Welcome to katecarruthers.com
Disclaimer: The opinions expressed here are solely my own and not those of any employer, client, or affiliated organisation.

Intelligence is leaving the cloud, and our governance frameworks have not noticed

Intelligence is moving off the cloud and onto devices we own and control. Our governance models are still built for a world of centralised chokepoints - API logs, model providers, and labs we can regulate. That world is fading. What replaces it is messier, more distributed, and much harder to see.

Intelligence is leaving the cloud, and our governance frameworks have not noticed
Photo by Harrison Broadbent / Unsplash

Intelligence is leaving the cloud, and our governance frameworks have not noticed

Every AI governance conversation I sit in still starts from the same premise: the thing we are worried about is big, expensive, and owned by someone we can call. Gigawatt datacentres. Frontier labs with legal teams and usage policies. Regulators who can, at least in theory, pick up the phone.

That premise is quietly going out of date.

While everyone has been arguing about how to regulate the frontier, a second story has been running underneath it: intelligence has been shrinking and slipping out of the datacentre entirely. Models in the 2 to 8 billion parameter range, heavily quantised, now run on a Raspberry Pi with a cheap accelerator bolted on. A model that needed a server-class GPU eighteen months ago now draws a few watts on your desk. Gartner predicts that by 2027, organisations will use small, task-specific models at least three times more than general-purpose large language models. That tracks with a wider infrastructure shift: Gartner has separately estimated that around 75% of enterprise-generated data will be created and processed outside a traditional centralised data centre or cloud, up from roughly 10% less than a decade ago. Whether or not the exact ratios hold, the direction is right - and it is happening faster than most governance frameworks are built for.

I think this matters more than most of the frontier model debate, and I do not think we are taking it seriously yet.

The good version of this story is genuinely good

I do not want to undersell what edge AI makes possible, because it is real and it is overdue. A wearable that processes your biometric data on-device and never phones home. A translation tool that works in a community with no reliable connectivity. A small business running a capable local assistant without paying cloud inference costs at scale.

I see the sovereignty angle most clearly in my own patch. Australia’s AI capability conversation has, for too long, treated “we have API access to a frontier model” as equivalent to genuine capability. It is not; it is rented capability, and it evaporates the moment a contract, a price, or a foreign policy decision changes. A university research group or a regional health service running a meaningful model on hardware they own and control is a real, if modest, step towards actual sovereignty. It is not glamorous. It is a Raspberry Pi in a server room, not a press release. But that is usually where real capability is built.

The bad version of the same story

Here is the problem: none of the mechanisms that make edge AI good are selective about who gets to use them.

💡
Edge AI defined: "Edge artificial intelligence (edge AI) deploys AI algorithms and AI models directly on local edge devices, such as sensors or Internet of Things (IoT) devices. This capability enables real-time data processing and analysis without constant reliance on cloud infrastructure." - IBM

The same decentralisation that lets a health worker run diagnostics offline also lets a criminal run an uncensored, fine-tuned model on hardware they own, with no logging, no usage policy, and no one watching. Social engineering that used to be bottlenecked by a human’s capacity to write convincing lies is now fully automated, with agents generating scam messages tailored to a specific person’s digital footprint at a volume no call centre could match. In 2024, a finance worker at the engineering firm Arup was tricked into wiring $25 million after joining a video call where every participant, including the CFO, was an AI deepfake. AI is lowering the skill floor for reconnaissance and exploitation against critical infrastructure. Deepfakes of political figures can manufacture a diplomatic incident before anyone has had time to check if it is real.

None of that is speculative. It has already happened, and the edge is what makes it durable rather than a one-off.

The part that should worry governance people specifically is this: a model running locally leaves no API log. There is no usage policy to violate, no account to suspend, no rate limit to hit. Everything we currently rely on to catch misuse of AI assumes the AI is sitting on someone else’s server. Once it is not, that entire layer of control simply is not there.

Why our current playbook does not reach this

Most of the AI governance effort I see, inside organisations and at a policy level, is still built around a chokepoint that is disappearing. Audit the model provider. Set usage terms. Monitor the API. That is a sensible approach to a centralised problem, and it is becoming less relevant to a decentralised one. You cannot audit a model running on hardware you do not know exists, in an environment you have no visibility into.

Which means the actual shift required is not a new set of rules for edge models. It is accepting that the “we regulate the labs and that covers the risk” model was always a proxy - and the proxy is losing its grip.

A simple governance pattern for a decentralised reality

If the chokepoint is disappearing, governance has to move with the capability. A useful starting point is to design as if local, unobservable models already exist inside and outside your organisation.

In practice, that looks like:

  • Assume local AI use: treat on-device and unsanctioned models as a baseline condition, not an exception to be stamped out.
  • Shift from provider control to outcome monitoring: focus on detecting harmful effects (fraud patterns, anomalous behaviour, synthetic media signals), rather than relying on API logs you will not have.
  • Harden people-facing systems: invest in verification mechanisms for high-risk interactions (payments, identity changes, executive communications), because humans are now the primary attack surface.
  • Build internal defensive capability: red-team with the same classes of small, local models adversaries can access; do not outsource your threat model to frontier labs.
  • Lift ambient AI literacy: ensure non-technical staff can recognise “slightly off” interactions and know how to escalate them quickly.

None of this is as neat as regulating a handful of labs. It is closer to public health than perimeter security: distributed, ongoing, and uneven. But it matches where the capability is going.

Everywhere, not somewhere

I keep coming back to the same conclusion: we have been treating AI safety as something that happens at a small number of well-known addresses. That was never fully true, and it is getting less true by the month.

When the capability is everywhere, the responsibility for governing it has to be everywhere too - not concentrated in a few labs we can subpoena if things go wrong. That is not a satisfying answer, because it does not come with a single body to hold accountable. But pretending the old chokepoints still work is not governance. It is nostalgia.

© 2002-2026 Kate Carruthers