{
  "schema_version": "1.0.0",
  "rubric_version": "1.0",
  "license": "CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/)",
  "record": {
    "id": "C-0002",
    "slug": "chips-are-where-declared",
    "title": "Chips are where they are declared to be",
    "aliases": [
      "chip location",
      "location verification"
    ],
    "status": "draft",
    "last_reviewed": "2026-09-23",
    "review_interval_days": 90,
    "steward": null,
    "provenance": {
      "drafted_by": "ai",
      "reviewed_by": []
    },
    "risk_flags": [],
    "flags": [],
    "one_liner": "Specific AI chips are physically located at the sites a party has declared, throughout the declared period.",
    "summary": "Location claims underpin export controls and chip-tracking proposals. If each chip's location can be checked, a registry of declared sites becomes enforceable and diversion of chips to undeclared facilities becomes detectable. The claim concerns specific devices and can be tested positively, which makes it more tractable than proving that no chips exist elsewhere. The main technical approach has a chip answer timed challenges from trusted servers, so that the delay bounds its distance from them. A rudimentary prototype on NVIDIA H100 chips has been reported with one published result and no systematic measurements. NVIDIA is reported to be developing a similar scheme that uses its own servers. Physical inspection and supply-chain records complement the approach. Known weaknesses are extraction of the chip's private key, which would let another device answer on its behalf, modification of the chip hardware, and limited reach into chips already in circulation.",
    "claim_class": "positive",
    "editors_synthesis": {
      "assessment": true,
      "markdown": "Chip location is one of the more tractable claims, because it concerns known devices and can be checked positively. Every publicly described location scheme is still proposed (R1), however.\n\n[[M-0018|Chip location verification]] (R1) times a chip's signed replies to trusted servers, so that signal delay bounds its distance from them [[S-0001]] [[S-0005]]. [[I-0009|Lucid's sovereignty certificates]] (R1) are a draft specification of this approach [[S-1404]]. [[M-0019|Chip registries]] (R1) supply the declared locations to test. [[M-0009|Guarantee processors]] (R1) could automate checks of approximate chip location, and their designers want them to be retrofittable to existing chip and server designs [[S-0035]].\n\nAn IAPS issue brief shows a single result from a rudimentary prototype on NVIDIA H100 chips: a landmark in Singapore bounding a chip in Singapore to within 300 miles [[S-1401]]. No systematic measurements, error rates or code have been published. NVIDIA has said that it is developing delay-based location verification using its own servers [[S-1402]]. It has published no design or results, and the fleet-management software it has announced is opt-in [[S-1413]].\n\nThe chip's private key must not be extractable, or another device can answer for it [[S-0005]]. Sources differ on coverage: Wasil and colleagues see location tracking as limited to newly produced chips [[S-0062]], while Brass and Aarne expect that the H100's trusted execution environment could implement it [[S-1400]]. A verified location says nothing about what a chip computes, so proposals pair it with checks on use [[S-0063]].",
      "text": "Chip location is one of the more tractable claims, because it concerns known devices and can be checked positively. Every publicly described location scheme is still proposed (R1), however. Chip location verification (R1) times a chip's signed replies to trusted servers, so that signal delay bounds its distance from them [S-0001] [S-0005]. Lucid's sovereignty certificates (R1) are a draft specification of this approach [S-1404]. Chip registries (R1) supply the declared locations to test. Guarantee processors (R1) could automate checks of approximate chip location, and their designers want them to be retrofittable to existing chip and server designs [S-0035]. An IAPS issue brief shows a single result from a rudimentary prototype on NVIDIA H100 chips: a landmark in Singapore bounding a chip in Singapore to within 300 miles [S-1401]. No systematic measurements, error rates or code have been published. NVIDIA has said that it is developing delay-based location verification using its own servers [S-1402]. It has published no design or results, and the fleet-management software it has announced is opt-in [S-1413]. The chip's private key must not be extractable, or another device can answer for it [S-0005]. Sources differ on coverage: Wasil and colleagues see location tracking as limited to newly produced chips [S-0062], while Brass and Aarne expect that the H100's trusted execution environment could implement it [S-1400]. A verified location says nothing about what a chip computes, so proposals pair it with checks on use [S-0063]."
    },
    "sources": [
      {
        "source": "S-0001",
        "supports": "export-controlled chips straightforward to smuggle; location and owner unknowable after export; data-processing laws; verifiable latencies to trusted servers; co-location",
        "locator": "§5.2.1"
      },
      {
        "source": "S-0005",
        "supports": "location as a verification goal; time-based ping location attestation; private-key extraction enables spoofing; locate chips early and keep them monitored",
        "locator": "Verifying the location of AI compute; on-chip mechanisms"
      },
      {
        "source": "S-0062",
        "supports": "chip location tracking via unique identifiers; evasion by hardware modification or location spoofing; limited to new chips; needs manufacturing agreements",
        "locator": "Hardware-dependent methods; Table 1; Figure 4"
      },
      {
        "source": "S-0063",
        "supports": "declaration of chip locations; monitored facilities; inspectors with ongoing physical access; chip use verification",
        "locator": "§4; Articles V and VII (as summarised)"
      },
      {
        "source": "S-0029",
        "supports": "chip owner directory with serial numbers; physical inspection of sampled chips",
        "locator": "§3; §5"
      },
      {
        "source": "S-1400",
        "supports": "H100 trusted execution environment could likely implement location attestation",
        "locator": "Proposed Solution Requirements"
      },
      {
        "source": "S-1401",
        "supports": "rudimentary location-verification prototype on NVIDIA H100 chips (builder not named); single Singapore result within 300 miles; summarises Brass and Aarne's 2024 report",
        "locator": "issue brief, pp. 1-2"
      },
      {
        "source": "S-1402",
        "supports": "NVIDIA confirmed developing delay-based location verification with NVIDIA-run servers (citing Reuters, December 2025)",
        "locator": "§1.6"
      },
      {
        "source": "S-1413",
        "supports": "NVIDIA's opt-in, customer-installed fleet-management service with read-only telemetry; NVIDIA's statement that its GPUs lack hardware tracking, kill switches and backdoors (provider self-description)",
        "locator": "blog post"
      },
      {
        "source": "S-1404",
        "supports": "draft specification for location (sovereignty) certificates",
        "locator": "specification v0.1.0"
      },
      {
        "source": "S-0035",
        "supports": "flexHEG could enable automated verification of approximate chip location; designs should be retrofittable on existing chip and server designs",
        "locator": "How FlexHEGs Could Address Risks (Malicious Use); Recommended Areas of Technical Research"
      }
    ],
    "concepts": [
      "K-0004",
      "K-0019",
      "K-0005",
      "K-0015"
    ],
    "order": 2,
    "type": "claim",
    "url": "https://trustbutveri.fyi/claims/chips-are-where-declared/",
    "source_file": "content/claims/chips-are-where-declared.md",
    "flags_all": [
      "ai-drafted"
    ],
    "body_markdown": "## Why it matters\nProposals use chip location in three ways.\n\n- **Export controls.** High-end data-centre AI chips are subject to US export controls, but the Open Problems survey describes them as at present straightforward to smuggle [[S-0001]]. It names as a key technical problem that a chip's location or owner cannot currently be known after export [[S-0001]]. Verified location could also help cloud users check that their data is processed in line with local data-processing laws [[S-0001]].\n- **International agreements.** Wasil and colleagues list chip location tracking, using unique identifiers and tracking mechanisms built into chips, among the hardware-dependent methods for verifying agreements [[S-0062]]. A draft international agreement requires parties to declare chip locations and to keep large concentrations of chips in monitored facilities where inspectors have ongoing physical access [[S-0063]].\n- **A base for broader claims.** Scher and Thiergart treat locating AI compute as one of their main verification goals [[S-0005]]. They favour tracking chips over trying to detect secret data centres, and propose locating chips at an initial point in time and then keeping them monitored [[S-0005]]. The Open Problems survey also calls for methods to verify that a large number of chips are co-located in a single data centre [[S-0001]].\n\n## Why it is hard\nThe main technical proposal is delay-based. A chip exchanges timed messages with a network of trusted servers, and the measured latencies constrain where it can be [[S-0001]]. Scher and Thiergart describe AI chips using time-based pings to servers around the world to locate themselves [[S-0005]]. An IAPS issue brief from May 2025, which summarises a 2024 report by Brass and Aarne, states that a rudimentary version has been prototyped on NVIDIA H100 chips [[S-1401]]. It shows one result: a landmark in Singapore verifying that a chip in Singapore is within 300 miles of Singapore [[S-1401]].\n\nAvellar and Grunewald report, citing Reuters reporting from December 2025, that NVIDIA has confirmed it is developing location verification that estimates a chip's location from communication delays with NVIDIA-run servers [[S-1402]]. NVIDIA's own announcement from that month describes an opt-in fleet-management service that customers install and that reports read-only telemetry [[S-1413]]. The announcement states that NVIDIA GPUs do not have hardware tracking technology, kill switches or backdoors [[S-1413]].\n\n- **Binding to the physical chip.** Scher and Thiergart identify the main security issue as ensuring that a chip's private key cannot be extracted [[S-0005]]. Extraction would let other chips pretend to be the chip in question, so its location could be spoofed [[S-0005]]. Wasil and colleagues list modifying AI chip hardware and spoofing location as evasion techniques, and note that sophisticated actors may try to disable tracking [[S-0062]].\n- **Coverage.** Wasil and colleagues note that chip location tracking is limited to newly produced chips and requires agreements on manufacturing standards [[S-0062]]. Brass and Aarne, by contrast, expect that the H100's trusted execution environment could be used to implement location attestation [[S-1400]]. For chips without such features, location must be established by other means, such as physical inspection against a directory of chip serial numbers and owners [[S-0029]].\n- **Scope.** A verified location says where a chip is, not what it is computing or who controls it. Proposals therefore pair location with verification of chip use [[S-0063]], which on this site falls under [[C-0003]] and [[C-0004]].",
    "body_text": "Why it matters Proposals use chip location in three ways. - Export controls. High-end data-centre AI chips are subject to US export controls, but the Open Problems survey describes them as at present straightforward to smuggle [S-0001]. It names as a key technical problem that a chip's location or owner cannot currently be known after export [S-0001]. Verified location could also help cloud users check that their data is processed in line with local data-processing laws [S-0001]. - International agreements. Wasil and colleagues list chip location tracking, using unique identifiers and tracking mechanisms built into chips, among the hardware-dependent methods for verifying agreements [S-0062]. A draft international agreement requires parties to declare chip locations and to keep large concentrations of chips in monitored facilities where inspectors have ongoing physical access [S-0063]. - A base for broader claims. Scher and Thiergart treat locating AI compute as one of their main verification goals [S-0005]. They favour tracking chips over trying to detect secret data centres, and propose locating chips at an initial point in time and then keeping them monitored [S-0005]. The Open Problems survey also calls for methods to verify that a large number of chips are co-located in a single data centre [S-0001]. Why it is hard The main technical proposal is delay-based. A chip exchanges timed messages with a network of trusted servers, and the measured latencies constrain where it can be [S-0001]. Scher and Thiergart describe AI chips using time-based pings to servers around the world to locate themselves [S-0005]. An IAPS issue brief from May 2025, which summarises a 2024 report by Brass and Aarne, states that a rudimentary version has been prototyped on NVIDIA H100 chips [S-1401]. It shows one result: a landmark in Singapore verifying that a chip in Singapore is within 300 miles of Singapore [S-1401]. Avellar and Grunewald report, citing Reuters reporting from December 2025, that NVIDIA has confirmed it is developing location verification that estimates a chip's location from communication delays with NVIDIA-run servers [S-1402]. NVIDIA's own announcement from that month describes an opt-in fleet-management service that customers install and that reports read-only telemetry [S-1413]. The announcement states that NVIDIA GPUs do not have hardware tracking technology, kill switches or backdoors [S-1413]. - Binding to the physical chip. Scher and Thiergart identify the main security issue as ensuring that a chip's private key cannot be extracted [S-0005]. Extraction would let other chips pretend to be the chip in question, so its location could be spoofed [S-0005]. Wasil and colleagues list modifying AI chip hardware and spoofing location as evasion techniques, and note that sophisticated actors may try to disable tracking [S-0062]. - Coverage. Wasil and colleagues note that chip location tracking is limited to newly produced chips and requires agreements on manufacturing standards [S-0062]. Brass and Aarne, by contrast, expect that the H100's trusted execution environment could be used to implement location attestation [S-1400]. For chips without such features, location must be established by other means, such as physical inspection against a directory of chip serial numbers and owners [S-0029]. - Scope. A verified location says where a chip is, not what it is computing or who controls it. Proposals therefore pair location with verification of chip use [S-0063], which on this site falls under Declared hardware is idle or shut down and This compute runs inference, not training.",
    "addressed_by": [
      {
        "id": "M-0018",
        "title": "Chip location verification",
        "url": "https://trustbutveri.fyi/mechanisms/chip-location-verification/",
        "role": "primary",
        "note": "Bounds how far a responding chip can be from trusted landmark servers at the time of the check."
      },
      {
        "id": "M-0019",
        "title": "Chip registries and manufacturing records",
        "url": "https://trustbutveri.fyi/mechanisms/chip-registries-and-manufacturing-records/",
        "role": "supporting",
        "note": "Records declared locations, which inspections or location checks can test."
      },
      {
        "id": "M-0009",
        "title": "Hardware-enabled guarantees (flexHEG) and guarantee processors",
        "url": "https://trustbutveri.fyi/mechanisms/flexheg-guarantee-processors/",
        "role": "supporting",
        "note": "Automated verification of approximate chip location (S-0035); see M-0018."
      },
      {
        "id": "M-0016",
        "title": "Timed challenge-response and memory-occupation challenges",
        "url": "https://trustbutveri.fyi/mechanisms/timed-challenge-response/",
        "role": "supporting",
        "note": "Speed-of-light bounds on signed challenge round trips underlie delay-based location checks; see M-0018."
      },
      {
        "id": "I-0009",
        "title": "Lucid sovereignty (location) certificates",
        "url": "https://trustbutveri.fyi/implementations/lucid-location-certificates/",
        "role": "primary",
        "note": "Certifies a bounded region in which an attested workload's platform was running at a given time."
      }
    ],
    "referenced_by": [
      {
        "id": "M-0018",
        "title": "Chip location verification",
        "url": "https://trustbutveri.fyi/mechanisms/chip-location-verification/"
      },
      {
        "id": "M-0019",
        "title": "Chip registries and manufacturing records",
        "url": "https://trustbutveri.fyi/mechanisms/chip-registries-and-manufacturing-records/"
      },
      {
        "id": "M-0009",
        "title": "Hardware-enabled guarantees (flexHEG) and guarantee processors",
        "url": "https://trustbutveri.fyi/mechanisms/flexheg-guarantee-processors/"
      },
      {
        "id": "M-0016",
        "title": "Timed challenge-response and memory-occupation challenges",
        "url": "https://trustbutveri.fyi/mechanisms/timed-challenge-response/"
      },
      {
        "id": "I-0009",
        "title": "Lucid sovereignty (location) certificates",
        "url": "https://trustbutveri.fyi/implementations/lucid-location-certificates/"
      },
      {
        "id": "C-0001",
        "title": "Compute stock is at most a declared amount",
        "url": "https://trustbutveri.fyi/claims/compute-stock-is-bounded/"
      },
      {
        "id": "C-0003",
        "title": "Declared hardware is idle or shut down",
        "url": "https://trustbutveri.fyi/claims/declared-hardware-is-idle/"
      }
    ]
  }
}