Mechanism · Remote & side-channel sensing
Remote detection of data centres
Remote detection locates large data centres and estimates their power capacity without site access, using satellite imagery, heat signatures and public records such as permits.
Also called Satellite monitoring of data centres; Remote sensing of AI compute facilities; National technical means for AI compute
Summary
Remote detection of data centres is a set of methods for finding facilities and estimating their size from outside. Large AI data centres need buildings, substations and cooling equipment, and they shed roughly as much heat as the electricity they use. These features can be seen without the operator's cooperation. Analysts already combine satellite imagery with permits and utility filings to track the construction of known large facilities and estimate their power capacity. For verification, the harder task is finding facilities nobody has declared. As of September 2026 that has not been demonstrated, and automated detection of data centres remains mainly conceptual. Imagery also cannot see inside buildings or count chips. The main weaknesses are concealment, such as disguising a facility as other industry or building it underground, and sites too small to stand out. Verification frameworks treat these signals as supplements to stronger mechanisms.
R1. Public results so far monitor sites whose locations were already known; none shows a search that finds undeclared facilities.
Rubric assessment
- R1 met: Halstead and Larsen describe heat, imagery and other detection signals, ways to conceal a facility and the odds of detecting covert ones 3. Baker et al. place satellite imagery among supplementary verification mechanisms 4.
- R2 not met for this use: Krawec's case studies track known sites 1. Epoch AI's public dataset estimates the capacity of known large facilities 2. Krawec states that automated data-centre detection "remains primarily conceptual at present" 1.
Confidence is low because the level depends on scope. The public Epoch dataset and Krawec's case studies could arguably meet R2 for the supporting use of estimating the capacity of known sites (Compute stock is at most a declared amount).
- Published end-to-end results on finding previously unknown large facilities over a wide area, with measured miss and false-alarm rates.
- An evaluation against a stated concealment adversary, for example disguised or underground facilities.
How it works
Remote detection infers the existence, size and status of data centres without entering them 1. Electro-optical satellite imagery shows these features 1:
- large data halls;
- substations and switchyards;
- on-site gas turbines and backup generators;
- cooling towers and chillers;
- construction progress.
Analysts combine imagery with permits, utility filings, company announcements and other open sources 1. Free imagery comes from archives such as the ESA Copernicus Sentinel and NASA Landsat missions 1. Paid commercial imagery reaches sub-metre resolution, from providers such as Planet Labs, Airbus and Vantor 1.
Capacity can be estimated from cooling equipment 2 1. Epoch AI's Frontier Data Centers Hub finds chillers and cooling towers in satellite images and checks them against permits and public disclosures 2. From these it infers each facility's power capacity, and then the compute installed, in H100-equivalents 2.
Halstead and Larsen treat waste heat as the main obstacle to hiding a facility 3. They note that "each megawatt of electricity going into a datacenter must be matched with a megawatt going out in some form (mostly as heat)" 3. They list other signals 3:
- Infrared satellites can see exhaust air and cooling plumes.
- Radar interferometry can reveal ground movement from excavation.
- Ground moving-target radar can track logistics vehicles.
Ansari also notes that infrared remote sensing can detect undeclared data centres through their heat signatures 5.
Verification frameworks usually give these signals a supporting role 4. Baker et al. list satellite or aerial images, open-source intelligence, information from data-centre suppliers and financial audits as "less robust mechanisms" that could supplement the main ones 4. One of their main layers is national intelligence activities, which can draw on human, cyber and signals intelligence 4. Remote detection complements chip accounting (Chip registries and manufacturing records) and workload classification (Workload classification from telemetry and side channels).
What it establishes
From outside, analysts can see construction progress, site layout and power and cooling infrastructure, and can estimate power capacity approximately 1 2. In one of Krawec's case studies, Epoch AI's capacity estimates from cooling equipment ranged from about 200 to 500 MW, against a published expected capacity of 300 MW 1. Imagery can also reveal gaps between announced and observed construction 1.
Remote detection has four gaps:
- Electro-optical imagery "can only view the outside of buildings", so it gives no chip counts, chip types or actual power consumption 1.
- Capacity figures from cooling equipment are approximations, not measurements of energy use 1.
- Power figures alone cannot distinguish AI training from other high-performance computing 5.
- Chips that have been produced but not yet installed in data centres are hard to find this way 3.
Threat model
Remote detection assumes that large facilities have physical signatures that are hard to remove, such as buildings, substations, cooling equipment and waste heat 3 1. It uses imagery and public records, so it needs no cooperation from the operator 1.
The adversary may try to hide a facility 3. Halstead and Larsen consider disguising sites as industrial facilities, and underground designs whose cooling avoids visible plumes 3.
The approach also assumes access to recent imagery and skilled analysts. Krawec lists cloud cover, smoke and weather, the cost of recent high-resolution imagery and the need for trained analysts as constraints 1.
Evidence
- Krawec's May 2026 report for the Federation of American Scientists presents two case studies 1. One tracks a facility's construction over 2024 and 2025 against public announcements 1. The other counts infrastructure at an operating AI facility and checks it against utility records and permits 1.
- Epoch AI's hub covered 13 large US data centres at its launch in November 2025 2. Epoch estimated that they held about 2.5 million of the roughly 15 million H100-equivalents delivered to customers worldwide in recent years 2. The data are released under a Creative Commons Attribution licence 2.
- Halstead and Larsen estimate the chance that unilateral detection methods find a covert project within ten years of an international agreement 3. For a single site they give 26% at 10 MW, 35% at 100 MW and 50% at 1 GW 3. For ten sites of each size they give 37%, 67% and 85% 3. They call these estimates highly speculative, based entirely on intuition and qualitative reasoning 3.
- Krawec recommends satellite imagery as one element of verification for future agreements, and points to the IAEA's satellite imagery analysis team for nuclear safeguards 1. The report names thermal infrared, synthetic-aperture radar and multispectral imaging as directions for further research 1.
Limitations
- Facilities can be disguised as other industry or placed underground 3.
- A sufficiently small covert project could not be ruled out with confidence 3. Small data centres in existing buildings may lack distinctive signatures 1.
- Without a known location, telling data centres apart from other industrial facilities is hard, and automated detection is mainly conceptual 1.
- Chip counts, chip types and actual energy use cannot be observed 1.
- Cooling and power features vary across companies and countries, and not every site generates its own power 1.
Known flaws
Published flaws, with their severity, kind and status. How flaws are rated.
Facilities can be disguised or hidden
Halstead and Larsen discuss two ways to hide a facility. One is to disguise it as a legitimate industrial site. The other is to build it underground, with cooling that avoids visible heat plumes. They note that the underground option requires bespoke engineering 3.
Small sites may not be detectable
Search for unknown sites is undemonstrated
Krawec reports that telling data centres apart from other industrial facilities systematically is difficult. Automating detection would need large amounts of training imagery and a purpose-trained model. In Krawec's words, automated data-centre detection "remains primarily conceptual at present" 1.
Blockers
Wide-area, automated detection of data centres is not yet practical and needs large training datasets.
No measured detection or false-alarm rates for finding undeclared facilities have been published.
Recent high-resolution imagery is costly, is limited by weather and needs trained analysts.
Sources
- BC. Krawec (2026). Tracking Hyperscale AI Data Center Growth with Satellite Imagery. Federation of American Scientists. Source recordSupports: observable features; imagery sources and limits; capacity estimate example; cannot see inside; automated detection conceptual and its data needs; IAEA analogy; future sensors · Methodology; Opportunities and Challenges; Case Studies 1-2; Recommendations; Opportunities for Further Research
- CEpoch AI (2025). Introducing the Frontier Data Centers Hub. Epoch AI. Source recordSupports: public dataset; cooling-equipment-based capacity method; coverage figures; licence · announcement post
- CB. Halstead & T. Larsen (2026). Covert AI Projects. AI 2040. Source recordSupports: heat-balance argument; detection signals; concealment strategies; intuition-based detection probabilities and their conditions; limits for small projects; undeployed chips · detection sections; table of intuition-based detection probabilities by site size and number of sites
- BM. Baker et al. (2025). Verifying International Agreements on AI: Six Layers of Verification for Rules on Large-Scale AI Development and Deployment. RAND Corporation. Source recordSupports: satellite imagery, OSINT, supplier information and financial audits as supplementary mechanisms; national intelligence layer · §4.3, §4.4
- BS. Ansari (2026). Hardware-Level Governance of AI Compute: A Feasibility Taxonomy for Regulatory Compliance and Treaty Verification. arXiv. Source recordSupports: infrared imaging can detect undeclared data centres; power alone cannot separate AI from other HPC · §3.1 (M4)