{
  "schema_version": "1.0.0",
  "rubric_version": "1.0",
  "license": "CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/)",
  "record": {
    "id": "C-0010",
    "slug": "no-undeclared-compute",
    "title": "There is no undeclared relevant compute",
    "aliases": [
      "no hidden compute",
      "completeness of declarations"
    ],
    "status": "draft",
    "last_reviewed": "2026-09-23",
    "review_interval_days": 90,
    "steward": null,
    "provenance": {
      "drafted_by": "ai",
      "reviewed_by": []
    },
    "risk_flags": [],
    "flags": [],
    "one_liner": "A party controls no AI-relevant computing hardware or facilities, above an agreed threshold, beyond those it has declared.",
    "summary": "Every other check on declared hardware can be sidestepped if a party runs prohibited work on hardware it never declared. Verifying that no such compute exists is therefore central to many proposed AI agreements. It is also among the hardest claims to establish, because it asserts an absence across a whole country or organisation, and demonstrating non-existence is generally harder than demonstrating existence. No single technique establishes it. Proposals combine tracking chips from manufacture, so that the declared stock is complete; searching for undeclared facilities with satellite imagery, energy data, customs and financial intelligence; and human sources such as whistleblowers and inspections. Each has documented evasions, and the achievable assurance depends on how much compute a meaningful violation would require.",
    "claim_class": "negative",
    "editors_synthesis": {
      "assessment": true,
      "markdown": "This broadest of negative claims cannot rest on one method, since no single verification method is foolproof [[S-0062]]. The two mechanisms built primarily for it, [[M-0020|remote detection of data centres]] and [[M-0007|proofs of useful work]], are proposed (R1), as are the chip registries and location checks that support it. RAND splits the claim into undeclared use of declared clusters, which reduces to claims such as [[C-0003]] and [[C-0004]], and undeclared clusters [[S-0002]].\n\nOne strategy makes the declared stock complete from the start, through [[M-0019|chip registries]] and [[M-0018|location verification]]. Scher and Thiergart favour this strategy [[S-0005]]. The other searches for what was missed, through remote detection of data centres and other national technical means [[S-0062]]. Proofs of useful work would leave declared hardware little spare capacity, but cannot find a facility that was never declared [[S-1102]].\n\nSatellite imagery, permits and utility filings already track the construction of known large facilities, but automated data-centre detection remains primarily conceptual [[S-1409]].\n\nChips sold before tracking began may not be locatable [[S-0029]], and facilities can be hidden underground or camouflaged [[S-0062]]. It is unclear how small undeclared compute can be and still matter [[S-0002]] [[S-0053]]. Draft agreements therefore pair technical measures with intelligence, challenge inspections and whistleblowers [[S-0063]].",
      "text": "This broadest of negative claims cannot rest on one method, since no single verification method is foolproof [S-0062]. The two mechanisms built primarily for it, remote detection of data centres and proofs of useful work, are proposed (R1), as are the chip registries and location checks that support it. RAND splits the claim into undeclared use of declared clusters, which reduces to claims such as Declared hardware is idle or shut down and This compute runs inference, not training, and undeclared clusters [S-0002]. One strategy makes the declared stock complete from the start, through chip registries and location verification. Scher and Thiergart favour this strategy [S-0005]. The other searches for what was missed, through remote detection of data centres and other national technical means [S-0062]. Proofs of useful work would leave declared hardware little spare capacity, but cannot find a facility that was never declared [S-1102]. Satellite imagery, permits and utility filings already track the construction of known large facilities, but automated data-centre detection remains primarily conceptual [S-1409]. Chips sold before tracking began may not be locatable [S-0029], and facilities can be hidden underground or camouflaged [S-0062]. It is unclear how small undeclared compute can be and still matter [S-0002] [S-0053]. Draft agreements therefore pair technical measures with intelligence, challenge inspections and whistleblowers [S-0063]."
    },
    "sources": [
      {
        "source": "S-0002",
        "supports": "Subgoal 2 (2.A, 2.B, 2.B.1, 2.B.2); focus on large-scale clusters; unclear whether dangerous deployment requires scale; personnel and intelligence layers",
        "locator": "§2.2; §3.2, Figure 4; §4"
      },
      {
        "source": "S-0004",
        "supports": "existence easier to demonstrate than non-existence",
        "locator": "p. 31"
      },
      {
        "source": "S-0029",
        "supports": "sampling fails if prover amasses untracked chips; existing chips possibly not locatable",
        "locator": "abstract; §5"
      },
      {
        "source": "S-0005",
        "supports": "covert data centres may be hard to detect; tracking chips favoured; intelligence and whistleblowers as complements",
        "locator": "Verifying the location of AI compute (analysis)"
      },
      {
        "source": "S-0062",
        "supports": "unauthorised data centres as a violation type; no single method foolproof; national technical means and their limitations and evasions",
        "locator": "What to verify; Table 1; Figures 2–4"
      },
      {
        "source": "S-0063",
        "supports": "locating chips through supply-chain tracking, reporting, intelligence, OSINT, power monitoring, challenge inspections and whistleblowers",
        "locator": "§4; Articles V and X (as summarised)"
      },
      {
        "source": "S-0053",
        "supports": "detectability of large facilities; low-compute narrow models; decentralised training; underground data centres raise cost",
        "locator": "properties of compute; limitations"
      },
      {
        "source": "S-0014",
        "supports": "difficulty of verifying completeness of workload declarations and bounding unknown compute",
        "locator": "Limitations"
      },
      {
        "source": "S-1409",
        "supports": "satellite imagery, permits and utility filings track known facilities; automated data-centre detection primarily conceptual",
        "locator": "Methodology; Opportunities for Further Research"
      },
      {
        "source": "S-1102",
        "supports": "work-budget proposal; a proof cannot discover a datacenter that was never declared (provider proposal)",
        "locator": "blog post"
      }
    ],
    "concepts": [
      "K-0016",
      "K-0003",
      "K-0020",
      "K-0023"
    ],
    "order": 10,
    "type": "claim",
    "url": "https://trustbutveri.fyi/claims/no-undeclared-compute/",
    "source_file": "content/claims/no-undeclared-compute.md",
    "flags_all": [
      "ai-drafted"
    ],
    "body_markdown": "## Why it matters\nChecks on declared hardware say nothing about hardware that was never declared.\n\n- **RAND's framework** gives this its own goal: verifying that there are no undeclared uses of large-scale AI compute [[S-0002]]. It splits the goal into no undeclared use of declared clusters, and no undeclared clusters, whether inside known data centres or standalone [[S-0002]].\n- **Shavit's framework** depends on the same property. Without chip-ownership verification, a prover might covertly acquire a large quantity of chips and train on them without ever notifying the verifier [[S-0029]].\n- **Wasil and colleagues** list unauthorised data centres as one of two main violation types [[S-0062]].\n- **A draft international agreement** relies on a combination of supply-chain tracking, mandatory reporting, state intelligence, open-source intelligence, power monitoring, challenge inspections and whistleblowers to locate chips [[S-0063]].\n\n## Why it is hard\nThe claim asserts absence. The Oxford Martin report observes that demonstrating the existence of an object or process is often straightforward compared with demonstrating its non-existence [[S-0004]].\n\n- **Hidden facilities.** Scher and Thiergart judge that detecting covert data centres may be difficult, because AI compute may be hidden among other compute or in secret facilities [[S-0005]]. They see whistleblowers and intelligence as possible means of detection [[S-0005]]. Sastry and colleagues note that large training facilities are visible because of their size and power demands, and that hiding them underground would likely increase cost significantly [[S-0053]].\n- **Limits of each detection method.** Wasil and colleagues note that data centres could be concealed underground or camouflaged from satellite imagery, and that energy use can be disguised as other high-energy activity [[S-0062]]. Customs data is less useful against domestic chip production, and financial intelligence must separate illicit purchases from many legitimate ones [[S-0062]]. Whistleblowers may be deterred by fear of retaliation [[S-0062]].\n- **The existing stock.** Shavit notes that many chips already sold lack the security features his framework needs and may not be locatable by governments [[S-0029]]. A 2026 analysis of TEE-based monitoring notes the difficulty of verifying that workload declarations are complete and of forming tight bounds on unknown compute [[S-0014]].\n- **The threshold.** RAND's framework focuses on clusters with the computing power of thousands of high-end chips, while noting it is not clear that frontier AI deployment must happen at scale to be dangerous [[S-0002]]. Sastry and colleagues caution that low-compute narrow models can have dangerous capabilities, and that more viable decentralised training could undermine the detectability of compute [[S-0053]].",
    "body_text": "Why it matters Checks on declared hardware say nothing about hardware that was never declared. - RAND's framework gives this its own goal: verifying that there are no undeclared uses of large-scale AI compute [S-0002]. It splits the goal into no undeclared use of declared clusters, and no undeclared clusters, whether inside known data centres or standalone [S-0002]. - Shavit's framework depends on the same property. Without chip-ownership verification, a prover might covertly acquire a large quantity of chips and train on them without ever notifying the verifier [S-0029]. - Wasil and colleagues list unauthorised data centres as one of two main violation types [S-0062]. - A draft international agreement relies on a combination of supply-chain tracking, mandatory reporting, state intelligence, open-source intelligence, power monitoring, challenge inspections and whistleblowers to locate chips [S-0063]. Why it is hard The claim asserts absence. The Oxford Martin report observes that demonstrating the existence of an object or process is often straightforward compared with demonstrating its non-existence [S-0004]. - Hidden facilities. Scher and Thiergart judge that detecting covert data centres may be difficult, because AI compute may be hidden among other compute or in secret facilities [S-0005]. They see whistleblowers and intelligence as possible means of detection [S-0005]. Sastry and colleagues note that large training facilities are visible because of their size and power demands, and that hiding them underground would likely increase cost significantly [S-0053]. - Limits of each detection method. Wasil and colleagues note that data centres could be concealed underground or camouflaged from satellite imagery, and that energy use can be disguised as other high-energy activity [S-0062]. Customs data is less useful against domestic chip production, and financial intelligence must separate illicit purchases from many legitimate ones [S-0062]. Whistleblowers may be deterred by fear of retaliation [S-0062]. - The existing stock. Shavit notes that many chips already sold lack the security features his framework needs and may not be locatable by governments [S-0029]. A 2026 analysis of TEE-based monitoring notes the difficulty of verifying that workload declarations are complete and of forming tight bounds on unknown compute [S-0014]. - The threshold. RAND's framework focuses on clusters with the computing power of thousands of high-end chips, while noting it is not clear that frontier AI deployment must happen at scale to be dangerous [S-0002]. Sastry and colleagues caution that low-compute narrow models can have dangerous capabilities, and that more viable decentralised training could undermine the detectability of compute [S-0053].",
    "addressed_by": [
      {
        "id": "M-0018",
        "title": "Chip location verification",
        "url": "https://trustbutveri.fyi/mechanisms/chip-location-verification/",
        "role": "supporting",
        "note": "Can flag enrolled chips that stop responding or answer from outside declared regions; says nothing about chips outside the scheme."
      },
      {
        "id": "M-0019",
        "title": "Chip registries and manufacturing records",
        "url": "https://trustbutveri.fyi/mechanisms/chip-registries-and-manufacturing-records/",
        "role": "supporting",
        "note": "Supports checks that recorded chips have not been assembled into undeclared clusters."
      },
      {
        "id": "M-0002",
        "title": "Deterministic and bit-exact inference",
        "url": "https://trustbutveri.fyi/mechanisms/deterministic-inference/",
        "role": "supporting",
        "note": "Unreported batch elements alter the numerics, so covert computation inside batches becomes detectable (S-0020)."
      },
      {
        "id": "M-0010",
        "title": "On-chip telemetry from timing, memory and performance counters",
        "url": "https://trustbutveri.fyi/mechanisms/on-chip-telemetry/",
        "role": "supporting",
        "note": "Contention from undeclared co-running workloads shifts challenge timing (S-0033); coverage of other chips needs other mechanisms."
      },
      {
        "id": "M-0007",
        "title": "Proofs of useful work and resource exhaustion",
        "url": "https://trustbutveri.fyi/mechanisms/proofs-of-useful-work/",
        "role": "primary",
        "note": "On declared hardware only: bounds capacity left for unmonitored work; cannot find undeclared facilities."
      },
      {
        "id": "M-0020",
        "title": "Remote detection of data centres",
        "url": "https://trustbutveri.fyi/mechanisms/remote-detection-of-data-centres/",
        "role": "primary",
        "note": "Searches for large facilities that have not been declared."
      },
      {
        "id": "I-0012",
        "title": "Low-trust AI compute verification system overview",
        "url": "https://trustbutveri.fyi/implementations/low-trust-compute-verification-system-overview/",
        "role": "supporting",
        "note": "Memory challenges and resource accounting are proposed against hidden workloads."
      },
      {
        "id": "I-0004",
        "title": "Pearl proof-of-useful-work blockchain",
        "url": "https://trustbutveri.fyi/implementations/pearl-proof-of-useful-work/",
        "role": "supporting",
        "note": "Proves matrix-multiplication work for consensus; not applied to bounding the spare capacity of declared hardware."
      }
    ],
    "referenced_by": [
      {
        "id": "M-0018",
        "title": "Chip location verification",
        "url": "https://trustbutveri.fyi/mechanisms/chip-location-verification/"
      },
      {
        "id": "M-0019",
        "title": "Chip registries and manufacturing records",
        "url": "https://trustbutveri.fyi/mechanisms/chip-registries-and-manufacturing-records/"
      },
      {
        "id": "M-0002",
        "title": "Deterministic and bit-exact inference",
        "url": "https://trustbutveri.fyi/mechanisms/deterministic-inference/"
      },
      {
        "id": "M-0010",
        "title": "On-chip telemetry from timing, memory and performance counters",
        "url": "https://trustbutveri.fyi/mechanisms/on-chip-telemetry/"
      },
      {
        "id": "M-0007",
        "title": "Proofs of useful work and resource exhaustion",
        "url": "https://trustbutveri.fyi/mechanisms/proofs-of-useful-work/"
      },
      {
        "id": "M-0020",
        "title": "Remote detection of data centres",
        "url": "https://trustbutveri.fyi/mechanisms/remote-detection-of-data-centres/"
      },
      {
        "id": "I-0012",
        "title": "Low-trust AI compute verification system overview",
        "url": "https://trustbutveri.fyi/implementations/low-trust-compute-verification-system-overview/"
      },
      {
        "id": "I-0004",
        "title": "Pearl proof-of-useful-work blockchain",
        "url": "https://trustbutveri.fyi/implementations/pearl-proof-of-useful-work/"
      },
      {
        "id": "C-0001",
        "title": "Compute stock is at most a declared amount",
        "url": "https://trustbutveri.fyi/claims/compute-stock-is-bounded/"
      },
      {
        "id": "C-0007",
        "title": "A training run stayed within declared limits",
        "url": "https://trustbutveri.fyi/claims/training-within-declared-limits/"
      },
      {
        "id": "K-0003",
        "title": "Positive and negative claims",
        "url": "https://trustbutveri.fyi/concepts/positive-and-negative-claims/"
      }
    ]
  }
}