"It's just software on a server somewhere." The most common enforcement objection. Wrong surface.
You do not police the weights. You police the hardware. Training a frontier model takes specialized chips from a short list of makers, packed into large clusters that draw industrial power and leave a paper trail.
Advanced accelerators are high-value, low-volume goods. Export records, serial tracking, and end-use checks already exist in adjacent regimes. Extend them to large training runs.
Facilities above a compute threshold require a license, reporting, and inspection rights. Small labs and ordinary cloud users stay out of scope.
Modeled on IAEA visits: routine and challenge inspections of large data centers, power draw, and hardware inventories. Software can hide. Warehouses full of GPUs cannot.
Major cloud providers and chip foundries become reporting nodes. A secret crash program still needs fabs, power, and cooling. Those leave fingerprints.
Nuclear verification never claimed omniscience. It raised the cost and risk of cheating high enough that major powers stayed inside the deal. A superintelligence ban needs the same practical bar: enough visibility that a large illicit training run is hard to hide and expensive to attempt.
Deeper dive: nakadafoundation.org/blog/compute-governance-ai/