An isolated statement from one device doesn't actually prove the necessary negative: that an illicit training run is not happening anywhere within the relevant jurisdiction. As such, this section zooms out to clusters and systems: what a device credential establishes, how far location and cluster topology can be verified today, and why proving that no compute exists outside the declared system needs evidence that hardware cannot supply on its own.
A registry of covered accelerators can support several verification tasks. It can link a device credential to an owner, facility, jurisdiction, and reporting obligation. It can also make discrepancies visible when manufacturer, shipping, customs, provider, or site records disagree.
A registry is not a sensor. It is an institutional record whose value depends on how entries are created and reconciled.
Identity
A device credential can help a verifier distinguish a genuine covered device from an unauthenticated substitute. The verifier still needs to know:
- Who created or certified the identity
- Whether duplicate or counterfeit credentials are detectable
- How ownership transfers are recorded
- How lost, damaged, exported, or scrapped devices are handled
- How legacy and nonparticipating hardware enters the regime
- What evidence links the credential to the physical device being inspected
Identity is a useful anchor for evidence from other mechanisms. It does not establish location, interconnection, use, or completeness.
Location
Location-verification proposals often use network timing or challenge-response measurements. A verifier sends unpredictable challenges and checks whether response times are consistent with the claimed region. Such protocols may make some forms of remote spoofing costly, but they depend on:
- Secure time
- Protected processing
- Network conditions
- Calibration
- A tolerable false-positive rate
Hardware-governance surveys continue to treat robust, scalable location verification as an open research area rather than a fielded treaty capability.
O’Gara et al., Hardware-Enabled Mechanisms for Verifying Responsible AI Development — arXiv:2505.03742, 2025.
A location claim should therefore state its resolution and error model. “Inside Country A,” “inside this data center,” and “inside this rack” are different claims.
Cluster Topology
A collection of individually authenticated devices is not automatically a cluster. A verifier may need to establish:
- Which devices were connected
- Which interconnects and switches were used
- Whether the configuration changed during the reporting period
- Whether the workload was split across declared and undeclared devices
- Whether the cluster definition aggregates sequential, distributed, or cross-site activity
Current attestation support illustrates the distinction. Some configurations can report more about protected interconnects, while others attest devices independently. The treaty claim must follow the evidence, not the marketing category.
Completeness
The hardest claim is often negative: no relevant compute existed outside the declared system.
Attestation covers devices that participate. A registry covers devices that entered the registry. Neither proves that the fleet is complete. Completeness can draw on:
- Manufacturer and foundry production records
- Packaging, distribution, export, customs, and shipping records
- Provider inventories and allocation records
- Physical inspection and device counts
- Power, cooling, construction, procurement, and network evidence
- Intelligence on undeclared facilities or diversion
- Insiders who report substitution, tampering, or hidden capacity
Hardware is therefore strongest for known, instrumented compute. The intelligence and human sections will address what remains when the operator never registers the device, never installs the monitor, or never submits evidence.
Try It
The treaty body wants to support the claim: “All covered accelerators at Site X are registered and accounted for.” Choose three evidence streams that do not share the same source. For each, name the actor that produces it and one way it could fail.

