Loading lesson…
If you sell cloud GPUs, the US government may soon require you to verify who your customers are. Know-your-customer rules from finance are being ported into AI infrastructure.
In January 2024, the US Department of Commerce released a notice of proposed rulemaking requiring US Infrastructure-as-a-Service providers — AWS, Google Cloud, Microsoft Azure, Lambda, CoreWeave, and others — to verify foreign customers' identities and report large AI training runs. The rule was finalized in January 2025 as the IaaS rule.
If you can buy unlimited compute anonymously, no frontier model regulation is enforceable.
— Common argument in export-control policy circles
The big idea: governments are treating compute like a strategic resource on par with uranium or semiconductors. Expect the rules to keep tightening and keep changing.
15 questions · take it digitally for instant feedback at tendril.neural-forge.io/learn/quiz/end-safety2-kyc-ai-labs-creators
Under the IaaS rule, what specific information must foreign customers provide to verify their identity when opening new accounts?
For how long must IaaS providers retain customer records under the finalized rule?
What does the acronym CIP stand for in the context of the IaaS rule?
Which entity issued the proposed rule that eventually became the IaaS rule?
When was the IaaS rule officially finalized?
What is a primary criticism of the IaaS rule raised by opponents?
How could a customer potentially circumvent reporting requirements under the rule?
The IaaS rule ports an existing framework from which industry to AI compute?
What is the stated rationale for treating compute as a regulated resource?
Which of the following is explicitly required to be reported under the IaaS rule?
The lesson draws an analogy comparing compute to what traditional strategic resource?
Which hardware components are specifically restricted under the broader US export control regime mentioned in the lesson?
What concern do privacy and civil liberties advocates raise about the IaaS rule?
The quote 'If you can buy unlimited compute anonymously, no frontier model regulation is enforceable' emphasizes what point?
What is required annually under the IaaS rule?