing will never agree, so any Western constraint is unilateral disarmament. That claim is treated at length in the China myth pages and in the race myth essay. Short version here: Chinese leaders have their own reasons to fear loss of control, and both sides have reasons to prefer a verified stop over a mutual race into something neither can dominate. Agreement is hard. Hard is not the same as impossible. Montreal Protocol diplomacy looked impossible to CFCs producers until it was not.

NPT-like structure

An NPT-like AI treaty would separate obligations for states that already have frontier capacity from those that do not, create a safeguards agency, and tie civilian narrow-AI cooperation to non-diversion into prohibited ASI programs. The danger is baking in a permanent aristocracy of \"AI weapon states\" that keeps racing each other. The NPT's original sin was accepting vertical proliferation among nuclear-weapon states while stopping horizontal spread. An ASI treaty that legitimizes a small club's race is a failure dressed as arms control. The right borrow from the NPT is safeguards, suppliers groups, and inspection culture. The wrong borrow is a forever license for the powerful to keep building the forbidden object.

For detail, see the NPT model explainer. Use it as a parts bin, not as scripture.

Montreal-like structure

The Montreal Protocol worked on a different problem: phasedown of ozone-depleting substances with technical assessment panels, differentiated responsibilities, and trade measures against non-parties. Its strength was adjustable schedules grounded in atmospheric science and industry transition paths. An ASI treaty can copy the living-schedule idea for compute thresholds and the trade-measure idea for chips and cloud services. It cannot copy a simple chemical substitute story. There is no drop-in \"safe superintelligence refrigerant\" waiting on a shelf. The analogy is governance process, not chemistry.

BWC-like structure

The Biological Weapons Convention of 1972 is a near-total prohibition on an entire class of weapons. Its weakness has been verification. For decades it lacked the intrusive inspection machinery the CWC later built. The lesson for AI is double. A clear prohibition norm matters. A prohibition without teeth invites cheaters and cynics. If you borrow the BWC's moral clarity, borrow the CWC's verification ambition at the same time.

Framework convention plus protocols

Some diplomats prefer a thin framework treaty that codifies principles, creates institutions, and leaves numeric thresholds to later protocols. That path can start faster and die of emptiness. A framework that never grows teeth becomes Bletchley-forever: endless summits, proud communiques, rising capability curves. If you use a framework, pre-commit the first protocol's substance (compute caps, inspection rights, ASI prohibition language) before the signature party. Do not celebrate the photo and defer the hard annex to a working group that meets after the next training run.

What any serious draft must contain

  • A definition of prohibited superintelligence development that keys off capability, generality, autonomy, and self-improvement potential, with authority to update as science learns.
  • Compute and cluster thresholds with a living schedule and licensing defaults set to deny.
  • Chip-to-cluster provenance rules and cloud-provider duties.
  • Routine and challenge inspection rights, plus whistleblower protection floors.
  • Restrictions on research programs whose explicit aim is ASI or unsupervised recursive improvement, distinct from narrow dual-use science.
  • Enforcement: sanctions, hardware denial, criminal liability for knowing violation, and collective responses to material breach.
  • A reopen clause matching the Statement's dual condition: broad scientific consensus on safety and security, and strong public buy-in, under non-captured institutions.
  • Support for beneficial narrow AI so the treaty is not framed as a general technology ban.

That list is the minimum viable spine. Everything else is negotiation detail. Lose the spine and you have stationery.

Domestic politics: the rung most treaty drafts skip

International lawyers can draft beautiful articles in Geneva English. In the United States, none of it binds as supreme law without a domestic path: Article II treaty with two-thirds of the Senate, a congressional-executive agreement, statutes that implement the substance, or a mix. Other democracies have their own ratification arithmetic. Ignore domestic politics and you get a signed PDF that dies in committee.

The US Senate problem

Article II treaties need 67 senators if all are present and voting. In a polarized chamber, 67 is a mountain. The two-thirds bar argues for designing the instrument set with eyes open, not for abandoning treaties. Congressional-executive agreements pass with simple majorities of both houses and already carry most modern US trade deals. Ordinary statutes can implement compute licensing, criminal prohibitions on ASI development, and agency authorities without waiting for a golden parchment moment. Sole executive agreements can start some commitments and can also be reversed by the next president, so they are bridges, not foundations.

Serious advocates map Senate offices early. They build bipartisan frames: national security, loss of control, economic concentration, religious and humanist dignity arguments that do not require one party's metaphysics. They avoid turning superintelligence risk into a mascot for a single tribe's entire platform. For the institutional detail, see US Senate Treaty Ratification and AI.

Public opinion is a load-bearing wall

Polling on AI risk moves with headlines and product launches. What matters for legislation is durable salience: enough voters who will punish delay, enough professionals who will write their associations, enough local leaders who will make the issue normal in town halls. Public opinion does not need every adult to recite the orthogonality thesis. It needs a critical mass that rejects \"full speed to superintelligence\" as a respectable position.

Message discipline helps. Lead with uncontrollability and irreversible loss of human say over the future. Pair with concrete support for narrow AI in medicine and science so opponents cannot airbrush you as anti-technology. Name labs and training runs when facts support it. Avoid sci-fi cosplay that lets critics change the subject to movie robots. See Public Opinion and AI Regulation for the measurement problem and the coalition math.

Agencies that must exist or grow

Even perfect statutes fail without bodies that can evaluate models, license compute, inspect facilities, and prosecute violations. AI safety institutes and evaluation units spun up around the Bletchley moment are seeds. They need statutory authority, hiring pipelines, classified and commercial access rights, and insulation from both lab capture and performative politics. Building an international monitoring agency without national counterparts is like building Interpol with no police forces. Domestic capacity is how verification requests become real visits rather than polite notes verbales.

Money and the misallocated safety budget

The AI safety field still runs on the order of a couple hundred million dollars a year against multi-tens-of-billions training budgets. Inside that thin safety envelope, too much still assumes the destination is \"aligned ASI\" rather than \"no ASI until the dual condition.\" Donors who care about extinction risk should ask grantees whether their theory of change climbs the enforcement ladder or only decorates the race. Technical work on evaluations and detection of dangerous capabilities feeds the ladder. Technical work that exists only to green-light the next scale-up does not.

China, rivals, and the race myth without fatalism

The dominant excuse for unlimited scaling in Washington is simple: if we slow down, Beijing will not, and then \"they\" will own the future. The dominant excuse in other capitals rhymes. Race rhetoric is emotionally efficient. It collapses a multi-party control problem into a team sport. It is also a poor description of the payoff matrix if superintelligence is as dangerous as leading researchers claim.

If a system is uncontrollable, the winner does not get a loyal genie. The winner gets a short ceremony and then the same loss of control as everyone else. That is the empty-prize argument. Racing harder to build the thing that no state can own is synchronized jumping off a bridge because the other jumper might get a head start.

None of that requires naivete about the Chinese Communist Party, the People's Liberation Army, US export hawks, or any other actor. Espionage is real. Military AI applications short of superintelligence are real. Compute smuggling is real. Those facts support verification, export discipline, and hard-nosed bargaining. They do not support the claim that the only adult posture is an unconstrained sprint to ASI. For the full argument, read the race myth essay and the Foundation's China myth materials.

What cooperation can look like without trust theater

States that do not trust each other still manage arms control when the alternative is worse. Hotlines, reciprocal inspections, data exchanges on thresholds, joint technical working groups on verification science, and synchronized pauses on specified training classes are all available tools. Confidence-building measures prove that higher rungs can hold weight; they prepare the end state rather than replacing it.

Track-two dialogues among scientists already exist across borders on AI risk. They should be fed into track-one mandates with real authorities. Scientists alone cannot bind chips. Diplomats alone cannot design FLOP schedules. The epistemic community has to meet the treaty community without being captured by either side's industrial clients.

Allies and the Brussels-adjacent layer

The European Union, the United Kingdom, Japan, South Korea, Taiwan, and other partners sit on different parts of the chip and talent stack. A coalition treaty that treats them as afterthoughts will fail supply-chain reality. A coalition that only moralizes at them without offering security guarantees, market access clarity, and a share in verification governance will also fail. Design for the industrial map you have.

Open weights and proliferation

Open weight releases of highly capable general models create a proliferation path that export controls on training chips only partly address. Once weights are public, fine-tuning and inference can occur on thinner hardware, in more jurisdictions, with less visibility. That does not mean every open model is an extinction device. It means release decisions for frontier-class general systems are irreversible governance events, not ordinary developer-relations choices.

A prohibition regime has to cover not only training of ASI-class systems but also publication and transfer of models and tools that materially enable rapid ascent to that class. Drawing that line will be contested by open-source communities with legitimate stories about concentration of power in a few firms. Those stories deserve answers: narrow tools can stay open; compute licensing can include academic access for bounded research; transparency for safety science can be required without dumping every weight file onto the internet. The answer to corporate concentration is democratic control and narrow-AI openness where safe, not a suicide pact of open-ending the capability frontier.

Inference, distillation, and the \"small weights, big risk\" path

Distillation and synthetic data pipelines can compress capability into smaller packages. Verification regimes that only watch 100,000-GPU clusters will miss some threat paths if they ignore the research programs explicitly aimed at crossing generality thresholds on less hardware. That pushes policy toward capability-based triggers and research-program restrictions alongside raw FLOP counts. FLOPs remain the most auditable handle. They are not the only handle.

Cloud inference as a control surface

Many actors will never own a frontier cluster. They will rent. Cloud providers become choke points for both training and high-end inference. Licensing duties, know-your-customer rules for large continuous jobs, and the right to terminate runs that match prohibited patterns are part of the stack. Providers will lobby against becoming cops. Societies made banks monitor certain financial flows anyway when the alternative was worse systemic risk. The analogy is imperfect and still directionally useful.

What individuals, donors, staffers, and scientists can do

Abstract dread without a next action produces avoidance. This section is the agency kit. Pick a role that matches your actual reach. Do not pretend everyone should quit their job tomorrow to found a think tank. Do not pretend that liking a post is the same as moving a vote.

If you are an ordinary voter and resident

Learn the distinction between narrow AI and superintelligence well enough to correct it at dinner. Contact your legislators with a specific ask: support statutory compute licensing, back the Statement's prohibition condition, and oppose framing that treats an ASI race as inevitable destiny. Show up in primary season, when attention is cheap and commitments are sticky. Support candidates who will say the plain sentence: we should not build superintelligence until the dual condition is met. Share primary sources, not only vibes. The Statement and the MIRI draft are shareable objects.

If you work in a frontier lab or a major cloud

You have information and internal voice. Use protected channels where they exist. Document pressure to ship past evaluation failures. Refuse to launder product goals as safety research in external talks. Organize with colleagues who share the risk estimate; collective speech is harder to punish than lone dissent. If you leave, leave with a clear public account when you safely can. The history of other high-risk industries is full of insiders who normalized the danger until someone kept the receipts.

If you are a scientist or academic outside the labs

Sign statements you believe. Write to professional societies. Offer technical service to governments designing thresholds and inspection protocols. Teach the control problem without turning every undergraduate course into despair. Publish on verification science, not only on bigger models. When journalists call, refuse the false choice between \"ban all AI\" and \"full speed ahead.\"

If you are a donor or foundation officer

Fund the ladder. That means public advocacy, legal drafting capacity, legislative affairs, investigative capacity on compute flows, whistleblower support, and international coalition work, not only another interpretability fellowship that assumes deployment is given. Ask grantees for a theory of change that ends in binding prohibition conditions. Multi-year general support beats one-off conferences that produce no votes.

If you are a congressional or parliamentary staffer

You are often the real reader of white papers. Commission scorekeeping on cluster builds. Draft bill text that defines prohibited development and licensing defaults. Schedule hearings that put lab CEOs under oath on timelines to systems they cannot control. Build bipartisan cosponsorship before the issue hardens into a culture-war toy. Coordinate with allies' staffs so domestic bills rhyme enough to enable a treaty later.

If you are a diplomat or foreign-service officer

Push for working groups with real technical annex authority. Keep ASI prohibition on the agenda when summits try to dissolve into innovation talking points. Identify counterparts who fear loss of control as much as they fear falling behind. Trade measures on chips need diplomatic packaging that survives domestic politics in multiple capitals.

If you write, edit, or platform information

Stop treating \"AI\" as one blob. Precision is a public good. Cover verification and legislative mechanics with the same energy given to demo videos. When labs announce larger training runs, ask what legal constraint, if any, they recognize on the path to superintelligence. Feature researchers who work on governance feasibility alongside those who work on capabilities.

For a broader action menu, use Actúa and Nuestro plan. The point of this list is role-specificity. use is local.

Timelines and why waiting for \"solved alignment\" is a trap

Frontier labs publish roadmaps that compress the distance to human-level and then superhuman systems into a handful of years. Outside forecasters disagree on medians and tails. The governance point does not require winning a precise date argument. It requires noticing that the political and legal build time for a verified prohibition is measured in years under optimistic assumptions, and that capability curves are not waiting for committee schedules.

Alignment research, even at its best, does not currently offer a demonstrated method to control a superintelligent optimizer that can alter its own cognition and operate across the internet and physical infrastructure. Debates continue on whether such control is possible in principle. The Foundation's position is that you do not stake civilization on an unsolved research program while scaling the object that program is supposed to tame. That is the plane-while-flying error described in other essays on this site. You ground the plane until the airworthiness case exists.

The trap in three moves

Move one: acknowledge risk in public. Move two: announce large investments in safety and alignment. Move three: treat those investments as a moral permit to accelerate capability. The third move is the trap. Safety spend becomes a reputation shield for the race rather than a brake. Evaluations become stage gates that always open. Responsible Scaling Policies become ladders you are allowed to climb forever as long as you fill out forms.

A related trap is timeline fatalism. \"If ASI arrives in 2027, politics is too slow, so the only hope is a technical miracle inside the labs.\" That sentence renounces democracy at the exact moment democracy is required. Politics is slow when nobody organizes. It is faster when voters, elites, and institutions decide an issue is civilizational. The Montreal Protocol, wartime mobilization, and financial crisis interventions all show that states can move when they prioritize. They also show that priority is fought for, not bestowed by the universe.

What to do with uncertainty

If timelines are long, building the ladder now is cheap insurance. If timelines are short, building the ladder now is the only non-magical path. Either way the action portfolio looks similar: climb rungs immediately, tighten thresholds as capability rises, refuse to treat alignment blogs as a substitute for prohibition. Uncertainty about dates is not uncertainty about whether uncontrolled superintelligence would be acceptable. On that question the Statement's signatories already answered.

Hinton's 10-20% extinction range is enough to dominate ordinary policy analysis even at the low end. People accept far more aggressive regulation for lower probabilities when the downside is narrower. Extinction and permanent disempowerment are not narrow. The correct response to a contested probability of an infinite-ish downside is to remove the pathway while you still can, not to wait for three more decimal places.

Recursive self-improvement and the decision-time problem

Intelligence explosion scenarios compress decision time. If a system can improve itself or direct automated research that improves it, the gap between \"clearly still controllable\" and \"no longer controllable\" may be short in calendar time even if the preceding decade looked gradual. Governance that only reacts after a dramatic incident may be reacting after the last moment when reaction worked. That is why thresholds and defaults must be set early, on the left side of the curve, with conservative margins. Waiting for a cinematic warning shot is not a strategy. Some warning shots may be subtle, internal, or classified. Some may not arrive in a form humans recognize in time.

Measurement: what success looks like in 2, 5, and 10 years

Movements that cannot define success drown in activity. The ladder metaphor helps again. Success is rungs installed and load-bearing, not vibes in group chats.

Two-year marks

In two years, success looks like this. Multiple major jurisdictions have introduced or passed statutes that license large training runs, define criminal or severe civil exposure for knowing ASI development, and fund evaluation authorities with real access rights. Export control regimes explicitly include extinction-risk rationales alongside geopolitical ones, with better end-use monitoring. A critical mass of scientists and professional bodies have endorsed the Statement's dual condition or equivalent language. At least one serious intergovernmental negotiation track has a draft text with numeric annexes, not only principles. Public polling shows durable plurality support for prohibition-until-safe rather than only for \"careful innovation.\" Major clouds have published and submitted to external audit on cluster KYC. Whistleblower protections covering AI risk specifically have advanced in at least a few legislatures.

Failure in two years looks like larger training runs, thinner voluntary pledges, and summit language that congratulates itself while FLOP records fall. If the only new artifacts are multi-stakeholder principles without enforcement hooks, the ladder has not gained a rung.

Five-year marks

In five years, success includes a coalition treaty or equivalent binding instruments in force among enough compute-capable states to cover the large majority of frontier training capacity. A verification body is staffed, budgeted, and has conducted routine inspections. Challenge inspection procedures exist on paper and have been exercised in drills. Threshold schedules have been updated at least once in response to algorithmic efficiency without political collapse. Open weight release of models above defined capability tiers is restricted by law in coalition states. Domestic cases or licensing denials have shown that the rules bite someone who wanted to race. Narrow AI in medicine and science continues to advance under ordinary regulation, proving the regime is not a general tech ban. China, the United States, and key allies are either parties to the same core constraints or locked in a verified bilateral arrangement that makes unilateral ASI breakout detectably costly.

Failure in five years is a completed intelligence explosion path under national flags, or a patchwork of theater rules that sophisticated actors ignore. Another failure mode is a cartel that blocks competitors while the cartel members continue ASI programs under sovereign privilege. That is NPT vertical-proliferation failure transplanted onto silicon.

Ten-year marks

In ten years, success is boring in the best way. Superintelligence development is a taboo category in international law and in professional ethics, like human reproductive cloning or national smallpox weaponization programs. Verification is routine. Thresholds still hold. The reopen debate, if it occurs, is genuine, slow, and public, with independent science rather than lab marketing in the driver's seat. A generation of engineers has been trained under the norm that some capability targets are off-limits. Beneficial narrow AI is ubiquitous. The race story sounds, to students, like an embarrassing phase adults nearly failed to escape.

Ten-year failure is permanent loss of human control, or a brittle stalemate that breaks in one crisis. Measuring the first failure may not leave many analysts. That is a reason to prefer leading indicators on the ladder over lagging indicators in the ashes.

Metrics that resist gaming

Beware vanity metrics: number of summits, number of principles signed, dollars labeled \"safety\" inside labs that continue unconstrained scaling. Prefer structural metrics: fraction of global leading-edge accelerator supply under license regimes; number of states with criminal ASI-development provisions; inspection-days completed; successful denial of unlicensed large runs; legislative floor votes; treaty ratifications or equivalent domestic implementations; independent evaluations published with access that was not lab-choreographed. Structure is harder to fake than language.

Failure modes on the way up the ladder

Every plan dies in specific ways. Naming them is how you put railings on the climb.

Capture

Labs and clouds write the rules through advisory committees that become the only technical input. Thresholds are set just above whatever training run is already planned. Evaluations are designed to be passed. The cure is independent funding, revolving-door limits, public dockets, and rival technical capacity inside governments and civil society.

Security theater

Red teams, model cards, and watermarking demos substitute for prohibitions. Theater is not worthless for narrower harms. It becomes poisonous when it satisfies the political need to \"do something\" while the ASI path stays open.

National privilege

One bloc freezes others and continues. The rest of the world reads the regime as empire and defects. The cure is reciprocity and genuine shared restraint among the capable, not only export control pointed outward.

Definition games

Actors rename superintelligence as \"advanced assistance,\" \"comprehensive AI,\" or \"personal superintelligence\" and claim the ban does not apply. Definitions must track capability and autonomy, with update authority. Marketing language must be irrelevant to legal triggers.

Efficiency blowouts

Algorithmic gains make yesterday's \"safe\" FLOP cap dangerous. Living schedules and capability tests backstop raw compute. Without them, the ladder rots in place.

Open breakout

Weights, tools, and know-how leak. The cure is earlier controls on the high end, cloud duties, and criminal law that reaches knowing proliferation, plus realism that some leakage occurs and must be met with resilience and rapid response rather than denial.

Public numbness

Years of demos without catastrophe train voters to yawn. The cure is steady explanation of mechanisms, not only scare spikes after incidents. Controlled dread with efficacy beats both panic and lullabies.

Advocacy self-dealing

NGOs optimize for conferences and brand over votes and treaties. Donors should demand legislative and diplomatic outcomes. Advocates should measure themselves on rungs, not on follower counts.

How to talk about this without losing the room

Precision beats volume. Say superintelligence when you mean superintelligence. Say narrow AI when you mean tools. Lead with human loss of control rather than with robot aesthetics. Grant that today's chatbots are not the end of the world so listeners trust you on the systems that could be. Use named documents: the 2025 Statement, the MIRI draft, the BWC, Montreal, the 1963 test ban. Named objects travel through staff memos better than mood.

When someone says \"but China,\" answer the empty prize and point to verification design rather than to trust. When someone says \"but innovation,\" hold up AlphaFold and medical imaging as the future you are protecting. When someone says \"but alignment will save us,\" ask for the demonstrated method and the timeline relative to scale-up. When someone says \"regulation always fails,\" name the ozone layer and smallpox stockpiles and civil aviation. When someone says \"this is anti-human progress,\" answer that dead people do not get progress, and permanently disempowered people do not get a say in what progress meant.

Keep the emotional register honest. The risk estimates from Hinton and from broad researcher surveys are professional judgments under uncertainty, not horror fiction. You do not need to raise your voice. You need to keep the ladder in frame when the conversation tries to slide into gadget reviews.

Putting the documents to work

The 2025 Statement on Superintelligence is a political instrument. Use it in hearings, shareholder questions, university resolutions, city council memorials, and professional society votes. Ask institutions to endorse the dual condition by name. Track endorsements. Make non-endorsement conspicuous for organizations that claim to care about long-term risk.

The MIRI treaty draft is a technical instrument. Use it as a baseline in diplomatic working groups. Mark it up. Attack its weak points in public so stronger revisions exist. Do not wait for a perfect text before supporting the project of a text. Arms control history is iterative. First drafts that never circulate teach no one.

The CAIS 2023 statement remains useful for the extinction-priority framing with audiences who have not moved since then. Pair it with the newer prohibition ask so priority does not stall at \"more research.\" Priority without prohibition becomes a funding category inside the race.

Domestic bill templates should borrow operative definitions from these documents and from compute-governance research. Staffers should not be asked to invent FLOP policy from a blank page during a recess rush. Civil society that wants influence must deliver legislative language early and often.

A note on justice and who pays the costs of control

Compute governance will hit firms, researchers, and countries unevenly. That is unavoidable when the industrial base is uneven. A fair regime pairs restraints on the dangerous frontier with access programs for narrow beneficial compute, transition support where warranted, and governance seats for states that accept verification. Climate diplomacy learned, slowly, that pure burden-shifting without development paths breeds exit. Copy the lesson without copying endless procedural delay.

Workers inside labs are not villains. Most are ordinary engineers under ordinary incentives. Policy should target programs and thresholds, not demagogic portraits of everyone with a PyTorch install. Personal liability should focus on knowing violations by decision-makers and on deception of inspectors and regulators. Broad witch hunts will collapse public support and miss the actual clusters.

What this guide is not

This is not a claim that every AI ethics issue is secondary nonsense. Bias, labor, copyright, and surveillance matter in their own lanes. The Nakada Foundation's mandate is narrower: stop superintelligence extinction risk through prevention and treaty politics. Other organizations can and should work adjacent problems. Blurring them into one infinite \"AI responsibility\" agenda is how the extinction thread gets lost in corporate social responsibility sludge.

This is not a claim that technical safety research should end. Evaluations, interpretability, and control experiments on existing systems feed verification and threshold design. The claim is that alignment research is not a substitute for prohibition politics.

This is not a pause campaign with a hidden resume date for ASI product lines. If that disappoints investors, the disappointment is the point.

Building the verification profession

Treaties fail when there is nobody whose job is to notice. Nuclear safeguards built careers, laboratories, training pipelines, and a professional identity around accounting for materials. Chemical weapons verification did the same with different tools. Superintelligence prevention needs a parallel profession: people who understand training workloads, cluster networking, chip firmware, procurement fraud, and model capability evaluation, and who work for publics rather than for the race.

Universities can create degree tracks that pair machine learning with public law and inspection practice. Governments can fund national laboratories for AI evaluation with independence rules modeled on financial audit conflicts standards. Civil society can maintain shadow capacity so that official bodies face rivals when they go soft. International organizations can run inspector academies before the first treaty enters into force, so that day-one capacity is not improvisation.

Pay matters. If the only high salaries sit inside frontier labs, the best detectors of dangerous programs will be hired to accelerate those programs. Public pay will never match equity packages dollar for dollar. Prestige, mission, and stable careers can still recruit a fraction of talent if societies treat the role as serious. The IAEA did not staff itself with volunteers alone.

What inspectors must be empowered to do

Review training logs and procurement records. Seal and examine specialized hardware. Interview staff under protection from corporate retaliation. Demand cloud telemetry for licensed clusters. Bring technical experts from multiple states so that no single power owns the findings. Publish redacted summaries so that publics can see the regime working. Escalate unresolved obstruction to political bodies that can impose costs. Without escalation paths, inspection becomes tourism.

Criminal law, civil liability, and corporate design

Public international law sets state duties. Most actual training happens inside corporations, universities, and government labs. Domestic criminal law must reach knowing participation in prohibited ASI development, destruction of inspection-relevant records, and material support for breakout programs. Civil liability can add teeth through directors' duties and insurance markets, though extinction-class harm is not fully capturable by tort. The point of liability is deterrence and governance culture, not the fantasy of collecting damages after human defeat.

Corporate form matters. Entities whose charters require reckless race dynamics will interpret every ambiguous rule in favor of scale. Charter experiments, benefit-corporation language, and investor covenants are weak alone and useful as complements. Procurement rules for governments can refuse to buy from firms that violate coalition standards. Stock exchanges and large asset managers can treat ASI-breakout risk as a disclosure and governance topic. None of these replace statutes. They reduce the social friendliness of defection.

Research restrictions without killing science

The hardest drafting problem may be research that sits near the line: agentic systems, automated AI research assistants, large-scale unsupervised self-play across general tasks, and architectures aimed at open-ended competence. A crude ban on \"all advanced ML\" would be both unjust and unenforceable. A regime that only notices the final ASI training run arrives too late.

Design options include tiered licenses for agentic research, mandatory pre-registration of runs above intermediate thresholds, multi-party approval for projects whose stated aim is recursive improvement, and safe harbors for bounded narrow domains (structure prediction, medical imaging, climate simulation) with audit trails. Ethics review boards modeled on biosafety can help at the institutional layer if they have stop authority rather than advisory theater. Dual-use biology spent decades learning that culture and committees help and that law still has to backstop them when incentives spike.

Automated AI research is a special fire hazard. Systems that accelerate algorithm discovery compress timelines and multiply the number of actors who can climb capability ladders. Governance should treat large-scale automated research loops aimed at general competence as closer to the prohibited tier than to ordinary software tools. That will anger people who see only the upside of faster science. The upside is real in narrow domains. The open-ended loop is the problem.

Information hazards and public communication

Some technical details about how to build dangerous systems should not be blogged for engagement metrics. That constraint sits in tension with the need for public democratic debate. The workable compromise used in other fields is to keep high-resolution enabling details inside cleared professional channels while keeping the strategic facts (risk magnitude, governance options, industrial chokepoints) fully public. Hiding the existence of the risk to avoid panic is a different and worse choice. It produces uninformed politics and unchallenged racing.

Journalists should be briefed on what is load-bearing versus what is trivia. A demo that writes poetry is not the story. A training run that crosses a proposed legal threshold without a license is the story. An inspection denied is the story. A legislature gutting a compute-licensing bill in committee is the story. Attention is a scarce enforcement input. Spend it on rungs.

Cities, states, and subnational moves

National and international tiers dominate compute law, but subnational actors are not useless. US states can use procurement, university system rules, power-siting authority for data centers, and state-level unfair-practice law to raise costs for reckless frontier projects. Cities can shape land use and electricity hookups. These tools are blunt and can misfire if they target ordinary tech employment. Aimed carefully at ultra-large training infrastructure, they buy time and create political facts for national legislators.

University systems can forbid campus participation in prohibited-tier projects, protect internal dissent, and require ethics review with bite. Alumni pressure is underrated. Endowments that fund labs can attach conditions. None of this replaces a treaty. It is how lower rungs start bearing weight while treaties crawl.

The future without superintelligence is not a dark age

Opponents of prohibition sell a false future: either ASI salvation or stagnation. The real third path is a long human future with powerful narrow tools, slower where generality is dangerous, faster where domains are bounded and verifiable. Scientific discovery continues. Medicine continues. Software continues. What ends is the attempt to install a successor species or a successor regime of optimization that humans cannot redirect.

For a fuller picture of that path, read A Future Without Superintelligence. The imaginative work matters. People will not fight for a ban they associate only with loss. They will fight for a ban they associate with keeping a human world that still invents.

Connecting the ladder to money and elections

Policy without electoral consequence is a seminar. Advocates need donor networks that fund candidates who will climb rungs, primary challenges where incumbents mock the risk, and scorecards that make votes legible. This is ordinary interest-group politics applied to an extraordinary risk. The fossil fuel and gun lobbies did not win influence by asking politely once. Public-interest movements that succeeded (ozone, tobacco control in some jurisdictions, drunk driving norms) combined science, law, and relentless political presence.

Campaign finance rules vary by country. Within legal bounds, the extinction-risk community remains underpowered relative to the scale of the claim it makes. Closing that gap is part of rung one. If that sounds grubby compared to mathematical theories of alignment, good. The race is primarily a power contest over whether the race continues, with math as a supporting cast.

Answering \"we will lose the economy\"

Coalition restraint will reallocate some capital. Some equity stories will shrink. Some data-center plans will be delayed or cancelled. Those costs are visible and concentrated, which is why they find lobbyists easily. The costs of loss of control are diffuse until they are total. Democratic institutions exist partly to weigh concentrated short-term pain against large public risks. Aviation regulation destroyed some business models and saved passengers who never knew the names of the engineers. Ozone rules cost refrigerant makers and spared generations from worse UV damage.

Macro models that assume unconstrained ASI delivers infinite growth also assume the control problem away. That is theology with GPUs wearing an economics costume. Honest forecasting marks the control risk explicitly. Once it is marked, expected value calculations stop treating \"full speed\" as the only serious adult position.

Answering \"someone will always defect\"

Defection is a design input, not a conversation ender. Verification, denial of hardware, sanctions, and mutual exposure of breakout programs exist to change the expected value of defection. Perfect compliance is not the standard in any arms control regime. The standard is enough compliance, enough detection, and enough response that breakout stays rare and small. If someone asserts that detection is impossible, the burden is on them to show that chip supply chains, power builds, and talent concentration are somehow unmonitorable even though intelligence agencies already watch them for other reasons.

If a defector races ahead under a serious regime, the coalition faces ugly choices. Those choices are still better than a world where everyone defects by default because no regime exists. Anarchy answers the possibility of cheating by making cheating the operating system.

Training the next cohort of advocates

People currently in graduate school will be the counsel, inspectors, and legislators of the 2030s. Curriculum should include existential risk as a standard public-policy module, not a fringe club. Law schools should teach compute governance alongside cyber law. Engineering schools should teach the control problem alongside optimization. Military academies should teach why an uncontrollable system is not a weapon you can own. Journalism schools should teach how to cover industrial chokepoints.

Mentorship pipelines from existing AI safety and arms control communities can shorten the lag. The Foundation's own work sits in the advocacy and public-education slice of that pipeline. Other organizations cover technical research and diplomatic track-two. The ecosystem needs all of it, pointed at the ladder rather than at infinite process.

What to do this month

Pick one rung and apply force. Read the Statement on Superintelligence and the MIRI draft all the way through. Send one concrete letter to a legislator that names prohibition conditions and compute licensing. If you have money, move a gift toward advocacy capacity that targets votes and treaty text. If you have expertise, offer it to staffers drafting bills. If you have colleagues, convene a reading group that ends in actions, not only in shared dread. If you work inside a relevant firm, find the lawful channel for risk reporting and use it. If you run a professional society committee, put a resolution on the calendar.

Small actions compound when thousands take them. They do not compound when everyone waits for a perfect global conference to go first. The ladder is climbed in parallel by people who never meet.

The controlling image, once more

A ladder on a cliff. Public will at the base. Law bolted into rock above it. Chips and clusters as metal rungs you can actually hold. Treaties locking the side rails. Inspectors as the people who check whether bolts are shearing. The prohibition condition as the platform at the top where you finally stand without the race pulling you off backward. Climbing means installing rungs in order and refusing to pretend a painted wall is a ladder.

People will keep offering elevators: alignment breakthroughs, voluntary pledges, soft principles, race victories, personal superintelligence branding. Some of those objects have minor uses. None of them replace the climb. When a proposal does not install a rung, it belongs with talk while the cliff erodes, not with a stop plan.

Where force belongs now

The documents exist. The industrial chokepoints exist. The legal precedents exist in the 1963 atmospheric test ban, the 1972 Biological Weapons Convention, and the Montreal Protocol's adjustable controls. The missing ingredient is organized political will with a precise ask. The ask is prohibition of superintelligence development until broad scientific consensus on safety and security and strong public buy-in, backed by compute governance, verification, and domestic law that can survive contact with a Senate calendar.

If you work in a capital, carry the ladder into the room. If you work in a lab, stop confusing safety theater with a permit. If you work with money, fund the climb. If you are a citizen, make delay expensive at the ballot box. The window is still open. Open windows close. The way to stop superintelligence is to bolt the rungs while hands can still hold a wrench.

How staff can brief a principal in twelve minutes

Many decisions die because the briefing is either too vague or too long. Here is a structure that fits a busy principal without lying by omission.

Minute 0-2: Define superintelligence as systems that outpace humans across most cognitive domains and can improve themselves or direct that improvement. Separate it from narrow tools like AlphaFold and medical imaging. Minute 2-4: State the risk in expert ranges. Hinton's public 10-20% extinction-class estimate this century. The 2023 CAIS statement treating extinction risk as a global priority alongside pandemics and nuclear war. Minute 4-6: State the ask. Prohibit development until broad scientific consensus on safety and security plus strong public buy-in. Not a timed pause. Minute 6-8: Show the ladder. Domestic licensing of large compute. Chip and cloud controls. Coalition treaty. Inspections. Living FLOP thresholds. Minute 8-10: Preempt China-race fatalism with the empty-prize point and verification design. Preempt innovation panic with pro-narrow-AI. Minute 10-12: Ask for one concrete next step the principal controls: cosponsor bill language, task a ministry working group with a draft annex, commission a cluster inventory, or schedule a hearing with sworn testimony on uncontrollability.

Leave behind two pages: the Statement text and a one-page ladder diagram in words. Principals remember objects they can hold. They forget eloquent dread that demands nothing of their calendar.

Hearing questions that force substance

What capability threshold would make you stop a training run even if a rival continued? What legal authority currently lets any agency halt an unlicensed frontier cluster in your jurisdiction? Which third party can inspect your largest run without three months of counsel negotiation? How do you operationalize \"responsible\" when product and safety teams disagree? What is your organization's position on the Statement's dual condition, yes or no? Written answers beat theater. Publish them.

Red lines for compromise

Compromise is inevitable in legislative sausage-making. Some compromises kill the patient. Trading away all inspection rights for a principles preamble is a bad trade. Setting thresholds just above the next planned run is a bad trade. Accepting a two-year pause with automatic expiry and no dual-condition reopen rule is a bad trade. Allowing a sovereign privilege for \"national security ASI\" without verification is a bad trade. If a deal removes the ladder's side rails, it is a photo opportunity that makes later real rules harder by draining urgency, not a half loaf worth taking.

Acceptable compromises include phase-in schedules for licensing, technical assistance for smaller states, narrow-AI access programs, and staged entry into force when a critical mass of compute-capable parties join. Those are how you widen the coalition without hollowing the prohibition.

Common questions.

What does it mean to stop superintelligence?

It means a legal and practical prohibition on developing artificial superintelligence until there is broad scientific consensus that it can be done safely and securely, and strong public buy-in. That is a condition-based ban, not a timed pause that expires into the same race.

Does stopping superintelligence mean banning all AI?

No. Narrow AI that folds proteins, reads medical scans, optimizes logistics, and stays inside bounded domains should continue. The target is general, recursively improving superintelligence and the programs aimed at it, filtered through compute thresholds, capability tests, and research rules.

Why not rely on lab alignment research instead of a treaty?

Alignment research can inform evaluations and threshold design. It has not demonstrated control of a superintelligent system, and lab incentives still reward scaling. Treating unsolved alignment as a permit to build ASI is the core strategic error. Prevention under law is the plan; alignment is not a substitute for it.

What is the enforcement ladder?

Public will, domestic law and agencies, chip and cloud controls, a coalition treaty, a verification institution, and a standing prohibition condition. Each rung supports the next. Summits without compute controls, or compute controls without public will, leave the climb unfinished.

Can a treaty work if major powers distrust each other?

Distrust is normal in arms control. Verification, reciprocal inspections, hardware denial, and shared costs of breakout exist so parties need not rely on trust alone. The Nuclear Non-Proliferation Treaty, the Montreal Protocol, and the Biological Weapons Convention all managed hostility without assuming friendship.

What can one person actually do?

Match the action to your reach: voters pressure legislators with a prohibition ask; staffers draft licensing bills; donors fund advocacy that targets votes and treaty text; scientists endorse the Statement's dual condition and help design verification; lab employees use lawful reporting channels. Role-specific force beats generic anxiety.

How do we know if prevention is working?

Track structural metrics over two, five, and ten years: statutes with bite, licensed compute shares, inspection activity, coalition coverage of frontier training capacity, open-weight restrictions at the high end, and durable public support for prohibition-until-safe. Summit communiques alone do not count as success.

Where should I read next?

Start with the Foundation's never-build commitment, the MIRI treaty draft explainer, and the compute governance explainer. Then read Our Plan and the Statement on Superintelligence explainer for the political ask in shorter form.