Active concealment makes detection harder. Even at 10,000 or 100,000 H100-equivalents, hidden facilities cannot be ruled out with full confidence.
from the paper, for the record.
I'll also note that some Pause advocates make assurances about options to pause research (which is dangerous) but not necessarily inference using established models (circa. 3rd quarter 2026) which is presumably merely useful. and that this would make monitoring harder since activity would be allowed.
Some say, a pause is possible, it merely depends on political will. Others say, tech progress can never be stopped. Maybe the truth lies in the middle? Maybe we can 'catch all GPUs' (that is, effectively enforce a pause or other international agreement) as long as training run sizes are large enough? Maybe every government policy would therefore have a breakdown point, a number of FLOPs or H100-equivalents where the training run gets too small to enforce regulation?
In our new paper, How to Catch a GPU: A Taxonomy of Verification and Enforcement Mechanisms for International AI Agreements:
In addition, we investigate eight off switch/treaty verification proposals from the literature, and catalogue policies they propose. We think our tables with proposed policies, structured per sub-problem, are particularly useful for researchers:
In addition, we include a table with enforcement breakdown pionts per measure for the determining sub-problem detect hidden capacity:
And finally, we include a table in the appendix with proposed FLOP thresholds per off switch proposal:
We hope this work will be useful!
Full paper: https://arxiv.org/abs/2607.22619
Cite as (MLA): Koopmanschap, Raymond, and Otto Barten. "How to Catch a GPU: A Taxonomy of Verification and Enforcement Mechanisms for International AI Agreements."
EA Forum post: https://forum.effectivealtruism.org/posts/9yxcgyAmgFDyEFb2W/is-a-pause-enforceable-new-paper-out