New taxonomy exposes gaps in enforcing international AI agreements
Researchers reveal how to verify AI treaty compliance by tracking GPU capacity.
A new paper from researchers Raymond Koopmanschap and Otto Barten, accepted at the International Conference on Large-Scale AI Risks 2026, introduces a structured taxonomy for evaluating enforcement mechanisms in international AI agreements. The core principle: wherever sufficient compute capacity exists to violate an agreement, that capacity must be under a control regime. This breaks the enforcement problem into three sub-problems: preventing uncontrolled resource acquisition (e.g., clandestine GPU farms), detecting all compute capacity outside the control regime, and preventing escape from the regime itself.
The authors analyze existing policy proposals through this lens and find a significant imbalance: most efforts target preventing escape (e.g., hardware locks, monitoring of data centers), while the equally critical problems of detecting hidden compute and stopping resource acquisition receive far less attention. They also define an 'enforcement breaking point' — the FLOP threshold (or equivalent metric) at which a policy loses effectiveness. As the compute required for dangerous AI capabilities decreases over time, more actors can violate agreements, making enforcement progressively harder. The taxonomy provides a systematic way for policymakers to identify where enforceability breaks down first and prioritize efforts accordingly.
- Taxonomy splits AI agreement enforcement into three sub-problems: preventing uncontrolled GPU acquisition, detecting all capacity outside control, and preventing escape.
- Existing proposals focus 80%+ on escape prevention while neglecting detection of hidden compute and resource acquisition controls.
- The 'enforcement breaking point' is defined as the FLOP threshold where a policy ceases to be effective, which drops over time as compute requirements shrink.
Why It Matters
Gives policymakers a structured framework to identify critical gaps in AI treaty enforcement before they can be exploited.