Skip to main content
Regulation

AI and Crypto Won Because Math Is the Last Unregulated Domain

·8 mins

Here is a pattern worth sitting with. The two largest technology waves of the last fifteen years — first crypto, then AI — both grew up in the same place: the part of the world where you can do math without asking permission. Not because math is glamorous, and not because the people working on it were unusually brave. Because math, for a brief window, was the last domain a regulator hadn’t reached. You could write an algorithm, publish it, and run it before anyone had a form to fill out.

That framing comes from a conversation on Naval’s The AI Industrial Revolution, where the line lands almost as an aside: the big advances were “AI and before that, crypto,” and they happened in math because “it’s the last unregulated domain.” It inverts the usual story. We credit breakthroughs to genius, capital, or timing. This credits them to the absence of a gatekeeper — then asks the uncomfortable follow-up: what happens now that the gatekeepers are arriving?

The vacuum was real, and so was the growth #

Crypto is the cleanest case. Bitcoin launched in January 2009 into a genuine regulatory void — no licensing regime, no exchange rules, no agency with a clear mandate over it. For years that vacuum held, and the most legible artifact of it is the ICO boom. In 2017, roughly 875 token sales raised about $6.2 billion, with over $1.6 billion raised in December alone; in 2018, around 1,253 sales raised $7.8 billion before tapering off through the year (Zerocap). Billions of dollars moved into a brand-new asset class with essentially no securities-law scrutiny on the front end. Whatever you think of the quality of what got funded, the mechanism is the point: capital flowed because nobody had built the gate yet.

A correction to a figure that circulates with this story: you’ll see claims of a “3,200% market-cap gain in 2017.” I couldn’t stand it up against a working source — the article usually cited doesn’t report total-market-cap figures at all, and a frequently-linked CoinTelegraph piece (whose own headline says nearly 800%) is now a dead link. Treat the precise multiple as unverified; the ICO totals above are what hold up.

AI followed a similar arc on the investment side. The OECD’s study of venture capital flowing into AI firms describes a roughly order-of-magnitude rise over the 2010s — from a few billion dollars annually early in the decade to tens of billions by 2020 (OECD). The OECD page is currently returning an access error, so I’m reporting the shape of the trend rather than exact transaction counts I can’t re-verify here. The shape is what matters: a decade of compounding investment into a technology no jurisdiction had yet wrapped in binding, AI-specific law.

If “math is unregulated,” there’s a concrete legal reason it stayed that way in the U.S., and it’s worth knowing because it tells you exactly where the current fight is headed.

In the 1990s, Daniel Bernstein — a Berkeley math Ph.D. — wanted to publish an encryption algorithm called Snuffle. The government’s position was that encryption was a munition. Under the Arms Export Control Act and the ITAR scheme, Bernstein was told he had to submit his ideas for review, register as an arms dealer, and obtain a license before he could publish (EFF case page). Math, in other words, was classified as a weapon.

He sued, and he won — in two stages that are easy to conflate but worth keeping separate. At the district level (N.D. Cal.), Judge Marilyn Patel struck the licensing scheme down, and it’s her opinion that contains the quotable core of the doctrine: “Like music and mathematical equations, computer language is just that, language” (EFF). Then, on May 6, 1999, the Ninth Circuit affirmed Bernstein’s right to publish encryption source code and struck down the export regulations as an unconstitutional restraint on speech. The quote belongs to Patel’s district ruling; the appellate landmark is the 1999 decision. The government backed down, crypto export controls relaxed, and SSL, HTTPS, and commercial e-commerce became possible.

Sit with the template, because it’s about to repeat: a powerful mathematical artifact — an encryption algorithm then, a trained neural network now — that the government wants to treat as a controlled munition. That’s the whole game.

The gate is now reaching the weights #

For most of this history, regulation aimed at people and uses. What’s new is that it’s starting to aim at the math itself.

In January 2025, the U.S. created a first-of-its-kind export control on AI model weights — the learned numerical parameters of a trained network — under a new classification, ECCN 4E091. Models trained above a very high compute threshold would have required export licenses, and at the time the agency estimated only a handful of models globally exceeded it. The rule took effect on January 13, 2025, and was rescinded on May 13, 2025 after industry pushback that it would stifle American innovation (Sidley; US Studies Centre). It lasted four months. But notice what it was: structurally the same move the government made against Bernstein, pointed at weights instead of ciphers. The First Amendment question — whether controlling the weights of a model survives the “code as speech” precedent — has not been litigated. Bernstein governs source code. A multi-gigabyte weight file is a different kind of object, and nobody has tested it in court.

Europe took the other road and made it binding. Under the EU AI Act, a general-purpose model is presumed to carry “systemic risk” once the compute used to train it exceeds 10²⁵ floating-point operations — a bright-line presumption written directly into Article 51. The Act’s implementation timeline puts GPAI obligations into effect on August 2, 2025, with the Commission’s enforcement machinery following from August 2026. Providers above the line face adversarial-testing, incident-tracking, and cybersecurity duties, backed by penalties that reach into the low-single-digit percentages of global annual turnover (the Act’s penalty provisions, e.g. Article 99, set the general ceiling at up to 3% for most obligations, with GPAI-specific fines handled separately). I’ll resist quoting a precise count of how many models sit above the 10²⁵ line today — it depends on disclosures that aren’t reliably public — but the set is small and growing, and the direction is unambiguous: the most capable models now have a compliance surface.

That’s the threat the framing points at. The open frontier wasn’t a law of nature. It was a window, and you can watch it close in real time.

The honest counter-case #

I don’t think the “leave the math alone” instinct survives contact with the evidence cleanly, and a builder should hold the counterarguments with the same seriousness as the thesis.

The vacuum also bred predation. The same window that funded crypto funded an enormous amount of fraud. Regulators later concluded most 2017-era ICO tokens were unregistered securities, and the cleanup cost — Mt. Gox, collapsed tokens, retail losses — fell on ordinary investors, not founders. The honest counter-thesis: regulation enables sustainable innovation by building the institutional trust that lets a technology cross from speculation to mainstream adoption. “No gate” and “no accountability” turned out to be the same sentence.

Trust can be a moat, not just a tax. GDPR was widely called innovation-killing, yet it’s now credited by some economists with raising data-handling standards and handing compliant firms a trust advantage in regulated industries. The EU AI Act’s testing and transparency rules could become the baseline that serious enterprise buyers — healthcare, finance, government — simply demand. In those verticals, the compliant lab may out-compete the fast one.

Borderless math, bordered compute. The thesis holds for pure algorithms and breaks for industrial-scale ones. Math may be unregulatable, but a leading-edge fab sits in Taiwan and a data center sits in a jurisdiction. Export controls on top-tier accelerators are already bifurcating global AI development and constraining frontier work where the hardware is cut off. You can’t run a 10²⁵-FLOP training run on principles alone.

And “code is speech” may not stretch to AI systems. As FIRE’s analysis notes, the protection attaches to people’s expressive use of technology, not the technology itself. Governments regulate pharmaceuticals without triggering First Amendment review of the underlying chemistry — and may regulate AI systems under safety or commerce authority the same way. Bernstein is a strong card. It is not obviously a winning hand for a weight file.

What this means if you build #

Strip it to the operating lesson. Crypto and AI exploded partly because, for a while, you could practice them at the speed of math — publish, run, iterate, no permission slip. That speed advantage is a depreciating asset. Compute is the choke point regulators can actually grab, weights are now in the crosshairs, and the legal shield that protected the last math revolution was written for ciphers, not trained networks.

If your edge depends on that frontier staying open, you’re betting on a window, not a moat. The more durable position is the one the counter-case implies: build the thing that’s still fast and trustworthy enough to ship into a regulated world — because that world is visibly arriving for the math too.