AI Policy Wiki
Dashboard

Containment (Suleyman)

medium confidence · updated 2026-06-06

Mustafa Suleyman's framework (The Coming Wave, 2023) for managing transformative technology. Containment = 'managed development that ensures broad benefits while preventing catastrophic harms.' Argues AI + synthetic biology are the first wave that may be structurally uncontainable. Proposes a 10-point framework spanning technical safety, audits, choke points, makers, businesses, governments, alliances, culture, movements, and coherence.

Containment is the central concept in *The Coming Wave* (Mustafa Suleyman with Michael Bhaskar, 2023), defined as "the ability to monitor, curtail, control, and potentially close down technologies" so that their benefits flow broadly while catastrophic harms are prevented. Suleyman argues that prior technological waves were eventually contained through nation-state capacity, but that the coming wave of AI and synthetic biology is harder to contain, and proposes a ten-layer framework for attempting it.

Definition and argument

Suleyman defines containment as the ability to monitor, curtail, control, and potentially close down technologies, ensuring their benefits flow broadly while catastrophic harms are prevented (*The Coming Wave*). He argues that prior technological waves — agricultural, industrial, nuclear, and digital — were eventually contained through the capacity of nation-states, while the coming wave (AI plus synthetic biology) is, in his account, structurally harder to contain.

Suleyman attributes the difficulty to four properties. The first is omni-use: a single capability such as protein design, autonomous code generation, or persuasion has civilian, military, commercial, and mass-destruction applications, making the technology, in his framing, deployment-promiscuous relative to nuclear technology and its narrower set of uses. The second is hyper-evolution: iteration cycles measured in months rather than the decades of prior waves, which he argues outpaces the containment frameworks meant to govern them. The third is asymmetric impact: a small group of actors, or a single model, can produce globally scaled harm, and non-state actors can acquire capabilities previously limited to superpowers. The fourth is increasing autonomy: systems act in the world with diminishing human oversight, eroding the operator control that containment presupposes. Suleyman acknowledges that each property individually has precedent but argues that in combination they are, in his term, unprecedented.

A related argument in the book is what Suleyman calls the pessimism aversion trap: people closest to the technology, including builders and investors, systematically under-rate catastrophic scenarios because pessimism is culturally and professionally penalized within tech culture. He frames the book as a deliberate act of insider pessimism, a frontier-lab cofounder arguing for heavier containment on the grounds that he knows how fast capabilities are moving.

The 10-point containment framework

Suleyman proposes ten concentric layers of containment:

  1. Safety — technical and operational research (interpretability, red-teaming, alignment, adversarial robustness).
  2. Audits — third-party technical and behavioral audits with enforcement weight.
  3. Choke points — targeting compute, data, and talent as controllable leverage, described as the narrow gates where intervention remains possible.
  4. Makers — holding lab leadership personally responsible, on the view that the individuals who build these systems bear special obligations.
  5. Businesses — market-based incentives that reward safety, such as procurement standards, liability, and insurance.
  6. Governments — capacity-building inside regulators (analogs to the UK AISI and US AISI).
  7. Alliances — international coordination (G7 Hiroshima, the AISI network, the Bletchley/Seoul/Paris summit process).
  8. Culture — norms within the tech community that permit pessimism and counter the aversion trap.
  9. Movements — public pressure that makes containment politically profitable.
  10. Coherence — synthesis across the other nine layers, which Suleyman identifies as the hardest and most important, arguing that fragmented containment fails.

Relation to current frontier frameworks

Suleyman's ten-point framework is presented as an intellectual ancestor of several later frontier-governance instruments. The safety, audits, makers, and coherence layers appear structurally in Anthropic RSP v3.1 and in the OpenAI Preparedness Framework V2, and the cross-lab coordination idea appears explicitly in the Frontier Compliance Framework. The choke-point layer maps onto compute and hardware export controls such as the BIS Framework for AI Diffusion — Interim Final Rule (Jan 13, 2025) and the analysis in CSIS — DeepSeek, Huawei, Export Controls, and the Future of the U.S.-China AI Race (Allen, March 2025). The alliances layer corresponds to the The Bletchley Declaration (AI Safety Summit, 1–2 November 2023), the Frontier AI Safety Commitments (Seoul, 2024), the Paris AI Action Summit Declaration (2025), and the G7 Hiroshima Code of Conduct for Advanced AI (2023). The businesses layer, framed as voluntary pre-commitment, corresponds to the EU General-Purpose AI Code of Practice (Final Version, 2025), and the culture and coherence layers connect to Bengio's LawZero.

Debates and positions

Several framings reject or qualify the containment thesis. Narayanan and Kapoor reject the wave framing, arguing that AI will diffuse slowly like prior general-purpose technologies and that containment as Suleyman conceives it is over-designed for a threat profile they expect not to materialize. Regulation-skeptic positions in The Digitalist Papers reject containment as regulatory overreach: Cochrane on historical evidence that preemptive regulation fails, and Volokh on First Amendment and user-sovereignty grounds. On race dynamics, Abraham, Kavner, Moon, and Matheny and Hendrycks, Schmidt, and Wang argue that containment by a single lab or a single state is unstable under competitive pressure, with coordination the hard part.

A further tension noted on the book's source page concerns Suleyman's own trajectory. He was CEO of Inflection when writing the book and later became CEO of Microsoft AI; the move into a scaling-focused role at a hyperscaler is, per the source page, in tension with the book's containment thesis.

Status of containment, 2024–2026

Developments since the book's publication have pulled in both directions. Toward stronger containment, an AISI network emerged across the UK, US, Japan, Korea, and Singapore; frontier frameworks including RSP v3.1 and Preparedness V2 operationalized audits and capability thresholds; the EU AI Office took on the GPAI supervisor role (EU AI Office — Enforcement Framework + GPAI Provider Guidelines); and the sequence of international declarations from Bletchley through Seoul to Paris established a cooperation floor.

Toward weaker containment, open-weight proliferation (DeepSeek, Qwen, Kimi K2) means that once weights are released they cannot be recalled; the US industrial-policy turn in EO 14179 and the AI Action Plan explicitly deprioritized safety mandates; and race dynamics reduced appetite for voluntary restraint.

Relationships