There is no undeclared relevant compute
A party controls no AI-relevant computing hardware or facilities, above an agreed threshold, beyond those it has declared.
Every other check on declared hardware can be sidestepped if a party runs prohibited work on hardware it never declared. Verifying that no such compute exists is therefore central to many proposed AI agreements. It is also among the hardest claims to establish, because it asserts an absence across a whole country or organisation, and demonstrating non-existence is generally harder than demonstrating existence. No single technique establishes it. Proposals combine tracking chips from manufacture, so that the declared stock is complete; searching for undeclared facilities with satellite imagery, energy data, customs and financial intelligence; and human sources such as whistleblowers and inspections. Each has documented evasions, and the achievable assurance depends on how much compute a meaningful violation would require.
This broadest of negative claims cannot rest on one method, since no single verification method is foolproof 5. The two mechanisms built primarily for it, remote detection of data centres and proofs of useful work, are proposed (R1), as are the chip registries and location checks that support it. RAND splits the claim into undeclared use of declared clusters, which reduces to claims such as Declared hardware is idle or shut down and This compute runs inference, not training, and undeclared clusters 1.
One strategy makes the declared stock complete from the start, through chip registries and location verification. Scher and Thiergart favour this strategy 4. The other searches for what was missed, through remote detection of data centres and other national technical means 5. Proofs of useful work would leave declared hardware little spare capacity, but cannot find a facility that was never declared 10.
Satellite imagery, permits and utility filings already track the construction of known large facilities, but automated data-centre detection remains primarily conceptual 9.
Chips sold before tracking began may not be locatable 3, and facilities can be hidden underground or camouflaged 5. It is unclear how small undeclared compute can be and still matter 1 7. Draft agreements therefore pair technical measures with intelligence, challenge inspections and whistleblowers 6.
Mechanisms
- On declared hardware only: bounds capacity left for unmonitored work; cannot find undeclared facilities.
- Searches for large facilities that have not been declared.
- R2Deterministic and bit-exact inferencesupportingUnreported batch elements alter the numerics, so covert computation inside batches becomes detectable 1.
- Contention from undeclared co-running workloads shifts challenge timing 1; coverage of other chips needs other mechanisms.
- R2Pearl proof-of-useful-work blockchainsupportingProves matrix-multiplication work for consensus; not applied to bounding the spare capacity of declared hardware.
- R1Chip location verificationsupportingCan flag enrolled chips that stop responding or answer from outside declared regions; says nothing about chips outside the scheme.
- Supports checks that recorded chips have not been assembled into undeclared clusters.
- Memory challenges and resource accounting are proposed against hidden workloads.
Why it matters
Checks on declared hardware say nothing about hardware that was never declared.
- RAND's framework gives this its own goal: verifying that there are no undeclared uses of large-scale AI compute 1. It splits the goal into no undeclared use of declared clusters, and no undeclared clusters, whether inside known data centres or standalone 1.
- Shavit's framework depends on the same property. Without chip-ownership verification, a prover might covertly acquire a large quantity of chips and train on them without ever notifying the verifier 3.
- Wasil and colleagues list unauthorised data centres as one of two main violation types 5.
- A draft international agreement relies on a combination of supply-chain tracking, mandatory reporting, state intelligence, open-source intelligence, power monitoring, challenge inspections and whistleblowers to locate chips 6.
Why it is hard
The claim asserts absence. The Oxford Martin report observes that demonstrating the existence of an object or process is often straightforward compared with demonstrating its non-existence 2.
- Hidden facilities. Scher and Thiergart judge that detecting covert data centres may be difficult, because AI compute may be hidden among other compute or in secret facilities 4. They see whistleblowers and intelligence as possible means of detection 4. Sastry and colleagues note that large training facilities are visible because of their size and power demands, and that hiding them underground would likely increase cost significantly 7.
- Limits of each detection method. Wasil and colleagues note that data centres could be concealed underground or camouflaged from satellite imagery, and that energy use can be disguised as other high-energy activity 5. Customs data is less useful against domestic chip production, and financial intelligence must separate illicit purchases from many legitimate ones 5. Whistleblowers may be deterred by fear of retaliation 5.
- The existing stock. Shavit notes that many chips already sold lack the security features his framework needs and may not be locatable by governments 3. A 2026 analysis of TEE-based monitoring notes the difficulty of verifying that workload declarations are complete and of forming tight bounds on unknown compute 8.
- The threshold. RAND's framework focuses on clusters with the computing power of thousands of high-end chips, while noting it is not clear that frontier AI deployment must happen at scale to be dangerous 1. Sastry and colleagues caution that low-compute narrow models can have dangerous capabilities, and that more viable decentralised training could undermine the detectability of compute 7.
Sources
- BM. Baker et al. (2025). Verifying International Agreements on AI: Six Layers of Verification for Rules on Large-Scale AI Development and Deployment. RAND Corporation. Source recordSupports: Subgoal 2 (2.A, 2.B, 2.B.1, 2.B.2); focus on large-scale clusters; unclear whether dangerous deployment requires scale; personnel and intelligence layers · §2.2; §3.2, Figure 4; §4
- BB. Harack et al. (2025). Verification for International AI Governance. Oxford Martin AI Governance Initiative. Source recordSupports: existence easier to demonstrate than non-existence · p. 31
- BY. Shavit (2023). What does it take to catch a Chinchilla? Verifying Rules on Large-Scale Neural Network Training via Compute Monitoring. arXiv. Source recordSupports: sampling fails if prover amasses untracked chips; existing chips possibly not locatable · abstract; §5
- BA. Scher & L. Thiergart (2025). Mechanisms to Verify International Agreements About AI Development. arXiv. Source recordSupports: covert data centres may be hard to detect; tracking chips favoured; intelligence and whistleblowers as complements · Verifying the location of AI compute (analysis)
- BA. R. Wasil et al. (2024). Verification methods for international AI agreements. arXiv. Source recordSupports: unauthorised data centres as a violation type; no single method foolproof; national technical means and their limitations and evasions · What to verify; Table 1; Figures 2–4
- BA. Scher et al. (2025). An International Agreement to Prevent the Premature Creation of Artificial Superintelligence. Machine Intelligence Research Institute. Source recordSupports: locating chips through supply-chain tracking, reporting, intelligence, OSINT, power monitoring, challenge inspections and whistleblowers · §4; Articles V and X (as summarised)
- BG. Sastry et al. (2024). Computing Power and the Governance of Artificial Intelligence. arXiv. Source recordSupports: detectability of large facilities; low-compute narrow models; decentralised training; underground data centres raise cost · properties of compute; limitations
- CGloria Z (2026). On TEEs for Privacy-Preserving Monitoring in AI Governance. MIRI Technical Governance Team. Source recordSupports: difficulty of verifying completeness of workload declarations and bounding unknown compute · Limitations
- BC. Krawec (2026). Tracking Hyperscale AI Data Center Growth with Satellite Imagery. Federation of American Scientists. Source recordSupports: satellite imagery, permits and utility filings track known facilities; automated data-centre detection primarily conceptual · Methodology; Opportunities for Further Research
- CAttestable (2026). Pacing AI Requires Proof. Attestable blog. Source recordSupports: work-budget proposal; a proof cannot discover a datacenter that was never declared (provider proposal) · blog post