This could be appropriately dealt with through compute governance to make sure that there aren’t relevant amounts of AI chips in potential blacksites.
Or, if what you’re saying is that countries will just refuse access to inspectors at the sites that are visible, then you can start reaching into the coercive toolbox to punish that behavior and slow down the classified projects regardless.

Compute governance is only necessary to the extent that you can confidently know where large amounts of compute are, which I would describe as a relatively easy problem given how hard it is to hide fabs and how simple choking off production could be. In order to sabotage their operations, you don’t need to actually know what they’re using them for: the very fact that they’re not revealing it is a justification for sabotage.
This same basic setup is already how nuclear enrichment sites are handled. Nuclear enrichment facilities are very hard to hide outright, so states can be very confident about whether a rival is able to pursue a nuclear weapons program. If enrichment sites are observed, and if IAEA inspectors are refused access, then states start applying coercive leverage up to and including outright destroying the facilities.