Insights
Perspective10 min read

Code Is Cheap. Compute Is Sovereign.

Anyone can write an agent. Almost no one can power a frontier model. The fear of 'AI in the wrong hands' is real, but it is aimed at the wrong layer. The scarce, governable resource is not the code. It is the machine.

October 2, 2026
Code Is Cheap. Compute Is Sovereign.
Photo by Public domain (Wikimedia Commons) on Unsplash

There is a lot of talk right now about powerful AI falling into the wrong hands — guardrails, alignment, who is allowed to build an agent and who is allowed to turn the safety switches off. That debate matters. It is also incomplete.

The more durable question is not who wrote the model. It is who can run it at scale. The stack that actually decides capability runs from CPU to GPU to TPU to, eventually, quantum machines. Software diffuses; processing power does not. And that is how the contest is being managed — imperfectly, and in public.

The wrong layer of the fear

A capable agent is no longer a national-security secret. Open weights, fine-tuning, and tool-using agents have collapsed the cost of building something that looks intelligent. A small team can wire a model to email, a browser, a database, and a workflow in a weekend. The code is the easy part.

What that team cannot do is train, or cheaply serve, a system at the frontier. That takes clusters of advanced accelerators, high-bandwidth memory, advanced packaging, power, and the interconnect to make tens or hundreds of thousands of chips behave like one machine. Those inputs are physical. They show up on bills of lading, in fab output, and on a power grid. They can be counted, licensed, and — with enough political will — denied.

Researchers at the Centre for the Governance of AI put the logic cleanly: compute is detectable, excludable, and quantifiable. A model's weights can be copied; a chip cannot. That is why governments have spent the last four years trying to govern AI at the hardware layer rather than at the prompt layer.

What "access" actually means

The claim that China has full access to this stack is the part that needs correcting. China has deep access to talent, data, capital, and an industrial policy that treats compute as strategic infrastructure. It does not have open access to the leading American accelerators, or to the tools that make them. Extreme-ultraviolet lithography, advanced etch and deposition equipment, and U.S.-origin electronic design automation remain restricted. SMIC is still cut off from the kit required to close the process gap. After the Trump–Xi meetings in late September 2026, the White House kept advanced-chip and chipmaking controls out of the trade package entirely — negotiators treated them as security tools, not bargaining chips.

What China does have is a constrained, partly domestic, partly gray-market stack. Licensed, downgraded, and reviewed chips: Nvidia's China-specific H20 was pulled back under a license requirement in April 2025, and in January 2026 the Bureau of Industry and Security shifted certain H200- and MI325X-class chips from a presumption of denial to case-by-case review — only below set performance and memory-bandwidth thresholds, only with U.S. testing, only with a cap relative to U.S. sales, and only with end-use assurances. That is managed access, not open access. Beijing has also discouraged some of those purchases.

A domestic industry that is real and still behind: Huawei's Ascend line has taken a large share of China's AI-accelerator market as Nvidia's best chips stayed out, but Epoch AI's 2026 estimates put Huawei's total AI-compute output at under 4 percent of Nvidia's, and its best current chip at roughly half an H100 — a part that started shipping in 2022. Huawei's own chairman has said domestic demand already exceeds supply, which is why a full export push for Ascend is on hold. DeepSeek's reported plan for 160,000 Ascend chips in Inner Mongolia is a sign of the pivot, not of parity.

Then there is leakage and efficiency. Smuggling, cloud rentals, and pre-control stockpiles of high-bandwidth memory have all blunted the rules — export controls slow a program, they do not seal it. And DeepSeek already showed that a disciplined lab can reach near-frontier results on less hardware. Every gain in algorithmic efficiency weakens a pure chip embargo; it does not erase it. Training the next step up still wants more machines, more memory, and more electricity.

How it is managed

Four levers are doing the work, and none of them is a safety filter inside a chatbot. First, export controls on chips, tools, and know-how: the Commerce Department's advanced-computing rules, the Entity List, and restrictions on lithography and design software are the main fence, with allied versions in Europe, Japan, the Netherlands, and South Korea. They are coordinated, not identical — which is where diversion starts.

Second, cloud and end-use rules: denying a box is not enough if the same box can be rented, so licensing conditions now reach remote access and infrastructure-as-a-service, and 2026 guidance extended license duties to China-headquartered firms even when the buying entity sits outside China. Third, capital controls: outbound-investment rules restrict U.S. money flowing into sensitive Chinese AI, semiconductor, supercomputing, and quantum activity, while CFIUS runs the inbound side.

Fourth, quantum as a separate track. Quantum is not yet the engine training large language models; it is a parallel contest — cryptography, sensing, simulation — and it already has its own controls. Since 2024, certain quantum computers above defined qubit and error-rate thresholds need a U.S. license, along with key components, and those rules have not been rewritten as of late 2026.

The next constraint is not another chip logo. It is power. Frontier clusters are now gated by fab capacity, advanced packaging, high-bandwidth memory, and grid interconnection. A country can have the model and still be unable to turn it on.

What this means if you build

If you are shipping agents, assume the model layer will keep getting cheaper and more widely available — and do not assume the same about the cluster underneath it. The advantage that lasts is access to reliable compute, energy, and a supply chain that is not one licensing decision away from a halt.

If you are watching the geopolitics, watch the performance thresholds, not the press releases. Case-by-case licenses for last-generation accelerators are a commercial adjustment. The fence around leading-edge chips, the tools that make them, and the cloud paths around them is the actual policy. It is leaky. It is also the only control point that has held.

The fear of a powerful system in the wrong hands is not irrational. It is just late. By the time the weights exist, the decision was already made — in a fab, in a licensing office, and on a substation. Code is cheap. Compute is sovereign.

Interactive Intel helps SMEs and modern healthcare practices identify, deploy, and optimize AI agents that pay for themselves. Get your AI readiness score in five minutes, or find where AI pays back fastest with a fixed-price AI Opportunity Scan.