AI winners & losersChapter 8 of 10

The Next AI Moat May Be a Queue

Frontier AI needs credible safety testing. But the institutions that review models can also become barriers to entry. Chapter 7…

The Next AI Moat May Be a Queue

The next AI moat may not be better technology. It may be the ability to move through the safety review faster.

As models become more capable, governments and businesses face growing pressure to test dangerous capabilities before release. That is necessary. It also creates a new power structure built from testing bodies, documentation, scarce experts and access decisions.

Chapter 7 examines the boundary between legitimate safety and a regulatory moat—and why a queue can become a strategic advantage for the largest developers.

The Safety Problem Is Real

Frontier models are improving in more than writing and coding. Government security institutes report rapidly advancing capabilities in cybersecurity, chemistry, biology and autonomous task completion.

The UK AI Security Institute says it has evaluated more than 30 frontier systems. Its research indicates that the length of cyber tasks models can complete autonomously has been increasing at very short intervals since modern reasoning models emerged.

That creates a legitimate public interest in pre-release testing, controlled access and the ability to withhold especially dangerous capabilities.

The question is not whether safety evaluation should exist. It is who defines it, who performs it and who must wait for approval.

A Proposal for a Global Testing Body

In July 2026, Google DeepMind CEO Demis Hassabis proposed a U.S.-led international body for frontier-AI oversight. He suggested a structure inspired by FINRA: funded by industry, staffed by experts and able to test highly capable models before release.

The proposed organization could demand additional safeguards or even an industry-wide slowdown when risks rise. The model combines private technical expertise with public authority.

The logic is pragmatic. The companies understand their systems better than a young agency and possess the testing infrastructure, people and model access required.

That is also the governance problem. The largest developers would not merely be regulated. They could help shape the rules, thresholds, methods and conditions of access.

The organization that designs the safety test may also determine who is allowed to enter the test.

Europe Turns Safety Into a Process

The European Union has already built an institutional structure for general-purpose AI. Providers must prepare technical documentation, support downstream users and address European copyright obligations. Models with systemic risk face additional safety and risk-management duties.

The General-Purpose AI Code of Practice translates these requirements into chapters on transparency, copyright, safety and security. Signatories include Amazon, Anthropic, Google, Microsoft and OpenAI.

The obligations for new GPAI models have applied since August 2025. The European Commission’s broader supervisory and enforcement powers are scheduled to begin on August 2, 2026, together with further transparency requirements for AI-generated content.

Release therefore becomes a documented process of classification, evaluation, risk reporting, technical evidence and regulatory communication.

That process can build trust. It can also become an entry barrier when only large companies can afford the lawyers, safety researchers and documentation systems.

The Queue Forms at Several Gates

The next queue is not one license. It forms across several scarce checkpoints:

  • Compute access: advanced chips, clouds and secured clusters
  • Safety evaluation: cyber, biological, chemical and autonomy testing
  • Model access: controlled release of weights, APIs and internal versions
  • Regulatory documentation: technical files, risk reports and copyright evidence
  • Enterprise approval: privacy, liability, audit and procurement
  • Distribution access: clouds, app stores, operating systems and government catalogs

Every gate can be reasonable. Together they create a barrier of time and capital. A company with its own cloud, mature compliance systems and established regulator relationships moves through the gates faster.

A smaller developer can build a strong model and still wait months for evaluation capacity, insurance, documentation, cloud access and distribution.

Safety Becomes a Moat

Traditional software could launch globally once the product and servers were ready. Frontier AI is moving closer to aviation, finance or pharmaceuticals, where approval and continuing supervision are part of the business model.

For large developers, compliance is not merely a burden. It becomes an asset. Existing evaluation suites, safety laboratories, government relationships and audit processes lower the marginal cost of every new model generation.

New entrants must finance that infrastructure from the beginning. The gap between technical capability and a marketable product grows.

The moat no longer lies only in data, chips or model quality. It lies in the ability to complete a long review process repeatedly.

The queue becomes a moat when incumbents can move through it faster than new competitors.

Regulatory Capture Begins Politely

Capture does not require open corruption. It often begins with a reasonable problem: regulators need expertise that initially exists mainly inside the companies being regulated.

Large labs help develop testing methods, define safety terms and supply experts to working groups. Their proposals can be technically sound while still protecting their market position.

Thresholds can be designed around incumbent architectures. Documentation can turn proprietary development practices into de facto standards. Liability can reward balance-sheet strength more than actual safety.

An industry-funded regulator faces an additional structural tension: it depends on fees, data access and cooperation from the companies it supervises.

Protection requires institutional separation—independent leadership, transparent methods, reviewable criteria, appeals and real representation for smaller developers, academia and civil society.

Open Source Faces a Different Boundary

Open models complicate conventional pre-release control. Once weights are public, later restrictions are difficult to enforce.

From a safety perspective, the most capable open models may justify stronger requirements. From a competition perspective, those rules can weaken the strongest counterweight to closed platforms.

Large firms can provide monitored APIs, access controls and shutdown mechanisms. Startups, universities and sovereign users often depend on open weights for independence.

Crude regulation could therefore deepen the very dependency it seeks to manage.

A better approach grades obligations by demonstrated capability, distribution risk and concrete hazard rather than brand or model size alone.

The Evaluator Needs Real Model Access

External evaluation is only as good as the access granted. A tester can examine a public chat interface or receive deeper access to system prompts, safeguards, tools and prerelease versions.

The results can differ sharply. A model may appear harmless inside a restricted interface and exhibit different capabilities when connected to agents or powerful tools.

Regulators therefore need reproducible environments, technical interfaces and the authority to verify central claims independently.

Prerelease models also contain trade secrets and potentially sensitive security information. The testing body becomes a high-value target for espionage, cyberattack and political pressure.

The regulator must therefore be at least as secure as the companies it examines.

Who Controls the Scarcity of Evaluators?

Frontier evaluation requires scarce expertise: cybersecurity specialists, biologists, chemists, interpretability researchers, red teams and autonomy experts.

Many already work for the labs, governments or a handful of safety institutes. Their time becomes a constrained resource.

When testing capacity fails to keep pace with new models, queues form. Prioritization then becomes power: Which developer is tested first? Which national release receives priority? Which models remain restricted while waiting?

Large developers can finance internal pre-testing and deliver complete documentation. Smaller labs absorb longer delays and higher opportunity costs.

Neutral regulation therefore needs open standards, several accredited evaluators and capacity that does not depend on one institution.

Regulation Can Accelerate Innovation

A credible standard does not need to slow innovation. Clear rules can encourage investment because developers know which evidence they need and which liabilities they face.

Common testing reduces duplicate work. Mutual recognition between jurisdictions can prevent the same model from being evaluated from scratch in every market.

Regulatory sandboxes allow limited real-world deployment. Transparent safety cases can tell customers which capabilities were tested and under which conditions the system is safe enough to use.

The best regulation shortens uncertainty. The worst lengthens the queue without measurably reducing risk.

The Capital-Market Logic of Approval

Once release time and compliance become predictable, investors can price them. Developers with established safety and regulatory systems receive a lower risk discount.

Frontier labs face a conflict. Strong rules can reduce dangerous releases and also reduce the number of competitors. That raises incumbent platform value while increasing legal and political responsibility.

Cloud companies benefit when verified models, audit trails and regional compliance become integrated services. Safety and evaluation vendors become a new infrastructure category.

Independent labs without cloud support, open-model projects with uncertain liability and applications launching across many jurisdictions face greater pressure.

The regulatory premium may become as important as the technical premium.

The Gridizer Research Watchlist

  • formation and legal basis of a U.S.-led frontier-AI testing body
  • governance, funding and independence of industry-backed oversight
  • EU enforcement of GPAI obligations from August 2026
  • number and duration of external frontier-model evaluations
  • time between model completion and public release
  • small-lab access to accredited evaluators and regulatory sandboxes
  • rules for open weights, local models and mutual recognition
  • cost of safety cases, red teaming, audits and liability insurance
  • market share of cloud, compliance and evaluation platforms

Permission Becomes Part of the Product

Frontier AI is no longer determined by research, chips and distribution alone. A marketable model increasingly needs documented safety, external evaluation, legal clearance and access to controlled distribution channels.

That can make the technology safer. It can also concentrate power among companies able to shape standards, finance evaluation and survive long delays.

The next moat may not be a wall. It may be a queue in which the largest providers already stand at the front.

Sources and Further Reading