Provider records become a verification mechanism only when rules specify how they should be used. This section examines how know-your-customer requirements connect customer identity, ongoing monitoring, reporting, and access decisions.
Oversight for Frontier AI Through a Know-Your-Customer Scheme for Compute Providers
Janet Egan and Lennart Heim (2023)Source
The opening passage, selected parts of Box 3, complete §2.1, the opening of §2.2, and §§2.2.1–2.2.2 are reproduced under CC BY 4.0.
The US government should introduce a KYC scheme that ensures adequate monitoring for advanced AI cloud compute and allows the government to require compute providers to report high-risk entities and deny access to entities of concern. A KYC scheme requires businesses and organizations to verify the identity of their clients in order to provide them with access to particular goods and services. Introducing KYC requirements for entities accessing significant amounts of compute could help identify risks and enable further targeted restrictions where there is significant risk to national and global interests. Requiring compute providers to build greater awareness of the risks could encourage a safer AI industry aligned with public benefit.
It is important to note that this proposed KYC scheme for advanced AI cloud compute would not capture all AI models being developed or used by malicious actors. For example, there are already specific less-advanced models today, which do not require massive amounts of compute, that raise biochemical weapon development concerns or enable more targeted malicious cyber activity. Setting the threshold to capture and monitor the compute of all AI models would not be beneficial, as it would capture too much information to be useful while imposing a significant imposition on industry. Such risks could instead be managed through other safeguards, while the proposed in-depth KYC would focus on powerful foundation models trained on significant amounts of compute.
The history of the implementation of KYC in the financial sector could provide useful lessons for scheme design (Box 3).
Egan and Heim (2023) | CC BY 4.0
Box 3: Learning from KYC in the financial sector — selected requirements and implementation lessons
This legislation creates obligations for financial institutions to:
- implement a customer identification program
- conduct risk assessments
- undertake enhanced due diligence for customers assessed as higher risk
- identify and verify a customer’s beneficial owners
- conduct ongoing monitoring
- report suspicious activity to the US government.
Implementation: Obstacles and Adjustments
The financial sector presents a case study of situations in which non-compliance with obligations persisted until significant penalties were applied. For the first decade of the Bank Secrecy Act, from 1972 to 1985, regulators did not enforce reporting requirements, resulting in low compliance from financial institutions. However, a 1985 $500,000 penalty issued to the Bank of Boston led to a sharp increase in reporting, as well as more evasive behavior from customers. More recently, Congress has taken further action to increase enforcement. The Anti-Money Laundering Whistleblower Improvement Act, signed into law in December 2022, increases reporting incentives with greater financial rewards for successful tips.
KYC in the financial sector also demonstrates implementation risks, including the use of “structuring” to evade publicly set thresholds. In response to obligations for banks to report transactions exceeding $10,000 in any one day, entities and individuals started to intentionally break up transactions across bank accounts and/or days to avoid scrutiny. Amendments made through the 2001 PATRIOT Act have sought to address this by making structuring a criminal offense.
Reproduced from Egan and Heim, Box 3, under CC BY 4.0. Open the paper on arXiv.

