You're pledging to donate if the project hits its minimum goal and gets approved. If not, your funds will be returned.
Problem: The Philippines is currently negotiating a governance framework for the first physical hub of the US AI supply chain coalition Pax Silica. These negotiations are slated to finish sometime near the end of 2026. The negotiations are gridlocked, several senate inquiries are active, and the Senate record indicates the hub is projected to host 3 GW of datacenter compute. Our review found several salient issues with their regulatory infrastructure, namely an inability to classify frontier compute (using a 64bit FLOP metric which puts a B200 at a score of 12, compared to the legal threshold of 70, making it ineffective), and a catch all provision which would extend to inspection powers over compute - but currently only is scoped for WMDs. This is incredibly tractable, fixable by bureaucratic actions rather than legislation.
Why it matters: Compute is the most governable input for frontier AI, and several proposals in the field (registries and consolidation, on site verification, or a US-China agreement) rely on domestic regulatory capacity, even in middle powers. The Philippines is quickly becoming the weakest link in Southeast Asia, a major chip smuggling and diversion hub. As the first Pax Silica hub, it also sets precedents for future signatories (Argentina, Chile, Kazakhstan and Panama). Closing the gaps in it’s regulatory infrastructure stop bad actors from utilizing an under regulated hub to accumulate compute and increase their threat uplift, creates the capacity to implement proposals the AIS field has generated, and adds - along with creating a precedent for - friction that moves the threshold for a US-China deal. There are no AI safety organizations in the region working on this.
How we solve it: With our existing legislative connections and presence, we plan to complete a full audit of the nation's regulatory infrastructure for AI by mid-October, and run technocratic interventions (non-partisan information delivery) with relevant bodies through the end of November. We’re asking for between $10,000 to $50,000 for this work (ideal ask: 30,000). This proposal is time bounded, with completion by the 30th of November
Safe AI Philippines (SAIPH) is one of the Philippines’ first dedicated AI safety orgs driven to build the country’s long-term governance capacity via talent development, community building, and institutional engagement. Mainly, SAIPH runs career accelerators to train talented individuals and help them pivot their career into AI safety. Graduates of their accelerator programs have gone on to publish their writing in local newspapers and collaborate with think tanks and government agencies, with one fellow entering the term “catastrophic AI risk” for the first time in a House Resolution in Congress. At the present, SAIPH is one of the 10 civil society organizations functioning as technical advisors to the Philippine House of Representatives Technical Working Group on the AI Development and Regulation Act. Involved: Lenz Dagohoy, Lexley Villasis, Bernice Danielle Castillo, and Fiel Aquino
Youth for Responsible Innovation is a youth-led policy organization working on neglected, tractable AI governance problems in APAC middle powers. Our track record maps onto this work incredibly well: we've consulted on AI legislation in Malaysia and the Thailand - developing an ongoing relationship with Malaysia's NAIO and Thailand's EDTA in the process; briefed Singaporean MPs and our Ministry for Digital Development and Information on various risks from frontier AI; and co-drafted parliamentary questions with Opposition MPs on loss-of-control post Hugging Face. Involved: Vir Khosla
We’re looking for between $10,000 and $50,000 for this work, with an ideal funding amount of $30,000. The exact funding amounts are clearly broken down in this sheet, but essentially after fixed costs of $2,500 for domestic transport and meetings with relevant offices, the rest is allocated to funding members of our volunteer organizations to allocate more hours towards this project. As a result, the scope of our audit and amount of interventions we can run will scale with the amount of funding we receive. [This work is not political lobbying, and falls under the safe harbor exemption for providing information to governments, expanded on later].
The US-Philippines framework for the first physical Pax Silica hub will conclude around the end of 2026. The negotiations have been fraught with conflict: there is domestic pushback due to environmental concerns, individuals currently residing on land segmented for the special economic zone, and a rejection of the US attempt to gain jurisdiction over the land.
Political legislators are currently enquiring into the capacity of the nation's regulatory systems to hold up against the increased strain—indicating that the political will for updates exists. We’ve identified multiple active legislative inquiries / senate resolutions enquiring into these matters, with comparatively little or non-existent AI-safety scoped responses. This also demonstrates how neglected the region is: there are no major AI safety organizations currently working on shaping how the Pax Silica negotiations go, nor creating the regulatory capacity required for the nation to handle it.
Moreover, it seems as the Philippines scales its compute inflows while prior hub nations for chip smuggling (Singapore and Malaysia) tighten up their regimes, the Philippines becomes more of a viable candidate for diversion.
Since the Philippines is the first planned physical hub, it acts as a blueprint and case study for all future iterations of what this deal looks like. This means that the scale of our impact is significantly amplified: one interaction is able to scale to several nations. These interventions are, therefore, able to set a precedent that shapes bloc dynamics.
Second, through SafeAI Philippines and a variety of individual connections, we have existing legislative connections which significantly increases the confidence and subjective credence of our ToC. Reducing the legislative friction means that we can create impact more efficiently, but also do it far less expensively. We create a significant amount of legislative impact that also becomes a point of reference for a future bloc, at an incredibly low cost.
Third, regional alternatives are not strong contenders. Singapore has incredibly strong regulatory infrastructure and high talent concentration, limiting the efficacy and exigence of interventions. In Malaysia, corporate incentives have ossified far more - at least anecdotally from conversations with their AI Berhad (previously National AI Office). The pathway to impact is not that clear. The same goes for Vietnam, where there is no catalyzing event occuring: the political will to update legislation, the current large infrastructure project that makes it a contender for diversion, etc — all lead us to identify the Philippines as an important and tractable choice.
The context of the Philippines we identified, as well as the active legislative enquiries into their regulatory infrastructure, led our team to run a cursory exploration of certain pieces of legislation. From this initial review, we found several concerning issues. Namely:
The Philippine strategic goods list (NSGL Annex 2) uses a 64 bit floating point metric as a litmus for what compute it should control. This metric is incredibly archaic, inherited from the Wassenaar Arrangement (established in 1996), and has GPUs weighted at 0.3. This is incapable of dealing with frontier compute. This is even more clear when we place this in context: a H100 would be at roughly 20 with a threshold of 70. A B200 (which is several times more capable for AI) would score roughly 12, because it trades 64-bit performance for low-precision throughput. Not only is this metric incorrect for current forms of compute, it seems to be less of an indicator as compute evolves
Their catch-all (Republic Act No. 10697) is only written for weapons of mass destruction, and thus is not scoped to handle frontier compute and diversion potential. Malaysia, on the contrary, expanded their catch-all definition to include suspected AI chip diversion in July of last year.
The pattern with these issues, and other similar ones we identified, is fixing them would not require new legislation. Since the nation's Annex 3 is domestic, the cabinet committee that maintains it (NSC-STMCom) is able to unilaterally add entries and the licensing office (STMO) can implement it by memorandum circular. This means that our outlined approach of technocratic interventions would be sufficient, without requiring partisan involvement or lobbying.
Complete a comprehensive audit of the nation's regulatory infrastructure.
The two, fairly salient, issues above came from a quick readthrough by a single individual. A comprehensive review of the nation's regulatory infrastructure seems likely to reveal more potential areas for improvement. Although, in order to identify the potential areas for improvement, we’d need to complete the research, our initial walkthrough points us to 5 contenders:
Inspection. The STMO already has statutory authority to enter premises for end-use checks, but this only applies to strategic goods. Since AI chips aren't on the list, the inspection power does not apply. Fixing the strategic goods list would extend it, without a new law. This also evidences that these pieces are a causal and interdependent structure rather than disparate interventions - a single fix has compounding effects.
The border. There is no specific heading for an AI accelerator, just GPU’s, ergo an H100 would declare under the same heading as a gaming GPU. At customs, there is a lack of insight and understanding of the nation's own chip inflows and outflows.
A registry. Several proposals for multinational AI governance rely on the capacity to know where chips and clusters are. Since the BCDA is an investment promotion agency, every enterprise receiving incentives has to file an annual report. Increasing the scope of this to include the amount of compute held gives the government that information
The “consent gates”. The Philippines has lots of these: incentive registration conditions, local government approval, environmental compliance, indigenous consent if ancestral domain is implicated , and Senate concurrence if the framework turns out to be a treaty. They significantly underindex AI specifics; significant questions (what gets installed, by who, under which jurisdiction) are unanswered.
Our near term output goal would be collating all of these research contenders into a series of deliverables, comprehensible by relevant technocrats, as well as potentially published in domestic newspapers to buttress legitimacy.
Begin running technocratic interventions with each body
The cause behind the flaws we’ve identified doesn’t seem to be a lack of political will or exigence. The Special Goods List, for instance, was updated in May 2023, but missed the categories that the US created in October 2022. This means that the bureaucracy is interested in keeping these lists relevant; the bottleneck is an information deficit. Interventions 1 to 4 (preliminary list before full audit is completed, subject to change) will be delivered in the form of providing information to relevant technocratic and legislative bodies through direct briefings, papers, and support while drafting relevant updates. This is distinct from lobbying - we do not support or engage with partisan efforts to pass legislation or get specific candidates elected.
*Note For Funders: This is an activity that is therefore exempt from 501(c)(3) restrictions on lobbying, qualifying under the IRS statutory safe harbors for nonpartisan analysis and technical assistance under Internal Revenue Code Section 4911.
With that in mind, we plan to run the following interventions:
What Does Success Look Like?
Intervention 1: The Strategic Goods List: For STMO and the cabinet committee (NSC-STMCom) capable of independently updating the Annex’s and strategic / dual use goods lists, we’d brief them on the current shortcomings of their metrics, draft an Annex 3 implementation classifying AI accelerators by referencing their manufacturer classification codes (drawing from Malaysia's design, meaning that precedent lends us credence). We would also draft out the implementing memorandum circular. The office has a version of it from 2021 that we could reference (MC 21-37).
Impact 1: The Philippines now has the ability to legally define what an AI accelerator / frontier compute is. The Strategic Trade Management Act’s purview now extends to an updated definition of the hardware: exports, re-exports, transit, and transshipments are now actions that require the STMO’s authorization. Shipments can now be held at the border, and unlawfully moving accelerators without the correct authorization becomes an offence (under RA 10697). Since these chips are classified by referencing manufacturer codes, this metric stays up to date.
Intervention 2: Border Identification: For STMO and Customs, we’d brief them on the issues with the current demarcation program, as well as drafting an identification mechanism through something like manufacturer verification, bypassing the need for Customs to physically check the chips.
Impact 2: Customs agencies can now distinguish frontier compute from consumer hardware at the border. This doesn’t require actually opening or inspecting these items, and the nations inflows and outflows are now enumerable.
Intervention 3: Inspection Powers Intervention 1 means that AI chips now fall under a category that means they’re inspectable on premise. We’d brief the relevant offices and bodies of the new capabilities, as well as providing references to how it has been used in the past, and mapping their regulatory capabilities to those set out by middle-power governance research plans
Impact 3: The STMO can now enter AI-hosting premises for comprehensive inspections. There is a mechanism to verify whether chips are where they’re stated to be, meaning they gain the physical prerequisite to verification regimes without passing a new law.
Intervention 4: A Registry We’d brief the BCDA and FIRB on conditions for registering / updating information on compute disclosure, end user changes, etc as additional criterion within their existing annual reports mandatory for enterprises.
Impact 4: The state, and the AIS community writ large, has access to a record of who in the nation has accumulated compute, and is updated if the ownership of that compute changes.
[Outside Scope] Intervention 5: Create position papers, reports, and other material for legislators on negotiation terms for Pax Silica The negotiation is sealed - there is comparatively little information available. The main public position so far is that US law won't govern the zone. MAP (the main business association) has openly called for treating this as "a strategic negotiation" with sovereignty protections. Still, it remains unclear what is being negotiated for. Nobody explicitly knows what a host’s terms should truly look like for an emerging asset like this. Some precedent exists in other sectors: mining production sharing agreements (with features like output allocation, stabilisation), EDCA (access and inspection language), the Gulf compute deals (reciprocity). We’d utilize political standing, reputation, and connections built through the previous initiative as a mechanism to deliver further work. Writing a terms sheet or briefing politicians on 8-10 asks.
Impact 5: Negotiators now come to the table with informed, drafted asks and a nuanced perspective on their comparative position. Negotiated terms now are mutually beneficial, and protect salient rights like continued access, reciprocity, etc.
We hope to, given funding, complete our full audit by end September to mid October. From then, we’ll begin our interventions, aiming to complete those and achieve our stated impacts by the end of November.
Compute is the most governable input to frontier AI: unlike data or algorithms it is detectable, excludable, and quantifiable, and its supply chain runs through a handful of chokepoints. Most governance proposals (registries, KYC rules for cloud, on-chip/hardware security, verified
international agreements) assume a certain level of domestic capacity. These proposals, however, are often written for great powers, and do not consider the nations this hardware is forced to physically pass through. Our interventions build that capacity, and help AI safety through three crucial mechanisms: stopping bad actors from accumulating compute, enabling existing proposals that the field has already created, and moving the threshold for a US-China agreement.
Our interventions stop bad actors from accumulating compute through a “hub” nation with weak regulatory infrastructure
In peacetime, export controls are the primary tool for slowing dangerous concentrations of compute. However, these export controls often fail in hub or passthrough nations. Current estimates have chips diverted to China in 2024 at around 140,000, yet no clear or certain figure exists (CNAS, IAPS, Epoch AI). Southeast Asia seems to be the primary corridor facilitating this chip smuggling. Singapore is currently litigating a US$390 million server-fraud case with Nvidia hardware routed through Malaysia. Yet, these regions are responding by strengthening their regulatory infrastructure: Malaysia implemented a permit regime on AI-chip transit in July 2025. As Malaysia and Singapore continue to tighten their regulations, we’re able to draw a stark contrast to the Philippines - where smuggling chips is only somewhat classified as an offense. Bad actors are able to utilize these weaker hubs to accumulate greater amounts of compute, increasing threat uplift. As the Philippines opens a hub, this capacity scales and begins to pose a more salient risk - especially as Senate records show this hub is intended to host datacenters with a projected demand of three gigawatts (PSR 547 and PSR 563).
Intervention 1 allows the state to classify what an AI chip is, which turns chip smuggling or diversion through the nation into an offence. Intervention 2 allows these inflows to be quantifiable, acting as an early warning signal before bad actors are able to accumulate significant amounts of compute. Intervention 4 hedges for this risk in the long term, as salient risks may not be instantly apparent, but rather be a result of long term backsliding (ie the ownership of a shell company changing hands). We’re able to close the next diversion hub, or make it far more costly and transparent.
It gives the country the capacity to run pre-existing proposals ideated by the AIS governance field. Compute governance proposals consist of a few broad and recurring strategies or themes. We identify the following:
Cloud providers acting as verifiers (Heim, Fist, Egan et al, 2024)
On-chip hardware mechanisms for security and location governance (CNAS, 2024)
Layered and multi-stage verification for international rules on large-scale AI (Wasil et al, 2025)
A proposed agreement between the US and China verified by tracking chips through production/distribution and usage (MIRI, 2025)
These, to varying extents, presuppose or require a certain level of international regulatory capacity to be efficacious. At the end of the day, verification is to a incredibly large degree physical. Intervention 3 gives officers the lawful authority to ensure that chips are where they're meant to be. This is particularly important, as any future US-China agreement that attempts to restrict frontier compute will be reliant on people counting chips in middle powers - a capacity that at present is severely limited. Intervention 4 builds the national capacity for an "international AI chip registry" that appears in several proposals. It seems that these international registries are best created as a sum of national registries, yet they do not exist to a meaningful degree yet. We’d change that, building the capacities these proposals presuppose and therefore being a foundational necessity to realize their outcomes.
This pushes back the threshold for a US-China deal
Diffusing power across multi-agent systems of nations (especially when these agents have differing incentive sets) leads to better mean outcomes and a greater tail risk reduction. This contrasts systems where power is more concentrated in fewer agents (especially when those agents have the same accelerationist incentive sets) - this looks like US-China "race" dynamics.
Insofar as middle powers will not have the same incentive sets as labs hosting frontier labs, when external concerns outweigh their own potential economic gain (which is a far lower threshold), they begin to apply pressure and create friction. Middle powers form blocs that are asymmetrically exposed to AI. This resistance and friction creates a geopolitical climate that is amenable to a greater amount of international cooperation, and the implementation of more meaningful controls. Their incentives better align with an equitable, governed, slow buildout that gives their institutions ample time to adapt.
Conditional hosting and manufacturing everywhere make the race slower and costlier for both sides. It, to some degree, makes a deal the cheaper option, pushing the threshold of political will required back.
Moreover, agreements are signed in the small window occurring right after an incident creates an opportunity. I'd look to the Geneva test ban talks as an example of this. In four years, they produced no treaties, yet after the Cuban Missile Crisis, the Partial Test Ban Treaty was signed in ten months. This "warning shot" converted into tangible outcomes because of a geopolitical environment that made the deal amenable, but more saliently, had done the hard work of producing the institutions, processes, and leverage to execute.
In terms of position, middle powers are indeed able to do this. The Philippines have already rejected US law governance for a special economic zone without entirely ending the negotiation. Malaysia has run its own permit regime on the transit of AI chips. [Malaysia Introduces New Export Control Directive for Advanced AI Chips] When Washington pushed equipment controls in 2022, neither the Netherlands nor Japan adopted its rules. Finally, the magnitude of impact here is greatly increased when middle power nations, instead of applying friction independently, do it as a bloc.
See more detailed reasoning on this ToC in this appendix on middle power governance
Counterfactual Mapping:
Branch 1: There are no regulatory changes made in the near-term (high subjective credence)
Bureaucratic regimes are often incredibly inert and slow moving without external pressure. In Branch 2, we explain why this external pressure is unlikely to exist. Even if this “pressure” exists, if it is not paired with significant technocratic interventions and briefings, the information deficit is likely to persist, and change is likely to fail (like the May 2023 update of the Strategic Goods list, which failed to update compute metrics, even though that had become the international standard).
In short, this regulatory gap is likely to exist, at least in the near term. Given rapidly accelerating AI timelines, this seems incredibly harmful: bad actors are able to accumulate compute, increasing their potential threat uplift. Existing proposals are bottlenecked by regulatory capacity on ground, meaning that their implementation (especially globally) is slower than it could be.
Branch 2: This gap gets filled by another institution (low subjective credence)
We believe this is incredibly unlikely, given the region's significant neglectedness. There are no other alternative established domestic institutions with the technical know-how or AI safety context to deliver these interventions in a time-sensitive and efficacious manner. Although there are Western institutions with the technical knowledge, we identify three barriers to this. The first, regional context, is essential to targeting interventions in a political system that is not as clear cut. Moreover, active connections and legislative inclusion is a prerequisite to compelling inert bureaucracies to move. Finally, they just seem unlikely to engage with this as a whole; CSET, IAPS, and the like write for Western contexts - them pivoting to responding to PH Senate Inquiries and drafting domestic memorandum circulars feels unlikely.
Acceleration. Does making the Philippines a more credible host increases the buildout, thereby accelerating scaling? We take this objection fairly seriously, because this is a prima facie version of the qualification argument we use to convince legislators or technocrats to update their regulations (control capacity is what a trusted host has; Malaysia's permit regime is why its chip trade functions) and also the argument we use as to why they can create friction.
Can both be true? They can, at different levels. Total buildout is a function of capital outlays, demand and US policy. It isn’t a function of Philippine regulatory capacity - our final demand can, at most, increase the Philippines share of a fixed demand. A credible host may win a larger share of the governed flow.Yet, at the system level, conditional hosting everywhere raises the cost of the race. The net impact of this on total compute, then is small, and plausibly negative. Concurrently, the net impact on visible compute that can be a vessel for friction is large and positive.
A version of this project that more clearly accelerates is by creating a “paper tiger” - giving a false sense of legitimacy without actual constraints. An empowered government that is able to assuage its concerns, without truly increasing visibility or friction, would feasibly lead to a greater share of compute going to a host that doesn’t govern it. Either way, this doesn’t seem to impact the demand. This is why we focus on technocratic interventions instead of partisan lobbying or grassroots political capital building.
Killing the SEZ. Opponents of the zone could use our analysis to kill it outright. This is unlikely, but hypothetically possible. If it happens, the hub simply shifts locations to a new nation, with similarly incapable regulatory infrastructure. A similar intervention would be possible there, and it might work. Regardless, the counterfactual harm here doesn't really manifest, without our intervention, these two circumstances would be equal. Moreover, the analysis and technocratic interventions are focused on the relevant agencies (not opposition to Pax Silica in and of itself).
The same response is apt for displacement, where hard regulations make the datacenters/compute move to a more accommodating host. There is no comparative, as there are no tangible harms when the unregulated compute is hosted in one country or another.
The cost here makes this fairly unfeasible - but even then, this is not a world that is worse than a counterfactual without this intervention.
Capture after 2028. Elections could instate a Beijing-leaning government, which would inherit a registry of compute and inspection power. These instruments are dual use. My view here is that an opaque Philippines is worse for everyone than a transparent one, whoever governs. Any future agreement needs the instruments to exist regardless of who built them. In order to mitigate this, we implement safeguards - classification through reference mechanisms leaves little wiggle room for abuse down the line without changing policy.
"Crowding out" the local fight. The presence of an organization with funding can pull limited attention and political will from partners towards the "technical" lane and away from the land, water and FPIC fight that currently has momentum. This is hypothetically possible. But this is unlikely in practice. The resistance on these issues has far more domestic momentum than we could divert. Moreover, I'd say our work is additive - we supply what is unlikely to be produced domestically (See counterfactual).
Tension with the US. Could the work be read as active obstruction by the US? Very weak: Malaysia's compute regulatory infrastructure was welcomed by the US, and coalition membership presupposes the capacity to restrict chip access.
There are no bids on this project.