M-0019 / Accounting & provenance

Chip registries and manufacturing records

Recording each AI chip's identity and owner from the fab onwards, and cryptographically fixing manufacturing records, so that chips can be accounted for later.

R1 ProposedSource reviewed 2026-09-25

01 / The mechanism and its boundary

What the technique establishes

A chip registry records unique identifiers for AI chips, with their owners and sometimes their locations, from manufacture to destruction. A verifier can then sample chips and check that declared chains of custody match what is physically there. A related proposal protects the foundry's own record of chip IDs by publishing a cryptographic fingerprint of it, so that later changes would show. As of September 2026 these are published designs, and no AI chip registry or record commitment is in operation. The main obstacle is institutional: someone must run the registry, and covering re-exports needs cooperation from re-exporters and foreign governments. The main weaknesses are that records cover only chips that were recorded, that documents and serial numbers can be forged, and that a commitment cannot show the records were accurate when made. A commitment shows what was made, not where it went.

Threat model
Semi-trusted prover
Adversarial evaluation
Published analysis
Hardware needed
Existing hardware features
Prover cooperation
Required
Confidentiality
Partial
Category
Accounting & provenance

Claims and scope

A direct link identifies the intended claim. A supporting link supplies part of the evidence. Neither establishes that a complete verification system has been demonstrated.

Readiness for a stated use

R1 Proposed

Assessed use: a checkable record of which chips were made and who declared owning them

medium confidence · current · assessed 2026-09-25 · rubric 1.1

This is the source map’s editorial assessment. Production use is not evidence of resistance to every adversary.

Registry and record-commitment designs are public, but none has been built or tested.

  • R1 met: Baker et al. describe an AI chip registry for ownership declarations, with sampled chain-of-custody checks from manufacture to destruction, and state the goal and assumptions S-0002. Avellar and Grunewald describe how a regulator could run a registry of chip ownership and use it for random return requests S-1402. Cankaya proposes cryptographic commitments to foundry chip-ID records S-1408.
  • R2 not met: as of September 2026 no AI chip registry or manufacturing-record commitment has a public implementation, and no end-to-end results have been published S-0002 S-1402 S-1408. Export documentation checks are established practice, but they are not a registry, and Avellar and Grunewald rate them low in effectiveness as a verification tool S-1402. Ansari rates registry systems as near-term, not deployable now S-0007.

Evidence needed for the next level

  • A public pilot registry or published commitment to manufacturing records at realistic scale.

  • End-to-end results for sampled chain-of-custody checks, including how hard-to-spoof IDs are read and matched.

  • An adversarial evaluation of record falsification, forged serial numbers and unrecorded chips.

Limitations, flaws, and blockers

These are attributed assessments from the source map. Absence of a listed flaw is not a security guarantee.

significant / open / theoretical argument

Records cover only chips that were recorded

A registry or commitment accounts only for chips entered into it. Cankaya asks how a verifier would know it had found all chips, or how much "dark compute" remains, and notes that a fraudulent original record would mean unregistered chips had been made in advance S-1408. Halstead and Larsen propose reconstructing earlier production by auditing upstream suppliers S-1410.

S-1408S-1410

significant / open / theoretical argument

Documents and serial numbers can be forged

Avellar and Grunewald note that export documents can be forged, that companies can hide information behind obscure corporate structures, and that it may be possible to forge serial numbers on chips and racks. They recommend cryptographic attestation of a powered-on chip as an extra check S-1402.

S-1402

significant / open / theoretical argument

Insiders could alter records before they are fixed

Cankaya argues that insiders who can photograph process secrets could also tamper with production records S-1408. A commitment makes changes after publication detectable, but it cannot show that the records were accurate when committed S-1408.

S-1408

What still blocks use or stronger assurance

  1. No AI chip registry operates, and covering re-exports would need cooperation from re-exporters and foreign governments that may not be feasible everywhere.

    S-1402S-0002
  2. Linking records to physical chips needs hard-to-spoof unique IDs and inspections.

    S-0002S-1402S-1408
  3. Chips produced before a registry starts must be reconstructed from supplier records.

    S-1408S-1410

Connections in the research map

Complementary techniques

Concepts used

Organizations and developers

Sources and provenance

  1. S-0002 / Tier B

    Verifying International Agreements on AI: Six Layers of Verification for Rules on Large-Scale AI Development and Deployment ↗

    M. Baker, G. Kulp, O. Marks, M. Brundage, L. Heim · 2025 · RAND Corporation

    Supports: AI chip registry concept; sampled chain-of-custody checks; subgoal on undeclared clusters

    Locator: §3.2 and its footnote on the AI chip registry; §4.2.1.2

    Version and catalogue details
  2. S-1402 / Tier B

    Near-Term Verification Methods for AI Chip Exports ↗

    B. Avellar, E. Grunewald · 2026 · Institute for AI Policy and Strategy

    Supports: centralized ownership registry; random return requests; serial checks; forgery limits; effectiveness ratings

    Locator: §1.1, §1.2, §1.5

    Version and catalogue details
  3. S-1408 / Tier C

    TSMC most definitely has a golden record of all AI chips it made ↗

    N. Cankaya · 2025 · The Datacenter Lie Detector (Substack)

    Supports: ECID golden record; Merkle-root commitment; TAP readout; eFuse tamper evidence; dark compute; insider threat

    Locator: whole post

    Version and catalogue details
  4. S-0053 / Tier B

    Computing Power and the Governance of Artificial Intelligence ↗

    G. Sastry, L. Heim, H. Belfield, M. Anderljung, M. Brundage, J. Hazell, C. O'Keefe, G. K. Hadfield, R. Ngo, K. Pilz, G. Gor, E. Bluemke, S. Shoker, J. Egan, R. F. Trager, S. Avin, A. Weller, Y. Bengio, D. Coyle · 2024 · arXiv

    Supports: international AI chip registry listed among visibility mechanisms

    Locator: §4.A Visibility

    Version and catalogue details
  5. S-0056 / Tier B

    Secure, Governable Chips: Using On-Chip Mechanisms to Manage National Security Risks from AI & Advanced Computing ↗

    O. Aarne, T. Fist, C. Withers · 2024 · Center for a New American Security

    Supports: on-chip mechanisms need ownership tracking, supply-chain tracking and KYC

    Locator: 'What Would Effective On-Chip Governance Look Like?', pp. 9-10

    Version and catalogue details
  6. S-0007 / Tier B

    Hardware-Level Governance of AI Compute: A Feasibility Taxonomy for Regulatory Compliance and Treaty Verification ↗

    S. Ansari · 2026 · arXiv

    Supports: chain-of-custody framing; PUFs; blockchain serialization; customs data; manufacturing concentration; feasibility

    Locator: §3.1 (M7)

    Version and catalogue details
  7. S-1410 / Tier C

    Covert AI Projects ↗

    B. Halstead, T. Larsen · 2026 · AI 2040

    Supports: auditing upstream supply chain to reconstruct production

    Locator: section on preventing compute acquisition

    Version and catalogue details
  8. S-1400 / Tier B

    Location Verification for AI Chips ↗

    A. Brass, O. Aarne · 2024 · Institute for AI Policy and Strategy

    Supports: recommendation to combine location verification with a registry

    Locator: Detailed Summary

    Version and catalogue details
  9. S-3382 / Tier B

    Countering AI Chip Smuggling Has Become a National Security Priority ↗

    E. Grunewald, T. Fist · 2025 · Center for a New American Security (working paper)

    Supports: recommendation to report exports, re-exports and ownership transfers of controlled AI chips

    Locator: recommendation 2

    Version and catalogue details
  10. S-3383 / Tier A

    U.S. Authorities Shut Down Major China-Linked AI Tech Smuggling Network ↗

    U.S. Department of Justice · 2025 · U.S. Department of Justice, Office of Public Affairs

    Supports: December 2025 prosecution alleging removal and replacement of GPU labels before export

    Locator: criminal complaint summary

    Version and catalogue details
Source review date
2026-09-25
Drafted by (source map)
ai
Review handles (source map)
codex-review