Can the U.S. and China Deny AI?
Felix Choussat, mentored by Oscar Delaney, modelled how much delay a kinetic strike on AI infrastructure could actually buy.
Summary
Proposals for Mutually Assured AI Malfunction assume that the threat of sabotage can hold rivals at a stalemate over frontier AI development. This paper tests that assumption quantitatively, combining effective FLOP targets derived from capability benchmarks, compute forecasts, and software progress models to estimate the delay imposed by strikes that destroy between 50% and 90% of a nation's compute or that target the semiconductor supply chain. Destroying compute alone is not enough to force a stalemate. Minimal strikes buy one to two years; medium strikes combining datacenter and supply-chain attacks buy around three; maximal persistent strikes reach roughly four to five years at most, and require hitting several dozen targets across datacenters and fabs. The defender's response matters more than the strike: centralizing 90% of surviving compute offsets 80% to 90% of the delay, which can make a minimal strike counterproductive. The paper argues against relying on kinetic sabotage for indefinite deterrence and for lower-escalation mechanisms that leave room to negotiate.
