Nonfiction

Two Regulators Propose Treating Model Weights Like Critical Infrastructure

Draft rules under review in two jurisdictions would classify the trained weights of the largest models alongside power grids and telecom networks — with reporting, access-control, and incident-disclosure requirements to match.

Draft regulatory proposals under review in two jurisdictions this month would formally classify the weights of the largest trained models — the numerical parameters that constitute a model, as distinct from the code that runs it — as a category of critical infrastructure, alongside power generation, telecommunications, and financial clearing systems.

The classification, if adopted, would carry practical obligations well beyond the label. Organizations training or hosting models above a compute threshold would be required to report certain security incidents within fixed windows, maintain audited access logs for who can export or copy weight files, and in one draft, notify a regulator before certain classes of model are made available for download outside the organization's own infrastructure.

Supporters frame the move as catching up to reality rather than imposing something new. "We already treat the electrical grid's control systems as critical infrastructure because of what happens if they're compromised, not because of what they're made of," said one policy researcher who has reviewed both drafts. "The argument here is the same: it's about consequence, not category. If a sufficiently capable model's weights leak or are stolen, the downstream effects can look a lot more like a critical infrastructure incident than a normal data breach."

Critics, including several industry groups, argue the comparison doesn't hold up structurally. Power grids and telecom networks are physical systems with well-understood failure modes accumulated over a century of engineering practice; model weights are a comparatively new artifact, and there is no settled methodology yet for what "securing" them should even mean beyond conventional access control and encryption at rest. Others worry the compliance burden will fall hardest on smaller labs and open-weight projects that lack dedicated compliance staff, entrenching the largest incumbents further.

There is also a definitional problem neither draft fully resolves: what, precisely, counts as a covered model. Both proposals use a compute-based threshold for the training run that produced the weights, a proxy that has been criticized in earlier AI governance debates for being simultaneously too blunt — it doesn't distinguish between a model's actual capabilities or deployment context — and too easy to route around as training becomes more compute-efficient over time.

Neither proposal is close to final. Both are in early public comment periods, and comparable drafts have stalled at this stage before, sometimes for years. But the fact that two regulators arrived at a similar framing independently — using the same infrastructure comparison, if not the same thresholds — suggests the idea has more momentum than any single draft's odds of passing would indicate on its own. Whether "critical infrastructure" turns out to be the right conceptual bucket for model weights, or just the closest existing bucket regulators had on hand, is likely to be argued out in public comments over the coming months.