Undeclared compute
AI-relevant hardware, or uses of declared hardware, that a prover has not reported, and that verification must therefore detect or rule out.
Undeclared compute is AI-relevant hardware, or use of declared hardware, that a prover has not reported to the verifier 1.
RAND's verification framework separates two cases: undeclared uses of declared clusters, and undeclared clusters, whether inside known data centres or standalone 1. The problem is sharpest for hardware that predates tracking: Shavit notes that hundreds of thousands of ML chips had already been sold, many lacking the security features his framework needs 2, and Scher and Thiergart write that millions of AI-relevant chips exist with no central tracking 3. They judge that covert data centres may be difficult to detect, because AI compute can be hidden among other compute 3. Sastry and colleagues caution that more efficient algorithms and more viable decentralized training could reduce how much compute, or how concentrated, a prohibited activity needs 4. Proposed responses include:
- Tracking hardware. Monitoring the chip supply chain and keeping a directory of chip owners 2, as in chip registries and manufacturing records.
- Finding facilities. National technical means such as remote sensing, energy monitoring, customs data and financial intelligence, alongside whistleblowers 5, as in remote detection of data centres.
- Bounding declared capacity. Wiping memory to remove residual capacity for hidden workloads on declared hardware 6, as in memory wiping and proofs of secure erasure.
Related
Used in
- R1Bandwidth limits and compartmentalization
- R2Bounding unexplained information in outputs
- R1Chip registries and manufacturing records
- R2Deterministic and bit-exact inference
- R1Hardware-enabled guarantees (flexHEG) and guarantee processors
- R1Memory wiping and proofs of secure erasure
- R2On-chip telemetry from timing, memory and performance counters⚠
- R1Proofs of useful work and resource exhaustion
- R1Remote detection of data centres
- R1Reproducible computation packets
- R1Timed challenge-response and memory-occupation challenges
- R2Zero-knowledge proofs of inference
- R1AI 2040 inference-only verification stack
- Compute stock is at most a declared amount
- There is no undeclared relevant compute
Sources
- BM. Baker et al. (2025). Verifying International Agreements on AI: Six Layers of Verification for Rules on Large-Scale AI Development and Deployment. RAND Corporation. Source recordSupports: Subgoal 2: no undeclared uses of declared clusters (2.A) and no undeclared clusters in known data centres or standalone (2.B) · §3.2, Figure 4
- BY. Shavit (2023). What does it take to catch a Chinchilla? Verifying Rules on Large-Scale Neural Network Training via Compute Monitoring. arXiv. Source recordSupports: hundreds of thousands of ML chips already sold, many lacking the required security features; supply-chain monitoring and chip-owner directory · §1.2; §6; §6.1
- BA. Scher & L. Thiergart (2025). Mechanisms to Verify International Agreements About AI Development. arXiv. Source recordSupports: millions of AI-relevant chips exist without central tracking; covert data centres may be hard to detect because AI compute can be hidden among other compute · Verifying the location of AI compute
- BG. Sastry et al. (2024). Computing Power and the Governance of Artificial Intelligence. arXiv. Source recordSupports: algorithmic efficiency and decentralized training could undermine compute detectability · limitations of compute governance
- BA. R. Wasil et al. (2024). Verification methods for international AI agreements. arXiv. Source recordSupports: national technical means (remote sensing, energy monitoring, customs, financial intelligence) and whistleblowers · Verification methods; Table 1
- BN. Cankaya (2026). A System Overview for Near-Term, Low-Trust AI Compute Verification. Machine Intelligence Research Institute. Source recordSupports: memory wiping to remove residual capacity for hidden workloads · system architecture (memory wiping)