Skip to main content
Sources checked 11 Sep 2026

Compute verification

How inspectors could check limits on AI training, from a cluster’s power connections to records of its jobs.

Where these ideas come from

Proposals for chip inventories, workload checks and protected inspection records supply different parts of a compute agreement. The draft treaty brings those mechanisms into a proposed international regime.

The draft agreement

Scher, Abecassis, Barnett and Abeyta’s draft treaty, revised in May 2026, proposes chip registries, continuous use verification and challenge inspections. It requires verified shutdown when use cannot be adequately verified; its appendix sketches a possible progression from US–China cooperation to wider participation.

The mechanisms

Scher and Thiergart set out in 2024 what a chip registry, sampled inventory checks and movement monitoring would involve; the sampling tool is the arithmetic of one of their checks.

The six layers

Baker, Kulp, Marks, Brundage and Heim, in a RAND working paper of 2025, sorted verification into on-chip, off-chip and personnel layers, and described partial re-execution of declared jobs and compute accounting from analog sensors; the six things an inspector has to establish use their layers.

Confidential verification

Harack and colleagues’ 2025 report, published by the Oxford Martin AI Governance Initiative, proposes a jointly controlled data centre for sensitive verification work and examines verifiable confidential computing.

Hardware guarantees

Petrie, Aarne, Ammann and Dalrymple’s ARIA-commissioned flexHEG reports examine protected processors that monitor or restrict accelerator use. The technical report considers integrated designs and retrofits, including interlocks on the accelerator’s data path.

A near-term system

Cankaya at MIRI, 2026, described a low-trust system that captures evidence with fibre taps and commits to records before anyone evaluates them; the tap on the tray is that design.

The experiments

Rahman and Tajdari tested telemetry classifiers against disguised training workloads; attacks that evaded one classifier prompted another round of training. Scher, Sarbakysh and Moskvin tested network limits on four GPUs with roughly twenty times less intra-node bandwidth than their production comparison. Their monitoring implementation was spoofable, and reinforcement learning and low-rank fine-tuning were left for further work. Rahman separately examined distributed training as a challenge to compute governance.

Exports and location

Avellar and Grunewald’s 2026 report examines checks on chip exports. Brass and Aarne’s 2024 report and Brass’s 2025 brief examine location verification through timed exchanges. Fist and Grunewald’s 2023 CNAS report proposes random inspections against a chip registry to deter smuggling.

Cloud providers and the first proposal

Heim and colleagues (GovAI, 2024) on compute providers as the point of regulation; Shavit (2023) on catching a large training run by monitoring compute, the earliest of these.

The procedural model

The Chemical Weapons Convention supplies precedents for challenge inspections and managed access. The draft requires Council consensus before a challenge inspection. Under the Convention, an inspection request proceeds unless three-quarters of the Council vote to stop it.

The documents

The documents the verification family draws on: authors, title, date and status.
AuthorsTitleDateStatus
Scher, Abecassis, Barnett, Abeyta (MIRI; equal contribution)An International Agreement to Prevent the Premature Creation of Artificial Superintelligencev3, 8 May 2026 (arXiv; v1 13 Nov 2025)draft
Scher, Thiergart (MIRI)Mechanisms to Verify International Agreements About AI Development27 Nov 2024proposed
Baker (RAND), Kulp, Marks (University of Bristol), Brundage (AI Verification and Evaluation Research Institute), HeimVerifying International Agreements on AI: Six Layers of Verification for Rules on Large-Scale AI Development and Deployment21 Jul 2025proposed
Harack et al. (27 authors; published by the Oxford Martin AI Governance Initiative)Verification for International AI Governance3 Jul 2025 (the publisher’s date; the document prints none)proposed
Petrie, Aarne, Ammann, DalrympleFlexible Hardware-Enabled Guarantees for AI Compute (Part I)cover Apr 2025; arXiv 18 Jun 2025proposed
Petrie, AarnePart II: Technical Options for Flexible Hardware-Enabled Guaranteescover Apr 2025; arXiv 3 Jun 2025 (v3 18 Jun)proposed
Aarne, PetriePart III: International Security Applications of Flexible Hardware-Enabled Guaranteescover Apr 2025; arXiv 18 Jun 2025proposed
Cankaya (MIRI)A System Overview for Near-Term, Low-Trust AI Compute Verification23 Jun 2026proposed
Rahman, TajdariDetecting Hidden ML Training With Zero-Overhead Telemetry17 Jun 2026prototype
RahmanDoes Distributed Training Undermine Compute Governance?28 May 2026analysis
Scher (MIRI), Sarbakysh, Moskvin (SPAR fellows)De-risking Interconnect Limits for AI Verification30 Jul 2026prototype
Avellar (independent researcher; the work partly during an IAPS fellowship), Grunewald (IAPS)Near-Term Verification Methods for AI Chip ExportsarXiv 7 Sep 2026; first published by IAPS in August 2026 under Grunewald’s bylineproposed
Brass, Aarne (the publisher’s attribution; the report itself is unbylined)Location Verification for AI Chips2024 (the publisher’s date; the document prints none)prototype
BrassLocation Verification for AI Chips, issue briefMay 2025prototype
Heim (GovAI), Fist, Egan, Huang, Zekany, Trager, Osborne, ZilbermanGoverning Through the Cloud: The Intermediary Role of Compute Providers in AI Regulation13 Mar 2024proposed
Fist (CNAS), GrunewaldPreventing AI Chip Smuggling to China24 Oct 2023proposed
Wasil, Reed, Miller, BarnettVerification methods for international AI agreements28 Aug 2024 (v2 4 Nov 2024)analysis
ShavitWhat does it take to catch a Chinchilla? Verifying Rules on Large-Scale Neural Network Training via Compute Monitoring20 Mar 2023 (v2 30 May 2023)proposed
Chen, Hu, Ye, XuRolloutPipe: Overlapping Pipelined Rollout and Training in Disaggregated On-Policy LLM Reinforcement Learning25 Jun 2026 (v2 5 Jul 2026)evidence
Organisation for the Prohibition of Chemical WeaponsChemical Weapons Convention, Article IX and Verification Annex Part X— (the consolidated text prints no date on the page cited)in force
Showing 20 of 22