Follow the capability
A company can stop offering a model while its capability persists elsewhere. Copies may remain with other operators. Earlier checkpoints may provide a starting point for further training. A permitted service might help build a replacement. Prevention therefore has to track the routes by which a prohibited capability could return.
W360's proposal is to assess these routes together. Closing a single route can move development to another. The aim would be a durable, verifiable A proposed continuing limit on what systems or combinations of systems are permitted to do., supported by lawful controls and independent review.
Models, transfers, and combinations
Model The learned numerical parameters of a model. A copy can support another deployment when software and hardware are available. are the numerical settings that largely determine a trained model's behavior. Controls could cover the possession, transfer, and use of weights associated with prohibited capabilities, including relevant checkpoints. Such controls would face an important limitation: digital information can be copied, and proving that no private copy remains is difficult.
Training another model from a stronger model’s outputs or behavior, transferring some of its capabilities. trains another system using outputs or guidance from a stronger one. Synthetic training data can serve a related role. A policy would need to distinguish ordinary educational or software uses from transfers that reproduce prohibited capabilities. Broad bans on all generated data would be both disruptive and poorly targeted.
Agent orchestration connects models to tools, memory, other agents, and repeated opportunities to act. A collection of individually permitted components may create a more capable system. Evaluations therefore need to examine the operational combination and its access, rather than treating each model as the entire product.
Compute and automated development
Accelerators, high bandwidth memory, fast interconnects, and large compute services are potential enforcement points. Registration, audited access controls, and accountable reporting could make large prohibited projects harder to organize. These are proposed tools, each with costs, technical limits, and opportunities for evasion.
Automated research and development deserves particular attention because it could make rebuilding faster or cheaper. A durable policy would need to limit prohibited successor development while allowing bounded scientific and engineering tools.
The feasibility test
A credible proposal must estimate what can be rebuilt using retained copies, distributed compute, improved algorithms, and nonparticipating jurisdictions. If dangerous capabilities become easy to reproduce on ordinary equipment, hardware controls alone lose effectiveness. That possibility strengthens the case for early action, while also setting a real limit on what any Reducing dangerous capability or access already available, including ways to rebuild it. can promise.