{"name":"AI Verification Tech Map","schema_version":"1.2.0","rubric_version":"1.1","generated":"2026-09-29T17:15:50.292Z","includes_drafts":true,"license":"CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/)","notes":"url is the record's page on this site; a source record gives the original work's link in source_url. Fields marked assessment:true are editorial judgments under the published rubric, not statements of fact. flags_all includes computed flags (review-overdue, critical-flaw-open). provenance.reviewed_by and readiness.assessed_by list reviewers by handle, including AI agents such as codex-review; an agent review is not independent expert review.","nodeTypes":[{"k":"C","type":"claim","label":"Claim","plural":"Claims","shape":"square","r":11,"desc":"Something one party wants to check about another party’s AI hardware or software."},{"k":"M","type":"mechanism","label":"Mechanism","plural":"Mechanisms","shape":"circle","r":7.5,"desc":"A technical means of checking a claim. Shaded by readiness."},{"k":"I","type":"implementation","label":"Implementation","plural":"Implementations","shape":"diamond","r":6.5,"desc":"A prototype, product or proposed architecture that realises a mechanism. Shaded by readiness."},{"k":"O","type":"organization","label":"Organization","plural":"Organizations","shape":"hexagon","r":6.5,"desc":"Who builds, studies or publishes the work."}],"edgeTypes":{"verifies":{"fwd":"Helps verify","rev":"Checked by","family":"verify","desc":"Aimed at the claim (primary) or contributes to it (supporting)."},"realises":{"fwd":"Implements","rev":"Implemented by","family":"build","desc":"An implementation realises a mechanism."},"develops":{"fwd":"Develops","rev":"Developed by","family":"org","desc":"An organization develops an implementation."},"works_on":{"fwd":"Works on","rev":"Worked on by","family":"org","desc":"The record cites or describes the organization's work on it, without naming it a developer."},"depends_on":{"fwd":"Depends on","rev":"Needed by","family":"depend","desc":"One mechanism or implementation needs another to work."}},"edgeStyle":{"verifies":{"c":"verify","w":1.5,"arrow":true},"realises":{"c":"edge","w":1.2,"arrow":true},"develops":{"c":"org","w":1.2,"arrow":true},"works_on":{"c":"org","w":1,"dash":[5,3],"arrow":true},"depends_on":{"c":"ink","w":1.2,"arrow":true}},"supportingStyle":{"w":1,"dash":[4,3]},"presets":[{"key":"overview","label":"Overview","desc":"Claims and the mechanisms primarily aimed at them.","types":"CM","rels":["verifies","realises"],"supporting":false}],"levels":[{"k":"R0","label":"Idea"},{"k":"R1","label":"Proposed"},{"k":"R2","label":"Demonstrated"},{"k":"R3","label":"In production"},{"k":"R4","label":"Deployment-ready"}],"categories":[{"k":"on-chip","label":"On-chip & hardware-enabled","short":"On-chip"},{"k":"off-chip-devices","label":"Off-chip devices & sensors","short":"Off-chip devices"},{"k":"cryptographic-computational","label":"Cryptographic & computational","short":"Crypto / compute"},{"k":"isolation-architecture","label":"Isolation & system architectures","short":"Isolation & architecture"},{"k":"accounting-provenance","label":"Compute accounting & provenance","short":"Accounting"},{"k":"remote-sensing","label":"Remote & side-channel sensing","short":"Sensing"}],"counts":{"C":10,"M":25,"I":17,"O":27},"rings":{"claims":250,"concepts":350,"mechanisms":480,"implementations":660,"categories":760,"organizations":860,"sources":1080,"sectors":[{"cat":"on-chip","a0":-2.0147,"a1":-1.1268},{"cat":"off-chip-devices","a0":-1.0568,"a1":-0.3986},{"cat":"remote-sensing","a0":-0.3286,"a1":0.1001},{"cat":"accounting-provenance","a0":0.1701,"a1":0.6752},{"cat":"isolation-architecture","a0":0.7452,"a1":1.7097},{"cat":"cryptographic-computational","a0":1.7797,"a1":4.1984}]},"nodes":[{"id":"C-0001","k":"C","l":"Compute stock is at most a declared amount","d":"A party holds no more AI-relevant compute, counted in chips or equivalent capacity, than the total it has declared.","h":"/claims/compute-stock-is-bounded/","cls":"Negative","w":7,"x":200.9,"y":148.8},{"id":"C-0002","k":"C","l":"Chips are where they are declared to be","d":"Specific AI chips are physically located at the sites a party has declared, throughout the declared period.","h":"/claims/chips-are-where-declared/","cls":"Positive","w":9,"x":250,"y":2.3},{"id":"C-0003","k":"C","l":"Declared hardware is idle or shut down","d":"Specified AI chips or facilities are not performing computation, or are powered off, throughout a declared period.","h":"/claims/declared-hardware-is-idle/","cls":"Negative","w":9,"x":-75,"y":-238.5},{"id":"C-0004","k":"C","l":"This compute runs inference, not training","d":"A declared cluster is used only to run existing models to produce outputs, and not to train new or more capable models.","h":"/claims/inference-not-training/","cls":"Mixed","w":29,"x":79.5,"y":-237},{"id":"C-0005","k":"C","l":"The declared model is the one being served","d":"Outputs delivered to users or auditors come from the specific model, weights and configuration the provider declared, not from a substitute.","h":"/claims/declared-model-is-served/","cls":"Positive","w":31,"x":-203.6,"y":145},{"id":"C-0006","k":"C","l":"Declared safeguards were applied during inference","d":"Specified safety measures, such as input filters, output checks or monitoring, actually ran on the requests a deployed model served.","h":"/claims/safeguards-were-applied/","cls":"Positive","w":13,"x":-250,"y":-2.3},{"id":"C-0007","k":"C","l":"A training run stayed within declared limits","d":"A declared training run used no more compute than permitted and had its declared properties, such as data, hyperparameters and resulting weights.","h":"/claims/training-within-declared-limits/","cls":"Mixed","w":17,"x":-200.9,"y":-148.8},{"id":"C-0008","k":"C","l":"Communication between compute groups is bounded","d":"Data flowing between specified groups of chips, or out of a facility, stays below a declared rate, so the groups cannot jointly run large workloads.","h":"/claims/bandwidth-is-bounded/","cls":"Negative","w":10,"x":75,"y":238.5},{"id":"C-0009","k":"C","l":"Model weights have not left the facility","d":"No copy of specified model weights has left a designated facility through networks, physical media or other channels.","h":"/claims/weights-have-not-left/","cls":"Negative","w":14,"x":-79.5,"y":237},{"id":"C-0010","k":"C","l":"There is no undeclared relevant compute","d":"A party controls no AI-relevant computing hardware or facilities, above an agreed threshold, beyond those it has declared.","h":"/claims/no-undeclared-compute/","cls":"Negative","w":12,"x":203.6,"y":-145},{"id":"M-0014","k":"M","l":"Bandwidth limits and compartmentalization","d":"Capping or removing network links between groups of accelerators, so that serving within each group still works but large training across groups becomes far slower.","h":"/mechanisms/bandwidth-limits-and-compartmentalization/","lv":"R2","sc":"detecting traffic above a limit between accelerator groups, not enforcing a cap","cat":"isolation-architecture","cats":["off-chip-devices"],"aka":["Traffic shaping","Isolated inference units","Interconnect limits"],"w":45,"x":101.2,"y":446.7},{"id":"M-0024","k":"M","l":"Bounding unexplained information in outputs","d":"Limits the hidden information a facility's outputs can carry by measuring how much of those outputs the declared computation fails to predict.","h":"/mechanisms/bounding-unexplained-information/","lv":"R2","sc":"bounding how much hidden information can leave in checked inference outputs","cat":"isolation-architecture","cats":["cryptographic-computational"],"aka":["Unexplained-information bound","Output compressibility bounds","Egress limiting by compression"],"w":33,"x":-9.6,"y":521.9},{"id":"M-0018","k":"M","l":"Chip location verification","d":"Timing a chip's signed replies to trusted servers at known places, so that the speed of light bounds how far away the chip can be.","h":"/mechanisms/chip-location-verification/","lv":"R1","sc":"bounding how far a chip is from trusted landmark servers when checked","cat":"accounting-provenance","cats":["on-chip"],"aka":["Delay-based location verification","Ping-based location attestation","Latency-based geolocation of chips"],"w":31,"x":438,"y":133.8},{"id":"M-0019","k":"M","l":"Chip registries and manufacturing records","d":"Recording each AI chip's identity and owner from the fab onwards, and cryptographically fixing manufacturing records, so that chips can be accounted for later.","h":"/mechanisms/chip-registries-and-manufacturing-records/","lv":"R1","sc":"a checkable record of which chips were made and who declared owning them","cat":"accounting-provenance","cats":["cryptographic-computational"],"aka":["AI chip registry","Chain-of-custody tracking for AI chips","Commitments to manufacturing records"],"w":26,"x":445.3,"y":272.4},{"id":"M-0025","k":"M","l":"Confidential multi-party verification","d":"Lets mutually distrusting parties run an agreed check over private models or records inside attested enclaves or zero-knowledge proofs, revealing only the result.","h":"/mechanisms/confidential-multi-party-verification/","lv":"R2","sc":"audits or evaluations of a private model that reveal neither party's inputs","cat":"cryptographic-computational","cats":["on-chip"],"aka":["Confidential audits","Attested confidential workflows","Trustless audits"],"w":36,"x":-441,"y":123.7},{"id":"M-0002","k":"M","l":"Deterministic and bit-exact inference","d":"Making model inference reproducible bit for bit, so that a verifier's re-run must match the provider's output exactly rather than approximately.","h":"/mechanisms/deterministic-inference/","lv":"R3","sc":"exact-replay checks that the declared model and setup produced the outputs","cat":"cryptographic-computational","aka":["Bit-exact inference","Batch-invariant inference","Reproducible inference"],"w":38,"x":-282.4,"y":439},{"id":"M-0011","k":"M","l":"Hardware performance throttling and licensing","d":"On-chip mechanisms that cut an AI accelerator's performance when a license expires or a trusted trigger fires, bounding what the hardware can do.","h":"/mechanisms/hardware-performance-throttling/","lv":"R1","sc":"performance limits a verifier can rely on, against an operator trying to bypass them","cat":"on-chip","cats":["accounting-provenance"],"aka":["Offline licensing","Performance limits","Microarchitectural throttling","Compute licensing","Usage limits"],"w":25,"x":50.7,"y":-455.2},{"id":"M-0009","k":"M","l":"Hardware-enabled guarantees (flexHEG) and guarantee processors","d":"Proposed chip add-ons, a guarantee processor inside a tamper-protected enclosure, that would check and enforce agreed rules on how AI accelerators are used.","h":"/mechanisms/flexheg-guarantee-processors/","lv":"R1","sc":"checking and enforcing training-compute limits on chips, against adversaries up to states","cat":"on-chip","cats":["isolation-architecture"],"aka":["flexHEG","Flexible hardware-enabled guarantees","Guarantee processor","Interlock","Hardware-enabled governance mechanisms (HEMs)","On-chip governance mechanisms"],"w":44,"x":-57.8,"y":-518.8},{"id":"M-0015","k":"M","l":"Memory wiping and proofs of secure erasure","d":"Overwriting a device's memory in a way a verifier can check, so that data from earlier, undeclared work cannot persist in memory the wipe reaches.","h":"/mechanisms/memory-wiping-and-secure-erasure/","lv":"R1","sc":"showing that no data from earlier work persists in memory the wipe reaches","cat":"isolation-architecture","cats":["cryptographic-computational"],"aka":["Proofs of secure erasure (PoSE)","Periodic memory wipes","Forced memorization"],"w":31,"x":233.6,"y":466.8},{"id":"M-0012","k":"M","l":"Model identity attestation","d":"Establishes that responses come from a specific, committed set of model weights, using enclave measurements or recomputation of sampled outputs.","h":"/mechanisms/model-identity-attestation/","lv":"R3","sc":"showing users that a service runs the declared model weights","cat":"cryptographic-computational","cats":["on-chip"],"crit":true,"fh":"/mechanisms/model-identity-attestation/#flaw-1","aka":["Model integrity verification","Proving which model is served","Weight commitment and attestation","Model provenance attestation"],"w":38,"x":-332.9,"y":314.6},{"id":"M-0013","k":"M","l":"Network taps and certifiers","d":"Devices on a cluster's network links that copy and hash all traffic, so a verifier can later check sampled records against declared work.","h":"/mechanisms/network-taps-and-certifiers/","lv":"R1","sc":"committing a complete record of cluster traffic, so declared inference can be checked","cat":"off-chip-devices","cats":["cryptographic-computational"],"aka":["Secure network taps","Cluster I/O fingerprinting","Secure Gateway Device"],"w":66,"x":267.5,"y":-371.8},{"id":"M-0010","k":"M","l":"On-chip telemetry from timing, memory and performance counters","d":"Uses timing, memory-residency and performance-counter signals measured on AI accelerators as evidence about which workloads they are running.","h":"/mechanisms/on-chip-telemetry/","lv":"R2","sc":"a verifier reading workload evidence from GPUs that a hostile operator controls","cat":"on-chip","cats":["remote-sensing"],"crit":true,"fh":"/mechanisms/on-chip-telemetry/#flaw-1","aka":["GPU telemetry","Performance counters","NVML telemetry","Compute metering","VRAM residency challenges"],"w":39,"x":170.6,"y":-493.3},{"id":"M-0007","k":"M","l":"Proofs of useful work for capacity accounting","d":"Cryptographic evidence that a given amount of matrix-multiplication work was completed, proposed as one input to accounting for spare capacity on declared hardware.","h":"/mechanisms/proofs-of-useful-work/","lv":"R1","sc":"bounding the spare capacity of declared hardware that could run training","cat":"cryptographic-computational","aka":["Proofs of useful work and resource exhaustion","proof of useful work","PoUW","proof-of-work accounting","resource exhaustion"],"w":27,"x":-309.6,"y":-420.3},{"id":"M-0020","k":"M","l":"Remote detection of data centres","d":"Remote detection locates large data centres and estimates their power capacity without site access, using satellite imagery, heat signatures and public records such as permits.","h":"/mechanisms/remote-detection-of-data-centres/","lv":"R1","sc":"finding undeclared data centres (capacity estimates for known sites would meet at least R2)","cat":"remote-sensing","aka":["Satellite monitoring of data centres","Remote sensing of AI compute facilities","National technical means for AI compute"],"w":20,"x":522,"y":-3.7},{"id":"M-0023","k":"M","l":"Safeguard attestation","d":"Hardware-signed evidence that an AI service ran its declared safeguards, such as a guardrail classifier or monitor, when producing a given response.","h":"/mechanisms/safeguard-attestation/","lv":"R2","sc":"attesting that a declared safeguard mediated a service's responses","cat":"cryptographic-computational","cats":["on-chip"],"aka":["Proof of guardrail","Attested safeguards","Verifiable safeguard execution"],"w":36,"x":-521.7,"y":16.5},{"id":"M-0001","k":"M","l":"Sampled inference recomputation","d":"A verifier re-runs a random sample of an AI provider's logged queries on a trusted copy of the declared model and checks the outputs match.","h":"/mechanisms/sampled-inference-recomputation/","lv":"R3","sc":"checking that recorded outputs came from the declared model and settings","cat":"cryptographic-computational","aka":["Inference recomputation","Recomputation-based inference verification","Partial recomputation"],"w":50,"x":-148.3,"y":433.3},{"id":"M-0022","k":"M","l":"Side-channel suppression for isolated facilities","d":"Shielding, filtering, jamming and inspecting an AI facility to limit hidden physical communication around monitored network links.","h":"/mechanisms/side-channel-suppression/","lv":"R1","sc":"bounding physical covert channels out of a verified enclosure","cat":"off-chip-devices","cats":["isolation-architecture"],"aka":["Covert-channel suppression","TEMPEST-style shielding for verification","Retrofitted side-channel defences"],"w":33,"x":400.1,"y":-222.9},{"id":"M-0017","k":"M","l":"Tamper evidence for verifier devices","d":"Enclosures, seals and sensors that make physical interference with verification hardware either visible or self-defeating.","h":"/mechanisms/tamper-evidence-for-verifier-devices/","lv":"R2","sc":"detecting tampering with verifier devices inside facilities the checked party controls","cat":"off-chip-devices","cats":["isolation-architecture"],"aka":["Tamper-evident enclosures","Tamper-respondent enclosures","Tamper-indicating enclosures","Anti-tamper sensing"],"w":33,"x":389.8,"y":-347.2},{"id":"M-0008","k":"M","l":"TEE remote attestation for AI workloads","d":"Trusted execution environments (TEEs) in CPUs and GPUs sign reports of loaded software, so a remote party can check which code ran an AI workload.","h":"/mechanisms/tee-remote-attestation/","lv":"R3","sc":"showing which software ran to a party that distrusts the operator holding the hardware","cat":"on-chip","cats":["cryptographic-computational"],"crit":true,"fh":"/mechanisms/tee-remote-attestation/#flaw-1","aka":["Confidential computing","GPU confidential computing","Remote attestation","Confidential VM attestation"],"w":69,"x":-149.7,"y":-432.8},{"id":"M-0016","k":"M","l":"Timed challenge-response and memory-occupation challenges","d":"A verifier sends unpredictable questions that a device can answer in time only if it holds specified data, or dedicates specified resources, locally.","h":"/mechanisms/timed-challenge-response/","lv":"R2","sc":"detecting whether a GPU is doing other work","cat":"cryptographic-computational","cats":["accounting-provenance"],"aka":["Memory challenges","Memory-occupation challenges","Software-based attestation","Proof-of-space-style challenges"],"w":34,"x":-352.1,"y":-293},{"id":"M-0006","k":"M","l":"Training-transcript verification (proof-of-learning)","d":"A trainer logs checkpoints, data order and settings, so a verifier can re-run sampled training segments and check that the claimed training happened.","h":"/mechanisms/proof-of-learning/","lv":"R2","sc":"checking from its transcript that a training run followed declared rules","cat":"cryptographic-computational","crit":true,"fh":"/mechanisms/proof-of-learning/#flaw-2","aka":["Proof-of-learning and training-transcript verification","proof-of-learning","PoL","proof of training transcript","PoTT","proof-of-training-data","PoTD","optimistic verifiable training"],"w":25,"x":-469.5,"y":-228.1},{"id":"M-0003","k":"M","l":"Whole-workload recomputation (reproducible packets)","d":"Organizing all AI workloads in a facility into discrete, reproducible units, so that a verifier can recompute a random sample and check each one.","h":"/mechanisms/reproducible-computation-packets/","lv":"R1","sc":"recomputing whole workloads to show a cluster runs only declared inference","cat":"isolation-architecture","cats":["cryptographic-computational"],"aka":["Reproducible computation packets","Packet-based verification"],"w":29,"x":296.8,"y":348.8},{"id":"M-0021","k":"M","l":"Workload classification from telemetry and side channels","d":"Telling whether chips are training, serving or doing non-AI work from GPU counters or power draw, signals that do not read weights or data.","h":"/mechanisms/workload-classification-from-telemetry/","lv":"R2","sc":"telling training from inference and other work, against an operator disguising workloads","cat":"remote-sensing","cats":["on-chip","off-chip-devices"],"aka":["Workload classification","Training detection from GPU telemetry","Power-based workload identification","Training-versus-inference classification"],"w":25,"x":446.8,"y":-100.6},{"id":"M-0004","k":"M","l":"Zero-knowledge proofs of inference","d":"A prover produces a cryptographic proof that an output came from running a committed model on a given input, without revealing the weights.","h":"/mechanisms/zk-proofs-of-inference/","lv":"R2","sc":"proving each output came from committed weights, against a prover who cheats","cat":"cryptographic-computational","aka":["ZKML inference proofs","verifiable inference with zkSNARKs"],"w":36,"x":-454.2,"y":257.3},{"id":"M-0005","k":"M","l":"Zero-knowledge proofs of training constraints","d":"Cryptographic proofs that a training run followed a committed dataset, procedure and rules, checkable without revealing the model or the data.","h":"/mechanisms/zk-proofs-of-training-constraints/","lv":"R2","sc":"proving a training run followed a committed specification and data","cat":"cryptographic-computational","aka":["zero-knowledge proofs of training","zkPoT","verifiable training"],"w":25,"x":-447.9,"y":-95.6},{"id":"I-0011","k":"I","l":"AI 2040 inference-only verification stack","d":"A proposed retrofit that isolates data-centre inference units, taps their front-end traffic and recomputes random samples to check that only declared inference runs.","h":"/implementations/ai-2040-inference-only-verification-plan/","lv":"R1","sc":"showing that retrofitted data centres run only inference","cat":"isolation-architecture","cats":["off-chip-devices","cryptographic-computational"],"kind":"Proposed architecture","aka":["AI 2040 verification plan (inference-only retrofit)","Inference-only retrofit"],"w":35,"x":234.3,"y":655.4},{"id":"I-0013","k":"I","l":"Apple Private Cloud Compute","d":"Apple's cloud AI inference service, in which user devices send requests only to servers that attest to running software published in a public transparency log.","h":"/implementations/apple-private-cloud-compute/","lv":"R3","sc":"showing users which software serves their AI requests, not which model","cat":"on-chip","cats":["cryptographic-computational"],"kind":"Product","aka":["PCC","Private Cloud Compute"],"w":15,"x":153.2,"y":-678.9},{"id":"I-0007","k":"I","l":"Attestable Audits","d":"A research prototype that runs AI safety benchmarks inside a trusted execution environment and publishes attestations binding the model, the audit and the results.","h":"/implementations/attestable-audits/","lv":"R2","sc":"showing users that the model answering them is the audited one","cat":"on-chip","cats":["cryptographic-computational"],"kind":"Research prototype","aka":["Attestable Audits prototype","Verifiable AI safety benchmarks in TEEs"],"w":20,"x":-141.8,"y":-628.2},{"id":"I-0005","k":"I","l":"Attestable zero-knowledge inference prover","d":"Attestable's zero-knowledge prover, which the company reports proves large language model outputs came from committed weights at tens of tokens per second.","h":"/implementations/attestable-zk-inference/","lv":"R1","sc":"proving an output came from committed weights","cat":"cryptographic-computational","kind":"Product","aka":["Attestable ZK prover"],"w":17,"x":-620.1,"y":173.9},{"id":"I-0016","k":"I","l":"Batch-invariant inference kernels (Thinking Machines)","d":"Open-source kernels from Thinking Machines Lab that make LLM outputs independent of batch size, adopted in vLLM and SGLang to give reproducible inference.","h":"/implementations/batch-invariant-inference-kernels/","lv":"R2","sc":"exact recomputation of served outputs by a verifier, with a cooperating provider","cat":"cryptographic-computational","kind":"Open-source project","aka":["batch_invariant_ops","VLLM_BATCH_INVARIANT","SGLang deterministic inference"],"w":11,"x":-468,"y":442.4},{"id":"I-0002","k":"I","l":"DiFR (Divergence From Reference)","d":"DiFR checks that an inference provider ran its declared model by comparing output tokens or activations with a trusted re-run using the same random seed.","h":"/implementations/difr/","lv":"R2","sc":"checking that outputs match the declared model, precision and sampling settings","cat":"cryptographic-computational","kind":"Research prototype","aka":["Token-DiFR","Activation-DiFR"],"w":18,"x":-376.6,"y":585.3},{"id":"I-0014","k":"I","l":"EZKL","d":"EZKL is a library from Zkonduit that turns neural networks into zero-knowledge circuits, so a prover can show an output came from a committed model.","h":"/implementations/ezkl/","lv":"R2","sc":"proving an output came from a committed model, against a prover who cheats","cat":"cryptographic-computational","kind":"Product","aka":["ezkl","Easy Zero-Knowledge Inference"],"w":14,"x":-695.7,"y":22},{"id":"I-0012","k":"I","l":"Low-trust AI compute verification system overview","d":"A retrofittable reference design in which network taps commit to all facility traffic, and air-gapped, independently sourced checkers later re-run randomly challenged records.","h":"/implementations/low-trust-compute-verification-system-overview/","lv":"R1","sc":"screening challenged records to show declared inference compute is not training","cat":"isolation-architecture","cats":["off-chip-devices","cryptographic-computational"],"kind":"Proposed architecture","aka":["Cankaya system overview","Near-term, low-trust AI compute verification"],"w":40,"x":14.1,"y":643.8},{"id":"I-0009","k":"I","l":"Lucid sovereignty (location) certificates","d":"A draft specification, hosted by Lucid Computing, for short-lived certificates that bound where a workload runs by timing signed exchanges with fixed anchors.","h":"/implementations/lucid-location-certificates/","lv":"R1","sc":"certifying the region where an attested workload ran at a given time","cat":"accounting-provenance","cats":["on-chip"],"kind":"Standard","aka":["Sovereignty Certificates","Ping-based location attestation","sovcert"],"w":18,"x":587.3,"y":264.2},{"id":"I-0004","k":"I","l":"Pearl proof-of-useful-work blockchain","d":"A blockchain whose mining is designed to be a by-product of GPU matrix multiplications in AI workloads, with public node and miner code.","h":"/implementations/pearl-proof-of-useful-work/","lv":"R3","sc":"proving GPUs did matrix-multiplication work in blockchain mining, not bounding spare capacity","cat":"cryptographic-computational","kind":"Open-source project","aka":["Pearl","Pearl protocol","PRL"],"w":19,"x":-412.8,"y":-560.4},{"id":"I-0017","k":"I","l":"PySyft double-blind evaluations","d":"PySyft coordinates an attested enclave where a model owner and evaluator run tests without sharing weights or private prompts.","h":"/implementations/pysyft-double-blind-evaluations/","lv":"R2","sc":"evaluating a private model on private prompts, neither party seeing the other's inputs","cat":"cryptographic-computational","cats":["on-chip"],"kind":"Research prototype","aka":["PySyft confidential evaluations"],"w":13,"x":-626.1,"y":-304.1},{"id":"I-0010","k":"I","l":"RAND secure inference data center (SIDC) design","d":"A RAND design for a purpose-built facility that serves already-trained AI models while protecting weights and inference data against state-level attackers.","h":"/implementations/rand-secure-inference-data-centers/","lv":"R1","sc":"the operator's own weight security, with no outside verification described","cat":"isolation-architecture","cats":["off-chip-devices"],"kind":"Proposed architecture","aka":["Secure inference data center","SIDC","Highly Secure Inference Data Centers"],"w":24,"x":397.3,"y":506.8},{"id":"I-0008","k":"I","l":"SASH confidential network logger","d":"An open-source prototype that routes a facility's inference traffic through a logger and re-runs requests on a separate cluster to check it serves inference.","h":"/implementations/sash-confidential-network-logger/","lv":"R1","sc":"telling inference from training on a mutually inspected cluster","cat":"off-chip-devices","cats":["cryptographic-computational"],"kind":"Research prototype","aka":["Confidential Network Logger (CNL)","SASH inference verification prototype"],"w":23,"x":480.9,"y":-428.4},{"id":"I-0006","k":"I","l":"Tinfoil model identity (Modelwrap)","d":"Tinfoil's method for proving which model weights its enclave-hosted inference service runs, by binding a dm-verity hash of the weights into remote attestation.","h":"/implementations/tinfoil-model-identity/","lv":"R3","sc":"showing clients that the served weights match a committed hash","cat":"cryptographic-computational","cats":["on-chip"],"crit":true,"fh":"/implementations/tinfoil-model-identity/#flaw-1","kind":"Product","aka":["Modelwrap","Tinfoil model integrity"],"w":19,"x":-495,"y":-411.9},{"id":"I-0001","k":"I","l":"TOPLOC","d":"TOPLOC is a hashing scheme from Prime Intellect that lets a verifier check whether an inference provider ran the model, prompt and precision it claims.","h":"/implementations/toploc/","lv":"R3","sc":"checking that untrusted providers used the claimed model, prompt and precision","cat":"cryptographic-computational","kind":"Open-source project","aka":["TOPLOC v2"],"w":16,"x":-208.6,"y":609.3},{"id":"I-0015","k":"I","l":"Verde and RepOps (Gensyn)","d":"Gensyn's system for checking delegated machine-learning jobs, which settles disagreements between providers by re-running a single operation with bitwise-reproducible operators.","h":"/implementations/gensyn-verde-repops/","lv":"R3","sc":"showing a delegated output came from the declared model, if one provider is honest","cat":"cryptographic-computational","kind":"Product","aka":["Verde","RepOps","Reproducible Operators","Gensyn Reproducible Execution Environment (REE)"],"w":14,"x":-629.8,"y":-134.4},{"id":"I-0003","k":"I","l":"zkLLM","d":"zkLLM is a GPU-accelerated zero-knowledge proof system that proves a large language model's output came from committed weights without revealing those weights.","h":"/implementations/zkllm/","lv":"R2","sc":"proving an output came from committed weights, against a prover who cheats","cat":"cryptographic-computational","kind":"Research prototype","aka":["zkLLM-CCS2024"],"w":16,"x":-605.6,"y":343},{"id":"O-0201","k":"O","l":"AI Futures Project","d":"A small research group forecasting the future of AI; publisher of the AI 2040 scenario, including an inference-only verification plan.","h":"/organizations/ai-futures-project/","kind":"Research organization","w":12,"x":552.5,"y":659},{"id":"O-0101","k":"O","l":"Amodo Design","d":"A hardware engineering company that builds and publishes prototypes for verifying AI agreements, including inference recomputation, network taps and memory wiping.","h":"/organizations/amodo-design/","kind":"Company","w":25,"x":338.4,"y":790.6},{"id":"O-0120","k":"O","l":"Attestable","d":"A company developing zero-knowledge proofs for AI systems; it reports a prover for large language model inference and proposes proof-based compute accounting.","h":"/organizations/attestable/","kind":"Company","w":7,"x":-858,"y":59.3},{"id":"O-0207","k":"O","l":"Center for a New American Security","d":"A nonprofit national-security policy organization; publisher of a report proposing on-chip mechanisms, including location verification, for governing AI chips.","h":"/organizations/center-for-a-new-american-security/","kind":"Research organization","aka":["CNAS"],"w":6,"x":422.5,"y":-749.1},{"id":"O-0211","k":"O","l":"Centre for the Governance of AI","d":"An AI governance think tank whose research includes compute governance.","h":"/organizations/centre-for-the-governance-of-ai/","kind":"Research organization","aka":["GovAI"],"w":3,"x":851.9,"y":-117.8},{"id":"O-0208","k":"O","l":"Epoch AI","d":"A research institute studying the trajectory of AI; it runs the Frontier Data Centers Hub, which estimates AI data-centre capacity from satellite imagery and permits.","h":"/organizations/epoch-ai/","kind":"Research organization","aka":["Epoch"],"w":4,"x":856.8,"y":73.8},{"id":"O-0206","k":"O","l":"Future of Life Institute","d":"A nonprofit working on extreme risks from transformative technology; it built secure-hardware proofs of concept for AI governance and partners on a network-logger prototype.","h":"/organizations/future-of-life-institute/","kind":"Nonprofit","aka":["FLI"],"w":5,"x":217,"y":-832.2},{"id":"O-0212","k":"O","l":"Gensyn","d":"A company building AI systems that forecast events; developer of the Verde verification protocol and the REE runtime for reproducible model inference.","h":"/organizations/gensyn/","kind":"Company","w":8,"x":-843.3,"y":-168.5},{"id":"O-0209","k":"O","l":"Hardware AI Governance Lab","d":"A University of Oxford lab, hosted by the Oxford Martin AI Governance Initiative, that studies how computer hardware can support AI governance and international coordination.","h":"/organizations/oxford-hardware-ai-governance-lab/","kind":"Academic","aka":["HAIGL","Oxford Hardware AI Governance Lab"],"w":4,"x":502.2,"y":-698.1},{"id":"O-0204","k":"O","l":"Institute for AI Policy and Strategy","d":"A nonpartisan think tank on AI policy; its work on AI chips includes a design and prototype for delay-based location verification.","h":"/organizations/institute-for-ai-policy-and-strategy/","kind":"Research organization","aka":["IAPS"],"w":7,"x":784.3,"y":352.8},{"id":"O-0210","k":"O","l":"Intelligence Security Laboratories","d":"A nonprofit lab that researches and builds high-security AI systems, including secure data centres.","h":"/organizations/intelligence-security-laboratories/","kind":"Research organization","aka":["ISL"],"w":3,"x":825,"y":-242.8},{"id":"O-0180","k":"O","l":"Lucid Computing","d":"A company offering attested, confidential-computing AI clusters; it hosts the Sovereignty Certificates location specification and runs a verification research programme.","h":"/organizations/lucid-computing/","kind":"Company","w":10,"x":691.4,"y":511.4},{"id":"O-0202","k":"O","l":"Machine Intelligence Research Institute","d":"A nonprofit focused on preventing human extinction from artificial superintelligence; its Technical Governance Team publishes designs and analyses for verifying AI agreements.","h":"/organizations/machine-intelligence-research-institute/","kind":"Research organization","aka":["MIRI"],"w":22,"x":-808.2,"y":293.8},{"id":"O-0140","k":"O","l":"NVIDIA","d":"An accelerated-computing company whose Hopper and Blackwell data-centre GPUs offer a confidential-computing mode with hardware attestation.","h":"/organizations/nvidia/","kind":"Company","w":11,"x":616,"y":-600.1},{"id":"O-0215","k":"O","l":"OpenMined","d":"A nonprofit developing PySyft, software for joint analysis of private data, including confidential AI evaluations.","h":"/organizations/openmined/","kind":"Nonprofit","w":4,"x":-853.5,"y":-105.4},{"id":"O-0205","k":"O","l":"Oxford Martin AI Governance Initiative","d":"A research programme at the University of Oxford that studies AI governance from technical and policy angles and hosts the Hardware AI Governance Lab.","h":"/organizations/oxford-martin-ai-governance-initiative/","kind":"Academic","aka":["AIGI","Oxford Martin AIGI"],"w":6,"x":858.3,"y":-54.1},{"id":"O-0121","k":"O","l":"Pearl Research Labs","d":"A company building AI inference infrastructure and Pearl, a blockchain whose proof-of-useful-work mining is a by-product of GPU matrix multiplication.","h":"/organizations/pearl-research/","kind":"Company","w":8,"x":-510.1,"y":-692.4},{"id":"O-0102","k":"O","l":"Planet Labs","d":"A company that builds and operates Earth-imaging satellites and sells their imagery; it is one commercial source used to track AI data-centre construction.","h":"/organizations/planet-labs/","kind":"Company","aka":["Planet","Planet Labs PBC"],"w":2,"x":859.9,"y":9.9},{"id":"O-0100","k":"O","l":"Prime Intellect","d":"An AI compute, training and inference company; developer of TOPLOC, a hashing scheme for verifying LLM inference.","h":"/organizations/prime-intellect/","kind":"Company","w":9,"x":-278.5,"y":813.6},{"id":"O-0200","k":"O","l":"RAND","d":"A nonprofit, nonpartisan research organization; its reports cover verification of international AI agreements, hardware-enabled governance mechanisms and secure inference data centres.","h":"/organizations/rand/","kind":"Research organization","w":9,"x":840.8,"y":-180.8},{"id":"O-0160","k":"O","l":"Singapore AI Safety Hub (SASH)","d":"A Singapore-based AI safety research and field-building organization; with international partners, it develops a confidential network logger for inference verification.","h":"/organizations/singapore-ai-safety-hub/","kind":"Nonprofit","aka":["SASH"],"w":6,"x":569.7,"y":-644.3},{"id":"O-0214","k":"O","l":"Thinking Machines Lab","d":"An AI research and product company; developer of batch-invariant kernels that make language-model outputs independent of batch size.","h":"/organizations/thinking-machines-lab/","kind":"Company","w":4,"x":-625,"y":590.7},{"id":"O-0141","k":"O","l":"Tinfoil","d":"A company offering AI inference inside secure hardware enclaves, with remote attestation that clients can check; developer of the Modelwrap model-identity tool.","h":"/organizations/tinfoil/","kind":"Company","w":13,"x":-828.5,"y":-230.8},{"id":"O-0142","k":"O","l":"University of Cambridge","d":"A UK university; researchers in its Department of Computer Science and Technology developed Attestable Audits, AI benchmarks run and attested inside trusted execution environments.","h":"/organizations/university-of-cambridge/","kind":"Academic","w":6,"x":-791.7,"y":-335.9},{"id":"O-0122","k":"O","l":"University of Waterloo","d":"A university in Waterloo, Ontario, Canada, whose researchers developed zkLLM, a zero-knowledge proof system for large language model inference.","h":"/organizations/university-of-waterloo/","kind":"Academic","w":4,"x":-748.3,"y":423.8},{"id":"O-0203","k":"O","l":"Verifiable Compute Foundation","d":"Lucid Computing describes VCF as a nonprofit that will allocate free research access to a bare-metal AI-verification cluster.","h":"/organizations/verifiable-compute-foundation/","kind":"Nonprofit","aka":["VCF"],"w":0,"x":849,"y":137.3},{"id":"O-0213","k":"O","l":"Zkonduit","d":"The company that makes EZKL, a library for proving in zero knowledge that a neural network produced a given output.","h":"/organizations/zkonduit/","kind":"Company","w":4,"x":-860,"y":-4.7}],"edges":[{"s":"M-0014","t":"C-0008","k":"verifies","role":"p","note":"Caps or removes communication between declared groups of accelerators (Dean (2026), Computing (2026))."},{"s":"M-0014","t":"C-0004","k":"verifies","role":"s","note":"Intended to leave inference workable while making large training impractical (Dean (2026), Computing (2026))."},{"s":"M-0014","t":"C-0007","k":"verifies","role":"s","note":"Bounds the size of model that can be trained efficiently across pods (Computing (2026))."},{"s":"M-0014","t":"C-0009","k":"verifies","role":"s","note":"A cap on outgoing bandwidth bounds how much weight data can leave a facility in a given time (Rinberg et al. (2026))."},{"s":"O-0101","t":"M-0014","k":"works_on"},{"s":"O-0180","t":"M-0014","k":"works_on"},{"s":"O-0201","t":"M-0014","k":"works_on"},{"s":"O-0202","t":"M-0014","k":"works_on"},{"s":"M-0014","t":"M-0013","k":"depends_on","note":"Monitored links are needed to show that all traffic leaving a group crosses the capped boundary."},{"s":"M-0014","t":"M-0017","k":"depends_on","note":"Shaping and monitoring devices must resist tampering and bypass."},{"s":"M-0024","t":"C-0009","k":"verifies","role":"p","note":"Bounds how much weight or other undeclared information can leave in checked outputs; does not close other channels."},{"s":"M-0024","t":"C-0004","k":"verifies","role":"s","note":"In the compute-agreement framing, outputs must be predictable by policy-compliant computation, which limits what undeclared workloads can export (Petrie & Mühlhäuser (2026))."},{"s":"M-0024","t":"C-0008","k":"verifies","role":"s","note":"Bounds effective unexplained output bandwidth rather than raw link bandwidth."},{"s":"M-0024","t":"M-0001","k":"depends_on","note":"Predictions of honest outputs come from recomputing declared workloads."},{"s":"M-0024","t":"M-0014","k":"depends_on","note":"The bound is meaningful only if outputs through the interlock are the prover's only channel."},{"s":"M-0024","t":"M-0022","k":"depends_on","note":"Physical side channels bypass output checks and must be suppressed separately."},{"s":"M-0024","t":"M-0013","k":"depends_on","note":"An interlock or tap must record commitments to all traffic."},{"s":"M-0018","t":"C-0002","k":"verifies","role":"p","note":"Bounds how far a responding chip can be from trusted landmark servers at the time of the check."},{"s":"M-0018","t":"C-0010","k":"verifies","role":"s","note":"Can flag enrolled chips that stop responding or answer from outside declared regions; says nothing about chips outside the scheme."},{"s":"O-0180","t":"M-0018","k":"works_on"},{"s":"O-0204","t":"M-0018","k":"works_on"},{"s":"O-0207","t":"M-0018","k":"works_on"},{"s":"O-0140","t":"M-0018","k":"works_on"},{"s":"M-0018","t":"M-0008","k":"depends_on","note":"Binding a timed reply to one physical chip relies on a per-chip key held in secure hardware, as in remote attestation."},{"s":"M-0019","t":"C-0001","k":"verifies","role":"p","note":"Gives a baseline of which chips were made and who declared owning them."},{"s":"M-0019","t":"C-0010","k":"verifies","role":"s","note":"Supports checks that recorded chips have not been assembled into undeclared clusters."},{"s":"M-0019","t":"C-0002","k":"verifies","role":"s","note":"Records declared locations, which inspections or location checks can test."},{"s":"O-0200","t":"M-0019","k":"works_on"},{"s":"O-0201","t":"M-0019","k":"works_on"},{"s":"O-0204","t":"M-0019","k":"works_on"},{"s":"M-0025","t":"C-0005","k":"verifies","role":"p","note":"Binds audit or capability-evaluation results to the model that is served, without revealing weights (Schnabl et al. (2025), Ding et al. (2026))."},{"s":"M-0025","t":"C-0006","k":"verifies","role":"s","note":"Plan-scoped monitoring runs an agreed classifier over private usage records (Penchas et al. (2026))."},{"s":"M-0025","t":"C-0007","k":"verifies","role":"s","note":"Zero-knowledge audits can prove properties of committed training data and weights (Waiwitlikhit et al. (2024))."},{"s":"O-0142","t":"M-0025","k":"works_on"},{"s":"O-0202","t":"M-0025","k":"works_on"},{"s":"O-0141","t":"M-0025","k":"works_on"},{"s":"O-0215","t":"M-0025","k":"works_on"},{"s":"M-0025","t":"M-0008","k":"depends_on","note":"TEE-based designs rely on measured launch and remote attestation."},{"s":"M-0002","t":"C-0005","k":"verifies","role":"p","note":"Enables exact-match recomputation checks that the declared model, weights and software setup produced the outputs."},{"s":"M-0002","t":"C-0004","k":"verifies","role":"s","note":"Bit-exact recomputation of declared inference removes the tolerance an operator could hide other work in (Cankaya (2026))."},{"s":"M-0002","t":"C-0009","k":"verifies","role":"s","note":"Removes the tolerance margin that steganographic exfiltration could use (Cankaya (2026))."},{"s":"M-0002","t":"C-0010","k":"verifies","role":"s","note":"Unreported batch elements alter the numerics, so covert computation inside batches becomes detectable (Cankaya (2026))."},{"s":"M-0011","t":"C-0001","k":"verifies","role":"s","note":"A verified performance cap bounds the effective capacity of declared hardware; needs attestation that the cap is active."},{"s":"M-0011","t":"C-0007","k":"verifies","role":"s","note":"Licenses that authorize a fixed amount of work would bound compute per license period (Kulp et al. (2024), O'Gara et al. (2025))."},{"s":"M-0011","t":"C-0003","k":"verifies","role":"s","note":"Unlicensed hardware falls back to reduced capacity or shuts down (O'Gara et al. (2025))."},{"s":"O-0200","t":"M-0011","k":"works_on"},{"s":"O-0207","t":"M-0011","k":"works_on"},{"s":"M-0011","t":"M-0010","k":"depends_on","note":"Licenses denominated in work need secure meters for the licensed quantities (S-0006)."},{"s":"M-0011","t":"M-0008","k":"depends_on","note":"A verifier needs attested configuration to know a cap is in force; licensing relies on secure boot and on-chip authentication (S-0057)."},{"s":"M-0009","t":"C-0007","k":"verifies","role":"p","note":"Verifiable claims about total training compute, and enforcement of compute thresholds (Petrie et al. (2025))."},{"s":"M-0009","t":"C-0005","k":"verifies","role":"s","note":"Deployment only to approved flexHEG devices, and verification of evaluation scores (Petrie et al. (2025))."},{"s":"M-0009","t":"C-0002","k":"verifies","role":"s","note":"Automated verification of approximate chip location (Petrie et al. (2025)); see Chip location verification."},{"s":"M-0009","t":"C-0008","k":"verifies","role":"s","note":"Interlocks on NVLink or NICs, and RAND's fixed-set pods, would bound communication (Petrie & Aarne (2025), Kulp et al. (2024))."},{"s":"M-0009","t":"C-0006","k":"verifies","role":"s","note":"Could require deployment-time safeguards on approved devices (Petrie et al. (2025))."},{"s":"O-0200","t":"M-0009","k":"works_on"},{"s":"O-0207","t":"M-0009","k":"works_on"},{"s":"M-0009","t":"M-0008","k":"depends_on","note":"Builds on existing secure boot, device identity and remote attestation; flexHEG would extend confidential-computing attestation (S-0035, S-1204)."},{"s":"M-0009","t":"M-0019","k":"depends_on","note":"Governance through flexHEG assumes a registry of equipped chips; covering non-flexHEG compute is a separate problem (S-1205)."},{"s":"M-0015","t":"C-0004","k":"verifies","role":"s","note":"Periodic wipes are proposed so that only verified inference outputs persist (Dean (2026)); Amodo frames wipes as verifying completeness of declared workloads (Design (2026))."},{"s":"O-0101","t":"M-0015","k":"works_on"},{"s":"O-0201","t":"M-0015","k":"works_on"},{"s":"O-0202","t":"M-0015","k":"works_on"},{"s":"M-0015","t":"M-0016","k":"depends_on","note":"The fill is checked by timed challenges, which must exclude outside help."},{"s":"M-0015","t":"M-0013","k":"depends_on","note":"Monitored links, or physical disconnection, are needed to rule out remote storage during challenges."},{"s":"M-0012","t":"C-0005","k":"verifies","role":"p","note":"Core purpose: responses come from the declared weights."},{"s":"M-0012","t":"C-0006","k":"verifies","role":"s","note":"Links an attested evaluation to the model later served (Schnabl et al. (2025))."},{"s":"M-0012","t":"C-0009","k":"verifies","role":"s","note":"The recomputation variant limits steganographic weight exfiltration through outputs (Rinberg et al. (2025))."},{"s":"O-0141","t":"M-0012","k":"works_on"},{"s":"O-0142","t":"M-0012","k":"works_on"},{"s":"O-0202","t":"M-0012","k":"works_on"},{"s":"M-0012","t":"M-0008","k":"depends_on","note":"The enclave variant relies on TEE and GPU attestation."},{"s":"M-0012","t":"M-0001","k":"depends_on","note":"The recomputation variant is a form of sampled inference recomputation."},{"s":"M-0013","t":"C-0004","k":"verifies","role":"p","note":"Supplies the committed record of cluster I/O that recomputation checks against declared inference (Dean (2026), Cankaya et al. (2026))."},{"s":"M-0013","t":"C-0009","k":"verifies","role":"s","note":"Aims to make covert exfiltration of results through tapped links infeasible (Cankaya et al. (2026))."},{"s":"M-0013","t":"C-0005","k":"verifies","role":"s","note":"Replaying challenged records with the declared model checks which model produced outputs (Cankaya et al. (2026), Dean (2026))."},{"s":"O-0101","t":"M-0013","k":"works_on"},{"s":"O-0160","t":"M-0013","k":"works_on"},{"s":"O-0201","t":"M-0013","k":"works_on"},{"s":"O-0202","t":"M-0013","k":"works_on"},{"s":"O-0209","t":"M-0013","k":"works_on"},{"s":"M-0013","t":"M-0001","k":"depends_on","note":"Challenged records are checked by recomputing them."},{"s":"M-0013","t":"M-0002","k":"depends_on","note":"Bit-exact replay is the main proposed way to remove covert capacity in model outputs."},{"s":"M-0013","t":"M-0017","k":"depends_on","note":"Taps and gateway devices must be physically protected and the facility monitored so all traffic passes through them."},{"s":"M-0013","t":"M-0022","k":"depends_on","note":"Radio, power-line and thermal channels bypass the tapped links."},{"s":"M-0010","t":"C-0004","k":"verifies","role":"p","note":"Classifying training versus other workloads from counters (Rahman & Tajdari (2026)) or timing (Monfared et al. (2026))."},{"s":"M-0010","t":"C-0003","k":"verifies","role":"p","note":"Utilization and residency signals indicate whether declared-idle hardware is busy (Monfared et al. (2026))."},{"s":"M-0010","t":"C-0010","k":"verifies","role":"s","note":"Contention from undeclared co-running workloads shifts challenge timing (Monfared et al. (2026)); coverage of other chips needs other mechanisms."},{"s":"M-0010","t":"C-0007","k":"verifies","role":"s","note":"Counters for FLOP, memory and interconnect traffic are proposed as meters for compute accounting (Kulp et al. (2024), O'Gara et al. (2025))."},{"s":"O-0202","t":"M-0010","k":"works_on"},{"s":"M-0010","t":"M-0008","k":"depends_on","note":"A tamper-resistant read path, an authenticated channel and secure boot of the monitoring software are needed for counters to be trustworthy (S-0037)."},{"s":"M-0007","t":"C-0004","k":"verifies","role":"p","note":"Bounds the spare capacity of declared hardware that could run unauthorised training; Attestable pairs work accounting with ZK inference proofs."},{"s":"M-0007","t":"C-0003","k":"verifies","role":"s","note":"Keeping declared hardware provably busy with agreed work, as an alternative to showing it idle."},{"s":"M-0007","t":"C-0010","k":"verifies","role":"s","note":"On declared hardware only: bounds capacity left for unmonitored work; cannot find undeclared facilities."},{"s":"O-0120","t":"M-0007","k":"works_on"},{"s":"O-0121","t":"M-0007","k":"works_on"},{"s":"O-0202","t":"M-0007","k":"works_on"},{"s":"M-0020","t":"C-0010","k":"verifies","role":"p","note":"Searches for large facilities that have not been declared."},{"s":"M-0020","t":"C-0001","k":"verifies","role":"s","note":"Estimates the power capacity, and so roughly the compute, of observed facilities."},{"s":"O-0102","t":"M-0020","k":"works_on"},{"s":"O-0201","t":"M-0020","k":"works_on"},{"s":"O-0208","t":"M-0020","k":"works_on"},{"s":"M-0023","t":"C-0006","k":"verifies","role":"p","note":"Attests that a measured safeguard program (guardrail, filter, monitor) mediated the attested responses; coverage of all traffic is not established."},{"s":"M-0023","t":"C-0005","k":"verifies","role":"s","note":"Property and audit attestations bind responses to a measured model (Chantasantitam et al. (2026), Schnabl et al. (2025))."},{"s":"O-0142","t":"M-0023","k":"works_on"},{"s":"O-0202","t":"M-0023","k":"works_on"},{"s":"O-0141","t":"M-0023","k":"works_on"},{"s":"M-0023","t":"M-0008","k":"depends_on","note":"Current designs rely on TEE measurement and remote attestation."},{"s":"M-0023","t":"M-0012","k":"depends_on","note":"Safeguard evidence is meaningful only when bound to the model actually served."},{"s":"M-0001","t":"C-0005","k":"verifies","role":"p","note":"Checks that sampled recorded outputs are consistent with the declared model, precision and sampling settings."},{"s":"M-0001","t":"C-0009","k":"verifies","role":"s","note":"Bounds how much information can be hidden steganographically in checked outputs. It is not a stand-alone defence against weight exfiltration (Rinberg et al. (2025))."},{"s":"M-0001","t":"C-0004","k":"verifies","role":"s","note":"Proposed as the correctness check in inference-only retrofit plans. Completeness needs other mechanisms (Dean (2026), Design (2026))."},{"s":"O-0100","t":"M-0001","k":"works_on"},{"s":"O-0101","t":"M-0001","k":"works_on"},{"s":"O-0201","t":"M-0001","k":"works_on"},{"s":"O-0202","t":"M-0001","k":"works_on"},{"s":"M-0001","t":"M-0013","k":"depends_on","note":"Network taps or trusted logging supply the recorded inputs and outputs that are sampled."},{"s":"M-0022","t":"C-0008","k":"verifies","role":"p","note":"Bounds the capacity of physical covert channels out of an enclosure, so that monitored links carry all significant traffic."},{"s":"M-0022","t":"C-0009","k":"verifies","role":"s","note":"Supports arguments that weights cannot leave by unmonitored physical routes."},{"s":"M-0022","t":"C-0004","k":"verifies","role":"s","note":"Inference-only designs count on suppressing unmonitored physical channels so that all significant traffic passes the taps (Cankaya (2026))."},{"s":"O-0202","t":"M-0022","k":"works_on"},{"s":"M-0017","t":"C-0004","k":"verifies","role":"s","note":"Protects the integrity of taps, gateways and recomputation hardware used for inference-only verification (Cankaya (2026), Dean (2026))."},{"s":"M-0017","t":"C-0008","k":"verifies","role":"s","note":"Protects network devices that enforce or monitor bandwidth boundaries (Cankaya (2026))."},{"s":"M-0008","t":"C-0005","k":"verifies","role":"p","note":"Attests the software stack that produced responses, and the model too when paired with a weight commitment (see Model identity attestation)."},{"s":"M-0008","t":"C-0006","k":"verifies","role":"s","note":"Can attest that measured policy software, such as filters and logging, wrapped the model (Z (2026)). The evaluation variant is Attestable Audits."},{"s":"M-0008","t":"C-0004","k":"verifies","role":"s","note":"Attests a declared inference deployment, but not that the same chips ran no other workloads (Z (2026))."},{"s":"M-0008","t":"C-0007","k":"verifies","role":"s","note":"PALM attests single-node training and fine-tuning operations (Chantasantitam et al. (2026)). Distributed training is left open."},{"s":"O-0140","t":"M-0008","k":"works_on"},{"s":"O-0141","t":"M-0008","k":"works_on"},{"s":"O-0142","t":"M-0008","k":"works_on"},{"s":"O-0202","t":"M-0008","k":"works_on"},{"s":"O-0206","t":"M-0008","k":"works_on"},{"s":"M-0016","t":"C-0003","k":"verifies","role":"p","note":"Compute and memory probes can reveal whether a GPU is engaged in other work (Monfared et al. (2026))."},{"s":"M-0016","t":"C-0004","k":"verifies","role":"s","note":"Listed as an alternative inference-verification direction that may not need a hardware retrofit (Dean (2026)); bounds spare memory (Cankaya (2026))."},{"s":"M-0016","t":"C-0002","k":"verifies","role":"s","note":"Speed-of-light bounds on signed challenge round trips underlie delay-based location checks; see Chip location verification."},{"s":"O-0101","t":"M-0016","k":"works_on"},{"s":"O-0202","t":"M-0016","k":"works_on"},{"s":"M-0016","t":"M-0014","k":"depends_on","note":"Excluding remote memory during challenges may need physical disconnection or isolation of the device group."},{"s":"M-0006","t":"C-0007","k":"verifies","role":"p","note":"Transcript checks for rules on training compute, data and hyperparameters (Shavit; Choi et al.)."},{"s":"M-0003","t":"C-0004","k":"verifies","role":"p","note":"Proposed as the correctness check for an inference-only retrofit (Dean (2026))."},{"s":"M-0003","t":"C-0007","k":"verifies","role":"s","note":"Proposed for later R&D verification by treating training steps as packets (Dean (2026), Design (2026))."},{"s":"O-0101","t":"M-0003","k":"works_on"},{"s":"O-0201","t":"M-0003","k":"works_on"},{"s":"M-0003","t":"M-0002","k":"depends_on","note":"Packets must be reproducible, which needs deterministic execution."},{"s":"M-0003","t":"M-0013","k":"depends_on","note":"Network taps copy traffic to the recomputation server."},{"s":"M-0021","t":"C-0004","k":"verifies","role":"p","note":"Classifies observed activity as training, inference or non-ML work."},{"s":"M-0021","t":"C-0007","k":"verifies","role":"s","note":"Can flag training on hardware declared for other uses; does not measure training size by itself."},{"s":"O-0202","t":"M-0021","k":"works_on"},{"s":"O-0210","t":"M-0021","k":"works_on"},{"s":"O-0101","t":"M-0021","k":"works_on"},{"s":"M-0021","t":"M-0010","k":"depends_on","note":"Classifiers that use software-read counters need a tamper-resistant, authenticated path for on-chip telemetry."},{"s":"M-0004","t":"C-0005","k":"verifies","role":"p","note":"Binds each proven output to committed weights and a public architecture."},{"s":"M-0004","t":"C-0004","k":"verifies","role":"s","note":"Attestable proposes using proofs to show accounted workloads used an approved, unchanged model."},{"s":"M-0004","t":"C-0006","k":"verifies","role":"s","note":"Attestable proposes that a proof could show an agreed input classifier was applied; South et al. prove evaluation results."},{"s":"O-0120","t":"M-0004","k":"works_on"},{"s":"O-0122","t":"M-0004","k":"works_on"},{"s":"M-0005","t":"C-0007","k":"verifies","role":"p","note":"Proves training followed a committed specification and data; the frontier design adds compute-threshold attestations."},{"s":"M-0005","t":"M-0013","k":"depends_on","note":"The frontier-scale design by Peigné et al. anchors its commitments with an auditor-controlled network tap or an attested SmartNIC."},{"s":"I-0011","t":"C-0004","k":"verifies","role":"p","note":"The stack's stated purpose: retrofitted data centres run only inference."},{"s":"I-0011","t":"C-0005","k":"verifies","role":"s","note":"Recomputation checks sampled packets against the declared model."},{"s":"I-0011","t":"C-0008","k":"verifies","role":"s","note":"Removing back-end networking limits communication between inference units."},{"s":"I-0011","t":"M-0013","k":"realises"},{"s":"I-0011","t":"M-0001","k":"realises"},{"s":"I-0011","t":"M-0003","k":"realises"},{"s":"I-0011","t":"M-0014","k":"realises"},{"s":"I-0011","t":"M-0015","k":"realises"},{"s":"I-0011","t":"M-0017","k":"realises"},{"s":"I-0011","t":"M-0022","k":"realises"},{"s":"O-0201","t":"I-0011","k":"develops"},{"s":"O-0101","t":"I-0011","k":"works_on"},{"s":"I-0011","t":"M-0001","k":"depends_on","note":"Correctness rests on sampled recomputation."},{"s":"I-0011","t":"M-0003","k":"depends_on","note":"Workloads must be organized into reproducible packets."},{"s":"I-0013","t":"C-0005","k":"verifies","role":"s","note":"Attests the software release that served a request. Apple reports that model assets share the code's integrity protection ((SEAR) (2024))."},{"s":"I-0013","t":"M-0008","k":"realises"},{"s":"I-0013","t":"M-0008","k":"depends_on","note":"Relies on hardware attestation: the Secure Enclave on Apple silicon servers, and Intel TDX, NVIDIA confidential computing and Google's Titan chip on Google Cloud."},{"s":"I-0007","t":"C-0005","k":"verifies","role":"p","note":"Users can check that the model answering them is the audited one."},{"s":"I-0007","t":"C-0006","k":"verifies","role":"s","note":"Attests that declared safety benchmarks were run on that model and what they scored; it does not attest runtime safeguards."},{"s":"I-0007","t":"M-0008","k":"realises"},{"s":"I-0007","t":"M-0012","k":"realises"},{"s":"O-0142","t":"I-0007","k":"develops"},{"s":"I-0007","t":"M-0008","k":"depends_on","note":"Built on AWS Nitro Enclaves attestation."},{"s":"I-0005","t":"C-0005","k":"verifies","role":"p","note":"Attestable reports proving y = F(W, x, r) for committed weights W."},{"s":"I-0005","t":"C-0004","k":"verifies","role":"s","note":"Proposed use: showing an accounted workload used an approved, unchanged model."},{"s":"I-0005","t":"C-0006","k":"verifies","role":"s","note":"Proposed use: showing an agreed input classifier was applied."},{"s":"I-0005","t":"M-0004","k":"realises"},{"s":"O-0120","t":"I-0005","k":"develops"},{"s":"I-0016","t":"C-0005","k":"verifies","role":"s","note":"Makes exact-match recomputation of served outputs possible when the verifier runs the same model, engine and hardware (Karvonen et al. (2025))."},{"s":"I-0016","t":"M-0002","k":"realises"},{"s":"O-0214","t":"I-0016","k":"develops"},{"s":"I-0002","t":"C-0005","k":"verifies","role":"p","note":"Checks that outputs are consistent with the declared model, precision and sampling configuration."},{"s":"I-0002","t":"C-0009","k":"verifies","role":"s","note":"Used as the estimator in a weight-exfiltration detection scheme (Rinberg et al. (2025))."},{"s":"I-0002","t":"M-0001","k":"realises"},{"s":"O-0101","t":"I-0002","k":"works_on"},{"s":"I-0014","t":"C-0005","k":"verifies","role":"p","note":"Proves an output follows from a committed model. South et al.'s results reach about a million parameters (South et al. (2024))."},{"s":"I-0014","t":"M-0004","k":"realises"},{"s":"O-0213","t":"I-0014","k":"develops"},{"s":"I-0012","t":"C-0004","k":"verifies","role":"p","note":"Challenged records are screened for inference versus training."},{"s":"I-0012","t":"C-0005","k":"verifies","role":"s","note":"Screening checks that the model is on an agreed whitelist."},{"s":"I-0012","t":"C-0006","k":"verifies","role":"s","note":"Screening checks that outputs are free of blacklisted uses, including with inspector agents."},{"s":"I-0012","t":"C-0010","k":"verifies","role":"s","note":"Memory challenges and resource accounting are proposed against hidden workloads."},{"s":"I-0012","t":"M-0013","k":"realises"},{"s":"I-0012","t":"M-0001","k":"realises"},{"s":"I-0012","t":"M-0002","k":"realises"},{"s":"I-0012","t":"M-0004","k":"realises"},{"s":"I-0012","t":"M-0015","k":"realises"},{"s":"I-0012","t":"M-0016","k":"realises"},{"s":"I-0012","t":"M-0022","k":"realises"},{"s":"O-0202","t":"I-0012","k":"develops"},{"s":"I-0012","t":"M-0013","k":"depends_on","note":"Taps are the default evidence-capture mechanism."},{"s":"I-0012","t":"M-0002","k":"depends_on","note":"Plan A evaluation relies on exact replay of declared computation."},{"s":"I-0009","t":"C-0002","k":"verifies","role":"p","note":"Certifies a bounded region in which an attested workload's platform was running at a given time."},{"s":"I-0009","t":"M-0018","k":"realises"},{"s":"O-0180","t":"I-0009","k":"develops"},{"s":"I-0009","t":"M-0008","k":"depends_on","note":"Location evidence is bound to a hardware-rooted TEE attestation quote."},{"s":"I-0004","t":"C-0004","k":"verifies","role":"p","note":"Proves matrix-multiplication work for consensus; not applied to bounding the spare capacity of declared hardware that could run training."},{"s":"I-0004","t":"C-0003","k":"verifies","role":"s","note":"Proves work for consensus; keeping declared hardware provably busy, as an alternative to showing it idle, is not demonstrated."},{"s":"I-0004","t":"C-0010","k":"verifies","role":"s","note":"On declared hardware only; cannot find undeclared facilities. Not applied to bounding spare capacity."},{"s":"I-0004","t":"M-0007","k":"realises"},{"s":"O-0121","t":"I-0004","k":"develops"},{"s":"I-0004","t":"M-0002","k":"depends_on","note":"The verifier recomputes a tile bit for bit, reproducing GPU arithmetic off the GPU with the Hawkeye technique."},{"s":"I-0017","t":"C-0005","k":"verifies","role":"p","note":"Both parties approve the attested workload that runs a private evaluation against the model and prompts they submit (Trask et al. (2026))."},{"s":"I-0017","t":"M-0025","k":"realises"},{"s":"O-0215","t":"I-0017","k":"develops"},{"s":"I-0017","t":"M-0008","k":"depends_on","note":"Both parties rely on remote attestation of the Intel TDX and NVIDIA H100 confidential-computing stack."},{"s":"I-0010","t":"C-0009","k":"verifies","role":"p","note":"Designed to keep weights and inference data inside the facility; the report does not describe how an external party would verify this."},{"s":"I-0010","t":"C-0005","k":"verifies","role":"s","note":"The compute sanctum checks resident weights against reference measurements before serving."},{"s":"I-0010","t":"C-0004","k":"verifies","role":"s","note":"Scoped to serving already-trained models."},{"s":"I-0010","t":"M-0014","k":"realises"},{"s":"I-0010","t":"M-0022","k":"realises"},{"s":"O-0200","t":"I-0010","k":"develops"},{"s":"I-0010","t":"M-0012","k":"depends_on","note":"Integrity checks compare loaded weights with reference measurements from a trusted setup."},{"s":"I-0008","t":"C-0004","k":"verifies","role":"p","note":"SASH describes the aim as distinguishing inference from training in data centres ((SASH) (2026))."},{"s":"I-0008","t":"C-0005","k":"verifies","role":"s","note":"Recomputation uses another copy of the declared model ((SASH) (2026), (SASH) (2026))."},{"s":"I-0008","t":"M-0013","k":"realises"},{"s":"I-0008","t":"M-0001","k":"realises"},{"s":"O-0160","t":"I-0008","k":"develops"},{"s":"O-0206","t":"I-0008","k":"works_on"},{"s":"I-0008","t":"M-0002","k":"depends_on","note":"The recomputation check compares output text exactly."},{"s":"I-0008","t":"M-0017","k":"depends_on","note":"The logger and recomputation cluster must be protected against tampering."},{"s":"I-0006","t":"C-0005","k":"verifies","role":"p","note":"Clients check that the served weights match a committed root hash."},{"s":"I-0006","t":"M-0012","k":"realises"},{"s":"I-0006","t":"M-0008","k":"realises"},{"s":"O-0141","t":"I-0006","k":"develops"},{"s":"I-0006","t":"M-0008","k":"depends_on","note":"Relies on AMD SEV-SNP or Intel TDX attestation and NVIDIA GPU confidential computing."},{"s":"I-0001","t":"C-0005","k":"verifies","role":"p","note":"Checks that the provider produced outputs with the claimed model weights, prompt and precision."},{"s":"I-0001","t":"M-0001","k":"realises"},{"s":"O-0100","t":"I-0001","k":"develops"},{"s":"I-0015","t":"C-0005","k":"verifies","role":"p","note":"A client learns that a delegated inference output came from the declared model and input, if at least one provider is honest (Arun et al. (2025), Ersoy (2025))."},{"s":"I-0015","t":"C-0007","k":"verifies","role":"s","note":"Also covers training and fine-tuning jobs delegated to several providers (Arun et al. (2025))."},{"s":"I-0015","t":"M-0002","k":"realises"},{"s":"I-0015","t":"M-0006","k":"realises"},{"s":"O-0212","t":"I-0015","k":"develops"},{"s":"I-0003","t":"C-0005","k":"verifies","role":"p","note":"Proves an output follows from committed weights and a public architecture."},{"s":"I-0003","t":"M-0004","k":"realises"},{"s":"O-0122","t":"I-0003","k":"develops"}]}