{
  "schema_version": "1.0.0",
  "rubric_version": "1.0",
  "license": "CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/)",
  "record": {
    "id": "C-0001",
    "slug": "compute-stock-is-bounded",
    "title": "Compute stock is at most a declared amount",
    "aliases": [
      "bounded compute stock",
      "chip inventory"
    ],
    "status": "draft",
    "last_reviewed": "2026-09-23",
    "review_interval_days": 90,
    "steward": null,
    "provenance": {
      "drafted_by": "ai",
      "reviewed_by": []
    },
    "risk_flags": [],
    "flags": [],
    "one_liner": "A party holds no more AI-relevant compute, counted in chips or equivalent capacity, than the total it has declared.",
    "summary": "Many proposed AI agreements start from an inventory: each party declares how many AI chips it holds, and others check that the real total is no larger. A bounded stock caps how much training or inference a party could run in secret, and anchors other checks, such as monitoring how chips are used. The claim is negative, which makes it hard to verify. Millions of AI-relevant chips already exist without central tracking, and a party could acquire or build chips outside any registry. Proposals combine monitoring of the chip supply chain from fabrication onward, registries of chips and their owners, inspections, and intelligence methods such as customs and financial data. Supply-chain tracking can reach newly produced chips; the existing stock is the main gap.",
    "claim_class": "negative",
    "editors_synthesis": {
      "assessment": true,
      "markdown": "No mechanism can yet bound a party's chip stock. Every approach is proposed (R1), and chip tracking would reach new production far better than chips already in circulation.\n\n[[M-0019|Chip registries and manufacturing records]] (R1) would follow each chip from the fab to its owner, so that inspectors can check a sample against the declared records [[S-0029]]. [[M-0020|Remote detection of data centres]] (R1) estimates the power capacity of large facilities from equipment visible outside [[S-1411]]. [[M-0011|Performance throttling and licensing]] (R1) would cap the work that declared chips can do [[S-0057]].\n\nApart from public estimates of the power capacity of known large facilities [[S-1411]], only designs and policy analyses are public. No chip registry has been built for verification. The concentrated chip supply chain is one reason the sources treat new production as trackable [[S-0053]] [[S-0029]].\n\nMillions of AI-relevant chips already exist with no central tracking [[S-0005]]. Domestic chip manufacture and older chips are listed as evasion routes [[S-0062]]. Draft agreements therefore pair technical measures with intelligence, inspections and whistleblowers [[S-0063]].",
      "text": "No mechanism can yet bound a party's chip stock. Every approach is proposed (R1), and chip tracking would reach new production far better than chips already in circulation. Chip registries and manufacturing records (R1) would follow each chip from the fab to its owner, so that inspectors can check a sample against the declared records [S-0029]. Remote detection of data centres (R1) estimates the power capacity of large facilities from equipment visible outside [S-1411]. Performance throttling and licensing (R1) would cap the work that declared chips can do [S-0057]. Apart from public estimates of the power capacity of known large facilities [S-1411], only designs and policy analyses are public. No chip registry has been built for verification. The concentrated chip supply chain is one reason the sources treat new production as trackable [S-0053] [S-0029]. Millions of AI-relevant chips already exist with no central tracking [S-0005]. Domestic chip manufacture and older chips are listed as evasion routes [S-0062]. Draft agreements therefore pair technical measures with intelligence, inspections and whistleblowers [S-0063]."
    },
    "sources": [
      {
        "source": "S-0029",
        "supports": "supply-chain monitoring to prevent amassing untracked chips; chip owner directory, sampled inspection and chain of custody; many existing chips lack features and may not be locatable",
        "locator": "abstract; §3; §5"
      },
      {
        "source": "S-0053",
        "supports": "compute is detectable, excludable and quantifiable with a concentrated supply chain; international chip registry listed; algorithmic progress and decentralised training",
        "locator": "abstract; §§ on properties of compute and visibility mechanisms; limitations"
      },
      {
        "source": "S-0063",
        "supports": "chip consolidation into monitored facilities; >16 H100-equivalents only in monitored facilities; methods for locating chips; production monitoring",
        "locator": "§4; Articles V–VI (as summarised)"
      },
      {
        "source": "S-0005",
        "supports": "millions of AI-relevant chips without central tracking; locate chips early then keep them monitored",
        "locator": "Verifying the location of AI compute"
      },
      {
        "source": "S-0062",
        "supports": "customs data, financial intelligence and fab inspections; limits and evasions (domestic manufacture, older chips); chip location tracking limited to new chips",
        "locator": "Verification methods; Table 1; Figures 2–4"
      },
      {
        "source": "S-0002",
        "supports": "large-scale defined as computing power of thousands of high-end AI chips under a single entity",
        "locator": "§2.2"
      },
      {
        "source": "S-1411",
        "supports": "power capacity of known large data centres inferred from visible cooling equipment",
        "locator": "methodology"
      },
      {
        "source": "S-0057",
        "supports": "offline licensing: a renewable licence grants a compute budget, after which the chip refuses or slows the relevant operations",
        "locator": "p. viii"
      }
    ],
    "concepts": [
      "K-0016",
      "K-0023",
      "K-0003",
      "K-0020"
    ],
    "order": 1,
    "type": "claim",
    "url": "https://trustbutveri.fyi/claims/compute-stock-is-bounded/",
    "source_file": "content/claims/compute-stock-is-bounded.md",
    "flags_all": [
      "ai-drafted"
    ],
    "body_markdown": "## Why it matters\nAn accurate chip count underpins other checks on compute. Proposals rely on it in several ways:\n\n- **Shavit's monitoring framework** has three stages: on-chip logging, proofs about training runs, and monitoring of the chip supply chain [[S-0029]]. The third stage exists so that no actor can avoid discovery by amassing a large quantity of untracked chips [[S-0029]]. Without it, a prover could covertly acquire chips and train on them without ever notifying the verifier, bypassing checks on the chips it did declare [[S-0029]].\n- **Sastry and colleagues** describe AI-relevant compute as detectable, excludable and quantifiable, and produced through an extremely concentrated supply chain [[S-0053]]. They list an international AI chip registry among possible mechanisms for regulatory visibility [[S-0053]].\n- **A draft international agreement** would prohibit concentrations of more than 16 H100-equivalents outside monitored facilities [[S-0063]]. It would consolidate existing chips into those facilities and track new production [[S-0063]]. Chips would be located through supply-chain tracking, mandatory reporting, intelligence gathering, open-source intelligence, power monitoring, challenge inspections and whistleblowers [[S-0063]].\n- **Scher and Thiergart** argue for locating AI chips at an initial point in time and then keeping them monitored, rather than relying on detecting secret data centres later [[S-0005]].\n\n## Why it is hard\nThe claim is negative: it asserts that no chips exist beyond the declared total.\n\n- **The existing stock.** Shavit noted in 2023 that hundreds of thousands of ML chips had already been sold, many lacking the security features his framework needs and possibly not locatable by governments [[S-0029]]. Scher and Thiergart write that millions of AI-relevant chips already exist with no central tracking, which could make an initial inventory difficult [[S-0005]].\n- **Tracking must start at the fab.** Shavit's design monitors the small number of fabrication facilities that make leading-edge chips [[S-0029]]. It records each chip's burned-in serial number in a directory of chip owners, kept up to date when chips are resold or damaged [[S-0029]]. Responsibility for any missing chip precursors lies with the most recent holder [[S-0029]].\n- **Supporting methods have gaps.** Wasil and colleagues note that customs data is less useful against countries that can manufacture components domestically, and that financial intelligence is limited because many hardware purchases have legitimate uses [[S-0062]]. Inspections of chip fabrication plants are resource-intensive and put intellectual property at risk [[S-0062]]. The same authors list local chip manufacture and the use of older chips as evasion routes, and note that chip location tracking would apply only to new chips [[S-0062]].\n- **Chips are not a fixed unit of capacity.** RAND's framework counts a cluster as large-scale if it has the computing power of thousands of high-end AI chips controlled by a single entity [[S-0002]]. Sastry and colleagues caution that algorithmic progress can reduce the compute needed for a given capability, and that decentralised training could undermine the detectability of compute [[S-0053]].\n\nThe claim is closely tied to [[C-0010]], which asks whether any compute lies outside the declared stock, and to [[C-0002]], which asks whether declared chips are where they are said to be.",
    "body_text": "Why it matters An accurate chip count underpins other checks on compute. Proposals rely on it in several ways: - Shavit's monitoring framework has three stages: on-chip logging, proofs about training runs, and monitoring of the chip supply chain [S-0029]. The third stage exists so that no actor can avoid discovery by amassing a large quantity of untracked chips [S-0029]. Without it, a prover could covertly acquire chips and train on them without ever notifying the verifier, bypassing checks on the chips it did declare [S-0029]. - Sastry and colleagues describe AI-relevant compute as detectable, excludable and quantifiable, and produced through an extremely concentrated supply chain [S-0053]. They list an international AI chip registry among possible mechanisms for regulatory visibility [S-0053]. - A draft international agreement would prohibit concentrations of more than 16 H100-equivalents outside monitored facilities [S-0063]. It would consolidate existing chips into those facilities and track new production [S-0063]. Chips would be located through supply-chain tracking, mandatory reporting, intelligence gathering, open-source intelligence, power monitoring, challenge inspections and whistleblowers [S-0063]. - Scher and Thiergart argue for locating AI chips at an initial point in time and then keeping them monitored, rather than relying on detecting secret data centres later [S-0005]. Why it is hard The claim is negative: it asserts that no chips exist beyond the declared total. - The existing stock. Shavit noted in 2023 that hundreds of thousands of ML chips had already been sold, many lacking the security features his framework needs and possibly not locatable by governments [S-0029]. Scher and Thiergart write that millions of AI-relevant chips already exist with no central tracking, which could make an initial inventory difficult [S-0005]. - Tracking must start at the fab. Shavit's design monitors the small number of fabrication facilities that make leading-edge chips [S-0029]. It records each chip's burned-in serial number in a directory of chip owners, kept up to date when chips are resold or damaged [S-0029]. Responsibility for any missing chip precursors lies with the most recent holder [S-0029]. - Supporting methods have gaps. Wasil and colleagues note that customs data is less useful against countries that can manufacture components domestically, and that financial intelligence is limited because many hardware purchases have legitimate uses [S-0062]. Inspections of chip fabrication plants are resource-intensive and put intellectual property at risk [S-0062]. The same authors list local chip manufacture and the use of older chips as evasion routes, and note that chip location tracking would apply only to new chips [S-0062]. - Chips are not a fixed unit of capacity. RAND's framework counts a cluster as large-scale if it has the computing power of thousands of high-end AI chips controlled by a single entity [S-0002]. Sastry and colleagues caution that algorithmic progress can reduce the compute needed for a given capability, and that decentralised training could undermine the detectability of compute [S-0053]. The claim is closely tied to There is no undeclared relevant compute, which asks whether any compute lies outside the declared stock, and to Chips are where they are declared to be, which asks whether declared chips are where they are said to be.",
    "addressed_by": [
      {
        "id": "M-0019",
        "title": "Chip registries and manufacturing records",
        "url": "https://trustbutveri.fyi/mechanisms/chip-registries-and-manufacturing-records/",
        "role": "primary",
        "note": "Gives a baseline of which chips were made and who declared owning them."
      },
      {
        "id": "M-0011",
        "title": "Hardware performance throttling and licensing",
        "url": "https://trustbutveri.fyi/mechanisms/hardware-performance-throttling/",
        "role": "supporting",
        "note": "A verified performance cap bounds the effective capacity of declared hardware; needs attestation that the cap is active."
      },
      {
        "id": "M-0020",
        "title": "Remote detection of data centres",
        "url": "https://trustbutveri.fyi/mechanisms/remote-detection-of-data-centres/",
        "role": "supporting",
        "note": "Estimates the power capacity, and so roughly the compute, of observed facilities."
      }
    ],
    "referenced_by": [
      {
        "id": "M-0019",
        "title": "Chip registries and manufacturing records",
        "url": "https://trustbutveri.fyi/mechanisms/chip-registries-and-manufacturing-records/"
      },
      {
        "id": "M-0011",
        "title": "Hardware performance throttling and licensing",
        "url": "https://trustbutveri.fyi/mechanisms/hardware-performance-throttling/"
      },
      {
        "id": "M-0020",
        "title": "Remote detection of data centres",
        "url": "https://trustbutveri.fyi/mechanisms/remote-detection-of-data-centres/"
      },
      {
        "id": "C-0007",
        "title": "A training run stayed within declared limits",
        "url": "https://trustbutveri.fyi/claims/training-within-declared-limits/"
      },
      {
        "id": "O-0202",
        "title": "Machine Intelligence Research Institute",
        "url": "https://trustbutveri.fyi/organizations/machine-intelligence-research-institute/"
      }
    ]
  }
}