Claim · Negative

Compute stock is at most a declared amount

A party holds no more AI-relevant compute, counted in chips or equivalent capacity, than the total it has declared.

Many proposed AI agreements start from an inventory: each party declares how many AI chips it holds, and others check that the real total is no larger. A bounded stock caps how much training or inference a party could run in secret, and anchors other checks, such as monitoring how chips are used. The claim is negative, which makes it hard to verify. Millions of AI-relevant chips already exist without central tracking, and a party could acquire or build chips outside any registry. Proposals combine monitoring of the chip supply chain from fabrication onward, registries of chips and their owners, inspections, and intelligence methods such as customs and financial data. Supply-chain tracking can reach newly produced chips; the existing stock is the main gap.

State of verificationeditors' synthesis

No mechanism can yet bound a party's chip stock. Every approach is proposed (R1), and chip tracking would reach new production far better than chips already in circulation.

Chip registries and manufacturing records (R1) would follow each chip from the fab to its owner, so that inspectors can check a sample against the declared records 1. Remote detection of data centres (R1) estimates the power capacity of large facilities from equipment visible outside 7. Performance throttling and licensing (R1) would cap the work that declared chips can do 8.

Apart from public estimates of the power capacity of known large facilities 7, only designs and policy analyses are public. No chip registry has been built for verification. The concentrated chip supply chain is one reason the sources treat new production as trackable 2 1.

Millions of AI-relevant chips already exist with no central tracking 4. Domestic chip manufacture and older chips are listed as evasion routes 5. Draft agreements therefore pair technical measures with intelligence, inspections and whistleblowers 3.

Mechanisms

Why it matters

An accurate chip count underpins other checks on compute. Proposals rely on it in several ways:

  • Shavit's monitoring framework has three stages: on-chip logging, proofs about training runs, and monitoring of the chip supply chain 1. The third stage exists so that no actor can avoid discovery by amassing a large quantity of untracked chips 1. Without it, a prover could covertly acquire chips and train on them without ever notifying the verifier, bypassing checks on the chips it did declare 1.
  • Sastry and colleagues describe AI-relevant compute as detectable, excludable and quantifiable, and produced through an extremely concentrated supply chain 2. They list an international AI chip registry among possible mechanisms for regulatory visibility 2.
  • A draft international agreement would prohibit concentrations of more than 16 H100-equivalents outside monitored facilities 3. It would consolidate existing chips into those facilities and track new production 3. Chips would be located through supply-chain tracking, mandatory reporting, intelligence gathering, open-source intelligence, power monitoring, challenge inspections and whistleblowers 3.
  • Scher and Thiergart argue for locating AI chips at an initial point in time and then keeping them monitored, rather than relying on detecting secret data centres later 4.

Why it is hard

The claim is negative: it asserts that no chips exist beyond the declared total.

  • The existing stock. Shavit noted in 2023 that hundreds of thousands of ML chips had already been sold, many lacking the security features his framework needs and possibly not locatable by governments 1. Scher and Thiergart write that millions of AI-relevant chips already exist with no central tracking, which could make an initial inventory difficult 4.
  • Tracking must start at the fab. Shavit's design monitors the small number of fabrication facilities that make leading-edge chips 1. It records each chip's burned-in serial number in a directory of chip owners, kept up to date when chips are resold or damaged 1. Responsibility for any missing chip precursors lies with the most recent holder 1.
  • Supporting methods have gaps. Wasil and colleagues note that customs data is less useful against countries that can manufacture components domestically, and that financial intelligence is limited because many hardware purchases have legitimate uses 5. Inspections of chip fabrication plants are resource-intensive and put intellectual property at risk 5. The same authors list local chip manufacture and the use of older chips as evasion routes, and note that chip location tracking would apply only to new chips 5.
  • Chips are not a fixed unit of capacity. RAND's framework counts a cluster as large-scale if it has the computing power of thousands of high-end AI chips controlled by a single entity 6. Sastry and colleagues caution that algorithmic progress can reduce the compute needed for a given capability, and that decentralised training could undermine the detectability of compute 2.

The claim is closely tied to There is no undeclared relevant compute, which asks whether any compute lies outside the declared stock, and to Chips are where they are declared to be, which asks whether declared chips are where they are said to be.

Sources

  1. BY. Shavit (2023). What does it take to catch a Chinchilla? Verifying Rules on Large-Scale Neural Network Training via Compute Monitoring. arXiv. Source recordSupports: supply-chain monitoring to prevent amassing untracked chips; chip owner directory, sampled inspection and chain of custody; many existing chips lack features and may not be locatable · abstract; §3; §5
  2. BG. Sastry et al. (2024). Computing Power and the Governance of Artificial Intelligence. arXiv. Source recordSupports: compute is detectable, excludable and quantifiable with a concentrated supply chain; international chip registry listed; algorithmic progress and decentralised training · abstract; §§ on properties of compute and visibility mechanisms; limitations
  3. BA. Scher et al. (2025). An International Agreement to Prevent the Premature Creation of Artificial Superintelligence. Machine Intelligence Research Institute. Source recordSupports: chip consolidation into monitored facilities; >16 H100-equivalents only in monitored facilities; methods for locating chips; production monitoring · §4; Articles V–VI (as summarised)
  4. BA. Scher & L. Thiergart (2025). Mechanisms to Verify International Agreements About AI Development. arXiv. Source recordSupports: millions of AI-relevant chips without central tracking; locate chips early then keep them monitored · Verifying the location of AI compute
  5. BA. R. Wasil et al. (2024). Verification methods for international AI agreements. arXiv. Source recordSupports: customs data, financial intelligence and fab inspections; limits and evasions (domestic manufacture, older chips); chip location tracking limited to new chips · Verification methods; Table 1; Figures 2–4
  6. BM. Baker et al. (2025). Verifying International Agreements on AI: Six Layers of Verification for Rules on Large-Scale AI Development and Deployment. RAND Corporation. Source recordSupports: large-scale defined as computing power of thousands of high-end AI chips under a single entity · §2.2
  7. CEpoch AI (2025). Introducing the Frontier Data Centers Hub. Epoch AI. Source recordSupports: power capacity of known large data centres inferred from visible cooling equipment · methodology
  8. BG. Kulp et al. (2024). Hardware-Enabled Governance Mechanisms: Developing Technical Solutions to Exempt Items Otherwise Classified Under Export Control Classification Numbers 3A090 and 4A090. RAND Corporation. Source recordSupports: offline licensing: a renewable licence grants a compute budget, after which the chip refuses or slows the relevant operations · p. viii