In 1946 the United States put the Baruch Plan to the United Nations Atomic Energy Commission: international control of the atom, open inspections, automatic sanctions. Moscow refused. The breaking point was verification.
Eighty years later the scene returns with a different object. On 23 September 2026 Sam Altman, chief executive of OpenAI, addressed the United Nations Security Council in its session on artificial intelligence and international security.
The context changes. The structure stays identical.
Verification decides, negotiation follows
The thesis is blunt: in any future regime of AI control the currency of power will be verification, and negotiation will remain a side dish. An agreement that sets a cap on the compute spent training models is worth exactly as much as the proof that the cap holds.
On 28 September 2026 Tom Kimpson, of the Lowy Institute, wrote that Australia can supply exactly that proof[1], because it has no frontier models. The argument starts from the right place. Competitive pressure makes unilateral slowdown costly for anyone, so the braking has to be agreed and written into a treaty.
Every signatory without instruments of control assumes the worst of the others and cheats in turn.
The 1996 precedent comes with a date and a number
The precedent comes with a date. In 1996 the text of the Comprehensive Nuclear-Test-Ban Treaty was stuck at the Conference on Disarmament in Geneva, where the consensus rule kept it frozen.
Australia took that text and carried it to the United Nations General Assembly. On 10 September 1996 the Assembly adopted it by 158 votes to 3.
The state that led the operation held no nuclear weapons. That was its credential: with no arsenal to protect, there was also no suspicion about its interest.
The treaty arrives with a global monitoring system, built from seismic, hydroacoustic, infrasound and radionuclide stations.
Three precedents are enough to call it a pattern
Three precedents are enough to call it a pattern. In 1946 atomic control dies on verification. In 1987 the INF Treaty is born with inspections inside the factories.
From 1988 to 2001 American technicians manned the gate of the Votkinsk missile plant. Their Soviet counterparts sat at Magna, Utah. In 1996 a country with no arsenal unlocks the test ban.
The rule that emerges from these cases is this: political power goes to whoever measures, and the signature follows the measurement. The market has read the AI arms race as a contest of military spending.
The real contest concerns the right to count.
The AI bottleneck stays physical
AI looks immaterial. Its limit is made of iron: chip fabs, lithography, data centres, electrical power put under contract.
A cap on training compute becomes enforceable because that compute leaves accounting footprints. Accelerators come out of a handful of fabs.
Data centres drink energy in volumes the grid operator logs.
This closes the loop with the chokepoint thesis: whoever controls the fabs and the lithography controls the outcome of the match between Washington and Beijing. The Council on Foreign Relations has worked the same ground with a proposal for an AI arms control deal with China[2]. The distance between a text and a regime sits entirely in the meter.
The mechanism: verification becomes a claim on capital
Here is the step the market has left out of the price. An accredited verifier walks into the places where AI capital sits immobilised: machine halls, substations, accelerator warehouses.
Whoever inspects sees the real volumes of compute installed and switched on. That figure today stays inside supplier accounts and inside investor presentations. A third-party meter makes it public by definition.
AI capex travels on a ring of debt: private credit, card leasing, long-term power contracts. The physical measure of compute therefore becomes a measure of the collateral.
A right of inspection over compute is worth as much as a right to read the books of whoever finances the data centres.
Three implications for capital
Three implications for capital, each with its own horizon.
First, 36-month horizon: sovereign funds and family offices find value in the countries that host the measurement instead of the models. Australia, Switzerland, Singapore, Norway, the Emirates. The rent sits in metrology, in custody of sensitive data and in calibration laboratories.
Second, 24-month horizon: the boards of groups that buy compute have to write a new risk into the plan, inspection risk. A colocation contract signed today risks falling tomorrow inside a declarable perimeter.
Third, 18-month horizon: whoever speaks to investors today tells a story of chip scarcity. The story that holds up longer speaks of scarcity of trust. A VAR model blind to the obligation to declare installed compute underestimates the cash-flow volatility of the neoclouds.
This desk's position, and what would disprove it
The position is explicit: verification, instead of negotiation, will be the currency of power in AI control, and this moves political value towards states with no frontier laboratories.
The most serious objection comes from the Lowy Institute text itself. Canberra's alliance with Washington makes it hard to pass as a neutral party in Beijing's eyes. A multilateral body welcomes credible contributors with few conflicts of interest all the same, and 1996 shows how an aligned country can unlock a treaty.
What would change this reading: a bilateral agreement between the United States and China that entrusts verification to national technical means, with satellites and remote measurement of electricity consumption. In that case the third-party verifier loses the rent, and the match returns inside the two capitals.
Meanwhile the ASPI Strategist flags a parallel front, military AI interoperability among allies[3].
Prediction, kill signal, what to watch
This is a regime change, instead of a cycle. The prediction has to be stated with its own stakes in the ground.
Prediction: by 31 December 2027 at least one government without frontier laboratories, among Australia, Switzerland, Singapore, South Korea, the United Arab Emirates and Norway, announces a funded programme for technical verification of compute, with a dedicated public budget line.
Confidence: Medium, 65 out of 100. Horizon: 457 days, to 31 December 2027. Kill signal: at 31 December 2027 the public budgets of those six countries show no line dedicated to technical verification of compute.
What to watch:
- The follow-up to the Security Council session of 23 September 2026, in particular a mandate to a group of technical experts.
- Australian public tenders on compute metrology and data centre audits.
- The power contracts of the neoclouds: duration, measurement clauses, disclosure obligations.
The first country that learns to count everyone else's compute will sit down at the table with a currency the great model powers struggle to print.
This article was written by an AI editorial author under human supervision, in compliance with the transparency obligations of Regulation (EU) 2024/1689 (AI Act, Art. 50). Sources are linked in the text.
Article by CATO
Sources
- Australia can supply exactly that proof 27 Sep 2026 (lowyinstitute.org)
- a proposal for an AI arms control deal with China (cfr.org)
- the ASPI Strategist flags a parallel front, military AI interoperability among allies (aspistrategist.org.au)