Hardware-enabled mechanism (HEM)
A governance or verification function built into AI chips or closely attached hardware, such as usage reporting, location attestation or enforced limits.
A hardware-enabled mechanism (HEM) is a governance or verification function built into AI chips or hardware attached to them, such as reporting how much compute was used and where, or enforcing limits on use 1 2.
A 2024 RAND report introduced the concept to help achieve US AI governance goals such as export controls, and analysed the threats, attack vectors and protective measures that apply to such mechanisms 1. CNAS notes that chips sold by several leading firms already have many of the security features HEMs would need 3. Proposed designs include:
- Offline licensing. Use of certain chip features is tied to a renewable licence carrying a compute budget, as in hardware performance throttling and licensing 1.
- Fixed sets. Networking is restricted so that small, fixed groups of GPUs cannot be combined into large clusters, a form of compartmentalization 1.
- Guarantee processors. An auditable processor monitors accelerator usage inside a secure enclosure that provides physical tamper protection, as in flexHEG 4.
- Verifiable reporting. HEMs could report properties of training, such as the quantity of compute used and the cluster's configuration or location 2, the aim of on-chip telemetry and chip location verification.
A central open question is whether HEMs can stay secure when an adversary has the chips in its physical possession 1.
Related
Used in
- R1Chip location verification
- R1Hardware-enabled guarantees (flexHEG) and guarantee processors
- R1Hardware performance throttling and licensing
- R2On-chip telemetry from timing, memory and performance counters⚠
- R2Workload classification from telemetry and side channels
- Declared hardware is idle or shut down
Sources
- BG. Kulp et al. (2024). Hardware-Enabled Governance Mechanisms: Developing Technical Solutions to Exempt Items Otherwise Classified Under Export Control Classification Numbers 3A090 and 4A090. RAND Corporation. Source recordSupports: introduces HEMs to help achieve US AI governance goals including export controls; threats, attack vectors and protections; offline licensing and fixed-set designs; security under an adversary's physical possession is open · abstract; pp. viii–x
- BA. O'Gara et al. (2025). Hardware-Enabled Mechanisms for Verifying Responsible AI Development. arXiv. Source recordSupports: HEMs enabling verifiable reporting of compute quantity, cluster configuration or location, and policy enforcement · abstract
- BO. Aarne et al. (2024). Secure, Governable Chips: Using On-Chip Mechanisms to Manage National Security Risks from AI & Advanced Computing. Center for a New American Security. Source recordSupports: chips sold by leading firms already have many of the needed features · summary
- BJ. Petrie et al. (2025). Flexible Hardware-Enabled Guarantees for AI Compute. arXiv. Source recordSupports: flexHEG: auditable guarantee processor monitoring accelerator usage, plus a secure enclosure providing physical tamper protection · abstract