The summer of 2026 will be remembered as the moment the world woke up to both the possibilities and perils of AI. As we move towards a world of rogue agents, secret message boards, alignment battles, and ever more powerful AI systems, researchers at third-party AI safety organizations have emerged as heroes.
These organizations work to secure a safe and aligned future. They toil with limited resources, with infrastructure they do not themselves control, and with no small amount of existential dread.
Safety organizations need control of their own compute; a critical input to experimental AI safety. Their work already faces short timelines (both kinds), limited data access and rules around model use. Safety compute should be owned by, and answerable to, the safety organizations using it.
We should always have the compute to finish asking difficult questions. We should always find the compute to do inconvenient, unwelcome, or expensive research. We should always have enough compute to reproduce worrying results, verify findings, and find the answers we all collectively rely upon.
Independent safety organizations should work collectively to own serious amounts of compute, dedicated to safety and safety alone. The infrastructure to investigate powerful AI should be built alongside the infrastructure that creates it. The time is now to build sovereign safety compute alongside a permanent engineering team to run these clusters.
Understanding dangerous capabilities, deception, and failures of control needs infrastructure governed by the organizations pursuing those questions, just as labs need their compute to continue to build AI capability.
Without sovereign safety compute, these organizations remain exposed to spot rental prices, the commercial priorities of chipmakers, and the largesse of the very labs that they investigate. Access conditions determine which questions get pursued, for how long, and whether the results can be public. These rules are detrimental to the goals of AI safety, and we can secure a base of independent capacity by breaking ground on dedicated sovereign AI safety clusters.
organization proposal
I propose a not-for-profit organization whose members are independent safety organizations. These organizations elect a board, own their assets collectively through the institution, and hire a team of engineers to operate clusters dedicated to safety. Governments, frontier labs, and suppliers can contribute but will never receive ownership or votes. I have already proposed one such cluster in Singapore for open models; others in the U.S., mainland China and the EU should be built.
This is what sovereignty should mean for safety: the organizations doing the work control the capacity to pursue it. The charter must protect investigations and publication from donor vetoes, and contributions from model developers must confer no authority over the research agenda. Members keep their independence while sharing an institution strong enough to support their compute needs for the coming years.
The cluster engineers should work for that whole community, making experiments run faster and turning improvements and innovations gleaned from one project into tools available to the next. Shared eval environments, datasets, and interpretability tools are becoming more common in this field; compute is next.
Together AI and Y Combinator have already built a dedicated compute offering for YC companies. Safety organizations should organize shared capacity with collective ownership at its foundation.
Rental bills pay for hardware, the people running it, and a return to its owners. Safety organizations should be those owners. When useful machines keep working, the benefit should stay with the researchers using them.
For 5,000 B200s used 75% of the time, an illustrative five-year comparison puts buying and running the fleet at about $605 million, against $1.1 billion at a published on-demand rental rate. Nearly half a billion dollars saved if the fleet stays useful for five years and that rental price holds flat, even using retail hardware prices and funding the engineers, maintenance and confidentiality the work needs. That is money for more safety research, with the machines under the organizations’ control. We should turn rental bills the ecosystem already pays into infrastructure it collectively owns.
the freedom to keep investigating
Sovereignty buys time to follow evidence. It lets organizations plan difficult research programs knowing that essential capacity is secure.
It also reduces exposure to rising compute prices. CoreWeave reported an approximately 25% price increase in July alone. Safety organizations should secure capacity they can keep operating through shocks like that.
An owned cluster, with funded operations, provides capacity to keep working through rental price shocks, through lab donation freeze-outs, and through difficult funding environments.
During the Hugging Face incident, commercial AI services blocked parts of the team’s forensic analysis. The defenders turned to an open-weight model running on their own infrastructure. They needed to investigate an attack, and the tools they first reached for would not let them. Safety researchers should have that independent capacity ready before they need it.
The same institution can also provide other useful services like confidential computing, so sensitive investigations can draw from shared security expertise. Researchers need protected environments for their inputs, and they need the right to report what they discover without fear of losing access to the compute that they require.
The time is now to secure sovereign safety compute; the ecosystem will gain independence, save money, hold labs accountable, and sustain the essential work they do every day.
Manifestos Need Demands!
Safety organizations: become the founding owners. Commit workloads, set the research mission and give the common engineering team a mandate to improve how the field uses compute.
Frontier lab support: no matter where the lab is based, a sovereign compute cluster will help safeguard a safer AI future. Commit to assisting the safety organizations that you need most.
NVIDIA, AMD and other chipmakers: help build this through hardware donations, substantial discounts, dependable supply and engineering support. Give independent scrutiny of AI a durable place in the infrastructure your industry is creating.
Cluster builders and operators: bring costed proposals for thousands of accelerators owned by the safety organizations using them. Commit the people and expertise to make the service dependable.
LessWrong readers and mechanism designers: propose a simple, fair system for sharing this capacity, with room for urgent investigations, smaller organizations and independent replication.
Governments and host communities: offer deep tax incentives and infrastructure support. Come forward with a site plan, a power supply and a credible timetable.
Funders: turn recurring rental grants into collectively owned capacity. Finance hardware, engineers, operations and renewal with commitments that outlast a grant cycle.
Public support: if you believe in sovereign safety compute, share this in the groupchat, write a version of your own, and talk to your friends in AI about it.
sources & notes (AI generated)
Hugging Face. Disclosure and technical timeline describe local forensic analysis. Ownership does not itself establish security. The opening reflects the author’s judgment.
Singapore. Pacific Compute and earlier APSCI proposal. These are proposals, not commitments by named parties.
Shared infrastructure. Together/YC establishes pooled access, not ownership. Gemma Scope supplies shared interpretability tools.
Rent versus own. Illustrative, pre-tax USD scenario; prices checked September 7, 2026. Five years at 75% use yields 164.25M GPU-hours. At Lambda’s $6.69/hour, held flat, rental costs $1,098.83M. Ownership: $408.25M upfront + 5 × $38.342M operations + $5M exit = $604.96M; saving $493.87M. Capital: 625 eight-GPU servers at $440,000; $30M fabric; $20M storage; $20M fit-out; $10M confidential integration; $53.25M contingency. Annual costs: $11.342M power, $8M engineers, $2M security, $6M hosting, $8M maintenance, $3M administration/other. Power assumes 13.488MW peak, 80% average draw and $0.12/kWh. Budget assumptions: five-year fleet life, leased facilities, no discounts; excludes new-campus construction, taxes and financing. Nebius spot at $3.95 and CoreWeave spot at $4.26375 yield $44M–$95M cash savings. At 8% discounting, both favor rental; the on-demand ownership saving is $313M. Early replacement adds $285M, reducing on-demand cash savings to $209M. CoreWeave’s linked contract economics describe operating margins, not net profit.
Repricing. CoreWeave, August 11, p. 7: approximately 25% across offerings in July. Fixed reservations also hedge prices; owned operating costs can rise.
Confidential computing. NVIDIA threat model and key release. Protection requires a supported stack; research and publication rights require agreements.
Provenance. Caithrin rewrote a Codex-assisted draft. Codex contributed research, models and editorial refinements; OpenAI generated the illustration.


