# AI verification proposal

A proposal built with the Proposal Explorer of the AI Verification Tech Map (https://trustbutveri.fyi/), from its records of 2026-10-08. Interactive version: https://trustbutveri.fyi/explorer/?claims=C-0002&goal=G-0006

How to read it: a claim is something one party wants to verify about another's AI hardware or software. A mechanism is a general technique for verifying claims; it is "aimed at" a claim when that is its direct purpose, and "supporting" when it contributes without being aimed at it. A claim is addressed when a mechanism in the proposal is aimed at it and is not excluded by the filters; addressed does not mean verified, so check that mechanism's readiness and open flaws. Readiness levels R0 to R4 describe one record's public evidence for its assessed use and are never combined. Definitions: https://trustbutveri.fyi/about/methodology/ (roles, properties and flaws) and https://trustbutveri.fyi/about/readiness/ (readiness levels).

## Goal

The proposal is for the goal "Enforce chip export controls" (https://trustbutveri.fyi/goals/enforce-chip-export-controls/): Keep export-controlled AI chips at the destinations they were authorised for. The links from the goal to claims are the editors' judgment. Direct: The claim states part of what the goal requires. The goal cannot be verified without it. Supporting: Verifying the claim makes a direct claim easier to check or a violation less useful. The goal could be verified without it.

- Direct: Chips are where they are declared to be. End-location verification asks whether controlled chips remain in their authorised locations or jurisdictions. Reuel and colleagues call it a key technical problem for enforcement that a chip's location cannot currently be known after export. (Sources: B. Avellar & E. Grunewald 2026; A. Reuel et al. 2025.)

Outside this map, the goal also needs:

- End-user and end-use verification. Avellar and Grunewald also cover end-user verification, such as know-your-customer checks, and end-use verification, such as audits of compute provisioning. This map has no records for these compliance processes. (Sources: B. Avellar & E. Grunewald 2026.)

## Filters

Filters apply to mechanisms only and describe the setting the proposal is for.

None set. Every mechanism on the map was available.

## Claims

### 1. Chips are where they are declared to be

Specific AI chips are physically located at the sites a party has declared, throughout the declared period. ([Chips are where they are declared to be](https://trustbutveri.fyi/claims/chips-are-where-declared/))

Status: unaddressed. No mechanism in the proposal addresses it.


## Mechanisms

No mechanisms chosen.

## Possible additions

Mechanisms on the map, not in the proposal, that the records connect to an unaddressed or partly addressed claim, an open flaw or a dependency. Pointers, not recommendations: each brings its own readiness level and flaws, and none is claimed to close a flaw.

- **Chip location verification** (R1 Proposed, assessed for bounding how far a chip is from trusted landmark servers when checked)
  - Aimed at the claim "Chips are where they are declared to be", which is unaddressed.

