← All posts / Policy

Regulate the Compute Kings Like Banks: Inside Greg Jensen's 'Systemically Important AI' Framework

In a new Q&A, Bridgewater's Greg Jensen proposes treating any firm holding more than ~5% of U.S. or global AI compute like a systemically important bank — with bank-grade oversight and possible ownership caps — and warns open-source models can't be policed once RL training goes private.

Regulate the Compute Kings Like Banks: Inside Greg Jensen's 'Systemically Important AI' Framework

On September 17, Greg Jensen — managing chief investment officer of Bridgewater Associates and one of the earliest outside backers of both OpenAI and Anthropic — published the most specific regulatory blueprint yet from inside the AI capital stack. In a Q&A with Dakin Campbell at The Information, Jensen argued that any firm controlling more than roughly 5 percent of U.S. or global AI compute should be treated as a systemically important institution, supervised the way regulators supervise the biggest banks — with enhanced oversight and, potentially, ownership caps.

It is a short step from his September 11 warning that AI-driven disaster odds are “way higher than anybody should be comfortable with” (framed in coverage as 30–60 percent within two years) to this: an actual architecture for who gets regulated, and where the regulatory perimeter sits. His answer is not the model. It is the machine.

The proposal: SIFI logic, applied to silicon

After 2008, the lesson of Lehman was that size plus interconnectedness plus opaqueness equals systemic risk. The policy response — Dodd-Frank’s enhanced prudential standards — didn’t ban big banks. It made bigness itself the trigger: above certain thresholds, institutions submitted to Federal Reserve stress tests, capital surcharges, resolution plans (“living wills”), and ongoing supervisory scrutiny, regardless of whether they had misbehaved.

Jensen’s framework imports that logic wholesale. The analog of a bank’s balance sheet is a firm’s share of the AI compute base. Cross the ~5% line — of American or global capacity — and you become, in effect, an AI G-SIB: subject to bank-like oversight, with rules that could include caps on who can own how much of you. The threshold matters more than the number’s precision. It is designed to capture the handful of hyperscalers, frontier labs, and compute utilities whose failure, capture, or misuse would propagate through everything downstream — every startup renting GPUs, every enterprise running agents on top of that substrate.

This inverts the current regulatory instinct in two ways.

First, it regulates capacity, not training runs. The existing compute-threshold machinery — the 10²⁶ FLOP reporting bar in U.S. executive action, the EU AI Act’s systemic-risk tier at 10²⁵ — measures a flow: how much compute a training run consumed. Jensen’s bar measures a stock: who controls the installed base. Flows can be split into chunks below the threshold, offshored, or run on rented capacity; stocks are legible, auditable, and geographically sticky. For a macro investor, the choice is characteristic: regulate the thing that can’t be arbitraged away.

Second, it regulates the landlord, not just the tenant. Frontier-model developers are the current targets of bills like the Senate’s draft “duty of care” legislation. But much of the frontier’s compute sits on cloud infrastructure owned by parties that never train a model themselves. A compute-share threshold drags the Amazons, Microsofts, Googles — and the largest neoclouds — inside the perimeter, turning them into regulated infrastructure in practice, whether or not anyone calls them utilities.

The open-source problem: the perimeter leaks

The Q&A’s sharpest warning concerns open-weight models. Open-source systems, Jensen argued, are especially hard to police because they can be RL-trained privately — reinforcement-learning fine-tuning done behind closed doors, with no API logs, no usage telemetry, no deployer to subpoena. Once weights are downloadable, the capability-gating moment moves from “the lab releases a checkpoint” to “whoever holds the checkpoint post-trains it” — and the second event is invisible to any regulator.

The awkward footnote is that Jensen speaks from experience. Bridgewater has built its own AI investment stack, and the firm has previously reported using a fine-tuned open model to beat proprietary systems on financial-reasoning benchmarks. That is precisely the practice he describes as nearly impossible to supervise: a private actor, privately RL-training a public weight set, for competitive advantage. In the Q&A he flagged the open-source channel as the hole in any compute-based regime — you can stress-test the banks, but you cannot stress-test everyone’s basement.

It is a candid admission for a proposal advocate to make, and it defines the limits of his own framework: a 5% compute threshold disciplines the concentrated core of the industry while the decentralized edge — open weights plus private post-training — escapes it entirely. Jensen’s earlier prescriptions (criminal liability for developers, a “token tax” on machine labor, citizen equity in AI profits, co-authored with Bridgewater CEO Nir Bar Dea in their August New York Times essay) at least touch that edge: liability follows the model’s creators even after the weights leave the lab.

Why the seat matters — and what Bridgewater is doing about it

This is now the third act in Jensen’s month-long shift from AI bull to AI cage-builder. The sequence: the August op-ed proposing policies that would “hurt our business”; the September 11 Odd Lots appearance comparing AI to February 2020 and predicting regulators won’t act “until the AI starts killing people”; and now a structural proposal that would place his own early portfolio companies — and the hyperscalers that host them — under bank-style supervision. When the person asking to be regulated is one of the frontier’s earliest financiers, the political valence of “regulation costs innovation” changes.

Notably, Bridgewater’s money is not where the policy is. In a companion briefing the same day, Jensen disclosed that the hedge fund holds only a “very small position” in the AI build-out trade — the trade he called “incredible two years ago” that has since become largely consensus. The firm is simultaneously deepening its own AI research (its internal system, tested alongside human decision-making in Pure Alpha, is closing on a human investment process built over decades, in his telling) while keeping its financial exposure to the infrastructure boom minimal and demanding that the infrastructure’s owners be treated like systemically important banks. Bullish on capability, hedged on the trade, insistent on the cage.

The hard questions

The framework will be fought over three fault lines.

Measurement. What counts as “controlling” compute — owning, leasing, reserving? Does an Oracle lease to OpenAI attribute capacity to the landlord, the tenant, or both? Compute shares also swing wildly as new capacity lands; a 5% share today can be 3% next year with no divestment at all. Bank regulators solved this with careful asset definitions; AI regulators would need an equivalent before the threshold means anything.

Arbitrage. Firms just under the line have an incentive to stay there — fragmenting entities, shifting builds abroad, or routing through partners. Post-2008 banking knows this dance intimately: shadow banking grew precisely at the edges of the regulated perimeter. Expect “shadow compute.”

Sufficiency. Even Jensen concedes the open-source channel leaks. A regime that supervises six compute giants while open weights circulate freely may secure the core and miss the periphery — or push risk exactly to where nobody is watching.

None of which makes the proposal wrong; it makes it a first draft from an unusual source. The signal worth pricing is that the man who priced the AI boom before most institutions now argues the industry’s central banks are its compute holders — and that Washington should treat them that way before, not after, the first systemically important incident.

Sources for this article are listed in the frontmatter and rendered below.