Claim · Negative

Declared hardware is idle or shut down

Specified AI chips or facilities are not performing computation, or are powered off, throughout a declared period.

Some agreement designs would pause certain activities by keeping declared chips switched off or idle, or hold a reserve of compute that is verified not to be in use. Verifying idleness would let a party show it is not using hardware it still owns. It is a negative claim, but a comparatively simple one: chips need power to compute, so a facility's power draw, knowledge of on-site generation and possibly thermal imaging could show whether hardware is running. One analysis expects this to be verifiable with less invasive methods than those needed to check what running chips compute. The difficulties are binding and coverage: showing that the monitored facility holds the declared chips, and obtaining reliable power data that cannot be masked. On-chip telemetry and hardware licensing could add chip-level evidence or enforcement.

State of verificationeditors' synthesis

Idleness is one of the more approachable negative claims, because computing needs power and leaves physical traces. Evidence would come from facility power data and from on-chip mechanisms that can tell whether a chip is busy; of these, only on-chip telemetry is demonstrated (R2), and that for classifying workloads rather than for idleness.

Power draw, knowledge of on-site generation and possibly thermal imaging could show that a facility's chips are unpowered 1. On-chip telemetry (R2) and timed challenges (R1) could show whether a declared chip is busy. Licensing and throttling (R1) would make chips refuse or slow work once a licensed budget is spent 5. Proofs of useful work (R1) instead keep declared hardware provably busy with agreed work 8.

Energy monitoring is unproven in practice and open to masking 2. GPU timing and memory measurements correlate with compute activity even when host and device are untrusted 7.

A dark facility shows only that the hardware inside it is idle, so the claim depends on knowing where the declared chips are (Chips are where they are declared to be). Where chips must stay powered for permitted work, the claim becomes a bound on use (This compute runs inference, not training, A training run stayed within declared limits).

Mechanisms

Why it matters

Idleness lets a party show that hardware it still owns is not in use. Proposals use it in three ways:

  • Pausing large training runs. Scher and Thiergart observe that a data-centre operator can claim its chips are not being used in a large training run if the chips are not receiving the power they need to operate 1. They add that this can likely be verified with less invasive methods, such as the data centre's power draw, knowledge of on-site backup power generation, or possibly thermal imaging 1.
  • Holding compute in reserve. The AI 2040 verification plan suggests a small compute bank, verified not to be in use during an agreement, as a way to reduce the incentive to withdraw from it 3.
  • Monitoring energy use. Energy monitoring is one of the national technical means Wasil and colleagues consider for detecting unauthorised facilities, by analysing power consumption and converting energy estimates into an approximate count of operations 2.

Why it is hard

The claim is negative: it asserts that no computation takes place.

  • Power data describes a facility, not a chip. A verifier must know about every power source, including on-site generation 1. Wasil and colleagues note that energy monitoring is unproven in practice, that energy use may be disguised as other high-energy activity, and that detailed consumption data is hard to obtain 2. They list masking a data centre's energy use and siting a data centre at a power plant as evasion techniques 2.
  • Binding. A dark building shows that the chips inside it are idle, but not that the declared chips are the ones inside. The claim therefore depends on verifying chip location and custody, covered under Chips are where they are declared to be.
  • Chip-level evidence is immature. RAND's framework includes off-chip analog sensors, and lists estimating a workload's utilisation and associated physical signature, such as power, as a research problem 4. Monfared and colleagues report timing and memory measurements on GPUs that correlate with compute activity even when host and device are untrusted 7. One telemetry classifier detects training with 98.2% accuracy across its own corpus, falling to 43–87% on the most challenging disguised workloads held out from its training 6.
  • Hardware enforcement. RAND's offline-licensing design grants a chip a compute budget through a renewable licence; once the budget is spent, the chip would refuse the relevant operations or perform them at a much lower rate 5.

Where chips must stay powered for permitted tasks, the claim becomes a bound on use rather than idleness, and the questions of This compute runs inference, not training and A training run stayed within declared limits apply.

Sources

  1. BA. Scher & L. Thiergart (2025). Mechanisms to Verify International Agreements About AI Development. arXiv. Source recordSupports: chips without power cannot run a large training run; power draw, on-site generation and thermal imaging as less invasive verification · Verifying that known compute is not being used for a large training run
  2. BA. R. Wasil et al. (2024). Verification methods for international AI agreements. arXiv. Source recordSupports: energy monitoring to detect facilities and approximate FLOPs; unproven, can be masked, data hard to obtain; evasions · Energy monitoring; Table 1; Figure 2
  3. CR. Dean (2026). Verification Plan. AI 2040. Source recordSupports: compute bank verified not to be in use during an agreement · phase 3 (improving robustness)
  4. BM. Baker et al. (2025). Verifying International Agreements on AI: Six Layers of Verification for Rules on Large-Scale AI Development and Deployment. RAND Corporation. Source recordSupports: off-chip analog sensors; estimating utilisation and physical signature such as power as an R&D problem · §4; Table 2, Appendix A.6
  5. BG. Kulp et al. (2024). Hardware-Enabled Governance Mechanisms: Developing Technical Solutions to Exempt Items Otherwise Classified Under Export Control Classification Numbers 3A090 and 4A090. RAND Corporation. Source recordSupports: offline licensing tying chip features to a renewable licence with a compute budget · p. viii
  6. BR. Rahman & S. Tajdari (2026). Detecting Hidden ML Training With Zero-Overhead Telemetry. ICML 2026 Workshop on Technical AI Governance Research. Source recordSupports: telemetry classifier accuracy overall and on adversarially disguised workloads · abstract; §5.2
  7. BS. K. Monfared et al. (2026). Timing and Memory Telemetry on GPUs for AI Governance. arXiv. Source recordSupports: timing and memory observables that correlate with GPU compute activity when host and device are untrusted · abstract
  8. CAttestable (2026). Pacing AI Requires Proof. Attestable blog. Source recordSupports: approved work plus protocol-defined work fills a required work budget (provider proposal) · blog post