How a Treaty Can Be Verified

"It's just software on a server" is the most common enforcement objection. You do not police the weights. You police the hardware.

The choke point is compute

Training a frontier model takes enormous, traceable amounts of specialized chips from a short list of makers, packed into large clusters that draw industrial power and leave a paper trail. That physical layer can be watched the way fissile material is watched.

1

Chip tracking

Advanced accelerators are high-value, low-volume goods. Export records, serial tracking, and end-use checks already exist in adjacent regimes. Extend them to large training runs.

2

Cluster licensing

Facilities above a compute threshold require a license, reporting, and inspection rights. Small labs and ordinary cloud users stay out of scope.

3

On-site inspection

Like IAEA visits: scheduled and challenge inspections of large data centers, power draw, and hardware inventories. Software can hide; warehouses full of GPUs cannot.

4

Cloud and foundry rules

Major cloud providers and chip foundries become reporting nodes. A secret Manhattan Project still needs fabs, power, and cooling. Those leave fingerprints.

Perfect detection is not the standard

Nuclear verification never claimed omniscience. It raised the cost and risk of cheating high enough that major powers stayed inside the deal. A superintelligence ban needs the same practical bar: enough visibility that a large illicit training run is hard to hide and expensive to attempt.

Deeper dive

nakadafoundation.org/blog/compute-governance-ai/