Executive Summary

This article looks at a study that calculated whether a state could sidestep AI regulation by building a data center in the sea, and whether anyone outside could tell that it had. The paper went up on arXiv on September 16 and was written by James Teague, Ashmita Rajmohan and Yannick Muehlhaeuser. Almost every proposal for an international agreement limiting frontier AI development depends on verification, and the hardest task inside that verification is finding compute facilities nobody declared.

The answer splits. Running a training run equivalent to 100,000 H100s underwater does not break on electricity or on cooling. It breaks on the cabling that ties the switches together, and on the maintenance that has to continue by hand while the run is going. Over the 54 days Meta spent training Llama 3 405B, a cluster of 16,384 GPUs hit 419 unexpected interruptions, roughly one every three hours. A sealed pod offers nowhere to put that hand. The detection findings lean one way as well. An operating pod gives up little to heat or to sound, while satellite radar and vessel position tracking work rather well across the months when one is built and serviced.

Sections 1 through 4 follow the calculations in the paper and the sources the paper cites. Section 5 carries the study across to the question of what verifies a declared value, and that reading belongs to this article.

Key figures

Source: Teague, Rajmohan & Muehlhaeuser, arXiv:2609.18824 (September 16, 2026)

150–200 MW

Power for a 100,000-H100 training run

The GPUs alone account for about 70 MW. Server overhead and the switch fabric carry the total toward 150 MW, and the denser hardware of the next three to five years puts 200 MW at the high end

3%

Share of Natick's power spent on cooling

Land facilities have historically put 25 to 40 percent of their electricity into HVAC. Microsoft's Natick, sitting at 11 m, held the figure to 3 percent. Cooling is an advantage here, not a wall

419

Unexpected interruptions in the Llama 3 run

A public record covering 54 days on 16,384 H100 GPUs. Most of these fixes mean touching the hardware by hand, which a sealed pod does not allow

0.17 m/s

Slowest current that still hides the heat

Dumping 200 MW into the water and keeping the surface anomaly inside natural variability takes at least this much flow. Open coastal water usually moves faster than that

1

The Problem That Outlives the Signature

The paper's first sentence is about machinery, not about clauses. Most proposals for international agreements that place restrictions on frontier AI development require robust verification mechanisms to monitor compliance. A world with no agreement at all is not so different, the authors add, citing prior work that deterrence regimes depend on the ability to locate a rival's compute. A promise nobody can check returns nothing for having been made.

That narrows the task to one item. Finding the facilities a state might run quietly to evade a restriction, which the paper calls undeclared or "dark compute". Compute eats electricity, throws off heat and occupies space, so in principle it leaves traces. The open question is where those traces surface and how strong they are when they do.

The sea has been named as a candidate for a while. Water is free coolant, and a site 30 m down inside a territorial sea offers a satellite nothing but surface. The gap the authors point to sits right there. Underwater data centers have been suggested as an evasion vector, yet whether they are actually feasible at frontier scale, and whether they can be detected if they are, has not been seriously assessed. This paper sets out to make that assessment.

One yardstick stays fixed throughout. Can a single training run on the scale of 100,000 H100s be finished underwater? With the number pinned, the argument drops from taste to engineering. How many watts the thing needs, how far a cable reaches, how often a human hand is required. The work was carried out as part of the Orion AI Governance Initiative run by Arcadia Impact.

The question this study puts is not whether a facility can be built in the sea. It is about what a built facility leaves behind for someone outside to count. A treaty's reach rests on the accuracy of that count rather than on the wording of its clauses.

2

The Pods Already Running on the Seabed

Microsoft's Project Natick is the best known case. Phase 1 lowered a single rack of roughly two dozen servers to 11 m off the California coast from August to December 2015. Phase 2 was a different size. A module holding 864 servers sat on the seabed off Orkney at 36 m from June 2018 to July 2020, drawing 240 kW.

Two years in, the water came out ahead. Fewer than one percent of the servers failed, about one eighth the rate of equivalent facilities on land. Credit belonged to two things, and cold water was not one of them. The capsule was filled with dry nitrogen, which strips out the oxygen and humidity that drive corrosion, and none of the accidental bumps, cable pulls and maintenance errors of a staffed building ever happened. The same seal also works in reverse. A fault that a land site would repair within hours, restoring training continuity within minutes, stays dark underwater until the pod is lifted. Across deployments spanning two years or more these faults compound, and long-term performance slides behind an equivalently provisioned cluster on shore. Natick was formally discontinued in 2024 all the same. The reason widely suggested was the difficulty of servicing, upgrading and replacing sealed hardware. The project lead had dismissed that concern at an earlier point. The bottleneck of the next section is already showing here.

The commercial facilities actually running today are Chinese. Highlander, through its subsidiary HiCloud, followed initial tests in 2021 and a first commercial module in 2023 by placing a second commercial module off Hainan in February 2025, adding roughly 400 servers. The Hainan cluster now holds two pods with about 400 servers each, some 800 in total, at a depth near 35 m. Growing incrementally to 100 modules is the long-term target for that site. The Shanghai facility sits a step up in scale. Phase 1 construction finished in October 2025 and operation began in May 2026, making it the first underwater facility linked directly to an offshore wind farm, which supplies more than 95 percent of its power with the grid as backup. Phase 1 runs at 2.3 MW against a 24 MW capacity in the full build-out, and the structure holding its 192 racks weighs 1,950 tonnes. One caveat travels with all of that: the Shanghai facility is not completely submerged, which is why the paper drops it from the rest of its analysis.

The startup figures call for a different posture. Subsea Cloud's announced demonstration pod near Port Angeles, Washington, named Jules Verne, is a 20-foot container using dielectric immersion cooling, reported to hold 16 racks and around 800 servers at 9 m while drawing about 1 MW. The company claims retrieval within 4 to 16 hours for its lighter, pressure-equalised pods. The paper qualifies that claim four times over: an unverified vendor figure, reported at the company's 2022 announcement, covering transit to the site as well as the recovery itself, and never demonstrated at scale. Ahead of all of that, the authors write that they could not find independent verification of any operating facility from Subsea Cloud. NetworkOcean, a Y Combinator-backed startup, has announced a 0.5 to 1 MW test capsule and sketched barges scaling past 200 MW, with 2,048 NVIDIA H100s claimed as reserved for the planned barge. Its first step is to submerge the capsule a few metres below the surface of San Francisco Bay for an hour, and two California agencies flagged a lack of required permits, which brought it to a halt.

Designs divide between capsules sealed at one atmosphere, as at Natick, and pods equalised to the surrounding pressure, and yet every facility placed so far shares one condition. All of them sit between 9 and 36 m, inside a seasonally mixed surface layer. This is not the stable, near-freezing water below 100 m that deep seawater cooling relies on. Going deeper buys a colder and steadier heat sink while raising structural and installation demands. That trade runs head-on into the detection argument further down.

Between What's Deployed and What Frontier Scale Needs Natick Ph. 2 (2018–20) 0.24MW Startup pods (unverified) ~1MW Shanghai Phase 1 (live) 2.3MW Shanghai design target 24MW Frontier training need 150 150–200MW 1MW 10MW 100MW Reconstructed from arXiv:2609.18824 §2–3 and public announcements (log-scale x-axis) | Pebblous original diagram
▲ Deployments today sit in single megawatts; a 100,000-H100 run needs 150–200 MW — the gap only shows up on a log scale | Pebblous original diagram

Underwater data centers are not a thought experiment. The scale in the water today is measured in single megawatts, close to two orders of magnitude short of the 150 to 200 MW a 100,000-H100 training run asks for. The compute gap is wider still. Natick Phase 2 carried 864 servers, and it carried Xeon E5 processors with Arria 10 FPGAs and no GPUs at all, with compute the paper's table estimates in the hundreds of TFLOPS. Accelerator configurations at Hainan and Shanghai are undisclosed. And since a good part of the published specification comes from vendor disclosure, an article about verification that repeated those figures without verifying them would be arguing against itself.

3

The Power Gets There, the Hands Do Not

Start with electricity. A fleet of 100,000 H100s pulls about 70 MW at the GPUs alone. Add the server-side overhead of CPUs, network cards and power supplies, add the switch fabric, and the total climbs toward 150 MW. In the relevant three-to-five-year window a frontier cluster would run denser hardware such as H200s or B200s, and 200 MW becomes a plausible high end. Those are large numbers, and sending electricity out to sea is not a new trick. Submarine high-voltage direct current cables routinely carry gigawatt-scale loads, so delivering 150 to 200 MW over a dedicated cable sits well inside proven engineering, the paper judges.

Cooling runs in the favourable direction. Air conditioning has historically taken 25 to 40 percent of the electricity at a land facility. Natick, at 11 m, brought the cooling share down to 3 percent of total facility power. Seawater acts as an effectively unlimited heat sink, so the odds of this being the wall that stops underwater facilities are low. That 3 percent did not come out of deep cold water. It came from a shallow, seasonally mixed layer, and from deleting chillers, cooling towers and HVAC units outright.

3.1Cabling Runs Out at 3 m and 50 m

The wall stands somewhere else. A large training cluster only holds together if the GPUs are wired densely and precisely. In the reference 8,192-GPU design the authors cite, 256 leaf switches feed into 36 spine switches housed in dedicated spine racks. Every switch consumes power, which adds to the delivery burden. The engineering cost of the cabling itself weighs more. Direct-attach copper works up to about 3 m, and active optical cables or multimode fibre extend the reach to roughly 50 m at the leaf layer. The physical layout therefore has to be extremely dense and precisely arranged, and design effort and the risk of malfunction rise together with it.

Where the Cabling Runs Out: 3 m and 50 m Spine switches 36 · dedicated racks ≤50 m Optical cable / multimode fiber Leaf switches 256 ≤3 m Copper direct-attach (DAC) GPU racks Extremely dense, precise layout Reconstructed from the 8,192-GPU reference design in arXiv:2609.18824 §3.1 (256 leaf → 36 spine) | Pebblous original diagram
▲ Copper tops out near 3 m and optical near 50 m — the reference 8,192-GPU design has to fit inside those limits | Pebblous original diagram

3.2A Pair of Hands Every Three Hours

Maintenance is what decides the case. The most detailed public data point the paper brings in is Meta's 405B training run for Llama 3. Over 54 days on 16,384 H100 GPUs, the cluster experienced 419 unexpected interruptions, approximately one every three hours. The trouble sits in the shape of the remedy. Common tasks such as unplugging and reseating an InfiniBand transceiver are fundamentally hands-on operations.

In this generation of underwater facilities, a dead GPU or a failed network switch cannot be repaired until the entire pod is retrieved. Workloads are redistributed across the remaining healthy nodes, and failed hardware stays offline until recovery. Sending divers down runs into depth, safety and cost. Remotely operated vehicles are poor at precise connector work in confined spaces. The problem named as the reason for closing Natick comes back with the scale multiplied.

The advantage of the seal, the paper notes, stops short of reaching this far. Dry nitrogen does cut chip failures, and optical failures, arguably the most severe reliability problem, do not fall with a less corrosive atmosphere. Two paths remain. Perform very difficult maintenance underwater, or lay down enough redundant links and spare capacity to route around every point of failure. The second path substitutes capital for access and pays a severe penalty in schedule. One more clock runs against both. GPU generations turn over every 12 to 18 months while sealed pods are designed around three-to-five-year deployment cycles, so a mid-cycle upgrade has nowhere to go.

The paper's concluding sentence does not deny that the thing is possible. A state with resources to spare could absorb significant cost and timeline premiums and clear these obstacles. The facility that results is strategically uneconomic. It adds up only when concealment, rather than cost or performance, is the first objective.

4

Watch the Shipyards and the Ships, Not the Heat or the Sound

Detection comes next. The paper measures four modalities in turn, thermal, acoustic, optical and synthetic aperture radar, and the results come out uneven. Channels aimed at a facility while it operates land weakly. Channels aimed at the months of construction and servicing land hard.

Channel Window it aims at The paper's verdict Where it snags
Thermal Operating Mostly out of reach in open coastal water Above 0.17 m/s of current, the surface temperature anomaly drops under natural variability of ±0.3 to 0.5 °C
Acoustic Operating Better than thermal, blocked on attribution A sensor has to sit within 5 to 20 km, and ships, wind farms and pumping stations fill the 100 and 120 Hz band too
Optical and SAR Construction and repair The strongest of the four channels Pressure-vessel yards and power-cable ships are a narrow bottleneck, and those ships transmit their own position
Active sonar Operating Serves for confirmation, at a price Calling a contact a data center needs it in the end, and whoever pings gets exposed

Each row follows the body of the paper and the order-of-magnitude calculations in its appendix. The authors state that those appendix estimates are intended to bound the quantity in question rather than to model it precisely.

4.1Heat Buries Itself as Fast as the Water Moves

A 150 to 200 MW facility rejects waste heat into the water continuously. At frontier scale the pods spread across something on the order of 1.7 to 9 hectares, and heat leaving at the 35 m depth of current commercial deployments dilutes as it rises through the coastal water column. Current velocity in open coastal water usually sits well above 0.17 m/s, which puts the change in sea-surface temperature below the standard deviation of natural variability, ±0.3 to 0.5 °C. The signal disappears into the ocean's ordinary mood.

When the conditions change, the heat does show. The most conservative case the paper runs applies the heat capacity of fresh water to a body circulating at 0.005 m/s under wind alone. Rejecting 150 MW there lifts the surface by about 0.68 °C, and under summer stratification, with the mixing depth held to 10 m, it reaches roughly 2.4 °C. Both figures exceed natural variability, so calm shallow water hands the heat back as a signal. Three variables decide detectability, the paper concludes: depth, dispersion and location.

Quite apart from the weakness of the signal, the instruments carry limits of their own. Landsat-8 images thermal infrared at 100 m resolution, coarse against the signature a seabed facility would leave, and cloud cover opens persistent gaps in the record. Satellite thermal infrared has followed warm-water discharge before now. A 2006 study tracked the plume from Korea's roughly 5,900 MW Younggwang nuclear plant up to 100 km from the outfall using NOAA AVHRR and Landsat imagery. That water enters the sea from a concentrated point at the surface, while the waste heat of an underwater facility is smaller in volume, released at depth, and spread wide on its way up. A sharper commercial thermal satellite does not close the gap either. SatVu's HotSat-2 images day and night at 3.5 m resolution, and its imager operates in the mid-wave infrared, approximately 3.7 to 5 μm. Absolute sea-surface-temperature retrieval needs the paired thermal-infrared channels near 11 and 12 μm. The brightness-temperature difference between the two corrects for the absorption by atmospheric water vapour. The sensors that carry those channels, VIIRS, MODIS and Sentinel-3 SLSTR, have much coarser resolution. Finer resolution counts for nothing in the wrong band.

Turn depth, dispersion and location around and they read as a design brief for the side doing the hiding. Go as deep as structure and economics allow, spread as wide as the interconnect permits, and pick water as turbulent as a hull can withstand. Sites that look easy to hide in get ruled out by exactly that. A quiet cove, a narrow sheltered inlet, a lake: covert construction and operation look simpler in such places, and the thermal signal comes straight to the surface. The instruction to spread wide collides immediately with cabling that ends at 3 and 50 m. The note attached to the footprint estimate points the same way. The range of 1.7 to 9 hectares assumes 2 MW per pod, and no independently verified deployment reaches that figure. At 1 MW per pod the cluster becomes 150 to 200 pods and the footprint grows to 3.4 to 18 hectares.

4.2You Can Hear It Without Knowing Whose It Is

Acoustics fare somewhat better. A cluster fed by an alternating-current submarine link steps the voltage down locally, and the transformers radiate a stable tone at twice the supply frequency, 100 or 120 Hz, with harmonics on top. An order-of-magnitude estimate places the total source level at roughly 127 to 147 dB re 1 μPa at 1 m. That number sums 75 to 100 pods added incoherently, not a single pod, and carries a ±15 dB band. One comparison sets the scale. An offshore wind turbine can be approximated at 156 dB re 1 μPa at 1 m. A frontier-scale cluster is quieter than a single turbine. Unlike a submarine, which moves and engineers its noise downward, an underwater facility is a stationary industrial plant running continuously, which the authors suggest may make it an easier target for traditional acoustic surveillance.

The question is where you listen from. SOSUS, the US Navy's primary detection mechanism for submarines, is a set of hydrophone arrays positioned to exploit the SOFAR channel, whose axis at mid-latitudes lies at roughly 600 to 1,200 m. It can passively detect acoustic power of less than one watt at ranges of several hundred kilometres, and that capability depends on the sound coupling into the deep waveguide. The 30 to 35 m where underwater data centers currently sit is shallow coastal water, where propagation losses are substantially higher and bottom reverberation masks nearby targets. An AN/SSQ-53 DIFAR sonobuoy runs for up to 8 hours while transmitting data back by radio, covers the transformer frequency range and its harmonics, and provides directional bearings, so two of them can triangulate a contact. Detection requires positioning one within roughly 5 to 20 km of the cluster. Even that range was narrowed rather than read off a chart. A shallow-water spreading model gives 3 to 60 km on its own terms, and because mode stripping and bottom interaction push transmission loss above what the model predicts, the authors wrote down 5 to 20 km as the more defensible figure. In practice it means pushing sensors inside the 12 nautical mile (22 km) territorial sea of the state being monitored.

Sensor placement of that kind carries risk. A state concealing a facility would plausibly watch the surrounding water and the likely approach routes for intruding submarines and suspicious foreign objects, and would track anomalous surface-vessel activity using satellite AIS and coastal radar. The instruments of detection serve the other side just as well.

Even with the distance solved, attribution is still standing. Every shore-connected alternating-current installation along a coast radiates at 100 and 120 Hz. Ships' generators, offshore platforms, wind farms and pumping stations all pour energy into the same narrow band. Sound at those frequencies identifies very little by itself. Discrimination rests on the harmonic structure of the source, on whether the signal stays put in one place, and on the absence of any declared installation at that position. Confirming that a contact is a data center rather than ordinary marine infrastructure would in practice require active sonar, the paper writes. A small autonomous underwater vehicle such as the REMUS 600, used for seabed survey work, images a strip of seabed with side-scan sonar in a single pass, so a modest number of transects covers a cluster, and what comes back is a picture instead of an inferred contact. The cost is exposure. Active sonar pings the seabed, the vehicle's own noise is highly detectable by purpose-built intruder sonar, and launch and recovery put the deployer at the same risk as any other vessel conducting a physical inspection. Sonobuoys and autonomous vehicles alike are intrusive enough in another state's waters to need express provision in the agreement itself. Countermeasures can turn into signals as well. Restricting fishing vessels, imposing exclusion zones, deploying acoustic decoys, narrowing the monitoring a treaty may permit: the more aggressively a state does any of that, the more suspicion the measures themselves attract.

One assumption inside the paper fails to line up with another. The section on power builds on submarine high-voltage direct current cable, while the section on acoustics assumes a facility taking alternating current and stepping it down locally with transformers. A mains-frequency transformer tone is a product of alternating current. How much of that signature survives a direct-current feed with a differently arranged conversion stage is not something the paper works out anywhere. That gap is why the effectiveness of acoustic detection is hard to settle on this estimate alone.

4.3The Ships Announce Their Own Position

The most usable window is above the water. A submerged pod barely registers on optical sensors or radar, since optical sensing needs reflected sunlight, which attenuates rapidly from 30 to 35 m, and SAR produces near-zero return from submerged objects. Building one and putting it in place is another matter, and that process leaves distinctive traces. Approximately 14 to 17 countries currently have the capability to design and build full-sized submarines. Pressure-vessel fabrication concentrates inside that narrow base, in a small number of known, large shipyards, and the activity is inherently visible to satellite observation. The cable side is narrower again. Around 60 ships worldwide can lay submarine cable, and only 20 to 30 of them can install the higher-capacity power cable a seabed cluster requires. The operators are a known and small set as well: Prysmian, SubCom, Nexans, NEC, Global Marine, Jan De Nul and SBSS.

Where Two Narrow Bottlenecks Meet Submarine-capable countries 14–17 Pressure-vessel yards a few large yards Cable-laying ships worldwide ~60 total Power-cable ships 20–30 SAR vessel ID × satellite AIS Deployment-phase surveillance Reconstructed from the shipyard and cable-ship estimates in arXiv:2609.18824 §4.3 | Pebblous original diagram
▲ An operating pod is hard to catch, but the two narrow bottlenecks that build and carry it show up from orbit | Pebblous original diagram

The section on detection assumes the pool of shipyards able to manufacture these pressure vessels is 20 to 30 globally. The yards the paper names include CSSC and CSIC in China, Naval Group in France, Mitsubishi and Kawasaki in Japan, ThyssenKrupp Marine Systems in Germany, Saab Kockums in Sweden, and Hanwha Ocean and HD Hyundai in South Korea. The 20 to 30 shipyards and the 20 to 30 ships overlap in range while counting different objects, so reading the two together is a mistake worth avoiding. Open-source intelligence already watches shipyard activity by satellite, tracks construction progress and infers production rates from it.

These are commercial ships, and everything turns on that. SAR can identify and classify specific vessel types, and fusing that with satellite Automatic Identification System data flags the vessels that have disabled or modified their transponders, a technique already in use in sanctions enforcement and fishing regulation. Timing is the limit here. A cable installation completed before a verification regime came into force, or conducted in a manner consistent with other commercial activity, leaves no distinguishing signature. A satellite sees from the moment someone starts looking, and not one day before. Still, monitoring does not end when construction does. A facility running training year-round has to be maintained, and that generates surface activity recurring throughout its operational cycle. Construction may be long finished while the boats going out to repair keep making chances.

The recommendation follows that asymmetry exactly. The most effective pathway is surveillance at the deployment phase. It watches two things: the small pressure-vessel fabrication pool, and the AIS-tracked power-cable-laying fleet. On top of that the authors propose a clause under which parties to an agreement mutually agree to host small hydrophones and autonomous underwater vehicles in areas where such facilities might be built. The design of the proposal is the clever part. A state that rejected a clause mandating bilateral seabed hydrophone networks or regular vehicle surveys would generate significant suspicion of concealment by the refusal itself, which is how IAEA inspection protocols work. They also recommend that national intelligence agencies actively monitor developments in the area and research detection methodologies.

No single modality forecloses the pathway on its own, so the recommendation is to layer them and let one layer compensate for the weaknesses of another. The conclusion carries one further implication. Facilities built for commercial purposes and facilities built for evasion have very distinct engineering signatures. Going deep and dispersed and choosing turbulent water to suppress a thermal signal, or laying redundant links because maintenance is out of the question, are premiums that no facility chasing cost or performance has any reason to pay. The thing to look for is the shape of the design rather than the bare existence of an underwater data center.

The authors close by sizing this risk against the other evasion routes. An underground data center concealed in a mine or an excavated cavity can run off-grid power, disguise its construction as civil or mining activity, and service its hardware far more easily. Concealment inside an ordinary industrial building clears an even lower bar, since equipment arrives in ordinary shipments and personnel movements look unremarkable. These alternatives may be easier to detect once they are built than an underwater facility, and the greater difficulty of hiding underwater construction likely compensates for that. So the conclusion is that underwater facilities are a much harder path to treaty evasion than the alternatives. The residual risk is not zero, the authors add, so the detection channels discussed here are worth operationalising. They leave one more caveat of their own. The bottleneck at pressure-vessel fabrication may not be permanent. With significant investment in scaling that fabrication, the capsules could become factory-built modular units in serial production across multiple yards, which would erode both the cost premium and the monitoring advantage.

5

Why Pebblous Is Watching This Paper

From here the article leaves the paper and rereads the study through the eyes of people who work with data. The four sections above compress into one sentence. This paper weighed observability, not treaty language. How much can be counted by heat, by sound and by radar is the distance a treaty can reach. Regulation runs on measurement rather than on promises.

The shape matches a problem that data quality practice has held onto for a long time. How do you verify a declared value? What do you do with a value carrying no source, a value nobody can measure a second time, a value that keeps no record of who obtained it, when, and with which instrument? This paper takes the question people ask of a single dataset and scales it up to states and watts. Trust reaches exactly as far as counting does, on both sides of the comparison.

Three points carry over from the paper to data work. The first is the observation window. The strongest detection channel the study found was attached to construction and repair, not to the operating period. The limit on that channel points in the same direction. Work that finished before monitoring began leaves no signal behind. In data, verification is cheapest and most accurate at the moment a value is produced and transformed. Reconstructing it after everything has piled up costs ten times as much, and for some items it is not possible at all.

The second is attribution. Acoustic detection was not blocked by a weak signal. Ships radiate the same frequency, and so do wind turbines. In data quality, knowing that an anomaly exists and pinning down where it came from are problems of different difficulty. When a reading jumps and nobody can separate a sensor fault from a process change from a bug in the collection pipeline, alerts accumulate and no remedy goes out. Lineage deserves investment before signal strength does.

The third is a design in which refusing an inspection is itself information. The authors proposed mutual hydrophone hosting and regular surveys as treaty clauses, and they grounded the proposal on the point that rejecting such a clause becomes evidence for suspicion. Data contracts can carry the same device. A contract that sets audit-log access and sample re-measurement as conditions up front lets suppliers who cannot meet them filter themselves out. That approach puts verifiability in writing first instead of scoring quality after the fact.

The questions left open are worth writing down too. The calculations in this paper bound orders of magnitude, and the authors say as much. The pressure-vessel bottleneck may weaken once serial production arrives. The acoustic estimate is calculated for an alternating-current feed, so a change in how power is delivered calls for a fresh calculation. A paper on verification technology that attaches caveats like these to its own estimates is, in the end, the most instructive thing in it.

A team that takes in declared data might check the following four.

  • What share of the values we receive can be measured again? A value nobody can re-measure is a declaration, and a declaration is not data.
  • At which point is verification applied? After the load completes, or at the place where the value is produced?
  • Does it stop at noticing the anomaly, or can the source be pinned down? Without lineage there is no attribution.
  • Do the supply contracts state audit access and re-measurement conditions? If none of it is written down, there are no grounds to demand it later.

Thank you for reading this far. Every calculation and figure quoted here can be checked by anyone against the original at arXiv:2609.18824. We would be glad to hear what your team uses to trace a declared value back to its origin.

R

References

  • 1.Teague, J., Rajmohan, A., & Muehlhaeuser, Y. (2026-09-16). Could Underwater Data Centers Pose a Risk to AI Treaty Verification? arXiv preprint. arXiv:2609.18824