Undeclared compute
Undeclared compute is AI-relevant hardware, or use of declared hardware, that a prover has not reported to the verifier 1.
RAND's verification framework separates two cases: undeclared uses of declared clusters, and undeclared clusters, whether inside known data centres or standalone 1. The problem is sharpest for hardware that predates tracking. Shavit notes that hundreds of thousands of ML chips had already been sold, many lacking the security features his framework needs 2, and Scher and Thiergart write that millions of AI-relevant chips exist and that, to their knowledge, no central tracking of them has taken place 3. They judge that searching for secret data centres may help but is unlikely to carry a verification regime, because it will likely be too easy to hide AI compute among other compute or to build secret data centres 3. Sastry and colleagues caution that more efficient algorithms and more viable decentralized training could reduce how much compute, or how concentrated, a prohibited activity needs 4. Proposed responses include:
- Tracking hardware. Monitoring the chip supply chain and keeping a directory of chip owners 2, as in chip registries and manufacturing records.
- Finding facilities. National technical means such as remote sensing, energy monitoring, customs data and financial intelligence, alongside whistleblowers 5, as in remote detection of data centres.
- Bounding declared capacity. Wiping memory to remove residual capacity for hidden workloads on declared hardware 6, as in memory wiping and proofs of secure erasure.
Related
Used in
- R2Bandwidth limits and compartmentalization
- R2Bounding unexplained information in outputs
- R1Chip registries and manufacturing records
- R3Deterministic and bit-exact inference
- R1Hardware-enabled guarantees (flexHEG) and guarantee processors
- R1Memory wiping and proofs of secure erasure
- R2On-chip telemetry from timing, memory and performance counters⚠
- R1Proofs of useful work for capacity accounting
- R1Remote detection of data centres
- R1Whole-workload recomputation (reproducible packets)
- R2Timed challenge-response and memory-occupation challenges
- R2Zero-knowledge proofs of inference
- R1AI 2040 inference-only verification stack
- Compute stock is at most a declared amount
- There is no undeclared relevant compute
Sources
- BM. Baker et al. (2025). Verifying International Agreements on AI: Six Layers of Verification for Rules on Large-Scale AI Development and Deployment. RAND Corporation. Source recordSupports: Subgoal 2: no undeclared uses of declared clusters (2.A) and no undeclared clusters in known data centres or standalone (2.B) · §3.2, Figure 4
- BY. Shavit (2023). What does it take to catch a Chinchilla? Verifying Rules on Large-Scale Neural Network Training via Compute Monitoring. arXiv. Source recordSupports: hundreds of thousands of ML chips already sold, many lacking the required security features; supply-chain monitoring and chip-owner directory · §1.2; §6; §6.1
- BA. Scher & L. Thiergart (2025). Mechanisms to Verify International Agreements About AI Development. arXiv. Source recordSupports: millions of AI-relevant chips exist, with no central tracking to the authors' knowledge; detecting secret data centres unlikely to be load-bearing because AI compute will likely be too easy to hide · Verifying the location of AI compute
- BG. Sastry et al. (2024). Computing Power and the Governance of Artificial Intelligence. arXiv. Source recordSupports: algorithmic efficiency and decentralized training could undermine compute detectability · limitations of compute governance
- BA. R. Wasil et al. (2024). Verification methods for international AI agreements. arXiv. Source recordSupports: national technical means (remote sensing, energy monitoring, customs, financial intelligence) and whistleblowers · Verification methods; Table 1
- BN. Cankaya (2026). A System Overview for Near-Term, Low-Trust AI Compute Verification. Machine Intelligence Research Institute. Source recordSupports: memory wiping to remove residual capacity for hidden workloads · §5.1.2