01 / The mechanism and its boundary
What is being described
A hardware-enabled mechanism (HEM) is a governance or verification function built into AI chips or hardware attached to them, such as reporting how much compute was used and where, or enforcing limits on use S-0057 S-0006.
A 2024 RAND report introduced the concept to help achieve US AI governance goals such as export controls, and analysed the threats, attack vectors and protective measures that apply to such mechanisms S-0057. CNAS notes that chips sold by several leading firms already have many of the security features HEMs would need S-0056. Proposed designs include:
- Offline licensing. Use of certain chip features is tied to a renewable licence carrying a compute budget, as in hardware performance throttling and licensing S-0057.
- Fixed sets. Networking is restricted so that small, fixed groups of GPUs cannot be combined into large clusters, a form of compartmentalization S-0057.
- Guarantee processors. An auditable processor monitors accelerator usage inside a secure enclosure that provides physical tamper protection, as in flexHEG S-0035.
- Verifiable reporting. HEMs could report properties of training, such as the quantity of compute used and the cluster's configuration or location S-0006, the aim of on-chip telemetry and chip location verification.
A central open question is whether HEMs can stay secure when an adversary has the chips in its physical possession S-0057.
Connections in the research map
Related research
Sources and provenance
- S-0057 / Tier B
Hardware-Enabled Governance Mechanisms: Developing Technical Solutions to Exempt Items Otherwise Classified Under Export Control Classification Numbers 3A090 and 4A090 ↗
G. Kulp, D. Gonzales, E. Smith, L. Heim, P. Puri, M. J. D. Vermeer, Z. Winkelman · 2024 · RAND Corporation
Supports: introduces HEMs to help achieve US AI governance goals including export controls; threats, attack vectors and protections; offline licensing and fixed-set designs; security under an adversary's physical possession is open
Locator: abstract; pp. viii–x
Version and catalogue details - S-0006 / Tier B
Hardware-Enabled Mechanisms for Verifying Responsible AI Development ↗
A. O'Gara, G. Kulp, W. Hodgkins, J. Petrie, V. Immler, A. Aysu, K. Basu, S. Bhasin, S. Picek, A. Srivastava · 2025 · arXiv
Supports: HEMs enabling verifiable reporting of compute quantity, cluster configuration or location, and policy enforcement
Locator: abstract
Version and catalogue details - S-0056 / Tier B
Secure, Governable Chips: Using On-Chip Mechanisms to Manage National Security Risks from AI & Advanced Computing ↗
O. Aarne, T. Fist, C. Withers · 2024 · Center for a New American Security
Supports: chips sold by leading firms already have many of the needed features
Locator: summary
Version and catalogue details - S-0035 / Tier B
Flexible Hardware-Enabled Guarantees for AI Compute ↗
J. Petrie, O. Aarne, N. Ammann, D. Dalrymple · 2025 · arXiv
Supports: flexHEG: auditable guarantee processor monitoring accelerator usage, plus a secure enclosure providing physical tamper protection
Locator: abstract
Version and catalogue details
- Source review date
- 2026-09-25
- Drafted by (source map)
- ai
- Review handles (source map)
- codex-review