{
  "schema_version": "1.0.0",
  "rubric_version": "1.0",
  "license": "CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/)",
  "record": {
    "id": "K-0007",
    "slug": "hardware-enabled-mechanism",
    "title": "Hardware-enabled mechanism (HEM)",
    "aliases": [
      "HEM",
      "hardware-enabled governance mechanism",
      "on-chip mechanism"
    ],
    "status": "draft",
    "last_reviewed": "2026-09-23",
    "review_interval_days": 90,
    "steward": null,
    "provenance": {
      "drafted_by": "ai",
      "reviewed_by": []
    },
    "risk_flags": [],
    "flags": [],
    "one_liner": "A governance or verification function built into AI chips or closely attached hardware, such as usage reporting, location attestation or enforced limits.",
    "sources": [
      {
        "source": "S-0057",
        "supports": "introduces HEMs to help achieve US AI governance goals including export controls; threats, attack vectors and protections; offline licensing and fixed-set designs; security under an adversary's physical possession is open",
        "locator": "abstract; pp. viii–x"
      },
      {
        "source": "S-0006",
        "supports": "HEMs enabling verifiable reporting of compute quantity, cluster configuration or location, and policy enforcement",
        "locator": "abstract"
      },
      {
        "source": "S-0056",
        "supports": "chips sold by leading firms already have many of the needed features",
        "locator": "summary"
      },
      {
        "source": "S-0035",
        "supports": "flexHEG: auditable guarantee processor monitoring accelerator usage, plus a secure enclosure providing physical tamper protection",
        "locator": "abstract"
      }
    ],
    "related": [
      "K-0005",
      "K-0004",
      "K-0015",
      "K-0017"
    ],
    "type": "concept",
    "url": "https://trustbutveri.fyi/concepts/hardware-enabled-mechanism/",
    "source_file": "content/concepts/hardware-enabled-mechanism.md",
    "flags_all": [
      "ai-drafted"
    ],
    "body_markdown": "A hardware-enabled mechanism (HEM) is a governance or verification function built into AI chips or hardware attached to them, such as reporting how much compute was used and where, or enforcing limits on use [[S-0057]] [[S-0006]].\n\nA 2024 RAND report introduced the concept to help achieve US AI governance goals such as export controls, and analysed the threats, attack vectors and protective measures that apply to such mechanisms [[S-0057]]. CNAS notes that chips sold by several leading firms already have many of the security features HEMs would need [[S-0056]]. Proposed designs include:\n- **Offline licensing.** Use of certain chip features is tied to a renewable licence carrying a compute budget, as in [[M-0011|hardware performance throttling and licensing]] [[S-0057]].\n- **Fixed sets.** Networking is restricted so that small, fixed groups of GPUs cannot be combined into large clusters, a form of [[K-0017|compartmentalization]] [[S-0057]].\n- **Guarantee processors.** An auditable processor monitors accelerator usage inside a secure enclosure that provides physical tamper protection, as in [[M-0009|flexHEG]] [[S-0035]].\n- **Verifiable reporting.** HEMs could report properties of training, such as the quantity of compute used and the cluster's configuration or location [[S-0006]], the aim of [[M-0010|on-chip telemetry]] and [[M-0018|chip location verification]].\n\nA central open question is whether HEMs can stay secure when an adversary has the chips in its physical possession [[S-0057]].",
    "body_text": "A hardware-enabled mechanism (HEM) is a governance or verification function built into AI chips or hardware attached to them, such as reporting how much compute was used and where, or enforcing limits on use [S-0057] [S-0006]. A 2024 RAND report introduced the concept to help achieve US AI governance goals such as export controls, and analysed the threats, attack vectors and protective measures that apply to such mechanisms [S-0057]. CNAS notes that chips sold by several leading firms already have many of the security features HEMs would need [S-0056]. Proposed designs include: - Offline licensing. Use of certain chip features is tied to a renewable licence carrying a compute budget, as in hardware performance throttling and licensing [S-0057]. - Fixed sets. Networking is restricted so that small, fixed groups of GPUs cannot be combined into large clusters, a form of compartmentalization [S-0057]. - Guarantee processors. An auditable processor monitors accelerator usage inside a secure enclosure that provides physical tamper protection, as in flexHEG [S-0035]. - Verifiable reporting. HEMs could report properties of training, such as the quantity of compute used and the cluster's configuration or location [S-0006], the aim of on-chip telemetry and chip location verification. A central open question is whether HEMs can stay secure when an adversary has the chips in its physical possession [S-0057].",
    "referenced_by": [
      {
        "id": "M-0018",
        "title": "Chip location verification",
        "url": "https://trustbutveri.fyi/mechanisms/chip-location-verification/"
      },
      {
        "id": "M-0009",
        "title": "Hardware-enabled guarantees (flexHEG) and guarantee processors",
        "url": "https://trustbutveri.fyi/mechanisms/flexheg-guarantee-processors/"
      },
      {
        "id": "M-0011",
        "title": "Hardware performance throttling and licensing",
        "url": "https://trustbutveri.fyi/mechanisms/hardware-performance-throttling/"
      },
      {
        "id": "M-0010",
        "title": "On-chip telemetry from timing, memory and performance counters",
        "url": "https://trustbutveri.fyi/mechanisms/on-chip-telemetry/"
      },
      {
        "id": "M-0021",
        "title": "Workload classification from telemetry and side channels",
        "url": "https://trustbutveri.fyi/mechanisms/workload-classification-from-telemetry/"
      },
      {
        "id": "C-0003",
        "title": "Declared hardware is idle or shut down",
        "url": "https://trustbutveri.fyi/claims/declared-hardware-is-idle/"
      },
      {
        "id": "K-0005",
        "title": "Root of trust",
        "url": "https://trustbutveri.fyi/concepts/root-of-trust/"
      },
      {
        "id": "K-0015",
        "title": "Tamper evidence and tamper resistance",
        "url": "https://trustbutveri.fyi/concepts/tamper-evidence/"
      }
    ]
  }
}