C-0001

Compute stock is at most a declared amount

A party holds no more AI-relevant compute, counted in chips or equivalent capacity, than the total it has declared.

Source reviewed 2026-09-25

01 / The mechanism and its boundary

What is being described

The claim is that a party holds no more AI-relevant compute, counted in chips or equivalent capacity, than the total it has declared. Many proposed AI agreements start from this kind of declaration, which other parties then check. A bounded stock caps how much training or inference a party could run in secret, and anchors other checks, such as monitoring how chips are used. The claim is negative, which makes it hard to verify. Millions of AI-relevant chips already exist without central tracking, and a party could acquire or build chips outside any registry. Proposals combine monitoring of the chip supply chain from fabrication onward, registries of chips and their owners, inspections, and intelligence methods such as customs and financial data. Supply-chain tracking can reach newly produced chips; the existing stock is the main gap.

State of verification

Editorial synthesis from the AI Verification Tech Map.

No mechanism can yet bound a party's chip stock, and every approach is proposed (R1). Chip tracking would reach new production far better than chips already in circulation, partly because the chip supply chain is concentrated S-0053 S-0029.

Chip registries and manufacturing records (R1) would follow each chip from the fab to its owner, so that inspectors can check a sample against the declared records S-0029. Remote detection of data centres (R1) estimates the power capacity of large facilities from equipment visible outside, and public estimates exist for known large facilities S-1411. Performance throttling and licensing (R1) would cap the work that declared chips can do S-0057. Beyond these estimates, only designs and policy analyses are public, and no chip registry has been built for verification.

Millions of AI-relevant chips already exist with no central tracking S-0005, and domestic chip manufacture and older chips are listed as evasion routes S-0062. Draft agreements therefore pair technical measures with intelligence, inspections and whistleblowers S-0063.

Connections in the research map

Concepts used

Techniques addressing this claim

Sources and provenance

  1. S-0029 / Tier B

    What does it take to catch a Chinchilla? Verifying Rules on Large-Scale Neural Network Training via Compute Monitoring ↗

    Y. Shavit · 2023 · arXiv

    Supports: supply-chain monitoring to prevent amassing untracked chips; chip owner directory, sampled inspection and chain of custody; many existing chips lack features and may not be locatable

    Locator: abstract; §3; §5

    Version and catalogue details
  2. S-0053 / Tier B

    Computing Power and the Governance of Artificial Intelligence ↗

    G. Sastry, L. Heim, H. Belfield, M. Anderljung, M. Brundage, J. Hazell, C. O'Keefe, G. K. Hadfield, R. Ngo, K. Pilz, G. Gor, E. Bluemke, S. Shoker, J. Egan, R. F. Trager, S. Avin, A. Weller, Y. Bengio, D. Coyle · 2024 · arXiv

    Supports: compute is detectable, excludable and quantifiable with a concentrated supply chain; international chip registry listed; algorithmic progress and decentralised training

    Locator: abstract; §§ on properties of compute and visibility mechanisms; limitations

    Version and catalogue details
  3. S-0063 / Tier B

    An International Agreement to Prevent the Premature Creation of Artificial Superintelligence ↗

    A. Scher, D. Abecassis, P. Barnett, B. Abeyta · 2025 · Machine Intelligence Research Institute

    Supports: chip consolidation into monitored facilities; >16 H100-equivalents only in monitored facilities; methods for locating chips; production monitoring

    Locator: §4; Articles V–VI (as summarised)

    Version and catalogue details
  4. S-0005 / Tier B

    Mechanisms to Verify International Agreements About AI Development ↗

    A. Scher, L. Thiergart · 2025 · arXiv

    Supports: millions of AI-relevant chips without central tracking; locate chips early then keep them monitored

    Locator: Verifying the location of AI compute

    Version and catalogue details
  5. S-0062 / Tier B

    Verification methods for international AI agreements ↗

    A. R. Wasil, T. Reed, J. W. Miller, P. Barnett · 2024 · arXiv

    Supports: customs data, financial intelligence and fab inspections; limits and evasions (domestic manufacture, older chips); chip location tracking limited to new chips

    Locator: Verification methods; Table 1; Figures 2–4

    Version and catalogue details
  6. S-0002 / Tier B

    Verifying International Agreements on AI: Six Layers of Verification for Rules on Large-Scale AI Development and Deployment ↗

    M. Baker, G. Kulp, O. Marks, M. Brundage, L. Heim · 2025 · RAND Corporation

    Supports: large-scale defined as computing power of thousands of high-end AI chips under a single entity

    Locator: §2.2

    Version and catalogue details
  7. S-1411 / Tier C

    Introducing the Frontier Data Centers Hub ↗

    Epoch AI · 2025 · Epoch AI

    Supports: power capacity of known large data centres inferred from visible cooling equipment

    Locator: methodology

    Version and catalogue details
  8. S-0057 / Tier B

    Hardware-Enabled Governance Mechanisms: Developing Technical Solutions to Exempt Items Otherwise Classified Under Export Control Classification Numbers 3A090 and 4A090 ↗

    G. Kulp, D. Gonzales, E. Smith, L. Heim, P. Puri, M. J. D. Vermeer, Z. Winkelman · 2024 · RAND Corporation

    Supports: offline licensing: a renewable licence grants a compute budget, after which the chip refuses or slows the relevant operations

    Locator: p. viii

    Version and catalogue details
Source review date
2026-09-25
Drafted by (source map)
ai
Review handles (source map)
codex-review