01 / The mechanism and its boundary
What is being described
The claim is that specific AI chips are at the sites a party has declared, throughout the declared period. Such claims underpin export controls and chip-tracking proposals. Checking them would make a registry of declared sites enforceable and diversion to undeclared facilities detectable. It concerns specific devices and can be tested positively. It does not show what those chips are computing or rule out chips elsewhere S-0063. The main approach has a chip answer timed challenges from trusted servers, so that the delay bounds its distance from them. A rudimentary prototype on NVIDIA H100 chips has been reported with one published result and no systematic measurements. NVIDIA is reported to be developing a similar scheme using its own servers. Known weaknesses are extraction of the chip's private key, which would let another device answer on its behalf, modification of the chip hardware, and limited reach into chips already in circulation.
State of verification
Editorial synthesis from the AI Verification Tech Map.
Chip location concerns known devices and can be checked positively, so it is one of the more tractable claims, but every publicly described scheme is still proposed (R1).
Chip location verification (R1) times a chip's signed replies to trusted servers, so that signal delay bounds its distance from them S-0001 S-0005. Lucid's sovereignty certificates (R1) are a draft specification of this approach S-1404, and chip registries (R1) supply the declared locations to test. Guarantee processors (R1) could automate checks of approximate chip location, and their designers want them to be retrofittable to existing chip and server designs S-0035.
An IAPS issue brief reports a single result from a rudimentary prototype on NVIDIA H100 chips, a landmark in Singapore bounding a chip in Singapore to within 300 miles S-1401, and no systematic measurements, error rates or code have been published. NVIDIA has said that it is developing delay-based location verification using its own servers S-1402, but it has published no design or results, and its announced fleet-management software is opt-in S-1413.
The chip's private key must not be extractable, or another device can answer for it S-0005. Wasil and colleagues see location tracking as limited to newly produced chips S-0062, while Brass and Aarne expect that the H100's trusted execution environment could implement it S-1400.
Connections in the research map
Techniques addressing this claim
Sources and provenance
- S-0001 / Tier A
Open Problems in Technical AI Governance ↗
A. Reuel, B. Bucknall, S. Casper, T. Fist, L. Soder, O. Aarne, L. Hammond, L. Ibrahim, A. Chan, P. Wills, M. Anderljung, B. Garfinkel, L. Heim, A. Trask, G. Mukobi, R. Schaeffer, M. Baker, S. Hooker, I. Solaiman, A. S. Luccioni, N. Rajkumar, N. Moës, J. Ladish, D. Bau, P.-A. Bricman, N. Guha, J. Newman, Y. Bengio, T. South, A. Pentland, S. Koyejo, M. J. Kochenderfer, R. Trager · 2025 · Transactions on Machine Learning Research
Supports: export-controlled chips straightforward to smuggle; location and owner unknowable after export; data-processing laws; verifiable latencies to trusted servers; co-location
Locator: §5.2.1
Version and catalogue details - S-0005 / Tier B
Mechanisms to Verify International Agreements About AI Development ↗
A. Scher, L. Thiergart · 2025 · arXiv
Supports: location as a verification goal; time-based ping location attestation; private-key extraction enables spoofing; locate chips early and keep them monitored
Locator: Verifying the location of AI compute; on-chip mechanisms
Version and catalogue details - S-0062 / Tier B
Verification methods for international AI agreements ↗
A. R. Wasil, T. Reed, J. W. Miller, P. Barnett · 2024 · arXiv
Supports: chip location tracking via unique identifiers; evasion by hardware modification or location spoofing; limited to new chips; needs manufacturing agreements
Locator: Hardware-dependent methods; Table 1; Figure 4
Version and catalogue details - S-0063 / Tier B
An International Agreement to Prevent the Premature Creation of Artificial Superintelligence ↗
A. Scher, D. Abecassis, P. Barnett, B. Abeyta · 2025 · Machine Intelligence Research Institute
Supports: declaration of chip locations; monitored facilities; inspectors with ongoing physical access; chip use verification
Locator: §4; Articles V and VII (as summarised)
Version and catalogue details - S-0029 / Tier B
What does it take to catch a Chinchilla? Verifying Rules on Large-Scale Neural Network Training via Compute Monitoring ↗
Y. Shavit · 2023 · arXiv
Supports: chip owner directory with serial numbers; physical inspection of sampled chips
Locator: §3; §5
Version and catalogue details - S-1400 / Tier B
Location Verification for AI Chips ↗
A. Brass, O. Aarne · 2024 · Institute for AI Policy and Strategy
Supports: H100 trusted execution environment could likely implement location attestation
Locator: Proposed Solution Requirements
Version and catalogue details - S-1401 / Tier B
Location Verification for AI Chips (issue brief) ↗
A. Brass · 2025 · Institute for AI Policy and Strategy
Supports: rudimentary location-verification prototype on NVIDIA H100 chips (builder not named); single Singapore result within 300 miles; summarises Brass and Aarne's 2024 report
Locator: issue brief, pp. 1-2
Version and catalogue details - S-1402 / Tier B
Near-Term Verification Methods for AI Chip Exports ↗
B. Avellar, E. Grunewald · 2026 · Institute for AI Policy and Strategy
Supports: NVIDIA confirmed developing delay-based location verification with NVIDIA-run servers (citing Reuters, December 2025)
Locator: §1.6
Version and catalogue details - S-1413 / Tier B
Opt-In NVIDIA Software Enables Data Center Fleet Management ↗
NVIDIA · 2025 · NVIDIA Blog
Supports: NVIDIA's opt-in, customer-installed fleet-management service with read-only telemetry; NVIDIA's statement that its GPUs lack hardware tracking, kill switches and backdoors (provider self-description)
Locator: blog post
Version and catalogue details - S-1404 / Tier B
Sovereignty Certificates: draft specification, version 0.1.0 ↗
Sovereignty Certificates Working Group · 2025 · GitHub (Lucid-Computing/sovereignty-certificate-specification)
Supports: draft specification for location (sovereignty) certificates
Locator: specification v0.1.0
Version and catalogue details - S-0035 / Tier B
Flexible Hardware-Enabled Guarantees for AI Compute ↗
J. Petrie, O. Aarne, N. Ammann, D. Dalrymple · 2025 · arXiv
Supports: flexHEG could enable automated verification of approximate chip location; designs should be retrofittable on existing chip and server designs
Locator: How FlexHEGs Could Address Risks (Malicious Use); Recommended Areas of Technical Research
Version and catalogue details - S-3382 / Tier B
Countering AI Chip Smuggling Has Become a National Security Priority ↗
E. Grunewald, T. Fist · 2025 · Center for a New American Security (working paper)
Supports: authors' model-based range for AI chip smuggling into China in 2024; recommendation for software-based location verification
Locator: four lines of argument; recommendations 2 and 3
Version and catalogue details - S-3383 / Tier A
U.S. Authorities Shut Down Major China-Linked AI Tech Smuggling Network ↗
U.S. Department of Justice · 2025 · U.S. Department of Justice, Office of Public Affairs
Supports: December 2025 prosecution alleging GPU relabelling and misclassified exports
Locator: criminal complaint summary
Version and catalogue details
- Source review date
- 2026-09-25
- Drafted by (source map)
- ai
- Review handles (source map)
- codex-review