Skip to main content

AI Safety · Hardware

AI on a chip.Is it safer?


Etching a mind into silicon sounds like the obvious way to contain it. Three very different ideas hide behind the phrase. Only one is really a boundary, and even that one has a soft underbelly.

An AI chip with a guard beside it A dark silicon die, its surface a grid of fixed model weights, sits inside a dashed tamper-proof enclosure. Beside it, a smaller guarantee processor outlined in blue sits between the chip and the outside world, with pulses of data passing through it. Above, a licence ring slowly counts down. Labels read: weights fixed in metal, idea one, hardwired model; guarantee processor, idea two, sees every byte; licence expires unless renewed; enclosure opened, keys wiped. WEIGHTS FIXED IN METAL IDEA ONE · HARDWIRED MODEL GUARD PROCESSOR IDEA TWO · SEES EVERY BYTE LICENCE EXPIRES UNLESS RENEWED ENCLOSURE OPENED KEYS WIPED

After watching Geoffrey Hinton explain why digital minds are so hard to contain, one question wouldn't leave me alone. If software can copy itself everywhere, why not go the other way? Etch the AI into a chip. Give it walls it can't climb.

It turns out someone had already asked him. In a January 2025 episode of the Theories of Everything podcast, host Curt Jaimungal passed on a question from the computer scientist Scott Aaronson: what about building AIs on unclonable analog hardware, so they can't copy themselves all over the internet? (Theories of Everything) Hinton's answer cut both ways. That's how we work, he said. Analog minds can't share what they know efficiently, and that's a real cost. But if you're worried about safety, he allowed, the upside is that such a mind can't easily copy itself.

Copying is the heart of his worry. A digital model can run as many identical copies on different machines, each learning from different data, and the copies can pool what they learn by averaging their weight updates. That's how a model ends up knowing more than any single copy ever saw. People can't do this. To move knowledge from my head to yours, I have to produce words and you have to adjust your own brain to match. Hinton puts a sentence at about 100 bits. Large models can share trillions. He has made the same comparison before, including on PBS in 2023 (Amanpour & Company).

So the instinct is to narrow their channel too. Make the mind physical. Make it local. Make it stay put. It's the kind of idea a character in one of my novels might pitch in a tense late-night meeting, and it sounds almost too sensible. So I went looking for what engineers and governance researchers actually think.

"AI on a chip" hides three very different ideas. Only one of them is really a boundary.

17,000

tokens a second for one user, Taalas's claimed speed for a model built into its chip

<$1,000

the cost of the TEE.fail rig that forged trusted-hardware certificates

42–0

the House committee vote for chip location checks. It still isn't law.

Sources: Taalas · TEE.fail · Ripon Advance

Idea one · Speed

Bake the model into the silicon.

This one is real, it's already running, and it has almost nothing to do with safety.

In February 2026 a Toronto startup called Taalas unveiled the HC1, a chip with Meta's Llama 3.1 8B model physically built into it (Taalas). The model's weights aren't loaded from memory. They're fixed into the chip's structure, with storage and computation merged on the same die. Taalas claims about 17,000 tokens per second per user, nearly ten times the state of the art, at a tenth of the power. When the German tech outlet heise tried the public demo, it reached almost 16,000 (heise). It's available as a public chatbot demo and an API for developers. The company says it built this first product with 24 people and $30 million, out of the more than $200 million it had raised.

One model, very fast.

Tokens per second for a single user running Llama 3.1 8B.

Inference speed comparison Horizontal bar chart. Nvidia H200, about 230 tokens per second. Groq, 609. SambaNova, 916. Cerebras, 1,936. Taalas HC1, 17,000 claimed by the company, with a marker showing heise measured almost 16,000 on the public demo. Nvidia H200 230 Groq 609 SambaNova 916 Cerebras 1,936 Taalas HC1 17,000 claimed heise test: almost 16,000
Taalas's figure is the company's own claim; heise measured almost 16,000 on the public demo. The other figures are as reported by heise, from Nvidia's own baseline (H200) and independent benchmarks by Artificial Analysis. Sources: Taalas, heise.

There are trade-offs. To fit, the model was squeezed down to 3- and 6-bit numbers, which Taalas itself says costs some quality. And the chip runs that one model, nothing else. To build a chip for a different model, Taalas changes only two of the roughly 100 metal layers on the die, which it says takes about two months (Falk AI). On 6 August 2026, AMD announced a definitive agreement to buy the company, subject to the usual closing conditions and regulatory approvals (AMD).

A rival, Etched, makes a different bet. Its Sohu chip hardwires the transformer architecture rather than one model's weights, so it can run any transformer model, and nothing else (Spheron).

So is a model frozen in silicon a model on a leash? The writer Johan Falk argues it's closer to the opposite. A hardwired chip, he notes, behaves a lot like an open-weight model you've downloaded: no central oversight, no usage logs, no way to revoke access, and no way to push a fix if a flaw turns up after manufacture (Falk AI).

His conclusion is the one that matters for safety. Any testing has to happen before a model is etched into a million devices, because afterwards there's no recall button.

Freezing a mind doesn't make it safer. It just makes it harder to fix.

Idea two · Verification

Put a guard beside the chip.

The serious "boundaries" work looks quite different. It doesn't freeze the AI. It puts a witness next to it.

The most developed version is called a Flexible Hardware-Enabled Guarantee, or flexHEG, set out in an April 2025 report commissioned by ARIA, the UK's Advanced Research and Invention Agency (Petrie, Aarne, Ammann & Dalrymple). Picture a powerful AI chip sealed inside a tamper-proof enclosure together with a small "guarantee processor" that sees everything going in and out. The guard can prove facts about the chip's work without revealing the work itself, along the lines of "this model was trained with less than a set amount of computation." It could check roughly where the chip is, refuse to let model weights leave unencrypted, or require a valid licence before running very large jobs.

How a flexHEG would work.

Everything reaches the chip through the guard. The guard reports proofs, not data.

Diagram of a flexible hardware-enabled guarantee An AI chip and a guarantee processor sit together inside a dashed tamper-proof enclosure. All data passes between the outside world and the chip through the guarantee processor. The guard sends out proofs, such as a statement that a model was trained with less than a set amount of computation, without sending the data itself. A licence must be renewed or the chip stops. If the enclosure is opened, its secret keys are wiped and, optionally, fuses blow to disable the chip. TAMPER-PROOF ENCLOSURE AI chip runs the model Guarantee processor Data in and out only via the guard Proofs, not data "trained with less than X computation" Licence renew it or the chip stops Open the enclosure and its secret keys are wiped. Optionally, microscopic fuses blow and the chip is disabled for good.
Simplified from the flexHEG design. In the full proposal the rules the guard enforces can be updated, and the power to update them can sit with the chip's owner or with a group of countries. Source: Petrie et al., 2025.

The design has some striking details. If anyone tries to open the enclosure, the system wipes its secret keys, and it can be set to blow microscopic fuses that disable the chip for good. To stay current, the guard could require a firmware update every few months or the chip stops working. And the report makes a subtle point about off-switches. A "stop" signal can always be blocked by whoever controls what reaches the chip, so the only reliable off-switch is a licence that expires unless someone renews it.

Policy researchers like this approach because the rules could be updated by agreement, potentially needing sign-off from several countries, and because it avoids secret back doors. A 2024 report from the Center for a New American Security argued much the same: chip-level governance can work through privacy-preserving verification and renewable licences, without covert monitoring of users (CNAS).

Pieces of this are arriving faster than I expected. In December 2025, Nvidia confirmed it had built optional, customer-installed software that estimates which country its chips are running in by measuring the delay when they talk to Nvidia's servers (TechCrunch, citing Reuters). In Washington, the Chip Security Act would require location verification on export-controlled AI chips. It cleared the House Foreign Affairs Committee 42–0 in March 2026, but it is not law (Ripon Advance). A separate bill, the Stop Stealing Our Chips Act, passed the Senate in May 2026 and would pay whistleblowers who report illegal chip exports. It too still needs the House (Ripon Advance).

The motive is concrete. In December 2025 the US Justice Department said one network had exported or tried to export at least $160 million of controlled Nvidia H100 and H200 chips between October 2024 and May 2025, using falsified shipping papers (US DOJ). Our earlier piece on China's chip workaround covers why that hardware matters so much.

Where the pieces stand.

Status as of 10 October 2026.

  • flexHEG guard processorProposal in an ARIA-commissioned report, April 2025. Early versions may have to compromise on security.Not built
  • Firmware licence checksCould be pushed to chips already in service, but firmware alone is the easiest layer to tamper with.Proposal
  • Nvidia location softwareOptional and customer-installed; demonstrated privately, confirmed December 2025.Built, opt-in
  • Chip Security Act (H.R. 3447)Location checks on exported AI chips. Passed committee 42–0, March 2026.Not law
  • Stop Stealing Our Chips Act (S. 1473)Rewards for whistleblowers who report illegal chip exports. Passed the Senate, May 2026.Awaiting House
  • TEE.fail attack on trusted hardwarePublished late 2025. Intel and AMD say physical attacks like this are outside what their protections are designed to stop.No vendor fix
Sources: Petrie et al., Petrie (2024), TechCrunch, Ripon Advance (House), Ripon Advance (Senate), TEE.fail.

The soft underbelly

Where the guard fails.

The flexHEG authors are unusually candid about the limits of their own idea. Those limits are the real story.

01

It isn't built yet.

The report says early versions may have to compromise on security, with physical protection that may start as little more than locks, tamper-evident seals and cameras. The quickest near-term option, a licence check delivered as a firmware update to chips already in service, is also the easiest to tamper with (Petrie, 2024; Al Ramiah et al., 2025). CNAS estimated that hardening chips for genuinely hostile settings could take from 18 months to four years of focused work.

02

Rules can be split.

A cap on how much computing one chip can do might be dodged by slicing a big training run into many small ones (Al Ramiah et al., 2025). The flexHEG report flags a version of this itself: a chip may not be able to tell that the model it's running is only one "expert" inside a much larger system.

03

Physical access is the weak point.

This isn't hypothetical. In late 2025, researchers from Georgia Tech and Purdue showed an attack called TEE.fail: a device costing under $1,000, small enough to fit in a briefcase, that sits between a server's processor and its memory and reads the traffic, once the attacker also has administrator access to the machine (TEE.fail). With it they pulled secret keys out of the "trusted" security zones in Intel and AMD server chips, forged the digital certificates that prove a machine is trustworthy, and used those to fake the protections around Nvidia's GPU confidential computing too. Intel and AMD responded that physical attacks of this kind fall outside what their protections are designed to stop. That is exactly the threat a chip-level leash has to survive.

04

It governs compute, not intent.

This, to me, is the line that matters most. The flexHEG report states plainly that whether a computation counts as misuse often depends on what's done with the result afterwards, which the chip can't know. A guard can tell you who ran what, where and how much. It can't tell you what the model wants. That's why a 2026 policy paper treats hardware governance as one layer of a defence-in-depth stack, alongside software safeguards, institutions and legal liability. It also warns that the same controls could be turned into tools for surveillance or repression unless no single government or company can hold the switch alone (Gomes, The Open-Weight Paradox).

Hinton adds a weak point that's harder to engineer away. In the same interview he warned against assuming we can simply switch these systems off. A mind much smarter than us, trained on every account of human deception ever written, wouldn't need to break the enclosure. It could persuade the person holding the key (Theories of Everything).

Every hardware leash still ends in a human hand.

Idea three · Mortality

A mind that dies with its body.

Hinton's own counter-idea is the most poetic of the three and the least built. He calls it mortal computation, and he knows its limits from the inside. He told Jaimungal that his turn toward alarm came from two things at once: ChatGPT, and his own work at Google on analog computing to save power, which left him convinced that "digital computation was just better" (Theories of Everything). The brain still wins on energy, he noted. We run on about 30 watts and have around 100 trillion connections, roughly a hundred times more than the biggest models.

In his 2022 Forward-Forward paper, Hinton points out that computer science has always insisted on keeping software separate from hardware, so the same program can run anywhere. That makes the knowledge immortal (Hinton, 2022). Give that up, he suggests, and you could build cheap, imprecise analog hardware in which each chip learns to exploit its own physical quirks. The learned settings would be useless on any other chip, so the computation dies with the hardware. He even suggests that if you want a trillion-parameter network to run on a few watts, mortal computation may be the only option.

It's tempting to read this as the ultimate leash: nothing to copy, nothing to spread. But Hinton himself supplies the catch. A mortal machine's knowledge can move. You train a new chip to imitate the old one's answers, a technique called distillation that he helped develop. In a November 2023 talk at MIT he described handing knowledge to a younger machine this way, and called education slow and painful (Hinton, MIT abstract). Mortality doesn't stop a mind from spreading. It slows it to the speed of teaching. Which is, of course, exactly how our minds spread.

There's a second wrinkle. Much of the efficiency Hinton describes comes from computing inside memory rather than shuttling data back and forth, and that doesn't need mortality at all. IBM's analog in-memory chip, reported in Nature in 2023, ran speech recognition about 14 times more energy-efficiently than conventional hardware (Ambrogio et al., Nature). And Taalas, from idea one, gets its speed by merging memory and compute in ordinary digital silicon that can be manufactured again and again. The efficiency and the mortality can be pulled apart, and the industry seems to be keeping the first and skipping the second. Our piece on brain-inspired chips follows that thread further.

Three ways to put AI on a chip.

Compare what each one can and can't do.

Comparison of hardwired models, guard processors and mortal computation
Idea oneHardwired model Idea twoGuard beside the chip Idea threeMortal computation
ExampleTaalas HC1flexHEGHinton's proposal
Exists today?Unveiled February 2026; running as a demo and APIProposal; related pieces exist, such as Nvidia's opt-in location softwareResearch idea (2022)
Can it be copied?The chip can't be copied like a fileCan lock a model's weights to approved devicesNot directly; knowledge moves slowly, by teaching
Fixable after release?No, apart from small adapter filesYes: rules and firmware can be updatedOnly by training a new chip
Governs what the AI wants?NoNoNo
Sources: Taalas, Falk AI, Petrie et al., Hinton (2022).
how to ensure that they never want to take control
— Geoffrey Hinton, on the most urgent research question in AI. Abstract for his talk at MIT, November 2023.

What no chip can answer

From "how do we hold it?" to "what will it want?"

What struck me most is where Hinton himself lands. In that MIT abstract he doesn't name containment as the priority. He names motivation: the most urgent research question, he wrote, is how to make sure these systems never want to take control.

By August 2025 he'd gone further. At the Ai4 conference in Las Vegas he argued that trying to keep superintelligent AI submissive won't work, and that we should try to build in something like maternal instincts instead, so the systems genuinely care about people (CNN). Not everyone agreed. Fei-Fei Li, speaking at the same conference, said she thought that was the wrong way to frame it. But look at the shift. The person who did more than anyone to explain why digital minds are hard to contain has moved from asking how we hold them to asking what they'll want. Our profile of Geoffrey Hinton and The Race to Make Them Nicer go deeper on that turn.

What I take from all this.

A boundary enforced by hardware can do real things. It can stop a system from being quietly scaled up, smuggled across a border, copied or moved. Those are worth having, and the work deserves funding now, because the authors are right that it takes years to build.

But it can't make a system's goals benign. And its weakest point is physical: a determined actor with their hands on the device, and as TEE.fail shows, those hands don't have to be very well-funded.

This is the territory I keep circling in my SPECIEST novels. A constraint you can inspect from the outside is a different thing from a mind that's content inside it. The interesting stories, and I suspect the interesting real-world problems, begin where the leash and the creature disagree about what the leash is for.

Hinton would push that further. In the same podcast conversation he argued that multimodal chatbots may already have subjective experience in the only sense the phrase has ever meant: a perceptual system reporting something that turns out not to be true, like a robot whose camera has been fitted with a prism, pointing to where an object only seems to be (Theories of Everything). You don't have to agree with him to feel the question shift.

If a mind can be physically contained, does that settle anything about what it wants, or what it experiences?

How this piece was made

I chose the question and steered the argument after watching Hinton's interview. The research and drafting were done with Claude, an AI model made by Anthropic. Every figure, quote and link was checked against its original source before publishing. Credit where it's due.

Further reading on this site.

Ko-fi Buy me a coffee
Scroll to Top