How to Catch a GPU: A Taxonomy of Verification and Enforcement Mechanisms for International AI Agreements
This paper proposes a taxonomy for evaluating international AI agreements by decomposing enforcement into preventing uncontrolled resource acquisition, detecting external capacity, and preventing escape from control regimes, thereby identifying current gaps in existing proposals and defining the thresholds at which specific policies lose effectiveness.
Original paper licensed under CC BY 4.0 (http://creativecommons.org/licenses/by/4.0/). This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer
Imagine the world of artificial intelligence as a massive, high-stakes construction site where engineers are building digital giants. These giants, known as frontier AI models, are so powerful they could potentially cause catastrophic harm if they fall into the wrong hands or run wild. To keep everyone safe, countries are trying to write a global rulebook that says, "No one is allowed to build a giant bigger than a certain size." But here's the tricky part: how do you actually check if someone is following the rules? You can't just ask them nicely, and you can't peek inside every computer in the world. You need a way to catch the bad actors who are trying to sneak a giant machine into a tiny, hidden shed. This is the challenge of "verification and enforcement": making sure the rules aren't just words on a page, but something that actually works in the real world.
This paper, titled "How to Catch a GPU," acts like a detective's guidebook for these international AI agreements. The authors, Raymond Koopmanschap and Otto Barten, break down the massive problem of catching rule-breakers into three smaller, manageable tasks. They argue that to stop a violation, you have to do three things: stop people from stealing the building materials (the computer chips), make sure the people who are following the rules don't secretly start building a giant anyway, and—most importantly—find the secret sheds where the bad guys are hiding their machines.
The authors propose a new way to look at these problems, suggesting that as technology gets better and cheaper, the "giant" machines will get smaller. Eventually, a dangerous AI could fit inside a shipping container or even a small room. The paper analyzes various proposals from experts and finds that while we have good ideas for stopping people from stealing chips and for watching the people who are supposed to be good, we are terrible at finding the secret sheds. The authors suggest that as the required computer power drops, finding these hidden facilities becomes nearly impossible. They define a "breaking point"—a specific size where our current methods of looking for secrets stop working. They find that while we can likely keep track of the big factories, the moment a secret lab shrinks down to the size of a small warehouse (around 10,000 high-end graphics cards), it becomes very hard to tell it apart from a normal building, and if the bad guys try really hard to hide it, we might never find it at all.
The Three-Part Detective Game
To understand how the authors solve this, imagine you are trying to stop someone from building a super-fast race car in their garage. The paper breaks the job of the "traffic police" into three distinct games:
1. The "Don't Steal the Parts" Game (Preventing Uncontrolled Resource Acquisition)
This is about stopping the bad guys from getting the special engine parts they need. In the AI world, these "parts" are the powerful computer chips (GPUs) needed to train the AI. The authors note that right now, making these chips is like baking a very specific, complex cake; only a handful of bakeries in the world have the right ovens. Because there are so few places making them, it's actually quite easy to track them. If you watch the bakeries, you know where every cake goes. The paper suggests that as long as the supply chain stays this concentrated, we can probably stop people from sneaking chips out of the factory. Even if the "race car" gets smaller, the parts are still hard to get without the world noticing.
2. The "Don't Cheat in the Garage" Game (Preventing Escape from the Control Regime)
This game is for the people who are following the rules. Imagine a factory that is allowed to build small cars. The police want to make sure they don't secretly start building the forbidden super-car inside that same factory. The paper suggests that if we put cameras, sensors, and inspectors inside these allowed factories, we can catch them if they try to cheat. The authors argue this is actually the easiest part to solve. If a factory tries to build a forbidden machine, we can just cut the power to the whole building. It's like having a master switch that turns off the lights in a room; if someone is doing something they shouldn't, you just flip the switch. This works whether the machine is huge or small, as long as the machine is inside the room we are watching.
3. The "Find the Secret Shed" Game (Detecting Hidden Capacity)
This is the hardest game, and it's where the paper says things start to fall apart. This is about finding the bad guys who are building their super-car in a shed that the police don't even know exists. The authors explain that right now, big AI factories are easy to spot. They are huge, they use massive amounts of electricity, and they have giant cooling towers that look like industrial smokestacks. You can see them from space!
However, the paper warns that as AI gets smarter, it will need less power to do the same dangerous things. A machine that used to need a whole warehouse might soon fit in a shipping container.
- The Breaking Point: The authors calculate that once a facility shrinks to about 10,000 high-end chips (specifically H100-equivalents), it stops looking like a secret factory and starts looking like a normal office building or a warehouse.
- The Disappearing Act: At this size, the cooling systems become small enough to blend in with normal air conditioners, and the electricity usage looks just like a large supermarket or a hospital.
- The Active Hider: If the bad guys try to hide on purpose (using "active concealment"), the paper suggests we might not be able to find facilities anywhere between 10,000 and 100,000 chips. They could be in a basement, a warehouse, or a container, and our satellites and power monitors would just see a normal building.
Why This Matters
The paper concludes that while we have good plans for watching the factories we know about and stopping people from stealing chips, we are missing a plan for finding the secret ones. The authors suggest that if we don't figure out how to find these smaller, hidden labs, the whole system of international AI rules could fail. It's like having a speed limit sign that works great for big trucks, but if a tiny, fast motorcycle can sneak past the cameras, the rule doesn't actually keep the roads safe.
The authors don't say we should give up; instead, they say we need to focus our energy on the "Find the Secret Shed" problem. They point out that as technology improves, the size of the "forbidden machine" will get smaller, making the hiding game even harder. They suggest that researchers need to invent new ways to spot these tiny, hidden labs before the technology gets too small to see. Until then, the paper argues, the "Find the Secret Shed" part of the plan is the weakest link, and it's the one most likely to break first.
Drowning in papers in your field?
Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.