K-0007

Hardware-enabled mechanism (HEM)

A governance or verification function built into AI chips or closely attached hardware, such as usage reporting, location attestation or enforced limits.

Source reviewed 2026-09-25

01 / The mechanism and its boundary

What is being described

A hardware-enabled mechanism (HEM) is a governance or verification function built into AI chips or hardware attached to them, such as reporting how much compute was used and where, or enforcing limits on use S-0057 S-0006.

A 2024 RAND report introduced the concept to help achieve US AI governance goals such as export controls, and analysed the threats, attack vectors and protective measures that apply to such mechanisms S-0057. CNAS notes that chips sold by several leading firms already have many of the security features HEMs would need S-0056. Proposed designs include:

  • Offline licensing. Use of certain chip features is tied to a renewable licence carrying a compute budget, as in hardware performance throttling and licensing S-0057.
  • Fixed sets. Networking is restricted so that small, fixed groups of GPUs cannot be combined into large clusters, a form of compartmentalization S-0057.
  • Guarantee processors. An auditable processor monitors accelerator usage inside a secure enclosure that provides physical tamper protection, as in flexHEG S-0035.
  • Verifiable reporting. HEMs could report properties of training, such as the quantity of compute used and the cluster's configuration or location S-0006, the aim of on-chip telemetry and chip location verification.

A central open question is whether HEMs can stay secure when an adversary has the chips in its physical possession S-0057.

Connections in the research map

Related research

Sources and provenance

  1. S-0057 / Tier B

    Hardware-Enabled Governance Mechanisms: Developing Technical Solutions to Exempt Items Otherwise Classified Under Export Control Classification Numbers 3A090 and 4A090 ↗

    G. Kulp, D. Gonzales, E. Smith, L. Heim, P. Puri, M. J. D. Vermeer, Z. Winkelman · 2024 · RAND Corporation

    Supports: introduces HEMs to help achieve US AI governance goals including export controls; threats, attack vectors and protections; offline licensing and fixed-set designs; security under an adversary's physical possession is open

    Locator: abstract; pp. viii–x

    Version and catalogue details
  2. S-0006 / Tier B

    Hardware-Enabled Mechanisms for Verifying Responsible AI Development ↗

    A. O'Gara, G. Kulp, W. Hodgkins, J. Petrie, V. Immler, A. Aysu, K. Basu, S. Bhasin, S. Picek, A. Srivastava · 2025 · arXiv

    Supports: HEMs enabling verifiable reporting of compute quantity, cluster configuration or location, and policy enforcement

    Locator: abstract

    Version and catalogue details
  3. S-0056 / Tier B

    Secure, Governable Chips: Using On-Chip Mechanisms to Manage National Security Risks from AI & Advanced Computing ↗

    O. Aarne, T. Fist, C. Withers · 2024 · Center for a New American Security

    Supports: chips sold by leading firms already have many of the needed features

    Locator: summary

    Version and catalogue details
  4. S-0035 / Tier B

    Flexible Hardware-Enabled Guarantees for AI Compute ↗

    J. Petrie, O. Aarne, N. Ammann, D. Dalrymple · 2025 · arXiv

    Supports: flexHEG: auditable guarantee processor monitoring accelerator usage, plus a secure enclosure providing physical tamper protection

    Locator: abstract

    Version and catalogue details
Source review date
2026-09-25
Drafted by (source map)
ai
Review handles (source map)
codex-review