This lesson is a document packet. You will read three primary sources on how verification has actually worked in practice: the legal basis of IAEA safeguards, a proposal to monitor large AI training runs through the chips that run them, and an account of what inspectors failed to see in Iraq. Tasks at the end ask you to compare them.
Document 1. The Object and Scope of IAEA Safeguards
The following excerpts describe the legal commitment underlying comprehensive safeguards and the object against which the IAEA assesses compliance.
Preventing the spread of nuclear weapons is a complex task. Eighty years after the destructive power of nuclear weapons was first demonstrated, a number of international political and legal mechanisms are in place to help to achieve nuclear non-proliferation objectives. They include political commitments of States, multilateral treaties, other legally binding agreements in which States’ non-proliferation commitments are embedded, and, critically, IAEA safeguards. The IAEA plays a crucial independent verification role, aimed at assuring the international community that nuclear material, facilities and other items subject to safeguards are used only for peaceful purposes.
IAEA safeguards are a set of technical measures that allow the IAEA to independently verify a State’s legal commitment not to divert nuclear material from peaceful nuclear activities to nuclear weapons or other nuclear explosive devices. Pursuant to the IAEA’s Statute, which authorizes the IAEA to establish and administer safeguards, States accept the application of such measures through the conclusion of safeguards agreements with the IAEA.
The implementation of IAEA safeguards comprises four fundamental processes, namely (i) the collection and evaluation of information, (ii) the development of a safeguards approach for a State, (iii) the planning, conduct and evaluation of safeguards activities, including in-the-field and at Headquarters, and (iv) the drawing of safeguards conclusions. Throughout these processes, the IAEA performs various of safeguards activities, from the measurement of nuclear material items in facilities to the analysis of safeguards relevant information at Headquarters.
[…]
Though nuclear energy has the potential to contribute to the prosperity of the world, it may also be used for the development of nuclear weapons. The IAEA was established in 1957 to help reconcile the dual nature of the atom, so that nuclear energy could be placed in the service of peace and the development of humankind while protecting against its misuse. The implementation of IAEA safeguards assures the international community that nuclear material is used only for peaceful purposes.
Almost all countries use nuclear applications for a variety of peaceful purposes, including food and water security, energy, industrial applications and human health. Only a few of these activities involve the type of nuclear material that could potentially be diverted to produce nuclear weapons or other nuclear explosive devices.
The majority of safeguards agreements are concluded by the IAEA with non-nuclear-weapon States (NNWSs) party to the Treaty on the Non-Proliferation of Nuclear Weapons (NPT). Under the NPT, these States have committed not to produce or otherwise acquire nuclear weapons, to place all of their nuclear material and activities under IAEA safeguards and to allow the IAEA to verify their commitments.
[…]
Comprehensive safeguards agreements (CSAs): all non-nuclear-weapon States (NNWSs) party to the Treaty on the Non-Proliferation of Nuclear Weapons (NPT), as well as States party to the regional nuclear-weapon-free zone treaties (NWFZ Treaties), are required to conclude CSAs with the IAEA. Such agreements are concluded on the basis of INFCIRC/153 (Corrected). A State undertakes to accept IAEA safeguards on all nuclear material in all peaceful nuclear activities within its territory, under its jurisdiction or carried out under its control anywhere. Under these agreements, the IAEA has the right and obligation to ensure that safeguards are applied on all such nuclear material for the exclusive purpose of verifying that such material is not diverted to nuclear weapons or other nuclear explosive devices.
International Atomic Energy Agency (2024)
Document 2. What Does It Take to Catch a Chinchilla?
The second document moves from nuclear material to AI compute. Shavit proposes that the specialized chips used for large training runs log their own activity, so that governments could check whether a company or another government broke an agreed rule on training. The excerpt is his own summary of the three parts of that system.
In this paper, we propose a monitoring framework for enforcing rules on the training of ML models using large quantities of specialized ML chips. Its goal is to enable governments to verify that companies and other governments have complied with agreed guardrails on the development of ML models that would otherwise pose a danger to society or to international stability. The objective of this work is to lay out a possible system design, analyze its technical and logistical feasibility, and highlight important unsolved challenges that must be addressed to make it work.
The proposed solution has three parts:
- To prove compliance, an ML chip owner employs firmware that logs limited information about that chip’s activity, with their employment of that firmware attested via hardware features. We propose an activity logging strategy that is both lightweight, and maintains the confidentiality of the chip-owner’s trade secrets and private data, based on the NN weights present in the device’s high-bandwidth memory.
- By inspecting and analyzing the logs of a sufficient subset of the chips, inspectors can provably determine whether the chip-owner executed a rules-violating training run in the past few months, with high probability.
- Compute-producing countries leverage supply-chain monitoring to ensure that each chip is accounted for, so that actors can’t secretly acquire more ML chips and then underclaim their total to hide from inspectors.
The system is compatible with many different rules on training runs (see Section 2.1), including those based on the total chip-hours used to train a model, the type of data and algorithms used, and whether the produced model exceeds a performance threshold on selected benchmarks. To serve as a foundation for meaningful international coordination, the framework aspires to reliably detect violations of ML training rules even in the face of nation-state hackers attempting to circumvent it. At the same time, the system does not force ML developers to disclose their confidential training data or models. Also, as its focus is restricted to specialized data-center chips, the system does not affect individuals’ use of their personal computing devices.
Yonadav Shavit (2023) | CC BY 4.0
Document 3. Iraq and Undeclared Infrastructure
The first two documents describe systems as designed. This one describes a failure. Carlson explains why IAEA inspectors did not detect Iraq's clandestine program for years, what the access rules and detection techniques of the time could not reach, and what safeguards gained afterward, including environmental sampling and satellite imagery.
What do these cases tell us about the effectiveness of IAEA safeguards? Does the failure to detect undeclared activities, which in some cases were part of a pattern of clandestine activities extending over as long as 20 years, suggest fundamental weaknesses in safeguards? These failures can be attributed to a number of factors existing at the time, including:
- restrictions on inspector access – under traditional safeguards IAEA inspectors could access only defined strategic points at declared nuclear facilities (and certain locations outside facilities). In all these cases some undeclared activities had been undertaken on safeguarded sites, but away from the strategic points where inspectors could go;
- lack of detection techniques – e.g. until the introduction of environmental sampling (see below) it was very difficult to detect activities such as small-scale plutonium separation;
- IAEA culture – a “checklist” approach to inspections had evolved, with inspectors not being trained to look beyond the obvious. This, combined with the access restrictions already mentioned, led to many inspectors having a narrow perception of their duties. One reflection of this was the approach taken to safeguards exemptions, since tightened up.
While the Iraq situation was a low point for the IAEA safeguards system, there were some positive aspects. The existence of clandestine enrichment was first revealed through detection and analysis of microscopic uranium particles on the clothing of hostages held by the Iraqis. Thus an important new verification tool - environmental sampling - was introduced to safeguards. Also in unravelling Iraq’s nuclear program extensive use was made of satellite imagery. Environmental analysis and satellite imagery have since become well established safeguards techniques.
[…]
Clearly detecting undeclared nuclear activities at undeclared sites is more difficult - this is the greatest challenge currently facing safeguards. While it is possible indicators of undeclared nuclear activities could be detected through non-location-specific monitoring operations - such as wide area environmental monitoring (currently not considered sufficiently proven for deployment by the IAEA), or environmental analysis at a declared site fortuitously detecting emissions from another, undeclared, site - the fundamental problem here is identification of locations for investigation. Wider access rights are of limited practical value without leads on where to seek access. This requires information analysis - and is particularly dependent on information from states, whose information collection and analysis capabilities (including use of satellites and intelligence activities) are generally far greater than those of the IAEA.
John Carlson, Australian Safeguards and Non-Proliferation Office
The Tasks
Read Documents 1–3. Complete Task 5 and any one of Tasks 1–4.
In each answer:
- distinguish the text’s claims from your own inferences.
- support your analysis with specific evidence.

