Compute verification
How inspectors could check limits on AI training, from a cluster’s power connections to records of its jobs.
Where these ideas come from
Proposals for chip inventories, workload checks and protected inspection records supply different parts of a compute agreement. The draft treaty brings those mechanisms into a proposed international regime.
The draft agreement
Scher, Abecassis, Barnett and Abeyta’s draft treaty, revised in May 2026, proposes chip registries, continuous use verification and challenge inspections. It requires verified shutdown when use cannot be adequately verified; its appendix sketches a possible progression from US–China cooperation to wider participation.
The mechanisms
Scher and Thiergart set out in 2024 what a chip registry, sampled inventory checks and movement monitoring would involve; the sampling tool is the arithmetic of one of their checks.
The six layers
Baker, Kulp, Marks, Brundage and Heim, in a RAND working paper of 2025, sorted verification into on-chip, off-chip and personnel layers, and described partial re-execution of declared jobs and compute accounting from analog sensors; the six things an inspector has to establish use their layers.
Confidential verification
Harack and colleagues’ 2025 report, published by the Oxford Martin AI Governance Initiative, proposes a jointly controlled data centre for sensitive verification work and examines verifiable confidential computing.
Hardware guarantees
Petrie, Aarne, Ammann and Dalrymple’s ARIA-commissioned flexHEG reports examine protected processors that monitor or restrict accelerator use. The technical report considers integrated designs and retrofits, including interlocks on the accelerator’s data path.
A near-term system
Cankaya at MIRI, 2026, described a low-trust system that captures evidence with fibre taps and commits to records before anyone evaluates them; the tap on the tray is that design.
The experiments
Rahman and Tajdari tested telemetry classifiers against disguised training workloads; attacks that evaded one classifier prompted another round of training. Scher, Sarbakysh and Moskvin tested network limits on four GPUs with roughly twenty times less intra-node bandwidth than their production comparison. Their monitoring implementation was spoofable, and reinforcement learning and low-rank fine-tuning were left for further work. Rahman separately examined distributed training as a challenge to compute governance.
Exports and location
Avellar and Grunewald’s 2026 report examines checks on chip exports. Brass and Aarne’s 2024 report and Brass’s 2025 brief examine location verification through timed exchanges. Fist and Grunewald’s 2023 CNAS report proposes random inspections against a chip registry to deter smuggling.
Cloud providers and the first proposal
Heim and colleagues (GovAI, 2024) on compute providers as the point of regulation; Shavit (2023) on catching a large training run by monitoring compute, the earliest of these.
The procedural model
The Chemical Weapons Convention supplies precedents for challenge inspections and managed access. The draft requires Council consensus before a challenge inspection. Under the Convention, an inspection request proceeds unless three-quarters of the Council vote to stop it.