K-0016

Undeclared compute

AI-relevant hardware, or uses of declared hardware, that a prover has not reported, and that verification must therefore detect or rule out.

Source reviewed 2026-09-25

01 / The mechanism and its boundary

What is being described

Undeclared compute is AI-relevant hardware, or use of declared hardware, that a prover has not reported to the verifier S-0002.

RAND's verification framework separates two cases: undeclared uses of declared clusters, and undeclared clusters, whether inside known data centres or standalone S-0002. The problem is sharpest for hardware that predates tracking. Shavit notes that hundreds of thousands of ML chips had already been sold, many lacking the security features his framework needs S-0029, and Scher and Thiergart write that millions of AI-relevant chips exist and that, to their knowledge, no central tracking of them has taken place S-0005. They judge that searching for secret data centres may help but is unlikely to carry a verification regime, because it will likely be too easy to hide AI compute among other compute or to build secret data centres S-0005. Sastry and colleagues caution that more efficient algorithms and more viable decentralized training could reduce how much compute, or how concentrated, a prohibited activity needs S-0053. Proposed responses include:

Connections in the research map

Related research

Sources and provenance

  1. S-0002 / Tier B

    Verifying International Agreements on AI: Six Layers of Verification for Rules on Large-Scale AI Development and Deployment ↗

    M. Baker, G. Kulp, O. Marks, M. Brundage, L. Heim · 2025 · RAND Corporation

    Supports: Subgoal 2: no undeclared uses of declared clusters (2.A) and no undeclared clusters in known data centres or standalone (2.B)

    Locator: §3.2, Figure 4

    Version and catalogue details
  2. S-0029 / Tier B

    What does it take to catch a Chinchilla? Verifying Rules on Large-Scale Neural Network Training via Compute Monitoring ↗

    Y. Shavit · 2023 · arXiv

    Supports: hundreds of thousands of ML chips already sold, many lacking the required security features; supply-chain monitoring and chip-owner directory

    Locator: §1.2; §6; §6.1

    Version and catalogue details
  3. S-0005 / Tier B

    Mechanisms to Verify International Agreements About AI Development ↗

    A. Scher, L. Thiergart · 2025 · arXiv

    Supports: millions of AI-relevant chips exist, with no central tracking to the authors' knowledge; detecting secret data centres unlikely to be load-bearing because AI compute will likely be too easy to hide

    Locator: Verifying the location of AI compute

    Version and catalogue details
  4. S-0053 / Tier B

    Computing Power and the Governance of Artificial Intelligence ↗

    G. Sastry, L. Heim, H. Belfield, M. Anderljung, M. Brundage, J. Hazell, C. O'Keefe, G. K. Hadfield, R. Ngo, K. Pilz, G. Gor, E. Bluemke, S. Shoker, J. Egan, R. F. Trager, S. Avin, A. Weller, Y. Bengio, D. Coyle · 2024 · arXiv

    Supports: algorithmic efficiency and decentralized training could undermine compute detectability

    Locator: limitations of compute governance

    Version and catalogue details
  5. S-0062 / Tier B

    Verification methods for international AI agreements ↗

    A. R. Wasil, T. Reed, J. W. Miller, P. Barnett · 2024 · arXiv

    Supports: national technical means (remote sensing, energy monitoring, customs, financial intelligence) and whistleblowers

    Locator: Verification methods; Table 1

    Version and catalogue details
  6. S-0018 / Tier B

    A System Overview for Near-Term, Low-Trust AI Compute Verification ↗

    N. Cankaya · 2026 · Machine Intelligence Research Institute

    Supports: memory wiping to remove residual capacity for hidden workloads

    Locator: §5.1.2

    Version and catalogue details
Source review date
2026-09-25
Drafted by (source map)
ai
Review handles (source map)
codex-review