{
  "schema_version": "1.0.0",
  "rubric_version": "1.0",
  "license": "CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/)",
  "record": {
    "id": "K-0016",
    "slug": "undeclared-compute",
    "title": "Undeclared compute",
    "aliases": [
      "dark compute",
      "hidden compute",
      "covert compute"
    ],
    "status": "draft",
    "last_reviewed": "2026-09-23",
    "review_interval_days": 90,
    "steward": null,
    "provenance": {
      "drafted_by": "ai",
      "reviewed_by": []
    },
    "risk_flags": [],
    "flags": [],
    "one_liner": "AI-relevant hardware, or uses of declared hardware, that a prover has not reported, and that verification must therefore detect or rule out.",
    "sources": [
      {
        "source": "S-0002",
        "supports": "Subgoal 2: no undeclared uses of declared clusters (2.A) and no undeclared clusters in known data centres or standalone (2.B)",
        "locator": "§3.2, Figure 4"
      },
      {
        "source": "S-0029",
        "supports": "hundreds of thousands of ML chips already sold, many lacking the required security features; supply-chain monitoring and chip-owner directory",
        "locator": "§1.2; §6; §6.1"
      },
      {
        "source": "S-0005",
        "supports": "millions of AI-relevant chips exist without central tracking; covert data centres may be hard to detect because AI compute can be hidden among other compute",
        "locator": "Verifying the location of AI compute"
      },
      {
        "source": "S-0053",
        "supports": "algorithmic efficiency and decentralized training could undermine compute detectability",
        "locator": "limitations of compute governance"
      },
      {
        "source": "S-0062",
        "supports": "national technical means (remote sensing, energy monitoring, customs, financial intelligence) and whistleblowers",
        "locator": "Verification methods; Table 1"
      },
      {
        "source": "S-0018",
        "supports": "memory wiping to remove residual capacity for hidden workloads",
        "locator": "system architecture (memory wiping)"
      }
    ],
    "related": [
      "K-0003",
      "K-0020",
      "K-0023"
    ],
    "type": "concept",
    "url": "https://trustbutveri.fyi/concepts/undeclared-compute/",
    "source_file": "content/concepts/undeclared-compute.md",
    "flags_all": [
      "ai-drafted"
    ],
    "body_markdown": "Undeclared compute is AI-relevant hardware, or use of declared hardware, that a [[K-0001|prover]] has not reported to the verifier [[S-0002]].\n\nRAND's verification framework separates two cases: undeclared uses of declared clusters, and undeclared clusters, whether inside known data centres or standalone [[S-0002]]. The problem is sharpest for hardware that predates tracking: Shavit notes that hundreds of thousands of ML chips had already been sold, many lacking the security features his framework needs [[S-0029]], and Scher and Thiergart write that millions of AI-relevant chips exist with no central tracking [[S-0005]]. They judge that covert data centres may be difficult to detect, because AI compute can be hidden among other compute [[S-0005]]. Sastry and colleagues caution that more efficient algorithms and more viable decentralized training could reduce how much compute, or how concentrated, a prohibited activity needs [[S-0053]]. Proposed responses include:\n- **Tracking hardware.** Monitoring the chip supply chain and keeping a directory of chip owners [[S-0029]], as in [[M-0019|chip registries and manufacturing records]].\n- **Finding facilities.** National technical means such as remote sensing, energy monitoring, customs data and financial intelligence, alongside whistleblowers [[S-0062]], as in [[M-0020|remote detection of data centres]].\n- **Bounding declared capacity.** Wiping memory to remove residual capacity for hidden workloads on declared hardware [[S-0018]], as in [[M-0015|memory wiping and proofs of secure erasure]].",
    "body_text": "Undeclared compute is AI-relevant hardware, or use of declared hardware, that a prover has not reported to the verifier [S-0002]. RAND's verification framework separates two cases: undeclared uses of declared clusters, and undeclared clusters, whether inside known data centres or standalone [S-0002]. The problem is sharpest for hardware that predates tracking: Shavit notes that hundreds of thousands of ML chips had already been sold, many lacking the security features his framework needs [S-0029], and Scher and Thiergart write that millions of AI-relevant chips exist with no central tracking [S-0005]. They judge that covert data centres may be difficult to detect, because AI compute can be hidden among other compute [S-0005]. Sastry and colleagues caution that more efficient algorithms and more viable decentralized training could reduce how much compute, or how concentrated, a prohibited activity needs [S-0053]. Proposed responses include: - Tracking hardware. Monitoring the chip supply chain and keeping a directory of chip owners [S-0029], as in chip registries and manufacturing records. - Finding facilities. National technical means such as remote sensing, energy monitoring, customs data and financial intelligence, alongside whistleblowers [S-0062], as in remote detection of data centres. - Bounding declared capacity. Wiping memory to remove residual capacity for hidden workloads on declared hardware [S-0018], as in memory wiping and proofs of secure erasure.",
    "referenced_by": [
      {
        "id": "M-0014",
        "title": "Bandwidth limits and compartmentalization",
        "url": "https://trustbutveri.fyi/mechanisms/bandwidth-limits-and-compartmentalization/"
      },
      {
        "id": "M-0024",
        "title": "Bounding unexplained information in outputs",
        "url": "https://trustbutveri.fyi/mechanisms/bounding-unexplained-information/"
      },
      {
        "id": "M-0019",
        "title": "Chip registries and manufacturing records",
        "url": "https://trustbutveri.fyi/mechanisms/chip-registries-and-manufacturing-records/"
      },
      {
        "id": "M-0002",
        "title": "Deterministic and bit-exact inference",
        "url": "https://trustbutveri.fyi/mechanisms/deterministic-inference/"
      },
      {
        "id": "M-0009",
        "title": "Hardware-enabled guarantees (flexHEG) and guarantee processors",
        "url": "https://trustbutveri.fyi/mechanisms/flexheg-guarantee-processors/"
      },
      {
        "id": "M-0015",
        "title": "Memory wiping and proofs of secure erasure",
        "url": "https://trustbutveri.fyi/mechanisms/memory-wiping-and-secure-erasure/"
      },
      {
        "id": "M-0010",
        "title": "On-chip telemetry from timing, memory and performance counters",
        "url": "https://trustbutveri.fyi/mechanisms/on-chip-telemetry/"
      },
      {
        "id": "M-0007",
        "title": "Proofs of useful work and resource exhaustion",
        "url": "https://trustbutveri.fyi/mechanisms/proofs-of-useful-work/"
      },
      {
        "id": "M-0020",
        "title": "Remote detection of data centres",
        "url": "https://trustbutveri.fyi/mechanisms/remote-detection-of-data-centres/"
      },
      {
        "id": "M-0003",
        "title": "Reproducible computation packets",
        "url": "https://trustbutveri.fyi/mechanisms/reproducible-computation-packets/"
      },
      {
        "id": "M-0016",
        "title": "Timed challenge-response and memory-occupation challenges",
        "url": "https://trustbutveri.fyi/mechanisms/timed-challenge-response/"
      },
      {
        "id": "M-0004",
        "title": "Zero-knowledge proofs of inference",
        "url": "https://trustbutveri.fyi/mechanisms/zk-proofs-of-inference/"
      },
      {
        "id": "I-0011",
        "title": "AI 2040 inference-only verification stack",
        "url": "https://trustbutveri.fyi/implementations/ai-2040-inference-only-verification-plan/"
      },
      {
        "id": "C-0001",
        "title": "Compute stock is at most a declared amount",
        "url": "https://trustbutveri.fyi/claims/compute-stock-is-bounded/"
      },
      {
        "id": "C-0010",
        "title": "There is no undeclared relevant compute",
        "url": "https://trustbutveri.fyi/claims/no-undeclared-compute/"
      },
      {
        "id": "K-0023",
        "title": "FLOP accounting",
        "url": "https://trustbutveri.fyi/concepts/flop-accounting/"
      },
      {
        "id": "K-0003",
        "title": "Positive and negative claims",
        "url": "https://trustbutveri.fyi/concepts/positive-and-negative-claims/"
      },
      {
        "id": "K-0012",
        "title": "Proof of space",
        "url": "https://trustbutveri.fyi/concepts/proof-of-space/"
      },
      {
        "id": "K-0011",
        "title": "Proof of (useful) work",
        "url": "https://trustbutveri.fyi/concepts/proof-of-useful-work/"
      }
    ]
  }
}