01 / The mechanism and its boundary
What is being described
The claim is that a party controls no AI-relevant computing hardware or facilities, above an agreed threshold, beyond those it has declared. Every other check on declared hardware can be sidestepped if a party runs prohibited work on hardware it never declared. Verifying that no such compute exists is therefore central to many proposed AI agreements. It is also among the hardest claims to establish, because it asserts an absence across a whole country or organisation, and demonstrating non-existence is generally harder than demonstrating existence. No single technique establishes it. Proposals combine tracking chips from manufacture, so that the declared stock is complete; searching for undeclared facilities with satellite imagery, energy data, customs and financial intelligence; and human sources such as whistleblowers and inspections. Each has documented evasions, and the achievable assurance depends on how much compute a meaningful violation would require.
State of verification
Editorial synthesis from the AI Verification Tech Map.
No single verification method is foolproof for this broadest of negative claims S-0062, so draft agreements pair technical measures with intelligence, challenge inspections and whistleblowers S-0063. The only mechanism mapped primarily to this claim, remote detection of data centres, is proposed (R1), as are the chip registries and location checks that support it. RAND splits the claim into undeclared use of declared clusters, which reduces to claims such as Declared hardware is idle or shut down and This compute runs inference, not training, and undeclared clusters S-0002.
One strategy, which Scher and Thiergart favour, makes the declared stock complete from the start through chip registries and location verification S-0005. The other searches for what was missed, through remote detection of data centres and other national technical means S-0062. Satellite imagery, permits and utility filings already track the construction of known large facilities, but automated data-centre detection remains primarily conceptual S-1409. Proofs of useful work would leave declared hardware little spare capacity, but cannot find a facility that was never declared S-1102.
Chips sold before tracking began may not be locatable S-0029, facilities can be hidden underground or camouflaged S-0062, and it is unclear how small undeclared compute can be and still matter S-0002 S-0053.
Connections in the research map
Techniques addressing this claim
Sources and provenance
- S-0002 / Tier B
Verifying International Agreements on AI: Six Layers of Verification for Rules on Large-Scale AI Development and Deployment ↗
M. Baker, G. Kulp, O. Marks, M. Brundage, L. Heim · 2025 · RAND Corporation
Supports: Subgoal 2 (2.A, 2.B, 2.B.1, 2.B.2); focus on large-scale clusters; unclear whether dangerous deployment requires scale; personnel and intelligence layers
Locator: §2.2; §3.2, Figure 4; §4
Version and catalogue details - S-0004 / Tier B
Verification for International AI Governance ↗
B. Harack, R. F. Trager, A. Reuel, D. Manheim, M. Brundage, O. Aarne, A. Scher, Y. Pan, J. Xiao, K. Loke, S. N. Adan, G. Bas, N. A. Caputo, J. C. Morse, J. Ahuja, I. Duan, J. Egan, B. Bucknall, B. Rosen, R. Araujo, V. Boulanin, R. Lall, F. Barez, S. Alvira, C. Katzke, A. Atamli, A. Awad · 2025 · Oxford Martin AI Governance Initiative
Supports: existence easier to demonstrate than non-existence
Locator: p. 31
Version and catalogue details - S-0029 / Tier B
What does it take to catch a Chinchilla? Verifying Rules on Large-Scale Neural Network Training via Compute Monitoring ↗
Y. Shavit · 2023 · arXiv
Supports: sampling fails if prover amasses untracked chips; existing chips possibly not locatable
Locator: abstract; §5
Version and catalogue details - S-0005 / Tier B
Mechanisms to Verify International Agreements About AI Development ↗
A. Scher, L. Thiergart · 2025 · arXiv
Supports: covert data centres may be hard to detect; tracking chips favoured; intelligence and whistleblowers as complements
Locator: Verifying the location of AI compute (analysis)
Version and catalogue details - S-0062 / Tier B
Verification methods for international AI agreements ↗
A. R. Wasil, T. Reed, J. W. Miller, P. Barnett · 2024 · arXiv
Supports: unauthorised data centres as a violation type; no single method foolproof; national technical means and their limitations and evasions
Locator: What to verify; Table 1; Figures 2–4
Version and catalogue details - S-0063 / Tier B
An International Agreement to Prevent the Premature Creation of Artificial Superintelligence ↗
A. Scher, D. Abecassis, P. Barnett, B. Abeyta · 2025 · Machine Intelligence Research Institute
Supports: locating chips through supply-chain tracking, reporting, intelligence, OSINT, power monitoring, challenge inspections and whistleblowers
Locator: §4; Articles V and X (as summarised)
Version and catalogue details - S-0053 / Tier B
Computing Power and the Governance of Artificial Intelligence ↗
G. Sastry, L. Heim, H. Belfield, M. Anderljung, M. Brundage, J. Hazell, C. O'Keefe, G. K. Hadfield, R. Ngo, K. Pilz, G. Gor, E. Bluemke, S. Shoker, J. Egan, R. F. Trager, S. Avin, A. Weller, Y. Bengio, D. Coyle · 2024 · arXiv
Supports: detectability of large facilities; low-compute narrow models; decentralised training; underground data centres raise cost
Locator: properties of compute; limitations
Version and catalogue details - S-0014 / Tier C
On TEEs for Privacy-Preserving Monitoring in AI Governance ↗
Gloria Z · 2026 · MIRI Technical Governance Team
Supports: difficulty of verifying completeness of workload declarations and bounding unknown compute
Locator: Limitations
Version and catalogue details - S-1409 / Tier B
Tracking Hyperscale AI Data Center Growth with Satellite Imagery ↗
C. Krawec · 2026 · Federation of American Scientists
Supports: satellite imagery, permits and utility filings track known facilities; automated data-centre detection primarily conceptual
Locator: Methodology; Opportunities for Further Research
Version and catalogue details - S-1102 / Tier C
Pacing AI Requires Proof ↗
Attestable · 2026 · Attestable blog
Supports: work-budget proposal; a proof cannot discover a datacenter that was never declared (provider proposal)
Locator: blog post
Version and catalogue details - S-0060 / Tier B
Does Distributed Training Undermine Compute Governance? ↗
R. Rahman · 2026 · ICML 2026 Workshop on Technical AI Governance Research
Supports: 10^24, 10^25 and 10^26 FLOP thresholds evadable with $1.6M, $31M and $3.8B of hardware in sub-registration clusters; assumptions (DiLoCo-family training over 100 Mbps links, 16 H100-equivalents per node, about 740 days)
Locator: §3.1; §4
Version and catalogue details
- Source review date
- 2026-09-25
- Drafted by (source map)
- ai
- Review handles (source map)
- codex-review