As frontier artificial intelligence models approach human-level capabilities in dual-use domains including cyber operations, autonomous weapons design, and biological agent synthesis traditional governance mechanisms that rely solely on post-hoc software regulation or developer self-reporting are proving insufficient.
Software can be replicated instantly, finetuned to strip guardrails, or distributed via open weights. Consequently, physical compute infrastructure (advanced GPUs, TPUs, and specialized AI accelerators) represents the most effective regulatory bottleneck for frontier AI safety.
This paper proposes an international technical framework for Advanced Compute Verification (ACV). By integrating cryptographic hardware root-of-trust (RoT), secure enclaves, and standardized telemetry reporting into the semiconductor manufacturing supply chain, international oversight bodies can monitor high-risk compute clusters without compromising proprietary model architectures, intellectual property, or enterprise privacy.
1. The Case for Compute-Level Governance
Traditional regulatory regimes struggle with frontier AI due to three structural features of software:
Zero Marginal Cost of Duplication: Once weights are leaked or released, software safety interventions cannot be revoked.
Asymmetry of Detection: Algorithmic proliferation is difficult to trace compared to the highly concentrated physical manufacturing of advanced microelectronics.
Monolithic Choke Point: The global manufacturing pipeline for leading-edge semiconductors is bottlenecked across a handful of key nodes notably EUV lithography equipment providers (ASML), foundry fabricators (TSMC), and chip designers (NVIDIA, AMD). Because training state-of-the-art models requires tens of thousands of interconnected, high-bandwidth accelerators operating over months, governing the hardware substrate offers a physically verifiable, tamper-resistant mechanism for policy enforcement.
2. Technical Architecture for Hardware Verification To establish verifiable compute governance without enabling state surveillance or exposing enterprise secrets, an ACV framework relies on three technical pillars
A. Physical Root-of-Trust (RoT) & Hardware Attestation
In-Fab Key Provisioning: During fabrication, silicon dies are provisioned with unique, unalterable cryptographic keys embedded via Physical Unclonable Functions (PUFs) or write-once memory.
Remote Attestation: High-performance accelerators periodically generate signed cryptographic attestations confirming their authentic firmware state, hardware ID, and physical topology.
B. Enclave-Gated Compute Allocations & Cryptographic License Enforcers
Signed Compute Leases: Chips operate under cryptographic "leases" signed by authorized auditors or national AI Safety Institutes (AISIs). Compute jobs exceeding agreed capability thresholds (e.g., total Floating Point Operations, or FLOPs, exceeding $10^{26}$) require an active cryptographic signature to run across distributed interconnects.
Automatic Throttling: If hardware detects unauthorized cluster topologies or unverified multi-node communications intended to bypass compute caps, the interconnect fabric throttles inter-chip bandwidth, preventing large-scale distributed training.
C. Privacy-Preserving Telemetry via Zero-Knowledge Proofs (ZKPs)Verifiable Accounting without Data Leakage: Developers run Zero-Knowledge Proof (ZKP) circuits inside Trusted Execution Environments (TEEs. Audit Inputs: The framework reports aggregate FLOP consumption, network topology, and workload signatures to an auditing protocol without exposing model weights, training datasets, or proprietary fine-tuning methods.
3. Implementation & Policy Trade-offs
Regulatory Objective
Technical Implementation Trade-off / Mitigation Prevent Unauthorized Frontier Runs
Interconnect bandwidth caps and cryptographic lease signing.
Risk of performance overhead on benign workloads; mitigated via hardware-accelerated enclave processing.
Protect IP & Data Privacy ZK-telemetry and on-chip encrypted memory boundaries. Complexity in auditing ZK circuit logic; mitigated via standardized open-source audit protocols. Prevent Tampering & Hardware Modifications Physical anti-tamper sensors and mesh layers on silicon.
Higher chip manufacturing scrap rate; mitigated by phasing requirements into next-gen architectures.
4. Governance Integration & Multilateral Framework An effective compute governance regime requires harmonized implementation across national and international bodies:
Mandatory Chip Design Standards: Standard-setting bodies (IEEE, ISO) and multilateral export control regimes must integrate hardware RoT and attestation requirements into baseline technical definitions for high-performance AI accelerators.
Datacenter Auditing Standards: National regulators should require datacenters hosting over a given threshold of total compute capability to implement cryptographically verifiable cluster telemetry.
International Safeguards Inspections: Modeled after international scientific verification frameworks, auditors can use physical and cryptographic checks to verify that total deployed silicon matches registered datacenter capacity, eliminating "ghost clusters.
Conclusion
Governing artificial intelligence at the algorithmic layer is a reactive strategy; governing it at the physical hardware substrate provides proactive security. By standardizing cryptographic verification and privacy-preserving attestation directly on silicon, the international community can create an enforceable, transparent barrier against non-compliant frontier model development while preserving the growth of benign open research and commercial innovation.