Mechanism · Compute accounting & provenance
Chip registries and manufacturing records
Recording each AI chip's identity and owner from the fab onwards, and cryptographically fixing manufacturing records, so that chips can be accounted for later.
Also called AI chip registry; Chain-of-custody tracking for AI chips; Commitments to manufacturing records
Summary
A chip registry records unique identifiers for AI chips, with their owners and sometimes their locations, from manufacture to destruction. A verifier can then sample chips and check that declared chains of custody match what is physically there. A related proposal protects the foundry's own record of chip IDs by publishing a cryptographic fingerprint of it, so that later changes would show. As of September 2026 these are published designs, and no AI chip registry or record commitment is in operation. The main obstacle is institutional: someone must run the registry, and covering re-exports needs cooperation from re-exporters and foreign governments. The main weaknesses are that records cover only chips that were recorded, that documents and serial numbers can be forged, and that a commitment cannot show the records were accurate when made. A commitment shows what was made, not where it went.
R1: registry and record-commitment designs are public, but none has been built or tested.
Rubric assessment
- R1 met: Baker et al. describe an AI chip registry for ownership declarations, with sampled chain-of-custody checks from manufacture to destruction, and state the goal and assumptions 1. Avellar and Grunewald describe how a regulator could run a registry of chip ownership and use it for random return requests 2. Cankaya proposes cryptographic commitments to foundry chip-ID records 3.
- R2 not met: as of September 2026 no AI chip registry or manufacturing-record commitment has a public implementation, and no end-to-end results have been published 1 2 3. Export documentation checks are established practice, but they are not a registry, and Avellar and Grunewald rate them low in effectiveness as a verification tool 2. Ansari rates registry systems as near-term, not deployable now 5.
- A public pilot registry or published commitment to manufacturing records at realistic scale.
- End-to-end results for sampled chain-of-custody checks, including how hard-to-spoof IDs are read and matched.
- An adversarial evaluation of record falsification, forged serial numbers and unrecorded chips.
How it works
A chip registry records unique identifiers for AI chips, together with their owners and, in some designs, their locations 1. The aim is to account for chips over their lifetime 1 5. Baker et al. describe an AI chip registry as one possible way to report who owns AI compute 1. They note that declaring individual chips is not strictly necessary but makes verification easier 1. A verifier could check the locations and owners of random samples of chips, from manufacture to destruction, using inspections, possibly video cameras, and hard-to-spoof unique IDs 1.
Ansari describes lifecycle registries as a chain-of-custody layer similar to nuclear material accountancy 5. He cites proposals to identify chips with physical unclonable functions and to serialize them on a blockchain 5. Aarne, Fist and Withers write that on-chip governance mechanisms would need a way to track who owns data-centre AI chips, supported by supply-chain tracking and Know Your Customer policies 4.
In an export-control setting, Avellar and Grunewald describe a centralized registry of chip ownership 2. The regulator could pick random chip IDs from it and ask the owners to return those chips at short notice 2. During on-site inspections, inspectors would check the serial numbers of a random sample of chips against asset inventories and the records reported to the regulator 2.
Manufacturing records. Cankaya argues that the foundry already holds a "golden record" of the AI chips it has made 3. He writes that modern processors carry Electronic Chip IDs (ECIDs), burned into one-time-programmable fuses at wafer test, that encode the wafer lot, the wafer number and the die position 3. He proposes that the foundry build a Merkle tree over these IDs and publish only its root hash after each batch 3. Later tampering would then be detectable, while the IDs themselves stay private 3. An inspector could later read a chip's ECID through its test access port without opening the package 3.
Upstream audits. Halstead and Larsen propose auditing the semiconductor supply chain upstream, across logic fabrication, memory and packaging suppliers 6. This would give a record of past production that is hard to under-report without creating inconsistencies 6.
What it establishes
What these tools can show:
- Custody matches declarations. A registry, with sampled inspections, tests whether declared chains of custody match what is physically present 1 2.
- No undeclared clusters of recorded chips. It supports the wider goal of checking that large quantities of chips have not been assembled into undeclared clusters 1.
- Records were not changed later. A published commitment makes later changes to foundry records detectable 3.
What they cannot show:
- Unrecorded chips. Chips that were never recorded are not covered 3.
- Where chips went. Cankaya notes that a commitment shows what was made, and that "the harder question is where it went" 3.
- Accuracy at the start. A commitment cannot show that the records were correct when committed 3.
- Strong assurance from documents alone. Avellar and Grunewald rate export documentation checks low in effectiveness and useful mainly against actors of low to moderate sophistication 2.
Brass and Aarne suggest pairing a registry with location verification (Chip location verification) 7.
Threat model
These designs trust some parties:
- Owners declare truthfully, or are caught by sampled inspections 1.
- Foundries keep accurate ID records; Cankaya's proposal assumes the foundry holds the ECID data 3.
- IDs are hard to alter 1. Cankaya argues that a blown fuse cannot be restored, and that changing it would need focused-ion-beam work that leaves detectable traces 3.
The main threats named in the sources are forged documents and serial numbers 2, opaque corporate structures 2 and insiders altering production records 3. Ansari argues that the concentration of advanced manufacturing, with fewer than two dozen facilities making sub-14 nm chips as of 2023, makes a registry easier to enforce than for a commodity with distributed production 5.
Evidence
- Designs only. Baker et al., Avellar and Grunewald, and Cankaya publish designs; none reports an implementation 1 2 3.
- Feasibility ratings. Ansari rates registry systems as near-term 5. He rates trade-data analysis as deployable now, citing work that uses existing customs data to find circumvention patterns 5.
- Export-control ratings. Avellar and Grunewald rate export documentation checks as relatively established but low in effectiveness, and random return requests from a registry as novel and high in effectiveness 2.
Limitations
- Unrecorded chips. Chips outside the record are not covered, and a fraudulent original record would mean unregistered chips were made in advance 3. Reconstructing earlier production depends on supplier records 6.
- Forgery. Documents can be forged, and serial numbers on chips and racks may be forgeable 2.
- Insider tampering. Records can be altered before they are committed 3.
- Limited reach. Covering re-exports would need cooperation from re-exporters and foreign governments, which may not be feasible everywhere 2.
- Custody versus location. A commitment fixes what was made, but tracking where chips are needs inspections or location checks 3 1.
Known flaws
Published flaws, with their severity, kind and status. How flaws are rated.
Records cover only chips that were recorded
A registry or commitment accounts only for chips entered into it. Cankaya asks how a verifier would know it had found all chips, or how much "dark compute" remains, and notes that a fraudulent original record would mean unregistered chips had been made in advance 3. Halstead and Larsen propose reconstructing earlier production by auditing upstream suppliers 6.
Documents and serial numbers can be forged
Avellar and Grunewald note that export documents can be forged, that companies can hide information behind obscure corporate structures, and that it may be possible to forge serial numbers on chips and racks. They recommend cryptographic attestation of a powered-on chip as an extra check 2.
Blockers
No AI chip registry operates, and covering re-exports would need cooperation from re-exporters and foreign governments that may not be feasible everywhere.
Linking records to physical chips needs hard-to-spoof unique IDs and inspections.
Chips produced before a registry starts must be reconstructed from supplier records.
Sources
- BM. Baker et al. (2025). Verifying International Agreements on AI: Six Layers of Verification for Rules on Large-Scale AI Development and Deployment. RAND Corporation. Source recordSupports: AI chip registry concept; sampled chain-of-custody checks; subgoal on undeclared clusters · §3.2 and its footnote on the AI chip registry; §4.2.1.2
- BB. Avellar & E. Grunewald (2026). Near-Term Verification Methods for AI Chip Exports. arXiv. Source recordSupports: centralized ownership registry; random return requests; serial checks; forgery limits; effectiveness ratings · §1.1, §1.2, §1.5
- CN. Cankaya (2025). TSMC most definitely has a golden record of all AI chips it made. Substack (Naci Cankaya). Source recordSupports: ECID golden record; Merkle-root commitment; TAP readout; eFuse tamper evidence; dark compute; insider threat · whole post
- BO. Aarne et al. (2024). Secure, Governable Chips: Using On-Chip Mechanisms to Manage National Security Risks from AI & Advanced Computing. Center for a New American Security. Source recordSupports: on-chip mechanisms need ownership tracking, supply-chain tracking and KYC · 'What Would Effective On-Chip Governance Look Like?', pp. 9-10
- BS. Ansari (2026). Hardware-Level Governance of AI Compute: A Feasibility Taxonomy for Regulatory Compliance and Treaty Verification. arXiv. Source recordSupports: chain-of-custody framing; PUFs; blockchain serialization; customs data; manufacturing concentration; feasibility · §3.1 (M7)
- CB. Halstead & T. Larsen (2026). Covert AI Projects. AI 2040. Source recordSupports: auditing upstream supply chain to reconstruct production · section on preventing compute acquisition
- BA. Brass & O. Aarne (2024). Location Verification for AI Chips. Institute for AI Policy and Strategy. Source recordSupports: recommendation to combine location verification with a registry · Detailed Summary