Proposal Explorer

Build a verification proposal from the map's mechanisms. The report shows what their records say about coverage, strengths, gaps and sources.

How it works

  1. Choose a scenario: how far the prover can be trusted, what the verifier may do on site, whether new chips are allowed and whether secrets must stay hidden.
  2. Choose one or more goals. Each goal needs commitments, and each commitment rests on claims from this map.
  3. Pick mechanisms for each claim. The report lists coverage, strengths, gaps and possible additions, each linked to its record and sources.

Every proposal has its own link. The report offers prompts that pair that link with a task for an AI assistant.

Published designs

Start from one of the whole-system designs on this map.

Edit the proposal

Scenario

PresetsRival states, near termRival states, long termRegulator and developersVoluntary transparency

Prover

Verifier access

Hardware

Secrets

Goals
  • Keep capable models from helping anyone develop chemical, biological, radiological or nuclear weapons.

  • Keep AI systems from being used at scale to build more capable AI systems, including recursive self-improvement.

  • Keep every training run below an agreed compute threshold.

  • Serve only models that passed agreed checks, with their required safeguards.

  • Stop large-scale AI computation on demand and show that it stays stopped.

  • Keep the weights of capable models from being copied out of their declared facilities.

Mechanisms

Choose a goal to list the claims it needs and the mechanisms aimed at each.

All mechanisms (25)
  • R2 ↗
  • R2 ↗
  • R1 ↗
  • R1 ↗

    Assumes a semi-trusted prover; this scenario's prover is adversarial.

  • R2 ↗

    Assumes a semi-trusted prover; this scenario's prover is adversarial.

  • R3 ↗
  • R1 ↗

    Needs changes to future chip designs; this scenario uses existing chips.

  • R1 ↗

    Needs changes to future chip designs; this scenario uses existing chips.

  • R1 ↗
  • R3 ↗

    Assumes a semi-trusted prover; this scenario's prover is adversarial.

  • R1 ↗
  • R2 ↗

    Assumes a semi-trusted prover; this scenario's prover is adversarial.

  • R1 ↗
  • R1 ↗
  • R2 ↗

    Assumes a semi-trusted prover; this scenario's prover is adversarial.

  • R3 ↗
  • R1 ↗
  • R2 ↗
  • R3 ↗

    Assumes a semi-trusted prover; this scenario's prover is adversarial.

  • R2 ↗
  • R2 ↗

    The verifier must see weights, data or code, which this scenario keeps secret.

  • R1 ↗
  • R2 ↗
  • R2 ↗
  • R2 ↗

Missing a mechanism? Suggest an edit.

Start from a published design: AI 2040 inference-only verification stack · Low-trust AI compute verification system overview · RAND secure inference data center (SIDC) design. Clear the proposal.

Search

Full search page