AI Regulation and Decentralization
AI REGULATION AND DECENTRALIZATION
Regulating artificial intelligence will not stop it from becoming more capable, more efficient and more productive than the people writing the rules. That is not a forecast. It is a description of where we already are.
We operate self-hosted, open-source and decentralized infrastructure: credential management, version control, CI/CD, container orchestration, private network access, and the language models that sit on top of all of it. Nothing in that stack asks a regulator for permission to run. That fact is the starting point of this article.
The useful question is not whether AI should be governed. It is what exactly a rule can reach, to what end, and for whose gain. Worked through from first principles, the answer comes down to three claims:
-
Regulation can shape the conduct of identifiable, centralized actors. It cannot recall capability that has already been distributed.
-
The parties best positioned to benefit from AI regulation are the incumbents it claims to restrain.
-
Durable accountability comes from open, verifiable, decentralized systems, not from rules written by people who have never run the thing they regulate.
WHAT A RULE CAN ACTUALLY REACH
Regulation works in three steps: find a party, impose an obligation, punish non-compliance. Every step needs an identifiable, reachable actor. A frontier lab with an API endpoint, an office and a pending IPO is reachable. A file of model weights sitting on ten thousand hard drives is not.
Look at what is actually on the books as of October 2026.
-
European Union. The AI Act’s general-purpose model obligations have applied since August 2025. In July 2026 the Digital Omnibus deferred high-risk obligations to December 2027 for standalone systems and August 2028 for embedded ones. Transparency and general-purpose enforcement stayed on 2nd August 2026. Part of the reason for the delay: the harmonised technical standards for high-risk compliance were still behind schedule.
-
Open source in the EU. Article 53(2) waives only two of four baseline obligations for genuinely open models. Copyright policy and training-content summaries still apply, and the waiver disappears entirely for models classed as systemic risk.
-
United States of America. There is no comprehensive federal AI law. Executive Order 14365, signed in December 2025, set up a Justice Department task force to challenge state AI laws. Six months later, 29 states had enacted 109 new AI statutes anyway. A bipartisan preemption bill exists only as a discussion draft, released in June and never formally introduced.
So, Europe regulates on a timeline that slips when its own standards bodies cannot keep up. The USA has fifty answers and a federal government litigating against its own states. Meanwhile, Epoch AI estimates that open-weight models trail the best closed models by roughly four months.
Every one of these instruments regulates providers and deployers: who ships what, and who uses it for what. None of them regulates the arithmetic. That distinction is the whole argument.
THE HARDWARE REALITY
Near-frontier AI now runs on a machine in the low thousands of dollars. Epoch AI estimates that a model matching the best of six to twelve months earlier runs on a single GPU costing under $2,500. Flagship-scale weights need a small rack, which any business can buy or rent. Neither needs anyone’s permission.
The distribution of open weights has already happened, and much of it comes from China. According to Hugging Face’s Spring 2026 report, Chinese-origin models took 41% of global open-weight downloads between February 2025 and February 2026, against 36.5% for US-origin models. Alibaba’s Qwen alone has 151,448 derivative models on the Hub, 2.6 times Meta’s footprint.
What it takes to run them, by size:
Moonshot’s Kimi K3, at 2.8 trillion parameters, had its full weights published on Hugging Face on 27 July 2026. The ceiling of what anyone can download keeps rising.
Our own inference server carries a 96 GB workstation GPU and roughly 190 GB of system memory. On it we run Qwen3.8-27B. Beside it sits a test sandbox with Moonshot’s Kimi-VL-A3B-Thinking, an MIT-licensed vision-language reasoning model with 16 billion parameters and about 3 billion active, and Meta’s Llama 3.1 8B. We use it for just about everything we do with AI - literally. The machine cost about $20,000, and it is far from the only way in.
Here is what far less money buys today. Framework’s Desktop is a 4.5-litre box built on AMD’s Ryzen AI Max chips, with up to 192 GB of memory shared between processor and graphics on a 256-bit bus. Framework publishes the models it recommends for each configuration. For comparison, the fastest consumer option is a desktop built around NVIDIA’s RTX 5090.
The trade-off is capacity against speed. The RTX 5090 moves data about seven times faster, so a model that fits in its 32 GB answers far sooner: one analysis puts Qwen3.8-27B at roughly 73 tokens per second on it. The Framework machines hold four to six times more, so they run models the 5090 cannot load at all. Large dense models are slow on them, which is why Framework recommends mixture-of-experts models, where only a fraction of the weights work on each token.
Two caveats keep this honest. Framework’s DIY prices exclude storage and an operating system, and all three AI Max 300 configurations were out of stock when we checked; the 192 GB model ships on pre-order from November. The global memory shortage has pushed prices up across the board. Even so, every other option in the table sits well under $20,000, and the cheapest runs a genuinely useful model for less than a decent laptop.
So what, exactly, is the regulation? A rule that binds the company selling access does not touch the files on our drives, or the next ten thousand copies of them.
CASE STUDY: ONE SWITCH, TWO WORLDS
In June 2026, a single regulatory action showed the asymmetry in practice. Hosted access is a switch someone can flip. Downloaded weights are not.
Anthropic released two models, Claude Fable 5 and Claude Mythos 5, on 9th June 2026. On 12th June it suspended access to both to comply with USA Department of Commerce export controls. Commerce lifted the controls on 30th June, and access returned on 1st July.
On the same 12th June, Moonshot AI released Kimi K2.7-Code, a one-trillion-parameter coding model, as open weights. Nobody could switch that off. It was on Hugging Face, and then on every machine that pulled it.
Whether those controls were justified is a separate debate, and a national-security one. The mechanical lesson stands either way:
-
The rule reached the most identifiable, most compliant provider, and its paying customers lost access for nearly three weeks.
-
It did not and could not reach weights already published by anyone else.
-
Every customer who depended on the switched-off service learned what self-hosting is for.
A control regime that can only touch the actors who play by its rules does not reduce capability in the world. It relocates it.
WHO BENEFITS
Follow the money and the answer is the incumbents. In the first half of 2026, eleven of the largest tech and AI firms and their trade groups spent a record of more than $41 million on USA federal lobbying. Anthropic nearly tripled its outlay to $3.53 million, and OpenAI roughly doubled to $2.22 million. Four years earlier, Anthropic, Nvidia and OpenAI had no federal lobbyists at all.
The incumbents do not agree on every rule. Anthropic and OpenAI backed opposing AI liability bills in Illinois. What they agree on is having a seat at the table where the rules get written.
Economists named this pattern long before AI. George Stigler’s 1971 theory of economic regulation argued that, as a rule, an industry acquires its regulation and shapes it for its own benefit, and that any industry with enough political power will use the state to control who gets to enter. The mechanism is simple arithmetic:
-
Compliance is a fixed cost: lawyers, audits, documentation, reporting.
-
Fixed costs are cheap per unit at scale and ruinous for a small shop.
-
So every new obligation widens the moat around whoever is already large.
When a frontier-lab CEO asks Congress for a licensing regime, as OpenAI’s Sam Altman did in Senate testimony in May 2023, ask who is best placed to hold the licence. It is not the two-person team fine-tuning Qwen for a regional hospital.
The pattern went public in July 2026, after Kimi K3. Axios reported that parts of the administration were weighing restrictions on Chinese open-weight models, and quoted a source describing leading labs or their allies approaching officials every few months with ideas to ban open-source models. The New York Times, citing five people close to the talks, reported that OpenAI and Anthropic had lobbied regulators to restrict Chinese open-weight models.
The rest of the industry answered in public. On 24th July, Nvidia, Microsoft, Meta, IBM and others published Open Weights and American AI Leadership, warning that concentrating AI behind a few closed models creates single points of failure and asking Washington to avoid premature restrictions. OpenAI and Google signed within days. Anthropic did not. Its CEO wrote on 27th July that the company has never advocated a ban on open-weights models, and called instead for chip export controls, action against industrial-scale distillation, and mandatory safety testing for all sufficiently capable models, open or closed.
Take each side at its word and the alignment is still hard to miss. The companies selling access to closed frontier models were the ones reported to be pressing for restrictions. The companies selling chips, clouds and platforms lined up to keep weights open. In both camps the policy position tracked the business model, which is exactly what Stigler would have predicted.
The beneficiaries are the incumbents, the consultancies that sell compliance, and, wherever public grants follow the rules, the institutions already large enough to win them. The losers are the small builders the rules were never written for.
WHAT HISTORY KEEPS TELLING US
Centralized systems tend to fail the same way: they add layers of control to solve each new problem until the control costs more than it returns. The anthropologist Joseph Tainter made this the core of The Collapse of Complex Societies (1988). Complexity is an investment, its returns diminish, and collapse is the rapid shedding of complexity a society can no longer afford.
Three episodes show the pattern:
-
Rome, third century. Emperors paid for armies and administration by steadily debasing the silver coinage until the standard coin was little more than bronze with a silver wash. Diocletian’s Edict on Maximum Prices in 301 capped prices on more than a thousand goods and threatened profiteers with death. It was patchily enforced, its caps were widely ignored, and by 305 it was effectively dead.
-
The Soviet planned economy. Central planners set prices and quotas for an economy too complex for any office to see. Friedrich Hayek explained why in 1945: the knowledge needed to run an economy is dispersed among millions of people, and open prices are how it gets aggregated. The system ended in 1991.
-
Price controls generally. From ancient Rome to modern rent caps, a rule that fixes an outcome without changing the underlying incentives produces shortages, black markets and evasion.
AI regulation faces Hayek’s knowledge problem in its most extreme form. The thing being regulated changes every few months. The rulebook takes years, and Europe’s own standards bodies could not finish the technical standards in time for the original deadline.
The lesson is not that every rule fails. It is that rules which try to control a fast, dispersed, open system from the center are the kind that fail fastest.
THE COMPREHENSION GAP
The deepest problem is not bad intent. It is that most of the people writing and debating these rules have never deployed the thing they are regulating.
Consider a basic question: who is “the provider” of a model? Of the 28,531 GGUF conversions of Qwen models on Hugging Face, Qwen itself published 54. The community did the rest. The EU’s answer is a compute test: a downstream modifier becomes a provider only if the modification uses more than one-third of the original model’s training compute, and the Commission expects few modifications to reach it.
Practitioners can see why that line misses. Lawyers at DLA Piper report fine-tunes that materially changed a model’s capabilities using nowhere near that much compute. The rule measures the effort spent, not what the model can now do.
Practitioners see things that do not show up in a hearing room:
-
A model is a file. Quantization, fine-tuning and merging produce new files in hours.
-
Capability does not live in one company. It lives in weights, inference engines and the people who know how to run them.
-
The value is in the application: document extraction, retrieval pipelines, domain-specific assistants built for one niche problem.
That last point is the real opportunity. AI pays off when it is adapted to bespoke, niche problems by people who understand both the tool and the domain. In other words: SOLUTIONS THAT ADD VALUE! Broad-brush, one-size-fits-all centralized and controlling regulatory frameworks never worked for anything relative to value add or low time preference, so there is no reason to think they will work here.
The fix for the comprehension gap is comprehension: literacy, hands-on experience and critical thinking, for citizens and policymakers alike.
THE ALTERNATIVE: ACCOUNTABILITY YOU CAN VERIFY
If regulation cannot reach the weights, accountability has to attach to something that can be reached: keys, signatures and money. Three open layers already do this, and they work together.
-
Identity and reputation (Nostr web of trust). On Nostr, every user is a public key and every follow is a signed event. Services such as Vertex compute personalized PageRank over that social graph and sign every answer, so a client can check it without trusting the host. Relatr scores trust from each user’s own perspective, and anyone can run an instance from a Docker container. Zapstore already uses this to verify app developers in a permissionless app store.
-
Provenance (signatures anchored to Bitcoin). A published model can be signed by its maker; the OpenSSF has a model-signing specification for exactly this, and every NVIDIA model in its NGC catalog has shipped with such a signature since March 2025. Media can carry signed C2PA content credentials. Anchoring those hashes to Bitcoin through OpenTimestamps proves what existed and who signed it, no later than a given block, on a ledger nobody can rewrite.
-
Economic cost (sats). Small Lightning payments make every identity and every action cost something. That makes it expensive to spin up thousands of fake accounts, which is the cheapest attack on any reputation system.
Together these give honest builders a portable, verifiable track record that no platform can revoke. A bad actor faces the opposite. A fresh key with no history carries no trust. An unsigned model or image carries no provenance. A record of past behavior follows the key.
This needs to be stated precisely. A ledger records events, not intent, and it does not unmask anyone by itself. Web-of-trust systems can be gamed, and the PGP web of trust that inspired them never reached mainstream use. The answer to both is design. Scores computed per perspective leave no single global ranking to capture. Sats raise the cost of manufacturing trust. Signatures make imitation detectable.
Bad actors rarely pioneer anything. They exploit rules that stand still. A static regulation is a fixed target that rewards whoever finds the loophole first. An adaptive, transparent system shrinks the room they have to operate, every day, without waiting for a legislature.
THE STRONGEST OBJECTION
The best case for regulation is not about market share. It is about harms that are severe, irreversible or inflicted on people who never chose to take part.
Its defenders would put it this way:
-
Catastrophic misuse. Capable models might give real help to someone trying to build a biological or chemical weapon. One such event outweighs every efficiency gain, and reputation systems only react after the fact.
-
Harm to third parties at scale. Non-consensual intimate imagery, child sexual abuse material and deepfake fraud victimize people outside any web of trust. The EU’s 2026 Omnibus added prohibitions, effective 2nd December 2026, that cover both systems built to generate this material and general systems that can foreseeably produce it without adequate safeguards.
-
Collective action. No single builder has a reason to slow down for safety. Only a rule binds everyone at once.
This is the hardest part of the debate, and it deserves a straight answer:
-
Conduct law already covers most of it. Fraud, extortion, abuse material and impersonation are crimes regardless of the tool used. The argument here is against licensing capability, not against prosecuting crime. Prohibitions aimed at a harmful use are the defensible kind of rule.
-
The EU’s provider-side ban crosses from conduct into design. Its deployer side punishes using a system to make abuse material, which is exactly the right target. Its provider side also bans general systems that can foreseeably produce such material without adequate safeguards. Any sufficiently capable image model can foreseeably do that, and once weights are released they are, as even the open-weights coalition’s own letter concedes, beyond the original developer’s control. If publishing open weights counts as placing a system on the market, the rule falls hardest on open release while doing nothing about weights already circulating. And “adequate” will be defined by whoever can afford the compliance department. That is a capability rule wearing a conduct label.
-
Capability rules miss the target they name. Weights already published cannot be recalled, as June 2026 showed. A rule that binds only compliant providers leaves the determined bad actor exactly where he was.
-
Provenance protects victims better than prohibition. When authentic media is signed and timestamped, a fake becomes something you can disprove, not just something you can complain about.
On catastrophic misuse, honesty requires conceding that the evidence is contested. Researchers disagree on how much real uplift today’s models provide, and that disagreement is not settled. The question for policy is which instrument actually reduces the risk: controls on materials, labs and skills that a weapon physically requires, or rules on software that is already everywhere.
WHAT NATION-STATES SHOULD ACTUALLY DO
A state that wants its people to benefit from AI should stop trying to control the capability and start building the conditions for honest use of it.
-
Enforce conduct, not permission. Prosecute fraud, abuse and impersonation vigorously, whatever tool was used. Drop licensing regimes for capability that cannot be enforced against anyone except the compliant.
-
Fund comprehension. Put public money into technical literacy, open infrastructure and shared compute, not into grants that flow to the firms already large enough to apply.
-
Adopt open provenance in government. Require signed, timestamped records for official media, procurement and public datasets. Lead by example rather than by mandate.
-
Put a sunset on every AI rule. A field that turns over every few months cannot be governed by rules written to last decades. Make every rule expire unless it is shown to work.
-
Compete on adaptability. A small state cannot out-regulate Brussels or Washington. It can out-adapt them by staying open, cheap and fast for builders who run their own infrastructure.
We will end up with two systems running side by side either way. One is centralized, permissioned and captured by the people it was meant to restrain. The other is open, decentralized and already beyond anyone’s reach.
The only real choice is whether we understand the second one well enough to make it honest. That is a matter of comprehension, not control.
Sources
Regulation
-
EU AI Act 2026: what actually changed — Process Excellence Network
-
EU AI Act vs. AI Omnibus — BigID
-
Digital AI Omnibus delays key deadlines, introduces new rules — Cooley
-
Commission guidelines on GPAI obligations — DLA Piper
-
State AI laws reach 109 amid Trump push — Model Diplomat
-
The federal AI moratorium and state-preemption fight — CASRAI
-
Statement on the directive to suspend Fable 5 and Mythos 5 access — Anthropic
Open models and hardware
-
Chinese AI models overtake US rivals — Tech Insider, citing the Hugging Face Spring 2026 report
-
Hugging Face Hub analysis: Chinese labs dominate largest open models — The AI Wire, summarizing Hugging Face
-
Open-source AI statistics 2026 — citing Epoch AI
-
Running local AI in 2026 — DWU Consulting
-
Local LLM hardware guide 2026 — PC Server & Parts
-
Framework Desktop — Framework
-
Choosing a Framework Desktop for local AI — Framework blog
-
Framework Desktop DIY configurator (AI Max 300) and pre-built configurator (AI Max PRO 400) — Framework, prices read 10 October 2026
-
Kimi K2.6: open-weight agent model — Verdent
-
Moonshot releases Kimi K2.7-Code — Noqta
-
Everything you need to know about Moonshot AI and Kimi K3 — Fast Company
-
Kimi-VL-A3B-Thinking model card — Hugging Face
Lobbying
-
Big Tech spends millions to buy influence, first half of 2026 — Issue One
-
Anthropic triples lobbying; OpenAI doubles — AI Weekly, citing the Financial Times
-
Big Tech’s $20M lobbying blitz — The Rundown
-
Overview of the first Senate hearing on AI oversight — Crowell & Moring
-
The secret Trump administration battle to fight Chinese AI — Axios
-
OpenAI and Anthropic lobby Washington to restrict Chinese open-weight AI — Implicator.ai, citing The New York Times
-
Open Weights and American AI Leadership — open letter, 24 July 2026
-
Our position on open-weights models — Anthropic
Decentralized accountability
-
Web of Trust — OpenSats
-
Pippellia: reputation without a kill switch — Trust Revolution
-
Signing ML artifacts — Coalition for Secure AI
-
C2PA — Coalition for Content Provenance and Authenticity
History and theory (books and papers)
Write a comment