<!--
Source: https://scrutica.com/verification/sources
Generated: 2026-09-12T03:49:03.339Z
Format: Markdown extraction of the rendered HTML at the source URL.
For the full agent guide see: https://scrutica.com/llms-full.txt
For the MCP server see: https://scrutica.com/api/mcp
-->

# Sources
## Where these ideas come from

Proposals for chip inventories, workload checks and protected inspection records supply different parts of a compute agreement. The draft treaty brings those mechanisms into a proposed international regime.

#### The draft agreement

Scher, Abecassis, Barnett and Abeyta’s draft treaty, revised in May 2026, proposes chip registries, continuous use verification and challenge inspections. It requires verified shutdown when use cannot be adequately verified; its appendix sketches a possible progression from US–China cooperation to wider participation.

#### The mechanisms

Scher and Thiergart set out in 2024 what a chip registry, sampled inventory checks and movement monitoring would involve; the [sampling tool](https://scrutica.com/verification/inspection) is the arithmetic of one of their checks.

#### The six layers

Baker, Kulp, Marks, Brundage and Heim, in a RAND working paper of 2025, sorted verification into on-chip, off-chip and personnel layers, and described partial re-execution of declared jobs and compute accounting from analog sensors; the six things an inspector has to establish use their layers.

#### Confidential verification

Harack and colleagues’ 2025 report, published by the Oxford Martin AI Governance Initiative, proposes a jointly controlled data centre for sensitive verification work and examines verifiable confidential computing.

#### Hardware guarantees

Petrie, Aarne, Ammann and Dalrymple’s ARIA-commissioned flexHEG reports examine protected processors that monitor or restrict accelerator use. The technical report considers integrated designs and retrofits, including interlocks on the accelerator’s data path.

#### A near-term system

Cankaya at MIRI, 2026, described a low-trust system that captures evidence with fibre taps and commits to records before anyone evaluates them; the tap on the tray is that design.

#### The experiments

Rahman and Tajdari tested telemetry classifiers against disguised training workloads; attacks that evaded one classifier prompted another round of training. Scher, Sarbakysh and Moskvin tested network limits on four GPUs with roughly twenty times less intra-node bandwidth than their production comparison. Their monitoring implementation was spoofable, and reinforcement learning and low-rank fine-tuning were left for further work. Rahman separately examined distributed training as a challenge to compute governance.

#### Exports and location

Avellar and Grunewald’s 2026 report examines checks on chip exports. Brass and Aarne’s 2024 report and Brass’s 2025 brief examine location verification through timed exchanges. Fist and Grunewald’s 2023 CNAS report proposes random inspections against a chip registry to deter smuggling.

#### Cloud providers and the first proposal

Heim and colleagues (GovAI, 2024) on compute providers as the point of regulation; Shavit (2023) on catching a large training run by monitoring compute, the earliest of these.

#### The procedural model

The Chemical Weapons Convention supplies precedents for challenge inspections and managed access. The draft requires Council consensus before a challenge inspection. Under the Convention, an inspection request proceeds unless three-quarters of the Council vote to stop it.

### The documents

The documents the verification family draws on: authors, title, date and status.

| Authors | Title | Date | Status |
| --- | --- | --- | --- |
| Scher, Abecassis, Barnett, Abeyta (MIRI; equal contribution) | [An International Agreement to Prevent the Premature Creation of Artificial Superintelligence](https://arxiv.org/abs/2511.10783v3) | v3, 8 May 2026 (arXiv; v1 13 Nov 2025) | draft |
| Scher, Thiergart (MIRI) | [Mechanisms to Verify International Agreements About AI Development](https://intelligence.org/wp-content/uploads/2024/11/Mechanisms-to-Verify-International-Agreements-About-AI-Development-27-Nov-24.pdf) | 27 Nov 2024 | proposed |
| Baker (RAND), Kulp, Marks (University of Bristol), Brundage (AI Verification and Evaluation Research Institute), Heim | [Verifying International Agreements on AI: Six Layers of Verification for Rules on Large-Scale AI Development and Deployment](https://arxiv.org/abs/2507.15916) | 21 Jul 2025 | proposed |
| Harack et al. (27 authors; published by the Oxford Martin AI Governance Initiative) | [Verification for International AI Governance](https://aigi.ox.ac.uk/wp-content/uploads/2025/07/Verification_for_International_AI_Governance.pdf) | 3 Jul 2025 (the publisher’s date; the document prints none) | proposed |
| Petrie, Aarne, Ammann, Dalrymple | [Flexible Hardware-Enabled Guarantees for AI Compute (Part I)](https://arxiv.org/abs/2506.15093) | cover Apr 2025; arXiv 18 Jun 2025 | proposed |
| Petrie, Aarne | [Part II: Technical Options for Flexible Hardware-Enabled Guarantees](https://arxiv.org/abs/2506.03409) | cover Apr 2025; arXiv 3 Jun 2025 (v3 18 Jun) | proposed |
| Aarne, Petrie | [Part III: International Security Applications of Flexible Hardware-Enabled Guarantees](https://arxiv.org/abs/2506.15100) | cover Apr 2025; arXiv 18 Jun 2025 | proposed |
| Cankaya (MIRI) | [A System Overview for Near-Term, Low-Trust AI Compute Verification](https://techgov.intelligence.org/research/a-system-overview-for-near-term-low-trust-ai-compute-verification) | 23 Jun 2026 | proposed |
| Rahman, Tajdari | [Detecting Hidden ML Training With Zero-Overhead Telemetry](https://arxiv.org/abs/2606.19262) | 17 Jun 2026 | prototype |
| Rahman | [Does Distributed Training Undermine Compute Governance?](https://arxiv.org/abs/2605.29359) | 28 May 2026 | analysis |
| Scher (MIRI), Sarbakysh, Moskvin (SPAR fellows) | [De-risking Interconnect Limits for AI Verification](https://techgov.intelligence.org/blog/de-risking-interconnect-limits-for-ai-verification) | 30 Jul 2026 | prototype |
| Avellar (independent researcher; the work partly during an IAPS fellowship), Grunewald (IAPS) | [Near-Term Verification Methods for AI Chip Exports](https://arxiv.org/abs/2609.07637) | arXiv 7 Sep 2026; first published by IAPS in August 2026 under Grunewald’s byline | proposed |
| Brass, Aarne (the publisher’s attribution; the report itself is unbylined) | [Location Verification for AI Chips](https://www.iaps.ai/research/location-verification-for-ai-chips) | 2024 (the publisher’s date; the document prints none) | prototype |
| Brass | [Location Verification for AI Chips, issue brief](https://www.iaps.ai/s/Location-Verification-two-pager-68r3.pdf) | May 2025 | prototype |
| Heim (GovAI), Fist, Egan, Huang, Zekany, Trager, Osborne, Zilberman | [Governing Through the Cloud: The Intermediary Role of Compute Providers in AI Regulation](https://cdn.governance.ai/Governing-Through-the-Cloud_The-Intermediary-Role-of-Compute-Providers-in-AI-Regulation.pdf) | 13 Mar 2024 | proposed |
| Fist (CNAS), Grunewald | [Preventing AI Chip Smuggling to China](https://www.cnas.org/publications/reports/preventing-ai-chip-smuggling-to-china) | 24 Oct 2023 | proposed |
| Wasil, Reed, Miller, Barnett | [Verification methods for international AI agreements](https://arxiv.org/abs/2408.16074) | 28 Aug 2024 (v2 4 Nov 2024) | analysis |
| Shavit | [What does it take to catch a Chinchilla? Verifying Rules on Large-Scale Neural Network Training via Compute Monitoring](https://arxiv.org/abs/2303.11341) | 20 Mar 2023 (v2 30 May 2023) | proposed |
| Chen, Hu, Ye, Xu | [RolloutPipe: Overlapping Pipelined Rollout and Training in Disaggregated On-Policy LLM Reinforcement Learning](https://arxiv.org/abs/2606.26997) | 25 Jun 2026 (v2 5 Jul 2026) | evidence |
| Organisation for the Prohibition of Chemical Weapons | [Chemical Weapons Convention, Article IX and Verification Annex Part X](https://www.opcw.org/sites/default/files/documents/CWC/CWC_en.pdf) | — (the consolidated text prints no date on the page cited) | in force |
| NVIDIA | [GPU Claims, Attestation SDK claims guide (version 3.0)](https://docs.nvidia.com/attestation/advanced-documentation/latest/claims-guide/gpu_claims.html) | 1 Aug 2026 (page last updated) | existing |
| Epoch AI | [AI data centers; GPU clusters; the data-centres methodology](https://epoch.ai/data/data-centers-documentation/methodology) | read 11 Sep 2026 | data |

Showing 20 of 22Show all 22