There is no undeclared relevant compute
The claim is that a party controls no AI-relevant computing hardware or facilities, above an agreed threshold, beyond those it has declared.
Every other check on declared hardware can be sidestepped if a party runs prohibited work on hardware it never declared. Verifying that no such compute exists is therefore central to many proposed AI agreements. It is also among the hardest claims to establish, because it asserts an absence across a whole country or organisation, and demonstrating non-existence is generally harder than demonstrating existence.
No single technique establishes it. Proposals combine tracking chips from manufacture, so that the declared stock is complete; searching for undeclared facilities with satellite imagery, energy data, customs and financial intelligence; and human sources such as whistleblowers and inspections. Each has documented evasions, and the achievable assurance depends on how much compute a meaningful violation would require.
No single verification method is foolproof for this broadest of negative claims 5, so draft agreements pair technical measures with intelligence, challenge inspections and whistleblowers 6. The only mechanism mapped primarily to this claim, remote detection of data centres, is proposed (R1), as are the chip registries and location checks that support it. RAND splits the claim into undeclared use of declared clusters, which reduces to claims such as Declared hardware is idle or shut down and This compute runs inference, not training, and undeclared clusters 1.
One strategy, which Scher and Thiergart favour, makes the declared stock complete from the start through chip registries and location verification 4. The other searches for what was missed, through remote detection of data centres and other national technical means 5. Satellite imagery, permits and utility filings already track the construction of known large facilities, but automated data-centre detection remains primarily conceptual 9. Proofs of useful work would leave declared hardware little spare capacity, but cannot find a facility that was never declared 10.
Chips sold before tracking began may not be locatable 3, facilities can be hidden underground or camouflaged 5, and it is unclear how small undeclared compute can be and still matter 1 7.
On this page
Mechanisms
- Searches for large facilities that have not been declared.
- R3Deterministic and bit-exact inferencesupportingUnreported batch elements alter the numerics, so covert computation inside batches becomes detectable 1.
- R3Pearl proof-of-useful-work blockchainsupportingOn declared hardware only; cannot find undeclared facilities. Not applied to bounding spare capacity.
- Contention from undeclared co-running workloads shifts challenge timing 1; coverage of other chips needs other mechanisms.
- R1Chip location verificationsupportingCan flag enrolled chips that stop responding or answer from outside declared regions; says nothing about chips outside the scheme.
- Supports checks that recorded chips have not been assembled into undeclared clusters.
- Memory challenges and resource accounting are proposed against hidden workloads.
- On declared hardware only: bounds capacity left for unmonitored work; cannot find undeclared facilities.
Why it matters
Checks on declared hardware say nothing about hardware that was never declared.
- RAND's framework gives this its own goal: verifying that there are no undeclared uses of large-scale AI compute 1. It splits the goal into no undeclared use of declared clusters, and no undeclared clusters, whether inside known data centres or standalone 1.
- Shavit's framework depends on the same property. Without chip-ownership verification, a prover might covertly acquire a large quantity of chips and train on them without ever notifying the verifier 3.
- Wasil and colleagues list unauthorised data centres as one of two main violation types 5.
- A draft international agreement relies on a combination of supply-chain tracking, mandatory reporting, state intelligence, open-source intelligence, power monitoring, challenge inspections and whistleblowers to locate chips 6.
Why it is hard
The claim asserts absence. The Oxford Martin report observes that demonstrating the existence of an object or process is often straightforward compared with demonstrating its non-existence 2.
- Hidden facilities. Scher and Thiergart judge that detecting covert data centres may be difficult, because AI compute may be hidden among other compute or in secret facilities 4. They see whistleblowers and intelligence as possible means of detection 4. Sastry and colleagues note that large training facilities are visible because of their size and power demands, and that hiding them underground would likely increase cost significantly 7.
- Limits of each detection method. Wasil and colleagues note that data centres could be concealed underground or camouflaged from satellite imagery, and that energy use can be disguised as other high-energy activity 5. Customs data is less useful against domestic chip production, and financial intelligence must separate illicit purchases from many legitimate ones 5. Whistleblowers may be deterred by fear of retaliation 5.
- The existing stock. Shavit notes that many chips already sold lack the security features his framework needs and may not be locatable by governments 3. A 2026 analysis of TEE-based monitoring notes the difficulty of verifying that workload declarations are complete and of forming tight bounds on unknown compute 8.
- The threshold. RAND's framework focuses on clusters with the computing power of thousands of high-end chips, while noting it is not clear that frontier AI deployment must happen at scale to be dangerous 1. Sastry and colleagues caution that low-compute narrow models can have dangerous capabilities, and that more viable decentralised training could undermine the detectability of compute 7. Rahman estimates that the 10^24, 10^25 and 10^26 FLOP thresholds could be evaded with $1.6 million, $31 million and $3.8 billion of hardware respectively, arranged in clusters smaller than any proposed registration requirement 11. The estimate assumes distributed training over consumer-grade internet, nodes of at most 16 H100-equivalents and a run of up to about two years 11.
Sources
- BM. Baker et al. (2025). Verifying International Agreements on AI: Six Layers of Verification for Rules on Large-Scale AI Development and Deployment. RAND Corporation. Source recordSupports: Subgoal 2 (2.A, 2.B, 2.B.1, 2.B.2); focus on large-scale clusters; unclear whether dangerous deployment requires scale; personnel and intelligence layers · §2.2; §3.2, Figure 4; §4
- BB. Harack et al. (2025). Verification for International AI Governance. Oxford Martin AI Governance Initiative. Source recordSupports: existence easier to demonstrate than non-existence · p. 31
- BY. Shavit (2023). What does it take to catch a Chinchilla? Verifying Rules on Large-Scale Neural Network Training via Compute Monitoring. arXiv. Source recordSupports: sampling fails if prover amasses untracked chips; existing chips possibly not locatable · abstract; §5
- BA. Scher & L. Thiergart (2025). Mechanisms to Verify International Agreements About AI Development. arXiv. Source recordSupports: covert data centres may be hard to detect; tracking chips favoured; intelligence and whistleblowers as complements · Verifying the location of AI compute (analysis)
- BA. R. Wasil et al. (2024). Verification methods for international AI agreements. arXiv. Source recordSupports: unauthorised data centres as a violation type; no single method foolproof; national technical means and their limitations and evasions · What to verify; Table 1; Figures 2–4
- BA. Scher et al. (2025). An International Agreement to Prevent the Premature Creation of Artificial Superintelligence. Machine Intelligence Research Institute. Source recordSupports: locating chips through supply-chain tracking, reporting, intelligence, OSINT, power monitoring, challenge inspections and whistleblowers · §4; Articles V and X (as summarised)
- BG. Sastry et al. (2024). Computing Power and the Governance of Artificial Intelligence. arXiv. Source recordSupports: detectability of large facilities; low-compute narrow models; decentralised training; underground data centres raise cost · properties of compute; limitations
- CGloria Z (2026). On TEEs for Privacy-Preserving Monitoring in AI Governance. MIRI Technical Governance Team. Source recordSupports: difficulty of verifying completeness of workload declarations and bounding unknown compute · Limitations
- BC. Krawec (2026). Tracking Hyperscale AI Data Center Growth with Satellite Imagery. Federation of American Scientists. Source recordSupports: satellite imagery, permits and utility filings track known facilities; automated data-centre detection primarily conceptual · Methodology; Opportunities for Further Research
- CAttestable (2026). Pacing AI Requires Proof. Attestable blog. Source recordSupports: work-budget proposal; a proof cannot discover a datacenter that was never declared (provider proposal) · blog post
- BR. Rahman (2026). Does Distributed Training Undermine Compute Governance?. ICML 2026 Workshop on Technical AI Governance Research. Source recordSupports: 10^24, 10^25 and 10^26 FLOP thresholds evadable with $1.6M, $31M and $3.8B of hardware in sub-registration clusters; assumptions (DiLoCo-family training over 100 Mbps links, 16 H100-equivalents per node, about 740 days) · §3.1; §4