Let’s talk about what a frontier training run physically is.
Somewhere, there is a building containing tens of thousands of accelerator chips. Each was fabricated at one of the handful of leading manufacturers you mapped in Module 1, shipped across borders, bought with purchase orders, and installed by contractors. The building continuously draws power equivalent to the consumption of a small city for months. Every watt ends up as heat, so the facility is always dumping city-scale heat into the air or a river. The billions of dollars involved moves through banks and contracts, leaving records. Several hundred engineers have to be hired, which means job postings, moved equity, and LinkedIn.
While a state can lie in its declarations, it cannot hide such evidence in thermodynamics, customs, payrolls, or the electrical grid. Intelligence, as this course uses the word, means collecting and reading those traces without the cooperation of the actor being watched.
By the end of this submodule, you will be able to:
- For a frontier training run, name the signatures it leaves and the collection discipline that reads each, and state for any one of them what it establishes, what access it requires, and its main caveat.
- Convert a facility's power draw into an order-of-magnitude bound on its compute, classify a site from its draw alone, and state how fast that signature decays as performance per watt improves.
- Explain why intelligence identifies violations but does not resolve them: what national intelligence found that safeguards missed, why sharing with a verifier stays voluntary, and the limits the literature agrees on.
- Place an ambiguous signal on the sequence from anomaly to verification lead to suspected non-compliance, with a stated confidence, after evaluating its sources, weighing the base rate, and ruling out the analytic failures that make a confident assessment wrong.
- Choose the proportionate regime response to a lead, from clarification to challenge inspection, weighing the cost of a false alarm against the cost of a miss, and record the confidence, dissent, and blind spots the decision rests on.
- Write, for a decision-maker who has not taken the module, an overview of what intelligence-based mechanisms can see this year: current public artifacts, limits stated as the papers state them, and each blind spot with the mechanism that covers it.
Why Intelligence?
The two most unique and important properties of intelligence mechanisms:
- It works without the monitored actor’s permission.
- It doesn’t require additional infrastructure, technological or political.
The mechanisms in 2.1 and 2.2 assume cooperation: hardware roots of trust need chips built or retrofitted for the purpose, and provider reporting covers only what passes through a covered provider. Intelligence-based mechanisms do not. As intelligence mechanisms bypass the hurdle of political cooperation, we teach them as one of the most important mechanism categories. If an emergency pause started tomorrow, this layer would likely be the most feasible to start working by evening.
The three papers this module draws on name it differently. Wasil et al. call it the national technical means (NTM) category, Six Layers calls it Layer 6, and Scher and Thiergart call it the national-intelligence building blocks.
We divide the verification methods into three categories: (a) national technical means (methods requiring minimal or no access from suspected non-compliant nations), (b) access-dependent methods (methods that require approval from the nation suspected of unauthorized activities), and (c) hardware-dependent methods (methods that require rules around advanced hardware).
Wasil, Reed, Miller, and Barnett (2024)
A key problem with intelligence mechanisms, however, is ambiguity. A hundred-megawatt building full of accelerators might be a covert training site, or it might be a video-streaming company’s new region, and from the outside they can look identical. Several hundred data centers in the world are large enough to be candidates.
So, the questions that organize this section target this central issue of discernment: which traces are worth watching, and what does each one actually establish (2.3.1–2.3.5)? How do you read ambiguous traces without fooling yourself, which turns out to be the hardest part of the job (2.3.6)? And when you have the full picture, what do you tell the person who has to act on it (2.3.7)?
One collection discipline is missing from that list. Every paper this module draws on counts human sources (HUMINT) as intelligence, but the people inside a program, the channels that let them report, and the audits and inspections that grant a verifier access are too much for one section, and granted access is not intelligence in the sense above. They have a submodule of their own, 2.4.
By the end of this module, you should be able to take signals, whether they’re thermal plumes, an import spike, or a suspicious hiring wave, and identify what it establishes, what else would explain it, and what it justifies doing next.
Signatures
This module describes each signature in the same three parts: what it tells a verifier, what access it requires, and its main caveat. One question applies to every signature: would it survive an adversary who knows it is being watched?
Signatures fall into four families:
- Facility signatures — what the building is and looks like.
- Resource-flow signatures — power, water, chips, money moving in.
- Organizational signatures — who is hired, who contracts with whom.
- Operational signatures — what the site does, and when.
Provider-reported utilization belongs to 2.2, the declared side. This layer covers what never enters a report.
The Collection Disciplines
Intelligence is collected in a small number of ways, usually called the collection disciplines or the INTs, each named for its source. The map lists the eight this module uses, divided into literal and nonliteral collection. Open each card; sections 2.3.1–2.3.5 cover the disciplines one at a time, and HUMINT is read in 2.4.
Reading
The reading for this section is the source of the NTM category itself. Wasil and colleagues go through the national technical means method by method, the methods a verifier can use without the other side's approval, and the two questions on the card are the ones to hold on to.
Verification methods for international AI agreements
Read pp. 5–7, the national technical means category, method by method. Think
- Why does the word “unilaterally” matter in the definition of NTM?
- Which listed method did you not expect, and why?
Wasil, Reed, Miller, and Barnett (2024) | 7 min

