Chips are where they are declared to be
Specific AI chips are physically located at the sites a party has declared, throughout the declared period.
Location claims underpin export controls and chip-tracking proposals. If each chip's location can be checked, a registry of declared sites becomes enforceable and diversion of chips to undeclared facilities becomes detectable. The claim concerns specific devices and can be tested positively, which makes it more tractable than proving that no chips exist elsewhere. The main technical approach has a chip answer timed challenges from trusted servers, so that the delay bounds its distance from them. A rudimentary prototype on NVIDIA H100 chips has been reported with one published result and no systematic measurements. NVIDIA is reported to be developing a similar scheme that uses its own servers. Physical inspection and supply-chain records complement the approach. Known weaknesses are extraction of the chip's private key, which would let another device answer on its behalf, modification of the chip hardware, and limited reach into chips already in circulation.
Chip location is one of the more tractable claims, because it concerns known devices and can be checked positively. Every publicly described location scheme is still proposed (R1), however.
Chip location verification (R1) times a chip's signed replies to trusted servers, so that signal delay bounds its distance from them 1 2. Lucid's sovereignty certificates (R1) are a draft specification of this approach 10. Chip registries (R1) supply the declared locations to test. Guarantee processors (R1) could automate checks of approximate chip location, and their designers want them to be retrofittable to existing chip and server designs 11.
An IAPS issue brief shows a single result from a rudimentary prototype on NVIDIA H100 chips: a landmark in Singapore bounding a chip in Singapore to within 300 miles 7. No systematic measurements, error rates or code have been published. NVIDIA has said that it is developing delay-based location verification using its own servers 8. It has published no design or results, and the fleet-management software it has announced is opt-in 9.
The chip's private key must not be extractable, or another device can answer for it 2. Sources differ on coverage: Wasil and colleagues see location tracking as limited to newly produced chips 3, while Brass and Aarne expect that the H100's trusted execution environment could implement it 6. A verified location says nothing about what a chip computes, so proposals pair it with checks on use 4.
Mechanisms
- R1Chip location verificationprimaryBounds how far a responding chip can be from trusted landmark servers at the time of the check.
- Certifies a bounded region in which an attested workload's platform was running at a given time.
- Records declared locations, which inspections or location checks can test.
- Automated verification of approximate chip location 1; see Chip location verification.
- Speed-of-light bounds on signed challenge round trips underlie delay-based location checks; see Chip location verification.
Why it matters
Proposals use chip location in three ways.
- Export controls. High-end data-centre AI chips are subject to US export controls, but the Open Problems survey describes them as at present straightforward to smuggle 1. It names as a key technical problem that a chip's location or owner cannot currently be known after export 1. Verified location could also help cloud users check that their data is processed in line with local data-processing laws 1.
- International agreements. Wasil and colleagues list chip location tracking, using unique identifiers and tracking mechanisms built into chips, among the hardware-dependent methods for verifying agreements 3. A draft international agreement requires parties to declare chip locations and to keep large concentrations of chips in monitored facilities where inspectors have ongoing physical access 4.
- A base for broader claims. Scher and Thiergart treat locating AI compute as one of their main verification goals 2. They favour tracking chips over trying to detect secret data centres, and propose locating chips at an initial point in time and then keeping them monitored 2. The Open Problems survey also calls for methods to verify that a large number of chips are co-located in a single data centre 1.
Why it is hard
The main technical proposal is delay-based. A chip exchanges timed messages with a network of trusted servers, and the measured latencies constrain where it can be 1. Scher and Thiergart describe AI chips using time-based pings to servers around the world to locate themselves 2. An IAPS issue brief from May 2025, which summarises a 2024 report by Brass and Aarne, states that a rudimentary version has been prototyped on NVIDIA H100 chips 7. It shows one result: a landmark in Singapore verifying that a chip in Singapore is within 300 miles of Singapore 7.
Avellar and Grunewald report, citing Reuters reporting from December 2025, that NVIDIA has confirmed it is developing location verification that estimates a chip's location from communication delays with NVIDIA-run servers 8. NVIDIA's own announcement from that month describes an opt-in fleet-management service that customers install and that reports read-only telemetry 9. The announcement states that NVIDIA GPUs do not have hardware tracking technology, kill switches or backdoors 9.
- Binding to the physical chip. Scher and Thiergart identify the main security issue as ensuring that a chip's private key cannot be extracted 2. Extraction would let other chips pretend to be the chip in question, so its location could be spoofed 2. Wasil and colleagues list modifying AI chip hardware and spoofing location as evasion techniques, and note that sophisticated actors may try to disable tracking 3.
- Coverage. Wasil and colleagues note that chip location tracking is limited to newly produced chips and requires agreements on manufacturing standards 3. Brass and Aarne, by contrast, expect that the H100's trusted execution environment could be used to implement location attestation 6. For chips without such features, location must be established by other means, such as physical inspection against a directory of chip serial numbers and owners 5.
- Scope. A verified location says where a chip is, not what it is computing or who controls it. Proposals therefore pair location with verification of chip use 4, which on this site falls under Declared hardware is idle or shut down and This compute runs inference, not training.
Sources
- AA. Reuel et al. (2025). Open Problems in Technical AI Governance. Transactions on Machine Learning Research. Source recordSupports: export-controlled chips straightforward to smuggle; location and owner unknowable after export; data-processing laws; verifiable latencies to trusted servers; co-location · §5.2.1
- BA. Scher & L. Thiergart (2025). Mechanisms to Verify International Agreements About AI Development. arXiv. Source recordSupports: location as a verification goal; time-based ping location attestation; private-key extraction enables spoofing; locate chips early and keep them monitored · Verifying the location of AI compute; on-chip mechanisms
- BA. R. Wasil et al. (2024). Verification methods for international AI agreements. arXiv. Source recordSupports: chip location tracking via unique identifiers; evasion by hardware modification or location spoofing; limited to new chips; needs manufacturing agreements · Hardware-dependent methods; Table 1; Figure 4
- BA. Scher et al. (2025). An International Agreement to Prevent the Premature Creation of Artificial Superintelligence. Machine Intelligence Research Institute. Source recordSupports: declaration of chip locations; monitored facilities; inspectors with ongoing physical access; chip use verification · §4; Articles V and VII (as summarised)
- BY. Shavit (2023). What does it take to catch a Chinchilla? Verifying Rules on Large-Scale Neural Network Training via Compute Monitoring. arXiv. Source recordSupports: chip owner directory with serial numbers; physical inspection of sampled chips · §3; §5
- BA. Brass & O. Aarne (2024). Location Verification for AI Chips. Institute for AI Policy and Strategy. Source recordSupports: H100 trusted execution environment could likely implement location attestation · Proposed Solution Requirements
- BA. Brass & O. Aarne (2025). Location Verification for AI Chips (issue brief). Institute for AI Policy and Strategy. Source recordSupports: rudimentary location-verification prototype on NVIDIA H100 chips (builder not named); single Singapore result within 300 miles; summarises Brass and Aarne's 2024 report · issue brief, pp. 1-2
- BB. Avellar & E. Grunewald (2026). Near-Term Verification Methods for AI Chip Exports. arXiv. Source recordSupports: NVIDIA confirmed developing delay-based location verification with NVIDIA-run servers (citing Reuters, December 2025) · §1.6
- BNVIDIA (2025). Opt-In NVIDIA Software Enables Data Center Fleet Management. NVIDIA Blog. Source recordSupports: NVIDIA's opt-in, customer-installed fleet-management service with read-only telemetry; NVIDIA's statement that its GPUs lack hardware tracking, kill switches and backdoors (provider self-description) · blog post
- BSovereignty Certificates Working Group (2025). Sovereignty Certificates: draft specification, version 0.1.0. GitHub (Lucid-Computing/sovereignty-certificate-specification). Source recordSupports: draft specification for location (sovereignty) certificates · specification v0.1.0
- BJ. Petrie et al. (2025). Flexible Hardware-Enabled Guarantees for AI Compute. arXiv. Source recordSupports: flexHEG could enable automated verification of approximate chip location; designs should be retrofittable on existing chip and server designs · How FlexHEGs Could Address Risks (Malicious Use); Recommended Areas of Technical Research