Book AnalysisResearch-backed

The Coming Wave: Is Containment a Strategy or a Metaphor?

Test Mustafa Suleyman’s containment proposal against proliferation, concentration, dual use, state capacity, democratic legitimacy, surveillance, and adaptive governance.

The containment portfolio. A governance matrix linking threat model, intervention layer, accountable actor, verification, rights cost, evasion pathway, signpost, and recovery. Download the SVG asset.
Direct answer

Containment is a strategy only after naming the capability, misuse path, intervention layer, responsible institution, verification method, rights cost, evasion route, and failure response. No single barrier contains a general technology. Use a portfolio of technical, organizational, legal, market, and international controls whose concentration risks are themselves governed. Governance frameworks state processes and principles but do not demonstrate that institutions can contain every rapidly diffusing capability.

The containment dilemma

Suleyman argues that increasingly capable, general, and inexpensive technologies generate immense benefit while diffusing beyond reliable control. The dilemma is two-sided: failing to constrain catastrophic misuse and systemic disruption is dangerous, but building an apparatus strong enough to control general technologies can empower surveillance and authoritarian concentration.

The book’s central claim is urgency. AI and synthetic biology combine broad applicability with rapid improvement and incentives for proliferation. Containment is presented as the defining governance challenge.

Intellectual inheritance behind the Coming Wave

The intellectual genealogy includes dual-use science, nuclear nonproliferation, biosecurity, the Collingridge dilemma, responsible innovation, safety engineering, and international arms control. It also inherits state-capacity and political-theory questions: who can constrain whom, under which law, and with what recourse?

The “wave” metaphor emphasizes force and inevitability. The “containment” metaphor suggests a boundary. Both help orient attention, but neither specifies an intervention.

Counterevidence: technologies are governed, not simply contained

General technologies become embedded in institutions, standards, professions, markets, and everyday practices. Electricity and the internet were not held behind one border. Risks were shaped through layered, evolving governance, often after failures.

This counterargument favors adaptive control over a fantasy of final containment. It does not imply laissez-faire. Some capabilities, materials, or uses may justify strict restriction. The strategy must match the mechanism and remain revisable as evidence changes.

The hardest objection to urgency

Sweeping warnings can compress uncertain forecasts into inevitability. They may draw analogies across AI, biology, quantum technology, and robotics whose development and control mechanisms differ. Urgency can narrow public debate and privilege insiders who claim unique access to the threat.

The answer is claim-level decomposition. Separate observed capability from inference, scenario, probability, and policy judgment. Use current primary evidence at the publication cutoff for time-sensitive claims. Preserve genuine uncertainty rather than balancing hype with complacency.

containment portfolio: the claim-bearing evidence

Evidence snapshotModerate confidence

The book synthesizes technology history, industry experience, risk scenarios, and a proposed program of containment. NIST organizes AI risk management across govern, map, measure, and manage functions. OECD principles connect innovation with human rights, transparency, robustness, accountability, and international cooperation. These sources specify governance dimensions, not proof of complete containment.

suleyman-wave, nist-ai-rmf, oecd-ai-principles

Claim sources: suleyman-wave, nist-ai-rmf, oecd-ai-principles

Concentration is a containment risk

Compute controls, licensing, surveillance, and centralized monitoring can increase the power of states and incumbent firms. Those actors can themselves cause harm, suppress competition, or define safety around their interests.

Add governance of the governor:

  • transparent authority and scope;
  • independent audit;
  • due process and appeal;
  • sunset or renewal conditions for exceptional powers;
  • conflict-of-interest disclosure;
  • public reporting that does not expose dangerous detail;
  • international and civil-society participation.

A control that lowers one misuse path while creating unaccountable dependency has not completed the risk analysis.

Decompose the containment portfolio

Build one row per control:

| Field | Required question | |---|---| | Threat model | Which actor, capability, pathway, and consequence? | | Layer | Model, compute, data, lab, product, organization, market, or use? | | Mechanism | How does the control reduce likelihood or consequence? | | Authority | Who can impose, audit, and appeal it? | | Verification | Which evidence shows compliance and effect? | | Rights cost | Which privacy, speech, competition, or access cost follows? | | Evasion | How can actors route around it? | | Recovery | What happens after failure? |

The portfolio prevents one popular control from standing in for a complete strategy.

Test the containment institution

For each proposed control, name the capability it targets, the actor it binds, the evidence that triggers intervention, the authority that acts, and the route for challenge. Then test four failure modes: displacement to another jurisdiction, capture by dominant firms, expansion of surveillance beyond the target risk, and decay after political attention moves elsewhere.

A compute-reporting requirement, model evaluation, licensing rule, incident database, and procurement standard are not interchangeable. Each observes a different part of the system and fails on a different boundary. A portfolio is credible only when its controls connect and no single institution defines, measures, and excuses its own compliance.

Containment should also be reversible. Emergency authority needs expiry; thresholds need revision evidence; denied actors need proportionate appeal; and beneficial low-risk uses should not inherit controls designed for a different capability. Governance that cannot correct itself reproduces the very loss of control the book warns against.

A capability-evaluation case

A government proposes mandatory evaluation before deployment of a high-capability model. The label “evaluation” is insufficient. The threat model may include cyber misuse, autonomous replication, deceptive behavior, or critical-system failure. Each needs tasks, access conditions, thresholds, independent evaluators, and response authority.

Passing a benchmark cannot prove absence of dangerous capability. Failing one does not select the correct remedy automatically. A proportionate process may limit access, require mitigations, monitor use, and define suspension criteria while preserving appeal and research scrutiny.

Reversal conditions for the containment portfolio

Favor strict upstream control when a capability can produce irreversible large-scale harm, access is concentrated enough to verify, safer substitutes exist, and oversight has legitimate authority. Favor downstream standards, liability, monitoring, and resilience when the capability is diffuse, beneficial uses are broad, and upstream restriction is easily evaded or excessively coercive.

Change the portfolio when evaluations fail to predict real incidents, controls push activity into less visible channels, concentration costs grow, or new technical safeguards alter the trade-off.

Containment rhetoric

  • Calling a threat “unprecedented” without a causal comparison.
  • Naming containment without a threat model.
  • Treating principles as operational controls.
  • Assuming benchmark passage proves safety.
  • Ignoring the state or firm as a source of risk.
  • Borrowing nuclear analogies without matching material constraints.
  • Using urgency to remove appeal and public reasoning.
  • Treating failure of perfect control as a case for no governance.

The boundary of this reading of the Coming Wave

Limits and counterevidence

The book makes long-horizon claims about fast-changing technologies. Evidence, product capabilities, and governance arrangements can change before release and must be rechecked at the publication cutoff. The containment portfolio does not resolve classified evidence, international enforcement, or legal authority.

Clarify the protected values through alignment, test state–industry purpose in The Technological Republic, and ground claims in observed human–AI capability.

Named sources

Evidence and further reading

  1. The Coming Wavebook · accessed 2026-07-28
  2. Artificial Intelligence Risk Management Frameworkofficial · accessed 2026-07-28
  3. OECD AI Principlesofficial · accessed 2026-07-28
Publication record

Published July 29, 2026. No substantive revision has been recorded. Evidence last verified July 28, 2026.